paperclip/packages/mcp-server
Dotta b3343dbd64
feat(connections): add self-serve intent runtime (#12345)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents need a governed way to request app connections during issue
work.
> - The catalog now describes the available providers and setup methods.
> - A request must become a durable, company-scoped intent before an
operator acts on it.
> - This pull request adds that intent runtime across server, agent,
CLI, and shared contracts.
> - The benefit is a safe bridge from agent need to operator-approved
setup.

## Linked Issues or Issue Description

Refs #11965

This is stack 7 of 11. It depends on stack 6 and replaces another
reviewable part of #11965.

## What Changed

- Add connection intent types, validation, service logic, and routes.
- Add agent runtime tools and CLI support for connection requests.
- Add issue-thread interaction support for connection intents.
- Add runtime, route, adapter, and contract tests.
- Hold the final resolved-continuation row lock through asynchronous
adapter preparation until an actual process spawn, so parking or
reassignment cannot cross that boundary.
- Report Hermes Gateway's first remote run request through the shared
dispatch hook so the resolved-intent lock is released at the true
dispatch boundary.
- Revalidate the addressed user's live non-viewer membership and
connection-management authority for every intent mutation, including
OAuth completion.

## Verification

- `pnpm --filter @paperclipai/server typecheck`
- `pnpm --filter @paperclipai/server exec vitest run
src/__tests__/tool-access-service.test.ts`
- Result: 176 tests passed.
- `pnpm build`
- `pnpm --filter @paperclipai/server exec vitest run
src/__tests__/heartbeat-stale-queue-invalidation.test.ts` (32 passed;
includes non-process dispatch lock-release coverage)
- `pnpm exec vitest run --project @paperclipai/server
server/src/__tests__/connection-intents-service.test.ts -t
"addressed-user mutation"` (1 passed)
- `pnpm exec vitest run --project @paperclipai/server
server/src/__tests__/tool-access-service.test.ts -t "binds OAuth
callback completion to the initiating board session"` (1 passed)
- `pnpm --filter @paperclipai/hermes-paperclip-adapter test --
src/gateway/server/execute.test.ts` (23 passed; includes dispatch-hook
ordering and exactly-once coverage)
- `pnpm --filter @paperclipai/hermes-paperclip-adapter typecheck`

## Risks

- A malformed intent could create an unusable operator request.
- Validators and company checks reject invalid or cross-company
requests.
- The final continuation gate holds the issue row lock through adapter
preparation until process or remote dispatch; later operator changes use
the normal active-run interruption path.
- The change does not add a database migration.

> I checked `ROADMAP.md`. This stack continues the existing app
connection work from #11965 and does not duplicate another planned item.

## Model Used

OpenAI Codex, GPT-5. The runtime model ID and context window were not
exposed. The model used reasoning, tool use, and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have linked the public source pull request with `Refs #`
- [x] I have not referenced internal or instance-local Paperclip issues
or links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-08-29 12:08:34 -05:00
..
src feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
README.md feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
package.json build(deps-dev): bump typescript from 5.9.3 to 7.0.2 (#11880) 2026-08-25 14:49:05 -07:00
tsconfig.json Add standalone Paperclip MCP server package 2026-04-06 21:23:46 -05:00
vitest.config.ts Add standalone Paperclip MCP server package 2026-04-06 21:23:46 -05:00

README.md

Paperclip MCP Server

Model Context Protocol server for Paperclip.

This package is a thin MCP wrapper over the existing Paperclip REST API. It does not talk to the database directly and it does not reimplement business logic.

Authentication

The server reads its configuration from environment variables:

  • PAPERCLIP_API_URL - Paperclip base URL, for example http://localhost:3100
  • PAPERCLIP_API_KEY - bearer token used for /api requests
  • PAPERCLIP_COMPANY_ID - optional default company for company-scoped tools
  • PAPERCLIP_AGENT_ID - optional default agent for checkout helpers
  • PAPERCLIP_RUN_ID - optional run id forwarded on mutating requests

Inside an active heartbeat, Paperclip also injects PAPERCLIP_RUNTIME_TOOLS_* variables. They enable the run-scoped connections_search and connection_request tools and expire with the run.

Usage

npx -y @paperclipai/mcp-server

Or locally in this repo:

pnpm --filter @paperclipai/mcp-server build
node packages/mcp-server/dist/stdio.js

Tool Surface

Run-scoped connection tools:

  • connections_search
  • connection_request

Read tools:

  • paperclipMe
  • paperclipInboxLite
  • paperclipListAgents
  • paperclipGetAgent
  • paperclipListIssues
  • paperclipGetIssue
  • paperclipGetHeartbeatContext
  • paperclipListComments
  • paperclipGetComment
  • paperclipListIssueApprovals
  • paperclipListDocuments
  • paperclipGetDocument
  • paperclipListDocumentRevisions
  • paperclipListProjects
  • paperclipGetProject
  • paperclipGetIssueWorkspaceRuntime
  • paperclipWaitForIssueWorkspaceService
  • paperclipListGoals
  • paperclipGetGoal
  • paperclipListApprovals
  • paperclipGetApproval
  • paperclipGetApprovalIssues
  • paperclipListApprovalComments

Write tools:

  • paperclipCreateIssue
  • paperclipUpdateIssue
  • paperclipCheckoutIssue
  • paperclipReleaseIssue
  • paperclipAddComment
  • paperclipSuggestTasks
  • paperclipAskUserQuestions
  • paperclipRequestConfirmation
  • paperclipUpsertIssueDocument
  • paperclipRestoreIssueDocumentRevision
  • paperclipControlIssueWorkspaceServices
  • paperclipCreateApproval
  • paperclipLinkIssueApproval
  • paperclipUnlinkIssueApproval
  • paperclipApprovalDecision
  • paperclipAddApprovalComment

Escape hatch:

  • paperclipApiRequest

paperclipApiRequest is limited to paths under /api and JSON bodies. It is meant for endpoints that do not yet have a dedicated MCP tool.