Waleed 922515ffb0 fix(mcp): bound OAuth discovery/DCR/token fetches with a timeout (#5776)
* fix(mcp): bound OAuth discovery/DCR/token fetches with a timeout

The MCP SDK issues OAuth discovery, dynamic client registration, and token
exchange with a bare fetch and no AbortSignal (only the JSON-RPC layer gets the
SDK's request timeout), and undici's default headers/body timeouts are 5 min. A
slow or unresponsive authorization server therefore left /oauth/start pending for
minutes — the browser stuck on "Connecting…" forever.

Bound each guarded OAuth/revocation leg with a 30s AbortSignal.timeout, composed
with any caller signal so cancellation still works. Only our own deadline is
relabeled to an McpError; caller aborts and other failures propagate unchanged.
Scoped to createSsrfGuardedMcpFetch (OAuth/revoke/probe) — the live transport's
timeouts are untouched.

* fix(mcp): bound SSRF/DNS validation by the deadline too

Move the timeout signal ahead of validateMcpServerSsrf and race the validation
(whose dns.lookup takes no signal) against it, so the deadline covers the whole
guarded call — a stalled DNS resolution now rejects at timeoutMs instead of the
OS DNS timeout. Listener is cleaned up on settle so a late timeout can't surface
as an unhandled rejection.

* fix(mcp): compose caller signal before validation + attribute timeout by reason

Compose the caller's AbortSignal with the deadline up front and use the combined
signal for both SSRF validation and the HTTP request, so caller cancellation now
covers the whole guarded call (previously a caller abort during a stalled DNS
validation waited for the full deadline). Attribute the timeout relabel by the
rejection reason's identity rather than init.signal's state, so a caller signal
that aborts just after the deadline can't misattribute a genuine timeout.

* fix(mcp): adopt in-flight validation on early abort to avoid unhandled rejection

When raceWithSignal is entered with an already-aborted signal it returned without
attaching to the in-flight validateMcpServerSsrf promise, so a later SSRF/DNS
rejection could surface as an unhandled rejection. Swallow the orphaned promise's
settlement in the early-abort branch.

* test(mcp): use sleep() instead of raw setTimeout in pinned-fetch test

check:utils bans new Promise(resolve => setTimeout(...)) in favor of sleep() from
@sim/utils/helpers.
2026-07-20 14:51:42 -07:00

Sim.ai Documentation Slack X

Ask DeepWiki Set Up with Cursor

Sim — Integrate, Context, Build, and Monitor AI agents

A workspace to build, deploy and manage AI agents and workflows.

Quickstart

Cloud-hosted: sim.ai

Open sim.ai

Self-hosted

npx simstudio

Open http://localhost:3000

Docker must be installed and running. Use -p, --port <port> to run Sim on a different port, or --no-pull to skip pulling the latest Docker images.

The Sim platform — chat on the left, the visual workflow builder on the right

Capabilities

  • Connect 1,000+ integrations and every major LLM
  • Add Slack, Notion, HubSpot, Salesforce, databases, and more
  • Build agents visually, conversationally, or with code
  • Ingest files, knowledge bases, and structured table data
  • Monitor runs, logs, schedules, and workflow activity

One workspace, every surface

Chat and workflows are just the start — tables, files, knowledge, and scheduled tasks all live in the same workspace.

Tables in Sim — structured data your agents can query

Tables — a database, built in

Files in Sim — documents for your team and every agent

Files — one store for your team and every agent

Knowledge bases in Sim — synced docs your agents can search

Knowledge — your agents' memory

Scheduled tasks in Sim — recurring agent runs on a calendar

Scheduled tasks — runs on your schedule

Self-hosting

Docker Compose

git clone https://github.com/simstudioai/sim.git && cd sim
docker compose -f docker-compose.prod.yml up -d

Open http://localhost:3000

Sim also supports local models via Ollama and vLLM. See the Docker self-hosting docs for setup details.

Manual Setup

Requirements: Bun, Node.js v20+, PostgreSQL 12+ with pgvector

  1. Clone and install:
git clone https://github.com/simstudioai/sim.git
cd sim
bun install
bun run prepare  # Set up pre-commit hooks
  1. Set up PostgreSQL with pgvector:
docker run --name simstudio-db -e POSTGRES_PASSWORD=your_password -e POSTGRES_DB=simstudio -p 5432:5432 -d pgvector/pgvector:pg17

Or install manually via the pgvector guide.

  1. Configure environment:
cp apps/sim/.env.example apps/sim/.env
# Create your secrets
perl -i -pe "s/your_encryption_key/$(openssl rand -hex 32)/" apps/sim/.env
perl -i -pe "s/your_internal_api_secret/$(openssl rand -hex 32)/" apps/sim/.env
perl -i -pe "s/your_api_encryption_key/$(openssl rand -hex 32)/" apps/sim/.env
# DB configs for migration
cp packages/db/.env.example packages/db/.env
# Edit both .env files to set DATABASE_URL="postgresql://postgres:your_password@localhost:5432/simstudio"
  1. Run migrations:
cd packages/db && bun run db:migrate
  1. Start development servers:
bun run dev:full  # Starts Next.js app and realtime socket server

Or run separately: bun run dev (Next.js) and cd apps/sim && bun run dev:sockets (realtime).

Chat API Keys

Chat is a Sim-managed service. To use Chat on a self-hosted instance:

  • Go to https://sim.ai → Settings → Chat keys and generate a Chat API key
  • Set COPILOT_API_KEY environment variable in your self-hosted apps/sim/.env file to that value

Environment Variables

See the environment variables reference for the full list, or apps/sim/.env.example for defaults.

Tech Stack

Next.js · Bun · PostgreSQL · Drizzle · Better Auth · Tailwind — and the rest of the stack

Contributing

We welcome contributions! Please see our Contributing Guide for details.

License

This project is licensed under the Apache License 2.0 - see the LICENSE file for details.

Built by the Sim team in San Francisco

Languages
TypeScript 77%
MDX 20.8%
JavaScript 1.9%
CSS 0.1%