Michael Thomson
Multi-tenant data and MCP platform

Everstream

The hub several of my other systems integrate against. Workspaces own typed collections and streams; each stream is one connection to one external data source, and every tool the platform exposes is filtered to what the calling token is actually entitled to see.

Overview

Everstream exists so that an agent doesn't have to be wired to a database. It publishes an MCP manifest per user — already filtered, with a living-schema block describing that caller's own streams injected into the tool descriptions at serve time — so a Claude application can hand the whole list to the model and dispatch whatever comes back.

What it does
  • 01Workspace-scoped typed collections and streams
  • 02MCP manifest filtered per token
  • 03Account-scoped and per-run API credentials
  • 04Read-only and read-write stream archetypes
  • 05Cross-store composition in domain modules
  • 06Copy-paste integration kits per module

Streams and modules

A stream is one connection to one external source, owned by a collection, typed by its source. A module is a domain surface that ships tools, routes, and panels — and a module either owns a stream type or composes across several, fanning out across more than one store and returning a single answer.

Source types
  • Postgres
  • Firestore
  • Meta Ads
  • Social / web ingest
Per-stream config
  • Permission level on the stream itself
  • Living-schema description per user
  • Top fields surfaced into tool descriptions
Consumers
  • Everagentic
  • Sightly
  • A Figma plugin
  • Third-party client platforms

Two archetypes, decided before any code

Every stream type falls into one of two camps, and picking first is what keeps the safety property real rather than aspirational.

Read-only sources return a frozen client object, so no caller can monkey-patch a write method onto it, and the router file locks down mutating routes in a way that is grep-verifiable. Read-write sources carry an explicit permission level defaulting to read-only, enforced both by the client and by a keyword guard at the query layer that strips comments before scanning and whitelists first-statement verbs per level.

Writes that can't half-happen

Generated output is persisted as a serializable archive-swap: the previous generation is archived and the new one written in one transaction, alongside an audit row recording the generation. A refusal is recorded as an outcome with its exact error rather than silently producing nothing.

Capabilities
  • Serializable archive-swap on every generation
  • Audit row per generation, refusals included
  • Org-scoped rows with uniqueness re-scoped per tenant
  • Contract fixtures covering partial and unmatched records
Built with
Node.jsExpressMongoDBPostgreSQLMCPReactFirestoreMeta Ads APIFigma Plugin API