What happened
server/api_v2/mcp.py:124 sets default_mcp_id = hex(uuid.getnode()), the MAC address of the host, or a random 48-bit number when none can be read. When a request carries no user, project or org id, _set_defaults (:180-186) uses it: user_id = f"user-{default_mcp_id}" and proj_id = f"mcp-{user_id}".
In a container the value is the container's virtual interface, and behind a load balancer it differs per replica. A client that relies on the defaults writes to one project on replica A and another on replica B, and reads back a different subset each time. On a single host the value can change across container restarts as well.
Expected
The default identity is a configured value (an environment variable or a server setting with a fixed default), never host-derived. A request with no ids either goes to one documented default project or is rejected.
Notes
Code read at d6068cdbf (main), paths under packages/server/src/memmachine_server/. Not reproduced across two machines; uuid.getnode() is documented to return the hardware address.
🤖 Written by Claude Code (Claude Fable 5.1) on behalf of @edwinyyyu.
What happened
server/api_v2/mcp.py:124setsdefault_mcp_id = hex(uuid.getnode()), the MAC address of the host, or a random 48-bit number when none can be read. When a request carries no user, project or org id,_set_defaults(:180-186) uses it:user_id = f"user-{default_mcp_id}"andproj_id = f"mcp-{user_id}".In a container the value is the container's virtual interface, and behind a load balancer it differs per replica. A client that relies on the defaults writes to one project on replica A and another on replica B, and reads back a different subset each time. On a single host the value can change across container restarts as well.
Expected
The default identity is a configured value (an environment variable or a server setting with a fixed default), never host-derived. A request with no ids either goes to one documented default project or is rejected.
Notes
Code read at
d6068cdbf(main), paths underpackages/server/src/memmachine_server/. Not reproduced across two machines;uuid.getnode()is documented to return the hardware address.🤖 Written by Claude Code (Claude Fable 5.1) on behalf of @edwinyyyu.