Skip to content

feat(server): sign MCP connection grants for one year - #90

Merged
volod-vana merged 3 commits into
mainfrom
volod/mcp-grant-ttl
Oct 8, 2026
Merged

volod-vana merged 3 commits into
mainfrom
volod/mcp-grant-ttl

Conversation

@volod-vana

Copy link
Copy Markdown
Member

What

vana server start passes mcpGrantTtlSeconds: 365 * 24 * 3600 to startPersonalServer (constant MCP_GRANT_TTL_SECONDS in runtime-pkg/derived-config.mjs). Grants the Personal Server signs itself for MCP connections (an agent connecting over OAuth, or a scope request approved with no live grant to inherit an expiry from) then expire one year after signing instead of never. A scope request on a connection with a live grant still keeps that grant's expiry, perpetual included.

Depends on

personal-server-ts PR 374 (adds mcpGrantTtlSeconds and forwards it through startPersonalServer). Until a release containing it is pinned in runtime-pkg/package.json (currently 1.31.0), this change has no effect. Once released, bump the pin here (or in a follow-up) to turn it on.

Safe before the bump

Checked the published @opendatalabs/personal-server-ts-server@1.31.0: startPersonalServer builds the createServer options from a fixed list of named fields (rootPath, dataDir, ownerSignature, gatewayClient, readFulfillmentReporter, mcpOAuthApprovalUrl, mcpScopeRequestApprovalUrl), with no validation of extra keys. An unknown mcpGrantTtlSeconds is ignored, and the server keeps signing perpetual grants as today.

Tests

  • test/personal-server/derived-config.test.ts: the lifetime is one year and entry.mjs hands it to the server.
  • pnpm validate green (60 test files) with HOME and VANA_HOME in temp dirs. One unrelated flaky test (in-process-run log assertion) failed once and passed on rerun.

https://claude.ai/code/session_01Fcv6uEy4zcXaigzDNxeW3j

`vana server start` passes mcpGrantTtlSeconds = 365 days to the
Personal Server, so grants it signs itself for MCP connections expire
after a year instead of never. Takes effect once the runtime pins a
personal-server-ts release with the option; older servers ignore it.

Claude-Session: https://claude.ai/code/session_01Fcv6uEy4zcXaigzDNxeW3j
@volod-vana
volod-vana merged commit 58c6714 into main Oct 8, 2026
6 checks passed
github-actions Bot pushed a commit that referenced this pull request Oct 8, 2026
## [0.41.0](v0.40.1...v0.41.0) (2026-10-08)

### Features

* **server:** sign MCP connection grants for one year ([#90](#90)) ([58c6714](58c6714))
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 0.41.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant