mcp_server, ai_assistants: drop the --http sections (#1132 closed)

ispyisail
2026-09-29 13:02:53 +13:00
parent 6d5cf52fbd
commit 9ab0fa5357
2 changed files with 0 additions and 87 deletions
-37
@@ -219,43 +219,6 @@ The server speaks MCP over standard input and output.
---
## By web address
> **Status: pending.** This section describes
> [PR #1132](https://github.com/qelectrotech/qelectrotech-source-mirror/pull/1132),
> not yet merged. Nothing here works until that lands — check the PR
> before trying any of this against your own build. This section will drop
> this notice once it does.
Some assistants connect to a server by address instead of starting it. Start
it yourself, on this computer only:
```bash
QET_MCP_WORKSPACE=/path/to/drawings python3 qet_mcp.py --http
python3 qet_mcp.py --show-token
```
and give the assistant `http://127.0.0.1:8731/mcp` with the header
`Authorization: Bearer <token>`. For example in VS Code:
```json
{
"servers": {
"qet": {
"type": "http",
"url": "http://127.0.0.1:8731/mcp",
"headers": { "Authorization": "Bearer ${input:qet-token}" }
}
},
"inputs": [
{ "id": "qet-token", "type": "promptString", "description": "qet-mcp token", "password": true }
]
}
```
It offers only the reading tools unless started with `--allow-edit`. Every
option and what it refuses is on the [MCP server](mcp_server#over-http) page.
## ChatGPT, and Claude or Copilot in a web browser
These reach a server only through the internet, from their own computers.
-50
@@ -72,56 +72,6 @@ above are the only setup that matters, and both are covered below.
---
## Over HTTP
> **Status: pending.** This section describes
> [PR #1132](https://github.com/qelectrotech/qelectrotech-source-mirror/pull/1132),
> not yet merged. Nothing here works until that lands — check the PR
> before trying any of this against your own build. This section will drop
> this notice once it does.
Some assistants connect to a server by web address rather than starting it
themselves. `--http` serves the same tools on this computer only:
```bash
export QET_MCP_WORKSPACE=/home/you/drawings
python3 misc/qet-mcp/qet_mcp.py --http # http://127.0.0.1:8731/mcp
python3 misc/qet-mcp/qet_mcp.py --show-token # the token a client must send
```
The client sends `Authorization: Bearer <token>` with every request; its
setup usually has a "headers" field for it (examples on
[Connecting an AI assistant](ai_assistants#by-web-address)).
| Option | Effect |
|---|---|
| `--http [PORT]` | serve on `127.0.0.1:PORT` (default 8731). It never listens on any other address |
| `--allow-edit` | offer every tool. Without it only the eight that read a file are offered: `qet_project_info`, `qet_elements`, `qet_conductors`, `qet_items`, `qet_diff`, `qet_scan`, `qet_element_info`, `qet_element_search` |
| `--allow-origin ORIGIN` | a web page origin allowed to call, for a client that runs in a browser (repeatable) |
| `--show-token` / `--new-token` | print the token / replace it, which cuts off every client using the old one |
| `QET_MCP_TOKEN_FILE` | where the token is kept. Default: `~/.config/qet-mcp/token`; `%APPDATA%\qet-mcp\token` on Windows; `~/Library/Application Support/qet-mcp/token` on macOS |
What it refuses, before reading a request:
| Refused | Answer | Why |
|---|---|---|
| a `Host` other than `127.0.0.1:PORT` or `localhost:PORT` | 403 | a web page reaching a local server through a name of its own (DNS rebinding) |
| an `Origin` not allowed with `--allow-origin` | 403 | a web page you visit calling it |
| a missing or wrong token | 401 | anyone else on the machine |
| a body over 1 MB, not JSON, or a batch | 413 / 415 / 400 | |
| GET, DELETE and other methods | 405 | no event stream, no sessions |
The token file is created readable by you only; if others can read it, the
server refuses to use it. `QET_MCP_WORKSPACE` must be set, because a server
started by hand from your home folder would otherwise serve all of it.
Every call is logged to standard error with the tool and the paths it was
given, never file contents or the token.
It speaks the protocol versions that begin with `initialize` (2025-03-26 to
2025-11-25). Clients on the newer revision fall back to it.
---
## Using it without Claude Code
Added in