Minor Changes
- 48eb9f0: Require credentials on the HTTP
/mcpendpoint by default. SetMCP_AUTH_ENFORCEMENT=observeto keep anonymous/mcpaccess and record privacy-safe authentication migration events;/mcp/oauthand Claude Code plugin requests keep their challenge in both modes./mcp/oauthstays as a compatibility alias, each endpoint publishes its own OAuth protected-resource metadata, an empty or scheme-onlyAuthorization: Bearerheader counts as a missing credential, and CORS responses exposeWWW-AuthenticateandMCP-Session-Id.
Patch Changes
- 126379b: Answer an expired or revoked OAuth access token (
oat_…) on the hosted HTTP transport with an HTTP 401 and aWWW-Authenticate: Bearer error="invalid_token"challenge, so MCP clients refresh the token instead of showing a tool error. The server checks the token against the Context7 API before serving the request, caches the verdict in memory per token hash for about a minute on each replica, and fails open when the check is unavailable. SetMCP_OAUTH_TOKEN_VALIDATION=offto disable the check. When the Context7 API still rejects an OAuth token on a tool call, the tool text now says the sign-in expired instead of describing API keys.