5 October 2026
!!BREAKING CHANGES!!
Summary
AURA v0.2.18 changes how tool-name patterns and shared MCP tool names work:- Invalid patterns stop startup. AURA now checks every tool-name pattern when it loads the config. This covers
[agent].mcp_filter,[orchestration.worker.<name>].mcp_filter,[hitl].require_approval,[agent].client_tool_filter, and the keys of[mcp.servers.<name>.scratchpad]. - Some patterns match differently.
:,[abc], and{a,b}now have pattern meanings inmcp_filter,client_tool_filter, and scratchpad keys instead of matching those characters literally. Inrequire_approval,:now scopes a pattern to one MCP server. - Shared tool names resolve to one server. When multiple MCP servers advertise the same tool name, the server whose
[mcp.servers.<name>]key sorts first always provides it. - The web server connects to MCP servers before it starts accepting requests. Slow or unreachable servers lengthen startup.
Why
Before this release, the pattern fields didn’t share one syntax:mcp_filter,client_tool_filter, and scratchpad keys understood only*and?, and treated every other character literally.require_approvalaccepted[abc]and{a,b}, butmcp_filterdidn’t.- A pattern that could never match a tool name, such as one containing a space, loaded without an error. The mistake showed up only as a tool that was never selected or never gated.
- Patterns had no way to tell apart tools with the same name from different MCP servers. Which server’s tool the agent could call could change from run to run.
Patterns That Now Fail at Startup
A pattern that loaded before can now stop AURA from starting:Patterns That Now Match Differently
These patterns load without an error but select different tools than before:[hitl].require_approval already treated [abc] and {a,b} as a class and an alternation, so only the meaning of : changed there.
Shared Tool Names Resolve to One Server
AURA presents MCP tools to the model by their bare names, so only one server’s tool can hold a given name. When more than one server advertises the same tool name, the agent now always gets the tool from the server whose[mcp.servers.<name>] key sorts first. Only servers whose tool passes the agent’s or worker’s mcp_filter count. For example, [mcp.servers.alpha] wins over [mcp.servers.beta], whatever transport each server uses.
Text-fallback tool calls (fallback_tool_parsing) now resolve to the same server. Before, they could call the first server that advertised the name, even a server the agent’s mcp_filter excluded.
The web server logs a warning for each shared name at startup, and governance catalog sync logs the same warning:
mcp_filter, so an agent’s filter can select a different server than the warning names.
Web Server Startup Takes Longer
To find shared tool names, the web server now connects to each agent’s MCP servers once before it starts accepting requests. The servers are checked one at a time, and each connection can take up to[mcp].connect_timeout_secs. The check starts each stdio server’s command.
The check sends only static headers. A server that needs headers from headers_from_request logs a connection warning at startup, and the web server still starts.
Migration
To upgrade a config to AURA v0.2.18:- Check every pattern in
mcp_filter,require_approval,client_tool_filter, and scratchpad keys against Tool-Name Patterns. Fix each pattern listed in Patterns That Now Fail at Startup. - Search
mcp_filter,client_tool_filter, and scratchpad keys for:,[, and{. Confirm that the new meaning selects the tools you want. - Start the web server and look for
is advertised bywarnings in the startup log. For each shared name, confirm that the winning server is the one you want. - Optional. To use a shared tool from a server other than the winner, scope
mcp_filterto that server, for examplemcp_filter = ["other-server:*"]. You can also rename the tool on all but one server. - Check that your startup and readiness probe timeouts leave room for the MCP connection check: up to
[mcp].connect_timeout_secsfor each MCP server of each agent.
Startup Errors
An invalid pattern fails config load. The web server and CLI exit before they bind a port or open the REPL, and the error includes one of these messages. A character, construct, or: that the syntax doesn’t allow:
? or *.
