Skip to content

v0.8.0 — plugin manifest HTTP transport

Choose a tag to compare

@may-keepur may-keepur released this 18 May 09:55
· 122 commits to main since this release
af7dd66

Highlights

Plugin manifest now supports remote HTTP MCP servers (#273, KPR-236).

Until now, every plugin MCP server had to be a Node stdio subprocess with a compiled entry. With v0.8.0, a plugin.yaml entry can declare transport: http and point at any remote MCP server — the engine handles per-request authentication with the same per-agent key it already plumbs into stdio plugins as TASK_LEDGER_API_KEY. No new credential ceremony, no local shim.

mcp-servers:
  purchasing:
    transport: http
    url: https://app.example.com/mcp/purchasing
    description: "Purchasing operations — what's due, what's blocked"
    auth:
      type: api-key            # or "bearer"
      header: x-api-key        # optional; defaults: x-api-key (api-key) / Authorization (bearer)
      key-source: agentApiKey  # resolves config.taskLedger.agentKeys[agentId] ?? apiKey

What this unlocks

Operator plugins can register against remote MCP servers — including domain-specific operation-level MCPs built on the operator's own infrastructure — without writing a stdio wrapper. The motivating consumer is @keepur/hive-plugin-dodi consuming dodi's new /mcp/purchasing capability server directly.

Backward compatibility

Fully backward-compatible. Existing manifests work unchanged — transport defaults to "stdio" and every existing field is preserved. No DB migration. No config change required for any deployed instance.

Other changes

  • Defensive plugin loading: a single malformed plugin manifest now skips with a logged error instead of crashing the loader. One bad plugin no longer takes down the engine startup.
  • Parse-time validation for http entries: missing url, missing auth, empty auth.header, unknown auth.type, and unknown keySource are all rejected at load time with clear errors.
  • instance-capabilities honesty: http servers are classified as configured only when at least one per-agent key (or the global apiKey) is set — prevents the agent's toolkit section from advertising a server the runtime will skip.

Migration notes

None required. Adopt the new transport: http shape in your plugin manifest when you want to point at a remote MCP server; otherwise no action needed.

Pull requests

  • #273 — KPR-236: plugin manifest HTTP transport
  • #277 — release: v0.8.0

Install

npm install @keepur/hive@0.8.0
# or
hive update --tag=v0.8.0