Skip to content

MCP: no credentials in tool results, explicit hints, OpenAI domain challenge - #76

Merged
heliocosta-dev merged 2 commits into
mainfrom
openai-plugin-readiness
Oct 1, 2026
Merged

heliocosta-dev merged 2 commits into
mainfrom
openai-plugin-readiness

Conversation

@heliocosta-dev

Copy link
Copy Markdown
Member

Prepares the MCP server for OpenAI's plugin review (platform.openai.com/plugins). The same changes apply to every client, Claude included.

  • No credentials in tool results (OpenAI's restricted-data rule):
    • create_api_key and rotate_webhook_secret are removed from MCP.
    • get_webhook and create_webhook no longer return signing_secret, and create_webhook no longer accepts one.
    • The REST API, SDKs and dashboard are unchanged.
    • get_webhook is no longer admin-only, since it carries no secret.
  • Explicit annotations: every tool sends all four hints as booleans. openWorldHint: true is set on the send tools, create_broadcast, update_email, the webhook tools and the SES/DNS domain tools.
  • Server instructions: they state the consent rule from the terms (no purchased, rented or scraped lists), and that credentials and billing aren't available through the tools.
  • get_usage: no overage price and no plan names in the description.
  • Send tools: send_email and send_email_batch now say a repeated call sends again.
  • Domain verification: OPENAI_APPS_CHALLENGE_TOKEN is served at /.well-known/openai-apps-challenge, with a 404 when unset.
  • Also updated: consent scope labels (en and pt-BR), the dashboard MCP tool list, and the MCP docs (en and pt-BR).

Tests: api 549, web 839; typecheck, biome and the docs build pass.

🤖 Generated with Claude Code

heliocosta-dev and others added 2 commits October 1, 2026 18:29
…allenge

OpenAI's plugin review refuses tool results that carry auth secrets and
requires every annotation as an explicit boolean.

- create_api_key and rotate_webhook_secret leave the MCP surface;
  get_webhook and create_webhook no longer return the signing secret, and
  create_webhook no longer accepts one. REST API and dashboard unchanged.
- Every tool sends readOnlyHint, destructiveHint, idempotentHint and
  openWorldHint; open-world covers sends, webhooks and SES/DNS domain tools.
- Server instructions state the consent policy from the terms and that
  credentials and billing are not available through the tools.
- get_usage drops the overage price and plan names; send_email and
  send_email_batch say a repeated call sends again.
- OPENAI_APPS_CHALLENGE_TOKEN is served at /.well-known/openai-apps-challenge.
- Consent labels, dashboard tool list and docs follow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@heliocosta-dev
heliocosta-dev merged commit 6b445e5 into main Oct 1, 2026
4 checks passed
@heliocosta-dev
heliocosta-dev deleted the openai-plugin-readiness branch October 1, 2026 21:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant