Repository navigation
Add fx integration guide, document headless MCP auth - #528
Conversation
Verified end-to-end: fx connects to Kernel's MCP server, creates a browser session, runs execute_playwright_code, and cleans up. OAuth (the CLI-installed default) only works in an interactive session, so document the bearer_token_env path for fx ask/fx acp/CI.
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
Keep the fx page focused on why to connect Kernel and a working example; setup steps live in one place (the client reference page) instead of two.
There was a problem hiding this comment.
Stale comment
Risk assessment: Very Low
Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on
46e4c55).Re-evaluated the current diff (
+75/-1across 5 files) independently of the PR description.Current change set (docs site only):
- New
integrations/vercel/fx.mdxintegration page- One nav entry in
docs.json- Link additions in
integrations/overview.mdxandintegrations/vercel/overview.mdx- New “Headless and scripted use” section on
reference/mcp-server/clients/fx.mdx(placeholdersk_..., env-var auth viabearer_token_env)Delta since prior approval (
46e4c55→47f6190):
- Editorial trim only: removed a duplicated Setup section from
integrations/vercel/fx.mdxand replaced it with a pointer to the existing MCP client guide. Smaller surface than the previously approved revision.No application code, auth/billing/permissions logic, infrastructure, schema, or shared runtime paths changed. No
CODEOWNERSfile exists, so codeowner review is not required.Fits the Very Low criteria: documentation-only, small scoped diff, no production logic or infra impact.
Sent by Cursor Automation: Assign PR reviewers
OAuth currently fails for fx (interactively, not just headless) with an RFC 9207 issuer mismatch: Kernel's /authorize redirects straight to Clerk without restamping the issuer, so Clerk's response carries iss=clerk.onkernel.com instead of the advertised mcp.onkernel.com. fx verifies this strictly and rejects the flow before token exchange. Note it on the fx client page with the current error text and the bearer_token_env workaround, and add a general troubleshooting entry so other clients that start doing strict issuer verification have somewhere to land on the same fix.
There was a problem hiding this comment.
Stale comment
Risk assessment: Very Low
Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on
46e4c55).Re-evaluated the current HEAD (
79ee9a2,+96/-1across 6 files) from the file diffs only. PR description and Bugbot risk claims were ignored.Current change set (Mintlify docs site only):
- New
integrations/vercel/fx.mdxintegration page- Nav entry in
docs.json- Link additions in
integrations/overview.mdxandintegrations/vercel/overview.mdx- OAuth issuer-mismatch warning and API-key workaround (
bearer_token_env, placeholder key) onreference/mcp-server/clients/fx.mdx- New troubleshooting section on
reference/mcp-server/troubleshooting.mdxdescribing the same server-side issuer mismatch and API-key workaroundDelta since last assessment (
47f6190→79ee9a2):
- Documentation of an existing OAuth RFC 9207 issuer mismatch and the already-supported API-key path. No new pages of application logic. Still prose, callouts, and example config on the docs site.
No application code, auth/billing/permissions implementation, infrastructure, schema, or shared runtime paths changed. Documenting an existing auth bug is not an auth-model change. No
CODEOWNERSfile exists, so codeowner review is not required.Fits Very Low: documentation-only, small scoped diff, no production logic or infra impact.
Sent by Cursor Automation: Assign PR reviewers
Symptom and workaround first so it reads generically for any client that hits strict OAuth issuer verification, not just fx; root cause follows as supporting detail.
There was a problem hiding this comment.
Stale comment
Risk assessment: Very Low
Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on
46e4c55).Re-evaluated the current HEAD (
6ba5e36,+94/-1across 6 files) from the file diffs only. PR description and Bugbot risk claims were ignored.Current change set (Mintlify docs site only):
- New
integrations/vercel/fx.mdxintegration page- Nav entry in
docs.json- Link additions in
integrations/overview.mdxandintegrations/vercel/overview.mdx- OAuth issuer-mismatch warning and API-key workaround (
bearer_token_env, placeholder env var) onreference/mcp-server/clients/fx.mdx- Troubleshooting section on
reference/mcp-server/troubleshooting.mdxdescribing the same server-side issuer mismatch and API-key workaroundDelta since last assessment (
79ee9a2→6ba5e36):
- Editorial reorder only: troubleshooting entry now leads with the workaround, then the root cause. Same content, no new files or behavior.
No application code, auth/billing/permissions implementation, infrastructure, schema, or shared runtime paths changed. Documenting an existing auth bug is not an auth-model change. No
CODEOWNERSfile exists, so codeowner review is not required.Fits Very Low: documentation-only, small scoped diff, no production logic or infra impact.
Sent by Cursor Automation: Assign PR reviewers
Keep the symptom and fix; leave out the issuer-mismatch mechanics.
There was a problem hiding this comment.
Stale comment
Risk assessment: Very Low
Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on
46e4c55).Re-evaluated the current HEAD (
4f3edd8,+92/-1across 6 files) from the file diffs only. PR description and Bugbot risk claims were ignored.Current change set (Mintlify docs site only):
- New
integrations/vercel/fx.mdxintegration page- Nav entry in
docs.json- Link additions in
integrations/overview.mdxandintegrations/vercel/overview.mdx- OAuth failure warning and API-key workaround (
bearer_token_env, placeholder env var) onreference/mcp-server/clients/fx.mdx- Troubleshooting section on
reference/mcp-server/troubleshooting.mdxpointing strict-issuer clients at the existing API-key pathDelta since last assessment (
6ba5e36→4f3edd8):
- Editorial cut only: dropped the server-side issuer-mismatch root-cause paragraph and a cross-link sentence. Same pages, less detail, no new files or behavior.
No application code, auth/billing/permissions implementation, infrastructure, schema, or shared runtime paths changed. Documenting an existing auth workaround is not an auth-model change. No
CODEOWNERSfile exists, so codeowner review is not required.Fits Very Low: documentation-only, small scoped diff, no production logic or infra impact.
Sent by Cursor Automation: Assign PR reviewers
More illustrative than a static title fetch; verified end-to-end via fx ask against the real Kernel MCP server.
There was a problem hiding this comment.
Risk assessment: Very Low
Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on 46e4c55).
Re-evaluated the current HEAD (af82a39, +96 / -1 across 6 files) from the file diffs only. PR description and Bugbot risk claims were ignored.
Current change set (Mintlify docs site only):
- New
integrations/vercel/fx.mdxintegration page - Nav entry in
docs.json - Link additions in
integrations/overview.mdxandintegrations/vercel/overview.mdx - OAuth failure warning and API-key workaround (
bearer_token_env, placeholder env var) onreference/mcp-server/clients/fx.mdx - Troubleshooting section on
reference/mcp-server/troubleshooting.mdxpointing strict-issuer clients at the existing API-key path
Delta since last assessment (4f3edd8 → af82a39):
- Editorial example swap only:
fx askprompt changed from anexample.comtitle fetch to a Hacker News top-5 scrape, plus sample output. Same pages, no new files or behavior.
No application code, auth/billing/permissions implementation, infrastructure, schema, or shared runtime paths changed. Documenting an existing auth workaround is not an auth-model change. The fx ask string is a user-facing docs example, not a model system prompt. No CODEOWNERS file exists, so codeowner review is not required.
Fits Very Low: documentation-only, small scoped diff, no production logic or infra impact.
Sent by Cursor Automation: Assign PR reviewers


Summary
integrations/vercel/fx.mdx, an integration guide for connecting fx (Vercel Labs' native CLI coding agent) to Kernel's MCP server, and links it fromintegrations/overview.mdx,integrations/vercel/overview.mdx, and the nav.reference/mcp-server/clients/fx.mdxpage: the OAuth flowkernel mcp install --target fxsets up only works in an interactive fx session. Non-interactive runs (fx ask,fx acp, CI) need a Kernel API key via fx'sbearer_token_envfield instead — fx rejects a literalAuthorizationheader, so the generic API-key pattern used on other client pages doesn't apply here.Test plan
Verified end-to-end in a scratch environment before writing anything down:
~/.fx/mcp.jsonwithbearer_token_envpointing at a Kernel API keyfx askwith a prompt to create a browser session, runexecute_playwright_codeagainsthttps://example.com, and delete the session — got back the correct page title and confirmed viakernel browser listthat the session was cleaned upkernel mcp install --target fxfails in non-interactivefx askwith the exact error now documented on the client pagedocs.jsonvalidated as JSONNot run:
mintlify broken-links(exits non-zero in this sandbox with no other output, likely a network/environment issue unrelated to this change).Note
Low Risk
Documentation-only changes with no runtime, auth, or API behavior modifications.
Overview
Adds documentation for connecting Vercel Labs’ fx CLI agent to Kernel’s MCP server so it can manage cloud browser sessions and run Playwright via MCP tools.
A new
integrations/vercel/fxpage explains the integration, links to the fx client guide, and includes an examplefx askHacker News scrape. The Vercel integrations overview, integrations index, anddocs.jsonnav now point to that page.The
reference/mcp-server/clients/fxpage is expanded with an OAuth issuer mismatch warning (mcp.onkernel.comvsclerk.onkernel.com), a note that interactive/mcp authdoes not work for headlessfx ask/fx acp/ CI, and a Connect with an API key section using fx’sbearer_token_env(not staticAuthorizationheaders).reference/mcp-server/troubleshootingadds a short section on strict RFC 9207 clients and API-key fallback.Reviewed by Cursor Bugbot for commit af82a39. Bugbot is set up for automated code reviews on this repo. Configure here.