Skip to content

Fix MCP discovery and stop forwarding Cursor tokens - #3197

Open
enesgules wants to merge 5 commits into
masterfrom
abdullah/humio-endpoint-warnings-09a2
Open

enesgules wants to merge 5 commits into
masterfrom
abdullah/humio-endpoint-warnings-09a2

Conversation

@enesgules

@enesgules enesgules commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The hosted MCP server forwards Cursor direct_ session tokens to the REST API, where they cause 401 responses. Its path-aware OAuth metadata and server card return 404, and it logs every expected cap-0 subscription refusal.

  • Serve RFC 9728 metadata at /.well-known/oauth-protected-resource/mcp with resource: https://mcp.context7.com/mcp, and point WWW-Authenticate at it. The root document keeps resource: https://mcp.context7.com, because RFC 9728 requires resource to match the URL the document was built from. JWT audience validation does not change.
  • Serve a Server Card v1 document at /mcp/server-card, the location SEP-2127 reserves, with application/mcp-server-card+json.
  • Do not forward Cursor direct_ tokens (also dotted ones) as Authorization. When the bearer is not a Context7 credential, an explicit Context7 key header is used. REST still validates supported credentials.
  • Suppress only the exact subscription limit reached (0) refusal. Positive-cap failures stay visible.
  • README: Copilot allowlists and the tools list use query-docs. get-library-docs was renamed on 2025-12-29; there is no redirect, because 30 days of logs show no client calling the old name.

Clerk check (2026-09-30, development instance)

Clerk accepts resource=https://mcp.context7.com/mcp through the whole flow: authorize, consent, code exchange (an oat_ token), and refresh. The token passes Clerk userinfo and context7app /api/dashboard/whoami. Clerk does not validate the value at authorize (it also accepts not-a-url), so the change from origin to /mcp does not affect Clerk.

Existing users: a token issued with today's resource=https://mcp.context7.com/ refreshes with …/mcp, then again with the origin (rollback), then with an unrelated URL. All return new tokens, so existing OAuth sessions survive the deploy and a rollback.

SDK check (@modelcontextprotocol/client 2.0.0, real auth() flow up to the browser redirect): production today sends resource=https://mcp.context7.com/; this branch sends https://mcp.context7.com/mcp for /mcp/oauth and /mcp?client=claude-code-plugin, found through the WWW-Authenticate URL.

Pair with upstash/context7app#1180; deploy this PR first.

Closes CTX7-2787

Serve RFC 9728 path-aware metadata and a /mcp/server-card, alias get-library-docs to query-docs, stop forwarding Cursor IDE tokens to REST, and drop expected cap-0 listen logs.

Closes CTX7-2787

Co-authored-by: abdullah.enes.gules <abdullah.enes.gules@gmail.com>
@linear-code

linear-code Bot commented Sep 15, 2026

Copy link
Copy Markdown

CTX7-2787

@enesgules enesgules changed the title Advertise path-aware MCP PRM, restore get-library-docs, and silence listen-log noise Fix MCP discovery and redirect legacy tool calls without adding a tool Sep 17, 2026
…e origin

- Remove the get-library-docs → query-docs redirect. The tool was renamed
  on 2025-12-29, and 30 days of logs show no MCP client calling the old
  name. The README keeps the allowlist fixes and a one-line rename note.
- The root /.well-known/oauth-protected-resource keeps resource
  https://mcp.context7.com (RFC 9728: the resource must match the URL the
  document was built from). Only the path-aware /mcp document names /mcp.
- Serve the server card only at the reserved /mcp/server-card. /server-card
  had no traffic and is not a SEP-2127 location.
- Use the same card description as context7.com's server card.
@enesgules enesgules changed the title Fix MCP discovery and redirect legacy tool calls without adding a tool Fix MCP discovery and stop forwarding Cursor tokens Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants