Skip to content

[Tracking] MCP connector: reach docs.plus from Claude and ChatGPT #230

Description

@HMarzban

Goal

A person inside Claude or ChatGPT connects to docs.plus. They sign in as themselves and work with their own documents and heading chats.

Status

Live since 2026-09-28 at https://prodback.docs.plus/api/mcp. The server is stateless and builds one MCP server per request. It runs on @modelcontextprotocol/server 2.0.0, pinned exactly.

Nine tools: find_documents, get_outline, read_document, create_document, append_to_document, replace_section, list_chat_rooms, read_chat_thread and post_chat_message.

Guide: docs/mcp/README.md. Reference: docs/mcp/reference.md and apps/hocuspocus.server/API.md §MCP connector.

Done

Task Issue Shipped in
Turn on the Supabase OAuth server #223 1b109b553, plus the production toggle
Caller-side outline (get_outline) #224 c68d53947
Consent page at /oauth/consent #225 98c2c488a, e752b15aa
Stateless /api/mcp with the read tools #226 c68d53947
Tool errors name the field and a next step #227 c68d53947
Chat tools #228 c68d53947
Fix the lost content write, then the write tools #229 f2682d675, c68d53947
create_document none 0dacee392
Usage counts and the admin /mcp page none 89f3a6f8a, 331434e3d
Connected apps tab in Settings none 76cfed29e, bbcf499be, 0549f0fd5

Next

  1. Test the MCP connector in three AI apps, then finish its connect guide #357: test the connector in claude.ai, ChatGPT and Claude Code, then finish the guide.
  2. Build work continues in [Tracking] Editor next steps: Slash hardening, heading links, and MCP reads #328. Connected-app rows there: Refuse a connected-app rewrite of a section that holds media #329, Store links from Markdown import and connected-app writes on the hyperlink mark #335, Mark MCP chat posts with a fixed connected-app metadata key #336, Tell self-hosters to set APP_URL, because email and connected-app links use it #337, Add links and Comment quotes to MCP reads #343, Show a "via connected app" label on chat posts from a connected app #344, Add a get_changes MCP tool for changes since Last left #345, Cap the get_outline and list_chat_rooms output #380 and Test parallel connected-app writes across two collab replicas #381. Gated rows: Keep unchanged blocks when a connected app replaces a section #347, Let a connected app anchor a chat post to a quoted sentence #351 and Let an owner preview a connected app's edit before it applies #352. Ruling: RFC: should a burst of connected-app writes wait instead of failing busy? #360.

#329 comes first. Today a rewrite of a section that holds a picture deletes the picture.

Held, needs a ruling

The evidence is the admin /mcp usage page, not argument.

Decision Issue Answer after
Reach Claude Code as well #231 The #357 Claude Code run
Submit to the Anthropic directory #232 Real usage on /mcp
Ship a UI widget, or stay text-only #237 A text tool that people find awkward. A diff view belongs to #352

Alongside, not blocking

Task Issue
Name the two section rules apart in API.md #234
Correct three stale API documentation claims #235
Let the dev compose file scale rest-api (only if someone needs it) #236
Mention-driven demo agent in document-swarm #233

Shipped rules

  • A connected app writes and posts only in documents the caller owns. Maintainer ruling, 2026-09-23.
  • Trust follows the exact redirect URI (apps/webapp/src/utils/appTrust.ts), never the client name.
  • The connector asks for openid, email and profile only (0c2145dfc).
  • A connected-app token is refused outside /api/mcp (e4113fd9d, 24a4f68c2).
  • A chat post removes every @, so it sends no notification.
  • A read stops at 100,000 characters (MAX_READ_CHARS) and says so.

Do not build

Known gap

The server cannot check RFC 8707 audience today. Supabase always sets aud to authenticated and does not put the resource into the token (supabase/auth#2610). So the server requires the client_id claim, which only the OAuth flow mints. Check again when supabase/auth#2610 ships.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions