- forward_to_poke now checks the response's success field instead of
trusting the HTTP status alone; Poke can return 200 with
success: false on a soft failure, which was previously logged and
treated as delivered.
- README/start.sh pointed users to Settings > Advanced for the API
key, which issues a legacy pk_ key incompatible with the
inbound/api-message endpoint this project uses. Now points to
poke.com/kitchen -> API Keys for a V2 key.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
start.sh previously generated and persisted an MCP_API_KEY to .env
unconditionally on first run. In tunnel mode (POKE_TUNNEL=1, the
default) the local server runs unauthenticated and the Poke tunnel
handles auth — generating a key there is at best useless and at worst
overwrites the user's pre-set key, causing 421 errors at the tunnel.
Move .env loading and POKE_TUNNEL resolution above the generation
block, and skip generation entirely when POKE_TUNNEL=1. Re-source .env
after a successful generation so the rest of the script sees the new
value.
Fixes#9
- Add __version__ = "0.1.0" to src/server.py
- Add release.yml workflow to create GitHub Releases on v* tags
- Refactor start.sh OTA to use GitHub Releases API instead of commit SHAs
- start.sh: detect POKE_TUNNEL env var; skip MCP_API_KEY requirement and
auth when running via poke tunnel (server.py reads the same var)
- start.sh: pass POKE_TOKEN into Python via env var + use json.dumps to
safely escape quotes/backslashes in YAML (fixes shell-interpolation
injection risk, Copilot issue #5 / start.sh:72)
- start.sh: anchor MCP_API_KEY guard to non-commented line-start
assignments and also detect empty value (Copilot issues #1, #8 /
start.sh:104)
- start.sh: anchor re.sub pattern with re.MULTILINE so only the actual
assignment line is rewritten, not mid-line occurrences (Copilot
issue #2)
- start.sh: check re.sub replacement count, warn when poke_api_key key
is missing from config.yml (Copilot issue #6)
- start.sh: guard npm/npx usage with command -v check; fall back to npx
poke instead of hard-failing (Copilot issue #3)
- start.sh: use python3 consistently for server.py (Copilot issue #9 /
start.sh:134)
- start.sh: prefer npx poke tunnel; check command -v poke and fall back
gracefully (Copilot issue #10 / start.sh:135)
- server.py: honour POKE_TUNNEL=1 — skip bearer-token auth so the poke
tunnel handles identity; MCP_API_KEY becomes optional in that mode
- README.md: add Node.js/npm prerequisite note (Copilot issue #4)
- README.md: clarify server starts on first run; update AI agent prompt
(Copilot issue #11 / README.md:48)
Adds a copy-pasteable prompt for non-technical users to set up poke-mail
via their AI coding agent, a start.sh script that loads .env, activates
the virtualenv, starts the server, and tunnels to Poke, and recommended
container resource limits for orchestrators.