Skip to content

feat: draft anonymizing MCP proxy (Fullstory preset) - #1

Draft
anttiviljami wants to merge 1 commit into
mainfrom
claude/wizardly-lovelace-3vpe5g
Draft

anttiviljami wants to merge 1 commit into
mainfrom
claude/wizardly-lovelace-3vpe5g

Conversation

@anttiviljami

Copy link
Copy Markdown
Member

Summary

Draft MCP gateway (mcp-proxy/, self-contained, depends on published @epilot/anonymization@^0.2.0) that sits between Claude and Fullstory MCP and anonymizes every tool result before the model sees it. Motivation: Fullstory MCP returns end-user user_properties and has no access level to turn that off.

  • Holds the Fullstory API key (Fullstory's documented gateway auth); clients use their own revocable PROXY_TOKENS (header or /mcp/<token>)
  • User property bags (user_properties, userVars, traits, …) → strict: known PII pseudonymized, all other strings redacted unless KEEP_USER_PROPERTIES
  • Everything else → anonymizeUnknown + Fullstory overrides (displayName, uid, ip, latlong…), URL query redaction (except *.fullstory.com replay links), markdown Key: value handling
  • Images/blobs replaced; session_screenshot, session_get_a11y_tree, session_diff blocked (raw pixels/DOM)
  • Streamable HTTP: JSON + SSE (per event), session id passthrough; unknown content types fail closed; bodies never logged
  • Root vitest.config.ts excludes mcp-proxy/; separate CI job

Test plan

  • mcp-proxy: typecheck + 9 tests (sanitizer + e2e with fake upstream: auth, credential swap, JSON, SSE, blocked tools)
  • root tests still pass
  • Validate against live Fullstory MCP output (EU org) and extend overrides
  • Deploy target + secrets (SSM), OAuth front door for claude.ai

🤖 Generated with Claude Code

https://claude.ai/code/session_01DmJFpgrBbyyuyoyLFihyow


Generated by Claude Code

Gateway that holds the Fullstory MCP API key, authenticates clients with
revocable proxy tokens, and runs every tool result (JSON + SSE) through
@epilot/anonymization: strict mode for user property bags, URL query
redaction, binary content removal, and blocked raw-DOM/screenshot tools.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DmJFpgrBbyyuyoyLFihyow
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants