diff --git a/cli/testdata/coder_server_--help.golden b/cli/testdata/coder_server_--help.golden
index 068762bf89..3bc109d461 100644
--- a/cli/testdata/coder_server_--help.golden
+++ b/cli/testdata/coder_server_--help.golden
@@ -143,11 +143,6 @@ AI BRIDGE OPTIONS:
--aibridge-enabled bool, $CODER_AIBRIDGE_ENABLED (default: false)
Whether to start an in-memory aibridged instance.
- --aibridge-inject-coder-mcp-tools bool, $CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS (default: false)
- Whether to inject Coder's MCP tools into intercepted AI Bridge
- requests (requires the "oauth2" and "mcp-server-http" experiments to
- be enabled).
-
--aibridge-max-concurrency int, $CODER_AIBRIDGE_MAX_CONCURRENCY (default: 0)
Maximum number of concurrent AI Bridge requests per replica. Set to 0
to disable (unlimited).
diff --git a/cli/testdata/server-config.yaml.golden b/cli/testdata/server-config.yaml.golden
index 5c9eb8bd8b..974dec3b28 100644
--- a/cli/testdata/server-config.yaml.golden
+++ b/cli/testdata/server-config.yaml.golden
@@ -778,8 +778,10 @@ aibridge:
# https://docs.claude.com/en/docs/claude-code/settings#environment-variables.
# (default: global.anthropic.claude-haiku-4-5-20251001-v1:0, type: string)
bedrock_small_fast_model: global.anthropic.claude-haiku-4-5-20251001-v1:0
- # Whether to inject Coder's MCP tools into intercepted AI Bridge requests
- # (requires the "oauth2" and "mcp-server-http" experiments to be enabled).
+ # Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a
+ # future release. Whether to inject Coder's MCP tools into intercepted AI Bridge
+ # requests (requires the "oauth2" and "mcp-server-http" experiments to be
+ # enabled).
# (default: false, type: bool)
inject_coder_mcp_tools: false
# Length of time to retain data such as interceptions and all related records
diff --git a/coderd/apidoc/docs.go b/coderd/apidoc/docs.go
index 6c62a51fc7..d467e93342 100644
--- a/coderd/apidoc/docs.go
+++ b/coderd/apidoc/docs.go
@@ -12448,6 +12448,7 @@ const docTemplate = `{
"type": "boolean"
},
"inject_coder_mcp_tools": {
+ "description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "boolean"
},
"max_concurrency": {
@@ -15336,12 +15337,15 @@ const docTemplate = `{
"type": "string"
},
"mcp_tool_allow_regex": {
+ "description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"mcp_tool_deny_regex": {
+ "description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"mcp_url": {
+ "description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"no_refresh": {
diff --git a/coderd/apidoc/swagger.json b/coderd/apidoc/swagger.json
index 17f2a705de..3dec24581d 100644
--- a/coderd/apidoc/swagger.json
+++ b/coderd/apidoc/swagger.json
@@ -11058,6 +11058,7 @@
"type": "boolean"
},
"inject_coder_mcp_tools": {
+ "description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "boolean"
},
"max_concurrency": {
@@ -13858,12 +13859,15 @@
"type": "string"
},
"mcp_tool_allow_regex": {
+ "description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"mcp_tool_deny_regex": {
+ "description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"mcp_url": {
+ "description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"no_refresh": {
diff --git a/coderd/externalauth/externalauth.go b/coderd/externalauth/externalauth.go
index 2572154131..532c5b7e27 100644
--- a/coderd/externalauth/externalauth.go
+++ b/coderd/externalauth/externalauth.go
@@ -95,14 +95,20 @@ type Config struct {
// AppInstallationsURL is an API endpoint that returns a list of
// installations for the user. This is used for GitHub Apps.
AppInstallationsURL string
+ // Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ //
// MCPURL is the endpoint that clients must use to communicate with the associated
// MCP server.
MCPURL string
+ // Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ //
// MCPToolAllowRegex is a [regexp.Regexp] to match tools which are explicitly allowed to be
// injected into Coder AI Bridge upstream requests.
// In the case of conflicts, [MCPToolDenylistPattern] overrides items evaluated by this list.
// This field can be nil if unspecified in the config.
MCPToolAllowRegex *regexp.Regexp
+ // Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ //
// MCPToolDenyRegex is a [regexp.Regexp] to match tools which are explicitly NOT allowed to be
// injected into Coder AI Bridge upstream requests.
// In the case of conflicts, items evaluated by this list override [MCPToolAllowRegex].
diff --git a/codersdk/deployment.go b/codersdk/deployment.go
index 248e82685e..534ed5f4c9 100644
--- a/codersdk/deployment.go
+++ b/codersdk/deployment.go
@@ -970,9 +970,12 @@ type ExternalAuthConfig struct {
ExtraTokenKeys []string `json:"-" yaml:"extra_token_keys"`
DeviceFlow bool `json:"device_flow" yaml:"device_flow"`
DeviceCodeURL string `json:"device_code_url" yaml:"device_code_url"`
- MCPURL string `json:"mcp_url" yaml:"mcp_url"`
- MCPToolAllowRegex string `json:"mcp_tool_allow_regex" yaml:"mcp_tool_allow_regex"`
- MCPToolDenyRegex string `json:"mcp_tool_deny_regex" yaml:"mcp_tool_deny_regex"`
+ // Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ MCPURL string `json:"mcp_url" yaml:"mcp_url"`
+ // Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ MCPToolAllowRegex string `json:"mcp_tool_allow_regex" yaml:"mcp_tool_allow_regex"`
+ // Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ MCPToolDenyRegex string `json:"mcp_tool_deny_regex" yaml:"mcp_tool_deny_regex"`
// Regex allows API requesters to match an auth config by
// a string (e.g. coder.com) instead of by it's type.
//
@@ -3712,13 +3715,14 @@ Write out the current server config as YAML to stdout.`,
},
{
Name: "AI Bridge Inject Coder MCP tools",
- Description: "Whether to inject Coder's MCP tools into intercepted AI Bridge requests (requires the \"oauth2\" and \"mcp-server-http\" experiments to be enabled).",
+ Description: "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. Whether to inject Coder's MCP tools into intercepted AI Bridge requests (requires the \"oauth2\" and \"mcp-server-http\" experiments to be enabled).",
Flag: "aibridge-inject-coder-mcp-tools",
Env: "CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS",
Value: &c.AI.BridgeConfig.InjectCoderMCPTools,
Default: "false",
Group: &deploymentGroupAIBridge,
YAML: "inject_coder_mcp_tools",
+ Hidden: true,
},
{
Name: "AI Bridge Data Retention Duration",
@@ -3997,16 +4001,17 @@ Write out the current server config as YAML to stdout.`,
}
type AIBridgeConfig struct {
- Enabled serpent.Bool `json:"enabled" typescript:",notnull"`
- OpenAI AIBridgeOpenAIConfig `json:"openai" typescript:",notnull"`
- Anthropic AIBridgeAnthropicConfig `json:"anthropic" typescript:",notnull"`
- Bedrock AIBridgeBedrockConfig `json:"bedrock" typescript:",notnull"`
- InjectCoderMCPTools serpent.Bool `json:"inject_coder_mcp_tools" typescript:",notnull"`
- Retention serpent.Duration `json:"retention" typescript:",notnull"`
- MaxConcurrency serpent.Int64 `json:"max_concurrency" typescript:",notnull"`
- RateLimit serpent.Int64 `json:"rate_limit" typescript:",notnull"`
- StructuredLogging serpent.Bool `json:"structured_logging" typescript:",notnull"`
- SendActorHeaders serpent.Bool `json:"send_actor_headers" typescript:",notnull"`
+ Enabled serpent.Bool `json:"enabled" typescript:",notnull"`
+ OpenAI AIBridgeOpenAIConfig `json:"openai" typescript:",notnull"`
+ Anthropic AIBridgeAnthropicConfig `json:"anthropic" typescript:",notnull"`
+ Bedrock AIBridgeBedrockConfig `json:"bedrock" typescript:",notnull"`
+ // Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ InjectCoderMCPTools serpent.Bool `json:"inject_coder_mcp_tools" typescript:",notnull"`
+ Retention serpent.Duration `json:"retention" typescript:",notnull"`
+ MaxConcurrency serpent.Int64 `json:"max_concurrency" typescript:",notnull"`
+ RateLimit serpent.Int64 `json:"rate_limit" typescript:",notnull"`
+ StructuredLogging serpent.Bool `json:"structured_logging" typescript:",notnull"`
+ SendActorHeaders serpent.Bool `json:"send_actor_headers" typescript:",notnull"`
// Circuit breaker protects against cascading failures from upstream AI
// provider rate limits (429, 503, 529 overloaded).
CircuitBreakerEnabled serpent.Bool `json:"circuit_breaker_enabled" typescript:",notnull"`
diff --git a/docs/ai-coder/ai-bridge/mcp.md b/docs/ai-coder/ai-bridge/mcp.md
index d9061ec2b0..a4e8ee2453 100644
--- a/docs/ai-coder/ai-bridge/mcp.md
+++ b/docs/ai-coder/ai-bridge/mcp.md
@@ -1,5 +1,8 @@
# MCP
+> [!WARNING]
+> Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+
[Model Context Protocol (MCP)](https://modelcontextprotocol.io/docs/getting-started/intro) is a mechanism for connecting AI applications to external systems.
AI Bridge can connect to MCP servers and inject tools automatically, enabling you to centrally manage the list of tools you wish to grant your users.
@@ -55,7 +58,7 @@ If a model decides to invoke a tool and it has a `bmcp_` suffix and AI Bridge ha
In contrast, tools which are defined by the client (i.e. the [`Bash` tool](https://docs.claude.com/en/docs/claude-code/settings#tools-available-to-claude) defined by _Claude Code_) cannot be invoked by AI Bridge, and the tool call from the model will be relayed to the client, after which it will invoke the tool.
-If you have [Coder MCP Server](../mcp-server.md) enabled, as well as have [`CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS=true`](../../reference/cli/server#--aibridge-inject-coder-mcp-tools) set, Coder's MCP tools will be injected into intercepted requests.
+If you have [Coder MCP Server](../mcp-server.md) enabled, as well as have `CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS=true` set, Coder's MCP tools will be injected into intercepted requests.
### Troubleshooting
diff --git a/docs/reference/api/schemas.md b/docs/reference/api/schemas.md
index 7b86dce0bd..695395553d 100644
--- a/docs/reference/api/schemas.md
+++ b/docs/reference/api/schemas.md
@@ -422,7 +422,7 @@
| `circuit_breaker_max_requests` | integer | false | | |
| `circuit_breaker_timeout` | integer | false | | |
| `enabled` | boolean | false | | |
-| `inject_coder_mcp_tools` | boolean | false | | |
+| `inject_coder_mcp_tools` | boolean | false | | Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. |
| `max_concurrency` | integer | false | | |
| `openai` | [codersdk.AIBridgeOpenAIConfig](#codersdkaibridgeopenaiconfig) | false | | |
| `rate_limit` | integer | false | | |
@@ -4151,9 +4151,9 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
| `display_icon` | string | false | | Display icon is a URL to an icon to display in the UI. |
| `display_name` | string | false | | Display name is shown in the UI to identify the auth config. |
| `id` | string | false | | ID is a unique identifier for the auth config. It defaults to `type` when not provided. |
-| `mcp_tool_allow_regex` | string | false | | |
-| `mcp_tool_deny_regex` | string | false | | |
-| `mcp_url` | string | false | | |
+| `mcp_tool_allow_regex` | string | false | | Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. |
+| `mcp_tool_deny_regex` | string | false | | Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. |
+| `mcp_url` | string | false | | Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. |
| `no_refresh` | boolean | false | | |
|`regex`|string|false||Regex allows API requesters to match an auth config by a string (e.g. coder.com) instead of by it's type.
Git clone makes use of this by parsing the URL from: 'Username for "https://github.com":' And sending it to the Coder server to match against the Regex.|
diff --git a/docs/reference/cli/server.md b/docs/reference/cli/server.md
index acb0dcfc7b..d885cd0a22 100644
--- a/docs/reference/cli/server.md
+++ b/docs/reference/cli/server.md
@@ -1813,17 +1813,6 @@ The model to use when making requests to the AWS Bedrock API.
The small fast model to use when making requests to the AWS Bedrock API. Claude Code uses Haiku-class models to perform background tasks. See https://docs.claude.com/en/docs/claude-code/settings#environment-variables.
-### --aibridge-inject-coder-mcp-tools
-
-| | |
-|-------------|-----------------------------------------------------|
-| Type | bool |
-| Environment | $CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS |
-| YAML | aibridge.inject_coder_mcp_tools |
-| Default | false |
-
-Whether to inject Coder's MCP tools into intercepted AI Bridge requests (requires the "oauth2" and "mcp-server-http" experiments to be enabled).
-
### --aibridge-retention
| | |
diff --git a/enterprise/aibridged/mcp.go b/enterprise/aibridged/mcp.go
index 132139b990..800149f727 100644
--- a/enterprise/aibridged/mcp.go
+++ b/enterprise/aibridged/mcp.go
@@ -23,6 +23,7 @@ const (
InternalMCPServerID = "coder"
)
+// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
type MCPProxyBuilder interface {
// Build creates a [mcp.ServerProxier] for the given request initiator.
// At minimum, the Coder MCP server will be proxied.
@@ -34,6 +35,7 @@ type MCPProxyBuilder interface {
var _ MCPProxyBuilder = &MCPProxyFactory{}
+// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
type MCPProxyFactory struct {
logger slog.Logger
tracer trace.Tracer
diff --git a/enterprise/aibridgedserver/aibridgedserver.go b/enterprise/aibridgedserver/aibridgedserver.go
index e052e9a9aa..54104b7f4f 100644
--- a/enterprise/aibridgedserver/aibridgedserver.go
+++ b/enterprise/aibridgedserver/aibridgedserver.go
@@ -105,6 +105,7 @@ func NewServer(lifecycleCtx context.Context, store store, logger slog.Logger, ac
}
if bridgeCfg.InjectCoderMCPTools {
+ logger.Warn(lifecycleCtx, "inject MCP tools option is deprecated and will be removed in a future release")
coderMCPConfig, err := getCoderMCPServerConfig(experiments, accessURL)
if err != nil {
logger.Warn(lifecycleCtx, "failed to retrieve coder MCP server config, Coder MCP will not be available", slog.Error(err))
@@ -551,6 +552,7 @@ func (s *Server) IsAuthorized(ctx context.Context, in *proto.IsAuthorizedRequest
}, nil
}
+// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
func getCoderMCPServerConfig(experiments codersdk.Experiments, accessURL string) (*proto.MCPServerConfig, error) {
// Both the MCP & OAuth2 experiments are currently required in order to use our
// internal MCP server.
diff --git a/enterprise/cli/testdata/coder_server_--help.golden b/enterprise/cli/testdata/coder_server_--help.golden
index 3d1476f974..bdc48598cc 100644
--- a/enterprise/cli/testdata/coder_server_--help.golden
+++ b/enterprise/cli/testdata/coder_server_--help.golden
@@ -144,11 +144,6 @@ AI BRIDGE OPTIONS:
--aibridge-enabled bool, $CODER_AIBRIDGE_ENABLED (default: false)
Whether to start an in-memory aibridged instance.
- --aibridge-inject-coder-mcp-tools bool, $CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS (default: false)
- Whether to inject Coder's MCP tools into intercepted AI Bridge
- requests (requires the "oauth2" and "mcp-server-http" experiments to
- be enabled).
-
--aibridge-max-concurrency int, $CODER_AIBRIDGE_MAX_CONCURRENCY (default: 0)
Maximum number of concurrent AI Bridge requests per replica. Set to 0
to disable (unlimited).
diff --git a/site/src/api/typesGenerated.ts b/site/src/api/typesGenerated.ts
index fd9181b607..0f60f47146 100644
--- a/site/src/api/typesGenerated.ts
+++ b/site/src/api/typesGenerated.ts
@@ -32,6 +32,9 @@ export interface AIBridgeConfig {
readonly openai: AIBridgeOpenAIConfig;
readonly anthropic: AIBridgeAnthropicConfig;
readonly bedrock: AIBridgeBedrockConfig;
+ /**
+ * Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ */
readonly inject_coder_mcp_tools: boolean;
readonly retention: number;
readonly max_concurrency: number;
@@ -2711,8 +2714,17 @@ export interface ExternalAuthConfig {
readonly scopes: readonly string[];
readonly device_flow: boolean;
readonly device_code_url: string;
+ /**
+ * Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ */
readonly mcp_url: string;
+ /**
+ * Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ */
readonly mcp_tool_allow_regex: string;
+ /**
+ * Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
+ */
readonly mcp_tool_deny_regex: string;
/**
* Regex allows API requesters to match an auth config by