Add MCP server for the roadmap - #364
Merged
Merged
Conversation
Adds a laravel/mcp server at /mcp, authenticated with Sanctum tokens that users can create and revoke on their profile page. Tools respect the same visibility rules as the site, and moving items is limited to admins and employees.
MCP is off by default. Admins enable it under Settings > MCP. While it's off the endpoint returns a 404 and the profile token section is hidden. The new /mcp/docs page explains how to create a token and connect a client, and lists the available tools.
…tings The docs page and the MCP settings tab now share the same instructions for Claude Code, Claude Desktop, ChatGPT, Cursor, VS Code and Codex. They show up in the settings once MCP is enabled.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds an MCP server built on
laravel/mcp, so AI assistants (Claude, Cursor, etc.) can work with the roadmap as the user that owns the token.Enabling
MCP is off by default. Admins turn it on under Settings → MCP. While it's off:
POST /mcpreturns a 404, even with a valid token/mcp/docsreturns a 404, except for admins and employees, who see it with a notice that MCP is disabledDocs
/mcp/docsexplains what the assistant can do, how to create a token and how to connect a client. It also lists the tools, read fromRoadmapServer::TOOLS. The connection instructions have a tab per client, with copyable snippets:claude mcp add --transport http …claude_desktop_config.jsonviamcp-remote. The web version (claude.ai) only supports OAuth connectors, and the page says so.The MCP tab in the admin settings shows the same instructions and tool list as soon as the toggle is switched on. The instructions live in shared components (
resources/views/components/mcp/*), andadmin.csssources them so Tailwind picks up their classes.Endpoint & auth
POST /mcp, protected byauth:sanctumand theapirate limiter.expires_atcolumn topersonal_access_tokens. The table predates Sanctum 3, and token creation fails without it.Tools
list-projectsget-projectlist-itemslatest,popular,last_commented), paginatedget-itemcomment-on-itemmove-itemAll lookups use the existing
visibleForCurrentUserscopes, so private projects and items stay hidden exactly as on the site. Comments go throughComment::create, so mentions and notifications work the same as on the site.Notes
Mcp::oauthRoutes(), which can come in a follow-up.Tests
tests/Feature/Mcp/*: visibility, filters, commenting rules, move permissions, and HTTP auth plus tool listing per roletests/Feature/Livewire/ProfileMcpTokensTest.php: create, show once, revoke only your own tokens, hidden when disabledtests/Feature/Controllers/McpControllerTest.php: docs page for guests and users, 404 when disabled, admin/employee access when disabledtests/Feature/Filament/McpSettingsTest.php: off by default, admins can turn it on, instructions only show once it's on