Skip to content

[MCPB]: Add a Claude Desktop bundle for the MCP server - #7

Merged
lloydwatkin merged 1 commit into
mainfrom
add-mcpb-bundle
Sep 18, 2026
Merged

lloydwatkin merged 1 commit into
mainfrom
add-mcpb-bundle

Conversation

@lloydwatkin

Copy link
Copy Markdown
Member

Claude Code can talk to the server over HTTP directly, but Claude Desktop cannot — its remote connector UI has no way to send an API token header, so Desktop users had no route in at all.

This adds an MCPB bundle under mcpb/: a .mcpb file that installs into Claude Desktop with a double-click. Inside is a dependency-free Node script that speaks stdio to Desktop and forwards every message verbatim to the server over HTTPS with the token attached — so it understands nothing about MCP and gains no capabilities of its own. The tools a user sees are exactly the ones their account can already reach in admin.

Claude Desktop  ──stdio──▶  mcpb proxy  ──HTTPS + token──▶  Rails app

Three user_config fields (server URL, API token, auth header name) keep the bundle generic, so anyone using the gem can pack their own. The token is stored in the OS keychain and revocable from the existing MCP Tokens page.

Packs to a 2.9 kB, three-file bundle with no node_modules.

Testing Notes

Automated: cd mcpb && npm test — 13 tests spawning the proxy as a real child process against a stub HTTP server: header injection (default and custom), chunk-split and multi-message stdin, the 204 notification case, unreachable server, non-JSON error bodies, parse errors, and missing configuration. CI runs these and attaches a packed bundle as an artifact.

Manual — happy path:

  1. cd mcpb && npx @anthropic-ai/mcpb pack . ../activeadmin-mcp.mcpb
  2. Generate a token from admin → MCP Tokens.
  3. Double-click the .mcpb, fill in the server URL, token, and (for Olio) X-MCP-Authorization as the auth header.
  4. New chat → ask Claude to list the admin resources. Expect the resources your account can read.

Verified end to end against production, which uses the custom header:

$ printf '%s\n%s\n%s\n' '{"jsonrpc":"2.0","id":1,"method":"initialize",...}' \
    '{"jsonrpc":"2.0","method":"notifications/initialized"}' \
    '{"jsonrpc":"2.0","id":2,"method":"tools/list"}' | node server/index.js

id 1 {"protocolVersion": "2025-06-18", "serverInfo": {"name": "activeadmin-mcp", "version": "0.0.3"}, ...}
id 2 tools: ['list_resources', 'query', 'update']

The notification correctly produced no reply.

Error cases:

  • Wrong token → {"jsonrpc":"2.0","id":1,"error":{"code":-32603,"message":"The server rejected the API token (HTTP 401). Generate a new token in the admin panel and update the extension's settings."}} — confirmed against production.
  • Unreachable URL → a -32603 error naming the URL, rather than Desktop hanging forever on a reply that never comes.
  • A notification that fails logs to stderr instead of replying, since JSON-RPC has no id to reply to.

README: new "Claude Desktop (MCPB bundle)" section covering how it works, building, installing, revoking access, and troubleshooting.

🤖 Generated with Claude Code

Claude Desktop's remote connector UI cannot send an API token header, so
it could not talk to the server at all. The bundle wraps a dependency-free
Node script that speaks stdio to Desktop and forwards each message
verbatim over HTTPS with the token attached, so it gains no capabilities
of its own.

Packs to a 2.9 kB, three-file bundle. CI runs the proxy tests and attaches
a build as an artifact.

Prompt: Can you help me build a MCPB to allow our staff to access the
admin MCP server? Also add details to the readme, including how to build
and how to install

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@lloydwatkin
lloydwatkin merged commit cb45333 into main Sep 18, 2026
2 checks passed
@lloydwatkin
lloydwatkin deleted the add-mcpb-bundle branch September 18, 2026 13:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants