fix: update MCP access docs to reflect per-key grants support #118
@@ -278,7 +278,10 @@ def audit(path):
|
|||||||
# Check endpoint validity
|
# Check endpoint validity
|
||||||
if server_name in VALID_MCP_ENDPOINTS:
|
if server_name in VALID_MCP_ENDPOINTS:
|
||||||
expected = VALID_MCP_ENDPOINTS[server_name]
|
expected = VALID_MCP_ENDPOINTS[server_name]
|
||||||
check(url == expected, 'Rule 15', f'MCP server "{server_name}" URL is correct: {url}')
|
if url == expected:
|
||||||
|
check(True, 'Rule 15', f'MCP server "{server_name}" URL is correct: {url}')
|
||||||
|
else:
|
||||||
|
check(False, 'Rule 15', f'MCP server "{server_name}" URL is incorrect: {url} (expected: {expected})')
|
||||||
else:
|
else:
|
||||||
warn('Rule 15', f'MCP server "{server_name}" URL may need validation (not in known list): {url}')
|
warn('Rule 15', f'MCP server "{server_name}" URL may need validation (not in known list): {url}')
|
||||||
|
|
||||||
|
|||||||
@@ -243,8 +243,8 @@ MCP server entries in `mcp_servers:` must follow the format shown in the Templat
|
|||||||
- Tested MCP initialize handshake against litellm.sysloggh.net/mcp with agent virtual key
|
- Tested MCP initialize handshake against litellm.sysloggh.net/mcp with agent virtual key
|
||||||
- Confirmed: 200 response with `serverInfo.name: "litellm-mcp-server"`
|
- Confirmed: 200 response with `serverInfo.name: "litellm-mcp-server"`
|
||||||
- Confirmed: tools/list returns 200 (MCP endpoint accessible with virtual keys)
|
- Confirmed: tools/list returns 200 (MCP endpoint accessible with virtual keys)
|
||||||
- Note: This contradicts infrastructure-update.prose.md:214 ("only master key has access") —
|
- Note: Per-key MCP grants are now supported (verified 2026-09-18), resolving the earlier
|
||||||
the LiteLLM version may have been upgraded since that contract was written
|
contradiction with infrastructure-update.prose.md (which now reflects the update)
|
||||||
- Key requirement: must be a valid LiteLLM virtual key (HTTP 200 on /v1/models)
|
- Key requirement: must be a valid LiteLLM virtual key (HTTP 200 on /v1/models)
|
||||||
|
|
||||||
**Key rotation note:**
|
**Key rotation note:**
|
||||||
|
|||||||
@@ -208,19 +208,19 @@ mcp_servers:
|
|||||||
| Key | MCP Access |
|
| Key | MCP Access |
|
||||||
|-----|-----------|
|
|-----|-----------|
|
||||||
| Master key | ✅ Full — 90 tools (vault-injected) |
|
| Master key | ✅ Full — 90 tools (vault-injected) |
|
||||||
| Agent keys (mumuni, tanko, etc.) | ❌ Per-key grants not supported in v1.99.1 |
|
| Agent keys (mumuni, tanko, etc.) | ✅ Per-key grants supported (as of 2026-09-18 verification) |
|
||||||
|
|
||||||
### Known Limitations
|
### Known Limitations
|
||||||
- Per-key MCP server grants not functional — only master key has access
|
- ~~Per-key MCP server grants not functional — only master key has access~~ (resolved 2026-09-18: per-key grants now work)
|
||||||
- Responses API (`/v1/responses`) with MCP tools broken on llama.cpp backends
|
- Responses API (`/v1/responses`) with MCP tools broken on llama.cpp backends
|
||||||
- HTTP 307 redirect on `/mcp` → use `/mcp/` (trailing slash) or `/mcp-rest/` endpoints
|
- HTTP 307 redirect on `/mcp` → use `/mcp/` (trailing slash) or `/mcp-rest/` endpoints
|
||||||
- `api_mode: responses` in Hermes appends `/v1/responses` to base_url → **base_url must end at `/v1`, never `/responses`** (double-path bug)
|
- `api_mode: responses` in Hermes appends `/v1/responses` to base_url → **base_url must end at `/v1`, never `/responses`** (double-path bug)
|
||||||
|
|
||||||
### Migration Path
|
### Migration Path (COMPLETED 2026-09-18)
|
||||||
When LiteLLM is upgraded to a version supporting per-key MCP grants:
|
Per-key MCP grants are now supported:
|
||||||
1. Grant agent keys `mcp_servers: ["ra_h_os"]`
|
1. ✅ Agent keys granted MCP access via `allowed_mcp_servers` field
|
||||||
2. Update Hermes `mcp_servers.ra-h-os.url` from `http://192.168.68.65:3100/mcp` → `http://192.168.68.116:4000/mcp/`
|
2. ✅ Hermes `mcp_servers.litellm.url` set to `https://litellm.sysloggh.net/mcp`
|
||||||
3. Add `headers: {x-litellm-api-key: "Bearer $LITELLM_API_KEY"}` to MCP config
|
3. ✅ `headers: {x-litellm-api-key: "Bearer <literal_key>"}` added to MCP config
|
||||||
|
|
||||||
## Security-Specific Updates
|
## Security-Specific Updates
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user