mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-10 20:50:08 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Apps give agents governed access to external tools. > - Several provider MCP servers lacked a supported catalog entry or failed during setup. > - Real browser tests identified specific registration, session, and form defects. > - This pull request adds seven catalog entries and fixes the shared paths used by eleven verified providers. > - Users can connect these providers through the existing Apps flow and control each action. ## Linked Issues or Issue Description **What existing behavior does this improve?** The Apps catalog and remote MCP setup, discovery, and action tester. **Subsystem affected** Shared app definitions, the server tool services, and the Apps UI. **Current behavior** Seven providers lack a catalog entry. Airtable can select an advertised client-metadata flow that fails. Calendly rejects the registration name. Tavily needs an initialized session before a call. Firecrawl exposes invalid defaults for optional nested form objects. HTTPS setup can display a callback that differs from the server callback. **Proposed behavior** Add Calendly, Exa, Firecrawl, GSC Wizard, Parallel Search, Tavily, and Windsor.ai. Preserve Airtable, Linear, Make, and PostHog. Use reviewed provider options through the shared MCP and OAuth paths. Display the callback supplied by the server. Omit untouched optional object inputs. **Reason and benefit** Eleven providers passed bounded reads through the real Paperclip browser action tester. This PR includes that verified set and its required shared fixes. Unfinished providers remain outside this change. AgentMail keeps its existing integration. **Breaking changes** No database migration. Existing OAuth credentials and action policies keep their ownership and access rules. Airtable's reviewed method re-registers a retained client-metadata binding through DCR. Tavily's reviewed method initializes sessions before dispatch. The existing customer, managed, and Vercel OAuth gateway paths now refresh on upstream 401 and return `oauth_refreshed_retry_required` (409), requiring an explicit caller retry. They do not replay the rejected call automatically; the next invocation initializes a fresh credential-scoped session when required. Related catalog work: #15545. This branch preserves current master catalog entries and does not add another Google Workspace integration. Open and closed provider PRs and public MCP issues were searched. No duplicate for this verified set was found. The change extends the shipped Connected Apps roadmap item. ## What Changed - Add seven catalog entries with official provider branding and reviewed permissions. - Update Airtable, Linear, and Make metadata and show Make in Apps. - Add authoritative provider source overrides that use the existing generation and review checks. - Add the reviewed Airtable DCR option and compatible Calendly registration names. - Initialize Tavily sessions before discovery and calls, including retained connections. Keep credential-scoped session caching and single call dispatch. - Use the server's callback URL in the OAuth setup UI. - Omit untouched optional object defaults; keep supplied empty strings, false, zero, and object values intact in the action tester, with strict required-child validation. - Require an explicit retry after OAuth refresh instead of replaying a tools/call with missing session headers. - Record all eleven successful reads, write policies, auth-method limits, and qualification caveats. Omit credentials and private account data. - Find chat connector cards through catalog search in browser tests, so pagination does not hide Slack or other later entries. ## Verification - Real browser qualification: eleven bounded reads passed. Catalog refresh and reload proof are recorded in `doc/connections/verified-mcp-qualification-2026-10-08.md`. - Provider writes and actual agent-adapter sessions were not run. Alternative documented auth methods and expiry refresh remain unqualified. - `pnpm -r typecheck`: passed. - `pnpm build`: passed. - Focused shared/catalog tests: 41 passed. Source override tests: 3 passed. Catalog regeneration fixture suite: 9 passed. Latest form regression suites: 31 passed. Gateway suite: 38 passed. Other focused UI suites passed before these last fixes. - UI token gates and both token sync checks: passed. - The catalog regeneration fixture includes the authoritative provider overrides; its full suite passes. The focused OAuth socket case passed on isolated rerun. - Complete local UI suite: 7,866 passed. CLI suite: 511 passed, 6 skipped. Complete shared suite: 892 passed. - The unchanged AgentMail/ClickUp discovery fallback suite passes all 45 cases. An OpenAI login test passed on isolated rerun. - Local broad database coverage is limited by macOS PostgreSQL shared-memory exhaustion (`shmget: No space left on device`, not disk space). The broad run was interrupted after diagnosis; no host settings or other running services were changed. - CI found that the Slack browser test assumed its catalog card was on the first page. The test now uses catalog search; the Slack case passes locally. Adjacent GitHub and iMessage cases could not start locally because embedded PostgreSQL initialization failed before browser assertions. - Final commit [`febe4520e`](https://github.com/paperclipai/paperclip/commit/febe4520e13d4b3a4121eafc3d22540c2b11379d): all 54 checks passed, with none pending or failed. [CI run](https://github.com/paperclipai/paperclip/actions/runs/37847182065) passed typecheck, build, all general and serialized test suites, all eight browser shards, runner checks, canary dry run, and the aggregate verification gate. - Greptile reviewed that exact final commit at 2026-10-08 21:33 UTC and returned 5/5 with no outstanding findings or unresolved threads. - PR UI preview against the existing local test server: Calendly catalog/setup observed; Firecrawl read passed after expanding More options with nested optional inputs untouched. This retest proves frontend behavior, not the revised OAuth backend against a live provider. <details> <summary>Browser evidence</summary>    </details> ## Risks - Provider registration and consent behavior can change. Airtable's DCR option is explicit and keeps the existing issuer, resource, redirect, and PKCE checks. - Tavily uses initialized sessions without automatic call retries. After a successful OAuth refresh following 401, callers now receive a retry-required result. A later explicit retry can still require reauthorization if the provider rejects the refreshed token. Provider writes are not live-qualified. - Optional object cleanup affects the shared action tester. Regression tests cover absent objects, required children, defaults, and populated values. - GSC Wizard's underlying Google data scopes and Google flow completion were not independently verified. Its account reported paid/trial metadata of unknown origin. No purchase was performed. - No database migration, new AgentMail integration, or change to existing action grants is included. ## Model Used OpenAI GPT-6 through Codex assisted with implementation, research, tool use, and code execution. The root backend model ID and context window are not exposed in this session. The cheaper subagents used OpenAI `gpt-6-luna`. No model context size is inferred. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass — targeted checks and complete UI/CLI/shared suites passed; the broad local database run was blocked by the macOS PostgreSQL startup limitation documented above. The full database/workspace suite passed in CI. - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
105 lines
3.0 KiB
JSON
105 lines
3.0 KiB
JSON
{
|
|
"schemaVersion": 1,
|
|
"slug": "linear",
|
|
"name": "Linear",
|
|
"description": "Create, update, and read Linear issues.",
|
|
"categories": [
|
|
"productivity"
|
|
],
|
|
"featured": true,
|
|
"branding": {
|
|
"logoUrl": "/brands/apps/linear.svg",
|
|
"darkLogoUrl": "/brands/apps/linear-dark.svg"
|
|
},
|
|
"urlPatterns": [
|
|
"https://mcp.linear.app/*"
|
|
],
|
|
"methods": [
|
|
{
|
|
"key": "mcp-oauth",
|
|
"transport": "mcp_remote",
|
|
"auth": "oauth",
|
|
"ownershipModes": [
|
|
"dcr",
|
|
"customer"
|
|
],
|
|
"whenToUse": "Use the provider-hosted connection for the quickest setup.",
|
|
"defaults": {
|
|
"serverUrl": "https://mcp.linear.app/mcp",
|
|
"authorizationEndpoint": "https://linear.app/oauth/authorize",
|
|
"tokenEndpoint": "https://api.linear.app/oauth/token",
|
|
"scopesHint": [
|
|
"read",
|
|
"write"
|
|
]
|
|
},
|
|
"guidanceMd": "Connect Linear for issues and projects. Paperclip registers its own OAuth client with Linear MCP; no developer-console setup is needed.",
|
|
"riskTier": "S2",
|
|
"requiredResourceFilters": [
|
|
"workspace",
|
|
"team",
|
|
"project"
|
|
],
|
|
"credentialSources": {
|
|
"vercelConnect": {
|
|
"services": [
|
|
"linear"
|
|
],
|
|
"principalModes": [
|
|
"user"
|
|
],
|
|
"scopes": [
|
|
"read",
|
|
"write"
|
|
],
|
|
"header": {
|
|
"name": "Authorization",
|
|
"prefix": "Bearer "
|
|
}
|
|
}
|
|
},
|
|
"label": "Sign in with Linear",
|
|
"consoleLinks": {
|
|
"docs": "https://linear.app/docs/mcp"
|
|
}
|
|
},
|
|
{
|
|
"key": "mcp-api-key",
|
|
"transport": "mcp_remote",
|
|
"auth": "api_key",
|
|
"ownershipModes": [
|
|
"customer"
|
|
],
|
|
"whenToUse": "Use a Linear API key when browser sign-in is not suitable.",
|
|
"defaults": {
|
|
"serverUrl": "https://mcp.linear.app/mcp"
|
|
},
|
|
"guidanceMd": "Create a Linear API key with the permissions needed for the actions you intend to allow. A key restricted to Read is supported for read-only use; workspace and role access still apply.",
|
|
"riskTier": "S2",
|
|
"label": "Use an API key",
|
|
"credentialFields": [
|
|
{
|
|
"key": "authorization",
|
|
"label": "Linear API key",
|
|
"type": "password",
|
|
"required": true,
|
|
"secret": true,
|
|
"helperMd": "Grant Read and Write only when those actions are intended. A Read-only key is supported; the key cannot exceed the owning user\u2019s workspace access.",
|
|
"placeholder": "Paste your Linear API key"
|
|
}
|
|
],
|
|
"keyPlacement": {
|
|
"location": "header",
|
|
"name": "Authorization",
|
|
"prefix": "Bearer "
|
|
},
|
|
"consoleLinks": {
|
|
"docs": "https://linear.app/docs/api-and-webhooks"
|
|
},
|
|
"warnings": [
|
|
"Linear\u2019s standard MCP endpoint exposes read and write tools; review the discovered catalog and Paperclip action policies."
|
|
]
|
|
}
|
|
]
|
|
}
|