Backend environment
The issuer origin, frontend origin, and configured browser origins are allowed by MCP origin checks. Requests without an
Origin header are supported. Origin permission is not OAuth permission.
Set frontend NEXT_PUBLIC_API_URL to the same canonical issuer. Docs and Settings fall back to NEXT_PUBLIC_CONVEX_SITE_URL, then the HTTP-action origin derived from NEXT_PUBLIC_CONVEX_URL. Rebuild after changing public environment variables.
Deploy the schema, backend functions and frontend together. OAuth, discovery, MCP, REST and dynamic client registration routes are available immediately after deployment; no enablement flags are required.
Release checklist
- Verify public HTTPS issuer routing, OAuth discovery and protected-resource metadata.
- Exercise sign-in/consent, exact redirects, PKCE exchange, denied scopes and restricted workspaces.
- Test actual CIMD/DCR metadata and, when selected, the client’s signing algorithm, key IDs and assertion audience.
- Call read-only tools, then a harmless user-approved write in a test workspace.
- Verify refresh rotation, replay/reuse rejection, revocation and lost-membership behavior.
- Test rate limits, DNS/key-fetch failure, production action memory and expected load.
- Connect the deployed server with each target external client, including ChatGPT before any directory/store submission.
- Complete an independent security review appropriate to the rollout.
Updating these docs
Edit guides undercontent/docs. Endpoint and tool pages derive from convex/publicApi/operations/catalog.helpers.ts and the shared OpenAPI builder; add or change an operation there rather than maintaining a second list. Keep the configured docs origin aligned with the deployed backend.
.source/ and are recreated by postinstall. The docs site is public at /docs; search indexes only documentation and generated catalog descriptions, never private workspace data.
