What does echoVic/orca-agent v0.5.6 add for MCP?

echoVic/orca-agent v0.5.6 adds CLI MCP management, streamable HTTP, parallel startup, OAuth, and read-only tool approval.

echoVic/orca-agent v0.5.6, published on 2026-10-05, introduces a dedicated orca mcp command suite to configure, inspect, authenticate, and remove Model Context Protocol (MCP) servers without editing configuration files by hand. The release switches remote MCP connections to streamable HTTP with legacy Server-Sent Events (SSE) fallback, connects servers asynchronously in parallel at startup, and executes read-only tools without approval prompts in suggest mode. This is the echoVic/orca-agent project, unrelated to stablyai/orca, the separate AI orchestrator repository.

Key facts

  • echoVic/orca-agent v0.5.6 was published under tag v0.5.6 at 2026-10-05T04:41:55Z.
  • The update adds six CLI subcommands: orca mcp add, list, get, remove, login, and logout.
  • Remote connections default to streamable HTTP (transport = "http") and fall back to legacy 2024-11-05 HTTP+SSE on HTTP 400, 404, or 405 responses.
  • The TUI connects configured MCP servers in parallel in the background as soon as it opens, instead of waiting sequentially on the first message.
  • Tools annotated by servers with readOnlyHint: true run without approval prompts in suggest mode and execute in plan mode.
  • Remote servers returning HTTP 401 without static tokens trigger OAuth 2.1 with PKCE, saving tokens to ~/.orca/mcp-credentials.json with 0600 file permissions.
  • Concurrent writes to ~/.orca/config.toml acquire an advisory lock on config.toml.lock to prevent multi-process data loss.
  • Installations update via npm install -g @blade-ai/orca@0.5.6.

Orca 0.5.6 command-line MCP management

Before version 0.5.6, configuring MCP servers in Orca required manually editing TOML tables inside ~/.orca/config.toml. Version 0.5.6 introduces the orca mcp command group to manage server definitions from the terminal:

orca mcp add docs -- npx -y @acme/docs-mcp        # local (stdio)
orca mcp add tracker --url https://mcp.example.com/mcp
orca mcp list
orca mcp login tracker

The CLI suite provides six subcommands:

Subcommand

Syntax

Purpose

orca mcp add

orca mcp add <name> [flags] [-- <cmd>...]

Appends a stdio or remote MCP server to config.toml

orca mcp list

orca mcp list [--json]

Lists configured servers and auth states without printing secrets

orca mcp get

orca mcp get <name> [--json]

Displays detailed server settings and tool filters

orca mcp remove

orca mcp remove <name>

Deletes the server configuration and purges stored OAuth tokens

orca mcp login

orca mcp login <name>

Initiates OAuth 2.1 browser authentication for remote servers

orca mcp logout

orca mcp logout <name>

Deletes saved OAuth credentials for the specified server

orca mcp add writes server entries to ~/.orca/config.toml using toml_edit to preserve existing comments. Stdio processes accept -e KEY=VALUE environment flags, while remote servers accept --url, --transport http|sse, --header "Name: value", --bearer-token-env-var NAME, --client-id ID, and --callback-port PORT. Server names allow alphanumeric characters, hyphens, and underscores, but reject double underscores (__) and names that collide after lowercase normalization (such as GitHub and github).

orca mcp list and get accept --json and show auth status without exposing environment values, headers, or tokens. orca mcp remove <name> deletes the server block and its stored credentials.

Streamable HTTP transport and OAuth 2.1 in Orca 0.5.6

Orca 0.5.6 makes streamable HTTP the default transport (transport = "http"). Requests include Accept: application/json, text/event-stream and MCP-Protocol-Version headers, tracking session state via Mcp-Session-Id. If an HTTP session expires and returns 404, Orca reinitializes the session once and retries the request.

With transport = "sse", Orca tries streamable HTTP first, falling back to legacy 2024-11-05 HTTP+SSE only if the server returns status 400, 404, or 405. Orca announces protocol version 2025-06-18 during initialization and accepts 2025-06-18, 2025-03-26, and 2024-11-05. List requests (tools/list, prompts/list, resources/list, resources/templates/list) follow nextCursor up to 100 pages. Orca also replies to incoming ping calls and returns JSON-RPC error -32601 for unhandled methods.

Authentication covers two workflows:

  1. Bearer tokens via environment variables: --bearer-token-env-var NAME transmits Authorization: Bearer <value> at runtime without writing tokens to disk.
  2. OAuth 2.1 with PKCE: When a remote server returns HTTP 401 without static credentials, Orca initiates OAuth 2.1 with PKCE. orca mcp login <name> (or l in /mcp) opens the system browser with a loopback callback on http://127.0.0.1:<port>/callback. Tokens are saved in ~/.orca/mcp-credentials.json with 0600 permissions and refreshed automatically. Users can cancel pending logins with l or Ctrl+C.

Parallel MCP startup and tool approval rules in Orca 0.5.6

In earlier versions, Orca connected MCP servers sequentially after the user submitted their first prompt. In version 0.5.6, the TUI connects all configured servers in parallel in the background when it opens.

Before the first prompt is sent, /mcp shows live connection states: starting, connected, failed, needs login, or disabled. Conversational turns wait only for servers still actively connecting, bounded by startup_timeout_ms (30 seconds default), and Esc interrupts the wait.

Permissions and tool interactions also receive several updates:

  • Read-only hints: Tools annotated with readOnlyHint: true (without destructiveHint: true) run without approval prompts in suggest mode and execute in plan mode.
  • Persistent approvals: The approval panel adds option 5 (always allow this tool) and option 6 (always allow this server), saving allow rules to configuration.
  • Pattern-less permission rules: Rules under [[permissions.rules]] can omit pattern to match every invocation of a tool or match whole servers using mcp__<server> or mcp__<server>__*.
  • MCP prompts as slash commands: Server prompts appear in the command menu as /mcp__<server>__<prompt> args. Esc cancels an unanswered prompt before execution.
  • Multimodal responses: deepseek-flash and auto accept image outputs from MCP tools (PNG, JPEG, GIF, WebP up to 5 MiB per image, up to 16 MiB per response, up to 3 newest images per request).

Breaking changes and configuration compatibility in Orca 0.5.6

Orca 0.5.6 modifies persisted session and configuration formats. Sessions or configurations written by version 0.5.6 containing MCP server entries, pattern-less rules, or transport = "http" cannot be read by Orca 0.5.5 or earlier. Version 0.5.6 continues to parse older configurations and sessions.

In unreviewed folders, workspace review takes precedence across direct prompts (orca "<prompt>"), --continue, and --resume before prompts run or MCP servers connect. Syntax or encoding errors in ~/.orca/config.toml emit terminal warnings specifying line and column numbers rather than failing silently, while keeping parsed values redacted.

Sources

Last verified: 2026-10-06.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.