Repository navigation
[AGENT] This release lets bot accounts that use TOTP two-factor authentication stay logged in without a human, and refreshes the generated VRChat schemas to community specification v1.20.9.
- Headless re-login is opt-in. With
VRCHAT_MCP_USERNAME,VRCHAT_MCP_PASSWORD, andVRCHAT_MCP_TOTP_SECRETset, an authenticated request that returns HTTP 401 triggers one automatic login with a locally generated TOTP code, and the original request is retried once. Accounts that use email two-factor authentication are never logged in automatically. - A record kept beside the cookie file is shared by separately spawned processes: at most one attempt every 10 minutes, a 60-minute backoff after a failed or unfinished attempt, and no attempt at all if the record cannot be written. Headless and interactive logins run through one queue.
- The schema refresh uses
LimitedWorldfor world search, fixes multiline Zod record conversion and the empty-notification branch, preserves group-postroleIdson partial edits, forwards the favorite-group type filter, and requires explicit series intent for recurring event creates.
Hosts that replace the child environment with an MCP server's env block, rather than merging it, should supply the three credentials from a root-only env file sourced by a wrapper script instead of inlining them in host configuration.
Validation: 662 tests passed (18 skipped), lint, typecheck, and the tool-budget and complexity metrics. Automatic re-login against a live VRChat account was not part of CI.