A Next.js web application for image generation and editing using AI models. Supports text-to-image and image-editing modes with authentication, usage tracking, and persistent generation history.
This is a Next.js backend application, not an MCP server. The codebase exposes HTTP API routes (app/api/*), not MCP tools. Tool definitions provided are inferred from route handlers and TypeScript parameter documentation, not from explicit MCP tool registration. No MCP protocol implementation is visible in the provided source. Tool descriptions are present but range from adequate to verbose (50-400 chars). Input schemas are partially visible through TypeScript types but lack formal JSON Schema definitions with explicit type declarations in the tool registration layer. Parameters generally have descriptions, but several lack type constraints or enum definitions. Output schemas are not documented. Error handling is HTTP-status-based, not MCP-style recovery guidance.
Initiates OAuth 2.0 authentication flow via Vercel OAuth provider with PKCE. Generates and stores state, code verifier, and nonce in HTTP-only cookies. Returns authorization URL redirect.
Cancels an in-progress image generation workflow by run ID. Returns success regardless of workflow state (already completed or already cancelled workflows do not cause errors).
Debug endpoint for testing token refresh behavior. Supports three test steps: view current session state, poison session to simulate expired token, and verify middleware refreshed the token. Used for validating OAuth token refresh mechanisms.
Deletes a single generation record from the user's history. Requires user ownership verification via email.
Generates images from text prompts with optional image inputs for editing. Supports multiple AI models (nb2, pro), thinking levels (minimal, standard, extended), resolutions (1K, 2K, 4K), and aspect ratios. Handles authentication, usage limits, and image format validation.
Returns the currently authenticated user's profile information (email, name, picture) from the session. Does not check token expiration as refresh is handled by middleware.
This is not an MCP server implementation. The codebase is a Next.js web application with HTTP API routes, not an MCP protocol server. No MCP-compliant tool registration, schema definitions, or protocol implementation is present in the source.
Tool definitions are inferred from TypeScript parameter annotations and route handlers, not explicitly registered via MCP. Per hard scoring rules, inferred tool definitions must be capped at 50 overall.
Input schemas lack formal JSON Schema definitions with explicit 'type' and 'required' fields. Schemas are inferred from TypeScript type annotations but not formalized in the tool definitions. generate_image accepts both file and URL uploads but does not use discriminated unions or oneOf to clarify mutual exclusivity.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 33 | 2026-07-28+ | v2 |
Retrieves aggregate statistics about image generations across all users, including median generation duration and sample count. Cached for performance.
Retrieves the current status of an image generation workflow. Returns completion status with results, failure status with errors, or running status with start time for progress tracking.
Combined initialization endpoint returning user authentication status and usage limits in a single request. Returns user profile (if logged in), usage remaining/reset time for anonymous users, and server configuration status.
Fetches paginated list of the authenticated user's saved image generations from history. Returns generations with pagination metadata.
Handles OAuth 2.0 callback after user authorization. Exchanges authorization code for tokens, verifies state/nonce, decodes JWT, creates/updates user in database, and establishes session via iron-session encrypted cookie.
Saves a completed image generation to the user's persistent history in the database. Stores generation metadata including prompt, model, settings, and output image URL. Requires authentication.
Signs out the authenticated user by clearing the encrypted session cookie and user cookie. Supports both POST and GET methods. Clears all authentication state.
No output schemas are documented. Tools like get_user_generations, get_generation_stats, and get_current_user lack documented return types. LLMs cannot plan downstream calls or extract typed fields without this information.
Parameters lack enum constraints. 'mode' in generate_image should be constrained to ['text-to-image', 'image-editing']; 'selectedModel' to ['nb2', 'pro']; 'thinkingLevel' to ['minimal', 'standard', 'extended']; 'resolution' to ['1K', '2K', '4K']. Free-form strings invite hallucinated values.
Error handling does not provide recovery guidance. HTTP error responses (e.g., 400, 401, 500) do not indicate whether the error is retryable, user-fixable, or fatal. LLMs cannot determine next steps.
Irreversible operations (delete_generation, sign_out_user, cancel_generation) lack confirmation or dry-run support. An agent may accidentally delete user data or cancel in-progress work without user approval.
Authentication state is managed via HTTP cookies and sessions, not MCP-compatible token passing. Tools like authenticate_oauth and handle_oauth_callback assume browser-based OAuth flow; incompatible with agent-to-server MCP usage.
Pagination in get_user_generations uses offset/limit but does not document max limit, total count, or next_cursor. The description states 'max 50' but provides no guidance on handling large result sets or iteration patterns.
Parameter descriptions are inconsistent in detail. Some (e.g., generate_image's 'prompt') provide character limits; others (e.g., 'reauth' in authenticate_oauth) lack context on when to use. Consistency and actionability vary across the 13 tools.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) are present. Agents cannot distinguish safe (read-only) operations from risky (destructive) ones without explicit marking.
debug_session_refresh is a debug endpoint that should not be exposed to agents in production. Tools like this undermine security and signal incomplete production hardening.