Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
3bf0ed0
feat: add secret-aware fetch gateway
cursoragent Mar 27, 2026
4c3bc65
Fix account secrets approval flow
cursoragent Mar 27, 2026
35fd55d
Fix secret placeholder gateway guards
cursoragent Mar 27, 2026
98b2683
Fix approved fetch test secret usage
cursoragent Mar 27, 2026
8dbf01d
Harden fetch gateway enforcement
cursoragent Mar 27, 2026
55fbed9
Fix UI events and tests
cursoragent Mar 27, 2026
9d93730
Fix test stubs and MCP e2e flow
cursoragent Mar 27, 2026
3223c76
Fix account secrets POST route
cursoragent Mar 27, 2026
e471112
Enhance documentation for secret management in MCP capabilities
kentcdodds Mar 27, 2026
ceb4295
Remove secret update and get capabilities from MCP secrets domain
kentcdodds Mar 27, 2026
aae4b55
Refactor account secrets management and enhance UI
kentcdodds Mar 27, 2026
2b84553
Remove MCP Apps starter guide and update references
kentcdodds Mar 27, 2026
d7475bc
Update smoke test to reflect changes in account management UI
kentcdodds Mar 27, 2026
a0e13cc
Fix smoke test heading and share secret path helper
cursoragent Mar 27, 2026
b9ed16e
Add structured execute guidance for auth failures.
kentcdodds Mar 27, 2026
f8fe65b
Format files updated by validation.
kentcdodds Mar 27, 2026
ee24eec
Move account secret route helpers into shared module.
kentcdodds Mar 27, 2026
4170b44
Fix secret host validation and share approval helpers
cursoragent Mar 27, 2026
2f32b12
Remove execute-time secrets helper alias.
kentcdodds Mar 27, 2026
48b50bb
Format executor cleanup.
kentcdodds Mar 27, 2026
7b784b7
Enhance secret management guidance across MCP documentation
kentcdodds Mar 27, 2026
539743f
Tighten secret collection guidance in MCP tools.
kentcdodds Mar 27, 2026
c86253d
Format account secrets route.
kentcdodds Mar 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ This file is intentionally brief. Detailed instructions live in focused docs:
- [docs/agents/oxlint-js-plugins.md](./docs/agents/oxlint-js-plugins.md)
- [docs/agents/remix/index.md](./docs/agents/remix/index.md)
- [docs/agents/cloudflare-agents-sdk.md](./docs/agents/cloudflare-agents-sdk.md)
- [docs/agents/mcp-apps-starter-guide.md](./docs/agents/mcp-apps-starter-guide.md)
- [docs/agents/mcp-apps-spec-notes.md](./docs/agents/mcp-apps-spec-notes.md)
- MCP capabilities (search/execute graph, domains, registry):
- [docs/agents/adding-capabilities.md](./docs/agents/adding-capabilities.md)
- Project setup references:
Expand Down
16 changes: 16 additions & 0 deletions docs/agents/adding-capabilities.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,11 @@
User-persisted codemode skills (`meta` domain) are documented in
[`mcp-skills.md`](./mcp-skills.md).

Secret-bearing outbound requests are governed by
[`secret-host-approval.md`](./secret-host-approval.md). Read that doc before
adding any capability or workflow that saves secrets, uses placeholder-based
`fetch`, or discusses host approval.

Kody exposes a compact MCP surface (`search` and `execute`) and keeps the real
capability graph behind that surface. To add a new capability, register it
through a **domain** and the **builtin registry**—do not add a new public MCP
Expand Down Expand Up @@ -188,6 +193,10 @@ Keep handlers focused on host-side work. The sandboxed model code should only
orchestrate capability calls; it should not hold credentials or perform raw
network access.

For secret-aware outbound requests, treat host approval as admin-only policy. Do
not add MCP-side or execute-time mutation paths for a secret's allowed hosts.
Only the authenticated account admin UI may widen that policy.

`CapabilityContext` provides:

- `env`: access to Cloudflare bindings such as D1, KV, R2, AI, and Worker
Expand All @@ -202,6 +211,13 @@ Use handlers for things like:
- Cloudflare product APIs
- containers or sandbox orchestration

If a capability surfaces secret metadata or secret-using network behavior, make
the description explicit about the approval model:

- secret save/update does not authorize outbound use
- a blocked host must be approved through the account admin UI
- the agent should stop and surface the approval link instead of retrying

## Testing

Public MCP behavior should be verified through the compact tool surface:
Expand Down
27 changes: 27 additions & 0 deletions docs/agents/mcp-apps-spec-notes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
# MCP Apps Spec Notes

This repo currently uses one generic MCP Apps shell rather than a family of app
implementations. For MCP Apps behavior, prefer the upstream spec and API docs
over project-local conventions.

## Read First

- [MCP Apps API docs](https://apps.extensions.modelcontextprotocol.io/api/)
- [MCP Apps stable spec](https://github.com/modelcontextprotocol/ext-apps/blob/main/specification/2026-01-26/apps.mdx)
- [MCP UI introduction](https://mcpui.dev/guide/introduction)
- [`@modelcontextprotocol/ext-apps`](https://github.com/modelcontextprotocol/ext-apps)

## Repo-Specific Notes

- The repo exposes a single generic shell via `open_generated_ui`.
- Saved apps are reopened by `app_id`; inline renders are ephemeral.
- If an OAuth provider requires a callback URL, use a persisted hosted saved app
rather than an inline render.
- For secret-bearing requests and host approval policy, also read
[`secret-host-approval.md`](./secret-host-approval.md).

## Relevant Code

- `packages/worker/src/mcp/tools/open-generated-ui.ts`
- `packages/worker/client/mcp-apps/generated-ui-shell.ts`
- `packages/worker/client/routes/saved-ui.tsx`
282 changes: 0 additions & 282 deletions docs/agents/mcp-apps-starter-guide.md

This file was deleted.

Loading
Loading