upstash/context7 · error

Invalid response from

Error message

Invalid response from ${deployment.baseUrl}/api/auth/mcp

What it means

Thrown by getOnPremMcpAuthStatus when the discovery endpoint returns HTTP 200 but the JSON body either isn't parseable as an object or lacks a boolean `enabled` field. The CLI expects `{ enabled: boolean }` to decide whether MCP auth is active on the on-prem deployment; anything else is treated as an invalid response.

Solutions

  1. Confirm the URL is the Context7 deployment root (curl the endpoint and inspect the JSON body).
  2. Upgrade the on-prem deployment to a version whose /api/auth/mcp returns { enabled: boolean }.
  3. Remove any proxy/WAF that rewrites the response for this path.
  4. Re-run setup; if the schema intentionally changed, update the CLI version to match your deployment.

Example fix

// before (proxy returns HTML with 200)
curl https://my-onprem.internal/api/auth/mcp   # <!DOCTYPE html>...

// after (correct deployment)
curl https://context7-onprem.internal/api/auth/mcp   # {"enabled":true}
Defensive patterns

Strategy: type-guard

Validate before calling

const res = await fetch(`${base}/api/auth/mcp`, { headers: { Accept: 'application/json' } });
const body: unknown = await res.json().catch(() => null);
if (!body || typeof body !== 'object' || !('enabled' in body)) {
  console.error('Endpoint did not return { enabled: boolean } — wrong host or old version');
}

Type guard

function isAuthStatus(v: unknown): v is { enabled: boolean } {
  return (
    typeof v === 'object' && v !== null &&
    'enabled' in v && typeof (v as { enabled: unknown }).enabled === 'boolean'
  );
}

Try / catch

try {
  const raw: unknown = await response.json();
  if (!isAuthStatus(raw)) throw new Error('Unexpected /api/auth/mcp response shape');
} catch (e) {
  console.error('Check that the base URL is the Context7 deployment root and versions match:', (e as Error).message);
}

Prevention

When it happens

Trigger: getOnPremMcpAuthStatus(deployment) is called, the /api/auth/mcp response is OK, but `JSON.parse` of the body yields a non-object/invalid JSON or `typeof body.enabled !== 'boolean'` — e.g. an HTML error page, empty body, or {"enabled": "yes"}.

Common situations: The base URL points at a reverse proxy or SPA that answers 200 with an HTML page for unknown routes; a deployment version returning a different auth-status schema; a captive portal or WAF intercepting the request.

Related errors


AI-assisted analysis of upstash/context7@4416fb855b (2026-09-16). Data as JSON: /api/errors/2637b85f301b44f6. Report an issue: GitHub.

Appendix: source

Thrown at packages/cli/src/setup/deployment.ts:74

  const response = await fetch(`${deployment.baseUrl}/api/auth/mcp`, {
    headers: { Accept: "application/json" },
    redirect: "manual",
    signal: AbortSignal.timeout(10_000),
  });

  if (response.status >= 300 && response.status < 400) {
    throw new Error(
      `Authentication discovery was redirected. Pass the final deployment URL instead of ${deployment.baseUrl}.`
    );
  }

  if (!response.ok) {
    throw new Error(`HTTP ${response.status} from ${deployment.baseUrl}/api/auth/mcp`);
  }

  const body = (await response.json()) as { enabled?: unknown };
  if (typeof body.enabled !== "boolean") {
    throw new Error(`Invalid response from ${deployment.baseUrl}/api/auth/mcp`);
  }
  return body.enabled;
}

View on GitHub (pinned to 4416fb855b)