# Reported issues for MateMCP

Pod holds 18 of 21 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [MateMCP](/mcp/matemcp).

## Most discussed

### Keep Companion and local Agent versions synchronized during Update now

## Summary

Using **Update now** in MateMCP Companion can update Companion while leaving the locally paired/running Agent on an older version.

This produces a partially upgraded installation where newly added Companion features depend on Agent APIs/capabilities that are not present in the running Agent.

The issue was previously closed as completed, but real-world verification after updating still shows:

```text
Skills & Memory is not available in the running Agent. Update/restart the Agent…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/96) · 2026-09-03 · closed · 5 comments

### Grok fails to connect to MCP URL shown in Companion during authentication check

## Summary

Adding the MCP URL shown in MateMCP Companion to **Grok** still fails during connector creation/authentication.

A first compatibility fix was merged in PR #85 (`Fix Grok OAuth discovery compatibility`) and CI passed, but real-world verification shows Grok still rejects the connector. Therefore this issue is reopened.

## Current observed behavior

Grok proceeds through connector creation/authentication checks and still ends with a generic connection failure.

The previously fixed…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/84) · 2026-09-03 · closed · 4 comments

### Windows Desktop update can cause opaque Agent downtime before recovery

Discovered during #238 / #273 installed-package verification on VHD-PC4.

## Observed behavior

On Windows, using the official Desktop `Update now` path can leave the machine itself online while the MateMCP Agent fails to return:

- VHD-PC4 Companion reported a newer official `agent-latest` Desktop package.
- `Update now` was invoked from the installed Companion; Agent audit recorded the semantic activation.
- The Windows machine remained reachable on the LAN (`192.168.200.217` responds to…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/275) · 2026-09-26 · closed · 3 comments

### Graceful Agent shutdown does not mark device offline promptly

Observed behavior:
- When an Agent is closed normally, api.matemcp.com continues to show it as online.
- Restarting the Agent after a normal close works correctly; there is no reconnect loop.

Expected behavior:
- A graceful Agent shutdown should mark the device offline promptly, rather than waiting only for the dashboard LastSeenAt TTL to expire.

Likely cause:
- Presence is currently refreshed through Relay -> Control Plane authenticate heartbeats, but there is no explicit disconnect/offline…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/17) · 2026-08-31 · closed · 3 comments

### Agents remain offline after Relay heartbeat update

Observed behavior:
- Relay heartbeat fix was merged/published.
- Server was updated with `curl -fsSL https://raw.githubusercontent.com/vrassouli/MateMCP/main/deploy/install.sh | sudo bash`.
- Dashboard still showed existing agents as offline because the server installer was still pulling `vrassouli/matemcp-relay:dev` while `main` CI publishes `:latest`; installer/compose defaults were corrected.
- After updating to `:latest`, a Windows Agent could enter a repeated `Connected to MateMCP Relay as…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/16) · 2026-08-31 · closed · 3 comments

### Fix macOS bootstrap without a GitHub auth token

## Problem

`scripts/bootstrap-macos.sh` fails immediately on a normal public `agent-latest` install when neither `GH_TOKEN` nor `GITHUB_TOKEN` is set.

Observed on MacBook3 while installing the current `agent-latest` Desktop package:

```text
Resolving MateMCP-Desktop-macos-arm64.tar.gz from release agent-latest...
scripts/bootstrap-macos.sh: line 51: CURL_AUTH_ARGS[@]: unbound variable
```

The script uses `set -euo pipefail`, initializes `CURL_AUTH_ARGS=()`, and later expands…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/282) · 2026-09-27 · closed · 1 comment

### Production Relay still returns 403 for Computer Use tools after scope fix merged

## Problem

Production Relay still returns raw HTTP `403 Forbidden` for newly published Computer Use / Vision / Browser tools on an otherwise healthy enrolled Agent.

Real reproduction on `MacBook3`:

1. `shell_exec("echo ok")` → PASS
2. `browser_open("http://127.0.0.1:5233/login")` → `403 Forbidden` from `https://relay.matemcp.com/mcp/<agent>`
3. `window_list()` → same `403 Forbidden`

Tool discovery includes the Browser/Vision/Desktop schemas, so this is not a missing-tool or general…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/211) · 2026-09-15 · closed · 1 comment

### Host integration: bind ChatGPT conversation attachments to Agent upload without model-serialized base64

## Problem

During real end-to-end field testing of #113, ChatGPT could access the active conversation attachment as a mounted runtime file and compute its exact size/SHA-256, and MateMCP upload tools could accept small literal base64 chunks. However, the current ChatGPT tool invocation boundary does not expose the conversation attachment as a file/stream/reference that can be bound directly to `agent_file_upload_chunk`.

The only available path is for the model to serialize attachment bytes…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/203) · 2026-09-15 · open · 1 comment

## Most recent

### Interactive Shell renders raw ANSI/VT escape sequences

## Problem

The Companion **Interactive Shell** renders PTY/SSH output as plain text. ANSI/VT control sequences therefore appear visibly inside the black terminal area instead of being interpreted or safely normalized.

Example observed output:

```text
[1t[?1004h[?9001h(root@192.168.200.34) Password: [2;1Hecho READY; uname -a[2;21H[2;21H READY FreeBSD OPNsense.internal ...
```

Sequences such as `ESC[?1004h`, `ESC[?9001h`, and cursor-positioning commands like `ESC[2;1H` should not be…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/307) · 2026-09-28 · closed · 0 comments

### macOS bootstrap release smoke fails with 403 resolving agent-latest asset

## Observed

The `companion-build` push workflow for final main commit `56c8faf4c6e59f66c17c7d3fdbce02903b9fd03f` built and published both Desktop packages successfully, and the Windows bootstrap smoke test passed. The macOS `smoke-bootstrap-release` job failed in `scripts/bootstrap-macos.sh` while resolving `MateMCP-Desktop-macos-arm64.tar.gz` from the `agent-latest` release:

```text
Resolving MateMCP-Desktop-macos-arm64.tar.gz from release agent-latest...
curl: (56) The requested URL…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/259) · 2026-09-26 · closed · 0 comments

### Full Access state written by Companion is ignored by Agent due to JSON casing mismatch

## Problem

Selecting **Full Access / Unattended** in Companion persists `agent-access-mode.json`, but the Agent continues creating interactive approval requests.

Real reproduction on MacBook3 after selecting Full Access:

- `~/Library/Application Support/MateMCP/agent-access-mode.json` contains `{"mode":2,"updatedAt":"..."}`.
- The installed Agent resolves that exact path.
- Instantiating `AgentAccessModeStore` from the installed `MateMCP.Agent.dll` and calling `GetAsync()` returns `Ask (0)`…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/213) · 2026-09-15 · closed · 0 comments

### Keep Relay OAuth scope policy in sync with the Agent MCP tool catalog

## Problem

Relay OAuth authorization uses an explicit MCP tool-name -> scope allowlist. Several Agent tools added after the original policy are published by the Agent but are not classified in `McpScopePolicy`, so they fail closed as `mcp:unsupported` and return HTTP 403 before reaching the Agent.

This was observed in the field with `project_resolve` while validating #113. PR #201 fixed the same omission for attachment upload tools, but the underlying drift risk remains.

## Goal

Make Relay…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/204) · 2026-09-15 · closed · 0 comments

### Fix ChatGPT OAuth reconnects by preserving offline_access and refresh tokens

## Problem

ChatGPT periodically asks the user to **Reconnect** a MateMCP Agent connection, sometimes after a few hours of inactivity and sometimes in the middle of an active chat/session.

This creates the impression that MateMCP is unstable even when the Agent and Relay connection are healthy.

GitHub and similar long-lived connectors generally refresh credentials silently and do not require the user to reconnect repeatedly.

## Root cause

MateMCP already enables the OAuth refresh-token flow…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/152) · 2026-09-13 · closed · 0 comments

### Fix Relay ForbidResult authentication-scheme exception

## Summary

Relay can throw instead of returning a 403 when `Results.Forbid()` is executed because no default forbid authentication scheme is configured.

Observed production exception:

```text
System.InvalidOperationException: No authenticationScheme was specified, and there was no DefaultForbidScheme found.
```

## Current code path

`src/MateMCP.Relay/Program.cs` still contains:

```csharp
if (!ScopeAllowsPayload(principal, ms.ToArray())) return Results.Forbid();
```

The Relay configures…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/112) · 2026-09-05 · closed · 0 comments

### Allow users to choose elevated Agent mode during and after installation

## Summary

MateMCP should allow the user to explicitly choose whether the Agent runs with elevated privileges.

This choice should be available both:

1. **during installation**, and
2. **after installation** from Companion/settings.

The goal is to support workflows that genuinely require Administrator/root privileges without forcing every MateMCP installation to run elevated by default.

## Desired behavior

### During installation

The installer should clearly offer a choice such as:

- Run…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/80) · 2026-09-02 · closed · 1 comment

### Add SSH-specific named-credential authentication tool to avoid generic secret-injection host blocks

## Problem

The Agent-side `shell_session_send_secret` implementation is working and has successfully authenticated SSH sessions end-to-end, but ChatGPT/MCP host-side safety can intermittently reject the generic secret-injection action before the request reaches MateMCP.

Verified from Windows Agent audit on 2026-09-02:

- successful SSH sessions have `secret.use` approval/audit followed by `Result=injected` for `common_pass`;
- failed attempts after a real SSH password prompt have no…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/66) · 2026-09-02 · closed · 0 comments

### Add Companion sign-out/re-enrollment and device management

## Goal
Add first-class account/device lifecycle management to the desktop Companion.

## Requested UX
- Show the current device/account connection state in Companion.
- Allow **Sign out / Remove this device** from Companion.
  - Revoke the current device in the control plane.
  - Remove its local relay credential/device identity so it is no longer connected.
- When not enrolled, provide **Sign in / Add this device** directly from Companion and restart the enrollment flow without reinstalling…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/63) · 2026-09-02 · closed · 0 comments

### Add structured SSH interactive-session start tool

## Problem

Interactive SSH workflows currently have to begin through the generic `shell_session_start(command)` tool. In ChatGPT/MCP hosts, that generic arbitrary-command surface can be blocked by host-side safety checks before the request reaches the MateMCP Agent. This has been reproduced with both `ssh administrator@192.168.200.37` and the otherwise benign `powershell.exe -NoExit` workaround.

Agent-side inspection confirms `shell_session_start` itself does not apply a command denylist; it…

[Read the thread](https://github.com/vrassouli/MateMCP/issues/56) · 2026-09-02 · closed · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/vrassouli/MateMCP/issues).
