Steps 0–10 of the v2 plan, 194 tests passing. Core infrastructure - Shared Redis client (src/redis.ts); all four Redis consumers migrated - Vitest test harness with vitest.config.ts and npm test/test:watch scripts Billing & invoicing (Steps 1–2) - Monthly invoice generation with idempotency (MySQL uq_customer_period unique key) - Cron job with Redis distributed lock (Lua compare-delete, 1-hr TTL) - Invoice emailer via nodemailer (FETCHERPAY SMTP) - Billing middleware: checkLimit gate in handleToolCall; platform attribution fix Email multi-tenancy (Step 3) - EmailCtx = Account | EmailCredentials; imap.ts + smtp.ts accept both - resolveEmailCtx helper in tools.ts; all email tools use customer credentials Analytics + platform health (Steps 4–5) - Chart.js bar charts for platform breakdown and daily activity - Token expiry check in getCredential with dynamic import refresh - platform-health.ts: per-platform health probe with 10-min Redis cache - GET /api/health/platforms; "Token expired" amber badge in dashboard Tool schema filtering (Step 6) - stripAccountParam deep-clones tool schemas; multi-tenant sessions never see the internal account enum OAuth hardening (Step 7) - Atomic auth code consumption: UPDATE SET used=TRUE, check affectedRows - customer_id threaded through oauth_auth_codes → oauth_tokens - getTokenCustomer(); requireAuth resolves req.customer from Bearer token - Consent page requires authenticated session; redirect_uri validated against registered URIs; http://localhost:* loopback wildcard DCR browser flow (Step 8) - ensureOAuthAppRegistered() upserts pre-registered SquareMCP OAuth app on startup with redirect URIs for mcp-callback, localhost:*, claude-desktop, opencode - GET /oauth/connect-mcp → server-side redirect (client_id off frontend) - GET /oauth/mcp-callback → exchanges code, renders config snippet page with copy buttons for Claude Desktop and Codex CLI Webhooks (Step 9) - webhook_url + webhook_secret columns on customers - deliverWebhook(): HMAC-SHA256 signing, 3× exponential retry (1s/4s/16s), Redis DLQ with 7-day TTL on total failure - isValidWebhookUrl(): SSRF protection (blocks RFC-1918, localhost, .local) - POST /api/webhooks/config (secret returned once), GET, DELETE - GET /api/admin/webhooks/dlq/:customerId - WhatsApp POST route uses express.raw() for raw body preservation - Dashboard Webhooks tab with secret-once display and copy button Developer docs (Step 10) - docs/ static HTML site (GitHub Pages, no build pipeline) - index.html: landing page with client + platform overview - getting-started.html: tabbed MCP config for Claude Desktop, Codex CLI, opencode - platforms.html: LinkedIn, TikTok, WhatsApp, Instagram, Twitter, Telegram guides - agent-tutorial.html: complete Node.js agent (Anthropic SDK + MCP SDK), LinkedIn posting loop, extensions for multi-platform + inbound webhook reaction Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
SquareMCP
SquareMCP is the productization path for Hermes: a managed MCP gateway for internal tools.
Positioning
Expose internal tools to AI agents with:
- authentication
- tool permissions
- audit logs
- observability
- managed hosting
The product is aimed at teams building internal AI copilots that need speed, control, and governance.
Offer
Core product
SquareMCP, a managed MCP gateway for internal tools.
Primary buyer
Teams building internal support, operations, and workflow copilots.
Why they buy
- safer access to internal systems
- faster deployment of agent tooling
- auditability for regulated or high-trust environments
Packaging
Free
- 1 workspace
- 2 connectors
- limited monthly tool calls
- community support
Team
Price: $199 to $499 per month
- 10 connectors
- role based permissions
- audit logs
- retries and rate limits
- email support
Business
Price: $1,500 to $3,000 per month
- SSO
- private networking
- longer log retention
- alerts
- SLA
- advanced observability
Enterprise
Price: $20k to $100k+ per year
- VPC or on prem deployment
- compliance features
- dedicated support
- custom connectors
- architecture review
Revenue model
- subscription
- setup fee
- usage
Recommended starting offer:
- $5k to $10k setup
- $500 to $3k monthly
30-day launch sequence
- Ship the landing page with "Book a pilot" CTA
- Write and post the Show HN launch
- Post the short pitch on LinkedIn the same week
- Schedule Product Hunt after initial social proof
Repo layout
incubation/: product strategy and go-to-market notessite/: landing page scaffold
Verification
Run the live site verification suite with:
npm run test:product-site:verifynpm run deploy:product-site:verifynpm run test:product-site:cleanup
Verification notes live in:
site/VERIFICATION.md