Welcome to AuthPlane Hackathon Support #7
Replies: 4 comments
|
I have a few specific questions regarding my MCP App (Murmur - personal CRM, built with Skybridge v1.4.1 + AuthPlane v0.1.1) that I'm submitting to the Speedrun Challenge. This is specifically regarding the Point 4 in the rules section "Connect it in Claude or ChatGPT — Skybridge's local emulator and built-in tunnel make this fast — and show a real, authenticated tool call rendering the UI."
This is a screenshot from my Devtools, but the Codex blocks this in iframe from rendering.
|
|
I am just seeing this message so I will get back with an answer and let you
submit your project after that if you like to change anything.
Uruba
…On Sun, Aug 30, 2026 at 3:02 PM Harsh Kumar ***@***.***> wrote:
Hi @urubaniazi-dotcom <https://github.com/urubaniazi-dotcom>,
I have a few specific questions regarding my MCP App (Murmur - personal
CRM, built with Skybridge v1.4.1 + AuthPlane v0.1.1) that I'm submitting to
the Speedrun Challenge. This is specifically regarding the Point 4 in the
rules section "*Connect it in Claude or ChatGPT — Skybridge's local
emulator and built-in tunnel make this fast — and show a real,
authenticated tool call rendering the UI*."
1.
In Chatgpt, there is no custom MCP server support for free/Plus
personal accounts. The OpenAI docs at
https://help.openai.com/en/articles/12584461 say full MCP is "only
available to Business and Enterprise/Edu users, currently" and Pro users
can connect MCPs but with read-only restrictions. What is the recommended
submission path for Plus or Free users? Should submitters default to
Claude.ai (which has custom connectors on free accounts) - but facing some
connection problems or to Codex desktop (which supports custom MCPs on the
free plan but renders views in a dark iframe with a script-src 'self' CSP
that blocks our view JS)?
2.
Codex desktop iframe + Skybridge view components. When I connect my
MCP server to Codex via http://localhost:3000/mcp, the OAuth flow
works end-to-end (DCR, PKCE, JWT, scope enforcement, 16/16 e2e green). But
when a tool returns a view: { component: "..." } result, Codex's iframe
renders the body empty. DevTools console shows:
Refused to load the script '
http://localhost:3000/_skybridge/view/identity'
because it violates the Content Security Policy directive:
"script-src 'self' 'wasm-unsafe-eval' 'unsafe-inline' 'unsafe-eval'
blob: ..."
The iframe is hosted at web-sandbox.oaiusercontent.com (cross-origin
from localhost:3000). The script-src 'self' resolves to
oaiusercontent.com, not our app. I tried the production build (npx
skybridge build) and Vercel deploy - same CSP block. Does the production
build's view JS get served from the same origin as the MCP endpoint,
bypassing 'self'? If not, what's the recommended path for Skybridge
developers to demo MCP App views in Codex?
3.
Workaround validation : is the DevTools an acceptable recording
surface for the Speedrun Challenge? Skybridge ships the DevTools as a
built-in MCP host with full OAuth, tool invocation, and view rendering. The
Speedrun Challenge rule 4 says "Connect it in Claude or ChatGPT" - does the
DevTools satisfy this for submission purposes, or do you require a real
third-party chat host (Claude.ai / ChatGPT.com / Codex) for judging?
Image: image (view on web)
<https://github.com/user-attachments/assets/624fa2f3-2575-4af1-81cb-8e70a7afddda>
This is a screenshot from my Devtools, but the Codex blocks this in iframe
from rendering.
—
Reply to this email directly, view it on GitHub
<#7?email_source=notifications&email_token=CBCCGKH4VKH546STSIDZH235MSP5ZA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBSGEYDIOBTUZZGKYLTN5XKO3LFNZ2GS33OUVSXMZLOOSWGM33PORSXEX3DNRUWG2Y#discussioncomment-18210483>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/CBCCGKG2WBN2YST5SOCCQ735MSP5ZAVCNFSNUABJKJSXA33TNF2G64TZHMYTENRWGAYDENBQGE5UI2LTMN2XG43JN5XDWMJQGYZTGNBZGSQXMAQ>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/CBCCGKBRYPL42GVELM6C7J35MSP5ZA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBSGEYDIOBTUZZGKYLTN5XKO3LFNZ2GS33OUVSXMZLOOSVGM33PORSXEX3JN5ZQ>
and Android
<https://github.com/notifications/mobile/android/CBCCGKG4VVWRAOLS6J7KGYD5MSP5ZA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBSGEYDIOBTUZZGKYLTN5XKO3LFNZ2GS33OUVSXMZLOOSXGM33PORSXEX3BNZSHE33JMQ>.
Download it today!
You are receiving this because you were mentioned.Message ID:
***@***.***>
|
|
Hi @urubaniazi-dotcom, I am still not entirely sure why my Codex Desktop blocked my localhost Skybridge app view from rendering but my most likely guess is that the localhost version failed because ChatGPT’s sandbox CSP blocked Vite/React scripts like |
|
Hi @Harshkumar62367 great to hear the project is submitted. It's currently under review, same as the other submissions. Answers to your questions, for the record (and for anyone else who runs into the same thing): Nothing further needed on your end. Good luck with the review! |

Uh oh!
There was an error while loading. Please reload this page.
This is the place to get unstuck while you build with AuthPlane during the hackathon.
A few things to know before you post:
What this channel is for:
Before you post
Check the docs and the FAQ first. If you're hitting an error, the common errors reference covers the top 20 issues people actually run into, with causes and fixes.
When you post, include:
The team and community will be around throughout the hackathon to help. Don't sit on a blocker; just ask.
Good luck building and we are excited to have you here!
All reactions