# Reported issues for Kagura Memory Cloud

Pod holds 21 of 58 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [Kagura Memory Cloud](/mcp/kagura-memory-cloud).

## Most discussed

### Shared-context MCP reads fail when caller workspace has no API key

## Summary

When an admin (or any user who is not the workspace owner) reads a shared context via MCP (`recall`, `explore`, `analyze_context`, `reference`), the embedding-key lookup is keyed on the **caller's** `User.current_workspace_id` rather than the **context's** `workspace_id`. If the caller's own workspace has no `ExternalAPIKey` configured, the request fails with:

```
OpenAI API key not configured for workspace {workspace_id}.
Configure a workspace OpenAI API key in settings...
```

—…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/708) · 2026-05-18 · closed · 3 comments

### mcp: ChatGPT stops after server/discover on v0.67.0 — client is modern-only, server must speak MCP 2026-07-28 (dual-era)

## Symptom

After v0.67.0 (#1541 / #1542), registering the server as a ChatGPT custom connector still fails ("Something went wrong with setting up the connection"). The 500 is gone; the failure moved one step later.

## Evidence (production API log, UTC, two registration attempts on v0.67.0)

```
06:13:32 POST /api/v1/oauth/token 200
06:13:33 POST /mcp                          401  (unauthenticated probe → WWW-Authenticate)
06:13:33 GET /.well-known/oauth-protected-resource /…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1544) · 2026-09-18 · closed · 2 comments

### feat(auth): support OAuth Bearer tokens on REST /api/v1/* endpoints

## Summary

The REST API layer at `/api/v1/*` does not validate OAuth access tokens issued by the device-flow login (`kagura auth login`). Only the `/mcp` endpoint honors OAuth Bearer tokens today.

As a result, SDK CLI commands that use REST transports — `kagura files list`, `kagura files upload`, `kagura resource list`, `kagura resource import`, etc. — **fail against production for any user authenticated via OAuth only**. The workaround is to put a long-lived API key (`kagura_...`) in…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/649) · 2026-05-14 · closed · 2 comments

### fix(cli): create_admin fails on .mcp.json write when running in Docker container

## Summary

**⚠️ Severity correction (2026-04-06)**: original issue marked this as "severity: low", but code inspection shows `db.commit()` runs **after** `_write_mcp_json()`, so the `PermissionError` triggers a session rollback and **silently drops the entire admin creation** (user + workspace + API key + TOTP secret + embedding provider config). The original trace above showed only the file-write failure because the DB rollback happens silently on session exit. **Actual severity: high —…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/194) · 2026-04-06 · closed · 2 comments

### fix(mcp): keep memory writes user-directed for Directory 1.D and 1.F

## Problem

An audit of v0.80.0 against the Directory policy (item: no retrieval of Claude's memory, chat history, conversation summaries or uploaded files) found no path by which the server reads such data. `SERVER_CAPABILITIES` is `{"tools": {}}` (`backend/src/mcp_server/transport.py:223`), the server sends no sampling, roots or elicitation requests, and data enters only as `tools/call` arguments. Memories are client-authored: the client composes the content and submits it with `remember`,…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1721) · 2026-09-26 · closed · 1 comment

### fix(mcp): sleep rollback TypeError + setup_resource None return

Two functional bugs in `backend/src/mcp_server/tools/`, both surfaced by running
`make type-check` (`pyright src/`) — which is configured in this repo but **not run by CI**.
Neither is caught by ruff or by the 6 433-test suite.

Found while auditing for #1437; see the correction comment there.

---

## Bug 1 — `sleep.py:400` raises `TypeError` during sleep-run rollback

`mcp_server/tools/sleep.py:24` binds the **stdlib** logger:

```python
logger = logging.getLogger(__name__)
```

but line 400…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1440) · 2026-07-26 · closed · 1 comment

### fix(mcp): Context.last_used_at is never updated - list_contexts recency sort is meaningless

## Problem

`Context.last_used_at` (`backend/src/models/auth.py`, added in #169, `DateTime(timezone=True)`, `server_default=func.now()`) is returned by MCP `list_contexts` and drives its "recent usage" sort (`backend/src/mcp_server/tools/context.py:588-623`), but **no code path ever updates it after row creation**.

Evidence (grep over `backend/src`):

- The only `.last_used_at = utcnow()` assignments are on API keys, share keys, resource tokens, account links, and memories — never on…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1257) · 2026-07-14 · closed · 1 comment

### feat(mcp): read-only MCP tools list_my_bindings / describe_binding (#626 follow-up)

## Summary

Add the two read-only MCP tools that were intentionally deferred from #626 (PR #628) to keep the main PR shippable:

- **`mcp__kagura-memory__list_my_bindings`** — list the calling principal's public-bound API keys (owner of the keys, not the bound contexts). Returns `[{key_id, name, context_id, context_name, created_at}]`.
- **`mcp__kagura-memory__describe_binding`** — given a `key_id` or `context_id`, return the same shape plus `prefix`.

Both are **read-only**. Credential mint…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/629) · 2026-05-13 · closed · 1 comment

## Most recent

### fix(mcp): bound the remaining unbounded tool responses

## Overview

#1685 bounded `reference`. The v0.80.0 re-audit found other tools whose responses have no size bound, several of them on a default call. Claude clients cap tool results at about 150k characters (claude.ai) and 25k tokens (Claude Code); an oversized result is cut or saved to a file instead of reaching the model. None of the affected files has changed since (checked at v0.81.0).

## Evidence

Code links are at `212ae467` (v0.81.0). Sizes are worst-case estimates from the audit's…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1743) · 2026-09-27 · closed · 0 comments

### fix(mcp): 503 on auth outages and actionable errors on remaining paths

## Overview

#1684 made tool failures actionable on the main dispatch path. The v0.80.0 re-audit found paths it did not reach: authentication faults reported as bad credentials with raw exception text, `ValueError` subclasses echoed as caller errors, unknown arguments silently ignored, and a few generic 500s. None of the affected files has changed since (checked at v0.81.0).

## Evidence

Code links are at `212ae467` (v0.81.0).

- **Auth outage → 401 with raw text.** Any non-auth exception…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1742) · 2026-09-27 · closed · 0 comments

### fix(auth): loopback ports, consent redirect host, revoke and introspect auth

## Overview

Close the OAuth gaps the v0.80.0 re-audit found against Claude's connector authentication docs, the MCP authorization security considerations and RFC 8252 / 7009 / 7662. None of the affected files has changed since (checked at v0.81.0).

## Evidence

Code links are at `212ae467` (v0.81.0).

- **Loopback redirect port must match exactly.**…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1741) · 2026-09-27 · closed · 0 comments

### fix(mcp): validate Origin and align Streamable HTTP sessions and versions

## Overview

Bring the Streamable HTTP transport in line with the MCP spec requirements the Anthropic Software Directory review checks. The v0.80.0 re-audit found five transport gaps; none of the affected files has changed since (checked at v0.81.0).

## Evidence

Code links are at `212ae467` (v0.81.0).

- **No Origin validation.** [`mcp_asgi_app`](https://github.com/kagura-ai/memory-cloud/blob/212ae467a495f4d991b6fd73b737542c16973fa1/backend/src/mcp_server/transport.py#L1099-L1121) never reads…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1740) · 2026-09-27 · closed · 0 comments

### fix(auth): reword the session-only refusal without "bearer"

## Problem

`require_session_auth` is the `SessionUser` dependency (`backend/src/auth/dependencies.py:426`, alias at `:949`). It refuses any `Authorization: Bearer …` credential, whether a `kagura_` API key or an OAuth access token, at `dependencies.py:470-476`:

```
403 {"error": "HTTP-403",
     "message": "Bearer tokens (API keys or OAuth) are not allowed for Web UI endpoints. Use browser session authentication.",
     "details": {}}
```

The response has no `WWW-Authenticate` header. The…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1719) · 2026-09-26 · closed · 0 comments

### feat(plugin): add a login skill for Claude Code and Codex

## Problem

Re-authenticating the Kagura Memory MCP connection is a recurring task: an expired or revoked token (`401 invalid_token`), a new machine, a workspace change, or a token narrowed to `memory:read` that now gets `403 insufficient_scope` on write tools (#1686, v0.79.0). Today the only guidance lives inside `/kagura-memory:setup`. That skill is a large, first-time setup flow, so it is heavy for this recurring step.

## Proposal

Add a focused `login` skill to the kagura-memory plugin for…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1704) · 2026-09-25 · closed · 0 comments

### fix(mcp): bound reference responses with selective retrieval

## Overview

Give callers a bounded way to retrieve memory details. reference currently returns all content/details with no field selection, output bound or continuation mechanism.

## Evidence

At audit commit `cea425079e190bbb144af4d336b7958470b94951`:

- [reference projection](https://github.com/kagura-ai/memory-cloud/blob/cea425079e190bbb144af4d336b7958470b94951/backend/src/mcp_server/tools/memory.py#L1153) returns content/details in full.
-…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1685) · 2026-09-24 · closed · 0 comments

### mcp: ChatGPT コネクタ登録が失敗 — server/discover 等の未知 method が transport fallthrough で 500

## 症状

ChatGPT でカスタム MCP コネクタ(`https://memory.kagura-ai.com/mcp`)を登録すると、OAuth 同意まで通った直後に失敗する。2026-09-17 と 2026-09-18 に計 4 回試行、全部同じ落ち方。

## 本番ログ(kagura-api-blue, v0.66.0)

OAuth は完走している:

1. `POST /api/v1/oauth/register` → 201(`dcr_client_registered`, provider=chatgpt)
2. `GET/POST /api/v1/oauth/authorize` → 200 / 303
3. `POST /api/v1/oauth/token` → 200

直後の最初の MCP リクエストで 500:

```
MCP session creating: mcp-… (user=…, workspace=…)
MCP request (Streamable HTTP): method=server/discover,…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1541) · 2026-09-18 · closed · 0 comments

### fix(worker-apps): validate the signing secret's shape — a placeholder string was accepted and broke production webhook verification

## What happened

On 2026-08-02 a signing-secret rotation was performed against
`POST /api/v1/admin/worker-apps/slack/default/rotate-secret`. The request body
carried a **placeholder string** instead of the real secret — the snippet's
`"…paste the new signing secret here…"` was submitted verbatim.

The API returned **200**. The placeholder was encrypted and stored as the
`active` signing secret.

Every subsequent Slack webhook failed signature verification. When the
`retiring` window elapsed,…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1478) · 2026-08-03 · closed · 0 comments

### feat(frontend): expose memory_link_template in the connector runtime UI — it is readable but not writable

## Problem

`WorkerRuntimeConfig.memory_link_template` can be persisted via
`PATCH /api/v1/workspace-connectors/{id}/runtime` and is surfaced in the
frontend type (`workspace-connectors.ts`: `memory_link_template: string | null`),
but **there is no UI to set it**.

`updateConnectorRuntime` has exactly one call site —
`handleVisionEnabledChange` in
`frontend/src/app/(authenticated)/workspace/integrations/connectors/page.tsx`.
So the connectors page can edit exactly one runtime field:…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1471) · 2026-08-01 · closed · 0 comments

### fix(mcp): rollback reports success when a merge action could not be reversed

Follow-up to #1440 / PR #1441. Found by a belated second-opinion review of the merged diff.

## The gap

`services/sleep/undo.py:revert_shadow_merge_edge()` returns `False` for **two materially different
situations** — its own docstring says so:

```
Returns:
    True if an edge was restored or deleted; False if nothing matched
    (the shadow merge was already undone, or the edge was retyped by a
    later writer).
```

1. **already undone** — benign. The rollback has nothing to do; logging…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1450) · 2026-07-28 · closed · 0 comments

### fix(mcp): supersede-candidate lifecycle gaps (detect/accept/docstring)

## Summary

Three confirmed lifecycle gaps in the #1403 supersede-candidate feature (all adversarial-panel CONFIRMED).

### F2 — detection silently skipped when the new memory already has any outgoing edge (Low)

In `backend/src/services/memory_service.py`, the supersede-candidate detection block (~4420-4454) sits **after** the pre-existing `existing_edges` idempotency early-return in `_create_knn_seed_edges` (~4394-4407, which returns if the memory has **any** outgoing edge). Because…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1422) · 2026-07-21 · closed · 0 comments

### fix(db): e74 CHECK rebuild locks memory_access_events (no NOT VALID)

## Summary

`backend/alembic/versions/e74_1401_mae_explore.py` (added in-range by #1400) widens the `valid_mae_operation` CHECK constraint on `memory_access_events` to allow `'explore'`. Both `upgrade()` and `downgrade()` do `op.drop_constraint(...)` + `op.create_check_constraint(...)`. `op.create_check_constraint` emits a plain `ALTER TABLE ... ADD CONSTRAINT ... CHECK (...)` with **no `NOT VALID`** — so Postgres holds `ACCESS EXCLUSIVE` on the table and validates every existing row before…

[Read the thread](https://github.com/kagura-ai/memory-cloud/issues/1421) · 2026-07-21 · closed · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/kagura-ai/memory-cloud/issues).
