Commit Graph
5745 Commits
Author SHA1 Message Date
arc53-machine 39063d5e41 Mark fixed values in the chat instead of showing them, and keep them on reload
A value the owner fixed may be a secret, and tool-call events reach whoever
runs the agent, so query and body values the owner fixed now show as
(fixed); a value the connection sets, like Telegram's default chat, still
shows. sent_arguments is saved with the conversation, so a reopened chat
shows the same arguments as the live one.
2026-09-29 12:09:13 +01:00
arc53-machine 01caae80ad Show one account at a time on a connector's page
With several accounts of a service, a dropdown picks the one shown along
with its knowledge and tools, instead of listing every account. The page
opens on the account behind the tool it was opened from, else one that
needs signing in again.
2026-09-29 12:07:47 +01:00
arc53-machine e29ea53837 Choose whose account a shared tool uses with a compact switch
The two large picker tiles become a small My account / Each member's own
switch; the line under it still says what the choice means.
2026-09-29 12:05:35 +01:00
arc53-machine 301a59ef51 Open Sync more for an MCP preset at choosing what to sync
The launcher passed only reconnect through for MCP presets, so Sync more
on a Linear account asked to sign in again instead of showing its teams.
2026-09-29 11:38:27 +01:00
arc53-machine 5d7502631f Document syncing Linear into Knowledge 2026-09-29 11:32:40 +01:00
arc53-machine 2168b2188b Pick Linear teams and projects to sync after signing in to Linear
Signing in to Linear now goes on to choosing what to sync, as the
drawer's Sync more does: teams and projects to pick, whether to bring
comments (on) and the picked projects' documents. The tools still come
with the sign-in, and Skip keeps only them. A source is named after what
it syncs until the name is edited. Signing in again goes straight to the
summary.
2026-09-29 11:32:40 +01:00
arc53-machine 03d1b10897 Sync Linear issues and documents into Knowledge with the Linear sign-in
The Linear connector now syncs as well as giving agents its tools, from
one connection. Linear's MCP server is its own OAuth issuer, so its
tokens are read through the same MCP tools the agents use (list_issues,
get_issue, list_comments, list_documents) rather than Linear's GraphQL
API, and no OAuth app has to be registered.

A source picks teams and projects, with comments (on by default) and the
projects' documents. Each issue becomes one document with its state,
assignee, priority, labels, description and comments, filed under its
team and citing its Linear URL. Each sync reads up to 500 issues and 100
documents again. /api/connections/<id>/linear lists the teams and
projects to pick from. Sources sync on their schedule with the owner's
connection, and pause when the sign-in needs reconnecting.
2026-09-29 11:32:40 +01:00
arc53-machine 805e65eeb4 Call an MCP server's tools from the server with a connection's sign-in
run_connection_session opens one MCP session signed in with an MCP OAuth
connection's stored tokens and runs a batch of tool calls in it, so a
sync makes hundreds of calls over one sign-in. The tokens only go to the
server the connection signed in to. A sign-in that expired and cannot be
renewed flags the connection for reconnecting, which pauses its sources;
network trouble and rate limits are reported as worth retrying.
2026-09-29 11:32:40 +01:00
arc53-machine 6eda4a6738 Renew a stored MCP sign-in once its access token expires
The MCP SDK knows a token's expiry only when it obtained the token in the
same process. A worker or a restarted API loading tokens from the
connection sent an expired one, got a 401 and asked the owner to sign in
again. The expiry is now saved with the tokens and handed back to the SDK,
which then renews the token with its refresh token first; a token saved
before expiries were kept is renewed once. A sign-in that cannot be
renewed raises MCPReauthorizationRequired.
2026-09-29 11:32:21 +01:00
arc53-machine bcfa8b349b Document GitHub write access and the permissions it needs
Explains the opt-in switch, the full endpoint it uses, how write actions
default to asking first, the admin's Write access switch, and which
fine-grained token or GitHub App permissions changes need.
2026-09-29 11:22:01 +01:00
arc53-machine 34dc74c0ad Offer GitHub write tools in the connect wizard, drawer and admin page
The GitHub tools step gets a second switch under Let agents use GitHub:
Also let agents make changes (issues, comments, pull requests), off by
default. A connection's page has the same switch on its GitHub tool, which
re-reads the tool's actions from the other endpoint. Both are hidden when
an admin turns changes off in the new Write access section of
Admin > Connectors. The token hint and the GitHub App setup note name the
permissions changes need.
2026-09-29 11:22:01 +01:00
arc53-machine 12ad4f5e85 Let a GitHub connection opt into write tools
A GitHub connection's MCP tool can now point at GitHub's full endpoint
(/mcp/) instead of the read-only one when its owner opts in, at setup
(allow_writes) or later (PUT /api/connections/<id>/writes), which re-reads
the actions and keeps the choices for those on both endpoints. Actions from
the write endpoint are writes unless GitHub marks them read-only, so they
default to asking first.

Admins can forbid it per connector (allow_writes in Admin > Connectors,
kept in app_metadata). Then the option is refused, a refresh goes back to
read-only, and at run time the tool only ever calls the read-only endpoint
and write calls are denied with a reason.
2026-09-29 11:22:01 +01:00
arc53-machine dba2de590b Show the arguments a tool call sends, fixed values included
The approval card and a finished call showed what the model asked for,
even where a fixed value replaced it. Calls now carry sent_arguments for
the chat, leaving headers out since they may hold a fixed secret. The
model's own arguments are kept as they were, because they are what later
turns replay to it and it never sees fixed values.
2026-09-29 11:08:50 +01:00
arc53-machine 52217d43be Keep a connected tool card's title to the service name
The server adds the account to a tool's name so pickers can tell accounts
apart; the card names the account on its own line already.
2026-09-29 10:49:48 +01:00
arc53-machine db63eae93f Name a connected tool's account by the name its owner gave it 2026-09-29 10:47:02 +01:00
arc53-machine bdc453eaab Show the model an account only where it tells tools apart
Actions that different services share are described with the service
alone; the account is named only when one service is connected twice.
2026-09-29 10:42:03 +01:00
arc53-machine e0e83b5492 Document account names, fixed values and the Telegram default chat 2026-09-29 10:42:03 +01:00
arc53-machine d633560d7a Name accounts in the connect wizard and rename them in the drawer
The connect wizard asks for an optional account name (keys and sign-ins
alike) and sets it once the account exists. In the connector drawer a
named account shows its name with the account under it, and Rename in
the account menu changes or clears the name.
2026-09-29 10:42:03 +01:00
arc53-machine bdcb88866a Let people name accounts and use the names to tell accounts apart
Connections get an account_name (migration 0039) that the owner sets with
PATCH /api/connections/<id>; the account label stays the account's
identity, so signing in again still finds it. When someone has more than
one account of a service, its tools are listed as "Telegram · <account>"
and the model sees each account's actions under the account's name
(telegram_send_message_alerts_bot) with the account in the description,
instead of _1 and _2. Actions shared by different services are named
after the service. Tools a user renamed keep their name.
2026-09-29 10:41:54 +01:00
arc53-machine 607c2296e3 Show the Telegram default chat in the connect form and the drawer
The connect form shows field hints; Telegram's Default chat ID says what
it does and how to find a chat's id. In the drawer, a chat set on the
account shows as set there instead of as a choice.
2026-09-29 10:41:54 +01:00
arc53-machine c3e83ff9dd Add a default chat to the Telegram connector
A Telegram connection can now hold an optional default chat ID. When it
is set, both Telegram actions send there, the model is no longer asked
for a chat, and a chat it names anyway is ignored. In member mode each
member's own connection supplies their own chat. The same bot with a
different chat is a separate connection.
2026-09-29 10:41:48 +01:00
arc53-machine 744cfde565 Fix a tool's parameters from the connector drawer
Under Customize, each action now opens its parameters. Each one is either
left to the AI or set to Always use a value, which is sent on every call
and never shown to the AI. Actions with fixed values carry a small count.
2026-09-29 10:41:37 +01:00
arc53-machine 28b56e8b03 Add an endpoint to fix a connection tool's parameters
PUT /api/connections/<id>/tools/<tool_id>/parameters takes an action and
a map of parameter to value (always use it) or null (let the model
decide), checked against the action's schema; only the tool's owner can
call it. Connection tools now list each action's parameters and whether
they are fixed.
2026-09-29 10:41:20 +01:00
arc53-machine 54bea5a1d8 Keep fixed values when an MCP server's tools are refreshed or re-saved
Parameters that still exist after re-reading the server keep the value the
user fixed; parameters the server dropped go with the old schema.
2026-09-29 10:41:20 +01:00
arc53-machine f6bdd853d5 Validate tool action updates and keep fixed values owner-only
update_tool_actions now checks the submitted actions against the tool's
stored ones: no new actions or parameters, fixed values must fit their
parameter's type. A team editor can still switch actions on and off but
gets 403 for changing a fixed value.
2026-09-29 10:41:13 +01:00
arc53-machine 34038ae1c2 Keep fixed tool parameters fixed when the model sends them
A parameter hidden from the model with a stored value is now always sent
with that value; a model that names the key anyway (by mistake, or because
a prompt told it to) no longer overrides it. 0 and false are real fixed
values; an empty value still means the parameter is left out.
2026-09-29 10:41:13 +01:00
arc53-machine bbf83f02b2 Skip scheduled sync of a remote source paused for reconnect
S3 and GitHub sources synced from a connection kept being retried on
every schedule after their connection needed reconnecting, failing and
notifying the owner each time. They now wait, like Drive and Confluence
sources, and resume when the connection is reconnected.
2026-09-29 10:41:03 +01:00
arc53-machine 84230409c6 Document the GitHub connector
How members connect with a fine-grained token or Sign in with GitHub, how
an admin registers the GitHub App (callback URL, permissions, requesting
authorization during installation, settings), and that
GITHUB_ACCESS_TOKEN now reads public repositories only.
2026-09-29 10:41:03 +01:00
arc53-machine 2a6c40d45a Connect GitHub with a token or Sign in with GitHub, then pick repos and tools
The connect wizard offers both sign-ins when the GitHub App is set up
(token only otherwise, with a link to create a fine-grained token), and
says when GitHub refuses a token. After sign-in, one step turns on the
read-only GitHub tools and picks a repository to sync. The repository
picker searches what the connection can read; a GitHub App sign-in can
choose more repositories on GitHub and the list reloads.

A token connection is shown by its GitHub login rather than a key hint,
and a connection set up without tools can add them from its page. The
GitHub upload tile keeps reading public repositories by URL, and points
to the GitHub connection for private ones.
2026-09-29 10:41:03 +01:00
arc53-machine 489ef567a3 Show GitHub's optional GitHub App setup in Admin > Connectors
GitHub is Ready with tokens alone and marked Tokens only until its GitHub
App settings are set. Its setup guide lists them, the callback URL to
register, and the App permissions and install option to choose.
2026-09-29 10:41:03 +01:00
arc53-machine 74cbf68ffc Show GitHub's optional GitHub App settings in Admin > Connectors
The admin connectors API lists the settings that add Sign in with GitHub
and whether they are complete, next to the required settings (none for
GitHub, which works with tokens alone).
2026-09-29 10:41:03 +01:00
arc53-machine 7b516ade82 Add a built-in GitHub connector for repository sync and read-only tools
One GitHub connection feeds both a Knowledge source and an agent tool.
Users connect with a personal access token, checked against GitHub and
named after the account, or, when an admin registers a GitHub App
(GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET, GITHUB_APP_SLUG), with Sign in
with GitHub. App tokens expire after eight hours and are refreshed before
each sync or tool call; tokens with no expiry are never treated as expired.

The catalog gains an optional second sign-in method (oauth_settings,
exposed as sign_in_methods) without changing any other connector.

Sync lists the repositories the connection can read (the token's own, or
the App installations') and ingests one with the connection's token. The
tool is GitHub's read-only MCP server (api.githubcopilot.com/mcp/readonly):
setup discovers its actions and creates it bound to the connection, and
the executor sends the connection's token only to that server.
2026-09-29 10:41:03 +01:00
arc53-machine 3572d968ec Read private repositories only with the user's own GitHub token
GITHUB_ACCESS_TOKEN belongs to the server, but any user could ingest any
repository it can see, private ones included. It is now used only for
public repositories; the loader checks the repository's visibility first
and asks for a GitHub connection otherwise.

The loader also takes a token from the connection a source syncs from.
Merging a connection's keys into a plain repository URL no longer fails
on json.loads, manual Sync now passes the source's connection, and a
token GitHub rejects pauses the connection's sources for reconnect.
2026-09-29 10:41:03 +01:00
arc53-machine 35d6d80e87 Key cached MCP clients by a digest of the whole token
The cache key held the first ten characters of a bearer token or API key.
Every fine-grained GitHub token starts with github_pat_, so two users of
the same server shared one cached client, and with it the first user's
token, for up to five minutes.
2026-09-29 10:41:03 +01:00
arc53-machine f4397a7a65 Show each connected account as its own tool, managed in place
A connected tool's card has its switch again and names its account, so
two accounts of one service are two tools you can turn on and off. Manage
connection in its menu opens the connection panel on the Tools page
instead of leaving for Connectors.
2026-09-29 10:05:41 +01:00
arc53-machine bacab4cfe7 Check a preset's switch for a key-based connection to its server
A custom MCP connection at a preset's address is reported and run as that
preset, but saving it checked the custom MCP switch. Turning custom servers
off now leaves a preset on a key alone, and turning the preset off stops it.
2026-09-29 09:36:25 +01:00
arc53-machine c9ff165491 Keep the file picker's account when the source type changes
The reset ran in an effect after the new picker had reported its default
account, so remote uploads could send no connection. It now happens with
the type change. A connection tile that is not set up says Not connected.
2026-09-29 00:54:07 +01:00
arc53-machine 526b7a9fb3 Treat a refused tool update as a failed save 2026-09-29 00:54:07 +01:00
arc53-machine 9cd8c6c45c Offer Continue only once the needed connection works
The launcher reports every close of its dialog, so a cancelled connect
turned Continue on. Readiness now comes from the connections in the store.
2026-09-29 00:54:07 +01:00
arc53-machine 2cb23938f7 Regroup connector categories and give empty Knowledge a way in
Linear, Jira & Confluence and Asana move to Projects & issues, Stripe to
Payments & business and Reddit to Search & web. An empty Knowledge page
offers Add knowledge and Connect a service.
2026-09-29 00:54:07 +01:00
arc53-machine 212fa4f8dc Set a tool's permissions by group, with actions in words
What a tool looks up and what it does are each set at once to Allow, Ask
first or Off; long lists fold behind Customize, where each action shows its
name in words and its description. A note says what Ask first means over
an agent's API. The panel follows a refreshed tool's actions.
2026-09-29 00:54:07 +01:00
arc53-machine 5c2a45fb74 Show connections that need signing in again where their tools are picked
The chat and agent tool pickers mark a tool whose connection expired and
offer Reconnect, which redoes the sign-in in place (or opens the connector
page for a custom server). The connector page names the account without
claiming it is connected and says what went wrong in plain words, keeping
the provider's message on hover.
2026-09-29 00:54:07 +01:00
arc53-machine 97e37a7e37 Manage a connected tool on its connector page
A tool from a connection shows the catalog's description and a Manage
connection button instead of its own switch, and its menu no longer opens
the raw MCP server form to reconnect. It says when it is off or needs
signing in again.
2026-09-29 00:54:07 +01:00
arc53-machine cc7b07817f Strings for connected tools, sign-in prompts, grouped permissions and Knowledge
Adds the copy the next changes use and finishes the Sources to Knowledge
wording in connector flows: reconnect toasts, the disconnect and remove
confirmations, the wizard's done step and the Knowledge picker. Permission
choices read Allow / Ask first / Off everywhere.
2026-09-29 00:54:07 +01:00
arc53-machine 8cf46f2e57 Give a different account its own connection when reconnecting 2026-09-29 00:43:48 +01:00
arc53-machine cdc5084e02 Refuse a disabled connector before falling back to a legacy tool secret 2026-09-29 00:41:57 +01:00
arc53-machine a260ca44f1 Check a tool's connection before writing its permissions 2026-09-29 00:40:33 +01:00
arc53-machine 33f29cb408 Authenticate MCP token requests one way under Basic auth
With client_secret_basic the MCP SDK sets the Basic header and still sends
client_id in the body; Linear refuses that as two authentication methods.
Token and refresh requests now drop the body client_id when the Basic
header is set, as RFC 6749 describes.
2026-09-28 23:43:49 +01:00
arc53-machine 0d42916d67 Hand the MCP SDK an authorization result with the issuer
mcp 2.x reads code, state and the RFC 9207 iss off the callback handler's
result; the handler still returned a (code, state) tuple, so every MCP
sign-in failed after the user approved it. The callback route now keeps the
issuer too, since servers that advertise it (Linear) refuse a sign-in
without it.
2026-09-28 23:32:21 +01:00
arc53-machine cdaaaaf427 Prefer the configured MCP OAuth callback over the page's origin
A page opened on a plain-HTTP address registered its own origin as the
callback, which servers such as Linear refuse. MCP_OAUTH_REDIRECT_URI now
wins when set; the page's value is the fallback.
2026-09-28 23:20:44 +01:00