Skip to content

docs(mcp): add headless and ssh guidance with API key authentication - #2180

Open
Adityakk9031 wants to merge 1 commit into
UsefulSoftwareCo:mainfrom
Adityakk9031:fix/issue-2168-mcp-auth-timeout-headless-api-key
Open

Adityakk9031 wants to merge 1 commit into
UsefulSoftwareCo:mainfrom
Adityakk9031:fix/issue-2168-mcp-auth-timeout-headless-api-key

Conversation

@Adityakk9031

Copy link
Copy Markdown
Contributor

Description

Closes #2168.

When connecting to hosted Executor v2 from headless, remote, or SSH environments (such as Codex CLI/App Server, CI, or remote machines), browser OAuth flows present two pain points:

  1. Browser OAuth tokens issued by WorkOS expire after 15 minutes. Some MCP clients (e.g. Codex) do not yet handle automatic token refresh, failing with "Authentication required".
  2. Browser OAuth loopback redirects to http://localhost:<port> fail or require manual tunnel forwarding in remote SSH sessions.

Executor Cloud already supports long-lived API key authentication over Authorization: Bearer <api-key>. This PR updates the MCP Connect card UI and the hosted documentation to guide users on using API keys for remote/SSH and headless clients.

Changes

  • packages/react/src/components/mcp-install-card.tsx: Added clear guidance under HTTP connection settings pointing remote/SSH users to create and use an API key via --header 'Authorization: Bearer <api-key>'.
  • apps/docs/hosted/cloud.mdx: Documented both Browser OAuth and API Key authentication methods with sample configs for Codex (~/.codex/config.toml) and generic MCP clients.
  • apps/docs/mcp-proxy.mdx: Added header authentication instructions for remote/headless setups.
  • .changeset/headless-ssh-mcp-auth-api-keys.md: Changeset for @executor-js/react.

Verification

  • bun x oxfmt --check on all modified files
  • bun run lint passed
  • bun x vitest run src/components/mcp-install-card.test.ts in packages/react passed

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] Authentication timeout on hosted v2

1 participant