Skip to content

v0.18.0: guided connector setup, encrypted connector variables, Splunk

Choose a tag to compare

@keysersoft keysersoft released this 03 Oct 13:07
3bd9f8b

Guided connector setup

Installing a connector now opens a setup page instead of a dialog: the fields are grouped (address, credentials, settings), with help and examples, and the credentials are checked against the API before anything is saved. OAuth connectors end with "Save and sign in", and the last screen shows a sample of real data (#834).

  • Every connector has a status: ready, needs input (a variable is still empty) or needs authorization. Connectors that are not ready are no longer offered to the AI client, which used to call them and get errors nobody could fix from the chat; the connector list says what is missing.
  • From the AI client, admins and editors can find and install connectors through a built-in "AnythingMCP Setup" connector. Secrets and sign-ins never go through the chat: the client gets a one-time link (30 minutes, single use, only for you) that opens the setup page.

Security

Self-hosted instances should update.

  • Connector variables are encrypted at rest. connectors.env_vars holds API keys, passwords and tokens and was stored in clear; it is now encrypted with your ENCRYPTION_KEY, like the auth settings already were. Existing rows are encrypted once at start (#837).
  • Connector OAuth is completed only by the person who started it. The callback used to exchange the code for whoever arrived with the state, so a consent link sent to someone else could hand over that person's provider tokens. Pending authorizations are also stored in the database now, so a restart or deploy in the middle no longer loses them (#832).
  • Credential fields in the install form and the connector editor opt out of browser and password-manager autofill, which had filled an Odoo API key with the user's AnythingMCP password (#840).

Everyone

  • Adapters for a vendor's own MCP server. A catalog adapter can bridge an official MCP server: at install AnythingMCP asks that server for its tools, so you get exactly what your version offers. First one: Splunk, over Splunk's MCP Server app (#830).
  • Rate limits are respected: a 429 gets at most one more try, after Retry-After when it is short, instead of three quick retries (#831).
  • Errors say what to do: a missing variable or an unauthorized connector comes with the link to fix it, an unknown host reads "Host not found", and JSON-RPC errors returned with HTTP 200 are treated as errors (#831, #836).
  • On iOS the verification code from the email is offered above the keyboard, and the code is in the email subject (#838).

Connectors

  • Catalog audit: every adapter added in #642 was checked against the vendor's real API. Fixed for all calls: OTTO Market, Clockodo, Quipu, Zalando, Papershift, Paperless-ngx, DocuWare, TimeTac, Matrix42, JTL-Wawi, Propstack, AFAS Profit; fixed in some tools: Sellsy, sevdesk (customers were created as suppliers), eBay, Zabbix, Axonaut, Aruba, bexio and 22 more. Six adapters whose APIs could not be reached are no longer listed (#833).
  • New Odoo (JSON-RPC) adapter for Odoo 14 to 18 (#833).
  • BuchhaltungsButler: real endpoints and the required filters, verified on a live account (#829).
  • Lexware Office: vouchers by type (get_voucher, get_sales_document), better voucher filters, and contacts created without empty fields (#836).

Cloud

  • After approving Claude into an empty workspace, a page explains how to add an app before handing back to the client (#834).
  • Reminder emails go to workspaces that still have no connector, two hours after an AI client was connected to an empty one (#831).

Self-hosted

  • Two additive database migrations (connector_oauth_attempts, connector_setup_links) run on start, as usual.
  • At the first start, connector variables are encrypted with ENCRYPTION_KEY (the log says Encrypted the variables of N connectors). Keep the key: without it the variables read as empty. To roll back to an earlier version, set ENV_VARS_AT_REST=plaintext and restart once first; see docs/operations/backup-restore.md.
  • Raw SQL on connectors.env_vars now sees ciphertext; use the API.
  • An OAuth authorization started before the update and finished after it fails as expired; start it again.

Docker: helpcodeai/anythingmcp:v0.18.0