yeelam-gordon/shared-mcp-gateway
v0.7.2MIT
Guide setup of one shared local MCP gateway with explicit, backed-up client configuration changes.
Changelog
All notable changes to this project are documented here. This project follows semantic versioning while recognizing that pre-1.0 releases may introduce breaking changes.
[0.7.2] - 2026-10-05
Fixed
- Resumed connectors rebuild obsolete gateway HTTP sessions after a daemon restart instead of failing discovery with
invalid_sessionand disconnecting after failed heartbeats. - Discovery and heartbeat can recover once from refused or interrupted local gateway connections, starting or reusing only the verified owned daemon when auto-start is configured.
- Concurrent recovery shares one initialization; outstanding old-session requests settle before retirement, while connector shutdown still cancels them within a bounded close.
- Downstream calls, claims and releases are never replayed automatically. Confirmed session rejection reports lost workflow ownership; ambiguous post-dispatch connection failures retain unknown-outcome guidance.
- Connector failures retain useful HTTP status and error context; gateway discovery no longer misleadingly identifies an "unknown backend".
[0.7.1] - 2026-10-03
Added
- Microsoft-aware MSAL browser, device-code, silent-renewal and configured app-only authentication.
- Explicit optional Microsoft host credentials through Azure CLI and VS Code's public Microsoft authentication API. The Windows VS Code route has been verified with genuine packaged-helper Mail authentication, a permitted native HTTP read and reconnect without Agency or a new gateway application registration.
- Confidential-client Basic/Post and private-key JWT authentication, client-credentials acquisition, RFC 8628 device authorization and authorization-response issuer checks.
- Explicit operator-trusted Microsoft API resource binding and validated permission repair before credential acquisition.
Fixed
- Atomic credential publication preserves renewed expiry, service selection and consent across identical token responses, restart and stale-generation races.
- Malformed access tokens are rejected before state mutation, device staging or persistence without exposing their values.
- Authentication helpers restrict inherited environments, isolate private profiles, display explicit consent windows and clean up only their owned processes within bounded deadlines.
- Cancelled authentication waits for bounded owned credential cleanup; unsettled cleanup reports uncertainty and retains lock provenance instead of claiming success.
- Equivalent Microsoft tenant GUID casing is normalized; device expiry is distinguished from helper cancellation; concurrent host callback completion is consumed once.
- Windows owner-only ACL publication avoids unnecessary same-owner writes, supports elevated-runner fixtures and gives the legacy PowerShell cold path a deadline-clipped 15-second budget.
Notes
- VS Code is an opt-in Windows host dependency and its Microsoft consent identifies Visual Studio Code. It does not establish registration-free standalone MSAL or universal Azure CLI access to every MCP service.
- Native WAM, mTLS and other deployment-specific authentication extensions remain explicitly outside this release.
[0.7.0] - 2026-10-01
Added
- Native MCP OAuth for remote HTTP backends through the official SDK, without requiring Agency: protected-resource and OAuth/OIDC discovery, PKCE, public-client registration, resource binding, and refresh.
- An explicit, bounded browser sign-in helper with private, atomic credential persistence and concurrency-safe refresh. Entra and other providers without dynamic registration use the operator's registered public client ID; tenant and client IDs are never guessed.
- Advisory diagnostics for mutable or unpinned
npxandnpm execpackage specifications during setup and migration, without changing execution or Copilot-owned approvals.
Fixed
- Expired credentials, rotated refresh tokens, concurrent sign-ins, and corrected resource metadata recover without losing newer credentials or retaining invalid discovery state.
- Established backend notification streams remain open beyond request deadlines while connection establishment and other HTTP traffic remain bounded.
- Confidential registration responses are rejected, and native OAuth configuration cannot be exported or imported through transfer packages.
- Authentication failures confirmed to reject a tool request before execution no longer unnecessarily block an exclusive backend; ambiguous downstream outcomes retain their existing safeguards.
- Updated transitive dependency resolutions for
fast-uriandip-address.
[0.6.1] - 2026-09-28
Fixed
- Concurrent terminal resume no longer launches process-inspection shells from every lock waiter. Only the lock holder records ownership; abandoned locks still receive provenance-aware recovery.
- Connectors use a shared 60-second startup budget and bounded 5-second authenticated handshakes, allowing simultaneous resumed sessions to reuse one gateway without failing at the former 20-second limit.
- Startup permission checks tolerate loaded Windows shell startup while respecting the coordinator's remaining deadline; standalone permission checks retain their existing limits and fail-closed behavior.
- Stale instance metadata is rechecked under the startup lock instead of rejecting a gateway whose new owner is still publishing its metadata.
- Regression coverage includes twelve independent starters, twelve real connector processes, shell-free live-lock waiting, and recovery after an owner exits during lock initialization.
[0.6.0] - 2026-09-24
Added
- Bring another client's MCP connections into the same shared catalog with explicit
--migratepreview and backed-up apply. Matching aliases and definitions deduplicate; conflicting definitions stop without replacement. - Migrate supported Claude Code, VS Code, OpenCode, Qwen Code, Kimi, Antigravity CLI JSON, and Codex TOML configurations through the same transaction layer. Different aliases stay separate, and unsupported client-managed authentication or policies fail explicitly.
- Back up both native configuration and shared catalog with hashes and exact restore commands. Report partial publication without silently undoing concurrent changes.
- Preserve non-MCP TOML data through a pinned parser; warn before regenerating comments and formatting, and retain the exact original backup.
- Exercise migration across all seven native formats and prove two SDK clients reuse the same imported connection and local process.
[0.5.0] - 2026-09-24
Added
- Setup can preview and import newly added user MCP entries into an existing gateway without a runtime upgrade, with backups, deduplication, and explicit conflict handling.
- Register the same gateway in six additional JSON client formats through one configuration-adapter layer. Codex receives a native CLI registration plan instead of a custom TOML rewrite; registration does not migrate the other client's existing servers.
- Thin Claude and Qwen plugin manifests expose the existing setup skill without embedding another runtime.
- Read the quickstart in English or 15 additional languages, with English remaining the canonical reference.
- Find separate installation and upgrade instructions for every client from the README navigation table.
- Separate CI release gates exercise fresh runtime installation, versioned upgrade and rollback, and recurring configuration synchronization.
- Source-based alternatives comparison distinguishes one client entry, backend resource sharing, and compact tool discovery.
Fixed
- Runtime publication retries transient Windows file-access failures within a short bounded window, without deleting an existing runtime or changing its permissions.
- Windows PowerShell 5.1 fallback allows a bounded 10-second cold start for owner-only permission checks; PowerShell 7 retains its 5-second limit, and failures still stop setup.
- Recurring sync preserves reserved object-property names as server aliases and refuses configuration changes detected during preparation rather than writing to a stale catalog.
[0.4.1] - 2026-09-24
Fixed
- Immediately retrying discovery after its last caller cancels now starts a fresh discovery instead of inheriting the cancelled request.
- Added boundary regressions for stale catalog generations, pending-release uncertainty, and heartbeat failure preserving an unknown-outcome server lock.
- Shortened setup autocomplete text and user-facing setup summaries while retaining approval and recovery instructions.
- Default transfer exports redact all endpoint URLs, including capability paths and signed query strings.
- Runtime reuse verifies packaged file contents rather than trusting only an installation marker.
- Ambiguous post-dispatch HTTP failures retain exclusive ownership until the outcome can be resolved.
- Windows owner-only permissions are applied atomically, avoiding temporary access failures during simultaneous gateway startup.
- Warm Windows permission checks are batched into one process, with tested PowerShell 7 and Windows PowerShell 5.1 handling.
- Existing-installation checks accept equivalent Windows path casing while continuing to reject different locations.
- The first uncertain HTTP failure explains the unknown outcome, lack of retry, and required exclusive-server recovery.
[0.4.0] - 2026-09-24
Added
claim_serverandrelease_serveracquire/release ownership for an entire backend workflow. Discovery reports therequiresExclusiveAccesssetting; the legacyplaywrightalias remains exclusive by default.- Single-flight backend catalog loading, bounded discovery, idle session expiry, and session heartbeats.
- Canonical configuration validation shared across gateway entry points.
Changed
- The public gateway surface remains six meta-tools.
claim_playwrightandrelease_playwrightare replaced byclaim_serverandrelease_server, each requiring aserverargument. - Running plugin or gateway processes must be restarted or re-adopted to use the 0.4 behavior after an upgrade.
Security
- Documented the local single-owner trust boundary and clarified that gateway approval does not replace backend authorization.