paperclip/packages/db/src
Dotta d387cc0ff0
feat(connections): add managed external MCP connectors (#12346)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connection intents need secure provider implementations to complete
setup.
> - Some providers use managed OAuth or external credential brokers.
> - Those tokens must stay out of durable Paperclip state and fail
closed when refresh fails.
> - This pull request adds managed connector backends and the required
storage contract.
> - The benefit is safer provider setup with governed credential
lifecycles.

## Linked Issues or Issue Description

Refs #11965

This is stack 8 of 11. It depends on stack 7 and replaces another
reviewable part of #11965.

## What Changed

- Add managed Google Workspace and external connector backends.
- Add Vercel Connect support without storing provider bearer tokens.
- Add replay-safe migration 0232 and its generated snapshot.
- Fail closed and clear stale token bindings when organization OAuth
refresh needs reauthorization.

## Verification

- `pnpm --filter @paperclipai/server typecheck`
- `pnpm --filter @paperclipai/server exec vitest run
src/__tests__/tool-access-service.test.ts`
- Result: 194 tests passed.
- `pnpm --filter @paperclipai/db check:migrations`
- `pnpm build`
- `pnpm exec vitest run --project @paperclipai/server
server/src/services/remote-url-credentials.test.ts` (5 passed, including
URL userinfo vault extraction)

## Risks

- Broker metadata errors can block provider setup.
- OAuth refresh failure disables the shared organization connection
until reauthorization.
- Migration 0232 is generated, ordered after 0231, and safe to replay.

> I checked `ROADMAP.md`. This stack continues the existing app
connection work from #11965 and does not duplicate another planned item.

## Model Used

OpenAI Codex, GPT-5. The runtime model ID and context window were not
exposed. The model used reasoning, tool use, and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have linked the public source pull request with `Refs #`
- [x] I have not referenced internal or instance-local Paperclip issues
or links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
2026-08-29 12:08:34 -05:00
..
migrations feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
schema feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00
adapter-auth-sessions-schema.test.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
agent-wakeup-requests-schema.test.ts fix: preserve recovery retries across restarts (#11817) 2026-08-20 17:09:42 -05:00
backup-lib.test.ts feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
backup-lib.ts feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
backup.ts
…
better-auth-account-issuer-migration.test.ts Add the Better Auth issuer column so signup and sign-in work (#12396) 2026-08-27 22:31:35 -07:00
built-in-agent-unique-marker-migration.test.ts fix: prevent duplicate built-in agents and self-heal reconciliation (#10223) 2026-07-28 11:12:58 -07:00
check-migration-numbering.ts
…
check-migration-safety.test.ts
…
check-migration-safety.ts
…
client-options.test.ts db: env-configurable client options; parallelize attention feed queries (#10795) 2026-08-04 06:30:36 -07:00
client-teardown-registry.test.ts fix(db): close test database clients before the embedded Postgres cluster stops (#12335) 2026-08-27 13:39:42 -07:00
client.test.ts feat(runner): add native persistence contracts (#12169) 2026-08-25 13:08:39 -05:00
client.ts fix(db): close test database clients before the embedded Postgres cluster stops (#12335) 2026-08-27 13:39:42 -07:00
company-secret-proposals-migration.test.ts Add governed secret alias confirmation cards (#11486) 2026-08-18 09:44:24 -05:00
connection-grants-phase2-migration.test.ts feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
connection-grants-phase4-migration.test.ts feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
connections-v3-schema-core-migration.test.ts feat(apps): add connection grants and delegated identities (#12341) 2026-08-29 12:08:33 -05:00
decision-queue-migrations.test.ts feat(decisions): add desk workflow and retention (#10672) 2026-08-02 10:47:03 -05:00
embedded-postgres-error.test.ts
…
embedded-postgres-error.ts
…
embedded-postgres-lifecycle.test.ts fix(workspaces): keep deferred seed databases reliable (#11706) 2026-08-19 10:41:29 -05:00
embedded-postgres-lifecycle.ts fix(workspaces): keep deferred seed databases reliable (#11706) 2026-08-19 10:41:29 -05:00
embedded-postgres-native.test.ts feat(cli): add managed install, update, and service lifecycle (#10045) 2026-07-31 18:52:23 -07:00
embedded-postgres-native.ts
…
environment-custom-images-schema.test.ts
…
external-objects-schema.test.ts
…
heartbeat-context-snapshot-index-migration.test.ts perf(server): cut steady-state DB hot paths in dashboard, attention, and productivity sweeps (#10992) 2026-08-06 11:56:40 -05:00
inbox-archive-agent-policies-migration.test.ts
…
index.ts fix(cli): make embedded-Postgres tests survive runner contention (#12466) 2026-08-28 13:51:54 -07:00
issue-comment-derived-attribution-migration.test.ts
…
issue-comment-on-behalf-migration.test.ts feat(issues): contain cross-issue agent side effects (#10837) 2026-08-04 13:17:49 -05:00
issue-thread-interaction-resolver-policy-migration.test.ts fix(interactions): authorize resolvers consistently (#11376) 2026-08-16 13:46:50 -05:00
migrate.ts
…
migration-runtime.ts
…
migration-safety-baseline.ts
…
migration-snapshot-drift.test.ts Repair the drizzle snapshot so generate emits no spurious migration (#12333) 2026-08-27 12:56:07 -07:00
migration-status.ts
…
nested-skill-folders-migration.test.ts
…
pipelines-schema.test.ts
…
question-response-delivery-migration.test.ts fix(interactions): deliver question answers durably (#12307) 2026-08-27 12:12:21 -05:00
runtime-config.test.ts
…
runtime-config.ts
…
seed.ts
…
status-card-migrations.test.ts fix(db): give the last two embedded-Postgres migration tests a timeout (#11313) 2026-08-12 21:30:50 -07:00
summary-slots-schema.test.ts feat: add built-in summarizer and summary slots (#9713) 2026-07-17 11:03:07 -05:00
table-size-estimates.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
test-embedded-postgres.test.ts fix(db): harden embedded Postgres test start with bounded retry (#10540) 2026-07-30 22:22:31 -07:00
test-embedded-postgres.ts fix(cli): make embedded-Postgres tests survive runner contention (#12466) 2026-08-28 13:51:54 -07:00
vercel-connect-credential-source-migration.test.ts feat(connections): add managed external MCP connectors (#12346) 2026-08-29 12:08:34 -05:00