Files
LangBot/skills/skills/langbot-space-ops/SKILL.md
T
Junyan Chin e9dd584792 feat: MCP server + in-repo skills (agent-friendly platform) (#2269)
* feat(api): support global API key from config.yaml (api.global_api_key)

Accept a config-defined global API key anywhere a web-UI key is accepted
(X-API-Key / Bearer), with no login session and no DB record. Useful for
automated deployments and AI agents (HTTP API + MCP). Defaults to empty
(disabled); does not require the lbk_ prefix.

- templates/config.yaml: add api.global_api_key with security notes
- service/apikey.py: verify_api_key checks global key first (constant-time)
- docs/API_KEY_AUTH.md: document the global key + security guidance
- tests: cover global-key match, prefix-free, fallback-to-db, disabled

* feat(mcp): expose LangBot management as an MCP server at /mcp

Add an MCP (Model Context Protocol) server so external AI agents can manage a
LangBot instance. Reuses the same API-key auth as the HTTP API (including the
config.yaml global API key).

- pkg/api/mcp/server.py: FastMCP server wrapping the service layer; 21 curated
  tools across system/bots/pipelines/models/knowledge/mcp-servers/skills
- pkg/api/mcp/mount.py: ASGI dispatcher fronting Quart; authenticates /mcp
  requests with an API key, runs the streamable-HTTP session manager lifespan
- controller/main.py: serve the wrapped ASGI app via hypercorn (was run_task)
- web: new 'MCP' tab in the API integration dialog showing endpoint, auth, and
  client config; i18n for 8 locales
- tests/manual/mcp_smoke.py: e2e check (401 unauth, list tools, call tools)

Tool surface is intentionally curated (not all ~25 route groups) to keep the
agent surface small, safe, and maintainable. Extend deliberately.

* feat(skills): add in-repo skills/ as the single source of truth

Migrate the agent skills + QA/e2e test harness from the (now archived)
langbot-app/langbot-skills repo into LangBot/skills/, and add four new skills.

Migrated:
- langbot-plugin-dev, langbot-testing (e2e), langbot-env-setup,
  langbot-skills-maintenance, langbot-eba-adapter-dev
- the bin/lbs CLI (src/, test/, scripts/, schemas/, qa-agent-docs/)

New:
- langbot-dev      core backend + web development
- langbot-deploy   Docker/K8s deployment + config.yaml + global API key
- langbot-mcp-ops  operating the LangBot MCP server (/mcp)
- langbot-space-ops operating the Space marketplace MCP server

- src/cli.ts repoRoot(): recognize the skills assets root (skills.index.json +
  bin/lbs) so the CLI works when nested inside the LangBot repo
- README.md: unified skill catalog; skills.index.json regenerated

Parity with source verified: bin/lbs validate + node test suite match the
source repo (only the uncommitted .lbpkg build-artifact fixture differs).

* docs(agents): document agent-facing surfaces + API/MCP/skills sync rule

* docs(readme): add 'Built for AI Agents' section across all locales

Highlight MCP server, in-repo skills (single source of truth), AGENTS.md
sync rule, and llms.txt. Cross-link LangBot Space MCP marketplace.

* style(mcp): fix ruff format + prettier lint in MCP server and API panel

* style(web): prettier format MCP i18n locale entries

* docs(skills): note MCP instance control in dev/testing skills

All development-guidance skills now point to the LangBot instance MCP
server (/mcp) and the Space marketplace MCP server, reusing API keys.
2026-06-20 15:14:47 +08:00

2.9 KiB

name, description
name description
langbot-space-ops Browse and search the LangBot Space marketplaces (plugins, MCP servers, skills) through the Space MCP server. Use when an AI agent needs to discover LangBot extensions on space.langbot.app over MCP. Covers the /mcp endpoint, Personal Access Token (PAT) auth, the tool surface, and client configuration. Triggers on "langbot space mcp", "search langbot plugins", "langbot marketplace mcp", "space.langbot.app mcp".

LangBot Space MCP Operations

LangBot Space (space.langbot.app) exposes an MCP server so user-facing AI agents can browse and search the marketplaces (plugins, MCP servers, skills).

Endpoint

https://space.langbot.app/mcp

Transport: streamable HTTP (stateless, JSON responses). For a self-hosted Space instance: http://<host>:8383/mcp.

Authentication

Reuses the existing Personal Access Token (PAT) — the same token the lbp CLI uses. Create one in your Space account (Profile → Personal Access Tokens), then send it as a Bearer token:

Authorization: Bearer lbpat_...uests without a valid PAT get `401 Unauthorized`.

## Client configuration

```json
{
  "mcpServers": {
    "langbot-space": {
      "url": "https://space.langbot.app/mcp",
      "headers": { "Authorization": "Bearer <your-pat>" }
    }
  }
}

Tool surface

Tool Purpose
list_plugins / search_plugins / get_plugin Plugin marketplace
list_mcp_servers / search_mcp_servers / get_mcp_server MCP-server marketplace
list_skills / search_skills / get_skill Skill marketplace

list_* and search_* are paged (page, page_size). get_* takes author + name. The tool surface mirrors the REST endpoints under /api/v1/marketplace/* and is read/browse only.

How to use

  1. Create a PAT in your Space account settings.
  2. Point your MCP client at https://space.langbot.app/mcp with the Bearer PAT.
  3. Use search_plugins / search_mcp_servers / search_skills to find items, then get_* for details (e.g. to obtain author/name for installation in LangBot itself).

Implementation & maintenance (for Space developers)

  • Server: internal/controller/mcp/server.go (official Go MCP SDK github.com/modelcontextprotocol/go-sdk). Tools call the service layer (PluginService, MCPService, SkillService) directly.
  • Mount: internal/controller/api.go at /mcp and /mcp/*any.
  • Auth: PAT via AccountService.ValidatePersonalAccessToken.
  • Docs: docs/MCP_SERVER.md.

When you add, remove, or change a marketplace API endpoint that should be agent-accessible, update the corresponding MCP tool and this skill. The MCP tool surface and the API must stay aligned (see AGENTS.md).

Pitfalls

  • The PAT prefix is lbpat_ (Space), distinct from LangBot's lbk_ API keys.
  • This server is read/browse only; it does not publish or modify marketplace items. Use the web UI or REST API (with appropriate auth) for that.