fix(mcp): stop writing literal env placeholders into client configs - #131
Merged
Merged
Conversation
- mcp-remote clients (Claude Desktop, Claude Code, Trae, Trae Solo): drop
"XMEMO_KEY": "${env:XMEMO_KEY}" from the env block. None of these clients
expand ${env:...} in env values, so mcp-remote received the literal text
(the same unsupported_key_interpolation the Kiro doctor reports).
mcp-remote already resolves ${XMEMO_KEY} in args from its inherited env.
- Codex: when there is no generated instance ID, send it through
[mcp_servers.XMemo.env_http_headers] instead of a "${...}" string in
http_headers, which Codex sends verbatim.
- Claude Desktop: print a credential hint pointing at the OAuth custom
connector (declared on the registry entry, not hardcoded in commands).
- MCP-SETUP-GUIDE: Claude Desktop section recommends the custom connector.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
An audit against the xmemo.dev homepage connect configs turned up two places where generated MCP configs carry placeholders the client never resolves.
envcontained"XMEMO_KEY": "${env:XMEMO_KEY}". None of these clients expand${env:...}in env values, so mcp-remote received the literal string as the key. The Kiro doctor already flags this pattern asunsupported_key_interpolation. The entry is removed. mcp-remote still resolves${XMEMO_KEY}inargsfrom the environment it inherits.X-Memory-OS-Agent-Instance-ID = "${XMEMO_AGENT_INSTANCE_ID}"sat inhttp_headers, which Codex sends verbatim. It now goes in[mcp_servers.XMemo.env_http_headers], which is also what the server's/api/v1/mcp/config/codexreturns.--writewith a real generated ID is unchanged.mcp add claude-desktopnow prints a pointer to Claude > Customize > Connectors > Add custom connector (OAuth, no key). It is declared asmcp.credentialHinton the registry entry, sosrc/commandsstays free of client-ID literals (Principle 4).Out of scope
yaml.jsalso writes${env:XMEMO_KEY}. Whether Hermes expands it needs checking separately.${XMEMO_AGENT_INSTANCE_ID}inhttp_headers. Grok's expansion semantics are unverified.Test plan
node --test test/cli.test.js test/command-model.test.js: 120/120 pass, including new tests for Codexenv_http_headers, the Claude Desktop hint, and the absence of the hint on Cursor.npm test, diffed againstmain: no new failures. Five tests fail identically on cleanmain: CLI-03, R1 getStoredCredential, the two skill-script doctor tests, and doctor discovery errorDetail.test/xmemo-standalone-skill.test.jshangs for more than 10 minutes on both.🤖 Generated with Claude Code