Repository navigation
perf(worker): cache verified Ed tokens in memory - #7
Merged
Merged
Conversation
Verify each Ed token once per isolate instead of on every /mcp request. Entries are keyed by SHA-256 of the token, expire after five minutes, are bounded to 1000 entries, and are evicted when a tool call reports an expired token. MCP_TOKEN_CACHE_TTL_SECONDS overrides the TTL; 0 disables the cache.
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
edstem-mcp | ba419ef | Commit Preview URL Branch Preview URL |
Sep 19 2026, 09:37 AM |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every
/mcprequest verified the Ed token withGET /api/userbefore the tool itself called Ed, so each tool call cost two Ed round-trips. This caches the verification result in the Worker isolate.{ edUserId, expiresAt }.onAuthExpiredon the Worker'sEdMcpRuntimeevicts the entry as soon as a tool call fails with an expired token, so a revoked token stops being trusted without waiting for the TTL.MCP_TOKEN_CACHE_TTL_SECONDSoverrides the TTL;0disables caching entirely. Documented in README and MCP_SETUP.md.The cache is per-isolate and best-effort: a cold isolate simply verifies again.
Tests
New cases in
tests/worker/worker.test.ts, all against the existing local fake Ed server (no real Ed calls): a repeat request skips/api/user, distinct tokens each verify, an expired entry re-verifies,MCP_TOKEN_CACHE_TTL_SECONDS=0disables caching, invalid tokens are not cached, and a tool call that hits a revoked token evicts the entry so the next request is rejected with 401.npm run check,npm run test:worker(10 pass), andnpm run build:workerall pass.