Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for Kagura Memory Cloud

Pod holds 21 of 58 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to Kagura Memory Cloud.

Most discussed

Shared-context MCP reads fail when caller workspace has no API key

Summary

When an admin (or any user who is not the workspace owner) reads a shared context via MCP (recall, explore, analyze_context, reference), the embedding-key lookup is keyed on the caller's User.current_workspace_id rather than the context's workspace_id. If the caller's own workspace has no ExternalAPIKey configured, the request fails with:

OpenAI API key not configured for workspace {workspace_id}.
Configure a workspace OpenAI API key in settings...

—…

Read the thread · 2026-05-18 · closed · 3 comments

mcp: ChatGPT stops after server/discover on v0.67.0 — client is modern-only, server must speak MCP 2026-07-28 (dual-era)

Symptom

After v0.67.0 (#1541 / #1542), registering the server as a ChatGPT custom connector still fails ("Something went wrong with setting up the connection"). The 500 is gone; the failure moved one step later.

Evidence (production API log, UTC, two registration attempts on v0.67.0)

06:13:32 POST /api/v1/oauth/token 200
06:13:33 POST /mcp                          401  (unauthenticated probe → WWW-Authenticate)
06:13:33 GET /.well-known/oauth-protected-resource /…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1544) · 2026-09-18 · closed · 2 comments

### feat(auth): support OAuth Bearer tokens on REST /api/v1/* endpoints

## Summary

The REST API layer at `/api/v1/*` does not validate OAuth access tokens issued by the device-flow login (`kagura auth login`). Only the `/mcp` endpoint honors OAuth Bearer tokens today.

As a result, SDK CLI commands that use REST transports — `kagura files list`, `kagura files upload`, `kagura resource list`, `kagura resource import`, etc. — **fail against production for any user authenticated via OAuth only**. The workaround is to put a long-lived API key (`kagura_...`) in…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/649) · 2026-05-14 · closed · 2 comments

### fix(cli): create_admin fails on .mcp.json write when running in Docker container

## Summary

**⚠️ Severity correction (2026-04-06)**: original issue marked this as "severity: low", but code inspection shows `db.commit()` runs **after** `_write_mcp_json()`, so the `PermissionError` triggers a session rollback and **silently drops the entire admin creation** (user + workspace + API key + TOTP secret + embedding provider config). The original trace above showed only the file-write failure because the DB rollback happens silently on session exit. **Actual severity: high —…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/194) · 2026-04-06 · closed · 2 comments

### fix(mcp): keep memory writes user-directed for Directory 1.D and 1.F

## Problem

An audit of v0.80.0 against the Directory policy (item: no retrieval of Claude's memory, chat history, conversation summaries or uploaded files) found no path by which the server reads such data. `SERVER_CAPABILITIES` is `{"tools": {}}` (`backend/src/mcp_server/transport.py:223`), the server sends no sampling, roots or elicitation requests, and data enters only as `tools/call` arguments. Memories are client-authored: the client composes the content and submits it with `remember`,…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1721) · 2026-09-26 · closed · 1 comment

### fix(mcp): sleep rollback TypeError + setup_resource None return

Two functional bugs in `backend/src/mcp_server/tools/`, both surfaced by running
`make type-check` (`pyright src/`) — which is configured in this repo but **not run by CI**.
Neither is caught by ruff or by the 6 433-test suite.

Found while auditing for #1437; see the correction comment there.

---

## Bug 1 — `sleep.py:400` raises `TypeError` during sleep-run rollback

`mcp_server/tools/sleep.py:24` binds the **stdlib** logger:

```python
logger = logging.getLogger(__name__)

but line 400…

Read the thread · 2026-07-26 · closed · 1 comment

fix(mcp): Context.last_used_at is never updated - list_contexts recency sort is meaningless

Problem

Context.last_used_at (backend/src/models/auth.py, added in #169, DateTime(timezone=True), server_default=func.now()) is returned by MCP list_contexts and drives its "recent usage" sort (backend/src/mcp_server/tools/context.py:588-623), but no code path ever updates it after row creation.

Evidence (grep over backend/src):

Read the thread · 2026-07-14 · closed · 1 comment

feat(mcp): read-only MCP tools list_my_bindings / describe_binding (#626 follow-up)

Summary

Add the two read-only MCP tools that were intentionally deferred from #626 (PR #628) to keep the main PR shippable:

Both are read-only. Credential mint…

Read the thread · 2026-05-13 · closed · 1 comment

Most recent

fix(mcp): bound the remaining unbounded tool responses

Overview

#1685 bounded reference. The v0.80.0 re-audit found other tools whose responses have no size bound, several of them on a default call. Claude clients cap tool results at about 150k characters (claude.ai) and 25k tokens (Claude Code); an oversized result is cut or saved to a file instead of reaching the model. None of the affected files has changed since (checked at v0.81.0).

Evidence

Code links are at 212ae467 (v0.81.0). Sizes are worst-case estimates from the audit's…

Read the thread · 2026-09-27 · closed · 0 comments

fix(mcp): 503 on auth outages and actionable errors on remaining paths

Overview

#1684 made tool failures actionable on the main dispatch path. The v0.80.0 re-audit found paths it did not reach: authentication faults reported as bad credentials with raw exception text, ValueError subclasses echoed as caller errors, unknown arguments silently ignored, and a few generic 500s. None of the affected files has changed since (checked at v0.81.0).

Evidence

Code links are at 212ae467 (v0.81.0).

Read the thread · 2026-09-27 · closed · 0 comments

fix(auth): loopback ports, consent redirect host, revoke and introspect auth

Overview

Close the OAuth gaps the v0.80.0 re-audit found against Claude's connector authentication docs, the MCP authorization security considerations and RFC 8252 / 7009 / 7662. None of the affected files has changed since (checked at v0.81.0).

Evidence

Code links are at 212ae467 (v0.81.0).

Read the thread · 2026-09-27 · closed · 0 comments

fix(mcp): validate Origin and align Streamable HTTP sessions and versions

Overview

Bring the Streamable HTTP transport in line with the MCP spec requirements the Anthropic Software Directory review checks. The v0.80.0 re-audit found five transport gaps; none of the affected files has changed since (checked at v0.81.0).

Evidence

Code links are at 212ae467 (v0.81.0).

Read the thread · 2026-09-27 · closed · 0 comments

fix(auth): reword the session-only refusal without "bearer"

Problem

require_session_auth is the SessionUser dependency (backend/src/auth/dependencies.py:426, alias at :949). It refuses any Authorization: Bearer … credential, whether a kagura_ API key or an OAuth access token, at dependencies.py:470-476:

403 {"error": "HTTP-403",
     "message": "Bearer tokens (API keys or OAuth) are not allowed for Web UI endpoints. Use browser session authentication.",
     "details": {}}

The response has no WWW-Authenticate header. The…

Read the thread · 2026-09-26 · closed · 0 comments

feat(plugin): add a login skill for Claude Code and Codex

Problem

Re-authenticating the Kagura Memory MCP connection is a recurring task: an expired or revoked token (401 invalid_token), a new machine, a workspace change, or a token narrowed to memory:read that now gets 403 insufficient_scope on write tools (#1686, v0.79.0). Today the only guidance lives inside /kagura-memory:setup. That skill is a large, first-time setup flow, so it is heavy for this recurring step.

Proposal

Add a focused login skill to the kagura-memory plugin for…

Read the thread · 2026-09-25 · closed · 0 comments

fix(mcp): bound reference responses with selective retrieval

Overview

Give callers a bounded way to retrieve memory details. reference currently returns all content/details with no field selection, output bound or continuation mechanism.

Evidence

At audit commit cea425079e190bbb144af4d336b7958470b94951:

Read the thread · 2026-09-24 · closed · 0 comments

mcp: ChatGPT コネクタ登録が失敗 — server/discover 等の未知 method が transport fallthrough で 500

症状

ChatGPT でカスタム MCP コネクタ(https://memory.kagura-ai.com/mcp)を登録すると、OAuth 同意まで通った直後に失敗する。2026-09-17 と 2026-09-18 に計 4 回試行、全部同じ落ち方。

本番ログ(kagura-api-blue, v0.66.0)

OAuth は完走している:

  1. POST /api/v1/oauth/register → 201(dcr_client_registered, provider=chatgpt)
  2. GET/POST /api/v1/oauth/authorize → 200 / 303
  3. POST /api/v1/oauth/token → 200

直後の最初の MCP リクエストで 500:

MCP session creating: mcp-… (user=…, workspace=…)
MCP request (Streamable HTTP): method=server/discover,…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1541) · 2026-09-18 · closed · 0 comments

### fix(worker-apps): validate the signing secret's shape — a placeholder string was accepted and broke production webhook verification

## What happened

On 2026-08-02 a signing-secret rotation was performed against
`POST /api/v1/admin/worker-apps/slack/default/rotate-secret`. The request body
carried a **placeholder string** instead of the real secret — the snippet's
`"…paste the new signing secret here…"` was submitted verbatim.

The API returned **200**. The placeholder was encrypted and stored as the
`active` signing secret.

Every subsequent Slack webhook failed signature verification. When the
`retiring` window elapsed,…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1478) · 2026-08-03 · closed · 0 comments

### feat(frontend): expose memory_link_template in the connector runtime UI — it is readable but not writable

## Problem

`WorkerRuntimeConfig.memory_link_template` can be persisted via
`PATCH /api/v1/workspace-connectors/{id}/runtime` and is surfaced in the
frontend type (`workspace-connectors.ts`: `memory_link_template: string | null`),
but **there is no UI to set it**.

`updateConnectorRuntime` has exactly one call site —
`handleVisionEnabledChange` in
`frontend/src/app/(authenticated)/workspace/integrations/connectors/page.tsx`.
So the connectors page can edit exactly one runtime field:…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1471) · 2026-08-01 · closed · 0 comments

### fix(mcp): rollback reports success when a merge action could not be reversed

Follow-up to #1440 / PR #1441. Found by a belated second-opinion review of the merged diff.

## The gap

`services/sleep/undo.py:revert_shadow_merge_edge()` returns `False` for **two materially different
situations** — its own docstring says so:

Returns: True if an edge was restored or deleted; False if nothing matched (the shadow merge was already undone, or the edge was retyped by a later writer).


1. **already undone** — benign. The rollback has nothing to do; logging…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1450) · 2026-07-28 · closed · 0 comments

### fix(mcp): supersede-candidate lifecycle gaps (detect/accept/docstring)

## Summary

Three confirmed lifecycle gaps in the #1403 supersede-candidate feature (all adversarial-panel CONFIRMED).

### F2 — detection silently skipped when the new memory already has any outgoing edge (Low)

In `backend/src/services/memory_service.py`, the supersede-candidate detection block (~4420-4454) sits **after** the pre-existing `existing_edges` idempotency early-return in `_create_knn_seed_edges` (~4394-4407, which returns if the memory has **any** outgoing edge). Because…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1422) · 2026-07-21 · closed · 0 comments

### fix(db): e74 CHECK rebuild locks memory_access_events (no NOT VALID)

## Summary

`backend/alembic/versions/e74_1401_mae_explore.py` (added in-range by #1400) widens the `valid_mae_operation` CHECK constraint on `memory_access_events` to allow `'explore'`. Both `upgrade()` and `downgrade()` do `op.drop_constraint(...)` + `op.create_check_constraint(...)`. `op.create_check_constraint` emits a plain `ALTER TABLE ... ADD CONSTRAINT ... CHECK (...)` with **no `NOT VALID`** — so Postgres holds `ACCESS EXCLUSIVE` on the table and validates every existing row before…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1421) · 2026-07-21 · closed · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/kagura-ai/memory-cloud/issues).