v0.24.2
connectorAccess can now grant individual tools, and a deployment can declare
named pools served at /mcp/<pool>. Nothing changes for a deployment that
returns "all" or connector ids and declares no pools.
Added
-
Named tool pools at
/mcp/<pool>.ConnectaConfig.poolsdeclares a
slice of connector ids and exactconnector.tooladdresses plus agrant
predicate over the authenticated identity, denied by default. The endpoint
serves the pool intersected with the identity'sconnectorAccess, so it can
only narrow. An undeclared name, a refusing grant, and a throwing grant are
one identical 404. Misdeclared pools refuse to boot. Clerk's 401 challenge
and protected-resource metadata follow the pool path so OAuth discovery
matches the URL the client used. Ethos records the decision. -
Tool-level grants in
identity.connectorAccess. Entries may be a
connector id (every tool) or an exactconnector.tooladdress (that tool
only); grants are additive. The scoped registry view filters below the
catalog service, sosearch_tools,describe_tools,call_tool,
call_destructive_tool, a program'sconnecta.searchandconnecta.call,
and the connection UI all see the same list, and an ungranted tool fails as
unknown_toolexactly like an absent one. There is no wildcard: a remote
catalog that drifts cannot widen a grant. An address the catalog lacks is
unreachable and warned once per isolate. An unparseable entry refuses the
request with 403 rather than failing open.