Repo: github.com/bvenkata/legacy2mcp
Letting an AI agent call a legacy system is risky. One wrong call to something like DeleteRecord and you have a problem.
legacy2mcp turns a SOAP/WSDL service, REST API or database into an MCP server, and it is safe by default:
Read-only by default. Write-like operations stay hidden until you opt in.
Schema-validated. Every call is checked before it reaches your backend.
Audit-logged. One JSON line per call.
Try it in 60 seconds
bash
pip install legacy2mcp
legacy2mcp init --rest-url https://petstore.swagger.io
legacy2mcp inspect --config config.yaml
For SOAP, use legacy2mcp init --wsdl-url instead.
inspect prints every MCP tool it generated. When it looks right, connect it to Claude Desktop or any MCP client:
json
{
"mcpServers": {
"legacy2mcp": {
"command": "uvx",
"args": ["legacy2mcp", "run", "--config", "/absolute/path/to/config.yaml"]
}
}
}
Known limits
The SOAP write filter is a name heuristic, so use include_operations for anything important. The MCP server has no auth yet, so don't expose it to untrusted callers.
Try it on your own system and tell me what breaks.
Repo: github.com/bvenkata/legacy2mcp · pip install legacy2mcp
Top comments (1)
Authentication Roadmap: Since the tool currently lacks authentication, how do you plan to handle enterprise authentication (such as OAuth2 bearer tokens, mutual TLS, or API keys passed dynamically from the MCP host)?
I'm new to dev.to! Any feedback or thoughts on my posts would be greatly appreciated.