magi-code 0.96.2

Repository-aware CLI coding agent for terminal work
Documentation
# MCP guide

Connects approved servers, discovers schemas and routes cancellable tool requests.

## Where to look

| Change | Owner |
| --- | --- |
| Initialization and request lifecycle | `client.rs`, `protocol.rs`, `jsonrpc.rs` |
| Bad-server isolation and routing | `manager.rs` |
| Qualified names and schema conversion | `names.rs`, `tool_schema.rs` |
| Child/HTTP/notification transport | `stdio.rs`, `http.rs`, `sse.rs` |
| Literal header validation/redaction | `headers.rs` |
| OAuth discovery/login/storage/refresh | `oauth.rs`, `oauth/{discovery,login,storage,tokens}.rs` |

## Local contracts

- Protocol version is `2025-03-26`; validate at protocol/client boundary. `QualifiedMcpToolName` encodes `mcp__server__tool` within 64 bytes using nonempty ASCII components without `__`; server names cannot end in `_`.
- Manager isolates bad servers and detects duplicate routes. Never advertise ambiguous names.
- Stdio uses newline JSON-RPC, not LSP Content-Length. Preserve 1 MiB frame cap and fail pending requests on EOF.
- POST accepts JSON/SSE and carries HTTP session ID. GET-SSE notifications are best effort: unsupported GET cannot break POST. Preserve isolated runtime cancellation/shutdown and HTTP-session DELETE teardown.
- Request timeout terminates connection rather than leaving it reusable. Shared `Arc<McpClient>` requests may overlap: remote calls stay outside teardown locks, close admission and fail siblings before cleanup. Serialize shared OAuth refreshes, not tool calls.
- Settings own structural parsing, one-time environment expansion and approval; see `../config/AGENTS.md`. Runtime validates resulting literal headers without re-expansion and redacts every header value in every output path.
- OAuth storage stays behind private facade, with token locks and protected files under configured home.