feat(mcp): serve OpenAI apps domain verification challenge - #1725
Merged
ctkm-aelf merged 1 commit intoOct 1, 2026
Merged
Conversation
OpenAI's plugin portal verifies control of the MCP host by fetching /.well-known/openai-apps-challenge and expecting the plugin's token as bare plain text. The path returned 404, so submission showed "Domain not verified". Serve the token from the optional OPENAI_APPS_CHALLENGE_TOKEN env var on the public /.well-known router; return 404 when unset, which matches today's behavior. Existing discovery documents are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
📊 Code coverage
Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end. |
ctkm-aelf
added a commit
that referenced
this pull request
Oct 1, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ctkm-aelf
added a commit
that referenced
this pull request
Oct 1, 2026
…sent (#1723) * feat(admin usage): configurable token views, data tables, and preloading (#1721) Admin Usage needed a selectable token total without double counting, immediately available filters and user details, and a visible data table that each panel can show directly or as an accordion. - Add a multi-select token picker to the dashboard and list. Total already includes Input and Output, so those selections are displayed but not added twice; selected cache-read and cache-write counts still add. An inline tooltip explains the overlap. - Add a per-panel Data table setting, defaulting to Always open with Accordion as the alternate mode. Persist and validate the field in the backend workspace contract. - Load Services, Billing accounts, and Acting users options when Usage opens. Preload visible user details in the background and cache usage and option queries for five minutes of freshness and ten minutes of retention. Source PR: #1721. Its rebased head 0e24c05 passed 24 CI checks with no failures, including the full backend, frontend, coverage, Rust feature, and CodeQL jobs. All 18 Admin Usage browser tests and 27 focused frontend tests passed locally. Deploy the backend workspace schema before the frontend because older backends reject the new table_display field. * docs(rollup): record 2026-10-01 admin usage integration * docs(rollup): record latest main sync * feat(mcp): serve OpenAI apps domain verification challenge (#1725) OpenAI's plugin portal verifies control of the MCP host by fetching /.well-known/openai-apps-challenge and expecting the plugin's token as bare plain text. The path returned 404, so submission showed "Domain not verified". Serve the token from the optional OPENAI_APPS_CHALLENGE_TOKEN env var on the public /.well-known router; return 404 when unset, which matches today's behavior. Existing discovery documents are unchanged. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * docs(rollup): record #1725 in 2026-10-01 ctkm-1 rollup Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(oauth): show exact scopes and lock app defaults * docs(rollup): record OAuth consent update --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The OpenAI plugin portal shows Domain not verified for the NyxID MCP server. It verifies the MCP host (
nyx-api.chrono-ai.fun) by fetching/.well-known/openai-apps-challengeand expecting the plugin's verification token as bare plain text. That path returns 404 today.Change
GET /.well-known/openai-apps-challengeon the existing/.well-knownrouter. It returns the token astext/plainfrom the new optionalOPENAI_APPS_CHALLENGE_TOKENenv var, and 404 when the variable is unset.AppConfig.openai_apps_challenge_token(trimmed; empty counts as unset), added to every config literal; documented indocs/ENV.md.Compatibility
Purely additive. The OIDC, OAuth AS, protected-resource and JWKS routes and handlers are unchanged, and no discovery document advertises the new path. Without the env var the route behaves exactly as today (404). The frontend nginx already proxies
/.well-knownto the backend.Validation
cargo test -p nyxid oidc_discovery: 7 passed (5 existing + 2 new: token served as plain text; 404 when unset)cargo clippy -p nyxid --all-targets -- -D warnings: cleancargo fmt --all -- --check: cleanRollout
OPENAI_APPS_CHALLENGE_TOKENto the token shown in the OpenAI portal.curl https://nyx-api.chrono-ai.fun/.well-known/openai-apps-challengemust print only the token.https://nyx-api.chrono-ai.fun).🤖 Generated with Claude Code