Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,18 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [1.1.8] - 2026-04-14

### Fixed

- **Authentication**: Updated email/password authentication to match Skylight's current web OAuth flow. The server now follows the browser login sequence (`/oauth/authorize` -> `/auth/session` -> `/oauth/token`) and uses the returned bearer token for API requests.

### Changed

- Centralized shared API constants, including the Skylight API version header
- Updated auth-related docs and error guidance to reflect OAuth-based login
- Added automated tests for the OAuth login flow and kept live smoke validation against the real API

## [1.1.7] - 2025-12-30
Comment thread
coderabbitai[bot] marked this conversation as resolved.

### Fixed
Expand Down
10 changes: 5 additions & 5 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,26 +33,26 @@ npm run generate:types # Generate TypeScript types from OpenAPI spec
**Key files**:
- `config.ts` - Zod-validated env config supporting two auth methods
- `api/client.ts` - HTTP client with Bearer/Basic auth, auto-login, subscription status tracking
- `api/auth.ts` - Login endpoint for email/password authentication
- `api/auth.ts` - Browser-style OAuth login flow for email/password authentication
- `api/generated-types.ts` - Auto-generated types from OpenAPI spec
- `utils/dates.ts` - Parses "today", "tomorrow", day names, YYYY-MM-DD

## Authentication

Two methods supported (validated via Zod refinement in `config.ts`):

1. **Email/Password** (recommended): Set `SKYLIGHT_EMAIL` and `SKYLIGHT_PASSWORD`. Server auto-logs in via POST /api/sessions and uses `Basic base64(userId:token)` format for subsequent requests.
1. **Email/Password** (recommended): Set `SKYLIGHT_EMAIL` and `SKYLIGHT_PASSWORD`. Server reproduces the Skylight web OAuth flow (`/oauth/authorize` -> login form -> `/auth/session` -> `/oauth/token`) and then uses the returned bearer token for API requests.
2. **Manual Token**: Set `SKYLIGHT_TOKEN` and optionally `SKYLIGHT_AUTH_TYPE` (bearer/basic).

Both require `SKYLIGHT_FRAME_ID` (household identifier from API URLs like `/api/frames/{frameId}/chores`).

**Note**: The Skylight API uses Basic auth with the format `Basic base64(userId:token)`, not Bearer tokens.
**Note**: Email/password auth now resolves to a bearer token. Manual token auth still supports either `bearer` or `basic`.

## Plus Subscription

Some features require a Skylight Plus subscription. The server detects subscription status from the login response (`subscription_status: "plus"`). Plus-only tools are not registered for non-Plus users.

**Plus-only domains**: Rewards, Meals, Photos
**Plus-only domains**: Rewards, Meals, Photos. Subscription status is inferred after login from live API access.

## MCP Tools (35+ total)

Expand Down Expand Up @@ -103,4 +103,4 @@ The release workflow (`.github/workflows/release.yml`) will:
## API Quirks

- **Calendar date_max is exclusive**: When querying calendar events, `date_max` is treated as exclusive. The code adds 1 day to include events on the end date.
- **Auth format**: API expects `Basic base64(userId:token)`, not Bearer tokens.
- **Auth format**: Managed email/password auth now uses OAuth and bearer tokens. Manual token auth may still use bearer or basic depending on the captured token.
12 changes: 9 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,7 +90,7 @@ The MCP server supports two authentication methods:

### Option 1: Email/Password (Recommended)

Use your Skylight account credentials. The server will automatically log in and manage tokens.
Use your Skylight account credentials. The server automatically follows Skylight's web OAuth login flow and manages the returned bearer token for you.

```env
SKYLIGHT_EMAIL=your_email@example.com
Expand All @@ -100,7 +100,7 @@ SKYLIGHT_FRAME_ID=your_frame_id

### Option 2: Manual Token (Legacy)

Capture a token from the Skylight app using a proxy tool.
Capture a bearer or basic token from Skylight traffic using a proxy tool.

```env
SKYLIGHT_TOKEN=your_token_here
Expand All @@ -123,11 +123,17 @@ You still need to find your frame ID (the household identifier):
|----------|----------|-------------|
| `SKYLIGHT_EMAIL` | Option 1 | Your Skylight account email |
| `SKYLIGHT_PASSWORD` | Option 1 | Your Skylight account password |
| `SKYLIGHT_TOKEN` | Option 2 | Your API token (if not using email/password) |
| `SKYLIGHT_TOKEN` | Option 2 | Your captured API token (if not using email/password) |
| `SKYLIGHT_AUTH_TYPE` | No | `bearer` (default) or `basic` (for manual token) |
| `SKYLIGHT_FRAME_ID` | Yes | Your household frame ID |
| `SKYLIGHT_TIMEZONE` | No | Default timezone (default: `America/New_York`) |

### Auth Notes

- Email/password auth no longer uses the legacy `/api/sessions` token flow.
- The server now reproduces the Skylight web login flow and exchanges the resulting authorization code for a bearer token.
- Manual token auth still works if you prefer to provide a captured token directly.

### Example .env file:

```env
Expand Down
8 changes: 4 additions & 4 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@eaglebyte/skylight-mcp",
"version": "1.1.7",
"version": "1.1.8",
"description": "MCP server for Skylight Calendar API - enables agentic interactions for calendar, chores, lists, and family management",
"type": "module",
"main": "dist/index.js",
Expand Down
Loading