Skip to content

MCP server, and connecting apps and CLIs with their own key - #1870

Draft
joepio wants to merge 5 commits into
developfrom
claude/atomic-mcp-r4jdjj
Draft

joepio wants to merge 5 commits into
developfrom
claude/atomic-mcp-r4jdjj

Conversation

@joepio

@joepio joepio commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Requested by Joep · project thread

Before: only the in-app assistant could work with Atomic Data, and the CLIs needed you to paste your agent secret.

After: npx @tomic/mcp connect, atomic-cli connect and ad-generate connect each make a key on your machine and open a link in the app, where you pick which drives it may reach and whether it may edit, then click Allow. Your own secret is never shared. Account settings lists them under Connected apps, each with Revoke. The MCP server then gives any MCP client ten tools to read, search, create, edit and delete in those drives. Setup is in browser/mcp/README.md, cli/README.md and docs/src/js-cli.md.

This is steps 1 and 2 of planning/mcp-endpoint.md (the plan from #1347). The data verbs the assistant used (get, query, search, classes, create, edit) move into @tomic/lib (assistant-tools.ts), together with the compact JSON-AD dialect, short subject refs and class helpers, and useAtomicTools now calls those functions.

How:

  • browser/mcp is a small stdio server on @modelcontextprotocol/sdk. Tools: list_drives, get_resource (documents and meetings include their text), search, semantic_search, query, get_user_classes, get_schema, create_resource, edit_resource, delete_resource (refuses a whole drive). Until approved, every tool answers with the approval link.
  • Connecting is a general lib API (agent-grants.ts): connectAgentUrl builds the link (optionally asking for edit rights or specific resources, which the page preselects), waitForGrant waits for Allow, publishAgentName sets the name shown in settings, grantAgent / grantsTo / revokeAgent do the rest. @tomic/lib/node has loadOrCreateLocalAgent for the key file. The server only lets an agent edit its own Agent resource, so the grant is not recorded there: the ACLs on the shared drives are the record, and a key finds its access by searching for resources that list it. Revoke removes it everywhere, including from what it created.
  • atomic-cli connect (Rust) does the same and writes ~/.config/atomic/config.toml, asking before replacing an existing one. Without a config the CLI now points there instead of prompting for the secret. ATOMIC_AGENT_SECRET and agentSecret still work for scripts and CI.

Not in this PR: editing a document's text over MCP, and a hosted endpoint with OAuth for claude.ai connectors (steps 4 and 5 of the plan).

Related Issues

Part of #1049. This covers the local server with writes; the hosted endpoint is still open there.

Checklist

  • Add changelog entry linking to issue, describe API changes (CHANGELOG.md, browser/CHANGELOG.md)
  • Add or update tests if needed (moved tests follow their modules into lib; new document-text.test.ts and agent-grants.test.ts; MCP, atomic-cli and ad-generate connect, approve, use and revoke exercised end to end in a browser against a local server)
  • Update docs if needed (browser/mcp/README.md, cli/README.md, docs/src/js-cli.md, planning/mcp-endpoint.md)

`@tomic/mcp` (browser/mcp) is a stdio MCP server for Claude Code, Claude
Desktop, Cursor and other clients. It runs locally and signs every edit
with the user's own Agent key, so writes are ordinary signed commits.
Tools: list_drives, get_resource (documents and meetings include their
text), search, semantic_search, query, get_user_classes, get_schema,
create_resource, edit_resource and delete_resource (never a whole drive).

The data verbs behind those tools now live in @tomic/lib
(assistant-tools.ts), and the in-app assistant calls the same functions,
so there is one implementation behind both surfaces. The compact JSON-AD
dialect, short subject refs and class helpers move from the data-browser
to @tomic/lib for the same reason. Reads no longer include the genesis
certificate, which is long and tells a model nothing.

This is steps 1 and 2 of planning/mcp-endpoint.md; a hosted endpoint
with OAuth (for claude.ai connectors) is not part of this change.
@joepio joepio self-assigned this Sep 28, 2026
atomic-mcp now makes a key on the machine it runs on and prints a link.
In the app (/app/connect-agent) the person picks which drives it may
reach and whether it may edit, then clicks Allow. Account settings lists
connected apps with a Revoke button.

Only an agent may edit its own Agent resource, so the grant is not
recorded there: the ACLs on the shared drives are the record. The app
adds the key to read (and write), the MCP finds its access by searching
for resources that list it, and revoking removes it everywhere, including
from what it created. The app remembers which apps were connected on the
private drive, so settings can list them.

ATOMIC_AGENT_SECRET still works for scripts and CI.
Any app that makes its own key (a CLI, a script, the MCP server) can now
ask for access the same way: connectAgentUrl builds the approval link,
optionally asking for edit rights or specific resources, waitForGrant
polls until the person clicks Allow, and publishAgentName sets the name
shown under Connected apps. The approval page honours the write and
target hints as preselections; the person still decides.

The MCP server now uses these instead of its own copies.
atomic-cli connect makes a key on this machine, prints the approval link
(/app/connect-agent), waits for Allow and writes the config. Without a
config the CLI now points there instead of asking for the secret.

ad-generate connect does the same for the codegen CLI, so private
ontologies no longer need an agent secret in atomic.config.json, which
often ends up in a repository. The key file helper moves from the MCP
server into @tomic/lib/node (loadOrCreateLocalAgent), shared by both.

Also adds the new screens' strings to the translation catalogs.
@joepio joepio changed the title Add an MCP server so LLM clients can read and edit Atomic Data MCP server, and connecting apps and CLIs with their own key Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant