Skip to content

fix(mcp): open guest signup instead of authenticated checkout - #73

Draft
cursor[bot] wants to merge 1 commit into
masterfrom
cursor/critical-bug-management-c653
Draft

cursor[bot] wants to merge 1 commit into
masterfrom
cursor/critical-bug-management-c653

Conversation

@cursor

@cursor cursor Bot commented Sep 30, 2026

Copy link
Copy Markdown

Bug and impact

microlink_create_checkout_session always failed with 401 Unauthorized. Agents could not buy a key through MCP: the tool posted to POST /api/v1/checkout/sessions, which now requires a CLI connect token.

Trigger: ask an assistant to buy Microlink. It calls microlink_create_checkout_session and the dashboard rejects the request. Checkout never starts.

Root cause

Gateway #223 locked sessions POST behind verifyConnectToken. CLI microlink buy was updated to mint a token via /connect. MCP has no local handshake, so it kept calling the now-private route. The leftover public path is POST /api/v1/checkout/signup (dashboard Sign up).

Fix

  • Create sessions via /api/v1/checkout/signup (guest, Stripe collects email, starter creatable plan).
  • Accept leftover email / planId inputs so old agent calls still validate, but do not send them.
  • Strip apiKey from poll results so the secret does not land in MCP logs (welcome email / dashboard).
  • Align the checkout output schema with the real dashboard poll body ({ state } plus optional expiresAt on create).

Validation

node --test test/*.test.js in packages/mcp (121 passed, 8 live skipped).

Note: microlinkhq/skills is not in this workspace. microlink-mcp/SKILL.md should drop required email / planId on create if that companion still documents them.

Open in Web View Automation 

POST /api/v1/checkout/sessions now requires a connect token, so
microlink_create_checkout_session always returned 401. Use the public
signup endpoint and strip apiKey from poll results.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: da418600-4f33-4bca-9566-9f10e58e128d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 36668051068

Warning

No base build found for commit f4eb879 on master.
Coverage changes can't be calculated without a base build.
If a base build is processing, this comment will update automatically when it completes.

Coverage: 80.789%

Details

  • Patch coverage: 20 of 20 lines across 6 files are fully covered (100%).

Uncovered Changes

No uncovered changes found.

Coverage Regressions

Requires a base build to compare against. How to fix this →


Coverage Stats

Coverage Status
Relevant Lines: 5952
Covered Lines: 4834
Line Coverage: 81.22%
Relevant Branches: 1023
Covered Branches: 801
Branch Coverage: 78.3%
Branches in Coverage %: Yes
Coverage Strength: 28.84 hits per line

💛 - Coveralls

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants