feat(mcp): fixed tool set on the shared /mcp endpoint - #798
Merged
Merged
Conversation
On the cloud, /mcp now lists the same eight tools for every user and reaches the caller's own tools through them: list connectors, search, describe, run a read-only tool, run a tool that changes data, the workspace guide, kg_how_to_obtain and the configuration link. - Scope is unchanged: connection grant, then MCP role, computed per request by attachVisibleTools; each run executes in the one connector that owns the tool, so a same-named tool elsewhere is never reached. - The read runner refuses tools that are not read-only; the write runner is annotated destructive. - Payment, banking and trading catalog connectors are not served on the shared endpoint; they stay on their server's own URL. - Initialize instructions are static; workspace notes and skills are returned by the guide tool instead. - /mcp/<serverId> is unchanged. Self-hosted keeps direct tools on /mcp unless MCP_SHARED_ENDPOINT_TOOLS=fixed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On the cloud,
/mcpnow lists one fixed set of eight tools for every user, and the caller's own tools are reached through them./mcp/<serverId>is unchanged and keeps listing a server's tools directly. Self-hosted instances keep direct tools on/mcpunlessMCP_SHARED_ENDPOINT_TOOLS=fixed.Tools
anythingmcp_list_connectorsanythingmcp_search_toolsanythingmcp_describe_toolanythingmcp_run_read_toolanythingmcp_run_write_toolanythingmcp_get_workspace_guidekg_how_to_obtainanythingmcp_get_configuration_urlInitialize instructions are one static text. Workspace content is only returned by the guide tool.
Scope and isolation
attachVisibleToolsresolves today: connection grant, then MCP role. A key pinned to one server is narrowed to that server.connectorIds: [tool.connectorId], the tool's own organization for licence and audit), so a same-named tool of another workspace is never found, described or run. Tested with colliding names.paymentsandbanking, plus PAYONE and Sorare) are not served on the shared endpoint; they stay on their server's own URL.Tests
shared-toolset.spec.ts: identical tools/list for different scopes, read/write enforcement, argument validation, exclusions, ambiguous names, colliding names, guide scoping, mode defaults.shared-endpoint.controller.spec.ts: through the controller with a real MCP client: colliding names across workspaces, roles, grants into another workspace, 405 on GET/DELETE, direct mode unchanged./mcp/<serverId>still lists 30 direct tools, legacy 2025-06-18 initialize + tools/list, audit rows written.