Skip to content

MCP default identity derives from the host MAC address, so a client that sends no ids gets a different project on every machine #1750

Description

@edwinyyyu

What happened

server/api_v2/mcp.py:124 sets default_mcp_id = hex(uuid.getnode()), the MAC address of the host, or a random 48-bit number when none can be read. When a request carries no user, project or org id, _set_defaults (:180-186) uses it: user_id = f"user-{default_mcp_id}" and proj_id = f"mcp-{user_id}".

In a container the value is the container's virtual interface, and behind a load balancer it differs per replica. A client that relies on the defaults writes to one project on replica A and another on replica B, and reads back a different subset each time. On a single host the value can change across container restarts as well.

Expected

The default identity is a configured value (an environment variable or a server setting with a fixed default), never host-derived. A request with no ids either goes to one documented default project or is rejected.

Notes

Code read at d6068cdbf (main), paths under packages/server/src/memmachine_server/. Not reproduced across two machines; uuid.getnode() is documented to return the hardware address.


🤖 Written by Claude Code (Claude Fable 5.1) on behalf of @edwinyyyu.

Metadata

Metadata

Assignees

No one assigned

    Labels

    horizontal scalingWrong or unsafe when more than one server process serves the same backends (replicas or workers)

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions