Problem
@weaverse/mcp@2.3.1 always registers live page, theme, project, and delete tools. Calls require WEAVERSE_API_KEY, while the README and source comments describe the authenticated account surface as read-only and claim no write tools are exposed.
Scope
- Require
WEAVERSE_ENABLE_LIVE_WRITES=true before registering the existing write/delete tools.
- Keep read tools available with the current Content API key.
- Print a startup warning when live writes are enabled.
- Make the README, package description, source comments, tool names, and MCP annotations describe the released behavior accurately.
- Preserve Content API authorization and shop/scope enforcement.
Acceptance criteria
Out of scope
Proposal APIs, changesets, approval/publication tools, Builder proposal infrastructure, and a new authentication system.
Problem
@weaverse/mcp@2.3.1always registers live page, theme, project, and delete tools. Calls requireWEAVERSE_API_KEY, while the README and source comments describe the authenticated account surface as read-only and claim no write tools are exposed.Scope
WEAVERSE_ENABLE_LIVE_WRITES=truebefore registering the existing write/delete tools.Acceptance criteria
Out of scope
Proposal APIs, changesets, approval/publication tools, Builder proposal infrastructure, and a new authentication system.