Skip to content

Add T3 Code, with a self-hosted MCP endpoint template - #92

Open
leoisadev1 wants to merge 3 commits into
UsefulSoftwareCo:mainfrom
leoisadev1:add-t3-code
Open

leoisadev1 wants to merge 3 commits into
UsefulSoftwareCo:mainfrom
leoisadev1:add-t3-code

Conversation

@leoisadev1

@leoisadev1 leoisadev1 commented Oct 8, 2026 •

Copy link
Copy Markdown

Summary

T3 Code now ships an MCP server that outside agents can drive (announcement, docs). It is self-hosted: every T3 Code environment serves its own https://<environment-address>/mcp, so there is no one URL to list, and the registry drops any MCP URL with a {placeholder} in it.

This adds curated/t3code.json (the MCP server and the t3 CLI) and lets an MCP surface publish a templated URL when it declares the token in variables, a field the discovery schema already has:

 isUnusableEndpoint(url, variables = [])
-  if url contains "{" or "}" → unusable
+  fill each declared {name} in url
+  if the filled url still contains "{" or "}" → unusable
   loopback hosts → unusable (unchanged)

The variables travel from the curated record through normalize.ts, the baseline discovery document, the worker's baseline backfill, and every applyEndpointVerdicts caller. The surface page shows them as a Variable row. verify-mcp-endpoints.ts reuses isUnusableEndpoint to skip templated URLs, since there is no one host to probe.

The MCP page also has to say how to sign in. T3 Code's approval page asks for a one-time pairing code, which no client can discover on its own. A curated auth: "oauth" MCP interface with a setup guide now publishes an oauth2 credential bound through well-known metadata, so the page shows the sign-in and the pairing step instead of "Authentication not yet determined". Only T3 Code sets setup; every other /disc/*.json document is byte-identical to main.

A separate commit fixes a bug this exposed: curated CLIs published their record slug as the command (github-com-cli, vercel-com-cli, and here t3-codes-cli) instead of the command itself (gh, vercel, t3).

Evidence

Before After
t3.codes on integrations.sh today t3.codes domain page with this branch
T3 Code MCP surface page, desktop
T3 Code MCP surface page, mobile
T3 Code CLI surface page, desktop

End to end against a real T3 Code environment (0.0.46-nightly), through both its T3 Connect relay URL and a Tailscale URL:

  • Endpoint: an unauthenticated initialize returns 401 with WWW-Authenticate: Bearer resource_metadata=".../.well-known/oauth-protected-resource/mcp". The metadata lists scopes orchestration:read and orchestration:operate, and the authorization server advertises S256 PKCE and public clients. Dynamic client registration returns 201 on both URLs.
  • Sign-in: the authorize URL redirects to /connect-agent, which names the agent, defaults to Read only, and keeps Approve disabled until a pairing code is entered. With a code from t3 auth pairing create, approval redirected with a code, and the token exchange returned a Bearer token scoped orchestration:read that expires in 30 days.
  • Tools: tools/list returned 80 tools, including t3_project_list, t3_thread_list, t3_thread_read, t3_thread_launch, t3_thread_send and orchestrator_capabilities, which back the record's description. t3_project_list succeeded. A read-only token calling t3_thread_send got capability_denied. The test session was revoked afterwards and the token then got 401.
  • CLI: the t3 npm package is published from pingdotgg/t3code by Julius Marminge and Theo. npx t3@latest --version prints t3 v0.0.45, its help describes the default command as "Run the T3 Code server", and t3 auth pairing create exists.
  • Before: dist/disc/t3.codes.json did not exist. GitHub's baseline CLI command was github-com-cli.
    After: dist/disc/t3.codes.json lists the MCP surface at https://{environment_address}/mcp with its variable and an oauth2 credential, and the CLI with command t3. GitHub's is gh.
  • Tests: new tests cover declared and undeclared placeholders, loopback hosts, the worker backfill keeping variables (it fails without the fix), the curated CLI command, and the OAuth credential. bun test: 104 pass, 8 fail; the same 8 fail on main (missing cli/dist/cli.js and the production smoke test). tsc --noEmit reports the same 12 errors as main. bun run build passes.

Not covered: the CLI page shows "Authentication not yet determined" and does not show the npx t3@latest install note, as every curated CLI does today. I did not run wrangler dev, so the pages above come from astro dev.

Merge Danger

Door: two-way. Reverting removes the record and restores the old placeholder rule.

Blast radius: MCP endpoint filtering on every render path, and baseline auth for curated MCP surfaces. A surface with no variables and a curated interface with no setup behave exactly as before, so only T3 Code is affected today. The CLI fix changes the baseline command for every curated CLI. Slugs come from names, so URLs stay the same.

Created with Claude Opus 5.5 in Claude Code.

leoisadev1 and others added 2 commits October 8, 2026 19:30
T3 Code environments each serve their own MCP server at
https://<environment-address>/mcp, so there is no shared URL to list.
A curated MCP surface can now publish `https://{environment_address}/mcp`
when it declares `environment_address` as a variable; undeclared
placeholders are still rejected, and the endpoint probe skips templates.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Curated CLI records are slugged `<domain>-cli`, and the baseline
discovery document used that slug as the command, so GitHub's page
listed `github-com-cli` instead of `gh`. Carry the interface name as
the command.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The baseline MCP surface said "Authentication not yet determined",
although the endpoint is verified OAuth, and nothing on the page said
the approval screen asks for a one-time pairing code. A curated
`auth: "oauth"` MCP interface with a `setup` guide now publishes an
oauth2 credential bound through well-known metadata. Only T3 Code sets
`setup`, so every other baseline document is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant