Repository navigation
feat(mcp): server.json for the official MCP registry — one remote entry on the user's own deployment, no npm entry (#21494) - #21530
Merged
objectstack-fleet[bot] merged 2 commits intoOct 3, 2026
Conversation
The registry can truthfully carry one entry for ObjectStack today: a
streamable-http remote whose host is the user's own deployment
(https://{host}/api/v1/mcp). Every CLI-served deployment mounts that route
default-on and admits OAuth or an osk_ key, measured on the published
@objectstack/cli 17.6.0.
No npm package entry: @objectstack/mcp declares no bin in any published
version, so `npx @objectstack/mcp` runs nothing, and the stdio transport
starts only as a mode of the user's app under `os start` in its project
directory, which a registry package entry has no field to express. With no
npm entry there is no mcpName ownership marker to publish, so no manifest
changes. The file is not in packages/mcp's files[], so nothing ships.
Validated with mcp-publisher 1.8.1 against the live registry and with ajv
against the published 2025-12-11 schema.
Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016GiHYRmLSNWTfbX9gVQkpz
…p-registry-server-json
Contributor
📓 Docs Drift Check
What this run could not see
Coarse fallback — 12 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): |
This was referenced Oct 3, 2026
objectstack-fleet
Bot
deleted the
claude/issue-21494-mcp-registry-server-json
branch
October 3, 2026 04:19
This was referenced Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #21494
Clause-②: no (registry metadata; no accept-set or published API surface change)
What this adds
packages/mcp/server.jsonis oneserver.jsonfor the official MCP registry, written from what ships. It is metadata only. It does not change code, any manifest or any workflow, and it adds no CI gate.It carries one entry: a
streamable-httpremote. The host in that URL is the user's own deployment:https://{host}/api/v1/mcp. It carries no npm package entry.The submission (
mcp-publisher loginandpublishunder the project's account) stays with the maintainer, on theMaintainer-action:line of #20791. So do the mcp.so, Smithery and PulseMCP listings. #20791 remains open.Measured first: which entry the registry can truthfully carry
Remote entry: yes
Measured on the published
@objectstack/cli@17.6.0. The command wasnpx -y @objectstack/cli@17.6.0 start --home SCRATCH -p RANDOM --no-ui. It booted the empty kernel and was torn down by its recorded process group.GET /api/v1/discovery"mcp": "/api/v1/mcp"initializeonPOST /api/v1/mcp, anonymous401, withWWW-Authenticate: Bearer realm="ObjectStack MCP", resource_metadata=".../.well-known/oauth-protected-resource"initializewithx-api-key: osk_…(key minted byPOST /api/v1/keysafter an email sign-up)200,serverInfo {"name":"objectstack","version":"1.0.0"}initializewithAuthorization: Bearer osk_…200createDispatcherPlugindefaultsprefixto/api/v1(packages/runtime/src/dispatcher-plugin.ts), andos serveconstructs it with no prefix.{host}in a remote URL and requireshttps(IsValidRemoteURLininternal/validators/utils.go, registry repo atbf4e88cb).x-api-keyis declared optional and secret. On https deployments the OAuth track is live.plugin-authrefuses it only on public plain HTTP.npm package entry over stdio: no
@objectstack/mcpcannot be run with npx. None of its 64 published versions declares abin(npm packument).npx -y @objectstack/mcp@17.6.0exits 1 withnpm error could not determine executable to run.OS_MCP_STDIO_ENABLED=true OS_MCP_STDIO_API_KEY=osk_… os start, run in the project directory (content/docs/ai/connect-mcp.mdx,packages/cli/src/commands/start.ts).npx -y @objectstack/cli@17.6.0 --versiondoes resolve a bin, because both bins point at one file. The registry'sPackagedefinition has no working-directory field. Its properties are environmentVariables, fileSha256, identifier, packageArguments, registryBaseUrl, registryType, runtimeArguments, runtimeHint, transport and version.Artifact: none (empty kernel — install apps via the Console marketplace)). The stdio plugin then refuses the key and the boot exits 1:OS_MCP_STDIO_API_KEY did not resolve to a valid identity … Refusing to start stdio (ADR-0101).So an npm entry would name nothing that runs today. Whether to ship a standalone stdio launcher is a product question, not this card's.
Ownership marker (A3): not owed, manifest untouched
mcpNamefromregistry.npmjs.org/{identifier}/{version}(internal/validators/registries/npm.go).@objectstack/mcp@17.6.0has nomcpName.With no npm entry, no marker is owed. So
package.jsonis not edited, and no changeset is added.Placement (A4)
mcp-publisher publishandmcp-publisher validateread./server.jsonfrom the working directory by default, or the path they are given.server.json(git grepfound zero before this PR).packages/mcp/server.json, beside the package whose surface it describes, andrepository.subfolderpoints there.mcp-publisher publish packages/mcp/server.json, or run it frompackages/mcp.npm pack --dry-runinpackages/mcplists CHANGELOG.md, LICENSE, README.md and package.json, with README.md as the positive control.server.jsonis absent, becausefilesnames onlydist,README.mdandCHANGELOG.md. This is why the PR carriesskip-changeset.Validation
All runs were at HEAD
9eda36398c. Each was a one-off local run. Nothing is committed.mcp-publisher validate packages/mcp/server.json. mcp-publisher 1.8.1 (commitf52dc85) is the latest release.POST /v0/validate, which runs schema and semantic validation (registry/v0/version: 1.8.1)✅ server.json is valid, exit 0POST https://registry.modelcontextprotocol.io/v0/validate{"valid":true,"issues":[]}https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json, schema version 2025-12-11, the registry'sCurrentSchemaVersion(fetched copy sha2563fba0959…)VALID, exit 0Negative controls. These show that both validators can fail:
{tenant}in the URL, with onlyhostdeclared. mcp-publisher exits 1 withinvalid-templated-url. ajv says VALID, because the schema alone cannot see this.http://{host}/…URL. mcp-publisher exits 1 withinvalid-remote-url. ajv says VALID.The registry validator is the stronger of the two, and the file passes both.
NOT MEASURED: namespace authentication at publish. It needs the project's account.
Choices the maintainer may change before submitting
name:io.github.objectstack-ai/objectstack. This is the GitHub-org namespace, and it matchesrepository.url. The registry docs say a login must be an Owner of the objectstack-ai org to publish under it. The alternative is a domain namespace,ai.objectstack/objectstack, which needs a DNS TXT record on the apex. Only this one line changes.version:17.6.0. This is the npmlatestrelease, the one whose surface this entry was written from. The registry needs a new version on every publish. Nothing here bumps it, because the card rules out a new gate.websiteUrl:https://objectstack.ai/docs/ai/connect-mcp. It maps tocontent/docs/ai/connect-mcp.mdxunder the docs site's/docsmount (apps/docs/lib/source.ts, the mappingcheck-published-readme-links.mjsreads). NOT MEASURED live: this container's egress proxy refuses CONNECT to objectstack.ai with 403.Acceptance notes
serverInfo.version"1.0.0"(measured above).MCPServerPluginOptions.versionis documented as "Defaults to package version." The registry calls server.jsonversionthe equivalent of MCPImplementation.version, so today the two differ: 17.6.0 here, 1.0.0 from the server. This is reported to the seat as a finding and is not touched here.https://{host}/api/v1/mcp.GET /v0/servers?search=objectstackanswered 0, and the controlsearch=weatheranswered 1.Gates
node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstackat9eda36398cnamed 42 commands. All 42 ran and exited 0. The--ranreconciliation printed "42 derived famil(ies) accounted for — 42 run, 0 NOT-MEASURED (a DERIVED zero …)". Four of them needed a workspace build first (turbo, 72 of 72 tasks):check:dts-closure,check:dual-build-cjs-loads,check:lean-entry-closureandcheck:sourcemap-no-sources-content.@objectstack/mcp.vitest runpassed 34 files and 382 tests.typecheckexited 0.pnpm lintrun:eslint.config.mjs: everyfilesglob names only{ts,tsx,mts,cts,js,jsx,mjs,cjs}. ESLint's own verdict on this file is "File ignored because no matching configuration was supplied."--format json: 1 result with 0 errors and 1 warning (that notice). So 0 files were linted.parserOptions.projectorprojectService. No source file referencesserver.json(git grepexit 1, control exit 0). So this diff cannot change the verdict on any other file.Generated by Claude Code