You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Publish docs.plus to the official MCP Registry #459
The official MCP Registry is where MCP aggregators, and GitHub's curated list, find servers. GitHub's list feeds the VS Code MCP gallery. docs.plus is not in the registry today: a registry search for docsplus returned 0 results on 2026-10-07. This issue publishes one entry, then asks GitHub to onboard it.
Parent: #230. Land after #458: this entry links to that page, and a published version cannot change.
Background (checked 2026-10-07)
Registry status. Preview: "Breaking changes or data resets may occur" (registry docs).
VS Code. Its MCP gallery reads GitHub's curated list (https://api.mcp.github.com/v0.1/servers), not the registry directly. GitHub onboards a new server by hand. After that, new registry versions sync on their own (GitHub staff, github/github-mcp-server discussion #1257, 2026-05-19).
Where
apps/webapp/public/.well-known/: new file mcp-registry-auth, beside security.txt. apps/webapp/src/proxy.ts:64-68 already keeps .well-known out of the proxy. apps/webapp/.dockerignore:91 keeps public in the image. So no proxy or Docker change is needed.
apps/hocuspocus.server/server.json: new file. The remote URL is the production REST origin plus MCP_MOUNT_PATH (/api/mcp, apps/hocuspocus.server/src/modules/mcp/http/controller.ts:8). It is the same URL as in docs/mcp/README.md.
What to build
Namespace proof by HTTP. The maintainer makes an Ed25519 key pair outside the repo, with the openssl steps in the registry's mcp-publisher CLI reference (HTTP Verification). The maintainer gives the builder only the base64 public key.
The builder adds apps/webapp/public/.well-known/mcp-registry-auth, one line: v=MCPv1; k=ed25519; p=<public key>. security.txt in the same folder is the precedent (commit 3f3e11ea9). This grants the namespace plus.docs/*.
apps/hocuspocus.server/server.json:
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "plus.docs/mcp",
"title": "docs.plus",
"description": "Find, read and edit your docs.plus documents and their heading chats.",
"version": "1.0.0",
"websiteUrl": "https://docs.plus/mcp",
"repository": { "url": "https://github.com/docs-plus/docs.plus", "source": "github", "subfolder": "apps/hocuspocus.server" },
"remotes": [{ "type": "streamable-http", "url": "https://prodback.docs.plus/api/mcp" }]
}
remotes[0].url equals the resource field that https://prodback.docs.plus/api/mcp/.well-known/oauth-protected-resource returns. Compare character for character, with no / at the end.
Review server.json once more, and run mcp-publisher validate from apps/hocuspocus.server. A published version cannot change and cannot be removed. A mistake is fixed only by publishing a higher version.
Run mcp-publisher login http --domain=docs.plus --private-key=<64-character hex private key>.
From apps/hocuspocus.server, run mcp-publisher publish. It reads ./server.json by default.
Post an onboarding request in github/github-mcp-server discussion #1257.
Steps 2 to 4 follow the registry's mcp-publisher CLI reference. They were not run for this issue.
Later, raise version only when the URL, title or description changes, or to correct a mistake.
The onboarding request is posted, with its link in a comment here.
Verify
Before publish: run Publish step 1.
After publish: run the registry curl in Acceptance criteria.
After it ships (does not block close)
After GitHub onboards it: curl -s "https://api.mcp.github.com/v0.1/servers?search=docs.plus" returns the entry, and VS Code's @mcp docs.plus search shows it.
Namespace proof (ruled 2026-10-07)
Use the HTTP web file, as the maintainer ruled.
Known trade-off: every self-hosted build also serves the auth file, so the docs.plus key holder could claim that host's namespace. The risk is small, and security.txt already ships docs.plus-specific content. If this ever matters, switch to mcp-publisher login dns and drop the file.
Summary
The official MCP Registry is where MCP aggregators, and GitHub's curated list, find servers. GitHub's list feeds the VS Code MCP gallery. docs.plus is not in the registry today: a registry search for
docsplusreturned 0 results on 2026-10-07. This issue publishes one entry, then asks GitHub to onboard it.Parent: #230. Land after #458: this entry links to that page, and a published version cannot change.
Background (checked 2026-10-07)
https://api.mcp.github.com/v0.1/servers), not the registry directly. GitHub onboards a new server by hand. After that, new registry versions sync on their own (GitHub staff, github/github-mcp-server discussion #1257, 2026-05-19).Where
apps/webapp/public/.well-known/: new filemcp-registry-auth, besidesecurity.txt.apps/webapp/src/proxy.ts:64-68already keeps.well-knownout of the proxy.apps/webapp/.dockerignore:91keepspublicin the image. So no proxy or Docker change is needed.apps/hocuspocus.server/server.json: new file. The remote URL is the production REST origin plusMCP_MOUNT_PATH(/api/mcp,apps/hocuspocus.server/src/modules/mcp/http/controller.ts:8). It is the same URL as indocs/mcp/README.md.What to build
Namespace proof by HTTP. The maintainer makes an Ed25519 key pair outside the repo, with the
opensslsteps in the registry'smcp-publisherCLI reference (HTTP Verification). The maintainer gives the builder only the base64 public key.The builder adds
apps/webapp/public/.well-known/mcp-registry-auth, one line:v=MCPv1; k=ed25519; p=<public key>.security.txtin the same folder is the precedent (commit3f3e11ea9). This grants the namespaceplus.docs/*.apps/hocuspocus.server/server.json:{ "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json", "name": "plus.docs/mcp", "title": "docs.plus", "description": "Find, read and edit your docs.plus documents and their heading chats.", "version": "1.0.0", "websiteUrl": "https://docs.plus/mcp", "repository": { "url": "https://github.com/docs-plus/docs.plus", "source": "github", "subfolder": "apps/hocuspocus.server" }, "remotes": [{ "type": "streamable-http", "url": "https://prodback.docs.plus/api/mcp" }] }websiteUrlis the route that Add a public docs.plus/mcp page so web search finds the MCP connector #458 ships. If Add a public docs.plus/mcp page so web search finds the MCP connector #458 Open decision 1 moves the page to/connect, usehttps://docs.plus/connect.Publish steps (maintainer only)
The private key never enters the repo, an issue or a commit.
curlin Acceptance criteria prints the onev=MCPv1line.websiteUrlopens the Add a public docs.plus/mcp page so web search finds the MCP connector #458 page, not a document.remotes[0].urlequals theresourcefield thathttps://prodback.docs.plus/api/mcp/.well-known/oauth-protected-resourcereturns. Compare character for character, with no/at the end.server.jsononce more, and runmcp-publisher validatefromapps/hocuspocus.server. A published version cannot change and cannot be removed. A mistake is fixed only by publishing a higherversion.mcp-publisher login http --domain=docs.plus --private-key=<64-character hex private key>.apps/hocuspocus.server, runmcp-publisher publish. It reads./server.jsonby default.Steps 2 to 4 follow the registry's
mcp-publisherCLI reference. They were not run for this issue.Later, raise
versiononly when the URL, title or description changes, or to correct a mistake.Out of scope
/mcppage: Add a public docs.plus/mcp page so web search finds the MCP connector #458.server.json. docs.plus ships a remote server only.Acceptance criteria
apps/webapp/public/.well-known/mcp-registry-authandapps/hocuspocus.server/server.jsonare onmain.curl -s https://docs.plus/.well-known/mcp-registry-authprints exactly the onev=MCPv1; k=ed25519; p=…line.curl -s "https://registry.modelcontextprotocol.io/v0.1/servers/plus.docs%2Fmcp/versions/latest"returns"status":"active".Verify
curlin Acceptance criteria.After it ships (does not block close)
curl -s "https://api.mcp.github.com/v0.1/servers?search=docs.plus"returns the entry, and VS Code's@mcp docs.plussearch shows it.Namespace proof (ruled 2026-10-07)
security.txtalready ships docs.plus-specific content. If this ever matters, switch tomcp-publisher login dnsand drop the file.