The MCP OAuth flow defaulted the authorization-request prompt parameter to 'consent'. Per OpenID Connect Core 1.0 §3.1.2.1 that asks the authorization server to re-prompt for consent only while reusing the existing browser authentication session. Cloudflare's MCP OAuth server (and other strict OIDC providers) honor that literally, so /mcp reauth landed on the consent screen attached to whichever account the browser cookie was for, leaving no way to switch the signed-in account. Default to 'login consent' instead so the provider first re-prompts for authentication (the page Claude Code shows on its reauth flow) and then re-confirms consent, preserving the original intent of always re-displaying the authorize screen. RFC 6749 §3.1 requires providers to ignore prompt values they do not support, so the two-value form is safe for non-OIDC servers. Existing per-server overrides via mcp.json's `oauth.prompt` (including the empty-string escape hatch) are unchanged. Fixes #3817
@oh-my-pi/pi-coding-agent
Core implementation package for the omp coding agent in the oh-my-pi monorepo.
For installation, setup, provider configuration, model roles, slash commands, and full CLI reference, see:
Package-specific references:
Memory backends
The agent supports three mutually-exclusive memory backends, selected via the memory.backend setting (Settings → Memory tab, or ~/.omp/config.yml):
off(default) — no memory subsystem runs.local— existing rollout-summarisation pipeline; writesmemory_summary.mdand consolidated artifacts under the agent dir.hindsight— talks to a Hindsight server (Cloud or self-hosted Docker), retains transcripts every Nth user turn, recalls memories on the first turn of a session, and exposesretain,recall, andreflect.
Hindsight quickstart
- Run a Hindsight server (Cloud or
docker run -p 8888:8888 ghcr.io/vectorize-io/hindsight:latest). - Set
memory.backend = "hindsight"andhindsight.apiUrl = "http://localhost:8888"(or your Cloud URL). - Optional environment overrides (env wins over settings):
HINDSIGHT_API_URL,HINDSIGHT_API_TOKEN— connectionHINDSIGHT_BANK_ID,HINDSIGHT_DYNAMIC_BANK_ID,HINDSIGHT_AGENT_NAME— bank addressingHINDSIGHT_AUTO_RECALL,HINDSIGHT_AUTO_RETAIN,HINDSIGHT_RETAIN_MODE— lifecycleHINDSIGHT_RECALL_BUDGET,HINDSIGHT_RECALL_MAX_TOKENS— recall sizingHINDSIGHT_BANK_MISSION,HINDSIGHT_DEBUG
Switching backends mid-session is honoured on the next system-prompt rebuild and the next /memory slash command. Existing users with memories.enabled = true|false are migrated to memory.backend = "local"|"off" exactly once on first launch.