Files
ai-memory/docs/logo-dark.png
T
AkitaOnRailsandClaude Opus 4.7 3500c8d67d install-mcp: fix Codex schema — bearer_token, not [mcp_servers.X.headers]
Codex was prompting users to run `codex mcp login ai-memory` (the
OAuth fallback) on every startup because ai-memory was writing the
wrong config key for static-token auth.

## What we used to write (wrong)

  [mcp_servers.ai-memory]
  url = "..."

  [mcp_servers.ai-memory.headers]
  Authorization = "Bearer ..."

The `headers` key does not exist in Codex's MCP server schema
(verified against `openai/codex/codex-rs/config/src/mcp_types.rs`).
Codex silently ignored the sub-table, saw no recognised auth
mechanism, and fell back to OAuth — which then failed because
ai-memory's homelab MCP doesn't expose an OAuth endpoint.

## What we write now (correct)

  [mcp_servers.ai-memory]
  url = "..."
  bearer_token = "..."

Codex's HTTP-transport MCP entry recognises:

  - `bearer_token`          : literal token (what we now use)
  - `bearer_token_env_var`  : env-var name; requires the user to
                              export the var before starting codex
  - `http_headers`          : static custom headers (different key
                              than what we used to write)
  - `env_http_headers`      : env-var-backed custom headers
  - `oauth` / `oauth_resource` / `scopes` : OAuth flow

We use the literal `bearer_token` because we already have the token
in hand (passed via `--auth-token`) — embedding it directly avoids
the shell-profile-editing step required by env-var indirection.

The print-mode snippet (`install-mcp --client codex` without
--apply) also mentions `bearer_token_env_var` as an alternative
for users who don't want the literal in the file.

## Tests

  - `codex_apply_writes_block_form_tables` updated to assert the
    NEW key (`bearer_token = "..."`) AND that the OLD wrong key
    (`[mcp_servers.X.headers]`) is NOT emitted. Regression guard.
  - `auth_token_threaded_into_every_client` now expects Codex's
    `bearer_token = "<token>"` shape instead of the
    `Bearer <token>` header substring used by the other clients.

## Migration

Users who already have the old shape need either:
  - re-running `install-mcp --client codex --apply` (it overwrites)
  - manually editing config.toml to delete the
    `[mcp_servers.X.headers]` sub-table and add
    `bearer_token = "..."` to the server block

The session that uncovered this fixed the user's config in place
before this commit landed; the binary fix prevents the same trap
on fresh installs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-22 23:53:29 -03:00

1.5 MiB
1376x768px