Repository navigation
Add T3 Code, with a self-hosted MCP endpoint template - #92
Open
leoisadev1 wants to merge 3 commits into
Open
leoisadev1 wants to merge 3 commits into
leoisadev1 wants to merge 3 commits into
Conversation
T3 Code environments each serve their own MCP server at
https://<environment-address>/mcp, so there is no shared URL to list.
A curated MCP surface can now publish `https://{environment_address}/mcp`
when it declares `environment_address` as a variable; undeclared
placeholders are still rejected, and the endpoint probe skips templates.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Curated CLI records are slugged `<domain>-cli`, and the baseline discovery document used that slug as the command, so GitHub's page listed `github-com-cli` instead of `gh`. Carry the interface name as the command. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
leoisadev1
force-pushed
the
add-t3-code
branch
from
October 8, 2026 23:30
9f20b4b to
e0917de
Compare
The baseline MCP surface said "Authentication not yet determined", although the endpoint is verified OAuth, and nothing on the page said the approval screen asks for a one-time pairing code. A curated `auth: "oauth"` MCP interface with a `setup` guide now publishes an oauth2 credential bound through well-known metadata. Only T3 Code sets `setup`, so every other baseline document is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
T3 Code now ships an MCP server that outside agents can drive (announcement, docs). It is self-hosted: every T3 Code environment serves its own
https://<environment-address>/mcp, so there is no one URL to list, and the registry drops any MCP URL with a{placeholder}in it.This adds
curated/t3code.json(the MCP server and thet3CLI) and lets an MCP surface publish a templated URL when it declares the token invariables, a field the discovery schema already has:The variables travel from the curated record through
normalize.ts, the baseline discovery document, the worker's baseline backfill, and everyapplyEndpointVerdictscaller. The surface page shows them as a Variable row.verify-mcp-endpoints.tsreusesisUnusableEndpointto skip templated URLs, since there is no one host to probe.The MCP page also has to say how to sign in. T3 Code's approval page asks for a one-time pairing code, which no client can discover on its own. A curated
auth: "oauth"MCP interface with asetupguide now publishes anoauth2credential bound through well-known metadata, so the page shows the sign-in and the pairing step instead of "Authentication not yet determined". Only T3 Code setssetup; every other/disc/*.jsondocument is byte-identical tomain.A separate commit fixes a bug this exposed: curated CLIs published their record slug as the command (
github-com-cli,vercel-com-cli, and heret3-codes-cli) instead of the command itself (gh,vercel,t3).Evidence
End to end against a real T3 Code environment (
0.0.46-nightly), through both its T3 Connect relay URL and a Tailscale URL:initializereturns401withWWW-Authenticate: Bearer resource_metadata=".../.well-known/oauth-protected-resource/mcp". The metadata lists scopesorchestration:readandorchestration:operate, and the authorization server advertises S256 PKCE and public clients. Dynamic client registration returns201on both URLs./connect-agent, which names the agent, defaults to Read only, and keeps Approve disabled until a pairing code is entered. With a code fromt3 auth pairing create, approval redirected with a code, and the token exchange returned a Bearer token scopedorchestration:readthat expires in 30 days.tools/listreturned 80 tools, includingt3_project_list,t3_thread_list,t3_thread_read,t3_thread_launch,t3_thread_sendandorchestrator_capabilities, which back the record's description.t3_project_listsucceeded. A read-only token callingt3_thread_sendgotcapability_denied. The test session was revoked afterwards and the token then got401.t3npm package is published frompingdotgg/t3codeby Julius Marminge and Theo.npx t3@latest --versionprintst3 v0.0.45, its help describes the default command as "Run the T3 Code server", andt3 auth pairing createexists.dist/disc/t3.codes.jsondid not exist. GitHub's baseline CLI command wasgithub-com-cli.After:
dist/disc/t3.codes.jsonlists the MCP surface athttps://{environment_address}/mcpwith its variable and anoauth2credential, and the CLI with commandt3. GitHub's isgh.bun test: 104 pass, 8 fail; the same 8 fail onmain(missingcli/dist/cli.jsand the production smoke test).tsc --noEmitreports the same 12 errors asmain.bun run buildpasses.Not covered: the CLI page shows "Authentication not yet determined" and does not show the
npx t3@latestinstall note, as every curated CLI does today. I did not runwrangler dev, so the pages above come fromastro dev.Merge Danger
Door: two-way. Reverting removes the record and restores the old placeholder rule.
Blast radius: MCP endpoint filtering on every render path, and baseline auth for curated MCP surfaces. A surface with no
variablesand a curated interface with nosetupbehave exactly as before, so only T3 Code is affected today. The CLI fix changes the baselinecommandfor every curated CLI. Slugs come from names, so URLs stay the same.Created with Claude Opus 5.5 in Claude Code.