changedInput schema / properties / auth_config / anyOf
Previous value: -[
- {
- "additionalProperties": false,
- "properties": {
- "aws_access_key_id": {
- "description": "AWS access key ID; required when aws_auth_type is accessKey",
- "minLength": 1,
- "type": "string"
- },
- "aws_auth_type": {
- "description": "AWS authentication mode: accessKey uses a key pair, assumedRole uses an IAM role, and serviceRole uses the runtime workload identity",
- "enum": [
- "accessKey",
- "assumedRole",
- "serviceRole"
- ],
- "type": "string"
- },
- "aws_external_id": {
- "anyOf": [
- {
- "type": "string"
- },
- {
- "type": "null"
- }
- ],
- "description": "Optional external ID required by the target IAM role"
- },
- "aws_region": {
- "description": "AWS region containing the secret, for example us-east-1",
- "type": "string"
- },
- "aws_role_arn": {
- "description": "IAM role ARN to assume; required when aws_auth_type is assumedRole",
- "minLength": 1,
- "type": "string"
- },
- "aws_secret_access_key": {
- "description": "AWS secret access key; required when aws_auth_type is accessKey and exposed to the MCP transcript",
- "minLength": 1,
- "type": "string"
- }
- },
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "azure_auth_mode": {
- "description": "Azure authentication mode: entra uses a client secret, managed uses managed identity, and default uses the runtime credential chain",
- "enum": [
- "entra",
- "managed",
- "default"
- ],
- "type": "string"
- },
- "azure_entra_client_id": {
- "description": "Microsoft Entra application client ID; required for entra authentication",
- "minLength": 1,
- "type": "string"
- },
- "azure_entra_client_secret": {
- "description": "Microsoft Entra client secret; required for entra authentication and exposed to the MCP transcript",
- "minLength": 1,
- "type": "string"
- },
- "azure_entra_tenant_id": {
- "description": "Microsoft Entra tenant ID; required for entra authentication",
- "minLength": 1,
- "type": "string"
- },
- "azure_managed_client_id": {
- "description": "Optional client ID of a user-assigned managed identity; omit for the system-assigned identity",
- "type": "string"
- },
- "azure_vault_url": {
- "description": "Azure Key Vault URL, for example https://example.vault.azure.net",
- "format": "uri",
- "type": "string"
- }
- },
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "vault_addr": {
- "description": "Base URL of the HashiCorp Vault server",
- "format": "uri",
- "type": "string"
- },
- "vault_auth_type": {
- "description": "HashiCorp Vault authentication mode: token, AppRole, or Kubernetes",
- "enum": [
- "token",
- "approle",
- "kubernetes"
- ],
- "type": "string"
- },
- "vault_namespace": {
- "description": "Optional HashiCorp Vault Enterprise namespace",
- "type": "string"
- },
- "vault_role": {
- "description": "HashiCorp Vault Kubernetes auth role name",
- "minLength": 1,
- "type": "string"
- },
- "vault_role_id": {
- "description": "HashiCorp Vault AppRole role ID; required for approle authentication",
- "minLength": 1,
- "type": "string"
- },
- "vault_secret_id": {
- "description": "HashiCorp Vault AppRole secret ID; required for approle authentication and exposed to the MCP transcript",
- "minLength": 1,
- "type": "string"
- },
- "vault_token": {
- "description": "HashiCorp Vault token; required for token authentication and exposed to the MCP transcript",
- "minLength": 1,
- "type": "string"
- }
- },
- "type": "object"
- }
-]New value: +[
+ {
+ "additionalProperties": false,
+ "properties": {
+ "aws_access_key_id": {
+ "description": "AWS access key ID; required when aws_auth_type is accessKey",
+ "minLength": 1,
+ "type": "string"
+ },
+ "aws_auth_type": {
+ "description": "AWS authentication mode: accessKey uses a key pair, assumedRole uses an IAM role, and serviceRole uses the runtime workload identity",
+ "enum": [
+ "accessKey",
+ "assumedRole",
+ "serviceRole"
+ ],
+ "type": "string"
+ },
+ "aws_external_id": {
+ "description": "Optional external ID required by the target IAM role",
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "aws_region": {
+ "description": "AWS region containing the secret, for example us-east-1",
+ "type": "string"
+ },
+ "aws_role_arn": {
+ "description": "IAM role ARN to assume; required when aws_auth_type is assumedRole",
+ "minLength": 1,
+ "type": "string"
+ },
+ "aws_secret_access_key": {
+ "description": "AWS secret access key; required when aws_auth_type is accessKey and exposed to the MCP transcript",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "azure_auth_mode": {
+ "description": "Azure authentication mode: entra uses a client secret, managed uses managed identity, and default uses the runtime credential chain",
+ "enum": [
+ "entra",
+ "managed",
+ "default"
+ ],
+ "type": "string"
+ },
+ "azure_entra_client_id": {
+ "description": "Microsoft Entra application client ID; required for entra authentication",
+ "minLength": 1,
+ "type": "string"
+ },
+ "azure_entra_client_secret": {
+ "description": "Microsoft Entra client secret; required for entra authentication and exposed to the MCP transcript",
+ "minLength": 1,
+ "type": "string"
+ },
+ "azure_entra_tenant_id": {
+ "description": "Microsoft Entra tenant ID; required for entra authentication",
+ "minLength": 1,
+ "type": "string"
+ },
+ "azure_managed_client_id": {
+ "description": "Optional client ID of a user-assigned managed identity; omit for the system-assigned identity",
+ "type": "string"
+ },
+ "azure_vault_url": {
+ "description": "Azure Key Vault URL, for example https://example.vault.azure.net",
+ "format": "uri",
+ "type": "string"
+ }
+ },
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "vault_addr": {
+ "description": "Base URL of the HashiCorp Vault server",
+ "format": "uri",
+ "type": "string"
+ },
+ "vault_auth_type": {
+ "description": "HashiCorp Vault authentication mode: token, AppRole, or Kubernetes",
+ "enum": [
+ "token",
+ "approle",
+ "kubernetes"
+ ],
+ "type": "string"
+ },
+ "vault_namespace": {
+ "description": "Optional HashiCorp Vault Enterprise namespace",
+ "type": "string"
+ },
+ "vault_role": {
+ "description": "HashiCorp Vault Kubernetes auth role name",
+ "minLength": 1,
+ "type": "string"
+ },
+ "vault_role_id": {
+ "description": "HashiCorp Vault AppRole role ID; required for approle authentication",
+ "minLength": 1,
+ "type": "string"
+ },
+ "vault_secret_id": {
+ "description": "HashiCorp Vault AppRole secret ID; required for approle authentication and exposed to the MCP transcript",
+ "minLength": 1,
+ "type": "string"
+ },
+ "vault_token": {
+ "description": "HashiCorp Vault token; required for token authentication and exposed to the MCP transcript",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "type": "object"
+ }
+]