You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 7d52c78
Browse filesBrowse the repository at this point in the historyBrowse files
AI-374: Warn against passing secrets through MCP factory_argument (#1688)
* AI-374: Warn against passing secrets through MCP factory_argument
`factory_argument` is serialized as an activity argument and therefore
recorded in workflow history, which is not obvious from the API surface.
Document that in the docstrings and READMEs for the MCP support in the
openai_agents and google_adk_agents contrib plugins, and point users at
resolving credentials worker-side inside the factory instead.
* AI-374: Correct and tighten the factory_argument secrets warning
Fix the claim that factory_argument is sent to every MCP activity, which
holds for stateless servers but not stateful ones, and document that a
zero-parameter stateless factory silently discards the value while it is
still written to history. Drop the maturity-badge glyph, qualify the web
UI claim for users running a payload codec, and state the factory-side
contract on the three provider docstrings.
* fix AI slop
Copy file name to clipboardExpand all lines: temporalio/contrib/google_adk_agents/README.md
+4Lines changed: 4 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -166,6 +166,10 @@ worker = Worker(
166
166
)
167
167
```
168
168
169
+
`TemporalMcpToolSet` also accepts an optional `factory_argument`. It is sent to the toolset activities and passed to the registered `toolset_factory` when the `McpToolset` is created.
170
+
171
+
**Do not pass secrets, credentials, or API keys through `factory_argument`.** It is an activity argument, so it is recorded in workflow history and, without a payload codec, visible in the web UI. Resolve credentials worker-side inside the toolset factory instead.
172
+
169
173
### Local ADK Runs
170
174
171
175
The same agent definitions can also be exercised outside Temporal with
Copy file name to clipboardExpand all lines: temporalio/contrib/openai_agents/README.md
+8Lines changed: 8 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -447,6 +447,14 @@ For implementation details and examples, see the [samples repository](https://gi
447
447
When using stateful servers, the dedicated worker maintaining the connection may fail due to network issues or server problems. When this happens, Temporal raises an `ApplicationError` and cannot automatically recover because it cannot restore the lost server state.
448
448
To recover from such failures, you need to implement your own application-level retry logic.
449
449
450
+
### Factory Arguments
451
+
452
+
Both `stateless_mcp_server()` and `stateful_mcp_server()` accept an optional `factory_argument`, which is passed to the registered server factory when the MCP server is created.
453
+
454
+
A stateless factory that declares no parameters — like the `lambda: MCPServerStdio(...)` example above — ignores the value, but it is still recorded in history.
455
+
456
+
**Do not pass secrets, credentials, or API keys through `factory_argument`.** It is an activity argument, so it is recorded in workflow history and, without a payload codec, visible in the web UI. Resolve credentials worker-side inside the server factory instead.
457
+
450
458
### Hosted MCP Tool
451
459
452
460
For network-accessible MCP servers, you can also use `HostedMCPTool` from the OpenAI Agents SDK, which uses an MCP client hosted by OpenAI.
0 commit comments