Skip to content

Plugin update - #3

Merged
spencer-g-smith merged 3 commits into
mainfrom
codex/oauth-plugin-v2
Sep 20, 2026
Merged

spencer-g-smith merged 3 commits into
mainfrom
codex/oauth-plugin-v2

Conversation

@spencer-g-smith

@spencer-g-smith spencer-g-smith commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Plugin v2.0.0 — OAuth, multi-client packaging

Rewrites the plugin as a v2.0.0 package that connects to the Expert System MCP server over OAuth instead of a user-supplied API key, and that installs in both Claude Code and Codex from one shared set of skills.

What changed

  • OAuth replaces API keys. The userConfig.api_key prompt is gone; both clients sign in through their own MCP connection controls against https://expert-system.starmode.dev/api/mcp.
  • Skills rewritten around MCP tools. research, macro, and financials drop the hand-written REST endpoint tables (~240 lines) in favor of short tool-workflow instructions, so tool schemas resolve at runtime. Each gets an agents/openai.yaml for Codex routing.
  • Multi-client manifests. New portable root plugin.json / mcp.json (Agent Plugins 1.0.0), plus .claude-plugin/ and .codex-plugin/ overlays sharing skills/. The root marketplace.json moved to .claude-plugin/marketplace.json, which is now canonical.
  • Repo tooling. Adds package.json, TypeScript, ESLint, Prettier, and tests/plugin.test.ts — six packaging checks covering version sync across manifests, credential-free connection shapes, marketplace parity with the server, YAML dependencies, the 11-tool surface, and policy files. Adds scripts/package-plugin.py for an allowlisted plugin-only archive.
  • Docs. Rewritten README with install/upgrade/troubleshooting for both clients, a new AGENTS.md on server–plugin sync rules, and documents/plugin-release.md with the release and validation checklist.

Next steps before release

  1. Confirm operator identity and support contact on the privacy/terms pages, and deploy them.
  2. Run EXPERT_SYSTEM_SERVER_ROOT=../expert-system bun run plugin:check — without that variable the cross-repo contract test is silently skipped.
  3. Validate the exact candidate commit from a fresh clone, including both client manifest validators.
  4. Untested: upgrade from a real v1 install (remove the old API-key config, confirm OAuth reconnect). No v1 install existed in this checkout.
  5. Run the behavioral matrix in documents/plugin-release.md in both clients, then ship v2.0.0-rc.1, soak for a day, and tag v2.0.0.

Compatibility: breaking for v1 users — the API-key plugin cannot talk to the OAuth-only server. Existing REST /api/v1 integrations are unaffected.

🤖 Generated with Claude Code

spencer-g-smith and others added 2 commits September 20, 2026 06:18
Runs typecheck, lint, format, and plugin:check with the server checked out
so the cross-repository contract test is not silently skipped.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Server-originated drift is not covered by the server repository's CI, so
check it daily rather than only on plugin changes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@spencer-g-smith
spencer-g-smith merged commit fa5b7aa into main Sep 20, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant