Changelog
1.2.7 (2026-09-28)
Improvements
- Internal code improvements and maintenance.
1.2.6 (2026-09-16)
Fixed
- MCP tools no longer read or write storefront-decorated data. MCP requests ran in the storefront context, so storefront-only extensions (SEO friendly image URLs, brand name prefixes and similar) took part in every read and write an MCP tool performed - the AI client saw decorated values and saved them back. A single product write also cleared the full-page cache for the whole catalog instead of just that product, which on a busy store meant the storefront rebuilding category and product pages dozens of times during one assistant session. MCP requests now run in their own dedicated context, so tools see and save plain product, customer and order data, and only the affected pages are refreshed. This pairs with MCP Tools 1.1.15, which composer updates alongside this extension
- Revoking a user's tokens now includes their personal access token. The
mirasvit:mcp:revokecommand, the admin Revoke all and Disable actions and the automatic cleanup on admin user deletion all left the personal access token active - the command even reported that all tokens had been revoked - so a token you believed was cancelled would start working again as soon as MCP was re-enabled for that user - Console commands failed on Magento 2.4.5.
mirasvit:mcp:revokeand the MCP token cleanup command ended in an error on 2.4.5 and 2.4.6, which ship an older console library than the commands expected - Unrecognized
/mcp/...addresses now return a clear JSON "not found" response instead of leaving the request hanging - Removed the unused
PKCEService::generateCodeVerifier()method, which had no callers and relied on a framework method absent from Magento 2.4.5. Generating a code verifier is the AI client's job; the server's side of PKCE is unchanged
1.2.5 (2026-08-25)
Fixed
- OAuth discovery endpoints now respond to path-suffixed well-known URLs (e.g.
/.well-known/oauth-protected-resource/mcp) required by RFC 9728-compliant AI clients such as xAI Grok — previously these requests returned 404 and prevented the client from completing OAuth discovery
1.2.4 (2026-04-29)
Fixed
- Fixed OAuth authorization being blocked by Magento's Content Security Policy in restrict mode — the AI client's redirect URL is now allowed for the consent form submission, so authorization completes successfully on stores with strict CSP enabled
1.2.3 (2026-04-21)
Improvements
- Added i18n support for 15 core locales (ar_SA, cs_CZ, de_DE, es_ES, fr_FR, it_IT, ja_JP, nl_NL, pl_PL, pt_BR, pt_PT, sv_SE, tr_TR, uk_UA, zh_Hans_CN)
1.2.2 (2026-04-17)
Improvements
- Added a Prompts shortcut to the MCP admin menu for quicker access to the Prompts management page
1.2.1 (2026-04-16)
Fixed
- Fixed admin users with full access seeing no MCP tools on the OAuth consent page — roles with "All" permissions now correctly grant access to all tools
1.2.0 (2026-04-15)
Features
- MCP Prompts — AI clients can now discover and use prompt templates served by the MCP server. Prompts support customizable arguments, and only prompts matching the user's permissions are shown. Manage prompts from the new "Prompts" page in the MCP admin menu
Improvements
- Active MCP sessions now stay alive longer — the session lifetime resets with each request, so sessions no longer expire unexpectedly during use
- Tool access checks now use explicit role-based permissions instead of inherited ACL rules, ensuring tools are only available when the admin role has the specific resource assigned
- ⚠️ Now requires
mirasvit/module-mcp-toolversion 1.1.0 or higher
1.1.7 (2026-04-13)
Fixed
- Fixed error on the MCP client configuration page when displaying dates (e.g. token creation or expiry dates)
1.1.6 (2026-04-01)
Features
- Personal Access Tokens (PAT) — Generate, reveal, and revoke long-lived bearer tokens for AI clients that do not support OAuth 2.1 (e.g. Manus.ai). Tokens are generated per admin user, require password confirmation to create or reveal, and appear in the MCP Users grid alongside OAuth clients. Configure under Stores Configuration MCP Server Authentication Personal Access Tokens
- ⚠️ New database table
mst_mcp_user_token— runbin/magento setup:upgradeafter updating
Improvements
- Authentication settings reorganized into separate OAuth 2.1 and Personal Access Tokens sections for clarity
1.1.5 (2026-03-27)
Features
- The MCP server now supports the Streamable HTTP transport introduced in MCP 2025-03-26, including session management, proper handling of JSON-RPC notifications, and session termination via DELETE requests
Improvements
- The server now negotiates the MCP protocol version with the client, supporting versions from 2024-11-05 through 2025-11-25 for broader AI client compatibility
- OpenAI Codex Desktop setup guide — added step-by-step configuration instructions for the Codex Desktop app
1.1.4 (2026-03-26)
Improvements
- MCP methods for prompts and resources no longer return errors
1.1.3 (2026-03-24)
Improvements
- Added validator for basic health check
1.1.2 (2026-03-20)
Improvements
- AI client configuration instructions improved
1.1.1 (2026-03-11)
Fixed
- Fixed the issue with error during compilation (PHP7.4)
1.1.0 (2026-03-10)
Improvements
- MCP server now accessible by simplified /mcp endpoint (/mcp/server/handle is still accessible)
- Authorization header lookup improved
1.0.8 (2026-02-26)
Features
- New tool - DocSearch. Modules should provide docs in markdown format placed in etc/mcp folder.
1.0.7 (2026-02-25)
Fixed
- Fixed the issue with OAuth consent page when admin secret key is enabled
1.0.6 (2026-02-19)
Fixed
- Error in the Stores - Configuration pages caused by incorrect layout file.
1.0.5 (2026-02-19)
Improvements
- Full schema definition in the "schema" action for REST API tool
- Refactoring
1.0.4 (2026-02-17)
Fixed
- The issue with copy buttons in AI Client settings.
1.0.3 (2026-02-16)
Improvements
- PHP8.4 compatibility.
- Server name compatibility with different AI clients.
1.0.2 (2026-02-13)
Fixed
- OAuth authorization redirect converting query parameters to path format, breaking redirect and resource URLs.
1.0.1 (2026-02-13)
Improvements
- REST Service names for 3rd-party endpoints.
1.0.0 (2026-02-12)
Features
- Initial release.