mirror of
https://github.com/akitaonrails/ai-memory.git
synced 2026-10-02 03:24:46 +08:00
Codex was prompting users to run `codex mcp login ai-memory` (the
OAuth fallback) on every startup because ai-memory was writing the
wrong config key for static-token auth.
## What we used to write (wrong)
[mcp_servers.ai-memory]
url = "..."
[mcp_servers.ai-memory.headers]
Authorization = "Bearer ..."
The `headers` key does not exist in Codex's MCP server schema
(verified against `openai/codex/codex-rs/config/src/mcp_types.rs`).
Codex silently ignored the sub-table, saw no recognised auth
mechanism, and fell back to OAuth — which then failed because
ai-memory's homelab MCP doesn't expose an OAuth endpoint.
## What we write now (correct)
[mcp_servers.ai-memory]
url = "..."
bearer_token = "..."
Codex's HTTP-transport MCP entry recognises:
- `bearer_token` : literal token (what we now use)
- `bearer_token_env_var` : env-var name; requires the user to
export the var before starting codex
- `http_headers` : static custom headers (different key
than what we used to write)
- `env_http_headers` : env-var-backed custom headers
- `oauth` / `oauth_resource` / `scopes` : OAuth flow
We use the literal `bearer_token` because we already have the token
in hand (passed via `--auth-token`) — embedding it directly avoids
the shell-profile-editing step required by env-var indirection.
The print-mode snippet (`install-mcp --client codex` without
--apply) also mentions `bearer_token_env_var` as an alternative
for users who don't want the literal in the file.
## Tests
- `codex_apply_writes_block_form_tables` updated to assert the
NEW key (`bearer_token = "..."`) AND that the OLD wrong key
(`[mcp_servers.X.headers]`) is NOT emitted. Regression guard.
- `auth_token_threaded_into_every_client` now expects Codex's
`bearer_token = "<token>"` shape instead of the
`Bearer <token>` header substring used by the other clients.
## Migration
Users who already have the old shape need either:
- re-running `install-mcp --client codex --apply` (it overwrites)
- manually editing config.toml to delete the
`[mcp_servers.X.headers]` sub-table and add
`bearer_token = "..."` to the server block
The session that uncovered this fixed the user's config in place
before this commit landed; the binary fix prevents the same trap
on fresh installs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1.5 MiB
1376x768px
1.5 MiB
1376x768px