Main's access model (team editors and viewers, edit_credentials, owner-only
OAuth servers, per-user tool preferences, resource sponsors) now applies to
connection-backed tools and sources. Our migrations are renumbered to
0040_connections and 0041_connection_account_name, after main's
0038_resource_access_settings and 0039_resource_sponsors.
Where the two sides met: MCP tools save and load their connections as the
tool owner, editors may add a key (a new connection on the owner's account)
but never rewrite an existing connection's secret, fixed values stay
owner-only, and a member's own connection is used in member mode.
An MCP preset that also syncs asked about Knowledge first and showed its
tools on a separate summary. After signing in it now shows the tools and
their permissions, then Sync into Knowledge underneath; Done or Add to
Knowledge closes the wizard, with a toast saying what syncs.
After removing a Linear connection, connecting again could skip signing in
and save Linear as an unconnected custom tool: a client cached before the
removal still held the old tokens, and a late token write re-created a
connection for them. A token write for a named connection no longer creates
one, removing or disconnecting a connection drops its cached clients, and a
sign-in server is never saved without its connection.
A first connect of a service that can sync now asks with a Sync into
Knowledge switch. It starts off from the Connectors page, Add tool and
the chat, and on when the wizard opens for Knowledge: the Add knowledge
tiles and the Connectors page listed for syncing. Off, the account is
still connected and the summary says where to sync later. On, the
picker, name and frequency show with collapsed Advanced retrieval
settings, sent with the sync; an incoherent prescreen blocks it as in
Upload. Sync more and reconnect are unchanged.
The connection setup endpoint takes sync.config, validated like an
upload's config, and passes it to the ingest task so the synced source
gets the chosen chunking and retrieval settings. An invalid config is
refused before the idempotency key is claimed.
An issue deleted after it was listed, or comments the token cannot read,
now lose that detail with a warning instead of failing the whole sync; an
unreadable document is skipped.
The chunker caches only a model's tokenizer.json in the embeddings cache.
FastEmbed counts any cached snapshot as the model, so it never downloaded
the ONNX graph and every load failed with NO_SUCHFILE. The loader now
checks the files FastEmbed needs and fetches them first when they are
missing; offline it leaves them for FastEmbed to report.
A value the owner fixed may be a secret, and tool-call events reach whoever
runs the agent, so query and body values the owner fixed now show as
(fixed); a value the connection sets, like Telegram's default chat, still
shows. sent_arguments is saved with the conversation, so a reopened chat
shows the same arguments as the live one.
With several accounts of a service, a dropdown picks the one shown along
with its knowledge and tools, instead of listing every account. The page
opens on the account behind the tool it was opened from, else one that
needs signing in again.
Signing in to Linear now goes on to choosing what to sync, as the
drawer's Sync more does: teams and projects to pick, whether to bring
comments (on) and the picked projects' documents. The tools still come
with the sign-in, and Skip keeps only them. A source is named after what
it syncs until the name is edited. Signing in again goes straight to the
summary.
The Linear connector now syncs as well as giving agents its tools, from
one connection. Linear's MCP server is its own OAuth issuer, so its
tokens are read through the same MCP tools the agents use (list_issues,
get_issue, list_comments, list_documents) rather than Linear's GraphQL
API, and no OAuth app has to be registered.
A source picks teams and projects, with comments (on by default) and the
projects' documents. Each issue becomes one document with its state,
assignee, priority, labels, description and comments, filed under its
team and citing its Linear URL. Each sync reads up to 500 issues and 100
documents again. /api/connections/<id>/linear lists the teams and
projects to pick from. Sources sync on their schedule with the owner's
connection, and pause when the sign-in needs reconnecting.
run_connection_session opens one MCP session signed in with an MCP OAuth
connection's stored tokens and runs a batch of tool calls in it, so a
sync makes hundreds of calls over one sign-in. The tokens only go to the
server the connection signed in to. A sign-in that expired and cannot be
renewed flags the connection for reconnecting, which pauses its sources;
network trouble and rate limits are reported as worth retrying.
The MCP SDK knows a token's expiry only when it obtained the token in the
same process. A worker or a restarted API loading tokens from the
connection sent an expired one, got a 401 and asked the owner to sign in
again. The expiry is now saved with the tokens and handed back to the SDK,
which then renews the token with its refresh token first; a token saved
before expiries were kept is renewed once. A sign-in that cannot be
renewed raises MCPReauthorizationRequired.
Explains the opt-in switch, the full endpoint it uses, how write actions
default to asking first, the admin's Write access switch, and which
fine-grained token or GitHub App permissions changes need.
The GitHub tools step gets a second switch under Let agents use GitHub:
Also let agents make changes (issues, comments, pull requests), off by
default. A connection's page has the same switch on its GitHub tool, which
re-reads the tool's actions from the other endpoint. Both are hidden when
an admin turns changes off in the new Write access section of
Admin > Connectors. The token hint and the GitHub App setup note name the
permissions changes need.
A GitHub connection's MCP tool can now point at GitHub's full endpoint
(/mcp/) instead of the read-only one when its owner opts in, at setup
(allow_writes) or later (PUT /api/connections/<id>/writes), which re-reads
the actions and keeps the choices for those on both endpoints. Actions from
the write endpoint are writes unless GitHub marks them read-only, so they
default to asking first.
Admins can forbid it per connector (allow_writes in Admin > Connectors,
kept in app_metadata). Then the option is refused, a refresh goes back to
read-only, and at run time the tool only ever calls the read-only endpoint
and write calls are denied with a reason.
The approval card and a finished call showed what the model asked for,
even where a fixed value replaced it. Calls now carry sent_arguments for
the chat, leaving headers out since they may hold a fixed secret. The
model's own arguments are kept as they were, because they are what later
turns replay to it and it never sees fixed values.
The connect wizard asks for an optional account name (keys and sign-ins
alike) and sets it once the account exists. In the connector drawer a
named account shows its name with the account under it, and Rename in
the account menu changes or clears the name.
Connections get an account_name (migration 0039) that the owner sets with
PATCH /api/connections/<id>; the account label stays the account's
identity, so signing in again still finds it. When someone has more than
one account of a service, its tools are listed as "Telegram · <account>"
and the model sees each account's actions under the account's name
(telegram_send_message_alerts_bot) with the account in the description,
instead of _1 and _2. Actions shared by different services are named
after the service. Tools a user renamed keep their name.
The connect form shows field hints; Telegram's Default chat ID says what
it does and how to find a chat's id. In the drawer, a chat set on the
account shows as set there instead of as a choice.
A Telegram connection can now hold an optional default chat ID. When it
is set, both Telegram actions send there, the model is no longer asked
for a chat, and a chat it names anyway is ignored. In member mode each
member's own connection supplies their own chat. The same bot with a
different chat is a separate connection.
Under Customize, each action now opens its parameters. Each one is either
left to the AI or set to Always use a value, which is sent on every call
and never shown to the AI. Actions with fixed values carry a small count.
PUT /api/connections/<id>/tools/<tool_id>/parameters takes an action and
a map of parameter to value (always use it) or null (let the model
decide), checked against the action's schema; only the tool's owner can
call it. Connection tools now list each action's parameters and whether
they are fixed.
update_tool_actions now checks the submitted actions against the tool's
stored ones: no new actions or parameters, fixed values must fit their
parameter's type. A team editor can still switch actions on and off but
gets 403 for changing a fixed value.
A parameter hidden from the model with a stored value is now always sent
with that value; a model that names the key anyway (by mistake, or because
a prompt told it to) no longer overrides it. 0 and false are real fixed
values; an empty value still means the parameter is left out.
S3 and GitHub sources synced from a connection kept being retried on
every schedule after their connection needed reconnecting, failing and
notifying the owner each time. They now wait, like Drive and Confluence
sources, and resume when the connection is reconnected.
How members connect with a fine-grained token or Sign in with GitHub, how
an admin registers the GitHub App (callback URL, permissions, requesting
authorization during installation, settings), and that
GITHUB_ACCESS_TOKEN now reads public repositories only.
The connect wizard offers both sign-ins when the GitHub App is set up
(token only otherwise, with a link to create a fine-grained token), and
says when GitHub refuses a token. After sign-in, one step turns on the
read-only GitHub tools and picks a repository to sync. The repository
picker searches what the connection can read; a GitHub App sign-in can
choose more repositories on GitHub and the list reloads.
A token connection is shown by its GitHub login rather than a key hint,
and a connection set up without tools can add them from its page. The
GitHub upload tile keeps reading public repositories by URL, and points
to the GitHub connection for private ones.
GitHub is Ready with tokens alone and marked Tokens only until its GitHub
App settings are set. Its setup guide lists them, the callback URL to
register, and the App permissions and install option to choose.
The admin connectors API lists the settings that add Sign in with GitHub
and whether they are complete, next to the required settings (none for
GitHub, which works with tokens alone).
One GitHub connection feeds both a Knowledge source and an agent tool.
Users connect with a personal access token, checked against GitHub and
named after the account, or, when an admin registers a GitHub App
(GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET, GITHUB_APP_SLUG), with Sign in
with GitHub. App tokens expire after eight hours and are refreshed before
each sync or tool call; tokens with no expiry are never treated as expired.
The catalog gains an optional second sign-in method (oauth_settings,
exposed as sign_in_methods) without changing any other connector.
Sync lists the repositories the connection can read (the token's own, or
the App installations') and ingests one with the connection's token. The
tool is GitHub's read-only MCP server (api.githubcopilot.com/mcp/readonly):
setup discovers its actions and creates it bound to the connection, and
the executor sends the connection's token only to that server.
GITHUB_ACCESS_TOKEN belongs to the server, but any user could ingest any
repository it can see, private ones included. It is now used only for
public repositories; the loader checks the repository's visibility first
and asks for a GitHub connection otherwise.
The loader also takes a token from the connection a source syncs from.
Merging a connection's keys into a plain repository URL no longer fails
on json.loads, manual Sync now passes the source's connection, and a
token GitHub rejects pauses the connection's sources for reconnect.
The cache key held the first ten characters of a bearer token or API key.
Every fine-grained GitHub token starts with github_pat_, so two users of
the same server shared one cached client, and with it the first user's
token, for up to five minutes.
A connected tool's card has its switch again and names its account, so
two accounts of one service are two tools you can turn on and off. Manage
connection in its menu opens the connection panel on the Tools page
instead of leaving for Connectors.
A custom MCP connection at a preset's address is reported and run as that
preset, but saving it checked the custom MCP switch. Turning custom servers
off now leaves a preset on a key alone, and turning the preset off stops it.