Skip to content

feat(mcp): expose environment usage summary - #8730

Closed
juliusmarminge wants to merge 360 commits into
t3code/codex-turn-mappingfrom
agents/mcp-environment/usage
Closed

juliusmarminge wants to merge 360 commits into
t3code/codex-turn-mappingfrom
agents/mcp-environment/usage

Conversation

@juliusmarminge

@juliusmarminge juliusmarminge commented Aug 30, 2026 •

Copy link
Copy Markdown
Member

Agents could not query the existing environment usage service through the authenticated MCP endpoint without relying on the client Usage page.

This change adds t3_environment_usage, a current-environment read over the existing UsageService. It validates a maximum 31-day daily window or 24-hour hourly window, returns deterministic bucket pages with Unicode-safe bounded model/pricing text, and preserves token, unpriced-record, source-status, and pricing provenance.

The result is deliberately narrower than the shared usage RPC: source fingerprints, host IDs, provider-home paths, volume IDs, transcript contents, credentials, and raw failures are omitted. Costs are labeled API-equivalent estimates, missing or failed sources remain explicit, and live-summary pagination warns that later pages can shift. The explicit read may scan transcripts, refresh cached pricing, and update existing scan caches; it adds no collector or telemetry path.

Focused validation: 76 service/production-registration/adapter/presentation tests, including MCP tools/list root-object properties, 31-day and 24-hour boundaries, invalid zones, Unicode astral-character encoding, deterministic pagination, partial/failed source redaction, capability/environment denial, and finite failure mapping. Targeted lint, contracts typecheck, and vp run -F t3 typecheck pass.

Dependency: immutable rollout base agents/mcp-controls/base-490318a at 490318afa505d3d033295eca12d7e62b4b922725. This is an independent standalone PR, not a member of native environment stack #8729.

Implemented by GPT-5.6-Sol via Codex in T3 Code.


Note

Medium Risk
New authenticated read path can trigger transcript scans and cache refresh; redaction and validation reduce leakage risk but live pagination and usage aggregation behavior affect agent-facing data.

Overview
Adds a read-only MCP tool t3_environment_usage so agents can query aggregated usage for the authenticated environment through the existing UsageService, without going through the Usage UI.

EnvironmentUsageMcpService enforces orchestration capability and environment ID match, validates bounded windows (up to 31 calendar days at daily resolution or 24 hours at hourly resolution, IANA timezone, hourly day-label rules), then projects usage into contract types with cursor-paginated, deterministically sorted buckets, Unicode-capped model text, and fixed metadata (costMeaning, paginationConsistency, cacheBehavior). Sensitive internals are stripped: no source fingerprints, paths, raw scan errors, or pricing URLs—generic source messages and a fixed litellm_public_model_prices provenance label instead.

The toolkit is wired into McpHttpServer, t3_environment_usage is added to Claude’s read-only MCP pre-approval list (with tests covering orchestrator + environment usage readonly annotations), and user/orchestrator docs plus UI tool presentation are updated. New contracts live in environmentUsageMcp.ts; registration tests assert tools/list includes the tool and expected input properties.

Reviewed by Cursor Bugbot for commit 1cf821a. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add t3_environment_usage MCP tool for environment usage summaries

  • Adds a new read-only MCP tool that reads bounded daily or hourly usage summaries from UsageService and returns sanitized, paginated bucket aggregates with source status, fixed pricing provenance, and cache metadata.
  • Introduces environmentUsageMcp.ts with input, result, and failure contracts; the service validates time windows (≤31 days daily, ≤24 hours hourly with local-day alignment), truncates text fields to Unicode limits, and removes source fingerprints and raw diagnostic paths.
  • Registers the toolkit in McpHttpServer.ts, adds t3_environment_usage to the Claude read-only allowlist in ClaudeAdapterV2.ts, and adds its presentation label in t3McpToolPresentation.ts.
  • Risk: EnvironmentUsageMcpService.make now maps all UsageReadError failures to finite public codes and drops underlying causes; any consumer relying on private error detail from the usage path will no longer receive it.

Macroscope summarized 1cf821a.

@coderabbitai

coderabbitai Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 220a6fbf-c270-48fd-8372-15259ead7971

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@juliusmarminge
juliusmarminge marked this pull request as ready for review August 30, 2026 02:26
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Aug 30, 2026
Comment thread packages/contracts/src/environmentUsageMcp.ts
@github-actions

github-actions Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for 1cf821a.

This comment will update automatically after the next completed run.

@macroscopeapp macroscopeapp Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions review of the new EnvironmentUsageMcpService and its contract/toolkit wiring. Two import/module-shape findings; the service definition (inline Context.Service interface, Foo["Service"] typing, environment-acquired dependencies, no ManagedRuntime/runPromise, structured Schema.TaggedErrorClass failure with a derived message) otherwise matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment thread apps/server/src/mcp/EnvironmentUsageMcpService.ts Outdated
Comment thread apps/server/src/mcp/EnvironmentUsageMcpService.test.ts Outdated
Comment thread docs/user/usage.md Outdated
@github-actions github-actions Bot added size:XL 500-999 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Aug 30, 2026
@macroscopeapp

macroscopeapp Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds and pre-approves a new authenticated MCP capability that exposes transcript-derived usage aggregates and can trigger scans and cache refreshes. Its new service, contracts, production registration, and agent-facing behavior make it broader than an auto-approvable bounded change.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge force-pushed the agents/mcp-environment/usage branch from 1183a77 to 53b66ab Compare August 30, 2026 17:28
@juliusmarminge
juliusmarminge changed the base branch from agents/mcp-controls/base-490318a to t3code/codex-turn-mapping August 30, 2026 17:28
@github-actions github-actions Bot added the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 30, 2026
Comment thread docs/user/usage.md Outdated
@github-actions github-actions Bot removed the 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. label Aug 30, 2026
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch from c01ff20 to 9d2539a Compare August 30, 2026 19:57
@juliusmarminge
juliusmarminge force-pushed the agents/mcp-environment/usage branch from 83bd6a0 to 9114fbc Compare August 30, 2026 20:12
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch 7 times, most recently from 877b9de to b82facd Compare September 5, 2026 04:52
mwolson and others added 5 commits September 4, 2026 21:54
Update every deterministic Codex turn/start expectation with the explicit user approvals reviewer emitted by the adapter, restoring exact replay coverage and unblocking the merge lane.
…ojects (#3640)

Restore versioned shell-cache hydration, reconcile repository enrichment across multiple environments, and decode non-null settled shell timestamps correctly.
Normalize subagent result disclosure across timeline rendering and collapsed/expanded states.

Co-authored-by: codex <codex@users.noreply.github.com>
Expose MCP tools for worktree handoff and status inspection, with focused server and contract coverage.

Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch 26 times, most recently from d2675dc to 9cbaf77 Compare September 23, 2026 07:35
@juliusmarminge
juliusmarminge force-pushed the t3code/codex-turn-mapping branch 3 times, most recently from 1bd44f2 to 3b9c885 Compare September 24, 2026 04:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L 100-499 changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants