paperclip/ui/storybook/stories
Dotta 0ffc091473
feat(connections): add durable GitHub identities and webhooks (#12843)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Agents need source control access for repository work
> - A shared token cannot preserve the responsible person's identity or
an agent's dedicated identity
> - GitHub App tokens also need durable refresh, repository access
checks, and webhook delivery
> - Paperclip already has managed connections, encrypted grants, run
secret leases, and merge-confirmation behavior
> - This pull request extends those systems with GitHub identities
instead of adding a parallel credential system
> - The benefit is durable GitHub access with explicit identity,
repository, runtime, and webhook boundaries

## Linked Issues or Issue Description

No public GitHub issue describes this connection change. This
description follows the feature request template.

**Subsystem affected**

Connected Apps, connection grants, secret resolution, native Git runtime
setup, webhook processing, and the Apps UI.

**Problem or motivation**

Users need to connect GitHub once and let agents use the correct GitHub
identity. A run should use a dedicated agent account when one exists.
Otherwise, it should use the responsible person's account. The
connection must survive token expiry, repository access changes, and
temporary instance downtime.

**Proposed solution**

Add user-owned and agent-owned GitHub grants to the existing connection
model. Resolve one identity for MCP, Git, `gh`, health checks, and
webhook bindings. Store provider tokens in the existing encrypted secret
system. Refresh expiring token pairs under the existing lease and
compare-and-swap path. Register signed Cloud webhook bindings and
process normalized pull request and installation events through a
durable local inbox.

**Alternatives considered**

An organization-wide GitHub token would lose person and agent
attribution. Environment variables alone would bypass the managed
connection and grant model. A new GitHub-only credential store would
duplicate the existing secret and access systems. GitHub App
installation tokens and private-key custody remain outside this first
version.

**Roadmap alignment**

This change implements the Connected Apps direction. It also extends the
shipped MCP Tool Gateway, per-agent secret access, and
action-attribution systems. It does not add a repository catalog. The
open repository catalog work in
[#11234](https://github.com/paperclipai/paperclip/pull/11234) is related
and complementary.

## What Changed

- Added agent-owned connection grants and a per-agent credential policy
with company and subject constraints.
- Added a managed GitHub App method while keeping the personal access
token method as an advanced fallback.
- Added durable access-token and refresh-token handling with proactive
rotation and one automatic recovery after a provider `401`.
- Added GitHub identity and installation summaries without storing
repository-name lists.
- Added signed Cloud webhook binding, event lease, acknowledgement,
local idempotency, pull request merge processing, and installation
access handling.
- Added one identity resolver for MCP, native Git, `gh`, checkout,
health checks, and webhook bindings.
- Added a class-3 run projection for `GH_TOKEN`, `GITHUB_TOKEN`, a
`github.com`-only credential helper, SSH-to-HTTPS rewrite, and GitHub
noreply commit attribution.
- Added personal and dedicated-agent setup choices plus identity,
repository, continuity, and webhook status in the Apps UI.
- Added schema migrations, tests, and connection documentation.

## Verification

- The current head is fully green in GitHub CI, including build,
typecheck, all serialized/general server shards, all browser shards,
policy, canary dry run, review, and security checks.
- Live staging proof completed with a non-expiring GitHub App user
token, selected-repository installation, repository add/remove refresh,
managed MCP, native `gh`, HTTPS clone/push/delete, GitHub noreply commit
attribution, signed merged-PR webhook acceptance, durable
Cloud-to-instance delivery, and installation-access event processing.
Temporary branches and temporary repository access were removed
afterward.
- `pnpm check:token-gates` passed.
- `pnpm -r typecheck` passed before and after the rebase onto
`origin/master`.
- `pnpm build` passed.
- The focused connector suite passed 285 tests after the rebase.
- The full stable suite passed 5,790 tests and failed 22 tests across 8
general server files. The failures reproduced as shared-runner
environment issues. They included `/tmp` versus `/private/tmp`, closed
database connections, and invalid high ephemeral ports. The focused
connection tests pass in isolation.

## Risks

- Migrations add agent grant subjects and a durable connection-event
inbox. Migration numbering and safety checks pass.
- A raw GitHub user token enters the agent process for Git and `gh`.
Per-tool Ask-first controls cannot limit those shell operations. The UI
warns users about this boundary.
- GitHub App user tokens can be non-expiring. Paperclip performs a
continuity check every 30 days, but provider revocation still requires a
reconnect.
- The webhook path accepts only signed and bounded payloads. It stores a
minimal normalized record and no raw provider payload.
- GitHub repository permissions remain authoritative. Removed access can
make a cached repository count temporarily stale, but runtime access
fails immediately.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex, `gpt-5.6-sol`, extended reasoning, tool use, code
execution, browser control, and multi-file repository editing. The
context window size was not provided.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-04 18:02:52 -05:00
..
access-profiles.stories.tsx feat(apps): add connection intent setup experience (#12347) 2026-08-29 12:08:35 -05:00
action-card.stories.tsx feat(mcp) [split 7/8]: activate Apps and gateway UI (#9562) 2026-07-14 15:40:08 -05:00
activity-feed.stories.tsx feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
agent-detail.stories.tsx feat(ui): design-system component convergence — Card/Badge adoption, multiplicative radius ladder, unified list surfaces (#9240) 2026-07-08 17:15:45 -07:00
agent-management.stories.tsx Remove cheap model profiles (#12683) 2026-09-01 14:57:38 -05:00
agent-skill-row.stories.tsx build(deps): bump lucide-react from 0.577.0 to 1.32.0 (#11885) 2026-08-25 10:54:14 -07:00
agent-skills-edge.stories.tsx Skill Studio: three-pane skill IDE with sandboxed test runs (#9241) 2026-07-09 13:08:56 -05:00
agents-using-skill.stories.tsx feat(skills): add beta releases for the core Paperclip skill (#10228) 2026-07-27 19:45:59 -05:00
app-activity-lifecycle.stories.tsx feat(mcp) [split 7/8]: activate Apps and gateway UI (#9562) 2026-07-14 15:40:08 -05:00
apps-connect-discoverability.stories.tsx feat(connections): add AppDefinition Wave 1 catalog (#9981) 2026-07-21 15:57:12 -05:00
apps-connect-name.stories.tsx feat(connections): add AppDefinition Wave 1 catalog (#9981) 2026-07-21 15:57:12 -05:00
artifacts.stories.tsx feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
assigned-backlog-safeguards.stories.tsx Guard assigned backlog liveness (#5428) 2026-05-07 12:25:26 -05:00
blocked-inbox.stories.tsx feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
budget-finance.stories.tsx [codex] add comprehensive UI Storybook coverage (#4132) 2026-04-20 12:13:23 -05:00
built-in-agents.stories.tsx feat: add built-in summarizer and summary slots (#9713) 2026-07-17 11:03:07 -05:00
chat-comments.stories.tsx feat: make recovery updates quieter (#10542) 2026-07-31 09:55:01 -07:00
control-plane-surfaces.stories.tsx [codex] add comprehensive UI Storybook coverage (#4132) 2026-04-20 12:13:23 -05:00
data-viz-misc.stories.tsx Remove the company brand color and per-company attachment limit (#12291) 2026-08-27 12:11:05 -07:00
decision-card.stories.tsx feat(decisions): add first-class propose mode (#10010) 2026-07-31 19:17:02 -07:00
decisions-desk.stories.tsx fix(interactions): authorize resolvers consistently (#11376) 2026-08-16 13:46:50 -05:00
dev-ops-surfaces.stories.tsx [codex] UI and dev ops quality-of-life (#6384) 2026-05-19 15:52:39 -05:00
dialogs-modals.stories.tsx Remove cheap model profiles (#12683) 2026-09-01 14:57:38 -05:00
document-annotations.stories.tsx feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
document-comments.stories.tsx feat(ui): single-source design tokens, visual regression suite, and theme retune (#9134) 2026-07-07 16:22:16 -05:00
environment-variables-editor.stories.tsx feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
external-objects.stories.tsx fix(external-objects): refresh PR status labels (#10704) 2026-08-02 20:24:52 -07:00
file-viewer.stories.tsx feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
fork-skill-flow.stories.tsx Skill Studio: three-pane skill IDE with sandboxed test runs (#9241) 2026-07-09 13:08:56 -05:00
forms-editors.stories.tsx feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
foundations.stories.tsx [codex] add comprehensive UI Storybook coverage (#4132) 2026-04-20 12:13:23 -05:00
frontmatter-panel.stories.tsx Skill Studio: three-pane skill IDE with sandboxed test runs (#9241) 2026-07-09 13:08:56 -05:00
gateways-tab.stories.tsx feat(mcp) [split 7/8]: activate Apps and gateway UI (#9562) 2026-07-14 15:40:08 -05:00
interrupt-handoff.stories.tsx [codex] Clarify interrupt handoffs and scoped wake semantics (#7855) 2026-06-09 21:57:21 -05:00
issue-blocked-notice.stories.tsx Show ordered live blocker work in task chat (#11487) 2026-08-16 15:10:05 -04:00
issue-management.stories.tsx feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
issue-plan-decompositions.stories.tsx Add accepted-plan decomposition exact-once guards and UI state (#6831) 2026-05-28 23:30:18 -07:00
issue-review-panel.stories.tsx Remove decision and review summaries from issue headers (#10891) 2026-08-05 10:23:16 -05:00
issue-thread-interactions.stories.tsx feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
managed-cloud-oauth-handoff.stories.tsx Make managed Cloud OAuth handoffs invisible (#12790) 2026-09-03 16:33:13 -05:00
monitor-surfaces.stories.tsx feat: make issue monitors visible across task surfaces (#9783) 2026-07-18 14:39:37 -05:00
navigation-layout.stories.tsx fix(ui): remove the Account badge and version line from the account menu (#12818) 2026-09-03 23:26:08 -07:00
notion-connect-flow.stories.tsx feat(connections): add durable GitHub identities and webhooks (#12843) 2026-09-04 18:02:52 -05:00
onboarding-agent-arc.stories.tsx feat(onboarding): Figma pass over the tenant arc (#12726) 2026-09-02 12:19:15 -07:00
onboarding-connect-model.stories.tsx Onboarding: model source tiles, one input canvas, and Storybook coverage for the agent arc (#12613) 2026-09-01 09:57:46 -07:00
overview.stories.tsx [codex] add comprehensive UI Storybook coverage (#4132) 2026-04-20 12:13:23 -05:00
permitted-vs-installed.stories.tsx feat(connections): add durable GitHub identities and webhooks (#12843) 2026-09-04 18:02:52 -05:00
personal-connection-identity.stories.tsx feat(connections): add durable GitHub identities and webhooks (#12843) 2026-09-04 18:02:52 -05:00
primitives-coverage.stories.tsx feat(apps): consolidate connector management (#12684) 2026-09-01 14:55:35 -05:00
project-execution-workspace-strategy.stories.tsx feat(ui): add shared workspace concurrency select to workspace policy editor (#10771) 2026-08-03 15:13:43 -05:00
projects-goals-workspaces.stories.tsx Add cheap model profiles for local adapters (#4881) 2026-04-30 15:32:04 -05:00
rich-work-product-cards.stories.tsx feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
routine-detail-c.stories.tsx feat(routines): activity-gated advanced run policy (editor + run rows) (#10225) 2026-07-27 19:05:44 -05:00
routine-secrets.stories.tsx feat(routines): expose activity gate API (#9438) 2026-07-24 16:47:24 -05:00
routines-list-groups.stories.tsx [codex] Polish routine layout follow-ups (#7858) 2026-06-09 18:55:01 -05:00
scheduled-retry.stories.tsx Add issue controls and retry-now recovery (#5426) 2026-05-07 12:23:13 -05:00
search.stories.tsx feat(search): filters, sorting, operators & command-palette parity (#9327) 2026-07-09 19:32:58 -05:00
searchable-select.stories.tsx [codex] Improve reusable workspace selector search (#8597) 2026-06-24 13:21:32 -05:00
secrets.stories.tsx feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
skill-policy-surfaces.stories.tsx feat(skills): open-by-default company skill policy and core UX (#9564) 2026-07-15 11:42:40 -05:00
skills-store-detail.stories.tsx feat(skills): add beta releases for the core Paperclip skill (#10228) 2026-07-27 19:45:59 -05:00
skills-store-discovery.stories.tsx feat(ui): refine streamlined workspace surfaces (#12747) 2026-09-02 23:55:55 -07:00
source-issue-recovery.stories.tsx fix: preserve recovery retries across restarts (#11817) 2026-08-20 17:09:42 -05:00
source-resolved-fold.stories.tsx [codex] Roll up May 17 branch changes (#6210) 2026-05-17 17:15:06 -05:00
status-language.stories.tsx [codex] Split PR #4692 UI/QoL updates (#4701) 2026-04-28 17:18:58 -05:00
sub-issues-workflow.stories.tsx Add cheap model profiles for local adapters (#4881) 2026-04-30 15:32:04 -05:00
successful-run-handoff.stories.tsx feat(ui): show a calm in-flight notice when a live run is on the issue (#11423) 2026-08-16 13:20:33 -05:00
summary-slot-card.stories.tsx feat: add built-in summarizer and summary slots (#9713) 2026-07-17 11:03:07 -05:00
task-watchdog-surfaces.stories.tsx [codex] feat(watchdog): add task watchdog control plane (#8339) 2026-06-19 15:38:52 -05:00
team-catalog.stories.tsx Gate Paperclip Runner setup behind an experimental flag (#12656) 2026-09-01 05:57:40 -05:00
test-tab.stories.tsx feat(apps): consolidate connector management (#12684) 2026-09-01 14:55:35 -05:00
user-secrets.stories.tsx feat(ui): single-source design tokens, visual regression suite, and theme retune (#9134) 2026-07-07 16:22:16 -05:00
ux-labs.stories.tsx Add recovery handoff system notices (#5289) 2026-05-06 06:05:58 -05:00
what-needs-me.stories.tsx feat(decisions): add desk workflow and retention (#10672) 2026-08-02 10:47:03 -05:00
work-timeline.stories.tsx [codex] Improve work timeline activity story (#9222) 2026-07-08 08:59:24 -05:00
workspace-file-browser.stories.tsx Add workspace file downloads 2026-06-26 06:05:57 -05:00
workspace-runtime-provisioning.stories.tsx feat(workspaces): defer isolated setup until runtime start (#10653) 2026-08-02 10:37:10 -05:00
workspace-service-control-bar.stories.tsx feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00