Guide
MCP and API
Connect Grok or Cursor to the colorbars.pro Worker. Streamable HTTP MCP, auth, training catalog, and the Grok marketplace checklist.
Two sites, two jobs
colorbars.pro is enterprise services: offerings, training, unsigned claims preview, Hang Radar ingest, preflight fixture scores, and briefings. colorbars.dev is the toolkit bench: watch, the token lab, and manifests. The pro MCP server does not replace the bench.
Endpoints
The Worker in this repo serves:
GET /api/openapi.json— OpenAPI 3.1 for the public surface.GET /api/v1— discovery (role, auth, links).GET /api/v1/training— course and workshop catalog.POST /mcp— stateless Streamable HTTP MCP (JSON-RPC 2.0).
Production URLs use https://colorbars.pro. They answer after a production
deploy of this Worker. This change set does not deploy.
Connect MCP
Grok needs a public HTTPS Streamable HTTP endpoint. The plugin manifest points at
https://colorbars.pro/mcp. There is no stdio server: the Astro site and the
API share this Worker.
The server is stateless. It does not issue Mcp-Session-Id. POST JSON-RPC. GET returns 405.
Send Accept: application/json, text/event-stream. One result comes back as JSON. A batch comes back as server-sent events.
Supported protocol versions: 2024-11-05, 2025-03-26, 2025-06-18.
Send MCP-Protocol-Version on requests after initialize.
When a browser sends Origin, the Worker allows https://colorbars.pro,
https://www.colorbars.pro, and localhost. Server-side clients omit Origin.
Grok
The repo ships .grok-plugin/plugin.json, .mcp.json, and skills/colorbars-pro/SKILL.md.
{
"mcpServers": {
"colorbars-pro": {
"type": "http",
"url": "https://colorbars.pro/mcp"
}
}
} Cursor
Add the same URL to the project MCP config. The skill file is skills/colorbars-pro/SKILL.md.
{
"mcpServers": {
"colorbars-pro": {
"url": "https://colorbars.pro/mcp"
}
}
} Auth
- Reads — offerings, training, claim scopes, catalog preview, preflight scores, and the Hang Radar contract need no credential.
- Briefings —
POST /api/v1/briefingsand thesubmit_briefingtool use the public contact contract. No API key. A non-emptywebsitefield is the honeypot and is dropped. - Hang Radar ingest —
Authorization: BearerorX-Hang-Radar-Key. The Worker compares it toHANG_RADAR_API_KEYwhen that secret is set. The MCP tool also acceptsapiKeyand does not echo it. - Claims — compiler output is unsigned.
desk_handoffbuilds a colorbars.dev URL withsource=pro. It does not mint a signed token. - Left off this surface —
/api/admin/*,/api/auth/*, and/api/sso/*stay on the manage UI. MCP tools do not call them.
Tools
Each tool returns the same JSON body as the matching HTTP call.
list_offerings,list_training,get_traininglist_claim_scopes,list_catalog_variants,preview_catalog,compile_claims,desk_handoffscore_preflight,describe_hang_radar,ingest_hang_radarsubmit_briefing
Resources use the colorbars-pro:// scheme (training, training/{id}, offerings, claims/scopes, hang-radar, openapi).
Grok marketplace and Tesla
Grok Build installs third-party plugins from a catalog entry in
xai-org/plugin-marketplace.
The entry is a remote source: repository URL plus a full 40-character commit SHA.
An official org repository is what review expects. Validate with
python3 scripts/validate-catalog.py and
python3 scripts/generate-plugin-index.py in that repo.
Tesla in-car Grok uses this same plugin path. colorbars.pro does not have a separate Tesla App Store listing.
This repository does not include a marketplace merge, a Tesla approval, or a production SHA pin.
The source account today is steelhead99x/colorbars-pro, and the repo is private.
Index generation can only fetch a public commit. The checklist in the repo is
docs/GROK-MARKETPLACE.md.