pi-mcp-adapter 3.2.0 makes the adapter usable inside apps that embed Pi and fixes several problems people ran into day to day. Apps can now run the adapter on MCP connections they manage themselves, and they keep control of approvals and results. OAuth sign-in works with servers that refuse localhost callbacks. Direct tools stay put when another Pi session updates the shared cache, and mcpScript now works in Bun-compiled builds of Pi.
Highlights
- Apps that embed Pi can now run the adapter on MCP connections they manage themselves, and keep control of approvals and results.
- OAuth sign-in now works with servers that reject
localhostcallbacks, such as Lovable. - Direct tools no longer vanish from a session when another Pi session updates the shared tool cache.
mcpScriptnow works in Bun-compiled builds of Pi.- Trusted projects no longer show a false "project servers blocked" warning at startup.
Need to know
The default OAuth callback address changed from localhost to 127.0.0.1. Most servers accept either. If a server you use only accepts localhost and sign-in starts failing, set oauth.redirectUri to its localhost callback URL in that server's config.
Changelog
Highlights
- Apps that embed Pi can now run the adapter on MCP connections they manage themselves, and keep control of approvals and results.
- OAuth sign-in now works with servers that reject
localhostcallbacks, such as Lovable. - Direct tools no longer vanish from a session when another Pi session updates the shared tool cache.
mcpScriptnow works in Bun-compiled builds of Pi.- Trusted projects no longer show a false "project servers blocked" warning at startup.
Added
- New
pi-mcp-adapter/host-managedentry point for apps that embed Pi and manage their own MCP connections. The app supplies the connections, records each approved call before it is sent, sees the raw result first, and decides when the adapter starts and stops. The adapter never retries a call or reconnects, and never reads config, OAuth, or keyring state. See Host-managed embedding. Thanks to @LeonEthan for the design in issue #716.
Changed
- OAuth callbacks now default to
http://127.0.0.1:<port>/callbackinstead oflocalhost, as RFC 8252 recommends. Servers that rejectlocalhost, such as Lovable, now work without extra setup. If a server only acceptslocalhost, setoauth.redirectUrito that address. Thanks to @ebysofyan for issue #711 and PR #712.
Fixed
- Pi no longer warns "MCP: Project servers blocked: … (blocked by project trust)" at startup in a project you already trust, including one trusted through a parent folder.
eagerandkeep-aliveproject servers now wait for Pi's trust check, and the approval prompt still appears when the session starts. Thanks to @pnym-ai for reporting issue #713. - Direct tools no longer disappear from a session when another Pi session writes different details for the same server to the shared cache, or when the cache entry expires, is deleted, or the server disconnects while idle. Each session now keeps the tools and resources it found. Changing the server's config still clears them. Thanks to @NoahWTeng for PR #718.
- A server's
mcp__<server>tool now comes back once the adapter can retry the server after a failed connection. Before, on Pi versions withoutunregisterTool, it stayed hidden for the rest of the session. A tool you turned off yourself stays off. Thanks to @fer-git for issue #717. mcpScriptworks when Pi runs as a Bun-compiled executable. Before, every call failed withCannot find package 'quickjs-wasi'from the sandbox worker. Thanks to @fmoda3 for issue #720.