feat(mcp)!: remove project-scoped MCP API keys - #1542
Merged
Merged
Conversation
MCP clients now authenticate with OAuth access tokens only. - Backend: drop the iw_proj_ key auth path, the X-API-Key header, the legacy MCP context type, the /api/v1/mcp-keys routes and service, the LEGACY_MCP_ENABLED setting and the legacyMcpEnabled feature flag. The permission constants move to mcp/mcp-permissions.ts. Migration 0039 drops the mcp_access_keys table. - MCP tools no longer accept 'xml' as an alias for 'prosemirror_xml'. - Frontend: remove the legacy key section in project settings, the create key dialog, the admin toggle and their translations; regenerate the API client. - E2E: the MCP suite authorizes through the OAuth flow (viewer grant for the read-only test); the legacy key spec is gone. - Docs: drop the legacy API key instructions.
Contributor
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: bobbyquantum/inkweld/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…egacy-mcp-keys # Conflicts: # backend/src/routes/mcp-keys.routes.ts
bobbyquantum
had a problem deploying
to
sonarcloud-analysis
September 29, 2026 23:06 — with
GitHub Actions
Error
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



MCP clients now authenticate with OAuth access tokens only. The project-scoped
iw_proj_...API keys and everything around them are removed.Backend
mcpAuthaccepts onlyAuthorization: Bearer <OAuth access token>. TheX-API-Keyheader and theiw_proj_branch are gone.McpLegacyContext/LegacyMcpContexttypes and everytype === 'legacy'branch inmcp.auth.tsandmcp.types.tsare gone.McpContextis now the OAuth context./api/v1/mcp-keysroutes,mcpKeyService, themcp_access_keysschema, theLEGACY_MCP_ENABLEDsetting and thelegacyMcpEnabledfeature flag.MCP_PERMISSIONS/McpPermissionmoved tomcp/mcp-permissions.ts.0039_drop-mcp-access-keys.sqldrops the table. Preview's table is dropped on the next migration apply.update_document_content/get_document_contentno longer acceptformat: "xml"as an alias forprosemirror_xml.actorLabelcolumn stays because existing preview rows use it.Frontend
CreateMcpKeyDialogComponent, the admin "Legacy MCP API Keys" toggle and their translations. The API client is regenerated.E2E
mcpContextnow authorizes through the OAuth PKCE flow (mcpToken). The read-only test uses aviewergrant. The X-API-Key and revoked-key tests andonline/mcp-legacy-key.spec.tsare removed.Kept on purpose
2026-07-28MCP handshake (initialize,Mcp-Session-Id) is still served. It is how clients on the previous protocol revision connect, including the MCP Inspector used by the e2e suite, so removing it would break current tools rather than old data.Testing
bun test: 1,750 pass.npm test: 9,370 pass.playwright.mcp.config.ts: 77 pass locally.