🛣️ feat: Add MCP Remote Proxy Support - #13076
Conversation
There was a problem hiding this comment.
Pull request overview
Adds outbound proxy support for remote MCP transports (SSE and Streamable HTTP) across the data-provider schemas and API runtime connection layer, including env-var fallbacks and SSRF-aware dispatching.
Changes:
- Introduces an admin-configurable
proxyfield for remote MCP SSE/Streamable HTTP configs with URL/protocol validation and env-var expansion. - Routes MCP HTTP/SSE fetch dispatchers through undici
ProxyAgent(includingPROXY/HTTP_PROXY/HTTPS_PROXY/NO_PROXYbehavior) while preserving timeout separation and redirect protections. - Updates tests and documentation/examples to cover proxy configuration and behavior.
Reviewed changes
Copilot reviewed 9 out of 9 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| packages/data-provider/src/mcp.ts | Adds proxy to remote MCP option schemas + prevents proxy from being accepted via user-input schema. |
| packages/data-provider/specs/mcp.spec.ts | Adds schema tests for admin proxy acceptance and user-input proxy rejection. |
| packages/api/src/utils/env.ts | Extends MCP env/template processing to include the new proxy field. |
| packages/api/src/utils/env.spec.ts | Adds coverage for env-variable expansion of proxy in MCP options. |
| packages/api/src/mcp/connection.ts | Implements proxy selection (explicit + env fallbacks), NO_PROXY handling, ProxyAgent dispatchers, and proxied-target SSRF preflight checks. |
| packages/api/src/mcp/tests/MCPConnectionSSRF.test.ts | Adds tests validating proxy dispatcher allocation, env proxy precedence/NO_PROXY behavior, and proxied SSRF preflight. |
| packages/api/src/mcp/tests/mcp.spec.ts | Adds tests validating proxy parsing/validation and env processing in MCP options. |
| librechat.example.yaml | Documents the new per-server proxy YAML field for remote MCP transports. |
| .env.example | Documents that remote MCP transports honor PROXY plus standard proxy env vars when unset. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
GitNexus: 🚀 deployedThe |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 33514c579c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@danny-avila |
|
@codex review |
|
Codex Review: Didn't find any major issues. Breezy! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…support # Conflicts: # packages/api/src/mcp/__tests__/MCPConnectionSSRF.test.ts
|
@codex review |
GitNexus: 🚀 deployedThe |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8509cb42e0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
GitNexus: 🚀 deployedThe |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 87ddb85963
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
GitNexus: 🚀 deployedThe |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 146be95c64
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. Hooray! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
1 similar comment
|
Codex Review: Didn't find any major issues. Hooray! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
GitNexus: 🚀 deployedThe |
|
@codex review |
|
Codex Review: Didn't find any major issues. Hooray! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
GitNexus: 🚀 deployedThe |
* feat: add MCP remote proxy support * fix: Harden MCP Proxy Review Findings * fix: Honor MCP Proxy Env Precedence * fix: Harden MCP proxy routing * fix: Align MCP proxy bypass semantics * test: Pin MCP proxy admin scope
* feat: add MCP remote proxy support * fix: Harden MCP Proxy Review Findings * fix: Honor MCP Proxy Env Precedence * fix: Harden MCP proxy routing * fix: Align MCP proxy bypass semantics * test: Pin MCP proxy admin scope
Summary
I added outbound proxy support for remote MCP SSE and Streamable HTTP transports, resolving #12995.
proxyfield for remote MCP transports with URL/protocol validation and environment variable resolution.PROXYenv var, plus standardHTTP_PROXY,HTTPS_PROXY, andNO_PROXYfallbacks when no per-server proxy is configured.ProxyAgentwhile preserving separate POST and long-lived SSE GET timeouts.NO_PROXYdirect-connect SSRF guards..env.example.Change Type
Testing
npm run smart-reinstallfrom the repo root.npx turbo run build --filter=librechat-data-provider --filter=@librechat/apifrom the repo root.npx jest specs/mcp.spec.ts --runInBand --coverage=falsefrompackages/data-provider.npx jest src/mcp/__tests__/mcp.spec.ts src/utils/env.spec.ts src/mcp/__tests__/MCPConnectionSSRF.test.ts --runInBand --coverage=falsefrompackages/api.npx eslint packages/api/src/mcp/connection.ts packages/api/src/mcp/__tests__/MCPConnectionSSRF.test.ts packages/api/src/mcp/__tests__/mcp.spec.ts packages/api/src/utils/env.ts packages/api/src/utils/env.spec.ts packages/data-provider/src/mcp.ts packages/data-provider/specs/mcp.spec.tsfrom the repo root.git diff --checkfrom the repo root.Test Configuration:
v20.19.510.8.2dev(36e95353e)Checklist