Ported from the Android edition's server:
- JSON-RPC notifications (requests without an id, e.g.
notifications/initialized) now get the bare HTTP 202 the MCP spec
requires instead of a malformed JSON-RPC error response, which strict
clients rejected.
- initialize echoes the client's requested protocolVersion when it is a
version we support (2024-11-05 / 2025-03-26 / 2025-06-18) instead of
always claiming 2025-03-26.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Publishes server work that shipped in the Android edition but never made
it to this repo:
- Full OAuth 2.0 flow (discovery metadata, dynamic client registration,
authorize + token endpoints) so claude.ai remote connectors and the
Android app can authenticate per-user instead of relying on the
sole-phone fallback.
- Safety governor: server-side heat model (intensity x time) with
automatic cooldown, per-user overrides via GET/POST /safety/config,
and governor state piggybacked on heartbeat pings so relay clients
can display it.
- SB_REQUIRE_MCP_AUTH env flag for multi-user deployments (disables the
unauthenticated sole-phone fallback).
- requirements-phone.txt and .env.example documenting the new knobs.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The March upload accidentally included server/__pycache__/*.pyc (stale
compiled bytecode) and a prebuilt deploy tarball. The README already
instructs users to build their own bundle, so neither belongs in git.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>