Skip to content

feat(server): MCP tools for settings, providers, git, pull requests, terminals, projects, pin order, and opening threads - #15445

Closed
maria-rcks wants to merge 20 commits into
pingdotgg:t3code/mcp-oauth/thread-targetsfrom
maria-rcks:t3code/mcp-app-control-followups
Closed

maria-rcks wants to merge 20 commits into
pingdotgg:t3code/mcp-oauth/thread-targetsfrom
maria-rcks:t3code/mcp-app-control-followups

Conversation

@maria-rcks

@maria-rcks maria-rcks commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked on #15428, which is stacked on #15219. GitHub can't target #15428's fork branch, so this PR is based on t3code/mcp-oauth/thread-targets and also shows #15428's commits. The new work is everything after #15428's commits.

Problem

After #15428, an MCP client still couldn't do much of what the app does. It couldn't change settings or keybindings, check providers and quota, run git or PR actions, use terminals, browse host folders to add a project, reorder pins, or open a thread in the user's window.

Change

Each tool is a thin wrapper over the service its WS method already uses. Anything that changes the environment, runs commands, pushes code, or reveals host paths needs a full-access caller.

  • Settings: t3_environment_read can include the full server settings (credentials redacted) and keybindings. t3_environment_preferences_update accepts any non-credential settings patch, a provider instance toggle or custom models, and keybinding upsert/remove. Credential fields, providerInstances and deviceHosts are rejected and stay in the Settings UI. Reads only return each provider instance's customModels from its opaque driver config, and strip credentials from settings URLs. Keybinding rule matching in the keybindings service now compares when expressions and shortcut spellings by meaning, so a listed rule always removes the stored one. The Settings UI gets the same fix.
  • Providers: t3_provider_status (full access, since messages can carry configured URLs) returns install, auth and version per instance, plus rate-limit windows and optional token/cost usage. t3_provider_refresh re-runs the provider checks. There's no login or logout over MCP, since an agent can't complete a sign-in.
  • Git: t3_git_status (read-only, full access because a cold status cache fetches) and t3_git (create/switch branch, pull, and the app's commit/push/open-PR flow). There's no merge or force-push.
  • Pull requests: t3_pull_request_read returns the overview, checks, conversation or a review thread, within a character budget. t3_pull_request_update can comment, reply, resolve or unresolve, request reviewers, and set labels. Reviewer names are matched against the host's candidates. GitHub and Forgejo take logins as given, and on GitLab and Bitbucket an unmatched name must be the host's own id. Merge, close, review approval and title/body edits are left out.
  • Terminals: t3_terminal_list, t3_terminal_read (scrollback with escape codes stripped, full access because output can hold secrets) and t3_terminal_control (open/write/close the same terminals the panel shows). Open attaches to a running shell instead of restarting it.
  • Projects: t3_folder_browse, t3_agent_session_scan and t3_agent_session_import. Creating a new or scratch project already works through t3_project_create and t3_thread_launch.
  • Pin order: t3_thread_organize gets move_pinned and move_active with beforeThreadId. The order-key helpers moved from client-runtime to @t3tools/shared/threadOrderKeys, and client-runtime re-exports them, so web and mobile are unchanged.
  • Open in client: t3_client_open_thread {threadId, panel?} goes through a new subscribeClientIntents stream. The window that acts is the desktop window that most recently reported focus to the preview broker (that history survives reconnects), or failing that a visible, focused window. So an outside agent in a terminal can still bring up a thread. Mobile doesn't act on it yet.
  • Fixes the existing t3_environment_preferences_update crash (Service not found: ThreadCommandExecutor), the same one-line wiring as fix(mcp): allow environment preference updates #15337.

Verification

  • Typecheck passes for server, contracts, shared, client-runtime and web. The MCP, CLI, adapter-allowlist, thread-sort and presentation tests pass, and lint is clean. A new case in core.test.ts checks that settings reads never contain credentials.
  • I ran it live in a dev app, with a full-access Claude Sonnet 5.5 thread calling each tool:

settings and keybinding writes round-trip

git status and pull request reads

terminal open, write, read, list, close

folder browse and agent session scan

pinned order before the move

pinned order after move_pinned

Not verified:

Written by claude-opus-5-5 in Claude Code, running in T3 Code.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Oct 4, 2026
Comment thread apps/server/src/mcp/toolkits/environment/handlers.ts
Comment thread apps/server/src/orchestration-v2/Adapters/ClaudeAdapterV2.ts
Comment thread apps/server/src/mcp/toolkits/environment/handlers.ts
Comment thread apps/server/src/mcp/toolkits/git/handlers.ts
Comment thread apps/server/src/mcp/toolkits/terminal/handlers.ts
Comment thread apps/server/src/mcp/toolkits/environment/handlers.ts Outdated
Comment thread apps/server/src/mcp/toolkits/thread/handlers.ts
Comment thread apps/server/src/mcp/toolkits/pullRequests/handlers.ts Outdated
Comment thread apps/server/src/mcp/toolkits/review/handlers.ts Outdated
Comment thread packages/contracts/src/rpc.ts
@macroscopeapp

macroscopeapp Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a large cross-cutting MCP capability spanning host access, terminals, Git, pull requests, providers, settings, approvals, and client navigation, including externally visible and destructive operations. It also changes authorization plumbing, so the scope and security-sensitive runtime impact require human review.

You can add or adjust custom eligibility rules. Learn more.

Comment thread apps/server/src/mcp/toolkits/environment/handlers.ts
Comment thread apps/server/src/mcp/toolkits/thread/handlers.ts Outdated
…movals, resolve team reviewers, target by focus recency
Comment thread apps/server/src/mcp/toolkits/environment/handlers.ts Outdated
Comment thread apps/server/src/mcp/PreviewAutomationBroker.ts Outdated
Comment thread apps/server/src/mcp/toolkits/environment/handlers.ts
Comment thread apps/server/src/mcp/toolkits/environment/handlers.ts
Comment thread apps/server/src/keybindings.ts Outdated
@maria-rcks

Copy link
Copy Markdown
Collaborator Author

Note

Written by claude-opus-5-5 on behalf of Maria

Moved to #15465, stacked on #15464 (GitHub stack #15466): same head (5dcdaaa), now on a pingdotgg branch, so it targets its parent and shows only its own commits. Review threads here are resolved or answered.

@maria-rcks maria-rcks closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL 1,000+ changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant