- atlassian: /v1/sse was deprecated by Atlassian after June 30 2026 —
installs OAuth'd fine then failed every handshake with 404 (#91538).
Now points at /v1/mcp/authv2, the endpoint Atlassian's docs recommend
for custom clients (live-probed: OAuth 2.1 + DCR intact).
- grafana (on top of @cedricziel's #93183 entry): defensive
default_excluded for ask_assistant (opaque Assistant delegation
meta-tool, bills usage) and agento11y_* (Grafana's own agent-obs
product suite) — both from Grafana's published tool tables, both
no-ops until the Cloud surface serves them; billing note added to
post_install.
The desktop app carried its own hardcoded list of 17 vendor MCP endpoints
(apps/desktop/src/lib/mcp-directory.ts) powering the composer suggestion
pills — a second PR-reviewed vendor list, overlapping and drifting from the
Nous-approved MCP catalog (optional-mcps/).
This makes the catalog the single source of truth:
- manifest schema: optional `suggest:` block (keywords + hosts), parsed,
validated, and normalized in mcp_catalog.py
- 15 new URL-only hosted-remote catalog entries (atlassian, sentry, datadog,
notion, stripe, vercel, supabase, netlify, hugging_face, asana, intercom,
airtable, webflow, paypal, square); figma + linear manifests gain suggest
blocks
- GET /api/mcp/catalog now serves the suggest metadata
- desktop suggestion provider builds its match index from the catalog;
the static directory remains only as a compatibility rung for older
backends without suggest metadata
- setup card source line prefers the catalog entry's transport URL
GitHub stays out of the catalog on purpose: its hosted MCP rejects generic
DCR and the bundled github/* skills (gh CLI) are the stronger integration.
New desktop `github` suggestion provider offers the github-auth skill
instead — gated on a new cached GET /api/git/gh-auth probe so already-
authenticated users never see the pill.