MCP Server for Enterprise Knowledge
EKOS is an open-source MCP server that gives AI agents structured, evidence-backed knowledge of your code, databases and documentation. Read-only, cited.
The Model Context Protocol (MCP) is how AI agents call tools. EKOS is an MCP server whose tools answer questions about your systems: what a table contains, what calls a function, what breaks if a column changes, what a status code means. It answers from a compiled knowledge ledger, not from a fresh search through files, and every answer cites the file and line it came from.
Start the server
ekos mcp serve --workspace /path/to/workspace # stdio (Claude Code, desktop clients)
ekos mcp serve --workspace /path/to/workspace --tcp 127.0.0.1:7331 # several clients, one server
ekos mcp serve --workspace /path/to/workspace --http 127.0.0.1:8080 # Streamable HTTP: VS Code, Visual Studio, ChatGPT
Register it with Claude Code:
claude mcp add ekos -- ekos --config /path/to/ekos.toml mcp serve --workspace /path/to/workspace
TCP and HTTP can require a bearer token. Bind them to loopback or a trusted network. See MCP Configuration.
What agents can ask
| Tool | What it answers |
|---|---|
ekos_search |
find objects by name or meaning: lexical, vector or hybrid |
ekos_query, ekos_retrieve |
a compiled answer as source-cited claims, plus the query plan behind it, with no LLM involved |
ekos_state |
one object in full: properties, relationships and evidence |
ekos_neighborhood, ekos_dependents, ekos_impact |
what is connected; what depends on this; what breaks, several hops out |
ekos_ekl |
structured queries in EKOS's query language, including point in time (AS OF) |
ekos_transformation_explain |
what a stored procedure, SQL view or ETL job does, step by step |
ekos_semantics_lookup |
what a business term or a coded value means, with its review status |
ekos_audit, ekos_diff |
which run wrote a fact, and what changed since a date |
The complete list, with arguments and limits: MCP Tools.
Read-only by design
Agents read EKOS knowledge. They do not change it. Every tool goes through a read-only runtime, except two review tools that append a review event and an opt-in note tool that writes only an inbox file. Some decisions are deliberately human-only and have no MCP tool at all: confirming a business definition, approving a database migration, promoting an agent's note. Unknown tool arguments are refused rather than silently ignored, and a truncated result says so.
Why not just let the agent read the files?
It can, and for a question whose answer sits at a known line, a direct grep is cheapest. Most questions are not like that. On a real 2,022-file repository, answering from the compiled ledger took 67–93% fewer tokens than searching raw source. One case, where the agent already knew the exact line, went the other way, and is published too. See the benchmark.