affaan-m/ECC · error · JsonRpcError

The user memory scope is disabled for this MCP server.

Error message

The user memory scope is disabled for this MCP server.

What it means

The memory server can be started with user-scope access disabled (ECC_MEMORY_ALLOW_USER_SCOPE !== '1'). When a recall request asks for the 'user' scope (explicitly or via DEFAULT_RECALL_SCOPES), assertScopesAuthorized rejects it with JsonRpcError -32602 to keep user-private memories inaccessible in that deployment.

Solutions

  1. Set ECC_MEMORY_ALLOW_USER_SCOPE=1 in the MCP server env if user-scope memory is intended
  2. Or pass explicit scopes without 'user' (e.g. ["project","shared"]) in the tool call
  3. Update the client's default recall scopes to exclude 'user'

Example fix

// before
{ "name": "memory-recall", "arguments": { "query": "auth design" } }
// after
{ "name": "memory-recall", "arguments": { "query": "auth design", "scopes": ["project", "shared"] } }
Defensive patterns

Strategy: type-guard

Validate before calling

const scopes = args.scopes || ['project','shared']; if (scopes.includes('user') && process.env.ECC_MEMORY_ALLOW_USER_SCOPE !== '1') throw new Error('user scope disabled on this server');

Type guard

const userScopeAllowed = (security, scopes) => security.allowUserScope || !(scopes || ['user']).includes('user');

Try / catch

try { const res = await client.callTool({ name: 'memory-recall', arguments }); } catch (e) { if (e.code === -32602 && /user memory scope is disabled/.test(e.message)) { arguments.scopes = ['project','shared']; return client.callTool({ name: 'memory-recall', arguments }); } throw e; }

Prevention

When it happens

Trigger: A tools/call to a memory recall tool with arguments.scopes containing 'user' (or omitting scopes so DEFAULT_RECALL_SCOPES applies, which includes 'user') while security.allowUserScope is false.

Common situations: Client default recall scopes include 'user' but the server was launched without ECC_MEMORY_ALLOW_USER_SCOPE=1; a multi-harness setup intentionally restricts user scope; config drift between client expectations and server startup env.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/dabd737296a64610. Report an issue: GitHub.

Appendix: source

Thrown at scripts/memory-mcp.mjs:191

function resolveServiceSecurity(options = {}) {
  const env = isRecord(options.env) ? options.env : process.env;
  const harness = options.harness ?? env.ECC_MEMORY_HARNESS;
  if (typeof harness !== 'string' || !SLUG_REGEXP.test(harness)) {
    throw new Error(
      'ECC_MEMORY_HARNESS must identify this MCP server with a lowercase harness slug.'
    );
  }
  return Object.freeze({
    harness,
    allowUserScope: options.allowUserScope ?? env.ECC_MEMORY_ALLOW_USER_SCOPE === '1',
  });
}

function assertScopesAuthorized(scopes, security) {
  const requestedScopes = scopes || DEFAULT_RECALL_SCOPES;
  if (!security.allowUserScope && requestedScopes.includes('user')) {
    throw new JsonRpcError(
      -32602,
      'The user memory scope is disabled for this MCP server.'
    );
  }
  return requestedScopes;
}

function textResult(payload) {
  const text = JSON.stringify(payload, null, 2);
  if (Buffer.byteLength(text, 'utf8') > MAX_RESPONSE_BYTES) {
    throw new JsonRpcError(-32001, 'Memory tool response exceeds the bounded output limit.');
  }
  return {
    content: [{
      type: 'text',
      text,
    }],
  };

View on GitHub (pinned to 8321021c54)