Skip to content

tracking(mcp): complete the post-V3 roadmap #4329

Description

@Phoenix500526

Problem

The dual-era MCP V3 rollout is complete in #1650, but the architecture document
still lists post-V3 work without one current coordination tracker. Some slices
have since shipped or gained their own tracker, while the remaining ownership
is fragmented.

Desired outcome

Maintain one authoritative view of MCP work after V3. Each implementation slice
may use its own focused issue and PR; this tracker closes when every item is
either shipped or linked to a durable child tracker and the architecture
document reflects its current state.

Checklist

  • Ship OAuth discovery, PKCE, dynamic client registration, Desktop login, and secret-safe IPC (feat(desktop): keep MCP config secrets on the main-process side of IPC #2919, feat(desktop): MCP OAuth login flow #2920)
  • Move MCP tokens and remaining credential-bearing configuration to platform-backed secret storage
  • Add resources/templates browse, read, subscribe/unsubscribe, and host UI
  • Add an authenticated loopback MCP proxy for controlled subprocess clients
  • Give config reload, per-server health, bounded backoff, and crash recovery one lifecycle owner; coordinate with feat(tui): manage client-owned MCP servers with /mcp #3838
  • Define finer-grained MCP permission policy without trusting server annotations
  • Add signed remote catalogs, last-known-good caching, guided setup schema, package provenance, and update permission diffs
  • Keep the architecture document synchronized as child work lands

Non-goals

Documentation

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions