QONTO-WP-0003-T03: MCP client auth + shared multi-harness config snippet
Gate /mcp with a shared-secret bearer token (QONTO_ASSISTANT_MCP_TOKEN,
mcp_auth.py::BearerTokenAuthMiddleware, constant-time compare, REST
untouched) since no OIDC issuer exists in this fleet yet -- pointing
FastMCP's OAuth Protected Resource flow at a non-existent issuer would be
worse than not having it. This token is a service credential, never a bank
credential; per-actor identity stays the existing X-Actor-* convention.
Add docs/mcp-integration.md: tool catalog, the two-layer auth model (workload
auth today vs. deferred OIDC target), and one shared {"mcpServers": {...}}
client config snippet (url + headers) usable across Claude Code, Claude
Desktop, Cursor, and Codex/Grok-style harnesses.
Verified live using only that snippet: unauthenticated and wrong-token
requests get 401 before reaching any tool; a request built from the
snippet's URL + headers lists tools and calls qonto_org_summary
successfully against the fixture-backed server.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
e1e47ae304
commit
d2ffd372b5
9 changed files with 259 additions and 5 deletions
|
|
@ -162,6 +162,13 @@ PY
|
|||
Use `window_days=31` for a recent-activity view. Use `window_days=90` or `93`
|
||||
when recurring fixed-cost hints are required.
|
||||
|
||||
## MCP surface
|
||||
|
||||
Phase 2 mounts a streamable-HTTP MCP adapter at `/mcp` on this same process,
|
||||
sharing the policy kernel and audit layer above. See
|
||||
`docs/mcp-integration.md` for the tool catalog, the auth model
|
||||
(`QONTO_ASSISTANT_MCP_TOKEN`), and the shared client config snippet.
|
||||
|
||||
## CostRunRate refresh path
|
||||
|
||||
`binky-control` should consume `GET /v1/snapshot` and extract:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue