Files
upstash__context7/server.json
T

68 lines
1.8 KiB
JSON
Raw Normal View History

{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.upstash/context7",
"title": "Context7",
"description": "Up-to-date code docs for any prompt",
"repository": {
"url": "https://github.com/upstash/context7",
"source": "github"
},
"websiteUrl": "https://context7.com",
"icons": [
{
"src": "https://raw.githubusercontent.com/upstash/context7/master/public/icon.png",
"mimeType": "image/png"
}
],
"version": "2.0.0",
"packages": [
{
"registryType": "npm",
"identifier": "@upstash/context7-mcp",
"version": "2.0.2",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"name": "CONTEXT7_API_KEY",
"description": "API key for authentication",
"isRequired": false,
"isSecret": true
}
]
},
{
"registryType": "mcpb",
"identifier": "https://github.com/upstash/context7/releases/download/@upstash/context7-mcp@2.0.2/context7.mcpb",
"version": "2.0.2",
"fileSha256": "aea76f179ceb92d22c289147c9d8343fb558d6dec93b144c9794e99239bb8194",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"name": "CONTEXT7_API_KEY",
"description": "API key for authentication",
"isRequired": false,
"isSecret": true
}
]
}
],
"remotes": [
{
"type": "streamable-http",
"url": "https://mcp.context7.com/mcp",
"headers": [
{
fix(cli): write the API key as an Authorization header (#2957) * fix(cli): write the API key as an Authorization header Codex resolves a server's auth mode by checking only for `bearer_token_env_var` or a header literally named `Authorization` (`auth_status_before_discovery` in codex-rs/rmcp-client/src/auth_status.rs, mirrored in `create_transport` in rmcp_client.rs). The custom `CONTEXT7_API_KEY` header matched neither, so Codex fell through to any OAuth credential stored for the same server name and URL and refreshed it during startup. A dead refresh token then failed the server with `invalid_grant` before the API key was ever sent, and re-running setup could not recover it because setup writes config.toml and never touches the credential store. The hosted endpoint accepts both header forms, so existing configs keep working. Two places keep the legacy header deliberately: the plugin .mcp.json files default to `${CONTEXT7_API_KEY:-}`, and the server rejects `Bearer` with an empty token while treating a missing header as anonymous; and `env` blocks in stdio configs, where the name is an environment variable rather than a header. * fix(plugins): send the API key via the Authorization header The Claude and Copilot plugin configs default to `${CONTEXT7_API_KEY:-}`, and both plugins document that an unset key still works over the anonymous tier. The Bearer form cannot express that: the server rejects `Bearer` with an empty token while treating an empty or missing Authorization header as anonymous. The raw-key form satisfies both states. It is genuinely parsed rather than ignored, verified by an invalid raw key being rejected, so a set key still authenticates while an unset one falls back to anonymous as documented. Once the server treats an empty-token Bearer as no header, these can move to the `Bearer <key>` form used everywhere else. * refactor(cli): narrow the Codex OAuth probe and trim its surface Only `oauth` proves a stored credential exists. `not_logged_in` also covers "no credential, server merely advertises OAuth", which is the normal state for anyone who never logged in, so treating it as stale told most users their config held a credential it did not. Collapse the module to the two functions the call site needs, derive nothing from a hand-maintained status list, and skip the subprocess entirely when the server is not already in Codex's config. Drop the probe timeout to 1.5s and kill with SIGKILL so it is a real ceiling rather than an intent, since the result is only an advisory hint. Lock the plugin manifests' raw-key form behind a test, so normalizing them to `Bearer` for consistency with the CLI fails loudly instead of silently breaking anonymous access. * refactor(cli): drop the Codex OAuth cleanup note The note existed because re-running setup could not rescue a stuck user. The Authorization header change in this same branch makes it rescue them: Codex never reads the stored credential once that header is present, so the credential is inert and the hint only offered cosmetic cleanup. Removing it drops a subprocess spawn from a user-facing path and a dependency on the shape of `codex mcp get --json`, an external contract this repo does not pin. The reason the header name matters moves to `withHeaders`, where the decision is encoded.
2026-07-29 18:38:10 +03:00
"name": "Authorization",
"description": "API key for authentication. Accepts \"Bearer <key>\" or the raw key.",
"isRequired": false,
"isSecret": true
}
]
}
]
2025-10-22 23:58:09 +03:00
}