Grant and request diagnostics

The admin UI adds Client authorizations and Request diagnostics. Configuration administrators can filter grants by exact user subject, client ID, endpoint and status, page through all matching users, inspect granted capabilities/resources/scopes, prefill an access check, and revoke a grant. Granted scopes are an upper bound, not the user's currently verified token permissions. Revocation blocks subsequent admission and cancels active streams; it cannot roll back upstream side effects. The personal portal remains restricted to the signed-in user's grants.

Request diagnostics persist completed MCP POST requests in managed SQLite/PostgreSQL and survive restarts. admin.request_retention defaults to 720h (30 days), accepts 24h–8760h, and automatically prunes expired records. The default query window is 24 hours, with completion-time filters, pagination and NDJSON export. Records contain IDs, verified identities, known routing names, timings and fixed outcome/reason codes, excluding arguments, results, tokens and raw error bodies. Detailed records are encrypted; query indexes retain identity/routing metadata, so protect the database and exported files. Statistics cover the full filtered window, including P95 and average approval wait for resumed operations.

Recording happens after request processing. Storage failure never replays or changes a business operation: the server logs the failure and the UI reports recording gaps during this run. A crash before persistence, in-flight requests and GET streams remain outside this history. Use independent approval-audit archives where required. Deployments without managed storage retain the existing short-lived in-memory diagnostics only.

GET /api/v1/requests accepts since and until (RFC3339 completion times), returning the actual window_start/window_end. format=ndjson exports up to 10,000 records under the same administrator authorization and filters; a nonzero X-MCPHub-Next-Cursor response header can be passed as cursor to continue, or narrow the UI time range. Request history is retained in fresh schema 10 storage; back up the database and matching key.

Admin-only APIs (on the admin listener, not the personal portal):

mcpbridge admin --profile ops get '/client-grants?subject=alice&status=active&limit=25'
mcpbridge admin --profile ops get '/requests?endpoint=database-prod&outcome=scope_denied&limit=25'

Both return next_cursor; pass it back as cursor with unchanged filters and, for request history, the returned time window. Grant filters also accept client and endpoint; request filters also accept request_id, subject, client and original tool. Normal pagination limits are 1–100. Revoke with POST /api/v1/client-grants/{grant_id}/revoke and {"subject":"alice"}.