Skip to content

Commit c2355fe

Browse files
khaliqgantclaude
andcommitted
docs(mcp-workforce): update README env contract for VFS clients
The README still documented WORKFORCE_INTEGRATION_GITHUB_TOKEN as the setup step for integration.* tools, but those tools no longer take a provider token — they write JSON drafts into the Relayfile mount and Relayfile's writeback worker handles the actual provider call. Updated the stand-alone setup example and the config table to point at RELAYFILE_MOUNT_ROOT (with the RELAYFILE_ROOT alias and the new WORKFORCE_WRITEBACK_TIMEOUT_MS override documented for completeness). Adds a sentence on the writeback model so readers understand why the MCP server never sees a provider token. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent b509753 commit c2355fe

1 file changed

Lines changed: 9 additions & 3 deletions

File tree

‎packages/mcp-workforce/README.md‎

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -25,12 +25,16 @@ then has tool access to:
2525
export WORKFORCE_WORKSPACE_ID=ws_demo
2626
export WORKFORCE_RUNTIME_TOKEN=<workspace-token> # required for workflow.*
2727
export SUPERMEMORY_API_KEY=<key> # required for memory.*
28-
export WORKFORCE_INTEGRATION_GITHUB_TOKEN=ghp_... # required for integration.github.*
28+
export RELAYFILE_MOUNT_ROOT=/path/to/relayfile/mount # required for integration.*
2929

3030
npx @agentworkforce/mcp-workforce
3131
```
3232

33-
The server speaks MCP over stdio.
33+
The server speaks MCP over stdio. Integration tools don't talk to
34+
GitHub/Linear/etc. directly — they write canonical JSON files inside
35+
the Relayfile mount, and Relayfile's writeback worker turns those
36+
into real provider API calls. Relayfile holds the OAuth credentials;
37+
the MCP server itself never sees a provider token.
3438

3539
## Persona-side wiring
3640

@@ -53,7 +57,9 @@ spawns a harness. Personas that want to declare it manually can use:
5357
| `WORKFORCE_CLOUD_URL` | Override cloud base URL | optional |
5458
| `SUPERMEMORY_API_KEY` | Memory adapter credentials | `memory.*` |
5559
| `SUPERMEMORY_ENDPOINT` | Override supermemory endpoint | optional |
56-
| `WORKFORCE_INTEGRATION_<PROVIDER>_TOKEN` | Direct provider token | `integration.<provider>.*` |
60+
| `RELAYFILE_MOUNT_ROOT` | Relayfile mount root the integration clients write into | `integration.*` |
61+
| `RELAYFILE_ROOT` | Legacy alias for `RELAYFILE_MOUNT_ROOT` | optional |
62+
| `WORKFORCE_WRITEBACK_TIMEOUT_MS` | Per-call writeback wait; default 30000 | optional |
5763

5864
Tools that lack their required env throw a clear setup error at first
5965
call — the server itself still boots so partial wiring is debuggable.

0 commit comments

Comments
 (0)