Skip to content

feat(mcp): serve OpenAI apps domain verification challenge - #1725

Merged
ctkm-aelf merged 1 commit into
rollup-2026-10-01-ctkm-1from
fix/openai-apps-domain-verification
Oct 1, 2026
Merged

ctkm-aelf merged 1 commit into
rollup-2026-10-01-ctkm-1from
fix/openai-apps-domain-verification

Conversation

@ctkm-aelf

Copy link
Copy Markdown
Collaborator

Why

The OpenAI plugin portal shows Domain not verified for the NyxID MCP server. It verifies the MCP host (nyx-api.chrono-ai.fun) by fetching /.well-known/openai-apps-challenge and expecting the plugin's verification token as bare plain text. That path returns 404 today.

Change

  • New public route GET /.well-known/openai-apps-challenge on the existing /.well-known router. It returns the token as text/plain from the new optional OPENAI_APPS_CHALLENGE_TOKEN env var, and 404 when the variable is unset.
  • AppConfig.openai_apps_challenge_token (trimmed; empty counts as unset), added to every config literal; documented in docs/ENV.md.

Compatibility

Purely additive. The OIDC, OAuth AS, protected-resource and JWKS routes and handlers are unchanged, and no discovery document advertises the new path. Without the env var the route behaves exactly as today (404). The frontend nginx already proxies /.well-known to the backend.

Validation

  • cargo test -p nyxid oidc_discovery: 7 passed (5 existing + 2 new: token served as plain text; 404 when unset)
  • cargo clippy -p nyxid --all-targets -- -D warnings: clean
  • cargo fmt --all -- --check: clean

Rollout

  1. Deploy the backend.
  2. Set OPENAI_APPS_CHALLENGE_TOKEN to the token shown in the OpenAI portal.
  3. curl https://nyx-api.chrono-ai.fun/.well-known/openai-apps-challenge must print only the token.
  4. Click verify in the portal (Challenge Base URL blank or https://nyx-api.chrono-ai.fun).

🤖 Generated with Claude Code

OpenAI's plugin portal verifies control of the MCP host by fetching
/.well-known/openai-apps-challenge and expecting the plugin's token as
bare plain text. The path returned 404, so submission showed
"Domain not verified".

Serve the token from the optional OPENAI_APPS_CHALLENGE_TOKEN env var on
the public /.well-known router; return 404 when unset, which matches
today's behavior. Existing discovery documents are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

📊 Code coverage

Component Lines Threshold Status Δ vs base
Backend (nyxid) 87.55% 73% ✅ 🔺 +0.01

Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end.

@ctkm-aelf
ctkm-aelf merged commit d85799b into rollup-2026-10-01-ctkm-1 Oct 1, 2026
35 checks passed
ctkm-aelf added a commit that referenced this pull request Oct 1, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ctkm-aelf added a commit that referenced this pull request Oct 1, 2026
…sent (#1723)

* feat(admin usage): configurable token views, data tables, and preloading (#1721)

Admin Usage needed a selectable token total without double counting, immediately available filters and user details, and a visible data table that each panel can show directly or as an accordion.

- Add a multi-select token picker to the dashboard and list. Total already includes Input and Output, so those selections are displayed but not added twice; selected cache-read and cache-write counts still add. An inline tooltip explains the overlap.
- Add a per-panel Data table setting, defaulting to Always open with Accordion as the alternate mode. Persist and validate the field in the backend workspace contract.
- Load Services, Billing accounts, and Acting users options when Usage opens. Preload visible user details in the background and cache usage and option queries for five minutes of freshness and ten minutes of retention.

Source PR: #1721. Its rebased head 0e24c05 passed 24 CI checks with no failures, including the full backend, frontend, coverage, Rust feature, and CodeQL jobs. All 18 Admin Usage browser tests and 27 focused frontend tests passed locally. Deploy the backend workspace schema before the frontend because older backends reject the new table_display field.

* docs(rollup): record 2026-10-01 admin usage integration

* docs(rollup): record latest main sync

* feat(mcp): serve OpenAI apps domain verification challenge (#1725)

OpenAI's plugin portal verifies control of the MCP host by fetching
/.well-known/openai-apps-challenge and expecting the plugin's token as
bare plain text. The path returned 404, so submission showed
"Domain not verified".

Serve the token from the optional OPENAI_APPS_CHALLENGE_TOKEN env var on
the public /.well-known router; return 404 when unset, which matches
today's behavior. Existing discovery documents are unchanged.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* docs(rollup): record #1725 in 2026-10-01 ctkm-1 rollup

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(oauth): show exact scopes and lock app defaults

* docs(rollup): record OAuth consent update

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant