Sign inSign up

garrardkitchen/mcp-explorer

By garrardkitchen

•Updated 6 months ago

MCP Explorer - A comprehensive Blazor Server app for exploring Model Context Protocol (MCP) servers

Image
Developer tools
0

7.3K

garrardkitchen/mcp-explorer repository overview

⁠Changelog

All notable changes to this project will be documented in this file.

The format is based on Common Changelog⁠, and this project adheres to Semantic Versioning⁠.

⁠[Unreleased]

⁠Fixed
  • Chat MCP tool calling: Upgrades Microsoft.Extensions.AI and Microsoft.Extensions.AI.OpenAI from 10.0.0 to 10.4.1 and OpenAI from 2.7.0 to 2.9.1 to resolve a runtime version mismatch with Microsoft.Extensions.AI.Abstractions 10.4.1 (transitively required by ModelContextProtocol 1.2.0). The mismatch caused UseFunctionInvocation to fail at runtime when invoking MCP tools from the Chat feature.
⁠Added
  • MCP SDK upgrade to 1.2.0: Upgrades ModelContextProtocol package from 0.4.0-preview.3 to 1.2.0 (stable release)
  • OAuth 2.0 / Incremental Scope Consent: New authentication mode for MCP server connections
    • Add OAuth 2.0 connections via a dedicated form (Client ID, optional Client Secret, Redirect URI, Scopes, optional Client Metadata Document URI)
    • Uses the SDK's ClientOAuthOptions and HttpClientTransportOptions.OAuth for standards-based authorization
    • AuthorizationRedirectDelegate opens the authorization URL in the system browser and awaits the callback via a local /oauth/callback endpoint
    • OAuth client secret is encrypted at rest using the existing SecretProtector pattern (AES-256)
    • OAuth credentials persisted and restored in UserPreferences alongside existing auth modes
    • Show/hide toggle for OAuth client secret in the editor (consistent with Azure credential pattern)
  • MCP server icons (Design A — Inline Thumbnail): Display server-supplied tool, prompt, and resource icons
    • 24×24 px inline <img> thumbnail (rounded 4px) shown in dropdown list items and detail panel headers
    • Letter-badge fallback (coloured by hash of item name) when no icon is provided
    • Icons sourced from Tool.Icons, Prompt.Icons, Resource.Icons (IList<Icon> with Source, MimeType, Sizes, Theme)
    • McpIconHelper.GetBestIconUrl() selects the best icon with optional theme preference
    • Applied to Tools, Prompts, and Resources views; ToolSelect component accepts new IconUrls parameter
⁠Changed
  • SDK breaking changes fixed: McpClientExtensions.CreateSamplingHandler → AIContentExtensions.CreateSamplingHandler

  • SDK API updates: ListToolsAsync, ListPromptsAsync, ListResourcesAsync, ListResourceTemplatesAsync, CallToolAsync, GetPromptAsync, ReadResourceAsync updated for new RequestOptions? parameter signatures in SDK 1.2.0

  • Elicitation schema types: ElicitRequestParams.EnumSchema replaced with the new split types (UntitledSingleSelectEnumSchema, TitledSingleSelectEnumSchema, UntitledMultiSelectEnumSchema, TitledMultiSelectEnumSchema, LegacyTitledEnumSchema) in ElicitationInputField.razor and Index.Elicitations.cs

  • ReadOnlyMemory<byte>: Fixed nullable operator misuse on non-nullable Data properties in ImageContentBlock and AudioContentBlock

  • JsonElement.StructuredContent: Uses JsonSerializer.Serialize(value.Value, ...) / GetRawText() instead of non-existent ToJsonString() extension in SDK 1.2.0

  • ReadResourceAsync: Updated call sites to pass Uri instead of string

  • Test dependencies: Bumped Microsoft.Extensions.Logging.Abstractions and Microsoft.Extensions.Logging to 10.0.5 in test project to resolve package downgrade conflict

  • Connection Groups: Organise connections into named, colour-coded groups

    • Create groups from a new Groups view (colour palette of 8 preset hex colours)
    • Edit group name and colour in-place from the Groups view
    • Delete groups with a confirmation dialog
    • Each connection can be assigned to a group; group cards display member connections as chips
    • Connection chips in the Groups view are clickable to set the active/default connection; selected chip is visually highlighted
    • Groups state persisted to UserPreferences (ConnectionGroups, ShowConnectionGroups flags)
  • Copy Connection: Duplicate any existing connection under a new name via a dedicated copy dialog; copied connection inherits all settings including group assignment

  • Starred Connections: Star/favourite individual connections

    • Starred connections are pinned to the top of the connection list (secondary sort)
    • "Show starred only" filter toggle to narrow the list to starred connections
    • Favourites persisted in UserPreferences (FavoriteConnections list)
  • Documentation: Enhanced workflow array iteration documentation with comprehensive guide

    • New "Understanding Array Iteration (Batch Processing)" section explaining the feature's purpose and benefits
    • Real-world use cases for Device Management, User Administration, Data Processing, and Testing scenarios
    • Technical explanation of how the workflow engine processes array iterations
    • Performance considerations including sequential execution details and batch processing best practices
    • Detailed iteration modes comparison table (None, Each, First, Last) with specific use cases
    • Enhanced parameter mapping section with step-by-step configuration guide
    • Practical examples showing multi-parameter array iteration with consistency requirements
    • New Example 5 demonstrating how to reference specific workflow steps (not just previous step)
    • Expanded troubleshooting section with three new array-iteration-specific entries:
      • "Array Iteration Not Working" with 7 solutions and debugging guide
      • "Wrong Array Elements Processed" with common path mistakes and corrections
      • "Multiple Parameters With Array Iteration" with correct vs incorrect pattern examples
    • Seven new best practices specific to array iteration including testing strategies and error handling
    • Total: 397 lines added, 28 lines removed (net +369 lines)
  • Documentation: Added comprehensive documentation pages for new features

    • Workflow Load Testing documentation page with configuration, metrics interpretation, timeline visualization, and troubleshooting guides
    • Import/Export Connections documentation page with step-by-step guides, security details, and common use cases
    • Updated features index with new feature entries and quick access links
  • Workflow Load Testing: Comprehensive load testing capability for workflows with configurable stress testing

    • Load Test Configuration: Configurable duration (120-3600 seconds) and max parallel executions (1-100)
    • Smart Ramp-Up/Down: Gradually increases parallelism in first 60 seconds and decreases in last 60 seconds to avoid overwhelming the system
    • Real-Time Progress Tracking:
      • Live metrics showing execution counts during test run
      • Time-based progress bar displaying elapsed time percentage
      • Success, failure, and partial completion counts with badges
    • Comprehensive Metrics:
      • Duration statistics: Average, Min, Max, Median, P95, P99
      • Success/failure rates and throughput (executions per second)
      • Peak concurrent executions
      • Step-by-step duration breakdown
    • Timeline Visualization: SVG chart showing cumulative successes (green), failures (red), and active executions (blue) over time
    • Automated Observations: Rule-based insights about reliability, performance variance, throughput patterns, and error analysis
    • Results Management:
      • Persistent storage to load_tests folder with sanitized file names
      • Load test history panel showing recent tests
      • View, export (JSON), and delete capabilities
      • Execution isolation: load test runs do NOT appear in Recent Executions list
    • Status Accuracy: Completed tests correctly show "Completed" status; only user-cancelled tests show "Cancelled"
    • Load test button (📊) positioned next to "Run Workflow" button, following workflow UI patterns
  • Workflow Chaining Feature: Complete multi-step workflow system for chaining MCP tools together

    • Visual Workflow Designer: Option 3 Hybrid List + Inspector layout with master-detail interface
    • Workflow Management: Create, edit, rename, delete workflows with full CRUD operations
    • Parameter Mapping: Three mapping sources - previous step outputs, manual values, or runtime prompts
    • JSON Property Selector Modal: Browse button (🔍) opens modal with tool response schema analysis
      • Interactive property tree showing types (object, array, string, number, boolean)
      • Click to select property paths with support for nested objects and arrays
      • Handles array indexing patterns (e.g., data[0].field)
      • Schema extraction via reflection from tool OutputSchema
      • Manual path editing still available alongside browsing
    • Split-View Workflow Editor:
      • Tool selector changed to compact dropdown (60% width)
      • Required Parameters panel on right side (40% width) showing non-optional parameters
      • Schema-based parameter analysis as visual reminder
      • Clear search button (✖) for tool filtering
    • Execution Progress Tracking:
      • Spinning animation indicator during workflow execution
      • Step counter display ("Executing Step X of Y")
      • Current tool name shown
      • Animated progress bar with gradient showing completion percentage
      • Real-time UI updates as each step begins
    • Tabbed Results Viewer:
      • Horizontal tabs showing "Step 1: ToolName", "Step 2: ToolName"
      • Status badges on each tab (✓ success, ✗ error, ⏱ running)
      • Active tab highlighted with accent color
      • Step details with input parameters and output JSON
    • Property Highlighting: Mark output properties to highlight in execution results with conditional display
    • Execution History: Last 10 executions saved per workflow with delete capability
    • Connection Management: Auto-connect to selected connection before execution
    • Error Handling: Configurable per-step (stop on error vs continue)
    • Import/Export: Share workflows as JSON files with wider modal
    • Enhanced Runtime Parameters: Organized by step with tool names and proper spacing
    • Modal Dialogs: All dialogs use consistent centered modal-backdrop pattern
    • Tool Search Persistence: Search filter persists when selecting tools
    • Tool Count Display: Shows filtered match count (e.g., "Tool (15) *")
  • New Workflows page (🔗 icon) in navigation

  • New WorkflowService with execution engine supporting nested JSON path extraction

  • New domain models: WorkflowDefinition, WorkflowStep, ParameterMapping, WorkflowExecution, WorkflowStepResult

  • New WorkflowExecutionViewer component with tabbed interface

  • Workflow persistence integrated with UserPreferencesStore

  • Schema analysis methods for extracting required parameters from tool schemas

⁠Changed
  • Root route now redirects to /connections page for better initial user experience
  • Navigation updated to include Workflows tab
  • Improved sensitive-data heuristics: Expanded WordValidatorExtensions.IsSensitive to reduce false positives on common language patterns:
    • Added quote characters (" and ') to TokenConstants.SpecialCharacters for proper paired delimiter handling
    • New allowances for hyphenated words (e.g., well-known, up-to-date, real-time)
    • New allowances for common abbreviations (e.g., e.g., i.e., etc, etc.)
    • New allowances for version patterns (e.g., v1, v2.0, v2.0.1)
    • New allowances for common ratios (e.g., 24/7, 9-5)
    • New allowances for short alphanumeric codes (e.g., A4, B2B, 2D, 3D, 4K, 5G)
    • New allowances for measurements with units (e.g., 5km, 10m, 100kg, 500mb, 12px)
    • New allowances for possessives (e.g., application's, user's, dogs', children's)
    • New allowances for slash-separated words (e.g., delegates/functions, and/or, true/false)
    • New allowances for generic type notation (e.g., IEnumerable<T>, List<string>, Dictionary<TKey,TValue>)
    • Tokens wrapped in paired delimiters ("", '', <>, {}, [], \\, //, ::, ;;, $$, %%) now correctly evaluate the inner content
⁠Fixed
  • Workflow execution stability: Fixed ObjectDisposedException errors when connections are disconnected during workflow execution or tool loading
    • Added graceful handling for disposed connections in Workflows.razor.cs and WorkflowService.cs
    • Connection disposal now properly clears references and provides user-friendly error messages
    • Workflow execution validates connection state before beginning execution

⁠[0.15.2] - 23-DEC-2025

⁠Changed
  • Elicitations tab visibility: The Elicitations tab is now positioned next to the Tools tab for better discoverability.

⁠[0.15.1] - 21-DEC-2025

⁠Changed
  • Elicitation timeout: Made elicitation timeout optional and configurable via appsettings.json (Elicitation:TimeoutSeconds). Default is now 0 (no timeout). Set to a positive number of seconds to enable automatic timeout and rejection of pending requests.
  • Tool invocation timeout: Increased tool/prompt/resource invocation timeout from 10 seconds to 5 minutes to accommodate elicitation interactions and long-running operations.
  • Navigation tab styling: Reduced pill-menu-item padding from 1.5rem to 0.875rem and added ellipsis overflow handling to prevent tab wrapping on smaller screens.

⁠[0.15.0] - 21-DEC-2025

⁠Added
  • Elicitation support: Added full support for MCP elicitation feature, allowing servers to request structured input from users during tool execution
    • New Elicitations tab (🤝 icon) displaying pending requests and history
    • Support for all primitive schema types: Boolean (toggle switch), Number (numeric input), String (text input with format awareness), and Enum (dropdown select)
    • String format support: Automatically renders appropriate input types based on format property:
      • email: Email input with validation
      • date: Date picker
      • datetime: DateTime picker
      • uri: URL input with validation
      • Default: Standard text input
    • Server-initiated modal dialogs for immediate response during tool execution
    • Standalone elicitations page for viewing and responding to pending requests
    • Complete history tracking with status badges (Pending, Accepted, Rejected)
    • ElicitationHandler configured in client capabilities with optional configurable timeout (default: no timeout)
    • Thread-safe ElicitationService using TaskCompletionSource pattern for async blocking
    • Event-driven UI updates for real-time modal display

⁠[0.14.2] - 19-DEC-2025

⁠Fixed
  • Connection filter focus behavior: Fixed issue where keyboard focus would return to the connection filter input field after every keypress when creating or editing connections. The filter input now only receives focus on the initial page navigation, allowing uninterrupted editing of connection details.

⁠[0.14.1] - 16-DEC-2025

⁠Added
  • CHANGELOG added to dockerhub image: Included the CHANGELOG.md file in the DockerHub image to provide users with easy access to version history and updates directly from the container.

⁠[0.14.0] - 12-DEC-2025

⁠Added
  • Connection search and filter: Added real-time search filter on the Connections page that filters connections by name, description (note), and authentication type. Features include 300ms debounce, auto-focus when tab is opened, Escape key to clear, and match highlighting matching the JsonViewer style.

⁠[0.13.0] - 12-DEC-2025

⁠Added
  • Copy tool, prompt, and resource names to clipboard: Added copy functionality for selected tool, prompt, and resource names, allowing users to easily copy names to clipboard for use in other contexts.

⁠[0.12.3] - 12-DEC-2025

⁠Added
  • Auto-reconnection for MCP server disconnections: Added automatic reconnection capability for MCP server disconnections that occur during tool, prompt, and resource invocations, improving reliability and user experience.

⁠[0.12.2] - 10-DEC-2025

⁠Fixed
  • Client credentials access token acquisition: Access token is now properly obtained for client credential connections. This ensures app roles are added as claims to the access token, which is required when client App Registration is requesting access to the API App Registration.

⁠[0.12.1] - 09-DEC-2025

⁠Changed
  • Chat history report generation: Implemented chat history report generation feature providing enhanced formatting and layout for exported chat sessions.

⁠[0.12.0] - 09-DEC-2025

⁠Added
  • Chat history markdown report generation: New feature to generate and export chat history as formatted markdown reports, making it easier to share and document chat sessions.

⁠[0.11.1] - 06-DEC-2025

⁠Added
  • End-to-end testing: Included Microsoft Playwright tests to confirm basic functionality, improving test coverage and reliability.

⁠[0.11.0] - 26-NOV-2025

⁠Added
  • Per-message model labels in Chat:
    • Chat messages (user, assistant, and tool-call) now persist and display the LLM model name used for each turn as a badge next to the role, ensuring historical messages remain tied to the correct model even after you change the selected model.

⁠[0.10.2] - 25-NOV-2025

⁠Added
  • Per-message copy-to-clipboard in Chat:
    • Each user and assistant message now shows a 📋 icon in its header that copies the message text to the clipboard when clicked.
    • On successful copy, the icon briefly changes to ✅ before reverting, providing inline visual confirmation without extra UI chrome.

⁠[0.10.1] - 22-NOV-2025

⁠Changed
  • Refined message sensitive-data heuristics:
    • WordValidatorExtensions.IsSensitive now trims leading/trailing punctuation and ignores plain-language tokens made only of letters (even when wrapped in punctuation), pure digits, and all-punctuation tokens.
    • Additional explicit allowances have been added for common dates, times, English contractions, and numeric ordinals (e.g., 21/06/2005, 16:00, I'm, 3rd), so these everyday patterns are not treated as sensitive by default.
    • This significantly reduces false positives on natural language such as "titles)." or "so. Topic: microsoft aspire" while preserving detection of mixed-character secrets (e.g., API keys, tokens).

⁠[0.10.0] - 22-NOV-2025

⁠Added
  • AI detection strictness and debug controls for sensitive-message protection:
    • New AiDetectionStrictness setting (Conservative, Balanced, Aggressive) in SensitiveFieldConfiguration, configurable from the Sensitive Fields page.
    • New ShowDetectionDebug flag that enables additional structured logging of why tokens/segments were classified as sensitive (source, shape, rule), without logging raw secret values.
⁠Changed
  • AI-based sensitive detection post-filtering:
    • DetectWithAiAsync now applies strictness-aware post-filtering so AI segments are only accepted when they contain configured sensitive keywords, heuristic-sensitive tokens, or digits (depending on strictness), with the updated heuristics applied to ignore benign date/time/ordinal/contraction-only segments in conservative modes.
    • Benign phrases that the model might over-zealously flag are dropped under Conservative mode, improving default usability.

⁠[0.9.0] - 22-NOV-2025

⁠Added
  • Chat /prompt slash command and prompt picker:
    • Typing /prompt in the Chat input now opens a modal listing prompts from currently selected and connected MCP servers.
    • Typing /prompt <filter> seeds the modal's search box so you can immediately narrow the prompt list.
    • The picker supports selecting a prompt, entering any required arguments, and resolving the prompt text, which replaces the original /prompt command in the chat input ready to send.

⁠[0.8.0] - 20-NOV-2025

⁠Added
  • Chat input always at bottom: Chat input box now remains at the bottom of the screen for better user experience and accessibility.

⁠[0.7.3] - 20-NOV-2025

⁠Changed
  • Improved reconnection visuals: Enhanced visual indicators when retrying to reconnect to an MCP server, providing better feedback to users during connection issues.

⁠[0.7.2] - 19-NOV-2025

⁠Changed
  • Documentation: Updated images in documentation for better clarity.

⁠[0.7.1] - 18-NOV-2025

⁠Changed
  • Enhanced sensitive detection: Improved sensitive content protection with enhanced keyword detection and validation without the assistance of AI.

⁠[0.7.0] - 18-NOV-2025

⁠Changed
  • Improved non-AI assisted detection: Enhanced sensitive content protection with improved keyword detection and validation logic. Added comprehensive unit tests and refactored validation criteria for better accuracy.

⁠[0.6.0] - 16-NOV-2025

⁠Added
  • Hybrid sensitive data detection: Added hybrid sensitive data detection with optional AI enhancement and visual indicators for user chat messages, providing flexible security options.

⁠[0.5.1] - 16-NOV-2025

⁠Changed
  • Upgrade to .NET 10.0: Upgraded .NET SDK and all dependencies to version 10.0 for improved performance and latest features.

⁠[0.5.0] - 16-NOV-2025

⁠Added
  • Sensitive Data Protection in User Chat Messages: User messages containing sensitive information are now automatically detected, encrypted, and displayed with inline redaction badges
    • Regex pattern matching (primary method): Fast, offline detection using keyword patterns - no API costs or latency
      • Always active and runs first
      • Detects both quoted and unquoted sensitive values: set key of 123abc or secret "abc123"
      • Works with flexible patterns: supports "of" keyword, colon (:), equals (=), and spaces
      • Automatically uses Additional Sensitive Fields from user preferences
    • Heuristic token scanning (Phase 2): Composition-based pass that flags tokens with mixed character classes (letters+digits or specials) excluding GUIDs, pure numbers, URLs, and simple letter-only words to catch secrets lacking a leading keyword
      • Fully local, negligible latency
      • Can surface unprefixed API keys (e.g., ghp_ABC123xyz, sk_live_x7Y8Z9abcDEF123)
    • AI-Enhanced Detection (optional, disabled by default): Use the selected LLM for context-aware sensitive data detection
      • Disabled by default – must be explicitly enabled in Sensitive Fields Configuration page
      • Only applies to chat messages – tool parameters remain regex-only for performance
      • Provides smarter detection without requiring specific keywords
      • Adds latency (1-3 seconds) and API costs; requires active model connection
      • Privacy: message is sent to provider for analysis before local encryption
      • Regex + heuristic phases serve as fallback if AI fails or returns no segments
    • Inline badge-style UI with show/hide toggles (👁️ / 👁️‍🗨️) matching the app's design aesthetic
    • Encrypted at rest using AES-256 encryption (same SecretProtector used for API keys)
    • Per-value reveal controls for granular visibility
    • Reveal state resets on page reload for security
  • New MessageContentProtectionService for detecting and protecting sensitive content in user messages
    • Primary detection uses regex patterns loaded from user preferences
    • Heuristic Phase 2 scanning added to broaden non-keyword detection coverage
    • Loads custom sensitive keywords from user preferences (SensitiveFieldConfig.AdditionalSensitiveFields)
    • Supports allow/deny lists for keyword exceptions
    • Optional DetectWithAiAsync method for AI-powered detection (user must opt-in)
    • IsAiDetectionEnabled method checks user preferences before invoking AI
  • New SensitiveMessageContent Razor component for rendering protected message content
  • New AiSensitiveDataDetection model for AI detection results
  • Extended ChatMessage model with SensitiveSegments property to track encrypted content
  • Extended SensitiveFieldConfiguration with UseAiDetection setting (defaults to false)
  • Added AI detection toggle to Sensitive Fields Configuration page with pros/cons & privacy notes
⁠Changed
  • Chat session storage now persists encrypted sensitive segments from user messages
  • User message display logic updated to render sensitive content with protection badges
  • MessageContentProtectionService pattern matching improved to handle unquoted values and "of" keyword
  • Added heuristic Phase 2 token scanning to complement regex keyword-based detection
  • Chat message sending flow now supports optional AI detection with automatic regex + heuristic fallback
  • Sensitive Fields page now includes AI-Enhanced Detection section with toggle, detailed information, and clear indication it's disabled by default
  • Tool parameter detection

Tag summary

Content type

Image

Digest

sha256:d5a8243b4…

Size

98.6 MB

Last updated

6 months ago

docker pull garrardkitchen/mcp-explorer