Skip to content

Add fx integration guide, document headless MCP auth - #528

Merged
dprevoznik merged 6 commits into
mainfrom
hypeship/fx-integration-guide
Sep 1, 2026
Merged

dprevoznik merged 6 commits into
mainfrom
hypeship/fx-integration-guide

Conversation

@dprevoznik

@dprevoznik dprevoznik commented Aug 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds integrations/vercel/fx.mdx, an integration guide for connecting fx (Vercel Labs' native CLI coding agent) to Kernel's MCP server, and links it from integrations/overview.mdx, integrations/vercel/overview.mdx, and the nav.
  • Documents a gap in the existing reference/mcp-server/clients/fx.mdx page: the OAuth flow kernel mcp install --target fx sets up only works in an interactive fx session. Non-interactive runs (fx ask, fx acp, CI) need a Kernel API key via fx's bearer_token_env field instead — fx rejects a literal Authorization header, so the generic API-key pattern used on other client pages doesn't apply here.

Test plan

Verified end-to-end in a scratch environment before writing anything down:

  • Installed fx 0.0.7, confirmed it authenticates against the model provider with no extra setup
  • Configured ~/.fx/mcp.json with bearer_token_env pointing at a Kernel API key
  • Ran fx ask with a prompt to create a browser session, run execute_playwright_code against https://example.com, and delete the session — got back the correct page title and confirmed via kernel browser list that the session was cleaned up
  • Confirmed the OAuth config written by kernel mcp install --target fx fails in non-interactive fx ask with the exact error now documented on the client page
  • docs.json validated as JSON

Not run: mintlify broken-links (exits non-zero in this sandbox with no other output, likely a network/environment issue unrelated to this change).


Note

Low Risk
Documentation-only changes with no runtime, auth, or API behavior modifications.

Overview
Adds documentation for connecting Vercel Labs’ fx CLI agent to Kernel’s MCP server so it can manage cloud browser sessions and run Playwright via MCP tools.

A new integrations/vercel/fx page explains the integration, links to the fx client guide, and includes an example fx ask Hacker News scrape. The Vercel integrations overview, integrations index, and docs.json nav now point to that page.

The reference/mcp-server/clients/fx page is expanded with an OAuth issuer mismatch warning (mcp.onkernel.com vs clerk.onkernel.com), a note that interactive /mcp auth does not work for headless fx ask / fx acp / CI, and a Connect with an API key section using fx’s bearer_token_env (not static Authorization headers). reference/mcp-server/troubleshooting adds a short section on strict RFC 9207 clients and API-key fallback.

Reviewed by Cursor Bugbot for commit af82a39. Bugbot is set up for automated code reviews on this repo. Configure here.

Verified end-to-end: fx connects to Kernel's MCP server, creates a
browser session, runs execute_playwright_code, and cleans up. OAuth
(the CLI-installed default) only works in an interactive session, so
document the bearer_token_env path for fx ask/fx acp/CI.
@mintlify

mintlify Bot commented Aug 29, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
Kernel 🟢 Ready View Preview Aug 29, 2026, 9:53 PM

💡 Tip: Enable Workflows to automatically generate PRs for you.

cursor[bot]
cursor Bot approved these changes Aug 29, 2026 •
Keep the fx page focused on why to connect Kernel and a working
example; setup steps live in one place (the client reference page)
instead of two.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk assessment: Very Low

Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on 46e4c55).

Re-evaluated the current diff (+75 / -1 across 5 files) independently of the PR description.

Current change set (docs site only):

  • New integrations/vercel/fx.mdx integration page
  • One nav entry in docs.json
  • Link additions in integrations/overview.mdx and integrations/vercel/overview.mdx
  • New “Headless and scripted use” section on reference/mcp-server/clients/fx.mdx (placeholder sk_..., env-var auth via bearer_token_env)

Delta since prior approval (46e4c55 → 47f6190):

  • Editorial trim only: removed a duplicated Setup section from integrations/vercel/fx.mdx and replaced it with a pointer to the existing MCP client guide. Smaller surface than the previously approved revision.

No application code, auth/billing/permissions logic, infrastructure, schema, or shared runtime paths changed. No CODEOWNERS file exists, so codeowner review is not required.

Fits the Very Low criteria: documentation-only, small scoped diff, no production logic or infra impact.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

OAuth currently fails for fx (interactively, not just headless) with
an RFC 9207 issuer mismatch: Kernel's /authorize redirects straight to
Clerk without restamping the issuer, so Clerk's response carries
iss=clerk.onkernel.com instead of the advertised mcp.onkernel.com. fx
verifies this strictly and rejects the flow before token exchange.

Note it on the fx client page with the current error text and the
bearer_token_env workaround, and add a general troubleshooting entry
so other clients that start doing strict issuer verification have
somewhere to land on the same fix.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk assessment: Very Low

Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on 46e4c55).

Re-evaluated the current HEAD (79ee9a2, +96 / -1 across 6 files) from the file diffs only. PR description and Bugbot risk claims were ignored.

Current change set (Mintlify docs site only):

  • New integrations/vercel/fx.mdx integration page
  • Nav entry in docs.json
  • Link additions in integrations/overview.mdx and integrations/vercel/overview.mdx
  • OAuth issuer-mismatch warning and API-key workaround (bearer_token_env, placeholder key) on reference/mcp-server/clients/fx.mdx
  • New troubleshooting section on reference/mcp-server/troubleshooting.mdx describing the same server-side issuer mismatch and API-key workaround

Delta since last assessment (47f6190 → 79ee9a2):

  • Documentation of an existing OAuth RFC 9207 issuer mismatch and the already-supported API-key path. No new pages of application logic. Still prose, callouts, and example config on the docs site.

No application code, auth/billing/permissions implementation, infrastructure, schema, or shared runtime paths changed. Documenting an existing auth bug is not an auth-model change. No CODEOWNERS file exists, so codeowner review is not required.

Fits Very Low: documentation-only, small scoped diff, no production logic or infra impact.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

Symptom and workaround first so it reads generically for any client
that hits strict OAuth issuer verification, not just fx; root cause
follows as supporting detail.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk assessment: Very Low

Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on 46e4c55).

Re-evaluated the current HEAD (6ba5e36, +94 / -1 across 6 files) from the file diffs only. PR description and Bugbot risk claims were ignored.

Current change set (Mintlify docs site only):

  • New integrations/vercel/fx.mdx integration page
  • Nav entry in docs.json
  • Link additions in integrations/overview.mdx and integrations/vercel/overview.mdx
  • OAuth issuer-mismatch warning and API-key workaround (bearer_token_env, placeholder env var) on reference/mcp-server/clients/fx.mdx
  • Troubleshooting section on reference/mcp-server/troubleshooting.mdx describing the same server-side issuer mismatch and API-key workaround

Delta since last assessment (79ee9a2 → 6ba5e36):

  • Editorial reorder only: troubleshooting entry now leads with the workaround, then the root cause. Same content, no new files or behavior.

No application code, auth/billing/permissions implementation, infrastructure, schema, or shared runtime paths changed. Documenting an existing auth bug is not an auth-model change. No CODEOWNERS file exists, so codeowner review is not required.

Fits Very Low: documentation-only, small scoped diff, no production logic or infra impact.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

Keep the symptom and fix; leave out the issuer-mismatch mechanics.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk assessment: Very Low

Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on 46e4c55).

Re-evaluated the current HEAD (4f3edd8, +92 / -1 across 6 files) from the file diffs only. PR description and Bugbot risk claims were ignored.

Current change set (Mintlify docs site only):

  • New integrations/vercel/fx.mdx integration page
  • Nav entry in docs.json
  • Link additions in integrations/overview.mdx and integrations/vercel/overview.mdx
  • OAuth failure warning and API-key workaround (bearer_token_env, placeholder env var) on reference/mcp-server/clients/fx.mdx
  • Troubleshooting section on reference/mcp-server/troubleshooting.mdx pointing strict-issuer clients at the existing API-key path

Delta since last assessment (6ba5e36 → 4f3edd8):

  • Editorial cut only: dropped the server-side issuer-mismatch root-cause paragraph and a cross-link sentence. Same pages, less detail, no new files or behavior.

No application code, auth/billing/permissions implementation, infrastructure, schema, or shared runtime paths changed. Documenting an existing auth workaround is not an auth-model change. No CODEOWNERS file exists, so codeowner review is not required.

Fits Very Low: documentation-only, small scoped diff, no production logic or infra impact.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

More illustrative than a static title fetch; verified end-to-end via
fx ask against the real Kernel MCP server.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk assessment: Very Low

Decision: Approval stands. Risk did not increase after the latest push. Not re-approving (already approved on 46e4c55).

Re-evaluated the current HEAD (af82a39, +96 / -1 across 6 files) from the file diffs only. PR description and Bugbot risk claims were ignored.

Current change set (Mintlify docs site only):

  • New integrations/vercel/fx.mdx integration page
  • Nav entry in docs.json
  • Link additions in integrations/overview.mdx and integrations/vercel/overview.mdx
  • OAuth failure warning and API-key workaround (bearer_token_env, placeholder env var) on reference/mcp-server/clients/fx.mdx
  • Troubleshooting section on reference/mcp-server/troubleshooting.mdx pointing strict-issuer clients at the existing API-key path

Delta since last assessment (4f3edd8 → af82a39):

  • Editorial example swap only: fx ask prompt changed from an example.com title fetch to a Hacker News top-5 scrape, plus sample output. Same pages, no new files or behavior.

No application code, auth/billing/permissions implementation, infrastructure, schema, or shared runtime paths changed. Documenting an existing auth workaround is not an auth-model change. The fx ask string is a user-facing docs example, not a model system prompt. No CODEOWNERS file exists, so codeowner review is not required.

Fits Very Low: documentation-only, small scoped diff, no production logic or infra impact.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

@dprevoznik
dprevoznik merged commit d879722 into main Sep 1, 2026
4 checks passed
@dprevoznik
dprevoznik deleted the hypeship/fx-integration-guide branch September 1, 2026 17:55

This branch was successfully deployed

1 active deployment
staging — af82a393 Deployed Sep 1, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants