The in-sandbox callback gateway read the bridge token only from "Authorization: Bearer <token>". The public Paperclip API documents the "X-API-Key: <token>" header, so an agent that follows those docs sends that header first and gets a 401 with "Invalid bridge token." The agent then retries with a bearer header and the same token. Both gateways now read the token through one helper. The helper prefers a bearer token in the Authorization header. It falls back to the X-API-Key header. The token still goes to the same constant-time comparison, and the closed header allowlist still strips both headers before either gateway forwards a request. Claude-Session: https://claude.ai/code/session_01U9PF3d9SASC9tomDRjyeVt |
||
|---|---|---|
| .. | ||
| adapter-utils | ||
| adapters | ||
| db | ||
| google-sheets-mcp-server | ||
| kv-demo-mcp-server | ||
| mcp-server | ||
| paperclip-eval-kernel | ||
| paperclip-runner | ||
| plugins | ||
| shared | ||
| skills-catalog | ||
| tailscale-https-broker | ||
| teams-catalog | ||