Skip to content

feat!: publish exa-mcp-server 4.0.0 library release - #448

Merged
wlue merged 8 commits into
v4from
remove-exa-tooling-from-mcp
Sep 30, 2026
Merged

wlue merged 8 commits into
v4from
remove-exa-tooling-from-mcp

Conversation

@wlue

@wlue wlue commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Prepare exa-mcp-server 4.0.0 as a breaking release after the library split and remove the deprecated OSS tool surface.

  • Publish ESM, CommonJS, and declaration library artifacts alongside the stdio CLI.
  • Expose initializeMcpServer, individual tool registration helpers, registry metadata, request header overrides, and provider-neutral opt-in analytics.
  • Remove the bundled Agnost analytics backend and keep hosted runtime behavior aligned with origin/main.
  • Remove deprecated tool implementations, registry entries, old Agent selection aliases, and compatibility-only registration overloads.
  • Update package, lockfile, server registry, Gemini extension, plugin, and CLI metadata to 4.0.0.

Breaking changes

  • The public package entry point is now dist/index.js / dist/index.cjs; the CLI remains available through the exa-mcp-server bin.
  • Analytics are no longer installed or emitted by default. Embedders that need instrumentation must provide the analytics hooks.
  • The OSS tool surface is limited to web_search_exa, web_search_advanced_exa, web_fetch_exa, and agent_run.
  • The active tool names and schemas remain stable for wire compatibility with the private MCP. Deprecated private-only tools and selection aliases are no longer shipped by OSS.

Validation

  • npm run ci
  • npm run build
  • npm pack --dry-run
  • ESM and CommonJS import smoke tests

wlue and others added 6 commits September 29, 2026 13:13
…nsion point

Phase 1 of the OSS/hosted split: make the package embeddable so wrapping
servers can consume the tool surface from npm instead of forking.

- Add src/index.ts as the public library entry, exporting
  initializeMcpServer, McpConfig, the tool registry, and the live tool
  registrars (web search, advanced search, fetch, agent run).
- Ship real library artifacts: ESM + CJS bundles and .d.ts files with a
  package exports map (the old "module" field pointed at raw TS source).
- Add McpConfig.requestHeaders: extra headers merged into every Exa API
  request after the built-in ones, so embedders can add attribution or
  override auth without package changes.
- Add a contract snapshot test pinning exported symbols and the
  registered tool/prompt/resource surface (names, schemas, descriptions,
  annotations) that downstream consumers depend on.
- Bump version to 3.3.0 across package.json, server.json,
  gemini-extension.json, and the serverInfo blocks.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…m in contract

Prepares the package for consumption by the hosted MCP server as an npm
dependency:

- Analytics are now injectable: initializeMcpServer only attaches Agnost
  tracking when config.analytics.agnostOrgId is explicitly provided.
  Library embedders get no tracking (and never inherit Exa's public write
  key) by default; the stdio and hosted entrypoints opt in explicitly
  with EXA_PUBLIC_AGNOST_ORG_ID, so their behavior is unchanged. The
  constant is deliberately not re-exported from the library entry.
- Contract snapshot now spells out zod enum values per param (e.g. the
  search category list), so accepted input values are drift-guarded, not
  just param names. Confirms `publication` as the canonical category per
  the live Exa API docs; the hosted server's `research paper` is the
  stale side of the mismatch and converges by adopting the library.
- Header extension verified for hosted needs: x-exa-integration,
  OAuth Authorization, x-exa-mcp-session-id, and x-exa-mcp-client are
  all built-ins, with requestHeaders merging last; new test asserts an
  embedder header overrides built-in OAuth/session headers.
- New piecemeal embedding test: registering individual tools onto a
  plain server fires no tracking side effects and the registry helpers
  work standalone.
- Bump version to 3.4.0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The package no longer ships any analytics backend or vendor dependency.
McpConfig.analytics now takes a small McpAnalytics interface:

- checkpoint(event, attributes?) — called from inside tool handlers with
  the same event names and attributes the previous inline markers used,
  so downstream dashboards keyed on them keep working
- wrapServer(server) — applied once per initializeMcpServer to the
  underlying server object, for providers that instrument transports

Both hooks are optional and the default is a no-op: embedders get zero
analytics side effects unless they pass a provider. The stdio and hosted
entrypoints no longer carry a tracking write key; the production write
key that was hardcoded here is in public git history and must be rotated
server-side — it no longer appears in the tree in any form.

Also drops the vendor dependency from package.json, threads the
analytics provider through every tool config, and adds tests for
wrapServer application, registration-time side-effect freedom, checkpoint
event-name stability, and full requestHeaders override precedence over
all built-in headers. Bump version to 3.5.0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The snapshot was interface data living in a test artifact — wrong review
weight, and its hand-rolled zod descriptor only approximated the wire
surface anyway. Keep the plain assertions on exported symbols and default
tool registration.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@wlue
wlue changed the base branch from main to v4 September 29, 2026 21:10
@wlue
wlue merged commit 122704a into v4 Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant