Skip to content

[Bug]: MCP bearer token for spawned Claude sessions is visible in process arguments #16028

Description

@axonario

Before submitting

  • I searched existing issues and did not find a duplicate.
  • I included enough detail to reproduce or investigate the problem.

Area

apps/server

Steps to reproduce

  1. Start T3 Code 0.0.45 (desktop app on Linux; server on 127.0.0.1:3773).
  2. Open a thread that uses the Claude provider.
  3. From any process running as the same user, list process arguments: ps -eo args.

Expected behavior

The bearer credential for the T3 Code MCP server does not appear in any process's argv. For example, it is passed through a file with mode 0600, an inherited file descriptor, or an environment variable.

Actual behavior

The spawned claude process receives the MCP configuration inline:

--mcp-config {"mcpServers":{"t3-code":{"type":"http","url":"http://127.0.0.1:3773/mcp","headers":{"Authorization":"Bearer <redacted>"}}}}

The token is readable in /proc/<pid>/cmdline and in ps output for as long as the session runs.

Impact

Any local process running as the same user, and any tool that captures process lists (monitoring, crash reports, shell history of a ps paste, screenshots), can read a credential that authorizes calls to the T3 Code MCP endpoint. The exposure is local and limited to the same user, but the token ends up in places where people don't expect secrets.

Version or commit

0.0.45

Environment

Arch-based Linux, t3code-bin package, desktop app, Claude provider.

Logs or stack traces

None; observed through process arguments.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions