-
v0.4.0 — nope-mcp (formerly amb-mcp), agent-ready
StableAll checks were successfulbuild-image / build (push) Successful in 6sreleased this
2026-10-03 05:59:26 +00:00 | 0 commits to main since this releaseAdded
- MCP Registry manifest (
server.json): publishes nope-mcp to the
official MCP Registry as
org.edufeed/nope-mcp, pointing at thehttps://mcp.edufeed.org/mcp
remote. Itsversionalways matchespackage.json. - Per-connection default relays via the connector URL: the HTTP transport
reads a?relays=parameter off theinitializerequest, e.g.
https://mcp.amb.edufeed.org/mcp?relays=sodix. The named relays become that
session's default set; the rest of the deployment's relays stay selectable
per call. Connector UIs typically offer only a name and a URL field, so the
URL is the only place a connection can express which corpus it wants.
Relays answer to their full URL, their hostname, or the first label of their
hostname; a name the deployment does not serve failsinitializewith HTTP
400 rather than silently falling back to the server default. Arbitrary URLs
are refused — the endpoint never opens sockets to caller-chosen hosts. - SODIX relay (
wss://sodix.edufeed.org) documented as an
AMB_EXTRA_RELAYSmember alongside the OERSI aggregation relay. list_relaysreportsdefaultRelaysSource(server-configor
connector-url), so a model can tell a deliberately narrowed session from
the deployment's standard corpus.- Per-tool-call logging: every tool call emits one JSON line on stderr
(ts,tool,ms,ok,session, summarizedargs,erroron
failure).LOG_LEVELcontrols it:info(default) logs every call,
warn/erroronly failures,silentnothing. stdout stays reserved for
the stdio transport.
Typed error payloads ({"error":"relay_unreachable",…}returned as text) are logged asok:falsewith the code. - MCP served at
/as well as/mcp(same session map, both paths accept
POST/GET/DELETE): a plain browserGET /— noMcp-Session-Idheader, no
Accept: text/event-stream— returns a small JSON info document (name,
version,mcp,docs,transport) instead of the usual "unknown
session" 404;GET /mcpis unchanged and always behaves as an MCP session
request. - Host- and path-aware OAuth protected-resource metadata (RFC 9728): the
PRM is built per request from the forwarded scheme + host (trust proxy
is now on, since Traefik terminates TLS) and served at both
/.well-known/oauth-protected-resource(resource: https://<host>/)
and the new/.well-known/oauth-protected-resource/mcp(resource: https://<host>/mcp); a 401'sWWW-Authenticatepoints at whichever PRM
matches the request path (/mcpand/mcp/alike). A host outside
HTTP_ALLOWED_HOSTS(when configured) falls back toOAUTH_RESOURCE_URL.
Behaviour change for existing connector owners: the root PRM's
resourcevalue changed fromhttps://<host>/mcptohttps://<host>/;
a connector that cached the old root PRM document needs to re-fetch it.
Connectors addressing/mcpdirectly are unaffected — that path now has
its own PRM at/.well-known/oauth-protected-resource/mcp. OAUTH_AUDIENCEis now a comma-separated list (default
nope-mcp,amb-mcp); a token whoseaudcontains any of them validates,
so tokens Keycloak still issues withaud: amb-mcpkeep working under the
new name.- MCP tool annotations (
readOnlyHint,destructiveHint, etc.) on every
registered tool, so clients that surface them (e.g. consent prompts)
classify each call correctly;signer_statusis annotated as the pure
read it is, not as a mutator. - English opening paragraph in the server
instructions:
buildServerInstructions({ openLicensesOnly })now leads with a
config-aware paragraph describing nope-mcp for any MCP client — not only
edufeed's German teacher base, since this server is listed in public MCP
directories — before the existing German routing guidance; it never claims
the open-license policy is active whenOPEN_LICENSES_ONLY=false.
Deploy notes
- Production's
HTTP_ALLOWED_HOSTSmust includemcp.edufeed.org— the
SDK's DNS-rebinding protection rejects any request whose Host is outside
this list once the list is set.
Changed
- Open-licensed results only:
search_resources,search_contentand
search_passagesreturn learning resources (kind 30142) only under CC0,
the Public Domain Mark, CC BY or CC BY-SA — the allowlist amb-indexer uses
for fulltext. NC/ND, all-rights-reserved and unlicensed resources are left
out; articles, wikis, publications, projects, measures and calendar events
carry no license and stay unfiltered. Searches with free text over-fetch and filter
client-side, because any relay field filter would disable amb-relay's
passage rerank; only asearch_resourcescall without free text (pure
metadata filters or a browse) addslicense.idfilters for every stored
open spelling to the relay query.get_resourcestill resolves any resource
and reportsopenLicense.OPEN_LICENSES_ONLY=falserestores unfiltered
results. - Renamed to
nope-mcp(formerlyamb-mcp). The package name, MCP
server name, HTTPWWW-Authenticaterealm, and docs now saynope-mcp.
amb-mcpremains a documented alias and a valid OAuth audience; existing
deployments and URLs (https://mcp.amb.edufeed.org/mcp) keep working
unchanged. search_passagesranking: requests vector weightalpha: 0.7from the
indexer instead of its keyword-leaning default 0.3, over-fetches
min(limit × 3, 100)chunks, keeps at most two passages per document and
drops hits below 10 % of the top score before truncating tolimit. A
Christmas escape game no longer tops a peace-education question on the
strength of the words "GRUNDSCHULE" and "Kinder", and one document no
longer fills three of ten slots.search_passagesguidance: the tool description and the server
instructions now tell the model to phrasequestionas a topical statement
naming subject and target group rather than the user's literal sentence,
and to say so instead of guessing when a passage carries only a snippet.
The reason given is flag-aware: withOPEN_LICENSES_ONLYon, a text-less
learning-resource passage simply has no fulltext yet, since license-gated
hits are already dropped before the model sees them; with it off, the
license-gated possibility is still named.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- MCP Registry manifest (