Skip to content

Add a global baseUrl setting for self-hosted servers - #2

Open
ntindle wants to merge 1 commit into
supermemoryai:mainfrom
ntindle:global-base-url
Open

ntindle wants to merge 1 commit into
supermemoryai:mainfrom
ntindle:global-base-url

Conversation

@ntindle

@ntindle ntindle commented Oct 4, 2026

Copy link
Copy Markdown

Problem

Muse runs plugin hooks and plugin MCP servers with a fixed environment allowlist. On Muse Code 1.4.2, plugin hooks get 17 variables (PATH, HOME, the plugin paths, temp dirs and a few shell variables) and the MCP server gets the same plus MUSE_SESSION_ID. SUPERMEMORY_API_URL set in the shell never reaches either, and managed_hooks_env_vars only applies to managed hooks. I checked this with an env-dump plugin in an isolated Muse home.

So today the only way to point this plugin at a self-hosted server is a .muse/supermemory.json in every repo, which the docs also say. Any repo or folder without that file falls back to https://api.supermemory.ai and sends the self-hosted key, the prompt and the transcript there. Two related problems for self-hosted users:

  • The MCP proxy always posts to mcp.supermemory.ai with the configured key, starting with initialize.
  • With no key stored, SessionStart opens the hosted browser login, whose key cannot work against a self-hosted server.

Change

  • getBaseUrl also reads baseUrl from ~/.supermemory-muse/settings.json. Order: SUPERMEMORY_API_URL, the project config, this setting, then https://api.supermemory.ai. The key name matches ~/.codex/supermemory.json in codex-supermemory.
  • A settings.json that mentions baseUrl but does not parse (a trailing comma, say) is an error instead of a silent fall back to the hosted API. A leading byte order mark is ignored.
  • When the base URL is not the hosted API, the MCP proxy answers with a JSON-RPC error instead of forwarding, unless SUPERMEMORY_MCP_URL or the new mcpUrl setting names an endpoint. mcpUrl exists because the env var cannot reach the proxy under Muse.
  • When the base URL is not the hosted API and no key is found, SessionStart says where to write the key instead of starting the browser login.
  • These guards also apply to existing per-project self-hosted configs. Hosted users with no baseUrl see no change.
  • README and /supermemory:status describe the resolution order. Version 0.1.1 → 0.1.2 in package.json and .muse-plugin/plugin.json, as in 0b8ab0d; happy to drop the bump if you'd rather do it at release.

Tests

node --test test/unit.mjs: 20 pass on Node 24 (Windows) and Node 22 (Linux). muse plugins validate . passes on Muse 1.4.2.

New cases cover:

  • the global setting, and the project config and env var taking precedence over it;
  • the broken-file and byte-order-mark cases;
  • other spellings of the hosted URL (https://API.supermemory.ai, :443, a trailing slash) not being treated as self-hosted;
  • the proxy refusing to forward with a self-hosted base URL, using mcpUrl when set, and still targeting mcp.supermemory.ai with no baseUrl;
  • SessionStart skipping the login for a self-hosted base URL and still starting it otherwise.

The script tests run with test/no-network.cjs preloaded, which fails any fetch and browser launch. 8 of the new cases fail on main.

I run this against a self-hosted server (Lite v0.0.8) across several machines, which is where the per-repo file stopped being workable.

🤖 Generated with Claude Code

Muse runs plugin hooks and MCP servers with a cleared environment, so
SUPERMEMORY_API_URL set in the shell never reaches them, and the only way
to point the plugin at a self-hosted server was a .muse/supermemory.json
in every repo.

getBaseUrl now also reads baseUrl from ~/.supermemory-muse/settings.json,
after the env var and the project config. A settings.json that sets
baseUrl but does not parse is an error rather than a silent fall back to
the hosted API. When the base URL is not the hosted API, the MCP proxy
does not forward to mcp.supermemory.ai unless mcpUrl or
SUPERMEMORY_MCP_URL names an endpoint, and SessionStart says where to put
a key instead of opening the hosted browser login.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant