From ba6a90720e6b501bdd6f391026739f0ac152a1e0 Mon Sep 17 00:00:00 2001 From: Harry Phan Date: Mon, 21 Sep 2026 13:03:16 +0700 Subject: [PATCH] docs(mcp): document login-pending.json in the README (WALM-647) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Credential Storage section named only credentials.json, so the second file the MCP writes into the same directory was undocumented — nothing said what it holds, that it is mode 0600, that it expires after 24 hours, or when it is cleared. Also adds the one missing line for MEMWAL_MCP_TRANSPORT, which until now was described only in docs/reference/environment-variables.md. --- packages/mcp/README.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/packages/mcp/README.md b/packages/mcp/README.md index 4a21e8584..730c08eeb 100644 --- a/packages/mcp/README.md +++ b/packages/mcp/README.md @@ -55,6 +55,8 @@ Use CLI flags or environment variables to override the default Walrus Memory end Enable verbose stderr logging with `MEMWAL_MCP_DEBUG=1`. +Set `MEMWAL_MCP_TRANSPORT=http` to dial the relayer's Streamable HTTP endpoint instead of the default SSE pair. Opt-in: reconnect replay is not transport-aware yet, so a write interrupted mid-send may be retried and duplicated. + ## Default Namespace By default the MCP tool schemas expose an optional `namespace` argument and the @@ -152,6 +154,16 @@ Credentials are stored locally in `~/.memwal/credentials.json`. To remove them: npx -y @mysten-incubation/memwal-mcp --logout ``` +A sign-in that is still in flight also writes `login-pending.json` beside that +file, in whichever directory `credentials.json` resolves to — `MEMWAL_CREDS_DIR` +moves both. It holds the delegate keypair minted for that sign-in, and it is +written before the browser can register the public half on-chain so an +interrupted login can be reclaimed instead of paid for a second time. Same +owner-only mode `0600` as `credentials.json`. + +It is removed once the sign-in completes, on `--logout`, and on a successful +recovery at the next start. A record older than 24 hours is discarded unread. + ## License Apache-2.0