Repository navigation
feat(server): sign MCP connection grants for one year - #90
Merged
Merged
Conversation
`vana server start` passes mcpGrantTtlSeconds = 365 days to the Personal Server, so grants it signs itself for MCP connections expire after a year instead of never. Takes effect once the runtime pins a personal-server-ts release with the option; older servers ignore it. Claude-Session: https://claude.ai/code/session_01Fcv6uEy4zcXaigzDNxeW3j
github-actions Bot
pushed a commit
that referenced
this pull request
Oct 8, 2026
## [0.41.0](v0.40.1...v0.41.0) (2026-10-08) ### Features * **server:** sign MCP connection grants for one year ([#90](#90)) ([58c6714](58c6714))
Contributor
|
🎉 This PR is included in version 0.41.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
vana server startpassesmcpGrantTtlSeconds: 365 * 24 * 3600tostartPersonalServer(constantMCP_GRANT_TTL_SECONDSinruntime-pkg/derived-config.mjs). Grants the Personal Server signs itself for MCP connections (an agent connecting over OAuth, or a scope request approved with no live grant to inherit an expiry from) then expire one year after signing instead of never. A scope request on a connection with a live grant still keeps that grant's expiry, perpetual included.Depends on
personal-server-ts PR 374 (adds
mcpGrantTtlSecondsand forwards it throughstartPersonalServer). Until a release containing it is pinned inruntime-pkg/package.json(currently 1.31.0), this change has no effect. Once released, bump the pin here (or in a follow-up) to turn it on.Safe before the bump
Checked the published
@opendatalabs/personal-server-ts-server@1.31.0:startPersonalServerbuilds thecreateServeroptions from a fixed list of named fields (rootPath,dataDir,ownerSignature,gatewayClient,readFulfillmentReporter,mcpOAuthApprovalUrl,mcpScopeRequestApprovalUrl), with no validation of extra keys. An unknownmcpGrantTtlSecondsis ignored, and the server keeps signing perpetual grants as today.Tests
test/personal-server/derived-config.test.ts: the lifetime is one year andentry.mjshands it to the server.pnpm validategreen (60 test files) with HOME and VANA_HOME in temp dirs. One unrelated flaky test (in-process-runlog assertion) failed once and passed on rerun.https://claude.ai/code/session_01Fcv6uEy4zcXaigzDNxeW3j