echoVic/orca-agent v0.5.6, published on 2026-10-05, introduces a dedicated orca mcp command suite to configure, inspect, authenticate, and remove Model Context Protocol (MCP) servers without editing configuration files by hand. The release switches remote MCP connections to streamable HTTP with legacy Server-Sent Events (SSE) fallback, connects servers asynchronously in parallel at startup, and executes read-only tools without approval prompts in suggest mode. This is the echoVic/orca-agent project, unrelated to stablyai/orca, the separate AI orchestrator repository.
Key facts
- echoVic/orca-agent v0.5.6 was published under tag
v0.5.6at 2026-10-05T04:41:55Z. - The update adds six CLI subcommands:
orca mcp add,list,get,remove,login, andlogout. - Remote connections default to streamable HTTP (
transport = "http") and fall back to legacy 2024-11-05 HTTP+SSE on HTTP 400, 404, or 405 responses. - The TUI connects configured MCP servers in parallel in the background as soon as it opens, instead of waiting sequentially on the first message.
- Tools annotated by servers with
readOnlyHint: truerun without approval prompts in suggest mode and execute in plan mode. - Remote servers returning HTTP 401 without static tokens trigger OAuth 2.1 with PKCE, saving tokens to
~/.orca/mcp-credentials.jsonwith 0600 file permissions. - Concurrent writes to
~/.orca/config.tomlacquire an advisory lock onconfig.toml.lockto prevent multi-process data loss. - Installations update via
npm install -g @blade-ai/orca@0.5.6.
Orca 0.5.6 command-line MCP management
Before version 0.5.6, configuring MCP servers in Orca required manually editing TOML tables inside ~/.orca/config.toml. Version 0.5.6 introduces the orca mcp command group to manage server definitions from the terminal:
orca mcp add docs -- npx -y @acme/docs-mcp # local (stdio)
orca mcp add tracker --url https://mcp.example.com/mcp
orca mcp list
orca mcp login trackerThe CLI suite provides six subcommands:
Subcommand | Syntax | Purpose |
|---|---|---|
|
| Appends a stdio or remote MCP server to |
|
| Lists configured servers and auth states without printing secrets |
|
| Displays detailed server settings and tool filters |
|
| Deletes the server configuration and purges stored OAuth tokens |
|
| Initiates OAuth 2.1 browser authentication for remote servers |
|
| Deletes saved OAuth credentials for the specified server |
orca mcp add writes server entries to ~/.orca/config.toml using toml_edit to preserve existing comments. Stdio processes accept -e KEY=VALUE environment flags, while remote servers accept --url, --transport http|sse, --header "Name: value", --bearer-token-env-var NAME, --client-id ID, and --callback-port PORT. Server names allow alphanumeric characters, hyphens, and underscores, but reject double underscores (__) and names that collide after lowercase normalization (such as GitHub and github).
orca mcp list and get accept --json and show auth status without exposing environment values, headers, or tokens. orca mcp remove <name> deletes the server block and its stored credentials.
Streamable HTTP transport and OAuth 2.1 in Orca 0.5.6
Orca 0.5.6 makes streamable HTTP the default transport (transport = "http"). Requests include Accept: application/json, text/event-stream and MCP-Protocol-Version headers, tracking session state via Mcp-Session-Id. If an HTTP session expires and returns 404, Orca reinitializes the session once and retries the request.
With transport = "sse", Orca tries streamable HTTP first, falling back to legacy 2024-11-05 HTTP+SSE only if the server returns status 400, 404, or 405. Orca announces protocol version 2025-06-18 during initialization and accepts 2025-06-18, 2025-03-26, and 2024-11-05. List requests (tools/list, prompts/list, resources/list, resources/templates/list) follow nextCursor up to 100 pages. Orca also replies to incoming ping calls and returns JSON-RPC error -32601 for unhandled methods.
Authentication covers two workflows:
- Bearer tokens via environment variables:
--bearer-token-env-var NAMEtransmitsAuthorization: Bearer <value>at runtime without writing tokens to disk. - OAuth 2.1 with PKCE: When a remote server returns HTTP 401 without static credentials, Orca initiates OAuth 2.1 with PKCE.
orca mcp login <name>(orlin/mcp) opens the system browser with a loopback callback onhttp://127.0.0.1:<port>/callback. Tokens are saved in~/.orca/mcp-credentials.jsonwith0600permissions and refreshed automatically. Users can cancel pending logins withlor Ctrl+C.
Parallel MCP startup and tool approval rules in Orca 0.5.6
In earlier versions, Orca connected MCP servers sequentially after the user submitted their first prompt. In version 0.5.6, the TUI connects all configured servers in parallel in the background when it opens.
Before the first prompt is sent, /mcp shows live connection states: starting, connected, failed, needs login, or disabled. Conversational turns wait only for servers still actively connecting, bounded by startup_timeout_ms (30 seconds default), and Esc interrupts the wait.
Permissions and tool interactions also receive several updates:
- Read-only hints: Tools annotated with
readOnlyHint: true(withoutdestructiveHint: true) run without approval prompts in suggest mode and execute in plan mode. - Persistent approvals: The approval panel adds option
5(always allow this tool) and option6(always allow this server), saving allow rules to configuration. - Pattern-less permission rules: Rules under
[[permissions.rules]]can omitpatternto match every invocation of a tool or match whole servers usingmcp__<server>ormcp__<server>__*. - MCP prompts as slash commands: Server prompts appear in the command menu as
/mcp__<server>__<prompt> args.Esccancels an unanswered prompt before execution. - Multimodal responses:
deepseek-flashandautoaccept image outputs from MCP tools (PNG, JPEG, GIF, WebP up to 5 MiB per image, up to 16 MiB per response, up to 3 newest images per request).
Breaking changes and configuration compatibility in Orca 0.5.6
Orca 0.5.6 modifies persisted session and configuration formats. Sessions or configurations written by version 0.5.6 containing MCP server entries, pattern-less rules, or transport = "http" cannot be read by Orca 0.5.5 or earlier. Version 0.5.6 continues to parse older configurations and sessions.
In unreviewed folders, workspace review takes precedence across direct prompts (orca "<prompt>"), --continue, and --resume before prompts run or MCP servers connect. Syntax or encoding errors in ~/.orca/config.toml emit terminal warnings specifying line and column numbers rather than failing silently, while keeping parsed values redacted.
Sources
- Release Orca v0.5.6: https://github.com/echoVic/orca-agent/releases/tag/v0.5.6 (read 2026-10-06)
- GitHub API v0.5.6 release metadata: https://api.github.com/repos/echoVic/orca-agent/releases/tags/v0.5.6 (read 2026-10-06)
- Orca changelog: https://orcaagent.dev/changelog/ (read 2026-10-06)
- echoVic/orca-agent README: https://raw.githubusercontent.com/echoVic/orca-agent/main/README.md (read 2026-10-06)
- Separate stablyai/orca repository: https://github.com/stablyai/orca (read 2026-10-06)
Last verified: 2026-10-06.