Repository navigation
providers: the definition of mercury (Mercury MCP server, dynamic client) - #1
Conversation
… of the Mercury MCP server A node starts an authorization only for a provider with a definition: without one, oauth/begin answers provider_unknown, and a configuration that names the provider is refused as a whole. The values come from the metadata of the server (read 2026-10-05): - protected resource metadata of https://mcp.mercury.com: resource https://mcp.mercury.com/mcp, authorization server https://mcp.mercury.com/. - authorization server metadata: authorize /authorize, token /token, registration /register, code_challenge_methods_supported S256, token_endpoint_auth_methods_supported includes none, no revocation_endpoint. So the definition is a dynamic client with PKCE S256, client_auth none, the RFC 8707 resource fixed in the authorization and the token calls, no revocation address, the public fields of the other OAuth definitions, and forward reaches the exact path /mcp of mcp.mercury.com only (the token and registration addresses on the same host stay unreachable). The tables of the tests (6.2, section 7, the canary public fields, the host configuration) and of docs/enclave.md carry the new row. No release is cut and the crate versions are unchanged.
adcbbce to
b677e49
Compare
entry-sanio
left a comment
There was a problem hiding this comment.
Reviewed against the metadata of the server and the rules of enclave.md sections 6 and 7.
The values. Read again today from https://mcp.mercury.com/.well-known/oauth-protected-resource and https://mcp.mercury.com/.well-known/oauth-authorization-server: the resource is https://mcp.mercury.com/mcp, the authorization, token and registration addresses are /authorize, /token and /register of that host, code_challenge_methods_supported is ["S256"], token_endpoint_auth_methods_supported includes none, and there is no revocation_endpoint. The definition states exactly these. It differs from the definition of granola in three values only: the authorization address, the token address and the host of api (with the resource that follows from it).
The address check. The token, authorization and registration addresses are on the host of the forward rule, so what keeps them out of reach of forward is that the rule is the exact path /mcp and no prefix. The load check refuses a definition whose api list reaches its token address, and every_provider_reaches_only_its_own_hosts now denies /token, /register and /mcp/other.
Checks. On b677e49 with the toolchain of rust-toolchain.toml (1.98.1): cargo fmt --check, cargo clippy --workspace --all-targets --locked -- -D warnings, cargo test --workspace --locked, the vector check and scripts/secret-access.sh --check pass. The tables of the tests and of docs/enclave.md 6.2, 6.4 and 7 carry the same row.
Not covered by this review, as the description says: a live authorization against Mercury.
The definition takes effect with the release that carries it. The version of the crates, predecessors.json and the tag follow in the release.
The release adds the provider definition of mercury (#1). Cargo.lock names the same packages as before. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
What
A provider definition for mercury, the hosted MCP server of Mercury (
https://mcp.mercury.com/mcp).client_idtooauth/begin)https://mcp.mercury.com/authorize, fixedresource=https://mcp.mercury.com/mcp, allowedscopehttps://mcp.mercury.com/token, client_auth none, form body, fixedresource=https://mcp.mercury.com/mcprevocation_endpoint)scope,expires_in,token_typemcp.mercury.com, exact/mcpThe values are those of the server metadata, read 2026-10-05:
GET https://mcp.mercury.com/.well-known/oauth-protected-resource: resourcehttps://mcp.mercury.com/mcp, authorization_servers["https://mcp.mercury.com/"].GET https://mcp.mercury.com/.well-known/oauth-authorization-server: authorization_endpoint/authorize, token_endpoint/token, registration_endpoint/register, code_challenge_methods_supported["S256"], token_endpoint_auth_methods_supported["client_secret_basic", "none"], no revocation_endpoint.The token, authorization and registration addresses share the host of the forward rule; the rule allows the exact path
/mcponly, so none of them is reachable throughforward(token_and_revocation_addresses_are_not_reachable_by_forwardcovers the token and authorization addresses, andevery_provider_reaches_only_its_own_hostsnow denies/token,/registerand/mcp/other).Release
A node refuses
oauth/beginfor a provider without a definition (provider_unknown), andPOST /v1/configrefuses a configuration that names one, so the definition takes effect with the release that carries it. No release is cut here and the crate versions are unchanged: the version bump,predecessors.jsonand the tag belong to the release.Checks
check(pinned toolchain: fmt, clippy, tests, vectors, secret-access)cargo test -p credential-enclave(local)cargo test -p credential-enclave-host(local)Not run: a live authorization against Mercury (it needs a Mercury account).