{"record":{"id":"2637b85f301b44f6","repo":"upstash/context7","slug":"invalid-response-from-deployment-baseurl-api-auth-mcp","errorCode":null,"errorMessage":"Invalid response from ${deployment.baseUrl}/api/auth/mcp","messagePattern":"Invalid response from (.+?)/api/auth/mcp","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/cli/src/setup/deployment.ts","lineNumber":74,"sourceCode":"  const response = await fetch(`${deployment.baseUrl}/api/auth/mcp`, {\n    headers: { Accept: \"application/json\" },\n    redirect: \"manual\",\n    signal: AbortSignal.timeout(10_000),\n  });\n\n  if (response.status >= 300 && response.status < 400) {\n    throw new Error(\n      `Authentication discovery was redirected. Pass the final deployment URL instead of ${deployment.baseUrl}.`\n    );\n  }\n\n  if (!response.ok) {\n    throw new Error(`HTTP ${response.status} from ${deployment.baseUrl}/api/auth/mcp`);\n  }\n\n  const body = (await response.json()) as { enabled?: unknown };\n  if (typeof body.enabled !== \"boolean\") {\n    throw new Error(`Invalid response from ${deployment.baseUrl}/api/auth/mcp`);\n  }\n  return body.enabled;\n}\n","sourceCodeStart":56,"sourceCodeEnd":78,"githubUrl":"https://github.com/upstash/context7/blob/4416fb855b8f752be735e34f943b5d0762701aad/packages/cli/src/setup/deployment.ts#L56-L78","documentation":"Thrown by getOnPremMcpAuthStatus when the discovery endpoint returns HTTP 200 but the JSON body either isn't parseable as an object or lacks a boolean `enabled` field. The CLI expects `{ enabled: boolean }` to decide whether MCP auth is active on the on-prem deployment; anything else is treated as an invalid response.","triggerScenarios":"getOnPremMcpAuthStatus(deployment) is called, the /api/auth/mcp response is OK, but `JSON.parse` of the body yields a non-object/invalid JSON or `typeof body.enabled !== 'boolean'` — e.g. an HTML error page, empty body, or {\"enabled\": \"yes\"}.","commonSituations":"The base URL points at a reverse proxy or SPA that answers 200 with an HTML page for unknown routes; a deployment version returning a different auth-status schema; a captive portal or WAF intercepting the request.","solutions":["Confirm the URL is the Context7 deployment root (curl the endpoint and inspect the JSON body).","Upgrade the on-prem deployment to a version whose /api/auth/mcp returns { enabled: boolean }.","Remove any proxy/WAF that rewrites the response for this path.","Re-run setup; if the schema intentionally changed, update the CLI version to match your deployment."],"exampleFix":"// before (proxy returns HTML with 200)\ncurl https://my-onprem.internal/api/auth/mcp   # <!DOCTYPE html>...\n\n// after (correct deployment)\ncurl https://context7-onprem.internal/api/auth/mcp   # {\"enabled\":true}","handlingStrategy":"type-guard","validationCode":"const res = await fetch(`${base}/api/auth/mcp`, { headers: { Accept: 'application/json' } });\nconst body: unknown = await res.json().catch(() => null);\nif (!body || typeof body !== 'object' || !('enabled' in body)) {\n  console.error('Endpoint did not return { enabled: boolean } — wrong host or old version');\n}","typeGuard":"function isAuthStatus(v: unknown): v is { enabled: boolean } {\n  return (\n    typeof v === 'object' && v !== null &&\n    'enabled' in v && typeof (v as { enabled: unknown }).enabled === 'boolean'\n  );\n}","tryCatchPattern":"try {\n  const raw: unknown = await response.json();\n  if (!isAuthStatus(raw)) throw new Error('Unexpected /api/auth/mcp response shape');\n} catch (e) {\n  console.error('Check that the base URL is the Context7 deployment root and versions match:', (e as Error).message);\n}","preventionTips":["Validate unknown API payloads with type guards before use.","curl the discovery endpoint and confirm the JSON shape during setup.","Keep on-prem deployment and CLI versions aligned so the auth schema matches."],"tags":["api","schema","http","unexpected-response"],"backgroundTag":"unexpected-response-shape","analyzedSha":"4416fb855b8f752be735e34f943b5d0762701aad","analyzedAt":"2026-09-16T20:28:07.148Z","contentChangedAt":"2026-09-16T20:28:07.148Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}