Files
shared-memory/.env.example
T
shadowdaoandClaude Opus 4.7 2bd8ea705d feat(auth): CLI tokens minted at /connect for containerized MCP clients
Adds a second token kind alongside Authentik OIDC access tokens for MCP
authentication. When the user visits /connect after signing into the Web
UI, the server mints an HMAC-signed JWT (kid="cli-v1") carrying their
Authentik identity in oidc_iss / oidc_sub claims. The token is shown
once in React state — never put in the URL or persisted on the client.

The MCP endpoint's bearer-token verifier dispatches by JWT `kid` header:
CLI tokens are verified locally via HS256(CLI_TOKEN_SECRET); everything
else goes through Authentik JWKS. Both paths resolve to the same
AuthenticatedClaims shape so userContextFromClaims handles them
identically.

This unblocks MCP clients running in containers where the OAuth loopback
callback isn't reachable — paste the token into Claude Code as a static
Authorization header and skip the OAuth flow entirely.

Revocation in v1 is "rotate CLI_TOKEN_SECRET to invalidate every issued
CLI token at once." Per-token revocation can come later if needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-15 08:36:11 -07:00

76 lines
3.6 KiB
Bash

# =============================================================================
# shared-memory — example environment file
# Copy to `.env` and fill in real values. Never commit `.env`.
# =============================================================================
# -----------------------------------------------------------------------------
# Public URL the app is reached at.
# Used for OIDC redirect URIs, MCP discovery metadata, and Auth.js callbacks.
# -----------------------------------------------------------------------------
PUBLIC_URL=https://memory.example.com
# -----------------------------------------------------------------------------
# Deployment mode
# -----------------------------------------------------------------------------
# By default the app exposes a plain HTTP port to the host for use behind an
# external reverse proxy (HAProxy, nginx, Traefik, Cloudflare Tunnel, etc.).
APP_PORT=3000
# Bind interface for the exposed port. Use 127.0.0.1 to only accept traffic
# from a proxy on the same host. Default 0.0.0.0 accepts from anywhere.
APP_BIND=0.0.0.0
# The two settings below are ONLY consumed by the optional `caddy` service,
# which is started with: `docker compose --profile tls up -d`.
# Leave them as-is if you terminate TLS upstream (HAProxy, etc.).
APP_HOSTNAME=memory.example.com
ACME_EMAIL=you@example.com
# -----------------------------------------------------------------------------
# Authentik OIDC
# Create two Applications in Authentik (one for the Web UI, one for the MCP
# resource server). See README.md for exact provider settings.
# -----------------------------------------------------------------------------
OIDC_ISSUER=https://auth.example.com/application/o/shared-memory/
OIDC_CLIENT_ID_WEB=replace-me
OIDC_CLIENT_SECRET_WEB=replace-me
OIDC_CLIENT_ID_MCP=replace-me
OIDC_AUDIENCE=shared-memory
# -----------------------------------------------------------------------------
# Database (Postgres 16 + pgvector — pgvector/pgvector:pg16 image)
# -----------------------------------------------------------------------------
POSTGRES_USER=memory
POSTGRES_PASSWORD=replace-me-with-a-strong-password
POSTGRES_DB=memory
# Built automatically by docker-compose from the values above. Override only
# if you point at an external Postgres.
# DATABASE_URL=postgres://memory:...@db:5432/memory
# -----------------------------------------------------------------------------
# Embedder sidecar (added in Phase 2; leave EMBEDDER_URL empty in Phase 1)
# -----------------------------------------------------------------------------
EMBEDDER_URL=
EMBEDDING_MODEL=Xenova/bge-small-en-v1.5
EMBEDDING_DIM=384
# -----------------------------------------------------------------------------
# NextAuth session signing — generate with: openssl rand -base64 32
# -----------------------------------------------------------------------------
NEXTAUTH_SECRET=replace-me-with-32-bytes-of-random
# -----------------------------------------------------------------------------
# CLI token signing key. Used to mint HMAC-signed JWTs from /connect for
# pasting into MCP clients (Claude Code etc.). Rotate to invalidate all
# outstanding CLI tokens at once. Generate with: openssl rand -base64 32
# -----------------------------------------------------------------------------
CLI_TOKEN_SECRET=replace-me-with-32-bytes-of-random
# -----------------------------------------------------------------------------
# App
# -----------------------------------------------------------------------------
LOG_LEVEL=info
# Optional: pin to a specific built image (e.g. for a registry-pushed build).
# IMAGE_REF=registry.example.com/shared-memory-web:0.1.0