Repository navigation
Add optional app-key MCP endpoint for Vercel Connect - #214
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Vercel Connect requires an authentication method, which prevented listing the existing anonymous PDF Tools MCP service. This adds an optional
/mcp/connectendpoint with Bearer app-key validation and a/connectkey-creation page. The public/mcpremains available without a key.App keys are HMAC-signed and expire after 90 days. They grant stateless PDF processing, with no user identity or access to stored documents. The service stores no individual key records; signing-secret rotation invalidates all Connect keys. Missing configuration fails closed with 503, and authentication happens before importing the PDF handler or reading document bytes. Public issuance adds no billing, quota, or abuse-prevention claim.
The reviewed source
31363785is deployed and verified at https://mcp.opendocuments.ai/connect and https://mcp.opendocuments.ai/mcp/connect. Live checks passed browser issuance, missing/forged/expired-key refusal, method/origin/size refusal, public discovery, and synthetic read/fill/zone/flatten. Vercel accepted the submission with HTTP 201 and Configuration Valid; catalog publication remains pending review. Activation and rollback instructions are indocs/REMOTE_CONNECT_API_KEYS.md.A copyable starter uses
@vercel/connect2.3.5. Its exact setup and demo scripts passed: create an expiring app key, store it in Connect, attach development only, retrieve the app credential using project OIDC, and discover/read/fill/flatten a generated one-page PDF. Returned field contents and zero interactive fields after flattening were verified.Validation:
These checks used synthetic PDFs and executed no real signatures. The Linux CI gate is separate from macOS/Windows host qualification and from public desktop release. The aggregate native suite was not claimed as fully run.