Conversation
`@tomic/mcp` (browser/mcp) is a stdio MCP server for Claude Code, Claude Desktop, Cursor and other clients. It runs locally and signs every edit with the user's own Agent key, so writes are ordinary signed commits. Tools: list_drives, get_resource (documents and meetings include their text), search, semantic_search, query, get_user_classes, get_schema, create_resource, edit_resource and delete_resource (never a whole drive). The data verbs behind those tools now live in @tomic/lib (assistant-tools.ts), and the in-app assistant calls the same functions, so there is one implementation behind both surfaces. The compact JSON-AD dialect, short subject refs and class helpers move from the data-browser to @tomic/lib for the same reason. Reads no longer include the genesis certificate, which is long and tells a model nothing. This is steps 1 and 2 of planning/mcp-endpoint.md; a hosted endpoint with OAuth (for claude.ai connectors) is not part of this change.
atomic-mcp now makes a key on the machine it runs on and prints a link. In the app (/app/connect-agent) the person picks which drives it may reach and whether it may edit, then clicks Allow. Account settings lists connected apps with a Revoke button. Only an agent may edit its own Agent resource, so the grant is not recorded there: the ACLs on the shared drives are the record. The app adds the key to read (and write), the MCP finds its access by searching for resources that list it, and revoking removes it everywhere, including from what it created. The app remembers which apps were connected on the private drive, so settings can list them. ATOMIC_AGENT_SECRET still works for scripts and CI.
Any app that makes its own key (a CLI, a script, the MCP server) can now ask for access the same way: connectAgentUrl builds the approval link, optionally asking for edit rights or specific resources, waitForGrant polls until the person clicks Allow, and publishAgentName sets the name shown under Connected apps. The approval page honours the write and target hints as preselections; the person still decides. The MCP server now uses these instead of its own copies.
atomic-cli connect makes a key on this machine, prints the approval link (/app/connect-agent), waits for Allow and writes the config. Without a config the CLI now points there instead of asking for the secret. ad-generate connect does the same for the codegen CLI, so private ontologies no longer need an agent secret in atomic.config.json, which often ends up in a repository. The key file helper moves from the MCP server into @tomic/lib/node (loadOrCreateLocalAgent), shared by both. Also adds the new screens' strings to the translation catalogs.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Joep · project thread
Before: only the in-app assistant could work with Atomic Data, and the CLIs needed you to paste your agent secret.
After:
npx @tomic/mcp connect,atomic-cli connectandad-generate connecteach make a key on your machine and open a link in the app, where you pick which drives it may reach and whether it may edit, then click Allow. Your own secret is never shared. Account settings lists them under Connected apps, each with Revoke. The MCP server then gives any MCP client ten tools to read, search, create, edit and delete in those drives. Setup is inbrowser/mcp/README.md,cli/README.mdanddocs/src/js-cli.md.This is steps 1 and 2 of
planning/mcp-endpoint.md(the plan from #1347). The data verbs the assistant used (get, query, search, classes, create, edit) move into@tomic/lib(assistant-tools.ts), together with the compact JSON-AD dialect, short subject refs and class helpers, anduseAtomicToolsnow calls those functions.How:
browser/mcpis a small stdio server on@modelcontextprotocol/sdk. Tools:list_drives,get_resource(documents and meetings include their text),search,semantic_search,query,get_user_classes,get_schema,create_resource,edit_resource,delete_resource(refuses a whole drive). Until approved, every tool answers with the approval link.agent-grants.ts):connectAgentUrlbuilds the link (optionally asking for edit rights or specific resources, which the page preselects),waitForGrantwaits for Allow,publishAgentNamesets the name shown in settings,grantAgent/grantsTo/revokeAgentdo the rest.@tomic/lib/nodehasloadOrCreateLocalAgentfor the key file. The server only lets an agent edit its own Agent resource, so the grant is not recorded there: the ACLs on the shared drives are the record, and a key finds its access by searching for resources that list it. Revoke removes it everywhere, including from what it created.atomic-cli connect(Rust) does the same and writes~/.config/atomic/config.toml, asking before replacing an existing one. Without a config the CLI now points there instead of prompting for the secret.ATOMIC_AGENT_SECRETandagentSecretstill work for scripts and CI.Not in this PR: editing a document's text over MCP, and a hosted endpoint with OAuth for claude.ai connectors (steps 4 and 5 of the plan).
Related Issues
Part of #1049. This covers the local server with writes; the hosted endpoint is still open there.
Checklist
CHANGELOG.md,browser/CHANGELOG.md)document-text.test.tsandagent-grants.test.ts; MCP,atomic-cliandad-generateconnect, approve, use and revoke exercised end to end in a browser against a local server)browser/mcp/README.md,cli/README.md,docs/src/js-cli.md,planning/mcp-endpoint.md)