Skip to content

Add optional app-key MCP endpoint for Vercel Connect - #214

Merged
silverstein merged 2 commits into
masterfrom
feat/connect-api-key-20261001
Oct 1, 2026
Merged

silverstein merged 2 commits into
masterfrom
feat/connect-api-key-20261001

Conversation

@silverstein

@silverstein silverstein commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Vercel Connect requires an authentication method, which prevented listing the existing anonymous PDF Tools MCP service. This adds an optional /mcp/connect endpoint with Bearer app-key validation and a /connect key-creation page. The public /mcp remains available without a key.

App keys are HMAC-signed and expire after 90 days. They grant stateless PDF processing, with no user identity or access to stored documents. The service stores no individual key records; signing-secret rotation invalidates all Connect keys. Missing configuration fails closed with 503, and authentication happens before importing the PDF handler or reading document bytes. Public issuance adds no billing, quota, or abuse-prevention claim.

The reviewed source 31363785 is deployed and verified at https://mcp.opendocuments.ai/connect and https://mcp.opendocuments.ai/mcp/connect. Live checks passed browser issuance, missing/forged/expired-key refusal, method/origin/size refusal, public discovery, and synthetic read/fill/zone/flatten. Vercel accepted the submission with HTTP 201 and Configuration Valid; catalog publication remains pending review. Activation and rollback instructions are in docs/REMOTE_CONNECT_API_KEYS.md.

A copyable starter uses @vercel/connect 2.3.5. Its exact setup and demo scripts passed: create an expiring app key, store it in Connect, attach development only, retrieve the app credential using project OIDC, and discover/read/fill/flatten a generated one-page PDF. Returned field contents and zero interactive fields after flattening were verified.

Validation:

  • The full Linux gate passed on Node 20.19 and 22.12: each ran 190 passing test files and 3,664 passing tests, with 8 files and 168 tests skipped as reported. Share contract, MCPB build, and packed MCPB smoke passed on both runtimes.
  • All 10 native authentication tests passed on Node 20.19.0 and Node 22; independent adversarial source review passed.
  • API entry points, framework-context refusal, desktop/mobile key UI, and live protected/public workflows passed. Syntax, native-suite registration, and whitespace checks passed.

These checks used synthetic PDFs and executed no real signatures. The Linux CI gate is separate from macOS/Windows host qualification and from public desktop release. The aggregate native suite was not claimed as fully run.

@silverstein
silverstein marked this pull request as ready for review October 1, 2026 01:06
@silverstein
silverstein merged commit 5ae56e5 into master Oct 1, 2026
4 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant