Skip to content

Version Packages - #535

Merged
kvz merged 1 commit into
mainfrom
changeset-release/main
Oct 4, 2026
Merged

kvz merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@transloadit/mcp-server@0.5.0

Minor Changes

  • 8b0c308: Let MCP clients connect to the hosted server by URL and satisfy the ChatGPT plugin and Claude
    connector requirements.

    • Hosted mode (TRANSLOADIT_MCP_RESOURCE_METADATA_URL) requires TRANSLOADIT_MCP_UPSTREAM_SECRET
      and refuses to start without it, so a missing production secret fails the deploy's health check
      instead of every authenticated tool call.
    • Hosted mode (TRANSLOADIT_MCP_RESOURCE_METADATA_URL): unauthenticated requests get a 401 with
      WWW-Authenticate: Bearer resource_metadata="…", browser Origins are limited to ChatGPT, Claude,
      Transloadit and loopback (overridable with allowedOrigins), and the server card advertises
      OAuth. Self-hosted TRANSLOADIT_MCP_TOKEN behavior is unchanged.
    • Every tool carries a title, readOnlyHint/destructiveHint/openWorldHint/idempotentHint
      annotations (only Assembly creation is destructive) and per-tool securitySchemes, also in
      _meta.securitySchemes, that match the deployment: oauth2 with each tool's full scopes when
      hosted, noauth where the server holds an Auth Key or a tool needs no account. Auth failures return isError results with
      _meta["mcp/www_authenticate"] so hosts show their account-linking UI.
    • Behavior change for self-hosted servers without credentials: account tools now return an
      isError result with mcp_missing_auth and a hint naming TRANSLOADIT_KEY/TRANSLOADIT_SECRET
      (transloadit_list_templates no longer adds an empty templates list to that error).
    • Behavior change for Express mounts: explicit allowedOrigins are now enforced by the router
      (wildcards *. and :* supported) even without DNS rebinding protection, so other browser
      Origins get HTTP 403 and allowed ones receive CORS headers.
    • transloadit_create_assembly with expected_uploads returns upload_instructions: per file the
      tus endpoint, metadata and a credential-free curl command (tus creation-with-upload), so agents
      can upload files that exist only in their sandbox, then call transloadit_wait_for_assembly.
      expected_uploads now accepts at most 100; larger values are rejected before an Assembly is
      created.
    • New transloadit_get_profile tool (_meta["openai/profile"]) returns the Workspace behind the
      credentials for multi-account hosts.
    • transloadit_create_assembly accepts ChatGPT-attached files through attachments
      (_meta["openai/fileParams"]), mapped onto the existing URL-input path.
    • MCP Apps result widget ui://transloadit/assembly-result with previews, download links and a
      Save as Template shortcut, linked from the Assembly tools with _meta.ui.resourceUri.
    • plugin.json, mcp.json and .codex-plugin/plugin.json describe the ChatGPT and Codex plugin.
    • Hosted mode serves JSON responses and turns an upstream rejection of the forwarded token into
      HTTP 401 (invalid_token) or 403 (insufficient_scope with the tool's scopes), so OAuth clients
      refresh or re-scope instead of retrying a dead token.
    • Request bodies are capped (1 MiB hosted, 10 MiB self-hosted, maxRequestBodyBytes) and larger
      ones get HTTP 413 without being buffered. URL inputs the server downloads are capped
      (maxUrlDownloadBytes, urlDownloadTimeoutMs), and hosted tokens are checked before downloading.
    • Hosted mode also challenges bare GET /mcp probes (Codex discovers OAuth from them); CORS now
      allows Mcp-Protocol-Version so browser hosts can connect.
    • Self-hosted servers sign with TRANSLOADIT_SIGNATURE_ALGORITHM (sha1, sha256 or sha384),
      so Console keys that require sha256 work; mismatches return an actionable
      mcp_invalid_signature hint.
    • The widget speaks the MCP Apps 2026-01-26 handshake (appInfo), shows failed tool calls, and
      allows https://*.r2.dev result URLs; TRANSLOADIT_MCP_RESULT_DOMAINS overrides its CSP.

Patch Changes

  • Updated dependencies [8b0c308]
    • @transloadit/node@5.2.0

@transloadit/node@5.2.0

Minor Changes

  • 8b0c308: Add an extraHeaders client option so trusted relays such as the hosted MCP service can send a
    fixed header (Transloadit-Mcp-Upstream) with every API request next to a forwarded bearer token.
    Like Authorization, these headers are dropped when a redirect leaves the API origin.

    listTemplates() also accepts fields, for API2 columns such as account_id that the default
    Template list omits.

    prepareInputFiles() accepts maxUrlDownloadBytes (a total for the call) and urlDownloadTimeoutMs
    (one deadline per download, redirects included) to bound URL downloads and beforeUrlDownload to vouch for a requester before a file is fetched locally; its
    download errors name only a URL's origin and path, never presigned query parameters.
    createAssembly() accepts onAssemblyCreated, called once API2 accepted the creation request.

transloadit@5.2.0

Minor Changes

  • 8b0c308: Add an extraHeaders client option so trusted relays such as the hosted MCP service can send a
    fixed header (Transloadit-Mcp-Upstream) with every API request next to a forwarded bearer token.
    Like Authorization, these headers are dropped when a redirect leaves the API origin.

    listTemplates() also accepts fields, for API2 columns such as account_id that the default
    Template list omits.

    prepareInputFiles() accepts maxUrlDownloadBytes (a total for the call) and urlDownloadTimeoutMs
    (one deadline per download, redirects included) to bound URL downloads and beforeUrlDownload to vouch for a requester before a file is fetched locally; its
    download errors name only a URL's origin and path, never presigned query parameters.
    createAssembly() accepts onAssemblyCreated, called once API2 accepted the creation request.

@kvz
kvz merged commit d5c635e into main Oct 4, 2026
27 of 28 checks passed
@kvz
kvz deleted the changeset-release/main branch October 4, 2026 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant