Sentinel Signal

MCP code: which copy is canonical

Source: docs/mcp-source-of-truth.md

Document Content

MCP code: which copy is canonical

Decided 2026-10-03 after a cross-repo review found the MCP code in four places, drifting apart.

| Component | Canonical source | Where it runs | Version (2026-10-03) | |---|---|---|---| | Hosted MCP server (https://mcp.sentinelsignal.io/mcp) | mcp_remote/ in this repo | IONOS host, mcp-remote service, deployed with scripts/prod_deploy.sh | SERVER_VERSION = "1.0.9" | | Local stdio package (pip install sentinel-signal-mcp) | sentinelsignal/sentinel-signal-mcp | users' machines, published to PyPI | 0.1.5 | | Helper code inside the hosted server | sentinel_signal_mcp/ in this repo | copied into the mcp-remote image | 0.1.1 | | MCP OAuth bridge (WorkOS) | token_service/ in this repo | https://token.sentinelsignal.io | n/a |

Retired

  • sentinelsignal/sentinel-signal-mcp-remote: a standalone copy of the hosted server that stopped at 1.0.6. Marked deprecated.
  • sentinelsignal/sentinel-signal-mcp-auth-bridge: the old Fly bridge behind auth.sentinelsignal.io, which no longer resolves. Marked deprecated.
  • .github/workflows/fly-deploy-mcp-remote.yml: removed. No workflow may deploy to Fly (tests/unit/test_mcp_remote_source.py).

Why the hosted server keeps its own helper copy

sentinel_signal_mcp/ is deliberately a vendored subset. The hosted server does not install the PyPI package (test_mcp_remote_deploy_files_are_repo_managed asserts this), so a PyPI release can never change production without a deploy. The two copies share credential and client helpers, not tools: the public package's extra tools are for local use.

When you change shared behaviour (credential resolution, API client error handling), make the change in both places in the same working session and bump the public package version.