Skip to content

Point plain /mcp challenges at a v1-owned metadata path - #2203

Closed
RhysSullivan wants to merge 1 commit into
mainfrom
mcp/v1-resource-metadata
Closed

RhysSullivan wants to merge 1 commit into
mainfrom
mcp/v1-resource-metadata

Conversation

@RhysSullivan

@RhysSullivan RhysSullivan commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

After the planned router cutover, Executor v2 serves executor.sh/mcp's root discovery documents, including /.well-known/oauth-protected-resource/mcp. v1's 401 on plain /mcp names that document, so a v1 client whose token expires would discover v2's authorization server and leave v1.

Plain /mcp challenges now name /.well-known/oauth-protected-resource/_v1/mcp. v1 serves the same document there (resource: https://executor.sh/mcp, authorization_servers: [https://signin.executor.sh]). The router keeps sending requests with an expired v1 token to v1, so a client that follows resource_metadata refreshes or signs in again on v1's AuthKit.

  • _v1 can never be an org slug (slugs have no _) and is not an org_ id, so it is classified as the bare document, not an org.
  • The old /.well-known/oauth-protected-resource/mcp is still served.
  • Org and toolkit URLs keep their own documents.

This is a no-op before the cutover: both paths return the same document on the current host.

Tests are in #2204.

@RhysSullivan
RhysSullivan added this pull request to stack #2205 October 8, 2026 03:37
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
executor-cloud c9a2516 Oct 08 2026, 03:41 AM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
executor-marketing c9a2516 Commit Preview URL

Branch Preview URL
Oct 08 2026, 03:39 AM

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Cloudflare preview

Torn down — the PR is closed.

@pkg-pr-new

pkg-pr-new Bot commented Oct 8, 2026

Copy link
Copy Markdown

Open in StackBlitz

@executor-js/cli

npm i https://pkg.pr.new/@executor-js/cli@2203

@executor-js/config

npm i https://pkg.pr.new/@executor-js/config@2203

@executor-js/execution

npm i https://pkg.pr.new/@executor-js/execution@2203

@executor-js/sdk

npm i https://pkg.pr.new/@executor-js/sdk@2203

@executor-js/codemode-core

npm i https://pkg.pr.new/@executor-js/codemode-core@2203

@executor-js/runtime-quickjs

npm i https://pkg.pr.new/@executor-js/runtime-quickjs@2203

@executor-js/plugin-file-secrets

npm i https://pkg.pr.new/@executor-js/plugin-file-secrets@2203

@executor-js/plugin-graphql

npm i https://pkg.pr.new/@executor-js/plugin-graphql@2203

@executor-js/plugin-keychain

npm i https://pkg.pr.new/@executor-js/plugin-keychain@2203

@executor-js/plugin-mcp

npm i https://pkg.pr.new/@executor-js/plugin-mcp@2203

@executor-js/plugin-onepassword

npm i https://pkg.pr.new/@executor-js/plugin-onepassword@2203

@executor-js/plugin-openapi

npm i https://pkg.pr.new/@executor-js/plugin-openapi@2203

executor

npm i https://pkg.pr.new/executor@2203

commit: c9a2516

@RhysSullivan

Copy link
Copy Markdown
Collaborator Author

Not needed: v2 now uses mcp.executor.sh, so v1 keeps executor.sh/mcp and its discovery unchanged.

Sent from my Claude

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant