Skip to content

Map: landing page for plausible-mcp #42

Description

@sergical

Destination

A decided spec for a public landing page at https://plausible-mcp.sentry.cool (not the apex of plausible-mcp.sentry.dev — see #43), whose live demo is the same MCP Apps artifact the server ships to real clients. Done when nothing is left to decide before someone builds and deploys it.

Notes

Domain: single-context — root CONTEXT.md plus docs/adr/, created lazily (docs/agents/domain.md).

Skills every session should consult: matt-grilling and matt-domain-modeling by default; matt-research for research tickets; matt-prototype for prototype tickets.

Standing preferences for this effort

  • This is a DX-team artifact. No Sentry brand or marketing sign-off. Visually coherent with Sentry, but explicit that it is not a supported Sentry product.
  • The page's primary job is an install funnel; the live demo is what makes it beat the README. Evaluation and trust content is a section, not the purpose.
  • Trust content stays minimal: confirm the security posture and link TELEMETRY.md. No narrative, no incident history.
  • Say MCP Apps, not MCP-UI. The community mcp-ui project was standardized as MCP Apps (SEP-1865, shipped 2026-01-26) — the first official MCP extension. Target @modelcontextprotocol/ext-apps, not @mcp-ui/*.
  • One artifact, not two: the MCP Apps ui:// resource for a lead tool is the landing page's demo. Visitors see what they would see in Claude.
  • The page does not live on plausible-mcp.sentry.dev. Reversed 2026-08-21 (Serve HTML at the Worker root without breaking /mcp or /internal #43): Access path matching is a segment-wise prefix, so the root path cannot be carved out of the bare-host OAuth application. Same origin was chosen while charting mainly to serve the WebMCP bridge, which was ruled out of scope the same session. The page gets its own hostname — plausible-mcp.sentry.cool, settled in Stand up the landing page hostname and add CORS on /mcp #44 — on the same Worker; the demo reaches /mcp cross-origin with one CORS header. Cloudflare Access is not modified and no connector URL changes.
  • The page is one self-contained HTML document. The apex shares a 60/min per-IP rate limiter with the MCP endpoints, so every extra subresource request is a request the demo no longer has (Serve HTML at the Worker root without breaking /mcp or /internal #43).

Decisions so far

  • Serve HTML at the Worker root without breaking /mcp or /internal — inline HTML string on a pathname === "/" branch in worker.ts, no assets binding and no wrangler/tsconfig change; classifyRoute untouched so the anonymous page records no telemetry. Corrected: there is no root carve-out — Access path matching is a segment-wise prefix (proven live: /mcp/foo is bypassed, /mcpfoo is not), and Managed OAuth issues opaque tokens the Worker can never validate, so the authorization server cannot be split off either. Do not touch Access; give the page its own hostname. Detail on branch research/worker-root-html, superseded in part by the correction comment.
  • Adopt MCP Apps, and pick the lead tool — adopt, with get_timeseries leading; its renderer generalizes to get_breakdown and get_conversions via the shared queryResultOutputSchema, but not to compare_periods. ext-apps/server cannot run on this Worker (peer-depends on SDK v1), so the ~15-line _meta.ui contract is hand-written and ext-apps stays a browser-only dependency of the iframe bundle. Claude Code not rendering costs nothing — /internal targets claude.ai and Cowork, and a _meta.ui tool still returns unchanged content. Detail on branch research/mcp-apps.

Not yet specified

  • How the page ships. Deploy path for the HTML — whether it rides the existing pnpm deploy Worker release or gets its own step, and whether page changes need the release pipeline at all. Waits on how HTML is served from the Worker.
  • Rate limiting and abuse bounds on the demo route. Shape depends entirely on which demo data mechanism is provisioned.
  • When ext-apps becomes usable server-side. Verified 2026-08-21: ext-apps#702 is open, with #719 and #720 competing open PRs (#710 closed as a duplicate). Adopt MCP Apps, and pick the lead tool #46 found @modelcontextprotocol/ext-apps/server peer-depends on the legacy SDK v1 and cannot run on this Worker, so the _meta.ui contract is hand-written. Upstream v2 migration is ext-apps#702; whether to adopt it once it lands is a later call.
  • Launch. Whether this gets announced anywhere, and where. Nothing to decide until the page exists.
  • Whether the lead tool's chart generalizes. Only visible once one chart has been built and reacted to.

Out of scope

  • WebMCP. Ruled out 2026-08-21 while charting. W3C Community Group incubation, origin trials live in Chrome 149→156 and Edge 150, but crawls in May and July 2026 found essentially zero adoption and no mainstream agent consumes WebMCP tools yet. Cloudflare's edge bridge would make it cheap, but the bridge uses the visitor's session against same-origin /mcp, which turns a marketing experiment into a security question. Revisit only when an agent ships support.
  • Changing the Cloudflare Access configuration. Ruled out 2026-08-21 by Serve HTML at the Worker root without breaking /mcp or /internal #43. Every variant fails: a root-scoped Bypass app swallows /internal (segment-wise prefix matching); a path-scoped Managed OAuth app breaks discovery, which Access serves at the app's own /.well-known/oauth-authorization-server; and splitting the authorization server onto a subdomain is impossible because Managed OAuth tokens are opaque, so the Worker cannot validate them. Moving /internal wholesale to a subdomain would work but forces every Sentry user to re-authorize — not worth it for a landing page.
  • Rolling MCP Apps across the remaining tools. Adopt MCP Apps, and pick the lead tool #46 found the get_timeseries renderer generalizes to get_breakdown and get_conversions for free via the shared queryResultOutputSchema, and not at all to compare_periods. This map decides adoption and specs one lead tool as the proof. The rollout is execution past the destination.
  • Auditing this Worker against the rest of the MCP 2026-07-28 core revision. Struck as a migration item on 2026-08-21: the Worker already runs that revision (@modelcontextprotocol/server 2.0.0, server/discover served at src/server.ts:72), so there is nothing to migrate. Any remaining conformance sweep — the Roots/Sampling/Logging deprecation clock, result obligations across all tools — is real work but unrelated to the landing page.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions