MCP smoke test
Use this recipe after creating a disposable tenant API key.
Run the smoke
Code
The smoke validates:
- protected-resource metadata at the standards-shaped
.well-knownURL; - unauthenticated
WWW-Authenticatediscovery; - authenticated
GET /api/mcpreturning405 Method Not Allowed; - MCP SDK initialization;
tools/list;whoamireturning structured content;prepare_api_writefailing safely or returning a frozen preparation payload.
OAuth activation check
Assert the canonical HollyHR authorization server:
Code
An empty authorization_servers array is a deployment defect after the Better
Auth cutover.
When HOLLYHR_MCP_EXPECT_OAUTH=1, the smoke also fetches:
Code
and verifies the issuer, JWKS URI, authorization endpoint, and token endpoint metadata expected by OAuth-capable MCP hosts.
Verify DCR, PKCE and the read-first scope contract:
Code
This content-free smoke verifies the canonical protected-resource metadata,
authorization-server metadata, public-client DCR, PKCE S256 and the minimal
read-first HollyHR scopes. It stops before interactive login. The protected
MCP Reviewer Readiness workflow completes provider-specific sign-in, consent,
token exchange, tool calls and the reversible write canary against the exact
production SHA.
First prompts
After connecting a real MCP host, use read-only prompts first:
Code
Code
Do not test writes in a customer tenant. MCP write commit requires host form
elicitation, mcp:write, the underlying data write scope, and the tenant
write-mode gate.