Skip to content

[@weaverse/mcp v3] Make live Content API tools explicit and opt-in #2

Description

@paul-phan

Problem

@weaverse/mcp@2.3.1 always registers live page, theme, project, and delete tools. Calls require WEAVERSE_API_KEY, while the README and source comments describe the authenticated account surface as read-only and claim no write tools are exposed.

Scope

  • Require WEAVERSE_ENABLE_LIVE_WRITES=true before registering the existing write/delete tools.
  • Keep read tools available with the current Content API key.
  • Print a startup warning when live writes are enabled.
  • Make the README, package description, source comments, tool names, and MCP annotations describe the released behavior accurately.
  • Preserve Content API authorization and shop/scope enforcement.

Acceptance criteria

  • Default tool discovery excludes every live mutation tool.
  • The flag plus compatible Content API credentials exposes the existing live tools.
  • Missing or incompatible credentials cannot invoke them.
  • One focused registry test proves both modes.
  • Documentation no longer calls a write-capable configuration read-only.

Out of scope

Proposal APIs, changesets, approval/publication tools, Builder proposal infrastructure, and a new authentication system.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

  • Status
    Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions