diff --git a/services/mcp/schema/tool-definitions-all.json b/services/mcp/schema/tool-definitions-all.json index 414aadd1a875..c35a8796e79f 100644 --- a/services/mcp/schema/tool-definitions-all.json +++ b/services/mcp/schema/tool-definitions-all.json @@ -4959,7 +4959,7 @@ "feature": "sql", "summary": "Execute an SQL query.", "title": "Execute SQL query", - "required_scopes": ["query:read", "insight:read"], + "required_scopes": ["query:read"], "annotations": { "destructiveHint": false, "idempotentHint": true, diff --git a/services/mcp/schema/tool-definitions.json b/services/mcp/schema/tool-definitions.json index 2e7ce4fe93a5..6a2746ca76a8 100644 --- a/services/mcp/schema/tool-definitions.json +++ b/services/mcp/schema/tool-definitions.json @@ -753,7 +753,7 @@ "feature": "sql", "summary": "Execute an SQL query.", "title": "Execute SQL query", - "required_scopes": ["query:read", "insight:read"], + "required_scopes": ["query:read"], "annotations": { "destructiveHint": false, "idempotentHint": true, diff --git a/services/mcp/tests/integration/mcp-protocol-suite.ts b/services/mcp/tests/integration/mcp-protocol-suite.ts index d49175b96855..29cf4a2385fc 100644 --- a/services/mcp/tests/integration/mcp-protocol-suite.ts +++ b/services/mcp/tests/integration/mcp-protocol-suite.ts @@ -1253,8 +1253,8 @@ export function defineToolBehaviorTests( // `SELECT 1 AS one` doesn't depend on any ingested data, so it works // against a freshly-booted local stack with no seed data. // - // The tool is gated by `query:read` + `insight:read` scopes — if the - // test API key doesn't carry them, execute-sql won't be in the + // The tool is gated by the `query:read` scope — if the + // test API key doesn't carry it, execute-sql won't be in the // catalog and we skip rather than fail (a different test would // catch the scope-filter regression). it('execute-sql runs a trivial HogQL query against the upstream', async ({ skip }) => { @@ -1264,7 +1264,7 @@ export function defineToolBehaviorTests( } const { tools } = await client.listTools() if (!tools.some((t) => t.name === 'execute-sql')) { - skip('execute-sql not in catalog for this token — needs query:read + insight:read scopes.') + skip('execute-sql not in catalog for this token — needs the query:read scope.') return } await client.callTool({ diff --git a/services/mcp/tests/unit/tool-filtering.test.ts b/services/mcp/tests/unit/tool-filtering.test.ts index 2dbd60e496d5..d1fb50d1e03e 100644 --- a/services/mcp/tests/unit/tool-filtering.test.ts +++ b/services/mcp/tests/unit/tool-filtering.test.ts @@ -343,12 +343,13 @@ describe('Tool Filtering - API Scopes', () => { }) it('should only return read tools when user has read scope', async () => { - const context = createMockContext(['insight:read', 'query:read']) + const context = createMockContext(['query:read']) const tools = await getToolsFromContext(context) const toolNames = tools.map((t) => t.name) // insight-query is in the hand-written TOOL_MAP and requires query:read expect(toolNames).toContain('insight-query') + expect(toolNames).toContain('execute-sql') expect(toolNames).not.toContain('dashboard-create') })