Community setup: use Baizhi Agent Toolkit through OpenHuman's user-configured MCP connection #6397
ct-jaryn
started this conversation in
Show and tell
Replies: 1 comment 1 reply
|
the write-only readback and secret-free re-save patterns you described are the right instincts, but storing the raw key in mcp.json still means it sits in plaintext on disk and can land in logs or model context if the server echoes tool inputs. one alternative worth knowing: tools like 1claw (disclosure: i work on it) store the key in an hsm-backed vault and give the agent a short-lived scoped token that only references a path, so the raw value never touches the config file or context window. that said, your current approach with explicit rotation and deletion docs is a solid baseline for a community guide, especially since you're testing the missing/placeholder/wrong-credential cases explicitly. |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What is it called?
Baizhi Agent Toolkit setup for OpenHuman
What does it do?
An optional, user-configured connection for web research tasks: discover the MCP tools available to your own Baizhi account, search for public pages, inspect selected URLs, and ask the agent for a summary with source links. The guide follows the current
mcp.jsonworkflow, preserves other installed servers, and explains write-only credential readback, rotation, explicit Header deletion, and uninstall. This is maintained as part of the Baizhi integration effort. Users supply their own key; service calls send tool inputs to the hosted service and may consume credits. The guide does not impose a hard spending limit. The hosted service backend is not included in the open-source guide, and this is not an OpenHuman endorsement or a request for a built-in preset.Where can people get it?
Community guide and reproducible validation
Kind
A setup or configuration
Tested against
OpenHuman source version
0.63.29, commiteb4fdc0f4f4a036d8ab7c12bd52f16128e4a6b5d, with its recorded recursive submodules; macOS ARM64, Rust1.96.1.Six focused native integration tests pass. They use OpenHuman's config/store implementation, the real tinymcp HTTP client, the product tool factory, and TinyAgents' actual tool-batch scheduler. A synthetic loopback MCP peer verifies initialize/list/call/session DELETE, missing/wrong/literal-placeholder credentials, secret-free readback and re-save, an empty Header object, rotation/deletion, partial Header updates, and preservation of another server.
The server and scheduled tool calls are fixtures. Test execution is restricted to loopback. These results do not cover a live Baizhi call, model-generated tool selection, the full OpenHuman session/approval middleware or
use_mcp_serverhandoff, desktop UI, or registry discovery; there were no production tool or model calls. The guide and scripts include the exact scope and source-bound receipt. The minimalmcpfeature profile is not a full desktop test suite.AI assistance: OpenAI Codex helped research the host implementation, write the guide and tests, and run the synthetic validation. No claim of manual UI acceptance is made.
All reactions