Skip to content

🛣️ feat: Add MCP Remote Proxy Support - #13076

Merged
danny-avila merged 7 commits into
devfrom
danny-avila/mcp-proxy-support
May 21, 2026
Merged

danny-avila merged 7 commits into
devfrom
danny-avila/mcp-proxy-support

Conversation

@danny-avila

Copy link
Copy Markdown
Collaborator

Summary

I added outbound proxy support for remote MCP SSE and Streamable HTTP transports, resolving #12995.

  • Added an admin-configurable proxy field for remote MCP transports with URL/protocol validation and environment variable resolution.
  • Honored LibreChat's PROXY env var, plus standard HTTP_PROXY, HTTPS_PROXY, and NO_PROXY fallbacks when no per-server proxy is configured.
  • Routed MCP SSE and Streamable HTTP fetch dispatchers through undici ProxyAgent while preserving separate POST and long-lived SSE GET timeouts.
  • Kept proxy configuration out of user-created MCP server input so end users cannot choose outbound proxy targets.
  • Added proxied-target SSRF preflight checks before network dispatch and preserved redirect credential stripping, safe redirect dispatchers, and NO_PROXY direct-connect SSRF guards.
  • Documented the new per-server YAML field and clarified the env proxy behavior in .env.example.

Change Type

  • New feature (non-breaking change which adds functionality)
  • This change requires a documentation update
  • Documentation update

Testing

  • Ran npm run smart-reinstall from the repo root.
  • Ran npx turbo run build --filter=librechat-data-provider --filter=@librechat/api from the repo root.
  • Ran npx jest specs/mcp.spec.ts --runInBand --coverage=false from packages/data-provider.
  • Ran npx jest src/mcp/__tests__/mcp.spec.ts src/utils/env.spec.ts src/mcp/__tests__/MCPConnectionSSRF.test.ts --runInBand --coverage=false from packages/api.
  • Ran npx eslint packages/api/src/mcp/connection.ts packages/api/src/mcp/__tests__/MCPConnectionSSRF.test.ts packages/api/src/mcp/__tests__/mcp.spec.ts packages/api/src/utils/env.ts packages/api/src/utils/env.spec.ts packages/data-provider/src/mcp.ts packages/data-provider/specs/mcp.spec.ts from the repo root.
  • Ran git diff --check from the repo root.

Test Configuration:

  • Node.js: v20.19.5
  • npm: 10.8.2
  • Base branch: dev (36e95353e)

Checklist

  • My code adheres to this project's style guidelines
  • I have performed a self-review of my own code
  • I have commented in any complex areas of my code
  • I have made pertinent documentation changes
  • My changes do not introduce new warnings
  • I have written tests demonstrating that my changes are effective or that my feature works
  • Local unit tests pass with my changes

Copilot AI review requested due to automatic review settings May 11, 2026 20:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds outbound proxy support for remote MCP transports (SSE and Streamable HTTP) across the data-provider schemas and API runtime connection layer, including env-var fallbacks and SSRF-aware dispatching.

Changes:

  • Introduces an admin-configurable proxy field for remote MCP SSE/Streamable HTTP configs with URL/protocol validation and env-var expansion.
  • Routes MCP HTTP/SSE fetch dispatchers through undici ProxyAgent (including PROXY/HTTP_PROXY/HTTPS_PROXY/NO_PROXY behavior) while preserving timeout separation and redirect protections.
  • Updates tests and documentation/examples to cover proxy configuration and behavior.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
packages/data-provider/src/mcp.ts Adds proxy to remote MCP option schemas + prevents proxy from being accepted via user-input schema.
packages/data-provider/specs/mcp.spec.ts Adds schema tests for admin proxy acceptance and user-input proxy rejection.
packages/api/src/utils/env.ts Extends MCP env/template processing to include the new proxy field.
packages/api/src/utils/env.spec.ts Adds coverage for env-variable expansion of proxy in MCP options.
packages/api/src/mcp/connection.ts Implements proxy selection (explicit + env fallbacks), NO_PROXY handling, ProxyAgent dispatchers, and proxied-target SSRF preflight checks.
packages/api/src/mcp/tests/MCPConnectionSSRF.test.ts Adds tests validating proxy dispatcher allocation, env proxy precedence/NO_PROXY behavior, and proxied SSRF preflight.
packages/api/src/mcp/tests/mcp.spec.ts Adds tests validating proxy parsing/validation and env processing in MCP options.
librechat.example.yaml Documents the new per-server proxy YAML field for remote MCP transports.
.env.example Documents that remote MCP transports honor PROXY plus standard proxy env vars when unset.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread packages/api/src/utils/env.ts Outdated
Comment thread packages/api/src/mcp/connection.ts Outdated
@github-actions

Copy link
Copy Markdown
Contributor

GitNexus: 🚀 deployed

The LibreChat-pr-13076 index is now live on the MCP server.
Deploy run

@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 33514c579c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/mcp/connection.ts Outdated
@inv-Eldho

Copy link
Copy Markdown

@danny-avila
Has the development been completed? Could you please provide an update on this? If it’s completed, please merge it into the main branch.

@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…support

# Conflicts:
#	packages/api/src/mcp/__tests__/MCPConnectionSSRF.test.ts
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@github-actions

Copy link
Copy Markdown
Contributor

GitNexus: 🚀 deployed

The LibreChat-pr-13076 index is now live on the MCP server.
Deploy run

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8509cb42e0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/mcp/connection.ts
Comment thread packages/api/src/mcp/connection.ts Outdated
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@github-actions

Copy link
Copy Markdown
Contributor

GitNexus: 🚀 deployed

The LibreChat-pr-13076 index is now live on the MCP server.
Deploy run

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 87ddb85963

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/mcp/connection.ts
Comment thread packages/api/src/mcp/connection.ts
Comment thread packages/api/src/mcp/connection.ts Outdated
Comment thread packages/api/src/mcp/connection.ts
@github-actions

Copy link
Copy Markdown
Contributor

GitNexus: 🚀 deployed

The LibreChat-pr-13076 index is now live on the MCP server.
Deploy run

@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 146be95c64

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/mcp/connection.ts Outdated
Comment thread packages/api/src/mcp/connection.ts
Comment thread packages/api/src/mcp/connection.ts Outdated
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

1 similar comment
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@github-actions

Copy link
Copy Markdown
Contributor

GitNexus: 🚀 deployed

The LibreChat-pr-13076 index is now live on the MCP server.
Deploy run

@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@github-actions

Copy link
Copy Markdown
Contributor

GitNexus: 🚀 deployed

The LibreChat-pr-13076 index is now live on the MCP server.
Deploy run

@danny-avila
danny-avila merged commit 05a3d1e into dev May 21, 2026
17 of 18 checks passed
@danny-avila
danny-avila deleted the danny-avila/mcp-proxy-support branch May 21, 2026 19:28
fuuuzzy pushed a commit to fuuuzzy/LibreChat that referenced this pull request May 22, 2026
* feat: add MCP remote proxy support

* fix: Harden MCP Proxy Review Findings

* fix: Honor MCP Proxy Env Precedence

* fix: Harden MCP proxy routing

* fix: Align MCP proxy bypass semantics

* test: Pin MCP proxy admin scope
ThomasVuNguyen pushed a commit to ThomasVuNguyen/LibreChat that referenced this pull request Jul 15, 2026
* feat: add MCP remote proxy support

* fix: Harden MCP Proxy Review Findings

* fix: Honor MCP Proxy Env Precedence

* fix: Harden MCP proxy routing

* fix: Align MCP proxy bypass semantics

* test: Pin MCP proxy admin scope
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Enhancement]: Support outbound proxy configuration for remote MCP HTTP/SSE transports

3 participants