You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Tracking] MCP connector: reach docs.plus from Claude and ChatGPT #230
A person inside Claude or ChatGPT connects to docs.plus. They sign in as themselves and work with their own documents and heading chats.
Status
Live since 2026-09-28 at https://prodback.docs.plus/api/mcp. The server is stateless and builds one MCP server per request. It runs on @modelcontextprotocol/server 2.0.0, pinned exactly.
Ten tools: find_documents, create_document, get_outline, read_document, append_to_document, edit_blocks, replace_text, list_chat_rooms, read_chat_thread and post_chat_message. replace_section was removed: agents edit at a position, never a whole section.
Guide: docs/mcp/README.md. Reference: docs/mcp/reference.md and apps/hocuspocus.server/API.md §MCP connector.
The server cannot check RFC 8707 audience today. Supabase always sets aud to authenticated and does not put the resource into the token (supabase/auth#2610). So the server requires the client_id claim, which only the OAuth flow mints. Check again when supabase/auth#2610 ships.
Goal
A person inside Claude or ChatGPT connects to docs.plus. They sign in as themselves and work with their own documents and heading chats.
Status
Live since 2026-09-28 at
https://prodback.docs.plus/api/mcp. The server is stateless and builds one MCP server per request. It runs on@modelcontextprotocol/server2.0.0, pinned exactly.Ten tools:
find_documents,create_document,get_outline,read_document,append_to_document,edit_blocks,replace_text,list_chat_rooms,read_chat_threadandpost_chat_message.replace_sectionwas removed: agents edit at a position, never a whole section.Guide:
docs/mcp/README.md. Reference:docs/mcp/reference.mdandapps/hocuspocus.server/API.md§MCP connector.Done
1b109b553, plus the production toggleget_outline)c68d53947/oauth/consent98c2c488a,e752b15aa/api/mcpwith the read toolsc68d53947c68d53947c68d53947f2682d675,c68d53947create_document0dacee392/mcppage89f3a6f8a,331434e3d76cfed29e,bbcf499be,0549f0fd5Next
#329 is done: positioned edits shipped, and a connected app can no longer remove media.
Held, needs a ruling
The evidence is the admin
/mcpusage page, not argument./mcpAlongside, not blocking
API.mdShipped rules
apps/webapp/src/utils/appTrust.ts), never the client name.openid,emailandprofileonly (0c2145dfc)./api/mcp(e4113fd9d,24a4f68c2).@, so it sends no notification.MAX_READ_CHARS) and says so.Do not build
scopescolumn. Supabase supports five fixed scopes, and OAuth scopes do not control table access.createMcpHandlerin@modelcontextprotocol/serveralready takes a web-standardRequest.Known gap
The server cannot check RFC 8707 audience today. Supabase always sets
audtoauthenticatedand does not put theresourceinto the token (supabase/auth#2610). So the server requires theclient_idclaim, which only the OAuth flow mints. Check again when supabase/auth#2610 ships.New issues from the 2026-10-07 review
listChanged) · Correct six MCP doc errors that disagree with the code #461 (doc errors) · Say when an MCP read leaves content out #380 (say when a read is cut, rewritten).