Sea Haven MCP platform — trust-tiered MCP servers + Cognito/Google auth broker, replacing seahaven-slack-bot and exec-aide (design phase)
Find a file
Adam Moussa 9cf124a24b Fold in Gemini (round-3, third model family) auth findings
- Gemini-BLOCK-1: AllowedOAuthScopes strictly filtering a V2 pre-token Lambda's output
  is unverified -> fatal Phase-0a check (§6 #8a); if it fails, pre-token fail-closed
  becomes the primary boundary.
- Gemini-BLOCK-2: Cognito access tokens carry client_id/scopes, not native aud -> align
  §1h + facade/server checks to client_id allow-list / scope-prefix audience proxy.
- Gemini-Q: 0a spike must run on production-equivalent Enterprise Grid + real licenses.
- Gemini-NIT (path-corrected): project memory is a private store at ~/.claude/.../memory/,
  not the repo and not Gemini's own ~/.gemini path.
Three model families now converge: structural plan sound; only open risk is the auth
token-mint mechanism, fully spike-gated in Phase 0a.
2026-06-11 13:22:55 -04:00
docs Fold in Gemini (round-3, third model family) auth findings 2026-06-11 13:22:55 -04:00
.gitignore Initial commit: sh-mcp design and plan 2026-06-09 19:25:24 -04:00
README.md Initial commit: sh-mcp design and plan 2026-06-09 19:25:24 -04:00

sh-mcp

Sea Haven MCP platform. A TypeScript monorepo of trust-tiered MCP servers that expose Sea Haven's proprietary integrations as tools, plus the Cognito/Google auth broker and the rebuilt scheduled jobs. This service replaces seahaven-slack-bot and exec-aide, which are deprecated completely; the conversational surface becomes a configurable Slack task agent.

Status: DESIGN / PLANNING. Not built. No stack deployed. The full design, auth architecture, scope matrix, and build plan live in docs/design.md. Read it before writing any code.

Shape (planned)

  • MCP servers (trust-tiered, remote HTTP, per-server IAM):
    • sh-mcp-ops — read-mostly, agent-facing (WO/PO/site lookups, KB search, Google Maps, Gmail/Calendar, tasks, reminders).
    • sh-mcp-finance — sensitive, read-only, audited (QBO vendor search, payment lookups).
    • sh-mcp-physical — DEFERRED, admin/out-of-band only (Lenel/Yealink/3CX control).
  • Auth — Google Workspace is the single IdP; an Amazon Cognito user pool federated to Google issues scoped, audience-bound JWTs; group → scope mapping via a pre-token Lambda. See design §2.
  • Jobs — rebuilt proactive Lambdas (email classify/digest, KB syncs).
  • Language — TypeScript everywhere (servers, packages, CDK, jobs).

Open decisions

  • Task-agent surface: Agentforce (recommended) vs marketplace Claude app vs custom Bolt assistant (design §12). Drives the model + guardrail story.
  • Endpoint exposure specifics (Slack egress ranges / WAF) — design §9 / §11.

Layout (target)

packages/   shared + one package per integration
servers/    sh-mcp-ops, sh-mcp-finance  (CDK stacks)
auth/       cognito, pre-token-lambda, group-sync-lambda
jobs/       rebuilt scheduled Lambdas
docs/       design.md  (the canonical plan)

See docs/design.md for the authoritative spec.