paperclip/packages/shared/src
Dotta 4d317274ce
feat(channels): add experimental iMessage Photon (#13299)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Channels connect external conversations to company tasks and agent
execution.
> - Slack, Discord, and AgentMail already provide durable delivery and
access controls.
> - People also need to reach an agent from Apple Messages and send
photos.
> - Photon provides shared Pro DMs, dedicated numbers, and authenticated
event recovery.
> - This pull request connects Photon to the existing channel services.
> - People can message an agent while Paperclip retains task ownership
and approval authority.

## Linked Issues or Issue Description

**Subsystem affected**

Cross-cutting: channel services, shared contracts, database constraints,
Apps, and agent Channels UI.

**Problem or motivation**

Paperclip has no iMessage channel. A person cannot use Apple Messages to
start a task, send a photo, or answer an agent's pending question.

**Proposed solution**

Add experimental **iMessage Photon** with Pro-compatible shared DMs or a
dedicated Photon Cloud number per agent channel. Reuse channel
admission, identity links, task generations, publication, and
interaction continuation. Keep groups disabled for shared allocation.
Dedicated lines support groups that an operator explicitly enables.
Require a fresh linked message and a published agent response before
setup completes.

**Alternatives considered**

Shared allocation has no owned phone number, so it reserves one project
and allows DMs only. Dedicated allocation reserves one stable number.
Local Mac access needs a separate deployment model. The upstream Photon
Chat SDK adapter does not persist the poll mappings and send receipts
required here. This change uses the lower-level SDK without adding
another agent runtime.

**Roadmap alignment**

This extends Connected Apps and agent communication through the existing
channel subsystem. It does not add a parallel tool connection or agent
loop. GitHub searches for Photon and iMessage found no matching provider
implementation.

**Additional context**

This ships behind the existing experimental channel gate. Dedicated-line
release qualification remains incomplete. Real Photon Pro DMs passed
task/reply, native poll, text answers, confirmation rejection, media,
restart, pause, reconnect, revocation, and removal tests. An
operator-supplied iPhone camera HEIC also passed the full round trip.
Dedicated groups remain unqualified. See [the verification
record](doc/connections/IMESSAGE-PHOTON-VERIFICATION.md) and [the
implementation plan](doc/plans/2026-09-11-imessage-photon.md).

## What Changed

- Add the provider catalog entry, shared setup contracts, and a forward
migration. A global partial index reserves the dedicated number or
shared project until its endpoint is archived.
- Add Cloud project inspection, vaulted project credentials,
selected-line token renewal, and a leased receiver. Persist checkpoint
updates under the receiver lease. Shared project replay accepts sparse
increasing sequences only after a complete recovery barrier.
- Connect DMs and enabled groups to existing task generations, sender
authorization, ordered delivery, and publication services. Keep each
iMessage conversation on its task after completion; only explicit `/new`
or `/close` releases the binding. Publish committed inbound comments
live and label their human bubbles “Sent from iMessage” in both
task-chat renderers.
- Persist immutable text/file send identities, upload receipts, poll
IDs, option IDs, per-person drafts, and canonical interaction
continuation proofs.
- Add source-bound file recovery, bounded HEIC/HEIF conversion, JPEG
previews, and related Live Photo companion video retention.
- Add the three-step setup flow and channel management surfaces with
official branding. Preserve the experimental gate and existing
pause/disconnect behavior.
- Add interactive production-component Storybooks for setup, access,
recovery, and ongoing conversations. Add provider, integration, catalog,
and browser regression coverage. Document setup, recovery, supported
boundaries, and qualification gaps.

## Verification

- Live Photon Pro, SDK 2.1.0: linked iPhone messages create a task and
receive native Codex replies in Apple Messages. Unlinked senders cannot
start work.
- Three real follow-ups each reopened the same completed task. Incoming
bubbles appeared on its open page without reload and showed “Sent from
iMessage.” The third follow-up ran after restarting the server on
`4d7222110`; the agent correctly repeated its previous reply from before
the restart.
- Native polls after restart, sequential text drafts, required-field
correction, explicit submission, approval rejection with a required
reason, and native continuation passed against Photon.
- PNG, text documents, synthetic HEIC, and a real iPhone camera HEIC
passed in both directions. The camera photo produced a 3024×4032 JPEG
preview. The native agent described it and returned the received HEIC
byte-for-byte.
- Pause/resume, reconnect, identity revocation, removal, `/status`,
`/new`, `/close`, and stale answers after close passed live. Messages
suppressed by pause did not become work on resume. Removal stopped
intake and removed credential bindings.
- All 304 focused tests passed on `4d7222110`. These cover Photon
unit/integration behavior, both task-chat renderers, live comment
hydration, completed-task continuity after restart, enabled groups,
duplicate delivery, and explicit reset/close. The selected Teams
completion-boundary regression also passed. Full workspace
typecheck/build and token gates passed for the conversation fix; the
final UI changes passed their affected typecheck/build and tests.
- All 26 new Photon Storybook Playwright cases passed in light and dark
themes, including the complete shared-DM setup journey and 390px mobile
follow-ups. UI typecheck and the Storybook build passed. These stories
use simulated Photon responses and do not replace the live evidence
above.
- The full chat-adapters browser suite previously passed all 39 cases.
Migration checks passed, and migration 0275 applied to the isolated live
instance with the earlier Photon migration already applied.
- The local full Vitest run was previously interrupted by the host's
embedded-Postgres shared-memory limit; it is not a full-suite pass. All
30 applicable CI checks passed on preceding head `7a5419cac`, with two
skipped checks and Greptile 5/5. Head `24f8e1aae` adds an explicit
required-story discovery guard to the 26 passing Storybook cases.
Greptile rates this final head 5/5 with no unresolved review threads.
All 30 applicable CI checks passed, with two optional checks skipped.
- A repeated live send key suppressed the duplicate but returned gRPC 6
/ SDK `internalError` without an original receipt. Paperclip keeps
unknown delivery unresolved. This provider behavior is covered by a
regression test.
- See [the verification
record](doc/connections/IMESSAGE-PHOTON-VERIFICATION.md) for package
versions, redacted live evidence, deterministic coverage, and remaining
qualification gaps.

## Risks

- Dedicated group qualification remains unrun; groups are disabled for
the approved Pro scope. Real iPhone camera HEIC passed transport,
preview generation, agent inspection, and return. Keep the channel
experimental; the dedicated-line release matrix remains incomplete.
- Shared recovery and attachment aliases were verified against the live
gateway. Duplicate writes currently return an error without the original
receipt; unresolved sends require operator resolution. The
implementation fails visibly on invalid replay ordering, a reset cursor,
or changed identity.
- The HEIF converter passed on macOS arm64 and in Linux CI. Windows HEIF
binaries have not been executed in this work. Linux musl has no packaged
converter. Unsupported conversion retains the original and reports the
missing preview.
- The migration adds a global reservation across companies for Photon
numbers and shared projects. Paused and revoked endpoints keep that
reservation until removal.
- Integration touches shared channel services. Existing provider browser
coverage passes; broad repository verification is recorded above.
- `pnpm-lock.yaml` is intentionally excluded under repository policy.
The repository bot owns lockfile updates. The additional Superagent
supply-chain scan is neutral/inconclusive because these new dependencies
are not yet in the committed lockfile. Its security scan passed; all
required CI checks pass.

## Model Used

OpenAI Codex, GPT-6 family, with reasoning, repository inspection, code
execution, browser testing, and tool use. The exact served model
identifier and context-window size are not exposed in this session. No
sub-agents were used.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-12 15:23:50 -05:00
..
app-definitions feat(channels): add experimental iMessage Photon (#13299) 2026-09-12 15:23:50 -05:00
runtime-exposure fix(workspaces): make managed runtimes reliable across restarts (#11740) 2026-08-19 14:55:16 -05:00
telemetry feat: add experimental native chat connectors (#13038) 2026-09-10 10:06:45 -05:00
types feat(channels): add experimental iMessage Photon (#13299) 2026-09-12 15:23:50 -05:00
validators feat(channels): add experimental iMessage Photon (#13299) 2026-09-12 15:23:50 -05:00
account-handle.test.ts feat(codex-local): give each Codex account its own home and path secret (#12709) 2026-09-02 14:46:53 -07:00
account-handle.ts feat(codex-local): give each Codex account its own home and path secret (#12709) 2026-09-02 14:46:53 -07:00
adapter-agnostic-keys.test.ts fix: deduplicate adapter-agnostic config keys (#9058) 2026-07-05 21:47:38 -07:00
adapter-auth-check-code.test.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
adapter-auth-check-code.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
adapter-auth-session.ts Add sandbox device-login for the Codex adapter (#11237) 2026-08-12 08:58:25 -07:00
adapter-type.ts feat(adapters): external adapter plugin system with dynamic UI parser 2026-04-03 21:11:20 +01:00
adapter-types.test.ts [codex] Split backend control-plane QoL slice (#4700) 2026-04-28 16:46:45 -05:00
agent-eligibility.test.ts feat(agents): warn when an agent's escalation path routes to a paused manager (#10657) 2026-08-01 17:42:42 -07:00
agent-eligibility.ts feat(agents): warn when an agent's escalation path routes to a paused manager (#10657) 2026-08-01 17:42:42 -07:00
agent-url-key.ts feat: company portability — export/import companies and agents 2026-03-02 09:06:58 -06:00
api.ts feat: maintained in_review review-path contract + stalled-review actions (#10675) 2026-08-04 13:54:40 -05:00
app-definitions-url.test.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
app-definitions.generated.ts feat(channels): add experimental iMessage Photon (#13299) 2026-09-12 15:23:50 -05:00
app-definitions.ingestion-report.json feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
app-definitions.test.ts feat(channels): add experimental iMessage Photon (#13299) 2026-09-12 15:23:50 -05:00
app-definitions.ts feat(channels): add experimental iMessage Photon (#13299) 2026-09-12 15:23:50 -05:00
company-import-transfer.test.ts feat: already-imported transfer error names the landed company (#12144) 2026-08-25 13:51:50 -07:00
company-import-transfer.ts feat: already-imported transfer error names the landed company (#12144) 2026-08-25 13:51:50 -07:00
config-schema.test.ts fix(config): preserve extensions and guard invalid repairs (#11005) 2026-08-07 00:41:19 -05:00
config-schema.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
connection-intent-guidance.test.ts feat(connections): connect services from native task feeds (#13058) 2026-09-08 15:55:26 -05:00
connection-intent-guidance.ts feat(connections): connect services from native task feeds (#13058) 2026-09-08 15:55:26 -05:00
constants.ts refactor: remove automatic productivity reviews (#13263) 2026-09-11 15:46:35 -05:00
decision.test.ts feat(decisions): add first-class propose mode (#10010) 2026-07-31 19:17:02 -07:00
document-anchors.test.ts [codex] Add document annotations and comments (#6733) 2026-05-26 06:41:23 -07:00
document-anchors.ts [codex] Add document annotations and comments (#6733) 2026-05-26 06:41:23 -07:00
env-file.test.ts fix(config): preserve env files during managed updates (#10980) 2026-08-07 00:54:43 -05:00
env-file.ts fix(config): preserve env files during managed updates (#10980) 2026-08-07 00:54:43 -05:00
environment-custom-images.test.ts Add browser SSH terminal for custom image setup (#8911) 2026-07-03 16:44:21 -07:00
environment-custom-images.ts Add browser SSH terminal for custom image setup (#8911) 2026-07-03 16:44:21 -07:00
environment-support.test.ts fix(runner): repair paid provider startup paths (#12769) 2026-09-04 07:58:44 -05:00
environment-support.ts fix(runner): repair paid provider startup paths (#12769) 2026-09-04 07:58:44 -05:00
execution-workspace-guards.ts Guard closed isolated workspaces on issues 2026-04-04 17:48:54 -05:00
external-objects-server.ts External object references across issue surfaces (#8512) 2026-06-23 08:27:19 -05:00
external-objects.test.ts External object references across issue surfaces (#8512) 2026-06-23 08:27:19 -05:00
external-objects.ts External object references across issue surfaces (#8512) 2026-06-23 08:27:19 -05:00
feature-catalog.test.ts Add a feature catalog build artifact derived from the experimental settings schema (#10055) 2026-07-22 18:12:56 -07:00
feature-catalog.ts feat: add experimental persistent agent chat (#13284) 2026-09-12 08:56:04 -05:00
frontmatter.test.ts Skill Studio: three-pane skill IDE with sandboxed test runs (#9241) 2026-07-09 13:08:56 -05:00
frontmatter.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
github-connectors.ts feat(connections): add durable GitHub identities and webhooks (#12843) 2026-09-04 18:02:52 -05:00
gitignore-runtime.test.ts chore: ignore materialized Paperclip runtime directory 2026-07-08 17:59:43 -07:00
google-workspace-connectors.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
home-paths.test.ts [codex] Add LLM Wiki plugin host support (#5597) 2026-05-10 07:34:12 -05:00
home-paths.ts [codex] Add LLM Wiki plugin host support (#5597) 2026-05-10 07:34:12 -05:00
humanize-connection.test.ts feat(mcp) [split 2/8]: add governed access contracts (#9557) 2026-07-14 12:57:20 -05:00
humanize-connection.ts feat(mcp) [split 2/8]: add governed access contracts (#9557) 2026-07-14 12:57:20 -05:00
index.ts feat(connections): add AgentMail inboxes and email tasks (#13256) 2026-09-11 16:56:38 -05:00
issue-attribution.test.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
issue-attribution.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
issue-references.test.ts Fix Cloud tenant issue identifier routes (#5196) 2026-05-04 13:20:58 -05:00
issue-references.ts Fix Cloud tenant issue identifier routes (#5196) 2026-05-04 13:20:58 -05:00
issue-thread-interactions.test.ts feat(runner): project native runs into task threads (#12321) 2026-08-29 19:26:20 -05:00
issue-write-denial.test.ts feat(issues): explain cross-task agent writes with attribution, audit receipts, and actionable denials (#10843) 2026-08-04 23:02:51 -05:00
issue-write-denial.ts feat(issues): explain cross-task agent writes with attribution, audit receipts, and actionable denials (#10843) 2026-08-04 23:02:51 -05:00
markdown-work-products.test.ts feat(artifacts): bridge Markdown work products into the document review surface (#11822) 2026-08-20 17:28:01 -07:00
markdown-work-products.ts feat(artifacts): bridge Markdown work products into the document review surface (#11822) 2026-08-20 17:28:01 -07:00
mcp-config-help-prompt.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
mcp-remote-headers.test.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
mcp-remote-headers.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
network-bind.ts Introduce bind presets for deployment setup 2026-04-11 07:09:07 -05:00
node-version.ts fix(adapters): prevent engine fallback and preserve usable runtime defaults (#13105) 2026-09-09 13:27:24 -05:00
oauth-endpoint-url.test.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
oauth-endpoint-url.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
pipeline-case-type.ts Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
pipeline-health.test.ts [codex] Deduplicate pipeline automation health warnings (#9090) 2026-07-06 12:12:18 -05:00
pipeline-health.ts [codex] Deduplicate pipeline automation health warnings (#9090) 2026-07-06 12:12:18 -05:00
portability-fidelity.test.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
portability-fidelity.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
portability-hash.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
portability-zip.test.ts fix(server): raise company import zip upload limit to 1 GB and make it operator-configurable (#11184) 2026-08-10 12:47:03 -07:00
portability-zip.ts fix(server): raise company import zip upload limit to 1 GB and make it operator-configurable (#11184) 2026-08-10 12:47:03 -07:00
project-mentions.test.ts [codex] Roll up May 17 branch changes (#6210) 2026-05-17 17:15:06 -05:00
project-mentions.ts Add pipeline workflow primitives and operator UI (#7903) 2026-06-26 12:02:44 -05:00
project-url-key.ts fix: append short UUID suffix to project slugs when non-ASCII characters are stripped to prevent slug collisions 2026-03-31 16:35:30 +00:00
resource-memberships.test.ts feat(server): add per-user document stars (#9952) 2026-07-27 19:13:35 -05:00
responsible-user-denial.test.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
responsible-user-denial.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
routine-variables.test.ts feat(routines): add date variable controls (#8655) 2026-06-26 12:00:16 -05:00
routine-variables.ts feat(routines): add date variable controls (#8655) 2026-06-26 12:00:16 -05:00
runner-goal.ts Add end-to-end session goals to Paperclip Runner 2026-09-08 16:18:47 -05:00
self-serve-mcp-research.json feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
self-serve-mcp-research.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
setting-defaults.test.ts Let operators supply defaults for selected instance settings (#12285) 2026-08-27 11:29:05 -07:00
setting-defaults.ts Let operators supply defaults for selected instance settings (#12285) 2026-08-27 11:29:05 -07:00
settings-visibility.test.ts Let operators hide the Provider vaults and Proposals tabs (#12284) 2026-08-27 11:28:15 -07:00
settings-visibility.ts Remove the instance Heartbeats settings page (#12282) 2026-08-27 11:31:43 -07:00
summary-slot.test.ts fix: isolate execution workspace summaries (#10790) 2026-08-11 08:56:32 -04:00
trust-policy.ts fix(auth): clarify protected-agent assignment blocks (#10893) 2026-08-05 10:09:17 -05:00
work-product.test.ts Add workspace file viewer and artifact links (#7681) 2026-06-09 17:17:43 -05:00
workspace-commands.test.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
workspace-commands.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
workspace-file-resource.test.ts fix(files): only highlight accessible workspace file links (#11090) 2026-08-11 12:11:45 -04:00
worktree-port-registry.test.ts fix(workspaces): make managed runtimes reliable across restarts (#11740) 2026-08-19 14:55:16 -05:00
worktree-port-registry.ts fix(workspaces): make managed runtimes reliable across restarts (#11740) 2026-08-19 14:55:16 -05:00
worktree-seed-source.test.ts fix(workspaces): seed managed worktrees when the base checkout has no config (#11752) 2026-08-20 08:42:16 -07:00
worktree-seed-source.ts fix(workspaces): seed managed worktrees when the base checkout has no config (#11752) 2026-08-20 08:42:16 -07:00