Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 0 additions & 50 deletions .changeset/mcp-oauth-discovery.md

This file was deleted.

16 changes: 0 additions & 16 deletions .changeset/mcp-upstream-header.md

This file was deleted.

56 changes: 56 additions & 0 deletions packages/mcp-server/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,61 @@
# @transloadit/mcp-server

## 0.5.0

### Minor Changes

- 8b0c308: Let MCP clients connect to the hosted server by URL and satisfy the ChatGPT plugin and Claude
connector requirements.

- Hosted mode (`TRANSLOADIT_MCP_RESOURCE_METADATA_URL`) requires `TRANSLOADIT_MCP_UPSTREAM_SECRET`
and refuses to start without it, so a missing production secret fails the deploy's health check
instead of every authenticated tool call.
- Hosted mode (`TRANSLOADIT_MCP_RESOURCE_METADATA_URL`): unauthenticated requests get a `401` with
`WWW-Authenticate: Bearer resource_metadata="…"`, browser Origins are limited to ChatGPT, Claude,
Transloadit and loopback (overridable with `allowedOrigins`), and the server card advertises
OAuth. Self-hosted `TRANSLOADIT_MCP_TOKEN` behavior is unchanged.
- Every tool carries a title, `readOnlyHint`/`destructiveHint`/`openWorldHint`/`idempotentHint`
annotations (only Assembly creation is destructive) and per-tool `securitySchemes`, also in
`_meta.securitySchemes`, that match the deployment: `oauth2` with each tool's full scopes when
hosted, `noauth` where the server holds an Auth Key or a tool needs no account. Auth failures return `isError` results with
`_meta["mcp/www_authenticate"]` so hosts show their account-linking UI.
- Behavior change for self-hosted servers without credentials: account tools now return an
`isError` result with `mcp_missing_auth` and a hint naming `TRANSLOADIT_KEY`/`TRANSLOADIT_SECRET`
(`transloadit_list_templates` no longer adds an empty `templates` list to that error).
- Behavior change for Express mounts: explicit `allowedOrigins` are now enforced by the router
(wildcards `*.` and `:*` supported) even without DNS rebinding protection, so other browser
Origins get HTTP 403 and allowed ones receive CORS headers.
- `transloadit_create_assembly` with `expected_uploads` returns `upload_instructions`: per file the
tus endpoint, metadata and a credential-free `curl` command (tus creation-with-upload), so agents
can upload files that exist only in their sandbox, then call `transloadit_wait_for_assembly`.
`expected_uploads` now accepts at most 100; larger values are rejected before an Assembly is
created.
- New `transloadit_get_profile` tool (`_meta["openai/profile"]`) returns the Workspace behind the
credentials for multi-account hosts.
- `transloadit_create_assembly` accepts ChatGPT-attached files through `attachments`
(`_meta["openai/fileParams"]`), mapped onto the existing URL-input path.
- MCP Apps result widget `ui://transloadit/assembly-result` with previews, download links and a
Save as Template shortcut, linked from the Assembly tools with `_meta.ui.resourceUri`.
- `plugin.json`, `mcp.json` and `.codex-plugin/plugin.json` describe the ChatGPT and Codex plugin.
- Hosted mode serves JSON responses and turns an upstream rejection of the forwarded token into
HTTP 401 (`invalid_token`) or 403 (`insufficient_scope` with the tool's scopes), so OAuth clients
refresh or re-scope instead of retrying a dead token.
- Request bodies are capped (1 MiB hosted, 10 MiB self-hosted, `maxRequestBodyBytes`) and larger
ones get HTTP 413 without being buffered. URL inputs the server downloads are capped
(`maxUrlDownloadBytes`, `urlDownloadTimeoutMs`), and hosted tokens are checked before downloading.
- Hosted mode also challenges bare `GET /mcp` probes (Codex discovers OAuth from them); CORS now
allows `Mcp-Protocol-Version` so browser hosts can connect.
- Self-hosted servers sign with `TRANSLOADIT_SIGNATURE_ALGORITHM` (`sha1`, `sha256` or `sha384`),
so Console keys that require `sha256` work; mismatches return an actionable
`mcp_invalid_signature` hint.
- The widget speaks the MCP Apps `2026-01-26` handshake (`appInfo`), shows failed tool calls, and
allows `https://*.r2.dev` result URLs; `TRANSLOADIT_MCP_RESULT_DOMAINS` overrides its CSP.

### Patch Changes

- Updated dependencies [8b0c308]
- @transloadit/node@5.2.0

## 0.4.2

### Patch Changes
Expand Down
4 changes: 2 additions & 2 deletions packages/mcp-server/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@transloadit/mcp-server",
"version": "0.4.2",
"version": "0.5.0",
"description": "Transloadit MCP server",
"keywords": [
"mcp",
Expand Down Expand Up @@ -62,7 +62,7 @@
},
"dependencies": {
"@modelcontextprotocol/sdk": "^1.29.0",
"@transloadit/node": "^5.1.0",
"@transloadit/node": "^5.2.0",
"@transloadit/sev-logger": "^0.1.9",
"express": "^5.2.1",
"prom-client": "^15.1.3",
Expand Down
16 changes: 16 additions & 0 deletions packages/node/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,21 @@
# @transloadit/node

## 5.2.0

### Minor Changes

- 8b0c308: Add an `extraHeaders` client option so trusted relays such as the hosted MCP service can send a
fixed header (`Transloadit-Mcp-Upstream`) with every API request next to a forwarded bearer token.
Like `Authorization`, these headers are dropped when a redirect leaves the API origin.

`listTemplates()` also accepts `fields`, for API2 columns such as `account_id` that the default
Template list omits.

`prepareInputFiles()` accepts `maxUrlDownloadBytes` (a total for the call) and `urlDownloadTimeoutMs`
(one deadline per download, redirects included) to bound URL downloads and `beforeUrlDownload` to vouch for a requester before a file is fetched locally; its
download errors name only a URL's origin and path, never presigned query parameters.
`createAssembly()` accepts `onAssemblyCreated`, called once API2 accepted the creation request.

## 5.1.0

### Minor Changes
Expand Down
2 changes: 1 addition & 1 deletion packages/node/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@transloadit/node",
"version": "5.1.0",
"version": "5.2.0",
"description": "Node.js SDK for Transloadit",
"homepage": "https://github.com/transloadit/node-sdk/tree/main/packages/node",
"bugs": {
Expand Down
2 changes: 1 addition & 1 deletion packages/transloadit/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "transloadit",
"version": "5.1.0",
"version": "5.2.0",
"description": "Node.js SDK for Transloadit",
"homepage": "https://github.com/transloadit/node-sdk/tree/main/packages/node",
"bugs": {
Expand Down
4 changes: 2 additions & 2 deletions yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -1607,7 +1607,7 @@ __metadata:
resolution: "@transloadit/mcp-server@workspace:packages/mcp-server"
dependencies:
"@modelcontextprotocol/sdk": "npm:^1.29.0"
"@transloadit/node": "npm:^5.1.0"
"@transloadit/node": "npm:^5.2.0"
"@transloadit/sev-logger": "npm:^0.1.9"
"@types/express": "npm:^5.0.6"
"@types/node": "npm:^25.8.0"
Expand All @@ -1621,7 +1621,7 @@ __metadata:
languageName: unknown
linkType: soft

"@transloadit/node@npm:^5.1.0, @transloadit/node@workspace:packages/node":
"@transloadit/node@npm:^5.2.0, @transloadit/node@workspace:packages/node":
version: 0.0.0-use.local
resolution: "@transloadit/node@workspace:packages/node"
dependencies:
Expand Down
Loading