fix(mcp): open guest signup instead of authenticated checkout - #73
cursor[bot] wants to merge 1 commit into
Conversation
POST /api/v1/checkout/sessions now requires a connect token, so microlink_create_checkout_session always returned 401. Use the public signup endpoint and strip apiKey from poll results.
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Coverage Report for CI Build 36668051068Warning No base build found for commit Coverage: 80.789%Details
Uncovered ChangesNo uncovered changes found. Coverage RegressionsRequires a base build to compare against. How to fix this → Coverage Stats
💛 - Coveralls |
Bug and impact
microlink_create_checkout_sessionalways failed with 401 Unauthorized. Agents could not buy a key through MCP: the tool posted toPOST /api/v1/checkout/sessions, which now requires a CLI connect token.Trigger: ask an assistant to buy Microlink. It calls
microlink_create_checkout_sessionand the dashboard rejects the request. Checkout never starts.Root cause
Gateway #223 locked sessions POST behind
verifyConnectToken. CLImicrolink buywas updated to mint a token via/connect. MCP has no local handshake, so it kept calling the now-private route. The leftover public path isPOST /api/v1/checkout/signup(dashboard Sign up).Fix
/api/v1/checkout/signup(guest, Stripe collects email, starter creatable plan).email/planIdinputs so old agent calls still validate, but do not send them.apiKeyfrom poll results so the secret does not land in MCP logs (welcome email / dashboard).{ state }plus optionalexpiresAton create).Validation
node --test test/*.test.jsinpackages/mcp(121 passed, 8 live skipped).Note:
microlinkhq/skillsis not in this workspace.microlink-mcp/SKILL.mdshould drop requiredemail/planIdon create if that companion still documents them.