Skip to content

Four more shipped docs pages still send a non-admin to "Setup → Connect an Agent", the one app that 403s for them #18143

Description

@claude

Filed by the domain:devx dev seat while landing #17648 (PR #18142). ⛔ Filed unlabelled and ungradeddomain:*, type and priority are the triage seat's.

Why this is a separate card

#17648 measured the defect and named three landing sites, and its Claim: declared exactly that file surface: content/docs/ai/connect-mcp.mdx, packages/mcp/src/plugin.ts, packages/mcp/README.md. PR #18142 fixes those three. The pages below carry the identical defect but sit outside that declared surface, so editing them there would have been a file-surface breach. They are the remainder, not a second opinion.

The measurement

#16746's ruling (option A, decision batch #85) is delivered by a navigationContributions entry in the account app (packages/mcp/src/connect-ui.ts), ⛔ not by opening Setup. SETUP_APP still declares requiredPermissions: ['setup.access'] (packages/platform-objects/src/apps/setup.app.ts:47), and PR #17646's acceptance pins that a permissionless principal still gets 403 PERMISSION_DENIED on /api/v1/meta/apps/setup. Keeping Setup shut is deliberate — ungating it was measured to expose 14+ unrelated Setup surfaces.

⇒ every text below names a path that principal cannot take. Measured on origin/main at a90a9f267, located by content:

site text shape
content/docs/api/index.mdx:68 "(the key is shown once), or from Setup → Connect an Agent in the Console." a direct mint instruction — same shape as the three #17648 fixed
content/docs/deployment/environment-variables.mdx:259 "Mint one from Setup → Connect an Agent (or POST /api/v1/keys)." a direct mint instruction, in the OS_MCP_STDIO_API_KEY row
content/docs/ai/agents.mdx:55 "Setup → Connect an Agent page: per-client connect snippets, the portable …" descriptive: calls it a Setup page
content/docs/getting-started/build-with-claude-code.mdx:435 "download and API-key minting — on the Setup → Connect an Agent page." descriptive: calls it a Setup page

Shape (⛔ not prescribed)

The same as #17648's: name both doors wherever one is named today — the Account app for any signed-in user, Setup for admins — rather than replacing one with the other, because the Setup entry stays for admins and is unchanged by #17646. PR #18142 is the worked precedent, and the Account-side facts it measured are reusable verbatim:

⚠️ The two descriptive rows may not want the full two-door treatment — dropping the Setup → prefix may be the whole edit, as it was for #17648's OS_MCP_SERVER_ENABLED=false callout. Whoever takes it should judge per row.

Deliberately NOT included

docs/adr/0101-mcp-stdio-principal-admission.md:104, docs/qa/platform-checklist/areas/ai.json:206, .changeset/16746-connect-agent-account-nav.md:12 and .changeset/oauth-agent-runs-as-the-user.md:12 also carry the phrase. All are dated records — a ruling, a test checklist and shipped release history — so they are history, ⛔ not drift, and ⛔ not part of this card.

A gate will not catch this

packages/cli/scripts/check-app-nav-i18n.mjs judges locale-bundle labels, never English prose in docs — and note that #17648's own brief is stale on this script: PR #17972 (#17891) widened it from setup-only to the declared population APPS = [{ name: 'setup' }, { name: 'account' }] (:161-164). The widening does not reach prose. The docs-drift check that surfaced these rows is advisory only and says so of itself. ⇒ this stays true until someone edits the prose.

Refs: #17648 (the three-site card) · PR #18142 (the fix, and the Account-side measurements) · #16746 (the ruling) · PR #17646 (the delivery) · #16815 (a different Connect-an-Agent prose defect, ⛔ not this one).

Dedup. #17648's own filing enumerated all 586 open issues over titles and bodies on Setup → Connect an Agent4 hits (PR #17646, #16746, #16815, #16804), ⛔ none of them this. I re-checked only the increment since that filing: all 429 issues and PRs created at or after 2026-09-11T08:07:57Z (5 REST pages, oldest fetched 2026-09-10T23:01 ⇒ the window is fully covered), matched over titles and bodies. Setup → Connect an Agent2: #17648 itself and PR #17972. ⛔ Neither is this card. Firing control: that same expression returning #17648 is the positive control. Nonsense control in the same window: 0.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions