Skip to content

[feat] keep project MCP configs with resolved tokens out of git #882

Description

@SaulMoro

Problem

Project-scope MCP configs hold resolved tokens in plaintext inside the business repo's working tree, and nothing keeps git away from them.

<business repo>/
├── .mcp.json            "Authorization": "Bearer ghp_…"     ?? untracked, not ignored
├── .cursor/mcp.json     …
├── .codex/config.toml   …
└── .teamai/.gitignore   covers teamai state only (buildSelfModeGitignore), not these

One git add -A commits the token. Today the only guard is a docs warning (docs/usage-guide.md, MCP Secrets: "add them to .gitignore"). Affects every project scope that receives an MCP server with a ${VAR}, single-repo mode included. #875 raises the stakes: those values become members' personal tokens.

Proposed Solution

When teamai writes a project-scope MCP config that contains a resolved ${VAR}, add its path to the repo's .git/info/exclude. Local to the clone, nothing committed, idempotent; uninstall removes the lines it added.

 reconcile project MCP config
   write .mcp.json (0600)
+  if it carries a resolved ${VAR} and git doesn't ignore it already
+    append ".mcp.json" to .git/info/exclude   (marker comment, like the profile block)

doctor reports a project MCP config with a resolved value that git would track.

Alternatives Considered

  • Write the paths into the committed .gitignore. Changes a file the team owns, on every member's machine; a team that commits a token-free .mcp.json on purpose would lose it.
  • Only keep the docs warning. What we have; it relies on every member reading it.
  • Keep ${VAR} placeholders in the config. Rejected in the docs: GUI-launched tools don't inherit the shell, so the server gets an empty token.

Additional Context

Found while implementing #879 (ticket 04's real-CLI run: git status shows ?? .mcp.json holding the fixture token in single-repo mode). Pre-existing on main; not part of #880.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions