Configuration & Credentials
What works
Section titled “What works”Read credentials in your handler, in this order:
- A bridge file —
.mm/integrations/{id}.jsoninside the project. This is what the bundled GitHub and Slack plugins read, and it keeps secrets per-project and gitignored. - An environment variable — whatever the MCP server was started with.
import { readFileSync } from 'node:fs';import { join } from 'node:path';
function token(projectPath: string): string { try { const f = JSON.parse(readFileSync(join(projectPath, '.mm/integrations/my-plugin.json'), 'utf8')); if (f.token) return f.token; } catch {} const env = process.env.MY_PLUGIN_TOKEN; if (env) return env; throw new Error('No token — set MY_PLUGIN_TOKEN or write .mm/integrations/my-plugin.json');}Don’t write secrets into .mm/config.json (it’s shared state, not a secret store) and don’t log them. Read them per call, so switching projects switches credentials.