Skip to content

perf(worker): cache verified Ed tokens in memory - #7

Merged
bunizao merged 1 commit into
mainfrom
perf/worker-token-cache
Sep 19, 2026
Merged

bunizao merged 1 commit into
mainfrom
perf/worker-token-cache

Conversation

@bunizao

@bunizao bunizao commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Every /mcp request verified the Ed token with GET /api/user before the tool itself called Ed, so each tool call cost two Ed round-trips. This caches the verification result in the Worker isolate.

  • Cache key is the SHA-256 hex of the raw token, so the token itself is never stored; the value is { edUserId, expiresAt }.
  • TTL is 5 minutes, bounded to 1000 entries with oldest-insertion eviction. Failed verifications are never cached.
  • onAuthExpired on the Worker's EdMcpRuntime evicts the entry as soon as a tool call fails with an expired token, so a revoked token stops being trusted without waiting for the TTL.
  • MCP_TOKEN_CACHE_TTL_SECONDS overrides the TTL; 0 disables caching entirely. Documented in README and MCP_SETUP.md.

The cache is per-isolate and best-effort: a cold isolate simply verifies again.

Tests

New cases in tests/worker/worker.test.ts, all against the existing local fake Ed server (no real Ed calls): a repeat request skips /api/user, distinct tokens each verify, an expired entry re-verifies, MCP_TOKEN_CACHE_TTL_SECONDS=0 disables caching, invalid tokens are not cached, and a tool call that hits a revoked token evicts the entry so the next request is rejected with 401.

npm run check, npm run test:worker (10 pass), and npm run build:worker all pass.

Verify each Ed token once per isolate instead of on every /mcp request.
Entries are keyed by SHA-256 of the token, expire after five minutes,
are bounded to 1000 entries, and are evicted when a tool call reports an
expired token. MCP_TOKEN_CACHE_TTL_SECONDS overrides the TTL; 0 disables
the cache.
Copilot AI lite review requested due to automatic review settings September 19, 2026 09:37

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
edstem-mcp ba419ef Commit Preview URL

Branch Preview URL
Sep 19 2026, 09:37 AM

@bunizao
bunizao merged commit bbb1b70 into main Sep 19, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants