Commit Graph

255 Commits

Author SHA1 Message Date
Fahreddin Özcan ca15df0443 docs: correct non-root image version floor to 1.3.2 (#3014) 2026-08-12 14:37:43 +03:00
Fahreddin Özcan 895c5c3997 docs: document running on-premise as a non-root user (#3005)
* docs: document running on-premise as a non-root user

* docs: correct the fsGroup claim for existing volumes
2026-08-10 12:27:43 +03:00
Konstantin Konstantinov 8d52608e4e feat: MCP v2 (#2843)
Co-authored-by: enesgules <abdullah.enes.gules@gmail.com>
Co-authored-by: Fahreddin Özcan <ozcanfahrettinn@gmail.com>
2026-08-06 15:57:58 +03:00
Drew 903a057dcc Add hyperlink in Documentation for user creation of API key in browser (#2992)
Co-authored-by: Enes Gules <101020733+enesgules@users.noreply.github.com>
2026-08-05 17:07:04 +03:00
Fahreddin Özcan 594a73133e docs: fix stale example URLs and complete the API methods table (#2964)
The 18 links reported by `mint broken-links` were a bug in CLI 4.2.212;
4.2.762 reports zero. Those pages are auto-generated from openapi.json
and all return 200. Fixes the real issues found while checking instead:

- Swagger Petstore URL in the GitOps manifest example returned 404
- `/websites/uploadcare_com` is a stale library ID (404); it is now
  `/websites/uploadcare`
- API methods table omitted the GitLab, Bitbucket, other-Git, Notion,
  and metrics endpoints, and collapsed the four repo endpoints into one
  `{provider}` row that does not match the spec
2026-07-30 11:52:34 +03:00
Fahreddin Özcan 6153debeaa docs(enterprise): document external Postgres with the embedded vector index (#2954) 2026-07-30 10:51:11 +03:00
Fahreddin Özcan b89a04e620 fix(cli): write the API key as an Authorization header (#2957)
* fix(cli): write the API key as an Authorization header

Codex resolves a server's auth mode by checking only for
`bearer_token_env_var` or a header literally named `Authorization`
(`auth_status_before_discovery` in codex-rs/rmcp-client/src/auth_status.rs,
mirrored in `create_transport` in rmcp_client.rs). The custom
`CONTEXT7_API_KEY` header matched neither, so Codex fell through to any OAuth
credential stored for the same server name and URL and refreshed it during
startup. A dead refresh token then failed the server with `invalid_grant`
before the API key was ever sent, and re-running setup could not recover it
because setup writes config.toml and never touches the credential store.

The hosted endpoint accepts both header forms, so existing configs keep
working.

Two places keep the legacy header deliberately: the plugin .mcp.json files
default to `${CONTEXT7_API_KEY:-}`, and the server rejects `Bearer` with an
empty token while treating a missing header as anonymous; and `env` blocks in
stdio configs, where the name is an environment variable rather than a header.

* fix(plugins): send the API key via the Authorization header

The Claude and Copilot plugin configs default to `${CONTEXT7_API_KEY:-}`, and
both plugins document that an unset key still works over the anonymous tier.
The Bearer form cannot express that: the server rejects `Bearer` with an empty
token while treating an empty or missing Authorization header as anonymous.

The raw-key form satisfies both states. It is genuinely parsed rather than
ignored, verified by an invalid raw key being rejected, so a set key still
authenticates while an unset one falls back to anonymous as documented.

Once the server treats an empty-token Bearer as no header, these can move to
the `Bearer <key>` form used everywhere else.

* refactor(cli): narrow the Codex OAuth probe and trim its surface

Only `oauth` proves a stored credential exists. `not_logged_in` also covers
"no credential, server merely advertises OAuth", which is the normal state for
anyone who never logged in, so treating it as stale told most users their
config held a credential it did not.

Collapse the module to the two functions the call site needs, derive nothing
from a hand-maintained status list, and skip the subprocess entirely when the
server is not already in Codex's config. Drop the probe timeout to 1.5s and
kill with SIGKILL so it is a real ceiling rather than an intent, since the
result is only an advisory hint.

Lock the plugin manifests' raw-key form behind a test, so normalizing them to
`Bearer` for consistency with the CLI fails loudly instead of silently
breaking anonymous access.

* refactor(cli): drop the Codex OAuth cleanup note

The note existed because re-running setup could not rescue a stuck user. The
Authorization header change in this same branch makes it rescue them: Codex
never reads the stored credential once that header is present, so the
credential is inert and the hint only offered cosmetic cleanup.

Removing it drops a subprocess spawn from a user-facing path and a dependency
on the shape of `codex mcp get --json`, an external contract this repo does not
pin. The reason the header name matters moves to `withHeaders`, where the
decision is encoded.
2026-07-29 18:38:10 +03:00
Fahreddin Özcan 80f9d6cfa1 docs(enterprise): add library access control page (#2928)
* docs(enterprise): add library access control page

* docs(enterprise): document central library access management

* docs(enterprise): library access lives under the Policies tab

* docs(enterprise): make library access MCP wording tool-name agnostic

* docs(enterprise): point library access to the Access tab

* docs(enterprise): refresh library access table screenshot

* docs(enterprise): restricted libraries read as not found, not denied

* docs(enterprise): cleaner library access table screenshot (curated 5-library scenario)

* docs(enterprise): tightly crop library access table screenshot

* docs(enterprise): add library access control to changelog
2026-07-29 11:07:11 +03:00
Fahreddin Özcan 6c343aedf8 docs(enterprise): changelog for v1.2.4 through v1.3.0 (#2953) 2026-07-29 11:04:23 +03:00
Fahreddin Özcan 305dd3ca10 docs(enterprise): multi-container scaling guide (#2917)
* docs(enterprise): add multi-container scaling guide

Document running On-Premise as multiple replicas with PostgreSQL + object
storage. Add the Scaling page under Deployment and cross-reference it from the
Kubernetes single-replica notes.

* docs(enterprise): migration guide for existing deployments + docker scaling pointer

- Scaling page: step-by-step migration using the built-in migrate command
  (Docker one-shot and Kubernetes Job), vector sync, encryption-key reuse
- Docker page: add a Scaling pointer

* docs(enterprise): add Settings > Scaling helper screenshots

Show the migration helper (single-container) and the multi-replica confirmation
in the migration section of the Scaling guide.

* docs(enterprise): point Scaling guide at the Helm chart and turnkey compose

- Docker Compose: reference the one-command bundled stack (Postgres + MinIO + LB)
- Kubernetes: use the Helm chart (single default, scaling.enabled to scale out)
- add on-prem / S3-compatible object storage (VECTOR_STORE_ENDPOINT)

* docs(enterprise): make Scaling deployment sections self-contained

On-prem customers get the image and docs, not the source repo, so inline the
full Docker Compose stack (with nginx.conf and .env) and the scaled Kubernetes
manifests (Secret + Deployment) instead of referencing repo files. Note the Helm
chart ships with the enterprise distribution.

* docs(enterprise): pgvector default for scaling, Postgres the only dependency

Vectors go to pgvector in the same Postgres, so object storage is no longer
required. Update config, compose (pgvector image, no MinIO), k8s secret, and the
migration (copies vectors into pgvector, no bucket sync). Object storage is now
an optional escape hatch for very large indexes.

* docs(enterprise): refresh Settings > Scaling screenshot for pgvector migration command

* docs(enterprise): pgvector only, drop the object storage option from the guide

Remove the VECTOR_STORE_URI config row and the 'Vectors on object storage'
section. Multi-replica uses Postgres + pgvector with no object storage.

* docs(enterprise): detailed pgvector provisioning guide

Expand the provisioning step with per-provider instructions (RDS/Aurora, Cloud
SQL, Azure Flexible Server, self-hosted/Docker), the 0.5.0 HNSW requirement,
CREATE EXTENSION, version verification, permission notes, and references. Add a
note on how vectors are stored (HNSW cosine, dimension from the model).

* docs(enterprise): explain the scaling model in Scale out

Every replica serves traffic and indexes; adding replicas grows both. Note how to
bound parse-vs-query contention with Max concurrent parses.

* docs(enterprise): drop SESSION_SECRET; ENCRYPTION_KEY now signs sessions

* docs(enterprise): add scaling sections to docker/kubernetes, link scaling page

- kubernetes: new Scaling section (StatefulSet -> Deployment + pgvector, Helm note)
- docker: refresh Scaling section (pgvector, turnkey compose)
- drop stale object-storage wording, both link to the Scaling guide

* docs(enterprise): add architecture diagram and a Helm page

- scaling: add an Architecture section with a Mermaid multi-replica diagram
- new Helm deployment page (install, scale, ingress, migration, values)
- add Helm to deployment nav; link it from the kubernetes and scaling pages

* docs(enterprise): move Helm page to its own PR (CTX7-1846)

* docs(enterprise): describe per-run Postgres lock instead of leader election

Match the code: scheduled jobs take a short advisory lock at fire time so one
replica runs each, rather than a persistent elected leader. Drop the leader
highlight from the architecture diagram; replicas are interchangeable.

* docs(enterprise): add Vector Stores page covering LanceDB, pgvector, and Milvus

Dedicated vector-store configuration page: backend comparison, VECTOR_STORE
selection, and Milvus / Zilliz Cloud setup. Cross-link from the scaling guide.

* docs(enterprise): note library access + SSO groups carry over in migration

The migrate command now copies per-library access rules and SSO group
memberships (and session epochs) alongside the other tables, so list them
in the migration step.
2026-07-24 10:32:20 +03:00
Fahreddin Özcan d8885b2308 docs(enterprise): Confluence by-page-URL indexing (UI + GitOps) (#2934)
- Document the By page URL mode on the Confluence integration page (with screenshot)
  alongside Browse spaces, including per-page Sub-pages and cross-space support.
- Document the confluence pageUrls / includeSubPages manifest fields in GitOps.
- Correct the space picker step to the current lazy-loaded dropdown.
2026-07-22 16:03:46 +03:00
Fahreddin Özcan 137ad5f1b3 docs(enterprise): Other Git integration (Gerrit/Gitea over HTTPS + SSH) (#2933)
* docs(enterprise): add Other Git integration page (HTTPS + SSH)

Document ingesting private repos from self-managed Git hosts (Gerrit, Gitea,
self-hosted Bitbucket) over HTTPS basic auth and SSH deploy keys, with Docker
and Kubernetes mount examples. Clarifies that SSH keys are mounted into the
container and never stored by Context7.

* docs(enterprise): SSH deploy key is configurable in the UI (mount is the alternative)

* docs(enterprise): add Other Git screenshots + Add a repository steps

- HTTPS and SSH tab screenshots
- 'Add a repository' Steps showing the clone-URL scheme selects auth
- ssh-keyscan snippet for known_hosts

* docs(enterprise): remove em dashes from Other Git page
2026-07-22 12:53:05 +03:00
Enes Gules eb7ac502f6 docs: add Manus to MCP clients list (#2905) 2026-07-13 16:43:37 +03:00
Fahreddin Özcan 26dcfcee92 docs(enterprise): add on-premise changelog page (#2904)
Adds enterprise/changelog to the On-Premise nav and the changelog page
(Mintlify <Update> components), backfilled for v1.0.0–v1.2.3.
2026-07-13 13:19:30 +03:00
Fahreddin Özcan a9d7c77f5e docs(enterprise): GitOps multi-source manifest + Confluence URL/whole-space (#2896)
- Document the manifest 'type' field routing entries to Confluence, website,
  llms.txt, and OpenAPI parsers (bare entries stay git)
- Add the per-type field table and the no-secrets/strict-validation notes
- Confluence: document the space URL field, 'index entire space' scope, and
  paginated page browsing; cross-link GitOps confluence entries
2026-07-10 17:41:14 +03:00
Fahreddin Özcan ea82d5585a docs(enterprise): document programmatic library import/export API (#2887)
* docs(enterprise): document programmatic library import/export API

- Add POST /import-libraries endpoint reference (openapi-enterprise.json + page)
- Register it under API Reference → Parse in the nav
- Add an Automating with the API section to the Library Import feature doc,
  covering the cloud license-key export and the on-prem JSON import

* docs: update export endpoint to /api/v1/enterprise/export, plain language

Match the renamed cloud export path, move the license key into the request
body, and reword the automation section without em dashes.

* docs(enterprise): export uses Authorization header; import requires an API key

* docs(enterprise): document the force query param on import
2026-07-08 13:29:34 +03:00
Fahreddin Özcan 7366cca8d2 docs(enterprise): Confluence integration page (#2879)
* docs(enterprise): add Confluence integration page

Document connecting Confluence (Cloud and self-hosted Data Center) and
indexing a space from Add. Includes screenshots and a nav entry under
Enterprise > Integrations.

* docs(enterprise): wider Confluence settings screenshot with mock site URL
2026-07-07 11:26:40 +03:00
Enes Gules 33229cb332 docs: enhance query descriptions for clarity and specificity (#2868)
* docs: enhance query descriptions for clarity and specificity

* update all propmts/skills

* format

* address pr review
2026-07-06 15:12:06 +03:00
Enes Gules dc967fa330 docs: document what Context7 indexes (parsed file types and source-code fallback) (#2881)
* docs: document parsed file types and source-code fallback (#2862)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs: document Generate docs option for private repos

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 15:09:28 +03:00
OrbisAI Security 68a6c63f3c fix: documentation contains hardcoded api key exampl... in api-guide.mdx (#2841) 2026-07-06 10:59:20 +03:00
vadim s. sabinich c8cbf3ea87 Add AnythingLLM to all-clients.mdx (#2859) 2026-07-03 10:57:18 +03:00
Enes Gules b1fb8b5232 docs: update Docker MCP Toolkit to remote server (fixes #790) (#2839)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 13:24:24 +03:00
Enes Gules 0647bb3451 add new attribute to docs (#2828) 2026-06-25 12:17:26 +03:00
Fahreddin Özcan a914a86934 docs: configure GitHub Enterprise Server host from the UI (#2823)
Document setting the GitHub Enterprise host before creating the App or token, so the App flow targets the on-prem server instead of github.com. Note the GITHUB_URL env var as a deploy-time alternative.
2026-06-24 12:27:13 +03:00
Fahreddin Özcan 74dc6ba95c CTX7-1760: Document GitOps for on-premise (#2816)
* CTX7-1760: document GitOps for on-premise

Add the GitOps page under the On-Premise docs: how reconciliation works, the
manifest format and fields, dashboard configuration, webhooks, disaster
recovery, and the REST API. Includes a dashboard screenshot.

* CTX7-1760: clarify GitOps webhook requirements (reachable host, push subscription)

* CTX7-1760: call out webhook caveat for pre-existing GitHub Apps

* CTX7-1760: add a Before you start prerequisites section to GitOps docs

* CTX7-1760: add GitHub Integration page; trim GitOps prerequisites to reference it

* CTX7-1760: group on-prem feature pages under a Features nav section

* CTX7-1760: move GitHub docs under an Integrations group, add setup screenshots

* Remove accidentally-staged docs/enterprise/integrations/github-actions.mdx

* CTX7-1760: use an admin API key example for the reconcile endpoint instead of a session cookie

* CTX7-1760: use connected-state GitHub App screenshot; split setup into create + install steps

* CTX7-1760: add Verify the App configuration section with permissions and webhook screenshots
2026-06-24 11:33:07 +03:00
Fahreddin Özcan 518bc98d21 docs(enterprise): add OIDC SSO guide (#2814)
Documents generic OIDC SSO setup for Context7 On-Premise, with dashboard
screenshots and a troubleshooting section. Adds the page to the On-Premise
Security nav group.
2026-06-24 11:32:54 +03:00
Fahreddin Özcan 8a6c029f65 docs(enterprise): add on-premise API reference (#2810)
* docs(enterprise): add on-premise API reference

Adds interactive API reference pages for the on-premise instance covering authentication, library search, documentation context, and all parse endpoints.

* docs(enterprise): remove duplicate openapi spec

* docs(enterprise): remove em dashes

* docs(enterprise): simplify authentication page

* docs(enterprise): add API key screenshots to authentication page

* docs(enterprise): link bearer auth description to authentication page
2026-06-23 11:22:52 +03:00
Fahreddin Özcan 2253765b3f feat(mcp): Enterprise-Managed Auth (id-jag) validation + Okta docs (#2798)
* feat(mcp): Enterprise-Managed Auth (id-jag) validation + Okta docs

* docs(enterprise): clarify Okta connection is client-side org config, drop wrong client JSON

* docs(enterprise): remove em dashes

* docs(enterprise): group Entra and Okta under Enterprise-Managed Auth, redirect old azure-apim path

* refactor docs

---------

Co-authored-by: enesgules <abdullah.enes.gules@gmail.com>
2026-06-22 11:55:06 +03:00
Enes Gules 73542b72d5 docs(library-owners): clarify folders/excludeFolders priority (#2799)
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
2026-06-19 16:55:53 +03:00
Fahreddin Özcan c97570227d docs(azure-apim): add auto-provision from Entra security group section (#2793)
Adds Part 4 Step 3 covering Microsoft Graph permissions (GroupMember.Read.All
+ User.ReadBasic.All), the WIF federated credential setup (issuer, subject,
audience values copied from the dashboard), group creation, dashboard config,
and "Sync now" verification. Updates the Step 2 roadmap note and adds a
troubleshooting entry for the most common pitfall: missing User.ReadBasic.All
returns 0 members synced even when the group has members.
2026-06-18 13:26:22 +03:00
Fahreddin Özcan cd12120f40 docs: on-premise library import/export (#2789)
Document the offline library transfer flow: export libraries from Context7
Cloud, import the bundle into an airgapped on-premise install (snippets are
re-embedded locally). Adds the page under Enterprise > On-Premise.
2026-06-17 15:09:28 +03:00
Fahreddin Özcan 0ab0597649 docs(azure-apim): document vscode.dev/redirect URI + manifest CLI fallback (#2784)
Adds the redirect URI registration step that VS Code with GitHub Copilot
requires, plus troubleshooting entries for AADSTS500113 and AADSTS50011.
Also notes the CLI alternative when the Manifest UI silently fails to
persist requestedAccessTokenVersion.
2026-06-17 12:26:27 +03:00
Enes Gules 195357db70 feat(docs): enhance documentation with improved titles, descriptions, and structured steps for clarity (#2778) 2026-06-17 10:18:21 +03:00
Fahreddin Özcan b692be18bf docs: backup and restore guide for on-premise (#2758)
* docs: backup and restore guide for on-premise

* docs: add dashboard restore flow and Keep all retention

* docs: use ctx7:restore in the local restore command

* docs: use consistent library/index vocabulary in backup-restore
2026-06-16 18:27:07 +03:00
Enes Gules 98fc4b814c fix(docs): update terminology and improve clarity across multiple documentation filestur (#2777) 2026-06-16 18:26:37 +03:00
Enes Gules 574fc642ab feat(docs): add VS Code extension documentation and update all clients reference (#2757) 2026-06-12 16:39:14 +03:00
Enes Gules 75361160c7 feat: update plugin version to 1.0.2 and add API key usage instructions in documentation (#2749) 2026-06-11 17:13:55 +03:00
Yui(ゆい) 43e410645c docs: document Docker MCP Toolkit stdio transport (#2734) 2026-06-11 11:43:29 +03:00
Enes Gules c10f116765 feat: add Context7 Codex plugin with installation instructions and documentation (#2748) 2026-06-11 11:41:36 +03:00
Enes Gules 06843a6b84 fix copilot cli plugin compatability (#2743) 2026-06-10 13:29:14 +03:00
Enes Gules cc011a4707 feat: add Codex client documentation and update OAuth flow details for existing clients (#2742) 2026-06-09 15:51:14 +03:00
Enes Gules dbc4c78cca fix: update references from Windsurf to Devin Desktop in documentation and templates (#2736) 2026-06-09 12:48:42 +03:00
Enes Akar 7dde3382b0 docs: add Policies and Rules How To pages (#2724)
Add the page files for the Policies and Rules dashboard tabs, which the
nav (docs.json) already references. Policies covers source-type access
and library filters; Rules covers global and library-specific teamspace
rules.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 16:39:37 +03:00
enesakar 0a6ecdcaf2 docs pages 2026-06-05 16:13:38 +03:00
Enes Gules 2e97dae44e refactor(cli): update CLI documentation and add deprecation warning to skill commands (#2711) 2026-06-02 16:15:51 +03:00
Zhao73 eb579860bf docs: fix verification docs typo (#2697) 2026-06-01 21:44:06 +03:00
Fahreddin Özcan 29edf154d8 docs(azure-apim): post-deploy updates (Settings tab, smoke test, etc.) (#2699)
* docs(azure-apim): reflect Settings tab + cascade-delete + audience-uniqueness

Three updates after merging the per-user identity feature to production:

1. Dashboard navigation: Entra cards moved from the Overview tab to a
   conditional Settings tab (only visible for enterprise teamspaces or
   active trials). Update Part 4 and the troubleshooting section.

2. Cascade-delete: clicking Remove on the Microsoft Entra ID card now
   removes both the tenant configuration AND all provisioned users in a
   single step. Add a note so admins know not to use Remove for
   single-user revocation.

3. Audience uniqueness: each MCP API app (audience GUID) can be claimed
   by one teamspace at a time. Document the failure mode and how to
   resolve it, since hitting it from a fresh setup is easy.

* docs(azure-apim): add Part 6 — smoke test the gateway from CLI

Walks through pre-authorizing Azure CLI on the Gateway app's scope and
running an `az account get-access-token` + curl against APIM end-to-end.
Lets admins validate the full OBO flow before pointing real MCP clients
at the gateway.

Renumber the original "Connect an MCP client" to Part 7.
2026-06-01 15:34:11 +03:00
Enes Gules 438b1df235 update open api docs (#2637) 2026-05-18 12:33:11 -07:00
Fahreddin Özcan 6f0f8b7b63 docs(enterprise): Azure APIM deployment guide (#2636)
* docs(enterprise): add Azure APIM deployment guide

Step-by-step guide for deploying Context7 behind Azure API Management
with Microsoft Entra ID per-user authentication via On-Behalf-Of (OBO)
token exchange. Covers APIM provisioning, Entra app registrations,
policy wiring, OAuth discovery surfaces, and connecting MCP clients
(VS Code Copilot, Cursor) through the gateway.

* docs(azure-apim): cover user pre-provisioning + fix variable typo

- Restructure Part 4 into two steps: tenant config + pre-provisioning
  users via the new dashboard card. Calls out that Context7 rejects
  unmapped oids — there is no auto-provisioning.
- Add troubleshooting entry for the unmapped-user 401 (most common
  failure once tenant config is correct).
- Fix \$APIM_NAME → \$APIM typo in the OAuth proxy provisioning
  commands; the rest of the doc uses \$APIM so the OAuth proxy
  commands would have failed as written.
2026-05-18 08:59:48 -07:00
Enes Gules 30df4a1cff docs: enhance library ID descriptions in API guide and OpenAPI spec (#2568) 2026-05-05 19:03:33 +03:00