Part of the October Challenge #846.
Why
When a tool call fails, the first step in debugging is to run it again outside the AI client. The log row already has the tool name, the arguments and the MCP server it came through, but rebuilding a valid MCP JSON-RPC request by hand (headers, protocol version, envelope) is slow and easy to get wrong. Browser DevTools, Postman and Insomnia all have "Copy as cURL". This issue adds that button to each entry on the Audit Log page.
What the log actually stores: tool_invocations.input holds the MCP tool arguments, saved before env vars are injected (dynamic-mcp-tools.ts:412-421). It does not hold the upstream HTTP request (URL, headers, body sent to the vendor API). So this feature replays the MCP tools/call against AnythingMCP. It does not replay the upstream API call. That is deliberate: upstream requests carry the connector's credentials.
Self-hosted vs Cloud
- Self-hosted: enabled in Community and Business. No
ee/ code.
- Cloud (
DEPLOYMENT_MODE=cloud): enabled. The command targets https://cloud.anythingmcp.com/mcp/<serverId>, which the user can already reach with their own credentials. Nothing instance-wide is exposed, and the button is client-side only with no new endpoint.
- Who can use it: any role that can see
/logs today. The command only contains data already shown in the expanded row, plus a placeholder for the credential.
What to build
- A "Copy as cURL" button in the expanded row (
logs/page.tsx:382-419), next to the User/Server meta line.
- Put a pure builder in
packages/frontend/src/lib/curl.ts: buildToolCallCurl({ origin, serverId, toolName, args, authMode }). Output:
curl -sS -X POST "https://host/mcp/<serverId>" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-H "MCP-Protocol-Version: 2025-06-18" \
-H "X-API-Key: $AMCP_MCP_API_KEY" \
--data-binary @- <<'JSON'
{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"<tool>","arguments":{...}}}
JSON
The quoted heredoc means no shell escaping is needed for the JSON. Before you finalize the headers, check that a bare tools/call (no initialize) is accepted by the stateless per-server endpoint on a local instance. If it is not, emit an initialize call first and say so in a comment.
- The credential is always a placeholder env var. Never put a real secret in the command. The auth header follows
MCP_AUTH_MODE from server.info(): legacy/both gives X-API-Key: $AMCP_MCP_API_KEY (per-user mcp_… keys work in every mode on /mcp/<id>, see mcp-combined-auth.guard.ts:64), and oauth2 gives Authorization: Bearer $AMCP_ACCESS_TOKEN. Never insert the dashboard session token (amcp_token in localStorage). The MCP guard accepts app JWTs (mcp-combined-auth.guard.ts:89-100), so pasting one would leak a full-account credential into shell history and tickets.
- Origin: reuse the logic in
mcp-server/[id]/page.tsx:98-102 (localhost → :4000, otherwise window.location.origin). Move it into lib/ rather than copying it.
- Disable the button, with a tooltip explaining why, when:
log.mcpServer is null. The call came through the shared /mcp endpoint, which on Cloud only exposes the eight anythingmcp_* tools (shared-toolset.ts:26-55), so a direct call by tool name would not work there.
log.input._amcp_truncated is present. The stored arguments are an excerpt (bound-payload.ts:16), so a replay would not be faithful.
- Reuse the clipboard fallback from
mcp-server/[id]/page.tsx:210-245 (it handles plain-HTTP LAN installs). Moving it into lib/clipboard.ts is welcome.
Where to look
packages/frontend/src/app/logs/page.tsx:382-419: expanded row (log.input, log.mcpServer, log.tool.name).
packages/backend/src/audit/audit.service.ts:204-224: fields returned per row (mcpServer.id/slug, tool.name).
packages/backend/src/mcp-server/dynamic-mcp-tools.ts:412-421: input: params (pre-env-injection args).
packages/backend/src/mcp-server/mcp-endpoint.controller.ts:1042-1048: stateless handler, legacy: 'stateless'.
packages/frontend/src/lib/api.ts:964-977: server.info() → mcpAuthMode.
Acceptance criteria
Out of scope
- Replaying the upstream vendor HTTP request (it is not stored, and it carries credentials).
- PowerShell/HTTPie variants, HAR export.
- A "Run again" button that executes from the browser.
Size
S (a few hours)
How to claim
Comment "I'd like to work on this" and we'll assign you. Rules in #846.
Part of the October Challenge #846.
Why
When a tool call fails, the first step in debugging is to run it again outside the AI client. The log row already has the tool name, the arguments and the MCP server it came through, but rebuilding a valid MCP JSON-RPC request by hand (headers, protocol version, envelope) is slow and easy to get wrong. Browser DevTools, Postman and Insomnia all have "Copy as cURL". This issue adds that button to each entry on the Audit Log page.
What the log actually stores:
tool_invocations.inputholds the MCP tool arguments, saved before env vars are injected (dynamic-mcp-tools.ts:412-421). It does not hold the upstream HTTP request (URL, headers, body sent to the vendor API). So this feature replays the MCPtools/callagainst AnythingMCP. It does not replay the upstream API call. That is deliberate: upstream requests carry the connector's credentials.Self-hosted vs Cloud
ee/code.DEPLOYMENT_MODE=cloud): enabled. The command targetshttps://cloud.anythingmcp.com/mcp/<serverId>, which the user can already reach with their own credentials. Nothing instance-wide is exposed, and the button is client-side only with no new endpoint./logstoday. The command only contains data already shown in the expanded row, plus a placeholder for the credential.What to build
logs/page.tsx:382-419), next to the User/Server meta line.packages/frontend/src/lib/curl.ts:buildToolCallCurl({ origin, serverId, toolName, args, authMode }). Output:tools/call(noinitialize) is accepted by the stateless per-server endpoint on a local instance. If it is not, emit aninitializecall first and say so in a comment.MCP_AUTH_MODEfromserver.info():legacy/bothgivesX-API-Key: $AMCP_MCP_API_KEY(per-usermcp_…keys work in every mode on/mcp/<id>, seemcp-combined-auth.guard.ts:64), andoauth2givesAuthorization: Bearer $AMCP_ACCESS_TOKEN. Never insert the dashboard session token (amcp_tokenin localStorage). The MCP guard accepts app JWTs (mcp-combined-auth.guard.ts:89-100), so pasting one would leak a full-account credential into shell history and tickets.mcp-server/[id]/page.tsx:98-102(localhost→:4000, otherwisewindow.location.origin). Move it intolib/rather than copying it.log.mcpServeris null. The call came through the shared/mcpendpoint, which on Cloud only exposes the eightanythingmcp_*tools (shared-toolset.ts:26-55), so a direct call by tool name would not work there.log.input._amcp_truncatedis present. The stored arguments are an excerpt (bound-payload.ts:16), so a replay would not be faithful.mcp-server/[id]/page.tsx:210-245(it handles plain-HTTP LAN installs). Moving it intolib/clipboard.tsis welcome.Where to look
packages/frontend/src/app/logs/page.tsx:382-419: expanded row (log.input,log.mcpServer,log.tool.name).packages/backend/src/audit/audit.service.ts:204-224: fields returned per row (mcpServer.id/slug,tool.name).packages/backend/src/mcp-server/dynamic-mcp-tools.ts:412-421:input: params(pre-env-injection args).packages/backend/src/mcp-server/mcp-endpoint.controller.ts:1042-1048: stateless handler,legacy: 'stateless'.packages/frontend/src/lib/api.ts:964-977:server.info()→mcpAuthMode.Acceptance criteria
AMCP_MCP_API_KEYand returns the tool result (describe the manual check in the PR).',",$, backticks and newlines survive unchanged (heredoc).packages/frontend/tests/e2e/(stub/api/audit/invocationsand/health/server-infolikeredesign.spec.ts, grant clipboard permission, assert the copied text). Run withcd packages/frontend && npm run test:e2e.docs/api-reference.mdnear the Audit section (line 219).Out of scope
Size
S (a few hours)
How to claim
Comment "I'd like to work on this" and we'll assign you. Rules in #846.