Skip to content

feat(mcp): fixed tool set on the shared /mcp endpoint - #798

Merged
keysersoft merged 1 commit into
mainfrom
keysersoft/mcp-fixed-toolset
Sep 29, 2026
Merged

keysersoft merged 1 commit into
mainfrom
keysersoft/mcp-fixed-toolset

Conversation

@keysersoft

Copy link
Copy Markdown
Contributor

On the cloud, /mcp now lists one fixed set of eight tools for every user, and the caller's own tools are reached through them. /mcp/<serverId> is unchanged and keeps listing a server's tools directly. Self-hosted instances keep direct tools on /mcp unless MCP_SHARED_ENDPOINT_TOOLS=fixed.

Tools

Tool Annotations Does
anythingmcp_list_connectors read-only Connectors this connection reaches, with read/write tool counts
anythingmcp_search_tools read-only Keyword / connector / access search over the caller's tools
anythingmcp_describe_tool read-only Full description, input schema, annotations, which runner to use
anythingmcp_run_read_tool read-only Runs a tool whose derived annotations say read-only; refuses anything else
anythingmcp_run_write_tool destructive Runs a tool that creates, changes, deletes or sends
anythingmcp_get_workspace_guide read-only Server and connector instructions plus applied skills, as tool output
kg_how_to_obtain read-only Always listed; answers "switched off" when the workspace disabled the graph
anythingmcp_get_configuration_url read-only Dashboard link and the direct URL of each of the user's servers

Initialize instructions are one static text. Workspace content is only returned by the guide tool.

Scope and isolation

  • The scope is exactly what attachVisibleTools resolves today: connection grant, then MCP role. A key pinned to one server is narrowed to that server.
  • Every run executes in the one connector that owns the tool (connectorIds: [tool.connectorId], the tool's own organization for licence and audit), so a same-named tool of another workspace is never found, described or run. Tested with colliding names.
  • Arguments are validated against the tool's schema before anything runs.
  • Payment, banking and trading catalog connectors (categories payments and banking, plus PAYONE and Sorare) are not served on the shared endpoint; they stay on their server's own URL.

Tests

  • shared-toolset.spec.ts: identical tools/list for different scopes, read/write enforcement, argument validation, exclusions, ambiguous names, colliding names, guide scoping, mode defaults.
  • shared-endpoint.controller.spec.ts: through the controller with a real MCP client: colliding names across workspaces, roles, grants into another workspace, 405 on GET/DELETE, direct mode unchanged.
  • Full backend suite green.
  • Local end-to-end with the built backend and a real Streamable HTTP client: 8 tools listed, OpenPLZ run live, write tool refused on the read runner, Todoist write reaches the connector, Wise refused, guide, KG, configuration link, /mcp/<serverId> still lists 30 direct tools, legacy 2025-06-18 initialize + tools/list, audit rows written.

On the cloud, /mcp now lists the same eight tools for every user and
reaches the caller's own tools through them: list connectors, search,
describe, run a read-only tool, run a tool that changes data, the
workspace guide, kg_how_to_obtain and the configuration link.

- Scope is unchanged: connection grant, then MCP role, computed per
  request by attachVisibleTools; each run executes in the one connector
  that owns the tool, so a same-named tool elsewhere is never reached.
- The read runner refuses tools that are not read-only; the write runner
  is annotated destructive.
- Payment, banking and trading catalog connectors are not served on the
  shared endpoint; they stay on their server's own URL.
- Initialize instructions are static; workspace notes and skills are
  returned by the guide tool instead.
- /mcp/<serverId> is unchanged. Self-hosted keeps direct tools on /mcp
  unless MCP_SHARED_ENDPOINT_TOOLS=fixed.
@keysersoft
keysersoft merged commit 6417b2a into main Sep 29, 2026
14 checks passed
@keysersoft
keysersoft deleted the keysersoft/mcp-fixed-toolset branch September 29, 2026 10:52
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant