From e7ca6f7ae592b1621c932237a248df8ea33780ee Mon Sep 17 00:00:00 2001 From: Alex Ezell Date: Tue, 4 Aug 2026 10:36:08 -0500 Subject: [PATCH 1/2] Add Codex attribution headers --- README.md | 7 +++++++ plugins/sprites/.mcp.json | 4 ++++ 2 files changed, 11 insertions(+) diff --git a/README.md b/README.md index eb84d72..8de1ef4 100644 --- a/README.md +++ b/README.md @@ -44,6 +44,13 @@ https://sprites.dev/mcp When Codex needs access, it will prompt you to authenticate through the plugin flow. +## Usage Attribution + +The plugin marks its hosted MCP requests as Codex-driven using the coarse, +privacy-safe [`client-signals`](https://github.com/superfly/client-signals) +headers. The marker is advisory analytics only and is never used for access +control, gating, or rate-limiting. + ## Example Prompts - "Use Sprites to list my active development environments." diff --git a/plugins/sprites/.mcp.json b/plugins/sprites/.mcp.json index 3a744ed..0cc5698 100644 --- a/plugins/sprites/.mcp.json +++ b/plugins/sprites/.mcp.json @@ -2,6 +2,10 @@ "mcpServers": { "sprites": { "url": "https://sprites.dev/mcp", + "http_headers": { + "Fly-Client-Interactive": "false", + "Fly-Client-Agent": "codex" + }, "tool_timeout_sec": 300 } } From 684a52342defafe00832246712045c52317bd056 Mon Sep 17 00:00:00 2001 From: Alex Ezell Date: Tue, 4 Aug 2026 11:59:11 -0500 Subject: [PATCH 2/2] Clarify what the attribution headers mean Fly-Client-Interactive is the client-signals instrumentation sentinel, not a claim that the session is unattended: with a valid agent marker present, requests classify as agent traffic regardless of its value. Name both headers explicitly in the README so the privacy claim is checkable rather than a link to follow. --- README.md | 21 ++++++++++++++++++--- 1 file changed, 18 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 8de1ef4..87b8328 100644 --- a/README.md +++ b/README.md @@ -46,10 +46,25 @@ When Codex needs access, it will prompt you to authenticate through the plugin f ## Usage Attribution -The plugin marks its hosted MCP requests as Codex-driven using the coarse, +The plugin attributes its hosted MCP requests to Codex using the coarse, privacy-safe [`client-signals`](https://github.com/superfly/client-signals) -headers. The marker is advisory analytics only and is never used for access -control, gating, or rate-limiting. +headers. It sends two fixed values on every request to `https://sprites.dev/mcp`: + +```text +Fly-Client-Agent: codex +Fly-Client-Interactive: false +``` + +`Fly-Client-Agent` is the attribution marker. `Fly-Client-Interactive` is the +instrumentation sentinel that `client-signals` requires before it will read the +marker at all; a static plugin configuration cannot observe whether a given +Codex session is attached to a terminal, so it sends a constant rather than a +measurement. Requests classify as agent traffic on the strength of the marker, +not this value. + +Both values are fixed in the plugin's MCP configuration. Nothing user-, +machine-, or repo-specific is sent, and the attribution is advisory analytics +only — it is never used for access control, gating, or rate-limiting. ## Example Prompts