Releases: jestatsio/astra-db-plugin
Release list
v2.1.0 — JEStats branding and safer authentication
JEStats Astra DB Plugin 2.1.0 is an unofficial Astra DB integration by JEStats, with CLI profile reuse, safer setup, and stronger hosted OAuth protection.
Fixed
- The Claude Code manifest no longer lists
hooks/hooks.json. Claude Code loads that file by default, so the extra entry registered it twice. - The Claude Code manifest sets
documentationUrl,supportUrl, andprivacyPolicyUrl, so the plugin directory links to this repository's README, issues, and privacy policy. - Brand the unofficial Astra DB plugin as JEStats Astra DB Plugin, with original artwork and the current jestats.io palette across manifests, documentation, CLI help, interactive views, and hosted consent.
- Prepare repository links and installer sources for
jestatsio/astra-db-plugin, retaining theastra-dbplugin ID,astra-db-marketplacemarketplace ID, and@erichare/astra-mcpnpm package. - Prepare the MCP Registry identity
io.github.jestatsio/astra-mcpfor the transferred repository's GitHub OIDC publisher. - Document existing Astra CLI profile reuse, make token entry optional in the Desktop bundle, and clarify that hosted OAuth still requires an Astra application token.
- Correct privacy disclosures for HTML export cleanup and shared hosted replay storage; add a full UX assessment and store submission draft.
- Show the hosted consent warning when Allow writes is selected.
- Add
login --profile/--astrarc: save connection selectors without copying the CLI token, honor profile rotation without restart, and pair tokens with their Astra control-plane environment. Add--astra-envfor manual token setup and clear missing-profile diagnostics. - Preserve existing credential, read-only, disabled, and permission settings when reinstalling Cursor, VS Code, and Bob.
- Require working shared replay storage for hosted OAuth code/refresh grants, consume authorization codes once, reject alternate sealed-token encodings, and block private IPv4-mapped/IPv6 metadata destinations. Self-hosters must configure Redis before upgrading; existing access tokens retain their normal expiry.
- Correct delete tool idempotency hints, include vendored-content NOTICE in npm/Desktop bundles, and publish release checksums.
- Use npm staged publishing with maintainer approval and exact package/registry readback; registry failures now block GitHub release publication.
Install or upgrade:
npx -y @erichare/astra-mcp@2.1.0 initThe attached Desktop .mcpb and IBM Bob bundle include NOTICE; verify downloads with SHA256SUMS. Hosted OAuth still requires an Astra application token and shared Redis replay storage. This release does not add delegated Astra account OAuth.
MCP Registry migration pending: the new io.github.jestatsio/astra-mcp listing is waiting for the old io.github.erichare/astra-mcp@2.0.0 listing to be retired, so its hosted URL can be reused. npm and these GitHub downloads are available.
Validation: merged-main CI passed, including 178 server tests and 35 repository tests. The public npm package passed read-only connectivity smoke tests through both MCP protocol paths. npm provenance references 0102d6d55c1f4f6eace6a770009085cf7f624941; this GitHub tag includes the later Claude directory fixes at merged commit da4660c1027afe120da093285e4ebd9e7e2760b8. The rebuilt CLI and bundled assets match the published npm package byte for byte.
v2.0.0
2.0: one first-party MCP server, one source tree for every agent, and a one-command install. This is a breaking release; see Upgrading from 1.x below.
Highlights
-
npx -y @erichare/astra-mcp initconfigures Claude Code, Codex, Cursor, VS Code, Windsurf, Gemini CLI, Claude Desktop, and IBM Bob.loginconnects a database from a hidden prompt and writes a git-ignored.env, and credentials are re-read on every call, so there's no restart.doctordiagnoses anduninstallreverses.install.shandinstall.ps1are thin wrappers. -
One MCP server,
@erichare/astra-mcp, on MCP SDK v2, serving both the 2025 and 2026-07-28 protocols. It replaces@datastax/astra-db-mcpand the read-only widgets server with 18 tools:- connection status, databases, overview, collection and table schemas
find, and vector and hybrid search by text, vector, or "more like this", on collections and tables- count, distinct values, vectorize providers
- offline
code_examples - insert, update, delete, and create collection, table, and index, plus drop
Any database is reachable through the
databaseargument. Errors are structured, with hints. There are resources and prompts with completions. -
Guarded writes. Destructive operations are confirmed by the user, through elicitation where the client supports it, or else an explicit
confirmafter approval. There's also a read-only mode. -
A single MCP Apps view shell (ext-apps 2): overview, collection, table, explorer, and similarity views, with drill-downs that keep a Back history, host theming, keyboard support, and live model-context updates.
-
Hosted server: the full tool set, writes opt-in per connection, and modernized OAuth (Client ID Metadata Documents with DNS-rebinding-safe fetching,
iss, audience-bound tokens, rotating refresh tokens, key rotation). With an optional Redis store (Vercel KV / Upstash), refresh tokens are single-use and a replay revokes the chain. Endpoints are restricted to Astra's Data API hosts. -
Skills everywhere. Commands and agents became skills:
setup,doctor,data-model-review, theoverview/collection/explore/similarshortcuts, and thereviewer,data-modeler, andmigration-helperpersonas. The examples readASTRA_DB_*from the environment and have per-language indexes. -
Hooks rewritten in Node. The credential guard inspects only new content and allows a git-ignored
.env, and a session hook adds one line of connection context. -
Distribution: npm (trusted publishing with provenance from the next release on), the MCP Registry, a Claude Desktop
.mcpb, an IBM Bob zip, Smithery, and Docker. Every piece is released from one workflow. -
Evals: MCP-mocked
claude plugin evalcases for vector search, filtered find, destructive confirmation, pasted tokens, and Go code.
Fixes
- Widget drill-downs render the result's own view instead of the originating template.
- "More like this" finds documents with typed (
uuid/objectId) ids. - The overview no longer stops silently at 10 keyspaces, and a failing keyspace reports its own error.
- IBM Bob gets valid mode groups and the widgets skill.
$ARGUMENTSno longer leaks into Codex skills.- The credential hook no longer blocks the edit that removes a leaked token.
- The skill and the plugin agree on environment variable names.
Upgrading from 1.x
- Run
npx -y @erichare/astra-mcp init. It replacesastra-widgetsand@datastax/astra-db-mcpentries in the configs it manages. - Claude Code: update the plugin (
claude plugin marketplace update astra-db-marketplace, thenclaude plugin update astra-db). The two servers become one,astra-db, so tools are nowmcp__plugin_astra-db_astra-db__*. Token, endpoint, keyspace, and read-only are plugin settings./astra-db:setup,/astra-db:doctor, and/astra-db:data-model-reviewkeep their names.sync-checkis gone, and the agents are now thereviewer,data-modeler, andmigration-helperskills. - Tool renames:
collection_card→describe_collection,similarity_search→vector_search,explore_collection→find.structuredContent.widgetis nowview. - Codex: the plugin moved from
codex/to the repository root. Update the marketplace and reinstallastra-db@astra-db-marketplace. - IBM Bob: the committed
.bob/bundle is gone. Runnpx -y @erichare/astra-mcp init --agents bob(add--projectfor a project bundle) or useastra-db-bob.zipfrom the release. Command and mode names are unchanged. - Environment:
ASTRA_DB_APPLICATION_TOKENandASTRA_DB_API_ENDPOINTas before, plus the optionalASTRA_DB_KEYSPACEandASTRA_DB_NAME.APPLICATION_TOKEN,API_ENDPOINT, and the Astra CLI'sASTRA_DB_TOKENare accepted as aliases. install.shnow forwardsinitoptions (sh -s -- --agents cursor --yes) instead of taking a target (bob,claude,codex,skills-dir).- Self-hosted server: the secret is now
ASTRA_MCP_AUTH_SECRET(ASTRA_WIDGETS_AUTH_SECRETis still read), and turn on Vercel's Include files outside the root directory. Existing connections keep working read-only; reconnect to grant writes. - Skill content is vendored instead of synced weekly from upstream (see NOTICE).
v1.2.1 — widgets everywhere + OAuth for ChatGPT
Widgets, everywhere — plus OAuth for ChatGPT and claude.ai
Ask about a collection and get a widget, not a wall of text. 1.2 adds the astra-widgets MCP server and four views; 1.2.1 adds the OAuth flow that lets ChatGPT and claude.ai connectors use the hosted server.
![]() |
![]() |
![]() |
![]() |
Highlights
- Four widgets: database overview, collection card (full metadata + sample document), similarity results (ranked bars + constellation map,
$vectorizetext / by-document / hybrid queries), collection explorer (filters, field inventory, paging, click-to-drill). - Inline in Claude Code desktop (widget templates), Claude.ai / Claude Desktop / ChatGPT (MCP Apps UI); a self-contained HTML page on Codex CLI and IBM Bob.
- Commands
/astra-db:overview,/astra-db:collection,/astra-db:similar,/astra-db:explore+ a proactiveastra-widgetsskill; ported to Codex ($astra-*) and Bob (/astra-*). The server ships in every layout and MCP config;install.sh bobinstalls it. - Hosted server at
https://astra-widgets-mcp.vercel.app/mcpwith OAuth 2.1 (discovery, dynamic client registration, PKCE consent page, refresh) — tokens are encrypted blobs carrying your own Astra credentials, nothing stored. Raw bearer +X-Astra-Endpointstill works for scripts and Claude Desktop viamcp-remote.
Install
# Claude Code
claude plugin marketplace add erichare/astra-db-plugin && claude plugin install astra-db@astra-db-marketplace
# Codex
codex plugin marketplace add erichare/astra-db-plugin && codex plugin add astra-db@astra-db-marketplace
# IBM Bob (from your project root)
curl -fsSL https://raw.githubusercontent.com/erichare/astra-db-plugin/main/install.sh | bash -s -- bobChatGPT
Settings → Security and login → Developer mode → Plugins → + → URL https://astra-widgets-mcp.vercel.app/mcp → OAuth → connect with your Astra token + endpoint once.
Full details in CHANGELOG.md.
v1.2.0 — collection widgets
Elegant collection widgets
- Widgets. New
astra-widgetsMCP server (TypeScript, bundled atserver/dist/index.js, no npm publish) with four read-only tools —database_overview,collection_card,similarity_search,explore_collection— each returningstructuredContentplus an MCP Apps UI resource (ui://astra-widgets/*): collection card, similarity results (ranked bars + constellation map), collection explorer (filters, paging, click-to-drill), and database overview.emit: "html_file"writes a self-contained page for harnesses without inline rendering. - New
astra-widgetsskill with a design spec and Claude Code desktop widget templates; new commands/astra-db:overview,/astra-db:collection,/astra-db:similar,/astra-db:explore(ported to Codex as$astra-*skills and to Bob as/astra-*commands). The server ships in every layout (codex/server,.bob/server) and in all three MCP configs;install.sh bobinstalls it too. - Hosted entrypoint for ChatGPT at
https://astra-widgets-mcp.vercel.app/mcp(server/api/mcp.ts, streamable HTTP, bearer = Astra token, endpoint viaX-Astra-Endpointheader or?endpoint=). - CI builds and tests the server (vitest) and parity-checks the committed bundle.
See v1.2.1 for the OAuth follow-up and screenshots.
v1.1.0 — feature parity for IBM Bob and Codex
Feature parity for IBM Bob and Codex
- Feature parity across harnesses. IBM Bob now gets the full bundle:
/astra-setup,/astra-doctor,/astra-data-model-reviewslash commands, three custom modes (astra-reviewer,astra-data-modeler,astra-migration-helper) in.bob/custom_modes.yaml, the Astra DB MCP server in.bob/mcp.json, and a credential-hygiene rule. OpenAI Codex / ChatGPT gets the same commands and agents as$astra-*skills. - Codex installs headlessly:
codex plugin marketplace add erichare/astra-db-plugin && codex plugin add astra-db@astra-db-marketplace(alsoinstall.sh codex-plugin). The Codex plugin root is now the self-containedcodex/directory. install.sh bobinstalls the whole Bob bundle and merges safely with existing.bob/config; new--globalflag targets~/.bob/.- Credential-guard hook now also matches Codex's
apply_patchtool; SessionStart hook gains a status message. - Releases pick the semver level from the conventional commit (
feat→ minor).
v1.0.0
Initial release: astra-toolkit skill (synced from sl-at-ibm/astra-toolkit-skill @ aebf0d6), commands (/astra-db:setup, /astra-db:data-model-review, /astra-db:sync-check), agents (astra-reviewer, astra-data-modeler, astra-migration-helper), credential-guard + freshness hooks, bundled @datastax/astra-db-mcp, and layouts for Claude Code, Agent Skills harnesses (Codex), and IBM Bob.
Install (Claude Code):
/plugin marketplace add erichare/astra-db-plugin
/plugin install astra-db@astra-db-marketplace



