Repository navigation
Hronaut + Kilo 7.7.3: protected global MCP setup and browser reconnect checks #14270
Hronom
started this conversation in
4. Show and tell
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hronaut maintainer here, sharing project-produced, AI-assisted test results rather than a compatibility claim from configuration alone.
The useful finding: in Kilo 7.7.3, saving a protected local MCP entry in project configuration did not make it usable. Kilo deliberately skips project MCP headers containing environment/file references. The same bearer-header connection worked in global configuration. Don't disable authentication or commit a literal token to work around this distinction.
Hronaut is a separate visible local browser with persistent workspaces. Using its actual 2.4.25 Linux Debian package, the check exercised Kilo's real marketplace installation API and connected MCP client:
The global entry produced by installation was:
{ "type": "remote", "url": "http://127.0.0.1:47812/mcp", "oauth": false, "headers": { "Authorization": "Bearer {env:HRONAUT_MCP_TOKEN}" } }That is an entry under global
mcp.hronaut, not a replacement configuration file. Hronaut must already be running on the same machine, and the Kilo process must receive the token securely.oauth: falseselects the bearer-header setup; it does not turn off Hronaut authentication.Full evidence, executed harness, result and native screenshot. The same 19 assertions passed in two fresh containers, including the expected project-scope exclusion. Earlier exploratory failures are documented too.
Limits: browser calls used Kilo's experimental MCP Apps endpoint—not a model-driven agent or normal permission-prompt test. This was isolated Linux/Xvfb with a synthetic page and container-only
--no-sandbox, not a desktop launch recommendation. Marketplace UI, ordinary credential handoff, other platforms and a full agent workflow remain unverified. No marketplace listing or Kilo endorsement is implied.For a personal evaluation, start with Hronaut setup. It is source-available under a proprietary license: one 10-day trial from the first agent tool call, then $4/month or $24/year per named user, up to three active devices. Binaries are unsigned; Mac builds are not Apple-notarized.
For people doing repeated localhost QA in Kilo: would keeping a visible browser tab across reconnects help your workflow, or is a disposable session sufficient? Public-safe examples are welcome; please don't share tokens or private app data.
All reactions