Skip to content

mcp: fix /api/mcp routing (404 on real calls) + surface it in the UI with curls - #109

Merged
ralyodio merged 1 commit into
masterfrom
mcp/fix-basepath
Jul 17, 2026
Merged

ralyodio merged 1 commit into
masterfrom
mcp/fix-basepath

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Critical fix

The MCP endpoint (#108) 404'd on every real MCP call. mcp-handler routes by URL pathname and defaults its endpoint to /mcp, but the route is mounted at /api/mcp — so withMcpAuth passed (auth worked) and then the handler returned 404 Not found. The in-memory contract test didn't catch it because it drives the SDK server directly, bypassing HTTP routing.

Fix: pass { basePath: "/api" } to createMcpHandler so it derives /api/mcp (+ maxDuration: 120 for a multi-account promote_url).

Verified end-to-end

Ran the built server locally with the real prod env and hit it with a throwaway token (read-only tools only, deleted after):

  • initialize → 200
  • tools/list → 200, all 4 tools
  • tools/call list_accounts → 200, returned the 6 connected accounts
  • tools/call generate_promo_post → 200, generated a real bluesky pitch

Now surfaced in the UI

The Social → API tokens page gains an "MCP server" section:

  • endpoint (/api/mcp)
  • agent config JSON (Claude Desktop / Cursor)
  • copy-paste curls for tools/list and promote_url, including the required Accept: application/json, text/event-stream header

docs/mcp.md gets the same curls.

Deploy

Same instance, no migration. tsc clean, next build compiles both routes.

🤖 Generated with Claude Code

@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

The MCP endpoint 404'd on every real call: mcp-handler routes by pathname and
defaults its endpoint to "/mcp", but the route is mounted at /api/mcp — so auth
passed (withMcpAuth) then the handler 404'd. (The in-memory contract test didn't
catch it because it bypasses HTTP routing.) Fixed by passing config
{ basePath: "/api" } so mcp-handler derives /api/mcp; maxDuration 120 for a
multi-account promote_url.

Verified end-to-end against a real running server + prod Supabase/AI (throwaway
token, read-only tools): initialize, tools/list, list_accounts (6 accounts),
generate_promo_post (real pitch) all 200.

Also surfaced the server in the UI: the Social → API tokens page now has an "MCP
server" section — endpoint, agent config JSON, and copy-paste curls (with the
required Accept: application/json, text/event-stream header). docs/mcp.md gains
the same curls.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@ralyodio
ralyodio merged commit 1f15f36 into master Jul 17, 2026
8 checks passed
@ralyodio
ralyodio deleted the mcp/fix-basepath branch July 17, 2026 12:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant