v2.2.0

Aki MCP Server 2.2: see every connection, block every guess

The control panel now shows who holds access and who uses it, shuts out password guessing on its own, and sets up AGY with one click. The toolset is leaner (36 tools) and the instruction you paste into your AI never changes again. Update, restart, and your existing connections keep working.

  • 36

    tools, leaner

    Three git tools merged into one, a vendor-API scraper removed

  • 5

    wrong guesses, then a 15 minute block

    Your own valid token is never blocked

  • 1

    shared access token

    It used to be a new one per grant, piling up

  • 2

    lines to paste, once

    The instruction is static, so no more re-pasting

See who has access

Panel section 7 is now “Security & connection limits”. Open it to answer “who can reach my machine, and who did, just now?”

New

Clients table

Every registered client with first seen, last approval, last token grant, and the address and agent at that moment. Each one shows if it is still signed in.

New

Active now

Addresses that used the valid token since the last restart (newest 64, kept in memory only). A new address stands out at once.

New

Remove or sign out, per client

One button per client. The panel tells you the shared token keeps working until you Roll token, so there is no false sense of safety.

New

A list that cleans itself

Clients never approved within 1 hour, or signed out and idle for 30 days, are cleared. Strangers cannot fill the client list, and old connectors stop piling up.

New

A security log you can read

Wrong passphrases, approvals, token grants, blocks and rolls go to security.log (rotated at 1 MB). The newest 200 lines show in the panel, and the terminal prints [security] events only, so an idle server stays silent.

Stops guessing, never you

The gatekeeper now rate limits failed attempts on its own. The numbers are sized so a real client never notices.

New

5 strikes, 15 minutes out

5 rejected credentials in 60 seconds (wrong passphrase, wrong client secret, invalid Bearer on /mcp) block that caller for 15 minutes with a 429 and Retry-After.

New

Registration flood guard

100 POST /register calls in 10 minutes block the caller too, and the unauthenticated registry stops storing clients at 500.

New

You set the numbers

Every limit is editable in section 7, which also lists blocked callers with a Release button. A save applies from the next request.

Real clients sail through

A valid Bearer token is never counted or refused. Protocol errors and unknown paths are never counted, so connecting several AIs in a row is fine.

New

Masked secrets, three rolls

Passphrase and access token show as dots with an eye button, so a screenshot carries neither. Roll passphrase keeps connected AIs signed in, Roll token replaces the token, and Roll & sign out all clients is the leak response.

Connect in fewer steps

Less to paste, less to remember, fewer things that quietly go stale.

New

AGY in one click

In the panel’s AGY tab, Apply to AGY CLI registers akimcp as a stdio command in ~/.gemini/config/mcp_config.json and pre-allows its tools, so the CLI stops asking per tool. The Antigravity IDE reads the same file. No token to paste.

Changed

Paste once, never again

The instruction for your AI is now two static lines: use the akimcp tools, and follow /akirule. Nothing version-dependent is left in it, so the “re-paste into each AI” warnings are gone.

Changed

One token for every client

Each grant used to mint a new access token that lived a year, and 12 piled up in testing. There is now one. Snippets you already pasted keep working, and you can roll it any time.

Changed

Postman, less pushy

The instruction injected into Postman chats is now one polite request that passes Postman’s safety check. Auto-inject is off by default; use Send now when you want it.

Fixed

Skill scripts just work

Trusted script folders (~/.claude/skills, ~/.aki/akidevrule) now work on a default install. Before, every machine needed a hand-added node or python3 row.

Leaner for the AI using it

Fewer wasted tokens and clearer failures, so the model spends its context on your work.

Changed

Shell output shaped for context

run_cmd strips ANSI codes and progress redraws and collapses repeated lines. Past about 20k characters it keeps the start and end, and saves the full text under ~/.aki/mcpsv/out/ to read back.

Fixed

Failures explain themselves

A failing command used to return only stderr. It now returns [exit code N] with stdout and stderr, and output up to 32 MB is captured (over 1 MB used to lose the whole result).

Changed

One git tool

aki__git replaces three tools, with op set to status, diff, log or tags. Output is compact and bounded, and a big diff is cut by whole file with the omitted files named first.

Changed

Rule context, half the payload

aki__akidevrule_context used to send about 90 KB of rules twice. It sends them once, drops a redundant “read SKILL.md” step, and tells web chats with no memory to keep a resumable working.md.

Changed

Errors that say what to do

A refused command names the allowed subcommands and points to panel section 6. The “no CDP port” error now explains how to attach to a browser window akimcp did not launch.

Fixed

create_directory is a true mkdir -p

Creating a folder two or more levels below an existing one used to fail with “parent directory does not exist”, despite the tool’s own promise. It works now.

Safer defaults, stated honestly

Tighter out of the box, plus a plain statement of what the guardrail is for.

Changed

Git write forms refused

The default allowlist now refuses git branch -D, git tag -d, git remote set-url and --output=. Read forms such as branch -a and tag -l still pass.

Changed

Trusted zones are write-protected

File tools refuse to write into trusted script folders, so a script the AI is allowed to run cannot be rewritten by the AI first.

Removed

A scraper is gone

aki__chrome_probe_ai scraped three vendors’ private web APIs, broke whenever they changed, and had no callers. devtools_eval can still run any fetch on demand.

Changed

Convenience first, guardrail second

Now written down as the design stance: the shell allowlist guards against weak or overeager models. It is not a lock against you, the owner.

Changed

A clearer panel

The tab title is AkiMCP v2.2.0, the header shows PID and uptime, a badge tells if AkiDevRule is installed or has an update, and icons are Font Awesome served offline instead of emoji.

Upgrade notes

Upgrading from 2.1?

Nothing to migrate and nothing to re-paste. Update the package, restart, then look at section 7 once.

  1. 1Update with the same command you used to install (below), then start it again.
  2. 2Open the control panel and scroll to section 7 to see your clients and active callers.
  3. 3Remove connectors you no longer use, then Roll token if you want a fresh one.
# Global CLI
npm install -g @akinet/akimcp
akimcp
# From source
git pull && npm install && npm start

What changed under the hood

Instruction for your AI

BeforeRe-paste whenever the rules updated

NowTwo static lines, pasted once

Access tokens

BeforeA new token per grant, none removed

NowOne shared token (an old file collapses to the first valid one)

Git tools

Beforeaki__git_status, aki__git_diff, aki__git_log

Nowaki__git with op = status, diff, log, tags

Browser quota probe

Beforeaki__chrome_probe_ai

NowRemoved. Use devtools_eval for a one-off fetch

AGY setup

BeforehttpUrl or serverUrl plus Bearer by hand

NowApply to AGY CLI, a stdio entry with no token

Postman daemon data

Before~/.aki/cdp-postman/

Now~/.aki/mcpsv/. The old folder is left unread, delete it when you like

If a secret leaks, you now have a button for it

The panel turns the clean-up into a few clicks. Which one depends on what was exposed.

Passphrase seen

Roll passphrase, then Roll & sign out all clients

Access token seen

Roll & sign out all clients

Unknown client in the list

Both rolls, then reconnect the AIs you trust

A connector you no longer use

Remove it, then Roll token

Know the limits

A security feature you can trust tells you where it stops.

  • With one shared token, Remove signs a client out but is not an instant revoke. Roll the token to cut access at once.
  • The rate limiter lives in memory, so a restart clears the blocked list.
  • Client names are self-declared. Trust the address and time columns more than the label.
  • Whether Tailscale Funnel passes the real client address to the limiter is not verified yet. It is tracked in the security doc.

Ready to try it?

See the new section 7 in the live panel preview, read the full security model, or go straight to the install page.