MCP Events pilot
agent-resources exposes a modern MCP 2026-07-28 endpoint at:
https://agent-resources-one.vercel.app/mcp
The first rollout is deliberately narrow: public GitHub activity for KAFKA2306/agent-resources only. It does not expose private repository data or write tools.
Event path
GitHub event
→ GitHub Actions workflow
→ short-lived GitHub OIDC token
→ /api/github-events
→ matching persisted subscriptions
→ signed HTTPS callback
→ ChatGPT Work / dots event task
Supported events:
github.issue.openedgithub.issue.closedgithub.issue.reopenedgithub.issue_comment.createdgithub.pull_request.openedgithub.pull_request.updatedgithub.pull_request.closedgithub.pull_request.reopenedgithub.pull_request_review.submittedgithub.workflow_run.completed
Security boundaries
- MCP Events protocol version:
2026-07-28. - Persistent subscriptions use a private Vercel Blob store.
- Subscription creation fails closed while Blob storage is unavailable.
- Current Vercel Private Blob OIDC authentication is supported; a long-lived
BLOB_READ_WRITE_TOKENis not required for a properly connected OIDC store. - GitHub ingress accepts only GitHub Actions OIDC tokens with audience
agent-resources-mcp-eventsfrom exactlyKAFKA2306/agent-resources. - Callback URLs must use HTTPS on port 443.
- DNS destinations are resolved before connection and private, local, reserved, or mixed public/private answers are rejected.
- Redirects are not followed.
- Deliveries use Standard Webhooks HMAC signatures and are capped at 256 KiB.
- User-authored issue, PR, review, and comment text is emitted as data, never as model instructions.
- Subscription IDs are deterministic and refreshes are idempotent.
- Signing-secret refresh keeps the previous key only for a short rotation window.
Activation
The code is safe to deploy before storage exists. The GitHub emitter treats HTTP 404 during bootstrap and HTTP 503 while storage is unavailable as dormant rather than a CI failure.
To activate subscriptions, attach a private Vercel Blob store to the agent-resources Vercel project. Prefer the current Vercel OIDC connection mode. Then add the MCP endpoint as a personal ChatGPT plugin in developer mode and rescan its events.
Health probe:
https://agent-resources-one.vercel.app/api/mcp-events-health
storageConfigured must be true before events/subscribe can succeed.