Skip to content

Only list permitted MCP tools - #309

Open
ulitmate wants to merge 1 commit into
lightningdevkit:mainfrom
ulitmate:fix/287-limit-mcp-tools
Open

ulitmate wants to merge 1 commit into
lightningdevkit:mainfrom
ulitmate:fix/287-limit-mcp-tools

Conversation

@ulitmate

@ulitmate ulitmate commented Oct 10, 2026 •

Copy link
Copy Markdown

Fixes #287.

The MCP server previously advertised every tool even when its configured macaroon could only call a subset. It now fetches the macaroon's effective permissions on startup and filters tools/list accordingly. If permission discovery fails, it warns and retains the existing full tool list.

Each MCP tool now explicitly names the RPC endpoint it calls. The RPC authorization mapping is shared through ldk-server-grpc so the server and MCP client cannot drift. get_permissions remains visible to every authenticated macaroon, and method caveats are honored.

Tests cover admin, restricted, preset, and method-limited macaroons, including an end-to-end restricted-token tool list.

AI tools were used to help prepare this change.

@ldk-reviews-bot

ldk-reviews-bot commented Oct 10, 2026 •

Copy link
Copy Markdown

👋 Thanks for assigning @benthecarman as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@benthecarman

Copy link
Copy Markdown
Collaborator

please wrap your commit messages and don't link the issue in the commit message either

Comment thread ldk-server-mcp/src/tools/mod.rs Outdated
}

/// Maps a tool name to the RPC it calls, e.g. `bolt11_receive` to `Bolt11Receive`.
fn rpc_method(tool_name: &str) -> String {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this feels flaky, can we just actually map them

@ulitmate ulitmate Oct 10, 2026 •

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated each ToolSpec to explicitly name its RPC endpoint and removed the name conversion function.

Scoped macaroons may only be allowed to call a few RPCs, but the MCP
server listed every tool, wasting model context and inviting calls the
server would deny.

On startup, call get_permissions and only list tools whose RPC the
macaroon's effective permissions and method caveats allow. Each tool
spec now names the RPC it calls explicitly, and filtering uses that.
Admin macaroons still see every tool and get_permissions is always
listed. If permissions cannot be fetched we warn and list every tool
as before. Hidden tools still route to the server so stale clients get
the server's permission error.

To share one RPC-to-permission table between the server and the MCP
client, move method_authorization from the server into
ldk-server-grpc's permissions module. The mapping is unchanged and the
server's contract test still covers it.

The startup probe now uses get_permissions instead of get_node_info,
which avoids a misleading warning for macaroons without node:read.

AI tools were used to help write this change and its tests.
@ulitmate
ulitmate force-pushed the fix/287-limit-mcp-tools branch from 8342448 to bf8612d Compare October 10, 2026 09:44
@ulitmate

ulitmate commented Oct 10, 2026 •

Copy link
Copy Markdown
Author

Addressed both review items: the commit message is wrapped with the issue reference removed, and every MCP tool now has an explicit RPC endpoint mapping.

Validated with formatting checks, 46 MCP tests, MCP clippy, the permission e2e suite, and the full all features workspace tests.

@ulitmate
ulitmate requested a review from benthecarman October 10, 2026 10:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Limit visible MCP tools with restricted token

3 participants