fix(mcp): eager-auth flag on the Grok connector links so Grok starts OAuth (#2167)

* fix(mcp): eager-auth flag on the Grok connector links so Grok starts OAuth

Live test after #2158: pasting the Grok URL into grok.com's custom
connector dialog listed all 150+ tools and never opened the sign-in. Grok
probes the URL without credentials, like claude.ai, and reads the lazy
200 on initialize as an authless server; only the 401 challenge starts
OAuth (#2159 fixed the same thing for the claude.ai link).

- lib/onboarding/checklist.ts: mcpServerUrl() builds the server URL with
  an optional eagerAuth flag; sideDoorServerUrl() gives the Grok side door
  auth=required and keeps ChatGPT lazy; claudeConnectorLink() reuses it.
  SIDE_DOORS / SideDoor move here from the component. Tests for all three.
- NewUserChecklist copies the door-specific URL (now with a client marker).
- ApiKeysPanel's Grok row copies the flagged URL, mirroring the Claude one.
- auth-mode.ts comment records the second consumer; registry entry's Grok
  step carries the flag; DECISIONS.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LhTJcwgzmN3TsLR8tVHwdi
Signed-off-by: Emil <emilmattsson14@gmail.com>

* docs(mcp): registry Claude.ai step carries auth=required too

Review pass on #2167: the registry entry flagged the Grok install URL
but left the Claude.ai step on the bare URL, which pre-fills "None" in
claude.ai's dialog (#2159). Same file, same flag, now consistent.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LhTJcwgzmN3TsLR8tVHwdi
Signed-off-by: Emil <emilmattsson14@gmail.com>

---------

Signed-off-by: Emil <emilmattsson14@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-09-02 16:55:23 +02:00
committed by GitHub
co-authored by Claude Fable 5.1
parent f1230282a9
commit a80ce54b78
7 changed files with 96 additions and 23 deletions
@@ -2,6 +2,9 @@ import { describe, expect, it } from 'vitest'
import {
checklistNumbers,
claudeConnectorLink,
mcpServerUrl,
sideDoorServerUrl,
SIDE_DOORS,
claudeStepDone,
completionPatchBody,
vatDeadlineLine,
@@ -105,6 +108,39 @@ describe('claudeStepDone', () => {
})
})
describe('mcpServerUrl', () => {
it('builds the namespaced URL with the client marker and no auth flag by default', () => {
expect(mcpServerUrl({ origin: 'https://app.testbrand.example', client: 'cursor' })).toBe(
'https://app.testbrand.example/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted&client=cursor',
)
})
it('appends auth=required when eagerAuth is set', () => {
const url = new URL(mcpServerUrl({ origin: 'http://localhost:3000', client: 'grok', eagerAuth: true }))
expect(url.searchParams.get('tool_namespace')).toBe('accounted')
expect(url.searchParams.get('client')).toBe('grok')
expect(url.searchParams.get('auth')).toBe('required')
})
})
describe('sideDoorServerUrl', () => {
it('lists chatgpt then grok', () => {
expect(SIDE_DOORS).toEqual(['chatgpt', 'grok'])
})
it('gives Grok the eager-auth flag: its dialog reads a 200 probe as "no auth" and never starts OAuth', () => {
const url = new URL(sideDoorServerUrl({ origin: 'https://app.testbrand.example', door: 'grok' }))
expect(url.searchParams.get('client')).toBe('grok')
expect(url.searchParams.get('auth')).toBe('required')
})
it('keeps ChatGPT on the lazy URL', () => {
const url = new URL(sideDoorServerUrl({ origin: 'https://app.testbrand.example', door: 'chatgpt' }))
expect(url.searchParams.get('client')).toBe('chatgpt')
expect(url.searchParams.get('auth')).toBeNull()
})
})
describe('claudeConnectorLink', () => {
it('builds the claude.ai deep link with namespace, client marker and eager-auth flag, from the page origin', () => {
const link = claudeConnectorLink({ origin: 'https://app.testbrand.example', appName: 'Testbrand' })
+41 -8
View File
@@ -76,18 +76,51 @@ export function claudeStepDone(input: { oauthKeyCount: number | null | undefined
return (input.oauthKeyCount ?? 0) > 0
}
/**
* The MCP server URL we hand to a client. `tool_namespace` is load-bearing
* (without it the server hands out legacy `gnubok_` tool names), `client`
* is a telemetry-only distribution marker, and the origin comes from the
* page so self-hosted and white-label domains link to themselves.
*
* `eagerAuth` appends `auth=required` (extensions/general/mcp-server/
* auth-mode.ts). Needed for clients whose Add-connector dialog probes the
* URL without credentials and reads the lazy 200 as "no authentication":
* claude.ai pre-fills "None" and Grok lists every tool without ever opening
* the sign-in. The 401 challenge is the only answer those dialogs read as
* OAuth. ChatGPT developer mode, Claude Code, Cursor and the stdio bridge
* keep the lazy URL.
*/
export function mcpServerUrl(input: { origin: string; client: string; eagerAuth?: boolean }): string {
const eager = input.eagerAuth ? '&auth=required' : ''
return `${input.origin}/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted&client=${input.client}${eager}`
}
/**
* Clients that get a collapsed "Using X?" side door under the checklist's
* Claude step. Each value keys the i18n strings step_claude_<door>_link /
* _steps and the telemetry step name. Order is display order.
*/
export const SIDE_DOORS = ['chatgpt', 'grok'] as const
export type SideDoor = (typeof SIDE_DOORS)[number]
/**
* The URL a side door copies. Grok's connector dialog behaves like
* claude.ai's (a 200 probe means "no auth", so the OAuth flow never starts)
* and needs the eager flag; ChatGPT's developer mode honours the lazy 401
* on the first protected call and keeps the plain URL.
*/
export function sideDoorServerUrl(input: { origin: string; door: SideDoor }): string {
return mcpServerUrl({ origin: input.origin, client: input.door, eagerAuth: input.door === 'grok' })
}
/**
* The claude.ai Add-custom-connector deep link the checklist's Claude step
* opens. Same shape as the Settings → API & MCP button: `tool_namespace` is
* load-bearing (without it the server hands out legacy `gnubok_` tool
* names), `client` is a telemetry-only distribution marker, `auth=required`
* makes claude.ai's dialog detect OAuth instead of "None" (see
* extensions/general/mcp-server/auth-mode.ts), and the origin comes from the
* page so self-hosted and white-label domains link to themselves. The link
* only prefills the dialog; the user reviews there.
* opens. Same shape as the Settings → API & MCP button (see mcpServerUrl for
* the query parameters). The link only prefills the dialog; the user reviews
* there.
*/
export function claudeConnectorLink(input: { origin: string; appName: string }): string {
const serverUrl = `${input.origin}/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted&client=claude-connector&auth=required`
const serverUrl = mcpServerUrl({ origin: input.origin, client: 'claude-connector', eagerAuth: true })
return (
'https://claude.ai/customize/connectors?modal=add-custom-connector' +
`&connectorName=${encodeURIComponent(input.appName)}` +