feat(mcp): unify the desktop MCP suggestion directory into the catalog

The desktop app carried its own hardcoded list of 17 vendor MCP endpoints
(apps/desktop/src/lib/mcp-directory.ts) powering the composer suggestion
pills — a second PR-reviewed vendor list, overlapping and drifting from the
Nous-approved MCP catalog (optional-mcps/).

This makes the catalog the single source of truth:

- manifest schema: optional `suggest:` block (keywords + hosts), parsed,
  validated, and normalized in mcp_catalog.py
- 15 new URL-only hosted-remote catalog entries (atlassian, sentry, datadog,
  notion, stripe, vercel, supabase, netlify, hugging_face, asana, intercom,
  airtable, webflow, paypal, square); figma + linear manifests gain suggest
  blocks
- GET /api/mcp/catalog now serves the suggest metadata
- desktop suggestion provider builds its match index from the catalog;
  the static directory remains only as a compatibility rung for older
  backends without suggest metadata
- setup card source line prefers the catalog entry's transport URL

GitHub stays out of the catalog on purpose: its hosted MCP rejects generic
DCR and the bundled github/* skills (gh CLI) are the stronger integration.
New desktop `github` suggestion provider offers the github-auth skill
instead — gated on a new cached GET /api/git/gh-auth probe so already-
authenticated users never see the pill.
This commit is contained in:
Teknium
2026-08-14 23:00:20 -07:00
parent 3f9150e5c4
commit fc8ebff6d8
33 changed files with 947 additions and 44 deletions
+31
View File
@@ -0,0 +1,31 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: airtable
description: >-
Bases, tables, and records from your Airtable workspace.
source: https://support.airtable.com/articles/9897799762-using-the-airtable-mcp-server
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.airtable.com/mcp
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- airtable
hosts:
- airtable.com
post_install: |
On first connection Hermes opens a browser to authorize with
Airtable (or run `hermes mcp login airtable`). Approve access,
then restart the session so tools load.
+31
View File
@@ -0,0 +1,31 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: asana
description: >-
Tasks, projects, and goals from your Asana workspace.
source: https://developers.asana.com/docs/using-asanas-mcp-server
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.asana.com/sse
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- asana
hosts:
- asana.com
post_install: |
On first connection Hermes opens a browser to authorize with
Asana (or run `hermes mcp login asana`). Approve access,
then restart the session so tools load.
+36
View File
@@ -0,0 +1,36 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: atlassian
description: >-
Jira issues and Confluence pages via Atlassian's hosted remote MCP.
source: https://support.atlassian.com/rovo/docs/getting-started-with-the-atlassian-remote-mcp-server/
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.atlassian.com/v1/sse
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- jira
- confluence
- atlassian
- bitbucket
hosts:
- atlassian.net
- atlassian.com
- jira.com
post_install: |
On first connection Hermes opens a browser to authorize with
Atlassian (or run `hermes mcp login atlassian`). Approve access,
then restart the session so tools load.
+33
View File
@@ -0,0 +1,33 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: datadog
description: >-
Logs, monitors, dashboards, and incidents from Datadog.
source: https://docs.datadoghq.com/bits_ai/mcp_server/
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.datadoghq.com/api/unstable/mcp-server/mcp
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- datadog
- apm
hosts:
- datadoghq.com
- datadoghq.eu
post_install: |
On first connection Hermes opens a browser to authorize with
Datadog (or run `hermes mcp login datadog`). Approve access,
then restart the session so tools load.
+9
View File
@@ -22,6 +22,15 @@ transport:
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- figma
- mockup
- wireframe
hosts:
- figma.com
post_install: |
On first connection Hermes opens a browser to authorize with Figma
(or run `hermes mcp login figma`). Approve access, then restart the
+34
View File
@@ -0,0 +1,34 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: hugging_face
description: >-
Models, datasets, Spaces, and papers from the Hugging Face Hub.
source: https://huggingface.co/docs/hub/agents-mcp
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
# Underscored name so UIs render "Hugging Face", not "Huggingface".
transport:
type: http
url: https://huggingface.co/mcp
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- hugging face
- huggingface
hosts:
- huggingface.co
- hf.co
post_install: |
On first connection Hermes opens a browser to authorize with
Hugging Face (or run `hermes mcp login hugging_face`). Approve access,
then restart the session so tools load.
+32
View File
@@ -0,0 +1,32 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: intercom
description: >-
Conversations, tickets, and customer data from Intercom.
source: https://developers.intercom.com/docs/guides/mcp
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.intercom.com/mcp
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- intercom
hosts:
- intercom.com
- intercom.io
post_install: |
On first connection Hermes opens a browser to authorize with
Intercom (or run `hermes mcp login intercom`). Approve access,
then restart the session so tools load.
+7
View File
@@ -30,6 +30,13 @@ auth:
# tool names under `tools.default_enabled`. Probe failure would then apply
# that list directly.
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- linear
hosts:
- linear.app
post_install: |
On first connection, Hermes will open a browser to authenticate with Linear.
After auth, restart your Hermes session so the Linear tools are loaded.
+32
View File
@@ -0,0 +1,32 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: netlify
description: >-
Sites, deploys, and env vars via Netlify's hosted MCP.
source: https://docs.netlify.com/build/build-with-ai/agent-setup-guides/agent-setup-overview/
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
# No `netlify.app` suggest host for the same deploy-preview reason as vercel.app.
transport:
type: http
url: https://netlify-mcp.netlify.app/mcp
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- netlify
hosts:
- netlify.com
post_install: |
On first connection Hermes opens a browser to authorize with
Netlify (or run `hermes mcp login netlify`). Approve access,
then restart the session so tools load.
+32
View File
@@ -0,0 +1,32 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: notion
description: >-
Pages and databases from your Notion workspace.
source: https://developers.notion.com/docs/mcp
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.notion.com/mcp
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- notion
hosts:
- notion.so
- notion.site
post_install: |
On first connection Hermes opens a browser to authorize with
Notion (or run `hermes mcp login notion`). Approve access,
then restart the session so tools load.
+31
View File
@@ -0,0 +1,31 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: paypal
description: >-
Payments, invoices, and subscriptions via PayPal's hosted MCP.
source: https://developer.paypal.com/tools/mcp-server/
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.paypal.com/sse
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- paypal
hosts:
- developer.paypal.com
post_install: |
On first connection Hermes opens a browser to authorize with
Paypal (or run `hermes mcp login paypal`). Approve access,
then restart the session so tools load.
+33
View File
@@ -0,0 +1,33 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: sentry
description: >-
Issues, stack traces, and error context from Sentry.
source: https://docs.sentry.io/product/sentry-mcp/
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.sentry.dev/mcp
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- sentry
- stack trace
- crash report
hosts:
- sentry.io
post_install: |
On first connection Hermes opens a browser to authorize with
Sentry (or run `hermes mcp login sentry`). Approve access,
then restart the session so tools load.
+33
View File
@@ -0,0 +1,33 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: square
description: >-
Catalog, orders, and payments via Square's hosted MCP.
source: https://developer.squareup.com/docs/mcp
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
# "square" the English word is everywhere ("square brackets") — only the
# unambiguous brand form triggers a suggestion.
transport:
type: http
url: https://mcp.squareup.com/sse
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- squareup
hosts:
- squareup.com
post_install: |
On first connection Hermes opens a browser to authorize with
Square (or run `hermes mcp login square`). Approve access,
then restart the session so tools load.
+31
View File
@@ -0,0 +1,31 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: stripe
description: >-
Payments, customers, and invoices via Stripe's hosted MCP.
source: https://docs.stripe.com/mcp
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.stripe.com
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- stripe
hosts:
- dashboard.stripe.com
post_install: |
On first connection Hermes opens a browser to authorize with
Stripe (or run `hermes mcp login stripe`). Approve access,
then restart the session so tools load.
+32
View File
@@ -0,0 +1,32 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: supabase
description: >-
Database, auth, and storage from your Supabase projects.
source: https://supabase.com/docs/guides/ai-tools/mcp
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
transport:
type: http
url: https://mcp.supabase.com/mcp
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- supabase
hosts:
- supabase.com
- supabase.co
post_install: |
On first connection Hermes opens a browser to authorize with
Supabase (or run `hermes mcp login supabase`). Approve access,
then restart the session so tools load.
+33
View File
@@ -0,0 +1,33 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: vercel
description: >-
Deployments, logs, and projects via Vercel's hosted MCP.
source: https://vercel.com/docs/mcp
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
# No `vercel.app` suggest host on purpose: pasted deploy-preview links are
# about the site being previewed, not about managing Vercel.
transport:
type: http
url: https://mcp.vercel.com
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- vercel
hosts:
- vercel.com
post_install: |
On first connection Hermes opens a browser to authorize with
Vercel (or run `hermes mcp login vercel`). Approve access,
then restart the session so tools load.
+32
View File
@@ -0,0 +1,32 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: webflow
description: >-
Sites, CMS collections, and pages via Webflow's hosted MCP.
source: https://developers.webflow.com/mcp/reference/getting-started
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration;
# Hermes's MCP client + mcp_oauth_manager handle discovery, PKCE, token
# exchange, and refresh.
# No `webflow.io` suggest host — that's published staging sites, not Webflow intent.
transport:
type: http
url: https://mcp.webflow.com/mcp
auth:
type: oauth
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- webflow
hosts:
- webflow.com
post_install: |
On first connection Hermes opens a browser to authorize with
Webflow (or run `hermes mcp login webflow`). Approve access,
then restart the session so tools load.