MoQ Studio Control plane

Guide

MCP and API

Connect Grok or Cursor to the colorbars.pro Worker. Streamable HTTP MCP, auth, training catalog, and the Grok marketplace checklist.

Two sites, two jobs

colorbars.pro is enterprise services: offerings, training, unsigned claims preview, Hang Radar ingest, preflight fixture scores, and briefings. colorbars.dev is the toolkit bench: watch, the token lab, and manifests. The pro MCP server does not replace the bench.

Endpoints

The Worker in this repo serves:

  • GET /api/openapi.json — OpenAPI 3.1 for the public surface.
  • GET /api/v1 — discovery (role, auth, links).
  • GET /api/v1/training — course and workshop catalog.
  • POST /mcp — stateless Streamable HTTP MCP (JSON-RPC 2.0).

Production URLs use https://colorbars.pro. They answer after a production deploy of this Worker. This change set does not deploy.

Connect MCP

Grok needs a public HTTPS Streamable HTTP endpoint. The plugin manifest points at https://colorbars.pro/mcp. There is no stdio server: the Astro site and the API share this Worker.

The server is stateless. It does not issue Mcp-Session-Id. POST JSON-RPC. GET returns 405.

Send Accept: application/json, text/event-stream. One result comes back as JSON. A batch comes back as server-sent events.

Supported protocol versions: 2024-11-05, 2025-03-26, 2025-06-18. Send MCP-Protocol-Version on requests after initialize.

When a browser sends Origin, the Worker allows https://colorbars.pro, https://www.colorbars.pro, and localhost. Server-side clients omit Origin.

Grok

The repo ships .grok-plugin/plugin.json, .mcp.json, and skills/colorbars-pro/SKILL.md.

{
  "mcpServers": {
    "colorbars-pro": {
      "type": "http",
      "url": "https://colorbars.pro/mcp"
    }
  }
}

Cursor

Add the same URL to the project MCP config. The skill file is skills/colorbars-pro/SKILL.md.

{
  "mcpServers": {
    "colorbars-pro": {
      "url": "https://colorbars.pro/mcp"
    }
  }
}

Auth

  • Reads — offerings, training, claim scopes, catalog preview, preflight scores, and the Hang Radar contract need no credential.
  • Briefings — POST /api/v1/briefings and the submit_briefing tool use the public contact contract. No API key. A non-empty website field is the honeypot and is dropped.
  • Hang Radar ingest — Authorization: Bearer or X-Hang-Radar-Key. The Worker compares it to HANG_RADAR_API_KEY when that secret is set. The MCP tool also accepts apiKey and does not echo it.
  • Claims — compiler output is unsigned. desk_handoff builds a colorbars.dev URL with source=pro. It does not mint a signed token.
  • Left off this surface — /api/admin/*, /api/auth/*, and /api/sso/* stay on the manage UI. MCP tools do not call them.

Tools

Each tool returns the same JSON body as the matching HTTP call.

  • list_offerings, list_training, get_training
  • list_claim_scopes, list_catalog_variants, preview_catalog, compile_claims, desk_handoff
  • score_preflight, describe_hang_radar, ingest_hang_radar
  • submit_briefing

Resources use the colorbars-pro:// scheme (training, training/{id}, offerings, claims/scopes, hang-radar, openapi).

Grok marketplace and Tesla

Grok Build installs third-party plugins from a catalog entry in xai-org/plugin-marketplace. The entry is a remote source: repository URL plus a full 40-character commit SHA. An official org repository is what review expects. Validate with python3 scripts/validate-catalog.py and python3 scripts/generate-plugin-index.py in that repo.

Tesla in-car Grok uses this same plugin path. colorbars.pro does not have a separate Tesla App Store listing.

This repository does not include a marketplace merge, a Tesla approval, or a production SHA pin. The source account today is steelhead99x/colorbars-pro, and the repo is private. Index generation can only fetch a public commit. The checklist in the repo is docs/GROK-MARKETPLACE.md.