100 Commits
Author SHA1 Message Date
arc53-machine 427b83c785 Save the API write allowlist one change at a time
Two quick toggles sent overlapping saves that could land out of order, and a
failed first save put back a list without the second choice. The choices
now lock while a save is in flight.
2026-09-29 19:15:34 +01:00
arc53-machine dab5aca96e Show a connected account's login, not a key ending, on tool cards
GitHub connections made with a token are named after the GitHub login;
the card called that login a key ending.
2026-09-29 19:00:41 +01:00
arc53-machine 154d693116 Name each Customize link's tool and say when the allowlist needs a key
Each tool's Customize link is described by the tool's name. The partial
badge reads "Not all via API". When the agent has no API key yet, the
note under What this agent uses says Access Details lists the changes
once it has one.
2026-09-29 18:57:27 +01:00
arc53-machine 736564198c Bring connector comments in line with where connections are managed 2026-09-29 18:56:16 +01:00
arc53-machine 54e9e8a335 Keep the In my chats switch and sign in again from cards
Tool tiles keep the caller's own In my chats switch, with the same
visibility and revert-on-failure as before, but without the label text
beside it; screen readers still get its name. A connected tool whose
connection needs signing in again has Sign in again in its menu, and a
paused synced source has Reconnect on its tile, both for the reader's own
connection and in place where the wizard can do it.
2026-09-29 18:56:01 +01:00
arc53-machine 6728163f2b Connect a service from Add knowledge without leaving the page
Connect your data no longer closes the dialog and navigates away, which
lost an unsaved agent or chat draft. It lists the services that sync,
one per service and in the Connectors page's order (catalog helpers now
shared with that page), and picking one opens the connect wizard in
place for Knowledge, with a Back to the source types. Only the Knowledge
page adds a Browse all connectors link. The tile's description leaves
out GitHub, which has its own tile.
2026-09-29 18:54:01 +01:00
arc53-machine cdab471c22 Remove the Add knowledge forms for synced services
Nothing opens the Google Drive, SharePoint, Confluence, S3 or Reddit
forms in Add knowledge any more: those services sync through the connect
wizard. Their pickers, saved-key account logic, setup notice, advanced
fields and strings go, and the remote upload sends the form's own
fields.
2026-09-29 18:51:10 +01:00
arc53-machine 6ccc506b8c Name the services Connect your data can sync
The tile names up to three services this instance can sync (then "and
more"), rather than services it may not offer, and spans the grid's
width so its line doesn't wrap into a tall tile.
2026-09-29 18:40:19 +01:00
arc53-machine 4468e19fb8 Fit the API write allowlist on a phone
A shorter section title that fits one line, and each tool's Off / All
choice beside its name rather than wrapping under it.
2026-09-29 18:40:19 +01:00
arc53-machine bea1a4672b Offer one Connect your data tile in Add knowledge
The source picker lists what needs no account (upload, URL, crawler,
GitHub, wiki) and one tile that opens the Connectors page on the services
that sync, in place of a tile per connection under two headings. GitHub
keeps its hand-over to connecting an account for private repositories.
2026-09-29 18:34:45 +01:00
arc53-machine c356ad18a9 Drop the In my chats switch and Manage connection from cards
Tool cards no longer carry the In my chats switch; the chat's Tools
picker (and a connection's drawer) still sets it, for the same tools. The
Manage connection item goes from tool and source menus, with the
in-place connection drawer on Tools: connections are managed on the
Connectors page. The owner's connected tool keeps Share and Delete; a
teammate's still opens the tool editor.
2026-09-29 18:33:21 +01:00
arc53-machine 371e6d7a17 Say that connector Allow is for chats, not the agent's API
A connector's Allow is the in-chat permission; changes through an
agent's API, widget or public link need the agent's own allowlist. The
badge in "What this agent uses" now reads "Not via API", its note says
where Allow applies, and for the owner it opens Access details with the
allowlist unfolded. The connector permission hint says the same.
2026-09-29 18:31:41 +01:00
arc53-machine 05bdb60956 Fold the API write allowlist into one choice per tool
Access details now shows the actions API, widget and public-link users
may take as the owner as a collapsed section with a summary line (which
tools can make changes, how many of all are allowed). Open, each tool has
one Off / All choice with its actions one by one under Customize, like a
connector's permissions. Entries and saving are unchanged.
2026-09-29 18:31:36 +01:00
arc53-machine 4b08e94be7 Name every person on agent pages by one rule
people_named_to decides whom the edit page and the share dialog name:
the reader, the holder's owner, anyone sharing a team with the reader and,
for the owner, whoever sponsored something on the holder. A resource's
owner, named as whom to ask or whose credentials a tool uses, also needs
the reader to see that resource. Sponsors, runs_as, contact and account
in resource_states and sponsors in sponsor_details all follow it; anyone
else is left unnamed and the pages say someone else.

A tool's run details (note, credential_mode, account, writes) come from
one function and only for a tool that runs. The share dialog keys each
person's own account on the per_user_account note, as the notice does,
and the unused noteKey helper and its string are gone.
2026-09-29 18:12:54 +01:00
arc53-machine 3cab8af753 Keep the removed-connection note server-owned
Only removing a connection notes it on a kept tool. A config save through
update_tool or update_tool_config carries the stored note and ignores the
client's copy, so it can neither fake nor clear it; creating a tool, an
MCP server save and an agent import start without one. The note is now
written even for a connection with no catalog key, and a kept tool its
owner gave credentials of its own since runs again.
2026-09-29 18:12:54 +01:00
arc53-machine d04f76e97a Say which resources are left out of runs and which can't run until fixed 2026-09-29 17:52:12 +01:00
arc53-machine ec19dae22c Ask an item's owner without naming strangers, and keep the canvas notice reachable
When the read doesn't name whom to ask, the notice asks the item's owner
without naming them. Items the reader may not see show their kind and a
short id instead of "Unnamed item". The workflow canvas notice fits narrow
screens, and closing it leaves a chip with the number of items not running
that opens it again.
2026-09-29 17:52:02 +01:00
arc53-machine 825cf5d866 Judge only owner-mode accounts and name only people the reader knows
A member-mode tool runs on each caller's own account, so the owner's
account no longer marks it stopped: it is active with the note
per_user_account, and only an admin turning its service off stops it.
connection_removed now needs the note remove_connection leaves on a kept
tool, so a tool that never had a connection (a tokenless ntfy) runs.

Whom to ask is contact_role resource_owner; contact names them only when
the reader can see the resource or they own the holder. connection carries
its id only with can_reconnect and the account's own name only for its
owner. Run state and audience are best effort (a failure logs and leaves
them out of the read), resolve answers are cached for the rest of a read,
and a workflow read names node resources by the run state's own names.
2026-09-29 17:52:02 +01:00
arc53-machine db9eb2b1c3 Correct what the agent sharing docs say about accounts, sponsors and switches
The table adds tools with saved credentials, says API and widget users
get the owner's account on a tool each person connects, that a sponsored
item runs as the owner again once the owner can use it, and that a
teammate's name shows only to people who share a team with them. The
editor switches are named per resource type, public-link users are said
to be asked only for writes that need approval, the allowlist is said to
cover sponsored and workflow node tools, and the badge names and the new
resource_states fields match the app.
2026-09-29 17:50:42 +01:00
arc53-machine 88e715405e Label who and whose credentials each agent item runs with, and let owners allow every outside write
The share dialog's list now follows who an item runs as now (runs_as),
not a sponsor on record, and names whose saved credentials a tool
without a connection uses. A tool each person connects says API and
widget users get the owner's account, and a tool whose owner the reader
shares no team with says it's someone else's. Badges say whether all or
some of a tool's writes are off for API use, or that an admin turned
changes off. The note names only API and widget users for tools each
person connects, since public-link users use their own account there.

The API write allowlist now builds its choices from the agent's
resource_states, so it offers tools an editor sponsored and a workflow
agent's node tools as well as the owner's own; the owner's tool list only
adds action descriptions. Both read the agent through one shared hook.
2026-09-29 17:49:54 +01:00
arc53-machine 3fc55dfad8 Say who a running item runs as and whose saved credentials a tool uses
resource_states gains runs_as, the live sponsor a running item runs as
(None once the owner can use it, even with a sponsor on record), and
writes_allowed, False when an admin turned off changes through the
tool's connector (its writes are then not listed for the allowlist).
account now also names the owner of an API tool's saved key, a signed-in
MCP server or stored secrets, not only of an owner-mode connection, and
only to a reader who shares a team with that person. A running tool's
connection id is no longer sent.
2026-09-29 17:44:59 +01:00
arc53-machine da75845fcf Document sharing agents and whose access what they use runs with
A new "Sharing agents and what they use" section covers viewers and
editors, whose access each tool, source and prompt runs with as the share
dialog labels it, sponsors, stopped resources, what API, widget and
public-link users can't do without the write allowlist, the wiki switch
and research steps. The sharing rules now mention the editor switches and
member-mode tools, the guardrails page no longer says editors can't
change guardrails, the connector guide uses the new tool share labels,
and related pages link to the section.
2026-09-29 17:35:17 +01:00
arc53-machine 05bac6dc7f List what an agent uses, and whose access each runs with, in its share dialog
The agent share dialog gains a collapsed "What this agent uses" section:
each attached tool, source and prompt, and a workflow agent's node tools
and sources, with whose access it runs with (your access, a sponsor's, the
owner's, your or someone's service account, or each person's own).
Stopped items are marked with why they stopped, and the section opens by
itself when one did. Tools with writes on stored credentials that aren't
in the API write allowlist are marked, with a note that API, widget and
public-link users can't make those changes until they're allowed in
Access Details. Only owners and editors get the data it reads.

A tool's share dialog uses the same words: "Your account" or "Each
person's own", and "The owner's account" for an editor who may share it.
2026-09-29 17:33:41 +01:00
arc53-machine 1945c312dc Say whose account each running tool uses on the agent and workflow reads
resource_states now carries, for a running tool, its credential mode when
it has a connection (after any mode an admin forces), whose account an
owner-mode connection acts as, and the write actions it takes on
credentials its owner stored, which API, widget and public-link users can
run only from the agent's API write allowlist. The service of a connected
tool is named whether it runs or not. Still only for people who may edit
the agent or workflow.
2026-09-29 17:33:36 +01:00
arc53-machine 9775dd1af9 Document what happens when an agent's resource stops working 2026-09-29 17:17:13 +01:00
arc53-machine 1fed332c6a Show which of an agent's resources stopped running, with a way to fix each
The agent page shows one notice in place of the sponsored-resources one:
who added what runs with their access, and every attached tool, source or
prompt that stopped, with the reason in plain words and what the reader
can do. Reconnect signs the account in again in place, Run it with my
access now asks first in the sponsor dialog naming who reaches the agent
and is sent with the next save, Remove takes the item off the form, and
when the reader can't fix it the notice says whom to ask.

The workflow builder shows the same notice over the canvas for its node
tools and sources, with take-over sent on the next save and Remove taking
the item off every agent node.
2026-09-29 17:16:36 +01:00
arc53-machine 2359e4546b Say which attached resources stopped running and why
The agent and workflow reads now return resource_states to people who may
edit them: every attached tool, source and prompt (and workflow node tool
and source) with active or stopped and the reason: deleted,
owner_lost_access, the sponsor reasons, connection_needs_reconnect,
connection_removed or connector_disabled. Each entry names the sponsor,
someone other than the reader who can fix it, the service for a connection
reason, and whether the reader may take it over or reconnect it. When
something can be taken over, sponsor_audience says who it would reach.

The state comes from the checks the run itself uses (ref_access,
resolve_holder_tool and the tool's connection as the run resolves it), so
the page and the run can't disagree. A run that leaves a resource out logs
resource_stopped with the holder, type, id and reason.

The workflow read gives sponsor details, run state and node resource names
only to people who may edit it, and names only resources the workflow runs,
someone sponsored, or the reader can see. Owner saves and new workflows
now refuse node tools and sources the owner can't use, like editor saves.
2026-09-29 17:11:58 +01:00
arc53-machine 90b385e9ea Document taking over stopped resources and how the agent's audience can grow 2026-09-29 16:55:00 +01:00
arc53-machine ff3f367f94 Let editors take over stopped resources and remove the owner's workflow tools
The sponsored-resources notice now says why each item stopped (the person
can no longer edit the agent, or can no longer edit the item) and offers
"Run it with my access" for items the reader may sponsor; the next save
sends that confirmation. Saves go through one confirmation round trip
shared by the agent form and the workflow builder, so the details sheet
closes on a confirmed save and stays open without an error when the
editor declines. An outdated confirmation shows a translated message and
reloads the sponsor details. The tool picker forgets a removed tool's row
once the removal is saved, and workflow node pickers keep a remove-only
option for the owner's private tools and sources.
2026-09-29 16:54:06 +01:00
arc53-machine 4d001f6a20 Stop stale sponsor records from vouching for re-added resources
A resource attached in a save now ignores any sponsor recorded for it
before it was removed: the caller must be able to sponsor it and confirm.
YAML import prunes the sponsors of resources it drops, for agents and
workflow graphs. Sponsor details, with the resources' names, go only to
people who may edit the agent. The workflow read returns the names of
every node tool and source, so editors can remove the owner's private
ones. An agent image is stored only once the save is known to go ahead.
2026-09-29 16:49:51 +01:00
arc53-machine 2f6f4edac2 Note that research steps skip actions they would have to ask about 2026-09-29 16:45:55 +01:00
arc53-machine f2760a9138 Refuse gated tool calls in research steps instead of running them
Research steps ran each tool call straight through the executor, never
asking check_pause, so approval-gated actions (including a public-link
visitor's wiki edits) and an outside caller's writes on the owner's
accounts ran unchecked. A step can't pause, so it now checks each call
first and answers any pause with a refusal the model reads, journaled
like a headless denial. Headless and research runs share the journaling.
2026-09-29 16:45:55 +01:00
arc53-machine ff10fcca0f Say the wiki switch covers API keys and widgets, not public links
Public-link visitors edit only wikis they can edit themselves and approve
each edit. The docs also note that with authentication off every caller
is the owner's local user, so the switch has no effect there.
2026-09-29 16:37:58 +01:00
arc53-machine 051452c438 Hold resumed turns and public-link visitors to the right wiki rules
A paused turn is found by the agent owner's id, so anyone holding one of
the owner's agent keys could resume the owner's own chat with its saved
wiki edit rights. A resume now counts as an API or widget caller when
either the saved state or the resuming request is one, cuts the wiki tool
to wiki_view unless the wiki allows outside edits, and gives the tool
executor the same flags. A request that names an agent, by key or id, may
only resume that agent's turn; otherwise the claim is released and the
request refused.

Public-link visitors run as themselves and reach only wikis they may edit,
so the wiki switch no longer applies to them. Instead every wiki write in
a public-link run waits for the visitor's approval, so the agent owner's
prompt or sources can't steer an edit to the visitor's wiki unasked.
2026-09-29 16:37:58 +01:00
arc53-machine 91e70d2f0c Answer 404 when a wiki settings change finds no row to update 2026-09-29 16:37:58 +01:00
arc53-machine c66afd6b30 Document who may sponsor a resource in someone else's agent 2026-09-29 16:34:53 +01:00
arc53-machine b2f1742409 Confirm before an agent runs your resources, and let editors remove the owner's tools
Saving an agent or workflow that the server refuses with
sponsor_confirmation_required opens a dialog naming each tool, source or
prompt and who reaches it through the agent (its teams, API key and
widget, public link, webhook), then saves again with confirm_sponsor. A
save the caller may not sponsor shows why instead of the raw message.
The tool picker adds a remove-only row for each attached tool the editor
can't list, so the owner's private tools can be taken off the agent.
2026-09-29 16:33:50 +01:00
arc53-machine 335241e2e6 Ask before an editor's resource runs with their access in someone else's agent
Sponsoring a tool, source or prompt the agent's owner can't use now takes
owning it or having edit access to it; use access alone no longer extends it
to the agent's audience. A save that would make the caller a new sponsor is
refused with 409 sponsor_confirmation_required (the resources and the
agent's audience) until it is retried with confirm_sponsor listing them.
When a sponsor loses access, the resource stops instead of passing to
whoever saves next; another editor takes it over only by confirming.
Workflows follow the same rules. sponsor_details now reports each
sponsorship's state, the reason it stopped, and whether the reader can
take it over.
2026-09-29 16:27:54 +01:00
arc53-machine d4b30f4838 Document who can edit a wiki from the API, widget and public links 2026-09-29 16:12:42 +01:00
arc53-machine 5a78fd1fa7 Add Wiki settings for the wiki's owner
A wiki's owner gets a Wiki settings item in the source's menu. It opens a
dialog with one switch, "Let API, widget and public-link users edit this
wiki", which saves at once and flips back if the server refuses. Editors
and viewers don't get the item; anyone without manage_settings who reaches
the dialog sees the switch read-only.
2026-09-29 16:11:41 +01:00
arc53-machine 3b44b6851d Let a wiki's owner decide whether API, widget and public-link runs edit it
A run from an agent's API key or widget acts as the agent's owner, so it
could rewrite any wiki the owner can edit. A new per-wiki setting,
wiki_outside_edits (off by default), decides whether such runs, and runs
from the agent's public link, get the wiki's edit actions. While it is off
they are offered only wiki_view, and the tool refuses writes itself after
reading the live setting. The owner changes it through the owner-only
/api/sources/<id>/wiki/settings route; tokens can read it but not change it.
2026-09-29 16:07:57 +01:00
arc53-machine 33a73bc442 Note that older API-key schedules keep the old rules until they run out
Schedules an API or widget chat set before schedules recorded their
origin run as the owner's own until they fire or expire.
2026-09-29 15:55:50 +01:00
arc53-machine 41a3362431 Describe what the API write allowlist covers now
It covers writes on any credentials the owner holds, for API-key and
widget callers, public-link users and the schedules they set, not only
connected accounts reached with the API key.
2026-09-29 15:55:50 +01:00
arc53-machine 51f88144c5 Run webhooks with the owner's rules again
The owner sets a webhook up and its URL is a secret, and a webhook run
already refuses every action that needs approval, so holding it to the
API write allowlist only broke the owner's own automations. Webhook runs
no longer count as external callers; schedules keep their caller rules.
The allowlist copy no longer names webhooks.
2026-09-29 15:55:36 +01:00
arc53-machine 080b75c81e Gate an API tool action only when it sends the owner's saved values
Every API tool counted as holding the owner's credentials, so outside
callers were refused any write on one even when it sends nothing the
owner stored. Now an action counts only when its headers or query
parameters carry a saved value (sealed or legacy plaintext) or the tool
stores credentials; the allowlist lists just those writes.
2026-09-29 15:54:30 +01:00
arc53-machine 029189fe0c Set up no agent run for a request with no token or API key
The answer routes refuse such a request with 401, but only after building
the agent, so a public agent's prompt tools were pre-fetched, and their
actions run, for nobody. Anonymous chat without an agent key is not
supported, so the processor now stops before any setup and the route
answers 401 as before.
2026-09-29 15:46:32 +01:00
arc53-machine daf6af57ae Keep outside callers' write limits in scheduled and webhook runs
A scheduled or webhook run acts as the agent's owner with no one to
approve, so a public-link user or API-key caller could have the agent
schedule a write and have it run on the owner's accounts. Runs now keep
the caller's rules: a schedule set by someone who reaches the agent only
by its public link runs as a public-link caller, one set through the API
(recorded as created_via 'api', migration 0042) and every webhook run as
an external caller, each with the agent's API write allowlist.
2026-09-29 15:44:24 +01:00
arc53-machine bfa67d3138 Keep pre-fetch off live-approval tools and outside callers' owner writes
Pre-fetch judged someone else's tool by its stored approval flags, which
a remote device or the code executor decides per call, and it took a
widget or API run for the owner because the run carries the owner's id.
Those tools no longer pre-fetch for anyone but their owner, an API-key or
public-link run treats every tool as someone else's, and writes with the
owner's credentials are never pre-fetched for them.
2026-09-29 15:41:37 +01:00
arc53-machine 5c8b97b609 Gate outside writes on the owner's stored credentials, not only connections
API-key, widget and public-link callers were held to the write allowlist
only on connected accounts, so they could still write through an API
tool or a signed-in MCP server that carries the owner's credentials. Any
write on credentials the caller doesn't hold is now refused unless the
owner allowlisted it, and a scheduled run for such a caller counts as not
holding any. The tool list names these writes per tool, so the allowlist
can offer them, and its copy now names every route it covers.
2026-09-29 15:41:34 +01:00
arc53-machine 656e3abbd0 Hold /v1 key holders to the API write allowlist
The /v1 route runs with the agent owner's token, so the processor took a
key holder for the owner: writes on the owner's connected accounts ran or
waited for an approval the client could send. The route now marks the
processor as an external caller server-side, which keeps the allowlist
in force for the run and any resume, including state saved before.
2026-09-29 15:36:36 +01:00
arc53-machine 72e1dc5fc3 Read the public-link flag safely on processors built without init
Callers that build a StreamProcessor without __init__ and stub the agent
key lookup never set the flag, and configuring the agent then failed.
It now reads as not a public-link caller.
2026-09-29 15:22:29 +01:00
arc53-machine 121b6dd071 Search every agent source in scheduled and webhook runs
Headless runs searched only the agent's primary source, so an agent whose
knowledge sat in its extra sources answered a schedule or webhook without
it. They now take the primary and every extra source through the same
owner-or-sponsor check a chat uses, shared as one helper, and retrieve
through the per-source dispatcher so each source keeps its own settings.
2026-09-29 15:19:26 +01:00
arc53-machine 454557c3b0 Pre-fetch prompt tools from the agent's toolset, not the caller's
Tool pre-fetch ran the caller's own active tools, so a teammate chatting
with a shared agent had the owner's prompt fill in from their tools, and
even the owner got every active tool rather than the agent's. It now uses
the toolset the run gets: the agent's tools as its owner or sponsor, or
the caller's tools and defaults outside an agent. Pre-fetch asks nobody,
so on someone else's tool it skips approval-gated actions and anything on
a connected account.
2026-09-29 15:16:29 +01:00
arc53-machine 5b85eac858 Type the saved config in the API write allowlist test 2026-09-29 15:13:22 +01:00
arc53-machine 3dc5080058 Refuse public-link writes on the owner's account unless allowlisted
Someone who reaches an agent only through its public link was offered the
approval card for writes on the owner's connected accounts, so a stranger
could approve for the owner. Those writes are now refused with a tool
result, like an API-key caller's, unless the owner allowed the action in
the agent's Access details. Team members keep the card, and a tool on the
caller's own account (member mode) is unaffected. The flag survives a
resume, and workflow nodes now follow the run's caller rules (scheduled,
API-key and public-link) instead of starting from none.
2026-09-29 15:12:46 +01:00
arc53-machine 27495f0bc2 Follow the tool's credential mode in the share dialog once it loads
The dialog read the mode once, so opening Share before the connections
loaded showed owner mode for a member-mode tool and ignored a forced
mode.
2026-09-29 15:12:41 +01:00
arc53-machine 875118ed20 Open the connector a ?connector= link names on the mounted page
The Connectors page read ?connector= only when it mounted, so the
Reconnect link in the global toast did nothing while the page was
already open.
2026-09-29 15:12:11 +01:00
arc53-machine 4b87f97785 Apply only the latest connectors load
Overlapping loadConnectors calls applied whichever answer arrived last,
so a load started before a connect could replace the newer connection
list. The slice now records the latest request and ignores older
answers.
2026-09-29 15:11:40 +01:00
arc53-machine c958b68191 Save the API write allowlist on the saved agent config
A toggle sent the form's draft config, so unsaved guardrail edits were
saved with it, and the form then read as changed because the saved
snapshot kept the old config. The allowlist now saves on top of the last
saved config and updates that snapshot.
2026-09-29 15:11:07 +01:00
arc53-machine 26bd4e2a3f Keep the GitHub loader tests off the network
With GITHUB_ACCESS_TOKEN set in the environment, load_data checked the
repository's visibility against the real GitHub API. The tests now clear
the instance token unless they set one.
2026-09-29 15:09:50 +01:00
arc53-machine 5a503e9b3c Give workflow node tools the owner's toolset whoever runs the workflow
A node's tools resolved as the person running the workflow, so a teammate
or public-link user lost every owner tool they could not use themselves.
They now resolve as the workflow owner, then as the editor who attached
them, like an agent's own tools. The runner stays the invoker, so a
member-mode connection still uses their own account.
2026-09-29 15:09:48 +01:00
arc53-machine 23e7145cee Give a member the account they just connected
Member-mode resolution ranked accounts by last_used_at first, so a
connection added by Connect to continue (never used) lost to any older
used account. Accounts now rank by the later of last use and creation.
2026-09-29 15:09:18 +01:00
arc53-machine 259da38f17 Classify connector actions by whole name words
The read fallback matched read verbs as substrings, so update_spreadsheet,
set_budget and enlist_member ran as reads with no approval. Names are now
split into words, and any write verb makes the action a write.
2026-09-29 15:08:14 +01:00
arc53-machine a3484cb567 Use the default connector callback URL in the integration guides 2026-09-29 15:07:14 +01:00
arc53-machine 1a7921a921 Keep non-object token_info values when encrypting connector sessions
Migration 0040 dropped token_info values that were not objects before
clearing the plaintext column. Objects stored as JSON strings are now
decoded, and other values are kept in the envelope under
legacy_token_info so downgrade restores them.
2026-09-29 15:07:11 +01:00
arc53-machine 793b8cb520 Lock fixed values in the tool editor for anyone but the owner
The server now refuses a fixed value or its filled-by-AI switch from team
editors, so the editor shows them locked instead of failing the save.
2026-09-29 14:17:35 +01:00
arc53-machine b2d26c72ed Drop the sharing settings of tools deleted with their connection
Removing a connection with its tools now also deletes those tools' sharing
switches in the same transaction, as deleting a tool on its own does.
Team grants and chat preferences were already removed with the tools.
2026-09-29 14:13:35 +01:00
arc53-machine a45e369d0f Run a tool only on a connection of the connector that provides it
At run time a tool now refuses a connection whose connector does not list
the tool's type (a Telegram bot token never reaches an ntfy or MCP tool),
and an MCP tool refuses a connection when no server is known for it,
instead of sending the key without checking. Legacy MCP rows still find
their server from the stored provider value.
2026-09-29 14:13:03 +01:00
arc53-machine a777aeac45 Open a team's shared source on the Knowledge page
Also cover the owner-only API write allowlist in the agent details modal.
2026-09-29 14:12:35 +01:00
arc53-machine ca6f840fcd Group a teammate's connected tool under its service in the tool pickers
The caller's connections never include a teammate's, so a shared connected tool fell under Built in or Custom. The composer and agent pickers now rank on the tool's connection id and name the service from the catalog, or from the tool's own name when the catalog has no match.
2026-09-29 14:12:35 +01:00
arc53-machine 0eb309a592 Keep a connected tool's credentials with its owner in the UI
The server lets only the owner change the secret on a tool's connection,
so an editor no longer gets live credential fields on a connected tool:
the locked-credentials notice shows and no config is sent, so a rename
or action edit still saves. The share dialog drops the "Editors can
change credentials" switch for a connected tool, uses the matching
editor hint, and says a viewer's runs use each member's own account in
member mode.

An editor the owner lets share now sees whose account shares use,
locked, and still has to confirm before sharing a tool that can act.
The owner's Reconnect is decided by the tool's connection id, so it no
longer flashes before the connections load, and the connection panel's
tool switch is labelled "In my chats", which is what it sets.
2026-09-29 14:12:31 +01:00
arc53-machine 4f5cd68771 Keep fixed values, tool type and connected servers out of editors' tool saves
/api/update_tool now checks submitted actions against the stored ones the
same way /api/update_tool_actions does: nothing can be added, and only the
tool's owner can change a fixed value. The tool type (name) can no longer
be changed after creation by anyone.

For API tools, changing who fills an existing header, query or body
parameter, its value, or clearing a stored value is now owner-only on both
/api/update_tool and /api/update_tool_config. Before, an editor could hand
a stored secret query value to the model and read it back in the chat.
The chat now masks every value that came from the stored action rather
than from the model.

A connection-backed MCP tool can no longer be moved to another server or
sign-in method through /api/update_tool or /api/update_tool_config (400,
pointing to /api/mcp_server/save), and a new key saved through
/api/update_tool_config goes to its connection, owner only.
2026-09-29 14:11:36 +01:00
arc53-machine a1789d2ab4 Merge main (roles and access revamp) into connectors
Main's access model (team editors and viewers, edit_credentials, owner-only
OAuth servers, per-user tool preferences, resource sponsors) now applies to
connection-backed tools and sources. Our migrations are renumbered to
0040_connections and 0041_connection_account_name, after main's
0038_resource_access_settings and 0039_resource_sponsors.

Where the two sides met: MCP tools save and load their connections as the
tool owner, editors may add a key (a new connection on the owner's account)
but never rewrite an existing connection's secret, fixed values stay
owner-only, and a member's own connection is used in member mode.
2026-09-29 14:02:26 +01:00
arc53-machine 7daa3eb972 Show Linear's tools and the Knowledge choice on one screen after signing in
An MCP preset that also syncs asked about Knowledge first and showed its
tools on a separate summary. After signing in it now shows the tools and
their permissions, then Sync into Knowledge underneath; Done or Add to
Knowledge closes the wizard, with a toast saying what syncs.
2026-09-29 13:32:12 +01:00
arc53-machine 85175fa8c1 Drop the owner-account warning box when sharing a tool
A tool that can act already asks the owner to confirm; one that only reads
names whose account members use in a plain line.
2026-09-29 13:13:27 +01:00
arc53-machine 56ababae71 Stop a removed MCP connection from saving its server as a custom tool
After removing a Linear connection, connecting again could skip signing in
and save Linear as an unconnected custom tool: a client cached before the
removal still held the old tokens, and a late token write re-created a
connection for them. A token write for a named connection no longer creates
one, removing or disconnecting a connection drops its cached clients, and a
sign-in server is never saved without its connection.
2026-09-29 13:13:27 +01:00
arc53-machine 159ac03904 Let FastEmbed download a model when completing its cache fails
Completing a partial snapshot is best effort; a network error or rate limit
there is logged and FastEmbed still tries its own sources.
2026-09-29 12:36:57 +01:00
arc53-machine f6f9ae670c Document the Sync into Knowledge choice when connecting 2026-09-29 12:17:33 +01:00
arc53-machine 18cc6443fc Ask before syncing into Knowledge when connecting a service
A first connect of a service that can sync now asks with a Sync into
Knowledge switch. It starts off from the Connectors page, Add tool and
the chat, and on when the wizard opens for Knowledge: the Add knowledge
tiles and the Connectors page listed for syncing. Off, the account is
still connected and the summary says where to sync later. On, the
picker, name and frequency show with collapsed Advanced retrieval
settings, sent with the sync; an incoherent prescreen blocks it as in
Upload. Sync more and reconnect are unchanged.
2026-09-29 12:17:33 +01:00
arc53-machine 54ba7c7b9b Apply retrieval settings to a source synced from the connect wizard
The connection setup endpoint takes sync.config, validated like an
upload's config, and passes it to the ingest task so the synced source
gets the chosen chunking and retrieval settings. An invalid config is
refused before the idempotency key is claimed.
2026-09-29 12:17:33 +01:00
arc53-machine f2349edb4c Keep a Linear sync going when one issue or document cannot be read
An issue deleted after it was listed, or comments the token cannot read,
now lose that detail with a warning instead of failing the whole sync; an
unreadable document is skipped.
2026-09-29 12:14:10 +01:00
arc53-machine 06de211e61 Download an embedding model whose cached snapshot lacks its graph
The chunker caches only a model's tokenizer.json in the embeddings cache.
FastEmbed counts any cached snapshot as the model, so it never downloaded
the ONNX graph and every load failed with NO_SUCHFILE. The loader now
checks the files FastEmbed needs and fetches them first when they are
missing; offline it leaves them for FastEmbed to report.
2026-09-29 12:12:28 +01:00
arc53-machine 39063d5e41 Mark fixed values in the chat instead of showing them, and keep them on reload
A value the owner fixed may be a secret, and tool-call events reach whoever
runs the agent, so query and body values the owner fixed now show as
(fixed); a value the connection sets, like Telegram's default chat, still
shows. sent_arguments is saved with the conversation, so a reopened chat
shows the same arguments as the live one.
2026-09-29 12:09:13 +01:00
arc53-machine 01caae80ad Show one account at a time on a connector's page
With several accounts of a service, a dropdown picks the one shown along
with its knowledge and tools, instead of listing every account. The page
opens on the account behind the tool it was opened from, else one that
needs signing in again.
2026-09-29 12:07:47 +01:00
arc53-machine e29ea53837 Choose whose account a shared tool uses with a compact switch
The two large picker tiles become a small My account / Each member's own
switch; the line under it still says what the choice means.
2026-09-29 12:05:35 +01:00
arc53-machine 301a59ef51 Open Sync more for an MCP preset at choosing what to sync
The launcher passed only reconnect through for MCP presets, so Sync more
on a Linear account asked to sign in again instead of showing its teams.
2026-09-29 11:38:27 +01:00
arc53-machine 5d7502631f Document syncing Linear into Knowledge 2026-09-29 11:32:40 +01:00
arc53-machine 2168b2188b Pick Linear teams and projects to sync after signing in to Linear
Signing in to Linear now goes on to choosing what to sync, as the
drawer's Sync more does: teams and projects to pick, whether to bring
comments (on) and the picked projects' documents. The tools still come
with the sign-in, and Skip keeps only them. A source is named after what
it syncs until the name is edited. Signing in again goes straight to the
summary.
2026-09-29 11:32:40 +01:00
arc53-machine 03d1b10897 Sync Linear issues and documents into Knowledge with the Linear sign-in
The Linear connector now syncs as well as giving agents its tools, from
one connection. Linear's MCP server is its own OAuth issuer, so its
tokens are read through the same MCP tools the agents use (list_issues,
get_issue, list_comments, list_documents) rather than Linear's GraphQL
API, and no OAuth app has to be registered.

A source picks teams and projects, with comments (on by default) and the
projects' documents. Each issue becomes one document with its state,
assignee, priority, labels, description and comments, filed under its
team and citing its Linear URL. Each sync reads up to 500 issues and 100
documents again. /api/connections/<id>/linear lists the teams and
projects to pick from. Sources sync on their schedule with the owner's
connection, and pause when the sign-in needs reconnecting.
2026-09-29 11:32:40 +01:00
arc53-machine 805e65eeb4 Call an MCP server's tools from the server with a connection's sign-in
run_connection_session opens one MCP session signed in with an MCP OAuth
connection's stored tokens and runs a batch of tool calls in it, so a
sync makes hundreds of calls over one sign-in. The tokens only go to the
server the connection signed in to. A sign-in that expired and cannot be
renewed flags the connection for reconnecting, which pauses its sources;
network trouble and rate limits are reported as worth retrying.
2026-09-29 11:32:40 +01:00
arc53-machine 6eda4a6738 Renew a stored MCP sign-in once its access token expires
The MCP SDK knows a token's expiry only when it obtained the token in the
same process. A worker or a restarted API loading tokens from the
connection sent an expired one, got a 401 and asked the owner to sign in
again. The expiry is now saved with the tokens and handed back to the SDK,
which then renews the token with its refresh token first; a token saved
before expiries were kept is renewed once. A sign-in that cannot be
renewed raises MCPReauthorizationRequired.
2026-09-29 11:32:21 +01:00
arc53-machine bcfa8b349b Document GitHub write access and the permissions it needs
Explains the opt-in switch, the full endpoint it uses, how write actions
default to asking first, the admin's Write access switch, and which
fine-grained token or GitHub App permissions changes need.
2026-09-29 11:22:01 +01:00
arc53-machine 34dc74c0ad Offer GitHub write tools in the connect wizard, drawer and admin page
The GitHub tools step gets a second switch under Let agents use GitHub:
Also let agents make changes (issues, comments, pull requests), off by
default. A connection's page has the same switch on its GitHub tool, which
re-reads the tool's actions from the other endpoint. Both are hidden when
an admin turns changes off in the new Write access section of
Admin > Connectors. The token hint and the GitHub App setup note name the
permissions changes need.
2026-09-29 11:22:01 +01:00
arc53-machine 12ad4f5e85 Let a GitHub connection opt into write tools
A GitHub connection's MCP tool can now point at GitHub's full endpoint
(/mcp/) instead of the read-only one when its owner opts in, at setup
(allow_writes) or later (PUT /api/connections/<id>/writes), which re-reads
the actions and keeps the choices for those on both endpoints. Actions from
the write endpoint are writes unless GitHub marks them read-only, so they
default to asking first.

Admins can forbid it per connector (allow_writes in Admin > Connectors,
kept in app_metadata). Then the option is refused, a refresh goes back to
read-only, and at run time the tool only ever calls the read-only endpoint
and write calls are denied with a reason.
2026-09-29 11:22:01 +01:00
arc53-machine dba2de590b Show the arguments a tool call sends, fixed values included
The approval card and a finished call showed what the model asked for,
even where a fixed value replaced it. Calls now carry sent_arguments for
the chat, leaving headers out since they may hold a fixed secret. The
model's own arguments are kept as they were, because they are what later
turns replay to it and it never sees fixed values.
2026-09-29 11:08:50 +01:00
arc53-machine 52217d43be Keep a connected tool card's title to the service name
The server adds the account to a tool's name so pickers can tell accounts
apart; the card names the account on its own line already.
2026-09-29 10:49:48 +01:00
arc53-machine db63eae93f Name a connected tool's account by the name its owner gave it 2026-09-29 10:47:02 +01:00
arc53-machine bdc453eaab Show the model an account only where it tells tools apart
Actions that different services share are described with the service
alone; the account is named only when one service is connected twice.
2026-09-29 10:42:03 +01:00
arc53-machine e0e83b5492 Document account names, fixed values and the Telegram default chat 2026-09-29 10:42:03 +01:00
arc53-machine d633560d7a Name accounts in the connect wizard and rename them in the drawer
The connect wizard asks for an optional account name (keys and sign-ins
alike) and sets it once the account exists. In the connector drawer a
named account shows its name with the account under it, and Rename in
the account menu changes or clears the name.
2026-09-29 10:42:03 +01:00