MCP servers, over streamable HTTP
A server is a row with a URL; its tools are discovered by a button and cached, then offered beside the built-in ones. Written by hand rather than taken from the reference SDK, because that SDK's transport does its own connecting -- and the one thing that must not be bypassed is check_url on every hop. Owning the transport is the point; the framing beside it is the small part. Sessions are per call: initialize, initialized, the call, a best-effort DELETE. Caching one wants an owner, a TTL, eviction, a lock and a shutdown hook, and the server may expire it under all of that anyway -- ToolContext is a session-free snapshot precisely so nothing in a tool holds live state. A server's names and descriptions reach the model as instructions and are bounded before they do; what it returns is escaped preformatted text, never markdown. Tools are namespaced per server, so two servers exposing "search" do not collide and neither shadows a built-in. Also: a round's calls now run together under a semaphore, results indexed so each tool turn stays paired with its call, and generation.status names what is running -- a remote tool is latency-bound, and a silent pause is what a hang looks like. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -47,6 +47,10 @@
|
||||
{{ icon("link", "icon--sm") }}
|
||||
<span class="nav-item__label">Tools</span>
|
||||
</a>
|
||||
<a class="nav-item {{ 'is-active' if section == 'mcp' }}" href="/admin/mcp">
|
||||
{{ icon("server", "icon--sm") }}
|
||||
<span class="nav-item__label">MCP servers</span>
|
||||
</a>
|
||||
<a class="nav-item {{ 'is-active' if section == 'prompts' }}" href="/admin/prompts">
|
||||
{{ icon("sparkle", "icon--sm") }}
|
||||
<span class="nav-item__label">Prompts</span>
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
{% from "_macros.html" import icon %}
|
||||
{#
|
||||
One MCP server in the list.
|
||||
|
||||
Swapped in place by the “Test & refresh” button, so this fragment has to be
|
||||
able to render on its own as well as inside the list.
|
||||
#}
|
||||
<div class="model-row {{ 'is-off' if not server.enabled }}" id="mcp-{{ server.id }}">
|
||||
<div class="model-row__main">
|
||||
<div class="model-row__title">
|
||||
<a class="model-row__name" href="/admin/mcp/{{ server.id }}/edit">{{ server.name }}</a>
|
||||
<span class="badge">{{ tool_count }} tool{{ '' if tool_count == 1 else 's' }}</span>
|
||||
{% if not server.enabled %}<span class="badge badge--danger">disabled</span>{% endif %}
|
||||
{% if not server.public %}<span class="badge">restricted</span>{% endif %}
|
||||
{% if server.allow_private %}<span class="badge">private network</span>{% endif %}
|
||||
{% if server.protocol_version %}
|
||||
<span class="badge badge--leaf">MCP {{ server.protocol_version }}</span>
|
||||
{% endif %}
|
||||
</div>
|
||||
<code class="model-row__id">{{ server.slug }} · {{ server.url }}</code>
|
||||
{% if message %}
|
||||
<p class="text-xs {{ 'danger' if message_kind == 'error' else 'faint' }}">{{ message }}</p>
|
||||
{% elif server.last_error %}
|
||||
<p class="text-xs danger">{{ server.last_error }}</p>
|
||||
{% endif %}
|
||||
</div>
|
||||
|
||||
<div class="model-row__actions">
|
||||
<button class="btn btn--sm" type="button"
|
||||
hx-post="/admin/mcp/{{ server.id }}/test"
|
||||
hx-target="#mcp-{{ server.id }}" hx-swap="outerHTML">
|
||||
{{ icon("refresh", "icon--sm") }} Test & refresh
|
||||
</button>
|
||||
<a class="btn btn--sm" href="/admin/mcp/{{ server.id }}/edit">Edit</a>
|
||||
</div>
|
||||
</div>
|
||||
@@ -0,0 +1,53 @@
|
||||
{% extends "admin/_layout.html" %}
|
||||
{% from "_macros.html" import icon %}
|
||||
{% set section = "mcp" %}
|
||||
|
||||
{% block title %}MCP servers - LLeMbas{% endblock %}
|
||||
{% block heading %}MCP servers{% endblock %}
|
||||
|
||||
{% block admin_content %}
|
||||
<p class="admin-lede">
|
||||
Remote servers speaking the Model Context Protocol over HTTP. Their tools are
|
||||
offered beside the built-in ones to models marked <strong>MCP servers</strong>.
|
||||
The list of tools is discovered and cached — press <strong>Test &
|
||||
refresh</strong> after adding one, and again whenever the server changes.
|
||||
</p>
|
||||
|
||||
<div class="alert">
|
||||
{{ icon("shield", "icon--sm") }}
|
||||
<span>
|
||||
A server's tool names and descriptions are sent to the model as
|
||||
instructions, and what it returns is read back as fact. Add servers you
|
||||
trust, the way you would a dependency.
|
||||
</span>
|
||||
</div>
|
||||
|
||||
{% if saved %}
|
||||
<div class="alert alert--success">{{ icon("check", "icon--sm") }} <span>{{ saved }}</span></div>
|
||||
{% endif %}
|
||||
|
||||
<div class="btn-row">
|
||||
<a class="btn btn--primary" href="/admin/mcp/new">
|
||||
{{ icon("plus", "icon--sm") }} Add a server
|
||||
</a>
|
||||
</div>
|
||||
|
||||
{% if not servers %}
|
||||
<div class="empty" style="padding: var(--sp-10) 0">
|
||||
{{ icon("server", "empty__mark") }}
|
||||
<p class="empty__text">
|
||||
No servers yet. You will need the URL of an MCP endpoint that speaks
|
||||
streamable HTTP — local ones launched as a subprocess are not supported.
|
||||
</p>
|
||||
</div>
|
||||
{% else %}
|
||||
|
||||
<div class="model-rows">
|
||||
{% for server in servers %}
|
||||
{% with tool_count = counts[server.id] %}
|
||||
{% include "admin/_mcp_row.html" %}
|
||||
{% endwith %}
|
||||
{% endfor %}
|
||||
</div>
|
||||
{% endif %}
|
||||
{% endblock %}
|
||||
@@ -0,0 +1,241 @@
|
||||
{% extends "admin/_layout.html" %}
|
||||
{% from "_macros.html" import icon %}
|
||||
{% set section = "mcp" %}
|
||||
|
||||
{% block title %}{{ "New server" if is_new else server.name }} - LLeMbas{% endblock %}
|
||||
{% block heading %}{{ "New MCP server" if is_new else server.name }}{% endblock %}
|
||||
|
||||
{% block admin_content %}
|
||||
<nav class="crumbs">
|
||||
<a class="crumbs__back" href="/admin/mcp">
|
||||
{{ icon("chevron-right", "icon--sm crumbs__icon") }} All servers
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
{% if error %}
|
||||
<div class="alert alert--error">{{ icon("warning", "icon--sm") }} <span>{{ error }}</span></div>
|
||||
{% endif %}
|
||||
|
||||
{% if server.last_error %}
|
||||
<div class="alert alert--error">
|
||||
{{ icon("warning", "icon--sm") }}
|
||||
<span>Last contacted unsuccessfully: {{ server.last_error }}</span>
|
||||
</div>
|
||||
{% endif %}
|
||||
|
||||
<form method="post" action="{{ '/admin/mcp' if is_new else '/admin/mcp/' ~ server.id }}"
|
||||
class="form-grid">
|
||||
|
||||
<section class="card">
|
||||
<h2 class="card__title">The server</h2>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="name">Name</label>
|
||||
<input class="input" id="name" name="name" value="{{ server.name }}" required
|
||||
maxlength="120" placeholder="GitHub">
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="slug">Identifier</label>
|
||||
<input class="input input--mono" id="slug" name="slug" value="{{ server.slug }}" required
|
||||
maxlength="24" pattern="[a-z0-9][a-z0-9_\-]*" placeholder="github">
|
||||
<p class="field__hint">
|
||||
Prefixed onto every tool name this server offers, so that two servers
|
||||
both exposing <code>search</code> do not collide.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="url">Endpoint URL</label>
|
||||
<input class="input input--mono" id="url" name="url" value="{{ server.url }}" required
|
||||
placeholder="https://mcp.example.com/mcp">
|
||||
<p class="field__hint">
|
||||
The streamable-HTTP endpoint itself, the one that accepts a POST. A
|
||||
server that answers with a redirect to somewhere else will be refused.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="headers">Extra headers</label>
|
||||
<textarea class="textarea input--mono" id="headers" name="headers" rows="3"
|
||||
spellcheck="false">{{ headers_text }}</textarea>
|
||||
<p class="field__hint">One <code>Name: value</code> per line.</p>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="timeout">Timeout (seconds)</label>
|
||||
<input class="input" id="timeout" name="timeout" value="{{ server.timeout }}"
|
||||
inputmode="numeric">
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="max_chars">Most characters to keep per call</label>
|
||||
<input class="input" id="max_chars" name="max_chars" value="{{ server.max_chars }}"
|
||||
inputmode="numeric">
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<section class="card">
|
||||
<h2 class="card__title">Credential</h2>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="secret_placement">How it is sent</label>
|
||||
<select class="select" id="secret_placement" name="secret_placement">
|
||||
{% for value, label in secret_placements %}
|
||||
<option value="{{ value }}" {{ 'selected' if value == server.secret_placement }}>
|
||||
{{ label }}
|
||||
</option>
|
||||
{% endfor %}
|
||||
</select>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="secret_name">Header or parameter name</label>
|
||||
<input class="input input--mono" id="secret_name" name="secret_name"
|
||||
value="{{ server.secret_name }}" maxlength="120">
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="secret">Secret</label>
|
||||
<input class="input input--mono" id="secret" name="secret" type="password"
|
||||
autocomplete="off" placeholder="No secret set"
|
||||
value="{{ unchanged if server.secret_encrypted else '' }}">
|
||||
<p class="field__hint">
|
||||
{% if server.secret_encrypted %}
|
||||
Currently <code>{{ masked }}</code>. Leave the dots alone to keep it,
|
||||
or clear the field to remove it.
|
||||
{% else %}
|
||||
Encrypted at rest and never shown again.
|
||||
{% endif %}
|
||||
</p>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
{% if tools %}
|
||||
<section class="card">
|
||||
<h2 class="card__title">Tools it offers</h2>
|
||||
<p class="field__hint">
|
||||
Discovered at the last refresh. Untick one to withhold it — a tool this
|
||||
server adds later is offered by default.
|
||||
</p>
|
||||
|
||||
<input type="hidden" name="tool_choices" value="1">
|
||||
<div class="checkbox-row checkbox-row--stacked">
|
||||
{% for tool in tools %}
|
||||
<label class="checkbox">
|
||||
<input type="hidden" name="tool_names" value="{{ tool.name }}">
|
||||
<input type="checkbox" name="tool_names_on" value="{{ tool.name }}"
|
||||
{{ 'checked' if tool.on }}>
|
||||
<span>
|
||||
<code>{{ tool.offer_name or tool.name }}</code>
|
||||
{% if tool.offer_name and tool.offer_name != tool.name %}
|
||||
<span class="faint text-xs">({{ tool.name }} on the server)</span>
|
||||
{% endif %}
|
||||
{% if tool.description %}
|
||||
<br><span class="faint text-xs">{{ tool.description }}</span>
|
||||
{% endif %}
|
||||
</span>
|
||||
</label>
|
||||
{% endfor %}
|
||||
</div>
|
||||
</section>
|
||||
{% elif not is_new %}
|
||||
<section class="card">
|
||||
<h2 class="card__title">Tools it offers</h2>
|
||||
<p class="field__hint">
|
||||
Nothing discovered yet. Save, then press <strong>Test & refresh</strong>
|
||||
on the <a href="/admin/mcp">list</a>.
|
||||
</p>
|
||||
</section>
|
||||
{% endif %}
|
||||
|
||||
<section class="card">
|
||||
<h2 class="card__title">Guidance</h2>
|
||||
|
||||
<div class="field">
|
||||
<textarea class="textarea" name="guidance" rows="4"
|
||||
placeholder="- Use the GitHub tools for anything about our repositories."
|
||||
>{{ server.guidance }}</textarea>
|
||||
<p class="field__hint">
|
||||
Added to the system message whenever any tool from this server is
|
||||
offered. One piece of guidance for the server, not one per tool —
|
||||
the tools carry their own descriptions.
|
||||
{% if prompt_overridden %}
|
||||
<br><strong>Someone has overridden this wording under
|
||||
<a href="/admin/prompts">Prompts</a></strong> — that is what the model
|
||||
sees, not this.
|
||||
{% endif %}
|
||||
</p>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<section class="card">
|
||||
<h2 class="card__title">Availability</h2>
|
||||
|
||||
<div class="field">
|
||||
<div class="checkbox-row">
|
||||
<label class="checkbox">
|
||||
<input type="checkbox" name="enabled" value="true" {{ 'checked' if server.enabled }}>
|
||||
<span>Enabled — offered in chats</span>
|
||||
</label>
|
||||
<label class="checkbox">
|
||||
<input type="checkbox" name="allow_private" value="true"
|
||||
{{ 'checked' if server.allow_private }}>
|
||||
<span>May reach private and loopback addresses</span>
|
||||
</label>
|
||||
</div>
|
||||
<p class="field__hint">
|
||||
Tick the second only for a server on your own network. It is what stops
|
||||
this being aimed at LLeMbas itself, a router, or a metadata endpoint.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label class="checkbox">
|
||||
<input type="checkbox" name="public" value="true" {{ 'checked' if server.public }}>
|
||||
<span>Available to everyone</span>
|
||||
</label>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<span class="field__label">Groups with access</span>
|
||||
{% if groups %}
|
||||
<div class="checkbox-row">
|
||||
{% for group in groups %}
|
||||
<label class="checkbox">
|
||||
<input type="checkbox" name="group_ids" value="{{ group.id }}"
|
||||
{{ 'checked' if group.id in selected_groups }}>
|
||||
<span>{{ group.name }}</span>
|
||||
</label>
|
||||
{% endfor %}
|
||||
</div>
|
||||
<p class="field__hint">Ignored while the server is available to everyone.</p>
|
||||
{% else %}
|
||||
<p class="field__hint">
|
||||
No groups yet — <a href="/admin/groups">create one</a> to restrict access.
|
||||
</p>
|
||||
{% endif %}
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label class="field__label" for="position">Position</label>
|
||||
<input class="input" id="position" name="position" value="{{ server.position }}"
|
||||
inputmode="numeric">
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<div class="btn-row">
|
||||
<button class="btn btn--primary" type="submit">
|
||||
{{ "Add server" if is_new else "Save changes" }}
|
||||
</button>
|
||||
<a class="btn btn--ghost" href="/admin/mcp">Back to all servers</a>
|
||||
{% if not is_new %}
|
||||
<button class="btn btn--danger" type="submit" formnovalidate
|
||||
formaction="/admin/mcp/{{ server.id }}/delete"
|
||||
data-confirm-button="Delete the server “{{ server.name }}”? Chats that used its tools keep their transcripts.">
|
||||
Delete
|
||||
</button>
|
||||
{% endif %}
|
||||
</div>
|
||||
</form>
|
||||
{% endblock %}
|
||||
Reference in New Issue
Block a user