Skip to content

docs(connect): document the Codex apikey query credential limitation - #1534

Merged
Dumbris merged 2 commits into
mainfrom
fix/issues-w5b9-docs-features-connect-clients
Oct 6, 2026
Merged

Dumbris merged 2 commits into
mainfrom
fix/issues-w5b9-docs-features-connect-clients

Conversation

@Dumbris

@Dumbris Dumbris commented Oct 6, 2026

Copy link
Copy Markdown
Member

Summary

Documents the limitation that the Codex client entry written by the Connect wizard carries its credential as a ?apikey= query parameter, and that this credential is written regardless of require_mcp_auth.

  • Final done-check residuals (Spec 108/109 UX effort) #1466: Root cause: Codex's config format cannot send a custom header the way other clients' entries do, so Connect falls back to the query-string credential, which was undocumented. Change: added a section to docs/features/connect-clients.md describing the limitation, the exposure (URLs may be logged/echoed), and that the credential is written even when require_mcp_auth is off. Test: docs-only change, no code test applicable.

Skipped items

None.

Review Status

clean after 2 round(s), unresolved findings []

Refs #1466

…(refs #1466)

Codex entries carry the credential as ?apikey= when require_mcp_auth is on.
Document the plain-text exposure, agent-token mitigation and the
env_http_headers manual alternative. Codex docs now support http_headers /
env_http_headers, so the clients.go comment claiming a literal header is
impossible is stale; follow-up: write an X-API-Key header for Codex.
@Dumbris
Dumbris enabled auto-merge (squash) October 6, 2026 10:13
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying mcpproxy-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: 8276200
Status: ✅  Deploy successful!
Preview URL: https://020df614.mcpproxy-docs.pages.dev
Branch Preview URL: https://fix-issues-w5b9-docs-feature.mcpproxy-docs.pages.dev

View logs

@Dumbris
Dumbris merged commit 936edd0 into main Oct 6, 2026
44 checks passed
@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants