Repository navigation
Align MCP origin defaults and credential selection - #80
Merged
Merged
Conversation
The official service stores an omitted or null connection_origin on an HTTP MCP tool as "service" (MV-01). Default it before the existing checks, so saved Agents, inline Session agents and per-Session replacements store exactly the explicit declaration and execution is unchanged. The environment origin and other transports keep their rejection.
Session reads, lists and event snapshots now show the credential that creation implicitly selected for an MCP tool without an explicit credential_id (MV-02), also after it is deleted. Only the response changes: the stored caller intent, retries and dispatch are unchanged, and only a binding whose Vault the Session attached is shown. Selection errors use the official fields (MV-03): a reference without vault_ids, outside the attached Vaults or for another server_url is a 400 invalid_request_error, and several implicit matches a 409 conflict_error. Missing, foreign-tenant and unattached references share one message, and caller values are echoed only within the shared bound.
Update the handler annotations, OpenAPI, CONTRIBUTING, the service README, credentials guide, contract README, the dated alignment section and the operation evidence register (MV).
A stdio tool with an omitted origin reported the explicit-origin error, although explicit service is rejected for it too. Non-HTTP transports now report that only HTTP transport is supported, with the same status, type and code. The official MCP script also deletes its reference Agent.
The projection re-marshalled the tool through a map and reordered its members. Replace only the credential_id value in document order. The unit test checks the order; the stored caller intent is covered by the PostgreSQL storedNull guard.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The minimal pinned-SDK MCP tool
{type, server_label, transport}now works on Core, as it does officially. Session MCP credential selection now projects and reports errors like the official service. The pinned baseline is unchanged (SDK 3.13.0 / d7c41ef /agents=v1).Behavior
connection_originon HTTP transport:"service"for saved Agents, inline Session agents and per-Session replacements.servicedeclaration, so execution is unchanged.environmentand non-HTTP transports stay rejected, now with an accurate message.credential_idshows the implicitly selected attached credential's ID in Session retrieve, list and the created, in-progress and idle event snapshots.vault_ids.noneinput requirement, before any write; caller values echoed only under the shared bounded-echo rule):credential_idwithoutvault_ids: 400 "MCP credential_id requires an attached vault".conflict_error"multiple attached vault credentials match MCP server_url ; specify credential_id".Evidence
credentials.md, both READMEs,official-semantics-alignment.mdandoperation-evidence.md(register MV).Validation
Independent acceptance, written from the requirements only: real Core with PostgreSQL, raw HTTP and the pinned SDK, 551 checks, no official or model calls.
The script was unchanged between runs (same sha256).
Live Turn: real Core, the daemon, native Codex and Kimi K3 on
environment: none, images built from each tree, with a new local MCP test server fixture.connection_originis rejected with 400 and nothing is created.mcp_callreturning the fixture marker, and the Session showsconnection_origin: "service".Tests: Go API, execution and store tests, including a real-PostgreSQL public test for tenants A and B, byte-identical not-found bodies and headers, and a whole-database no-write digest. Also the pinned-SDK official client suite and the TS client and Core Web tests.
Server gate: all
make checktargets, plus Web typecheck, core-doctor, unit tests and build, pass. The Playwright browser cases were not run on the server (no Google Chrome; the user approved the skip).make openapiandmake sqlc-generateare byte-identical.Independent blind review by a fresh Claude Code subagent (the user-approved replacement for GPT-6 Astra). It found no blockers and confirmed:
Its follow-ups are fixed in the last commits: the stdio message, the fixture cleanup, key order and a test guard. They were verified by focused tests and the gate without a new review, per the user's rule.
Not in this change: input after an attached credential is deleted (MV-04) and MCP configuration validation (MV-05/06). No full protocol compatibility is claimed.
Need help on this PR? Tag
@codesmithwith what you need. Autofix is disabled.