{"session": "28585272-a6c8-4e89-9ca9-459772bc64e0", "env": "main-hedy-lockwell", "command": "journal helper done 4178 \"Linear's MCP entry now fetches the sign-in token (cd965de4a on helper-linear-connect)\" | head -2; journal work end 147 --how \"Agent's Linear entry fetches the journal's sign-in token; branch helper-linear-connect cd965de4a; tests extended not run\" | head -2; journal helper report \"Alfred: to-do 4178 is on branch helper-linear-connect at cd965de4a (cut from main 60b87aabbb, nothing moved since). Cause: the journal already ran Linear's browser sign-in (Log in button, localhost redirect caught, token kept as a secret) but the entry it wrote into the agent's .mcp.json held only the address, so Claude saw only 'authenticate'. Fix: after the sign-in, the entry also carries a headersHelper command (python journal.py -m mcp_headers <root> <variable>) that prints the Authorization header from the secrets file each time the agent connects, so the token is never written into the config. src/mcp_headers.py is new; serve_mcp takes the helper (Claude writes it, Codex ignores it); integrations/base.py wire_mcp passes it and log_in re-wires. Before any sign-in, with the MCP switch on, the card says: 'Your agents cannot use Linear's tools yet: press Log in on this card and approve in your browser.' Never offered a key for the MCP server (the secret route is untouched). Test: features/integrations/test.py, the existing login test extended (browser-approval notice, entry holds the command and no token, the command prints the header); no new test function, the file stays at 10. Tests written, NOT run by me. Not done: the sign-in still has no refresh token, so an expired token needs Log in again; connecting does not open the browser by itself (it would make tests and every settings write open one). Codex has no helper hook for headers here, so it still needs its own login. Also unverified: that Claude Code accepts headersHelper in .mcp.json for an http server; worth a live check.\" | head -2", "parts": ["journal helper done 4178 \"Linear's MCP entry now fetches the sign-in token (cd965de4a on helper-linear-connect)\" | head -2", "journal work end 147 --how \"Agent's Linear entry fetches the journal's sign-in token; branch helper-linear-connect cd965de4a; tests extended not run\" | head -2", "journal helper report \"Alfred: to-do 4178 is on branch helper-linear-connect at cd965de4a (cut from main 60b87aabbb, nothing moved since). Cause: the journal already ran Linear's browser sign-in (Log in button, localhost redirect caught, token kept as a secret) but the entry it wrote into the agent's .mcp.json held only the address, so Claude saw only 'authenticate'. Fix: after the sign-in, the entry also carries a headersHelper command (python journal.py -m mcp_headers <root> <variable>) that prints the Authorization header from the secrets file each time the agent connects, so the token is never written into the config. src/mcp_headers.py is new; serve_mcp takes the helper (Claude writes it, Codex ignores it); integrations/base.py wire_mcp passes it and log_in re-wires. Before any sign-in, with the MCP switch on, the card says: 'Your agents cannot use Linear's tools yet: press Log in on this card and approve in your browser.' Never offered a key for the MCP server (the secret route is untouched). Test: features/integrations/test.py, the existing login test extended (browser-approval notice, entry holds the command and no token, the command prints the header); no new test function, the file stays at 10. Tests written, NOT run by me. Not done: the sign-in still has no refresh token, so an expired token needs Log in again; connecting does not open the browser by itself (it would make tests and every settings write open one). Codex has no helper hook for headers here, so it still needs its own login. Also unverified: that Claude Code accepts headersHelper in .mcp.json for an http server; worth a live check.\" | head -2"]}