mcp: real MCP server at /api/mcp exposing Promote (write + post to socials) - #108
Merged
Merged
Conversation
A Model Context Protocol server built on the official @modelcontextprotocol/sdk (via the mcp-handler Next adapter), mounted on the existing app — no new Railway service. Agents connect at https://crawlproof.com/api/mcp with a crp_ API token (the existing sp_api_token bearer auth) and get the Promote toolset, scoped to that user's own connected socials. Tools (module: promote): list_accounts, generate_promo_post, post_to_socials, promote_url — reusing the same generatePitch + postViaAccount pipeline as the in-app Promote feature. So an agent can "write a promo post for xxx.com and post it on my socials" in one call. Cookie-auth platforms surface as 'queued'. - app/api/mcp/route.ts: createMcpHandler + withMcpAuth(crp_ token verifier) - lib/mcp/promote.ts: registerPromoteTools(server) — the promote module - lib/sp/apiAuth.ts: extract authenticateToken(token) for the MCP verifier - deps: mcp-handler, @modelcontextprotocol/sdk - docs/mcp.md: connect-your-agent guide - test: promote tools register + are discoverable over the MCP protocol (SDK in-memory transport) Structured so more capabilities (audits, stats, …) drop in as additional registerXxxTools modules. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A real Model Context Protocol server — built on the official
@modelcontextprotocol/sdkvia themcp-handlerNext adapter — mounted on the existing app athttps://crawlproof.com/api/mcp. No new Railway service; same instance. Agents connect with your existingcrp_API token and get the Promote toolset, scoped to that user's own connected socials.The user story works end to end:
Tools (module:
promote)list_accounts— the caller's connected accounts (platform/handle/id)generate_promo_post— write an on-brand post for a URL (no publish)post_to_socials— publish given text to all/account_idspromote_url— one shot: write a per-platform variant per account and publishAll reuse the same
generatePitch+postViaAccountpipeline as in-app Promote (cookie-auth platforms surface asqueued).How it's wired
app/api/mcp/route.ts—createMcpHandler(registerPromoteTools)wrapped inwithMcpAuth(verifyToken, { required: true }); the verifier resolves thecrp_bearer via the existingsp_api_tokenauth and stashesuserIdonauthInfo.lib/mcp/promote.ts—registerPromoteTools(server); more capabilities drop in as additionalregisterXxxToolsmodules.lib/sp/apiAuth.ts— extractedauthenticateToken(token)(shared by the v1 API and the MCP verifier).docs/mcp.md— connect-your-agent guide (URL + Bearer header, ormcp-remotebridge).Deploy impact
Zero infra change — one new Next route on the existing web+worker service. Auth reuses the existing token scheme; no migration. Needs
ANTHROPIC_API_KEY/OPENAI_API_KEYin the web env for generation (the worker already has them).Verified
tscclean ·next buildcompiles/api/mcp· contract test registers the tools against the real SDK and discovers them over an in-memory MCP transport (4/4 tools + schemas).🤖 Generated with Claude Code