diff --git a/README.md b/README.md index eb84d72..87b8328 100644 --- a/README.md +++ b/README.md @@ -44,6 +44,28 @@ https://sprites.dev/mcp When Codex needs access, it will prompt you to authenticate through the plugin flow. +## Usage Attribution + +The plugin attributes its hosted MCP requests to Codex using the coarse, +privacy-safe [`client-signals`](https://github.com/superfly/client-signals) +headers. It sends two fixed values on every request to `https://sprites.dev/mcp`: + +```text +Fly-Client-Agent: codex +Fly-Client-Interactive: false +``` + +`Fly-Client-Agent` is the attribution marker. `Fly-Client-Interactive` is the +instrumentation sentinel that `client-signals` requires before it will read the +marker at all; a static plugin configuration cannot observe whether a given +Codex session is attached to a terminal, so it sends a constant rather than a +measurement. Requests classify as agent traffic on the strength of the marker, +not this value. + +Both values are fixed in the plugin's MCP configuration. Nothing user-, +machine-, or repo-specific is sent, and the attribution is advisory analytics +only — it is never used for access control, gating, or rate-limiting. + ## Example Prompts - "Use Sprites to list my active development environments." diff --git a/plugins/sprites/.mcp.json b/plugins/sprites/.mcp.json index 3a744ed..0cc5698 100644 --- a/plugins/sprites/.mcp.json +++ b/plugins/sprites/.mcp.json @@ -2,6 +2,10 @@ "mcpServers": { "sprites": { "url": "https://sprites.dev/mcp", + "http_headers": { + "Fly-Client-Interactive": "false", + "Fly-Client-Agent": "codex" + }, "tool_timeout_sec": 300 } }