vtcode_core/cli/args/webmcp.rs
1use clap::{Args, Subcommand, ValueHint};
2use std::path::PathBuf;
3
4/// WebMCP bridge command family.
5#[derive(Debug, Clone, Subcommand)]
6pub enum WebmcpCommand {
7 /// Start the standalone WebMCP server.
8 Serve(WebmcpServeArgs),
9 /// Start the server and print a one-time browser pairing code.
10 Pair(WebmcpPairArgs),
11 /// Show configured WebMCP listener status.
12 Status,
13 /// List the safe bridge operations.
14 Tools,
15 /// List configured headless workspace roots.
16 Roots,
17 /// Revoke in-process pairings when used by an embedding runtime.
18 Unpair,
19}
20
21/// Options for the standalone WebMCP server.
22#[derive(Debug, Clone, Args)]
23pub struct WebmcpServeArgs {
24 /// Literal loopback bind host. Remote clients require `--allow-remote` and a TLS-terminating reverse proxy.
25 #[arg(long, value_name = "HOST")]
26 pub host: Option<String>,
27 /// Bind port, or zero for a random available port.
28 #[arg(long, value_name = "PORT")]
29 pub port: Option<u16>,
30 /// Explicit browser origin allowlist. Repeat for multiple origins.
31 #[arg(long = "origin", value_name = "ORIGIN", action = clap::ArgAction::Append)]
32 pub origins: Vec<String>,
33 /// Explicit root exposed by headless mode. One root is supported per bridge.
34 #[arg(long = "allowed-root", value_name = "PATH", value_hint = ValueHint::DirPath, action = clap::ArgAction::Append)]
35 pub allowed_roots: Vec<PathBuf>,
36 /// Enable remote reverse-proxy mode (requires a `wss://` public URL; the listener remains loopback).
37 #[arg(long)]
38 pub allow_remote: bool,
39 /// Public WSS URL advertised for remote pairing.
40 #[arg(long, value_name = "URL")]
41 pub public_url: Option<String>,
42 /// Enable the read-only OpenAI-compatible remote MCP surface.
43 #[arg(long)]
44 pub mcp: bool,
45 /// Canonical external HTTPS URL for the remote MCP `/sse/` endpoint.
46 #[arg(long = "mcp-public-url", value_name = "URL")]
47 pub mcp_public_url: Option<String>,
48 /// External HTTPS OAuth authorization-server URL advertised to MCP clients.
49 #[arg(long = "mcp-authorization-server", value_name = "URL")]
50 pub mcp_authorization_server: Option<String>,
51 /// Environment variable containing the internal bearer token from the proxy.
52 #[arg(long = "mcp-proxy-token-env", value_name = "NAME")]
53 pub mcp_proxy_token_env: Option<String>,
54 /// Optional HTTP(S) URL prefix used for escaped file citation URLs.
55 #[arg(long = "mcp-citation-url-prefix", value_name = "URL")]
56 pub mcp_citation_url_prefix: Option<String>,
57}
58
59/// Options for starting a paired standalone server.
60#[derive(Debug, Clone, Args)]
61pub struct WebmcpPairArgs {
62 /// Browser origin to bind to the one-time pairing code.
63 #[arg(long, value_name = "ORIGIN")]
64 pub origin: String,
65 /// Literal bind host.
66 #[arg(long, value_name = "HOST")]
67 pub host: Option<String>,
68 /// Bind port, or zero for a random available port.
69 #[arg(long, value_name = "PORT")]
70 pub port: Option<u16>,
71 /// Enable remote reverse-proxy mode (requires a `wss://` public URL; the listener remains loopback).
72 #[arg(long)]
73 pub allow_remote: bool,
74 /// Public WSS URL advertised for remote pairing.
75 #[arg(long, value_name = "URL")]
76 pub public_url: Option<String>,
77}