{"record":{"id":"9a81417b90aed30f","repo":"upstash/context7","slug":"http-response-status-from-deployment-baseurl-api-auth-mcp","errorCode":null,"errorMessage":"HTTP ${response.status} from ${deployment.baseUrl}/api/auth/mcp","messagePattern":"HTTP (.+?) from (.+?)/api/auth/mcp","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/cli/src/setup/deployment.ts","lineNumber":69,"sourceCode":"  }\n  return `${deployment.baseUrl}/mcp`;\n}\n\nexport async function getOnPremMcpAuthStatus(deployment: CustomSetupDeployment): Promise<boolean> {\n  const response = await fetch(`${deployment.baseUrl}/api/auth/mcp`, {\n    headers: { Accept: \"application/json\" },\n    redirect: \"manual\",\n    signal: AbortSignal.timeout(10_000),\n  });\n\n  if (response.status >= 300 && response.status < 400) {\n    throw new Error(\n      `Authentication discovery was redirected. Pass the final deployment URL instead of ${deployment.baseUrl}.`\n    );\n  }\n\n  if (!response.ok) {\n    throw new Error(`HTTP ${response.status} from ${deployment.baseUrl}/api/auth/mcp`);\n  }\n\n  const body = (await response.json()) as { enabled?: unknown };\n  if (typeof body.enabled !== \"boolean\") {\n    throw new Error(`Invalid response from ${deployment.baseUrl}/api/auth/mcp`);\n  }\n  return body.enabled;\n}\n","sourceCodeStart":51,"sourceCodeEnd":78,"githubUrl":"https://github.com/upstash/context7/blob/4416fb855b8f752be735e34f943b5d0762701aad/packages/cli/src/setup/deployment.ts#L51-L78","documentation":"Thrown by getOnPremMcpAuthStatus when the auth discovery endpoint `${deployment.baseUrl}/api/auth/mcp` returns a non-OK, non-redirect status. It surfaces the raw HTTP status so the user can tell whether the endpoint is missing, unauthorized, or the server is failing.","triggerScenarios":"getOnPremMcpAuthStatus(deployment) is called and the fetch to /api/auth/mcp responds with status >= 400 (e.g. 401, 404, 500) or < 300 but not OK — after the 3xx check has passed.","commonSituations":"The base URL points to an app that doesn't expose /api/auth/mcp (404); an auth proxy rejects the unauthenticated probe (401/403); the on-prem deployment is an older/newer version without the MCP auth endpoint; server-side crash (500).","solutions":["Verify the base URL points at the actual Context7 deployment root, not a proxy or unrelated app.","Confirm the on-prem deployment version includes the MCP auth endpoint (/api/auth/mcp).","Check server logs for the corresponding error; retry if the status was 5xx/transient.","If an auth gateway blocks the probe, allow unauthenticated access to the discovery path."],"exampleFix":"// before (wrong host, 404)\nctx7 setup --url https://unrelated-app.internal\n\n// after (actual Context7 deployment)\nctx7 setup --url https://context7-onprem.internal","handlingStrategy":"retry","validationCode":"const res = await fetch(`${base}/api/auth/mcp`, { redirect: 'manual' });\nif (res.status === 404) console.error('Endpoint missing — check deployment version/base URL');\nif (res.status >= 500) console.error('Server error — retry later');","typeGuard":null,"tryCatchPattern":"try {\n  const enabled = await getOnPremMcpAuthStatus(deployment);\n} catch (e) {\n  const m = (e as Error).message.match(/^HTTP (\\d+)/);\n  if (m && Number(m[1]) >= 500) await retryWithBackoff(() => getOnPremMcpAuthStatus(deployment));\n  else console.error('Verify base URL and deployment version:', (e as Error).message);\n}","preventionTips":["Point the base URL at the real Context7 deployment root, not a proxy or unrelated app.","Confirm your on-prem version exposes /api/auth/mcp.","Retry 5xx; investigate 4xx (proxy auth blocking the probe)."],"tags":["http","api","network","configuration"],"backgroundTag":"http-error-status","analyzedSha":"4416fb855b8f752be735e34f943b5d0762701aad","analyzedAt":"2026-09-16T20:28:07.148Z","contentChangedAt":"2026-09-16T20:28:07.148Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}