Files
ha-gronod-addons/emby-mcp/docs/ROADMAP.md
gronod d8b642436b feat: Home Assistant add-on with in-process Go REST bridge
Bake the former Python bridge.py into emby-mcp as internal/bridge.
/mcp and /call/{tool} share one process. Session init errors are
returned instead of swallowed, and 401/400/404 trigger a fresh
initialize plus retry with the caller's Authorization header.
2026-09-21 16:31:34 +00:00

48 lines
2.3 KiB
Markdown

# Roadmap
Planned and candidate features for emby-mcp. Items here are scoped ideas, not
committed designs — each still needs its own implementation plan.
## Done
- [x] Go port of the 20 Python Emby.MCP tools (parity)
- [x] Streamable-HTTP transport (`MCP_TRANSPORT=http`, endpoint `/mcp`,
per-request Emby auth: Basic / Bearer token passthrough / `X-Emby-User-Id`
disambiguation)
- [x] Docker image publishing (multi-arch, Gitea registry)
- [x] Library browse tools (`retrieve_item_children`, `retrieve_season_list`,
`retrieve_episode_list`), series discovery via `search_for_item`'s
`item_types`, and `item_type`/`series_name`/played-state fields on items
- [x] `retrieve_next_episode` (`next_unplayed`/`latest` modes; resume counts
as next)
- [x] Subtitle/audio control: `retrieve_now_playing` + `set_subtitle` /
`set_audio_track` with GeneralCommand mid-play switching and
restart-at-position fallback
## Proposed: HTTP-mode hardening / extras
- **Per-token user allowlist**: an API key can currently act as any user via
`X-Emby-User-Id`. Optional env allowlist (e.g. `MCP_ALLOWED_USERS`) if
tighter control is wanted.
- **Session-scoped token revocation**: Basic-auth Emby tokens aren't revoked
when an MCP session closes (no SDK close hook); only the 15-min credential
cache TTL does a best-effort `Logout`. Could add explicit tracking if this
matters.
- **TLS**: HTTP mode is plain HTTP; README recommends a reverse proxy. In-binary
TLS (`MCP_TLS_CERT`/`MCP_TLS_KEY`) is possible if proxy-less deploys matter.
- **Legacy SSE transport**: `mcp.SSEHandler` (2024-11-05 spec) is available in
the SDK if an SSE-only client ever needs it; deliberately omitted as
deprecated.
## Ideas / backlog (unscoped)
- Movie/music-specific list tools (`retrieve_movie_list`, artist/album browse)
- `/Items/{Id}/Similar`, `/Shows/{Id}/Similar`, `/Items/{Id}/InstantMix` —
"more like this" tools
- `retrieve_next_up` (`/Shows/NextUp`) — continue-watching list for the authed
user (series-level; `retrieve_next_episode` is the single-series variant)
- `retrieve_missing_episodes` (`/Shows/Missing`, `/Shows/Upcoming`) — gaps in a
series collection
- Watch-state tools (played/unplayed) if a write path is wanted
- Image/artwork endpoints (probably out of scope — MCP clients can't render)