This is a patch release for v0.26.2. It repairs static configuration on connections migrated during the v0.26 upgrade, restores the MCP server Tools and Troubleshooting tabs, and fixes OAuth with ChatGPT CIMD clients and with servers such as AWS Knowledge MCP.
If you are upgrading from v0.25.x, you can upgrade directly to v0.26.3 and follow the Upgrade Notes in v0.26.2.
Fixes and Improvements
- Fixed a bug where existing connections migrated to vMCPs during the upgrade lost the static configuration values set on their catalog entry. The migration runs again on startup, so installations that already upgraded to v0.26.2 are repaired automatically.
- Restored the MCP server OAuth and OAuth debugger APIs. They were removed with the legacy MCP server APIs, but the Tools and Troubleshooting tabs on MCP servers still use them. The Troubleshooting tab now appears only for remote servers, and its Launch Server and Delete Deployment actions, which failed with a 404, are removed.
- Obot now lists prompts and resources only from components that advertise them. Before this fix, adding a tools-only server such as Google's Gmail MCP server to a vMCP made every request to that vMCP fail with
frontend identity unavailable. - ChatGPT can now finish CIMD OAuth connections to vMCPs. Obot now accepts
private_key_jwtclient assertions addressed to the scoped token endpoint it advertises for each vMCP (/oauth/token/{mcp_id}). - Obot now sends the
Content-TypeandAcceptheaders that the MCP specification requires when it probes a remote server during OAuth setup. Servers that reject requests without these headers, such as AWS Knowledge MCP, no longer fail OAuth metadata sync over and over withresource is required but not provided. - Users with a shared vMCP they can't edit can now view its tools read-only, and the tool count matches the tools their profile grants.
- Smaller UI fixes: Force single-user is now under Advanced and is hidden for remote MCP servers, saving registry connections and Git credentials in Platform > Settings now shows a confirmation, and the remote MCP server URL template placeholder shows
${API_HOST}correctly again.
What's Changed
- fix: mcp server remote form placeholder fix by @ivyjeong13 in #8137
- fix: confirmation settings save and vmcps tools fix by @ivyjeong13 in #8132
- fix: accept scoped token audience for CIMD OAuth clients by @calvinmclean in #8138
- fix: move force single-user into advanced & hide option on remote mcp servers by @ivyjeong13 in #8150
- chore: bump mmmcp to pickup listing fix by @thedadams in #8152
- fix: correctly migrate static configuration by @thedadams in #8167
- fix(mcp): send required OAuth initialization probe headers by @calvinmclean in #8165
- fix: restore MCP server OAuth APIs used by tools and troubleshooting by @thedadams in #8168
Full Changelog: v0.26.2...v0.26.3