Summary
Let a host observe every MCP bridge call without wrapping the tool, plus small follow-ups to the host-backed OAuth flow (#39), so OpenCompany can drop its own call wrapper and OAuth port.
Scope
tinymcp-bus: McpCallOutcome / McpCallError + MCP_CALL_RESULT_KIND; McpCallTool sets it as ToolResult.metadata on success and on errors once server and tool are known.
- OAuth: public
OAuthBundle; OAuthFlow::refresh that re-applies the public-endpoint guard.
config_doc: parse_with (registered host fields, lenient mode) and render symmetry for allowed_tools, disallowed_tools, timeout_secs.
SecretScrubber::with_secrets for host-known secrets.
Acceptance
fmt / clippy / tests / 90% per-file coverage green; bus serde round-trips; OpenHuman and OpenCompany compile against the branch.
Summary
Let a host observe every MCP bridge call without wrapping the tool, plus small follow-ups to the host-backed OAuth flow (#39), so OpenCompany can drop its own call wrapper and OAuth port.
Scope
tinymcp-bus:McpCallOutcome/McpCallError+MCP_CALL_RESULT_KIND;McpCallToolsets it asToolResult.metadataon success and on errors once server and tool are known.OAuthBundle;OAuthFlow::refreshthat re-applies the public-endpoint guard.config_doc:parse_with(registered host fields, lenient mode) and render symmetry forallowed_tools,disallowed_tools,timeout_secs.SecretScrubber::with_secretsfor host-known secrets.Acceptance
fmt / clippy / tests / 90% per-file coverage green; bus serde round-trips; OpenHuman and OpenCompany compile against the branch.