paperclip/doc/plans
Dotta d387cc0ff0
feat(connections): add managed external MCP connectors (#12346)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connection intents need secure provider implementations to complete
setup.
> - Some providers use managed OAuth or external credential brokers.
> - Those tokens must stay out of durable Paperclip state and fail
closed when refresh fails.
> - This pull request adds managed connector backends and the required
storage contract.
> - The benefit is safer provider setup with governed credential
lifecycles.

## Linked Issues or Issue Description

Refs #11965

This is stack 8 of 11. It depends on stack 7 and replaces another
reviewable part of #11965.

## What Changed

- Add managed Google Workspace and external connector backends.
- Add Vercel Connect support without storing provider bearer tokens.
- Add replay-safe migration 0232 and its generated snapshot.
- Fail closed and clear stale token bindings when organization OAuth
refresh needs reauthorization.

## Verification

- `pnpm --filter @paperclipai/server typecheck`
- `pnpm --filter @paperclipai/server exec vitest run
src/__tests__/tool-access-service.test.ts`
- Result: 194 tests passed.
- `pnpm --filter @paperclipai/db check:migrations`
- `pnpm build`
- `pnpm exec vitest run --project @paperclipai/server
server/src/services/remote-url-credentials.test.ts` (5 passed, including
URL userinfo vault extraction)

## Risks

- Broker metadata errors can block provider setup.
- OAuth refresh failure disables the shared organization connection
until reauthorization.
- Migration 0232 is generated, ordered after 0231, and safe to replay.

> I checked `ROADMAP.md`. This stack continues the existing app
connection work from #11965 and does not duplicate another planned item.

## Model Used

OpenAI Codex, GPT-5. The runtime model ID and context window were not
exposed. The model used reasoning, tool use, and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have linked the public source pull request with `Refs #`
- [x] I have not referenced internal or instance-local Paperclip issues
or links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
2026-08-29 12:08:34 -05:00
..
2026-02-16-module-system.md Add company import export v2 plan 2026-03-13 21:10:45 -05:00
2026-02-18-agent-authentication-implementation.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-18-agent-authentication.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-19-agent-mgmt-followup-plan.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-19-ceo-agent-creation-and-hiring.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-20-issue-run-orchestration-plan.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-20-storage-system-implementation.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-21-humans-and-permissions-implementation.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-21-humans-and-permissions.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-23-cursor-cloud-adapter.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-02-23-deployment-auth-mode-consolidation.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-03-10-workspace-strategy-and-git-worktrees.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-03-11-agent-chat-ui-and-issue-backed-conversations.md docs: organize plans into doc/plans with date prefixes 2026-03-13 09:11:56 -05:00
2026-03-13-TOKEN-OPTIMIZATION-PLAN.md fix: isolate codex home in worktrees 2026-03-13 11:53:56 -05:00
2026-03-13-agent-evals-framework.md docs: add agent evals framework plan 2026-03-13 15:07:56 -05:00
2026-03-13-company-import-export-v2.md Use positional source arg for company import 2026-03-23 08:14:51 -05:00
2026-03-13-features.md docs: update PRODUCT.md and add 2026-03-13 features plan 2026-03-13 07:25:23 -05:00
2026-03-13-paperclip-skill-tightening-plan.md docs: add paperclip skill tightening plan 2026-03-13 14:37:44 -05:00
2026-03-13-plugin-kitchen-sink-example.md Add kitchen sink plugin example 2026-03-13 23:03:51 -05:00
2026-03-13-workspace-product-model-and-work-product.md docs: add dated plan naming rule and align workspace plan 2026-03-13 09:16:28 -05:00
2026-03-14-adapter-skill-sync-rollout.md [codex] Add skills CLI and catalog management (#6782) 2026-05-28 07:33:51 -10:00
2026-03-14-billing-ledger-and-reporting.md feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
2026-03-14-budget-policies-and-enforcement.md feat(costs): add billing, quota, and budget control plane 2026-03-16 15:11:01 -05:00
2026-03-14-skills-ui-product-plan.md Refine portability export behavior and skill plans 2026-03-14 18:59:26 -05:00
2026-03-17-docker-release-browser-e2e.md feat: add release smoke workflow 2026-03-18 07:59:32 -05:00
2026-03-17-memory-service-surface-api.md chore: improve worktree tooling and security docs 2026-04-10 22:26:30 -05:00
2026-03-17-release-automation-and-versioning.md chore: switch release calver to mdd patch 2026-03-18 07:57:36 -05:00
2026-04-06-smart-model-routing.md docs: add smart model routing plan 2026-04-06 21:23:33 -05:00
2026-04-06-subissue-creation-on-issue-detail.md docs: add sub-issue issue detail plan 2026-04-06 21:24:22 -05:00
2026-04-07-issue-detail-speed-and-optimistic-inventory.md docs: add issue detail speed inventory plan 2026-04-09 06:14:12 -05:00
2026-04-07-pi-hooks-survey.md docs: survey pi and pi-mono hook surfaces 2026-04-09 06:14:12 -05:00
2026-04-08-agent-browser-process-cleanup-plan.md docs: add browser process cleanup plan 2026-04-09 06:14:12 -05:00
2026-04-08-agent-os-follow-up-plan.md docs: add agent-os follow-up plan 2026-04-09 06:14:12 -05:00
2026-04-08-agent-os-technical-report.md docs: add agent-os technical report 2026-04-09 06:14:12 -05:00
2026-04-12-vscode-task-interoperability-plan.md [codex] Harden execution reliability and heartbeat tooling (#3679) 2026-04-14 13:34:52 -05:00
2026-04-24-external-object-reference-backfill.md External object references across issue surfaces (#8512) 2026-06-23 08:27:19 -05:00
2026-04-26-plugin-secret-ref-company-scope.md Add secrets provider vaults and remote import (#5429) 2026-05-09 18:22:17 -05:00
2026-05-05-scaled-kanban-board-design.md Scale issue kanban board for high-volume columns (#5309) 2026-05-15 10:53:09 -05:00
2026-05-05-scaled-kanban-board.md Scale issue kanban board for high-volume columns (#5309) 2026-05-15 10:53:09 -05:00
2026-05-06-llm-wiki-paperclip-asset-security-gate.md [codex] Add LLM Wiki plugin host support (#5597) 2026-05-10 07:34:12 -05:00
2026-05-23-cli-api-parity-openapi-reference.ts Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
2026-05-23-cli-api-parity.md Improve CLI API parity coverage (#6626) 2026-06-02 17:13:29 -07:00
2026-05-26-skills-cli-catalog-contract.md [codex] Add skills CLI and catalog management (#6782) 2026-05-28 07:33:51 -10:00
2026-06-03-low-trust-review-contract.md Add low-trust review containment (#7530) 2026-06-05 16:48:02 -05:00
2026-06-05-agent-access-mcp-runtime-slots-adr.md feat(mcp) [split 8/8]: add e2e coverage and operator docs (#9563) 2026-07-14 15:48:57 -05:00
2026-08-26-self-serve-mcp-connections.md feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
workspace-product-model-and-work-product.md Incorporate Worktrunk patterns into workspace plan 2026-03-13 09:41:12 -05:00
workspace-technical-implementation.md Add workspace technical implementation spec 2026-03-13 16:37:40 -05:00