Skip to content

fix(mcp): stop writing literal env placeholders into client configs - #131

Merged
yunze7373 merged 1 commit into
mainfrom
fix/mcp-literal-env-placeholders
Oct 1, 2026
Merged

yunze7373 merged 1 commit into
mainfrom
fix/mcp-literal-env-placeholders

Conversation

@yunze7373

Copy link
Copy Markdown
Member

Summary

An audit against the xmemo.dev homepage connect configs turned up two places where generated MCP configs carry placeholders the client never resolves.

  • mcp-remote clients (Claude Desktop, Claude Code, Trae, Trae Solo): env contained "XMEMO_KEY": "${env:XMEMO_KEY}". None of these clients expand ${env:...} in env values, so mcp-remote received the literal string as the key. The Kiro doctor already flags this pattern as unsupported_key_interpolation. The entry is removed. mcp-remote still resolves ${XMEMO_KEY} in args from the environment it inherits.
  • Codex (print path, no generated ID): X-Memory-OS-Agent-Instance-ID = "${XMEMO_AGENT_INSTANCE_ID}" sat in http_headers, which Codex sends verbatim. It now goes in [mcp_servers.XMemo.env_http_headers], which is also what the server's /api/v1/mcp/config/codex returns. --write with a real generated ID is unchanged.
  • Claude Desktop hint: mcp add claude-desktop now prints a pointer to Claude > Customize > Connectors > Add custom connector (OAuth, no key). It is declared as mcp.credentialHint on the registry entry, so src/commands stays free of client-ID literals (Principle 4).
  • MCP-SETUP-GUIDE: the Claude Desktop section drops the self-reference and recommends the custom connector.

Out of scope

  • Hermes yaml.js also writes ${env:XMEMO_KEY}. Whether Hermes expands it needs checking separately.
  • Grok TOML still puts ${XMEMO_AGENT_INSTANCE_ID} in http_headers. Grok's expansion semantics are unverified.

Test plan

  • node --test test/cli.test.js test/command-model.test.js: 120/120 pass, including new tests for Codex env_http_headers, the Claude Desktop hint, and the absence of the hint on Cursor.
  • Full npm test, diffed against main: no new failures. Five tests fail identically on clean main: CLI-03, R1 getStoredCredential, the two skill-script doctor tests, and doctor discovery errorDetail. test/xmemo-standalone-skill.test.js hangs for more than 10 minutes on both.

🤖 Generated with Claude Code

- mcp-remote clients (Claude Desktop, Claude Code, Trae, Trae Solo): drop
  "XMEMO_KEY": "${env:XMEMO_KEY}" from the env block. None of these clients
  expand ${env:...} in env values, so mcp-remote received the literal text
  (the same unsupported_key_interpolation the Kiro doctor reports).
  mcp-remote already resolves ${XMEMO_KEY} in args from its inherited env.
- Codex: when there is no generated instance ID, send it through
  [mcp_servers.XMemo.env_http_headers] instead of a "${...}" string in
  http_headers, which Codex sends verbatim.
- Claude Desktop: print a credential hint pointing at the OAuth custom
  connector (declared on the registry entry, not hardcoded in commands).
- MCP-SETUP-GUIDE: Claude Desktop section recommends the custom connector.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@yunze7373
yunze7373 merged commit 80f94f6 into main Oct 1, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant