Repository navigation
Group session-less MCP calls and record Codex model in analytics - #240
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
rgarcia
approved these changes
Oct 9, 2026
rgarcia
left a comment
Contributor
There was a problem hiding this comment.
reviewed — looks good. two small test things, neither blocking:
Nits
src/lib/mcp/analytics.test.ts:1647-1664—firstandsecondrun on the real clock, so if the test crosses a :00/:30 window boundary they land in different sessions and the equality assertion fails. rare, but consider pinning time withsetSystemTimefrombun:test.src/lib/mcp/analytics.ts:563— nothing coverscaptureMcpCustomEvent(feedback / capability reports) getting the derived session. might be worth a test asserting a custom event lands in the same$session_idas a tool call from the same caller + client.
Collaborator
Author
|
Thanks, both addressed in the latest commit:
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Since the move to MCP SDK v2, clients that negotiate the 2026-07-28 protocol revision (no
initialize, nomcp-session-id, a fresh server per request) get a new PostHog$session_idon every tool call. Calls per session dropped from ~5.3 to ~1.4 the week of the upgrade, so session-based MCP analytics (session list, tool neighbors, calls per session) stopped working for most traffic.The SDK's fix for this is
enableConversationId, which injects aconversation_idargument into every tool and asks agents not to make parallel calls until they have one. This PR keeps that off and derives the session server-side instead:eventPropertiescomputes a key from the authenticated caller (Clerk user ID, or the API key), the organization, and the client name from request metadata.beforeSendhashes that key with a fixed 30-minute window into$session_idand the matching anonymousdistinct_id. Custom events (feedback, capability reports) use the same key.eventPropertiesand is removed before capture; no credential or user ID is sent.It also records
$mcp_llm_model(sourceclient_metadata) when Codex sendsx-codex-turn-metadata.modelon a tool call.captureModelstays off, so nollm_modelargument is injected and agents are never asked to self-report. Values must look like a model ID ([\w.:/@-]{1,100}, notunknown).Tradeoffs
Testing
bun test: 910 pass. New integration tests send 2026-07-28 requests throughcreateMcpHandlerand check that calls from the same caller and client share a session (and distinct ID), that a different caller or client gets a different one, that a carried transport session is kept, and that the model is recorded only from valid Codex metadata. The grouping test fails without the change.tsc --noEmitand prettier pass.Note
Medium Risk
Changes how all session-less MCP traffic is attributed in PostHog (distinct ids and session metrics); logic is hashed and allowlisted but mis-bucketing could merge or split sessions incorrectly.
Overview
Restores meaningful session-scoped MCP analytics for the 2026-07-28 protocol (no transport
mcp-session-id, fresh server per request) by deriving$session_idserver-side instead of enabling SDKenableConversationId.When a request has no real MCP session, instrumentation attaches a transient hashed
__mcp_analytics_session_keyfrom caller identity (Clerk user or API token), organization, and client name from request metadata.sanitizeMcpAnalyticsEventbuckets that key into 30-minute fixed windows to set$session_idand align anonymousdistinct_id; the internal key is stripped before capture. Transport sessions are unchanged. Custom events (e.g. feedback) use the same derivation.Also records
$mcp_llm_modelwith sourceclient_metadataontools/callwhen Codex sendsx-codex-turn-metadata.model, with strict validation (no agent self-report).Tests add 2026-07-28
createMcpHandlerflows: shared sessions per caller/client/window, feedback in the same derived session, preserved carried session, and Codex-only model properties.Reviewed by Cursor Bugbot for commit 11effae. Bugbot is set up for automated code reviews on this repo. Configure here.