Skip to content

feat(mcp): max mcp --http for ChatGPT and Claude in the browser - #398

Merged
leemour merged 3 commits into
mainfrom
feat/mcp-http
Oct 4, 2026
Merged

leemour merged 3 commits into
mainfrom
feat/mcp-http

Conversation

@leemour

@leemour leemour commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Task

CLI-58 for max: ChatGPT and Claude in the browser use max without a third-party proxy.

Why

docs/remote.md sent people to an external authenticating proxy. cli-messaging 0.146.0 has mcp --http with its own one-owner login and exports it for a CLI with its own MCP server (cli-messaging #527, #528).

What

  • @leemour/cli-messaging 0.145.0 → 0.146.0 (also brings max chats stats).
  • src/mcp/server.ts: serveOverHttpUntilStopped mounts createMaxServer's factory on serveOverHttp with OVER_HTTP (every write through the form); a busy port is configuration_error.
  • src/commands/mcp.ts: --http, --port, --public-url (https, no path), --revoke.
  • src/mcp/tools.ts: the form's confirmer is created once per server and shared by every instance. Over HTTP a modern-protocol request may be served by a fresh instance, which refused the answer as "not from this server" — found by the new HTTP test.
  • docs/remote.md rewritten around max mcp --http; docs/commands.md regenerated; changelog.

Testing

  • pnpm lint && pnpm typecheck && pnpm test (1392 passed), pnpm docs:check, pnpm parity:check.
  • Over a real local HTTP server with the owner login: a send asks through the form even without --confirm-send and goes once accepted, in both protocol eras; nothing is sent on decline.
  • Flags: --http without an https address is refused before anything starts; --revoke deletes the token file.
  • The built max in a sandbox (temporary folders, no account): 401 without a token, exit 0 about 15 ms after SIGINT under Node and Bun, nothing on stdout.
  • Not yet: the live check with Claude.ai / ChatGPT through a real tunnel — it needs the owner's browser and tunnel.

Not released: the owner ruled the next max release waits for more search features (NEED-564).

🤖 Generated with Claude Code

leemour and others added 2 commits October 4, 2026 22:05
Adopts cli-messaging 0.146.0 and mounts max's own MCP server on its
serveOverHttp: max mcp --http --public-url serves the tools on 127.0.0.1
behind the owner's tunnel with a one-owner login, every write through the
form; max mcp --revoke ends every browser login (CLI-58).

The form's confirmer is now one per server, shared by every instance the
factory builds: over HTTP a modern request may meet a fresh instance, and
the answer was refused as not from this server.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The stop is a parameter, Ctrl-C by default, so a test can end the server
without signalling the test process.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@leemour
leemour merged commit 231793b into main Oct 4, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant