Skip to content

Keep prod MCP credentials out of process arguments - #22

Merged
areshand merged 2 commits into
mainfrom
codex/prod-mcp-private-curl-io
Aug 22, 2026
Merged

Keep prod MCP credentials out of process arguments#22
areshand merged 2 commits into
mainfrom
codex/prod-mcp-private-curl-io

Conversation

@areshand

Copy link
Copy Markdown
Owner

Summary

  • write KMS signing input and MCP headers to create-new private files
  • pass the signed MCP request body to curl over stdin
  • keep bearer and MCP session headers out of process arguments
  • clean up private request and response files on all command outcomes

Security

Prevents other pod UIDs from observing the prod-mcp bearer token or signed operation permit through /proc process arguments.

Validation

Focused regression coverage is included. Local tests were not run; CI is the validation gate.

@areshand
areshand merged commit fb31645 into main Aug 22, 2026
4 checks passed
@areshand
areshand deleted the codex/prod-mcp-private-curl-io branch August 22, 2026 22:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant