Skip to content

feat(mcp)!: remove project-scoped MCP API keys - #1542

Merged
bobbyquantum merged 3 commits into
mainfrom
bobbyquantum/remove-legacy-mcp-keys
Sep 29, 2026
Merged

bobbyquantum merged 3 commits into
mainfrom
bobbyquantum/remove-legacy-mcp-keys

Conversation

@bobbyquantum

Copy link
Copy Markdown
Owner

MCP clients now authenticate with OAuth access tokens only. The project-scoped iw_proj_... API keys and everything around them are removed.

Backend

  • mcpAuth accepts only Authorization: Bearer <OAuth access token>. The X-API-Key header and the iw_proj_ branch are gone.
  • The McpLegacyContext / LegacyMcpContext types and every type === 'legacy' branch in mcp.auth.ts and mcp.types.ts are gone. McpContext is now the OAuth context.
  • Removed the /api/v1/mcp-keys routes, mcpKeyService, the mcp_access_keys schema, the LEGACY_MCP_ENABLED setting and the legacyMcpEnabled feature flag.
  • MCP_PERMISSIONS / McpPermission moved to mcp/mcp-permissions.ts.
  • Migration 0039_drop-mcp-access-keys.sql drops the table. Preview's table is dropped on the next migration apply.
  • update_document_content / get_document_content no longer accept format: "xml" as an alias for prosemirror_xml.
  • MCP activity events are always attributed to the OAuth user. The generic actorLabel column stays because existing preview rows use it.

Frontend

  • Removed the "Legacy API Keys" section in project settings, CreateMcpKeyDialogComponent, the admin "Legacy MCP API Keys" toggle and their translations. The API client is regenerated.

E2E

  • The MCP suite's mcpContext now authorizes through the OAuth PKCE flow (mcpToken). The read-only test uses a viewer grant. The X-API-Key and revoked-key tests and online/mcp-legacy-key.spec.ts are removed.

Kept on purpose

  • The pre-2026-07-28 MCP handshake (initialize, Mcp-Session-Id) is still served. It is how clients on the previous protocol revision connect, including the MCP Inspector used by the e2e suite, so removing it would break current tools rather than old data.

Testing

  • Backend bun test: 1,750 pass.
  • Frontend npm test: 9,370 pass.
  • playwright.mcp.config.ts: 77 pass locally.

MCP clients now authenticate with OAuth access tokens only.

- Backend: drop the iw_proj_ key auth path, the X-API-Key header, the
  legacy MCP context type, the /api/v1/mcp-keys routes and service, the
  LEGACY_MCP_ENABLED setting and the legacyMcpEnabled feature flag. The
  permission constants move to mcp/mcp-permissions.ts. Migration 0039
  drops the mcp_access_keys table.
- MCP tools no longer accept 'xml' as an alias for 'prosemirror_xml'.
- Frontend: remove the legacy key section in project settings, the create
  key dialog, the admin toggle and their translations; regenerate the API
  client.
- E2E: the MCP suite authorizes through the OAuth flow (viewer grant for
  the read-only test); the legacy key spec is gone.
- Docs: drop the legacy API key instructions.
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: bobbyquantum/inkweld/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: a68d77ea-ca05-49b4-b149-2340968ba82f


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…egacy-mcp-keys

# Conflicts:
#	backend/src/routes/mcp-keys.routes.ts
@bobbyquantum
bobbyquantum deployed to sonarcloud-analysis September 29, 2026 23:25 — with GitHub Actions Active
@sonarqubecloud

Copy link
Copy Markdown

@bobbyquantum
bobbyquantum merged commit 157f9cd into main Sep 29, 2026
33 checks passed
@bobbyquantum
bobbyquantum deleted the bobbyquantum/remove-legacy-mcp-keys branch September 29, 2026 23:50

This branch was successfully deployed

1 active deployment
sonarcloud-analysis — 0b9d58f9 Deployed Sep 29, 2026 by bobbyquantum via SonarCloud Code Analysis #5282
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant