Conversation
Serve RFC 9728 path-aware metadata and a /mcp/server-card, alias get-library-docs to query-docs, stop forwarding Cursor IDE tokens to REST, and drop expected cap-0 listen logs. Closes CTX7-2787 Co-authored-by: abdullah.enes.gules <abdullah.enes.gules@gmail.com>
…oint-warnings-09a2
…e origin - Remove the get-library-docs → query-docs redirect. The tool was renamed on 2025-12-29, and 30 days of logs show no MCP client calling the old name. The README keeps the allowlist fixes and a one-line rename note. - The root /.well-known/oauth-protected-resource keeps resource https://mcp.context7.com (RFC 9728: the resource must match the URL the document was built from). Only the path-aware /mcp document names /mcp. - Serve the server card only at the reserved /mcp/server-card. /server-card had no traffic and is not a SEP-2127 location. - Use the same card description as context7.com's server card.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The hosted MCP server forwards Cursor
direct_session tokens to the REST API, where they cause 401 responses. Its path-aware OAuth metadata and server card return 404, and it logs every expected cap-0 subscription refusal./.well-known/oauth-protected-resource/mcpwithresource: https://mcp.context7.com/mcp, and pointWWW-Authenticateat it. The root document keepsresource: https://mcp.context7.com, because RFC 9728 requiresresourceto match the URL the document was built from. JWT audience validation does not change./mcp/server-card, the location SEP-2127 reserves, withapplication/mcp-server-card+json.direct_tokens (also dotted ones) asAuthorization. When the bearer is not a Context7 credential, an explicit Context7 key header is used. REST still validates supported credentials.subscription limit reached (0)refusal. Positive-cap failures stay visible.query-docs.get-library-docswas renamed on 2025-12-29; there is no redirect, because 30 days of logs show no client calling the old name.Clerk check (2026-09-30, development instance)
Clerk accepts
resource=https://mcp.context7.com/mcpthrough the whole flow: authorize, consent, code exchange (anoat_token), and refresh. The token passes Clerkuserinfoand context7app/api/dashboard/whoami. Clerk does not validate the value at authorize (it also acceptsnot-a-url), so the change from origin to/mcpdoes not affect Clerk.Existing users: a token issued with today's
resource=https://mcp.context7.com/refreshes with…/mcp, then again with the origin (rollback), then with an unrelated URL. All return new tokens, so existing OAuth sessions survive the deploy and a rollback.SDK check (
@modelcontextprotocol/client2.0.0, realauth()flow up to the browser redirect): production today sendsresource=https://mcp.context7.com/; this branch sendshttps://mcp.context7.com/mcpfor/mcp/oauthand/mcp?client=claude-code-plugin, found through theWWW-AuthenticateURL.Pair with upstash/context7app#1180; deploy this PR first.
Closes CTX7-2787