Skip to content

🎃 Add "Copy as cURL" to an audit log entry to replay the MCP tool call #850

Description

@keysersoft

Part of the October Challenge #846.

Why

When a tool call fails, the first step in debugging is to run it again outside the AI client. The log row already has the tool name, the arguments and the MCP server it came through, but rebuilding a valid MCP JSON-RPC request by hand (headers, protocol version, envelope) is slow and easy to get wrong. Browser DevTools, Postman and Insomnia all have "Copy as cURL". This issue adds that button to each entry on the Audit Log page.

What the log actually stores: tool_invocations.input holds the MCP tool arguments, saved before env vars are injected (dynamic-mcp-tools.ts:412-421). It does not hold the upstream HTTP request (URL, headers, body sent to the vendor API). So this feature replays the MCP tools/call against AnythingMCP. It does not replay the upstream API call. That is deliberate: upstream requests carry the connector's credentials.

Self-hosted vs Cloud

  • Self-hosted: enabled in Community and Business. No ee/ code.
  • Cloud (DEPLOYMENT_MODE=cloud): enabled. The command targets https://cloud.anythingmcp.com/mcp/<serverId>, which the user can already reach with their own credentials. Nothing instance-wide is exposed, and the button is client-side only with no new endpoint.
  • Who can use it: any role that can see /logs today. The command only contains data already shown in the expanded row, plus a placeholder for the credential.

What to build

  1. A "Copy as cURL" button in the expanded row (logs/page.tsx:382-419), next to the User/Server meta line.
  2. Put a pure builder in packages/frontend/src/lib/curl.ts: buildToolCallCurl({ origin, serverId, toolName, args, authMode }). Output:
    curl -sS -X POST "https://host/mcp/<serverId>" \
      -H "Content-Type: application/json" \
      -H "Accept: application/json, text/event-stream" \
      -H "MCP-Protocol-Version: 2025-06-18" \
      -H "X-API-Key: $AMCP_MCP_API_KEY" \
      --data-binary @- <<'JSON'
    {"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"<tool>","arguments":{...}}}
    JSON
    The quoted heredoc means no shell escaping is needed for the JSON. Before you finalize the headers, check that a bare tools/call (no initialize) is accepted by the stateless per-server endpoint on a local instance. If it is not, emit an initialize call first and say so in a comment.
  3. The credential is always a placeholder env var. Never put a real secret in the command. The auth header follows MCP_AUTH_MODE from server.info(): legacy/both gives X-API-Key: $AMCP_MCP_API_KEY (per-user mcp_… keys work in every mode on /mcp/<id>, see mcp-combined-auth.guard.ts:64), and oauth2 gives Authorization: Bearer $AMCP_ACCESS_TOKEN. Never insert the dashboard session token (amcp_token in localStorage). The MCP guard accepts app JWTs (mcp-combined-auth.guard.ts:89-100), so pasting one would leak a full-account credential into shell history and tickets.
  4. Origin: reuse the logic in mcp-server/[id]/page.tsx:98-102 (localhost → :4000, otherwise window.location.origin). Move it into lib/ rather than copying it.
  5. Disable the button, with a tooltip explaining why, when:
    • log.mcpServer is null. The call came through the shared /mcp endpoint, which on Cloud only exposes the eight anythingmcp_* tools (shared-toolset.ts:26-55), so a direct call by tool name would not work there.
    • log.input._amcp_truncated is present. The stored arguments are an excerpt (bound-payload.ts:16), so a replay would not be faithful.
  6. Reuse the clipboard fallback from mcp-server/[id]/page.tsx:210-245 (it handles plain-HTTP LAN installs). Moving it into lib/clipboard.ts is welcome.

Where to look

  • packages/frontend/src/app/logs/page.tsx:382-419: expanded row (log.input, log.mcpServer, log.tool.name).
  • packages/backend/src/audit/audit.service.ts:204-224: fields returned per row (mcpServer.id/slug, tool.name).
  • packages/backend/src/mcp-server/dynamic-mcp-tools.ts:412-421: input: params (pre-env-injection args).
  • packages/backend/src/mcp-server/mcp-endpoint.controller.ts:1042-1048: stateless handler, legacy: 'stateless'.
  • packages/frontend/src/lib/api.ts:964-977: server.info() → mcpAuthMode.

Acceptance criteria

  • The copied command runs against a local instance with a real key exported as AMCP_MCP_API_KEY and returns the tool result (describe the manual check in the PR).
  • Args containing ', ", $, backticks and newlines survive unchanged (heredoc).
  • No token, key or cookie value ever appears in the output. The test asserts the placeholder is present.
  • The button is disabled for shared-endpoint rows and truncated inputs.
  • Playwright test in packages/frontend/tests/e2e/ (stub /api/audit/invocations and /health/server-info like redesign.spec.ts, grant clipboard permission, assert the copied text). Run with cd packages/frontend && npm run test:e2e.
  • Short "Replay a tool call" note added to docs/api-reference.md near the Audit section (line 219).

Out of scope

  • Replaying the upstream vendor HTTP request (it is not stored, and it carries credentials).
  • PowerShell/HTTPie variants, HAR export.
  • A "Run again" button that executes from the browser.

Size

S (a few hours)

How to claim

Comment "I'd like to work on this" and we'll assign you. Rules in #846.

Activity

  1. AYUshJaiswal454 commented on Oct 9, 2026

    @AYUshJaiswal454

    I'd like to work on this. I’ve read the issue requirements and will follow the repository’s contribution guidelines. My plan is to implement the Copy as cURL button with safe credential placeholders, handle disabled states for shared-endpoint rows and truncated inputs, and add the required tests and documentation. I’ll use AI assistance to explore the codebase, but I’ll review and test the changes myself. Could you please assign this issue to me?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions