Skip to content

feat: mint Connect tokens per tool call for the target repository - #158

Merged
HugoRCD merged 1 commit into
mainfrom
feat/connect-per-call-token
Sep 23, 2026
Merged

HugoRCD merged 1 commit into
mainfrom
feat/connect-per-call-token

Conversation

@HugoRCD

@HugoRCD HugoRCD commented Sep 23, 2026

Copy link
Copy Markdown
Member

🔗 Linked issue

None.

📚 Description

githubExtension({ connector, connect }) mints every Connect token with the same params, so all tool calls use one GitHub App installation. When the App is installed on several accounts, a call to a repository on another account fails with a 403. For example, an agent whose home repo is evloghq/evlog gets a 403 from github__createPullRequest on hugorcd/hr-folio.

This PR lets the Connect token be minted per tool call, for the call's target repository:

import githubExtension from '@github-tools/eve-extension'
import { perRepository } from '@github-tools/sdk/connect'

export default githubExtension({
  connector: 'github/my-connector',
  preset: 'pr-author',
  context: { owner: 'evloghq', repo: 'evlog' },
  connect: perRepository(),
})
  • Token providers receive the call. GithubTokenInput is now string | ((call?: GithubTokenCall) => Promise<string>), where the call is { toolName, input, owner?, repo? }. All 84 tool factories and the eve runtime pass it. owner / repo come from the tool's input after context defaults. Tools whose schema has no owner + repo (search, gists, notifications, createRepository) get them undefined, even though context merging adds those keys to every tool's args.
  • connect accepts a resolver: (ctx, call) => params in the extension and (call) => params in connectGithubTools / connectGithubToken. The static shape and the connect.subject resolver keep working unchanged.
  • perRepository(params?) in @github-tools/sdk/connect returns { ...params, authorizationDetails: [{ type: 'github_app_installation', org: owner, repositories: [repo] }] } for calls with a target, and params otherwise. It is callable in both resolver forms. It lives in the SDK because eve extension build generates the extension's package entry with only the default export. Using it from an eve agent therefore needs @github-tools/sdk as a direct dependency; the docs say so.
  • Scopes: per-call params go through the same derivation from preset / include / exclude as static params. As with static params, an explicit scopes in the resolved params replaces the derived scopes.
  • Caching: @vercel/connect caches tokens per (connector, params), and per-repository params are deterministic, so repeated calls on one repo reuse the token.
  • Errors: CONNECT_INSTALLATION_REQUIRED now names the target account ("The connector's GitHub App is not installed on hugorcd: …") when the token targets an org or a qualified repository.

Tests cover the connect params resolver, perRepository, the owner-naming installation error, and call threading through both createGithubTools and the eve runtime.

pnpm lint, pnpm typecheck, and pnpm test pass, as do the SDK and extension builds. Locally, the examples/eve build stops at the missing optional microsandbox package, and the apps/chat build runs out of heap during workflow graph extraction. Both fail the same way on main without this change.

📝 Checklist

  • I have linked an issue or discussion.
  • I have updated the documentation accordingly.

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
github-tools-docs Ready Ready Preview, v0 Sep 23, 2026 10:49am UTC
github-tools-test-agent Ready Ready Preview, v0 Sep 23, 2026 10:49am UTC

@github-actions

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@HugoRCD
HugoRCD merged commit 5df1f13 into main Sep 23, 2026
16 checks passed
@HugoRCD
HugoRCD deleted the feat/connect-per-call-token branch September 23, 2026 12:19

This branch was successfully deployed

2 active deployments
Preview – github-tools-docs — eca392a5 Deployed Sep 23, 2026 by vercel[bot]
Preview – github-tools-test-agent — eca392a5 Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant