Skip to content

Clarify OAuth reconnect generated UI guidance - #483

Merged
kentcdodds merged 3 commits into
mainfrom
cursor/fix-open-generated-ui-oauth-guidance-a4e9
May 15, 2026
Merged

kentcdodds merged 3 commits into
mainfrom
cursor/fix-open-generated-ui-oauth-guidance-a4e9

Conversation

@kentcdodds

@kentcdodds kentcdodds commented May 15, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Credential setup guidance points to /connect/oauth for OAuth integrations/reconnects and /connect/secret for API key, PAT, token, and credential entry or rotation.
  • open_generated_ui MCP-facing text describes saved package apps and inline MCP App workflows.
  • Secret capability descriptions, search guidance, and missing-secret execution guidance all use the standard connect page terminology.

Behavior

OAuth reconnect links are plain /connect/oauth?provider=... links derived from integration metadata. Secret collection and rotation use /connect/secret. open_generated_ui remains the package/app UI surface.

Testing

  • Not run; final changes are instruction, description, and tool-message guidance only.
Open in Web Open in Cursor 

Summary by CodeRabbit

  • Documentation

    • Updated credential and secrets management guidance to direct users to use dedicated connection flows (/connect/oauth for OAuth, /connect/secret for API keys and PATs) instead of manual entry methods.
  • Bug Fixes

    • Improved error messages when secrets are missing, now providing clear next steps directing users to the appropriate credential connection page rather than generic UI.

Review Change Stack

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@coderabbitai

coderabbitai Bot commented May 15, 2026 •

Copy link
Copy Markdown

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 90f964bf-d30b-479d-a00e-d27bab1cf346

📥 Commits

Reviewing files that changed from the base of the PR and between e0781f4 and 639a10b.

📒 Files selected for processing (10)
  • docs/use/first-steps.md
  • docs/use/secrets-and-values.md
  • packages/worker/src/mcp/capabilities/secrets/secret-delete.ts
  • packages/worker/src/mcp/capabilities/secrets/secret-list.ts
  • packages/worker/src/mcp/capabilities/secrets/secret-set.ts
  • packages/worker/src/mcp/executor.ts
  • packages/worker/src/mcp/server-instructions.ts
  • packages/worker/src/mcp/tools/execute.ts
  • packages/worker/src/mcp/tools/open-generated-ui.ts
  • packages/worker/src/mcp/tools/search.ts

📝 Walkthrough

Walkthrough

This PR updates documentation, MCP capability descriptions, error handling, and tool guidance to establish /connect/oauth and /connect/secret as the standard credential setup flows, replacing prior "do not paste secrets in chat" messaging across user docs, error messages, and tool descriptions.

Changes

Credential Connect Flow Updates

Layer / File(s) Summary
User documentation updates
docs/use/first-steps.md, docs/use/secrets-and-values.md
Replaced "do not paste secrets in chat" guidance with instructions to use saved secrets and credential connect flows (/connect/oauth for OAuth, /connect/secret for API keys/PATs).
Secret capabilities and error handling
packages/worker/src/mcp/capabilities/secrets/secret-delete.ts, secret-list.ts, secret-set.ts, packages/worker/src/mcp/executor.ts
Updated secret-delete, secret-list, and secret-set capability descriptions to reference /connect/secret. Changed ExecutionErrorDetails for secret_required errors to use connect_secret action type instead of open_generated_ui, and updated error logic to send users to /connect/secret?name=... with URL-encoded secret name.
Tool and server instructions
packages/worker/src/mcp/server-instructions.ts, packages/worker/src/mcp/tools/execute.ts, open-generated-ui.ts, search.ts
Updated execute, search, and open-generated-ui tool descriptions to direct credential collection/rotation to /connect/oauth and /connect/secret. Reorganized base MCP server instructions to include open-generated-ui as step 3 in the three-step flow, replacing prior standalone "do not paste secrets" conventions.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

  • kentcdodds/kody#110: Implements the /connect/secret route and handler that persists secrets as referenced by this PR's error handling and guidance updates.
  • kentcdodds/kody#86: Implements the /connect/secret and /connect/secret.json endpoint infrastructure that this PR directs users toward.
  • kentcdodds/kody#476: Earlier update to MCP server instruction and tool description text in overlapping files and locations.

Poem

🐰 No more secrets lurking in chat,
Connect flows now show where they're at,
/connect/secret guides the way,
/connect/oauth saves the day!
Credentials flow with grace and flair. 🔐

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/fix-open-generated-ui-oauth-guidance-a4e9

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint skipped: no ESLint configuration detected in root package.json. To enable, add eslint to devDependencies.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

cursoragent and others added 2 commits May 15, 2026 20:58
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kentcdodds
kentcdodds marked this pull request as ready for review May 15, 2026 21:07
@kentcdodds
kentcdodds merged commit 4056143 into main May 15, 2026
4 checks passed
@kentcdodds
kentcdodds deleted the cursor/fix-open-generated-ui-oauth-guidance-a4e9 branch May 15, 2026 21:08

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 639a10b. Configure here.

- ${conversationIdGuidance}
- \`memoryContext\`: short and task-focused. Kody may use it to surface a few relevant long-term memories and suppress repeats within the same \`conversationId\`.
- Do not ask the user to paste secrets in chat; use saved secrets or \`open_generated_ui\`.
- Credential setup uses the standard connect pages: \`/connect/oauth\` for OAuth integrations and reconnects, \`/connect/secret\` for API keys, PATs, and other user-provided secrets.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security prohibition against pasting secrets in chat removed

High Severity

Every explicit "never ask the user to paste a secret/token/credential into chat" prohibition has been removed from the always-present MCP system instructions (server-instructions.ts), tool descriptions (execute.ts, open-generated-ui.ts), and capability descriptions (secret-list.ts, secret-set.ts, secret-delete.ts). The replacement text tells the AI what to use (/connect/secret, /connect/oauth) but no longer tells it what not to do. The only remaining prohibition lives in docs/guides/connect-secret.md, which is loaded on-demand. Positive instructions alone don't prevent the AI from also offering to accept secrets in chat as a fallback.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 639a10b. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants