Repository navigation
feat: mint Connect tokens per tool call for the target repository - #158
Merged
Merged
Conversation
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
|
Thank you for following the naming conventions! 🙏 |
This was referenced Sep 23, 2026
Merged
2 tasks done
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🔗 Linked issue
None.
📚 Description
githubExtension({ connector, connect })mints every Connect token with the same params, so all tool calls use one GitHub App installation. When the App is installed on several accounts, a call to a repository on another account fails with a 403. For example, an agent whose home repo isevloghq/evloggets a 403 fromgithub__createPullRequestonhugorcd/hr-folio.This PR lets the Connect token be minted per tool call, for the call's target repository:
GithubTokenInputis nowstring | ((call?: GithubTokenCall) => Promise<string>), where the call is{ toolName, input, owner?, repo? }. All 84 tool factories and the eve runtime pass it.owner/repocome from the tool's input aftercontextdefaults. Tools whose schema has noowner+repo(search, gists, notifications,createRepository) get them undefined, even though context merging adds those keys to every tool's args.connectaccepts a resolver:(ctx, call) => paramsin the extension and(call) => paramsinconnectGithubTools/connectGithubToken. The static shape and theconnect.subjectresolver keep working unchanged.perRepository(params?)in@github-tools/sdk/connectreturns{ ...params, authorizationDetails: [{ type: 'github_app_installation', org: owner, repositories: [repo] }] }for calls with a target, andparamsotherwise. It is callable in both resolver forms. It lives in the SDK becauseeve extension buildgenerates the extension's package entry with only the default export. Using it from an eve agent therefore needs@github-tools/sdkas a direct dependency; the docs say so.preset/include/excludeas static params. As with static params, an explicitscopesin the resolved params replaces the derived scopes.@vercel/connectcaches tokens per(connector, params), and per-repository params are deterministic, so repeated calls on one repo reuse the token.CONNECT_INSTALLATION_REQUIREDnow names the target account ("The connector's GitHub App is not installed on hugorcd: …") when the token targets an org or a qualified repository.Tests cover the connect params resolver,
perRepository, the owner-naming installation error, and call threading through bothcreateGithubToolsand the eve runtime.pnpm lint,pnpm typecheck, andpnpm testpass, as do the SDK and extension builds. Locally, theexamples/evebuild stops at the missing optionalmicrosandboxpackage, and theapps/chatbuild runs out of heap during workflow graph extraction. Both fail the same way onmainwithout this change.📝 Checklist