Skip to content

feat: agents ask the user for a secret through a private card - #15907

Merged
juliusmarminge merged 22 commits into
mainfrom
t3code/webhooks-agent-secrets
Oct 5, 2026
Merged

juliusmarminge merged 22 commits into
mainfrom
t3code/webhooks-agent-secrets

Conversation

@juliusmarminge

@juliusmarminge juliusmarminge commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Agents had no private way to ask the user for a secret. An agent setting up something that needs a credential, such as a signed webhook ("trigger on every GitHub release"), would invent a secret or ask for it in chat, and the transcript would keep it. The scheduled-task tool also handed back a bare path when the environment had no public URL, and its description was written for timers.

Stacked on #15487.

What changed

  • request_secret (T3 MCP tool) asks the user for any secret through a card in the agent's thread and waits. It takes a label, a reason and an optional placeholder, and knows nothing about what the secret is for.
    • Saving stores the value under a one-use secretRef. The agent gets {status, secretRef}, never the value.
    • Other outcomes: declined, cancelled (the run ended), or timed_out. A timeout or an aborted call closes the card, so nobody can save a value that no agent will receive.
    • A clientRequestId makes retries safe: the same id returns the same card and ref.
    • While a card is open, the thread shows as needing input, like a question, in the sidebar, inbox, notifications and Live Activity.
  • Tools that need a secret take a secretRef and consume it. Webhook task signatures are the first (signature.secretRef).
    • A ref works once, and only in the project it was entered for.
    • A failed attempt from another project doesn't use it up.
    • An unused ref expires after 24 hours.
    • A retried schedule_task whose ref the first save already used keeps the secret that save stored.
  • SecretRequests service owns minting and consuming refs. Answering is a standalone secrets.answerRequest RPC: it stores the value first, then marks the card saved or declined. A card is answered once, and only while the run that asked is still going. Each request has one fixed-length ref derived from its thread and turn item, so long delegated-thread ids still fit in a file name.
  • secret_request turn item records only what was asked and the status. The event log, projections, clients and model context never see the value. secret_request.record is an internal command, so a client can't mark a request saved.
  • schedule_task for webhooks:
    • webhookUrl is returned only when it's a public URL, plus webhookSignature: none | set.
    • The description and agent instructions cover the placeholders a run sees and GitHub's signature settings.
    • They also say to call request_secret before saving instead of asking in chat, and that runs posting into the calling thread suit an orchestrator that delegates and dedupes.
  • Card on web and mobile. It has a title, then the reason, then a masked field (password managers and autofill off) with Save securely, then "Stored securely, never shown to the agent". Decline is a quiet action. Once answered, it collapses to one line. On web the field is masked text rather than a password input, so browsers don't offer to save it, and typing or pasting near an open card never reaches the composer.

Reusable, project-level secrets (named, listable, deletable) are deliberately left for later.

Verification

Typecheck is clean in contracts, shared, client-runtime, server, web, mobile and relay. 333 server, 169 relay and 675 client tests pass. New tests:

  • a saved answer becomes a one-use ref; the thread record never contains the value; reuse fails;
  • refs are scoped to their project, and a wrong-project attempt doesn't use one up;
  • declining stores nothing, and a card is answered once;
  • a webhook signature consumes a ref, which then can't be reused;
  • an MCP round trip with the real service: card, answer, saved plus a ref, never the value; the thread shows as needing input until it's answered; a retry with the same clientRequestId returns the same ref and no second card;
  • a delegated thread's long id still works, and an answer after the run stopped is refused;
  • a retried webhook save with an already used ref keeps its secret;
  • the client display-state logic.

End to end in the browser

This ran against a dev server linked to a personal relay stage with a real managed tunnel. I asked Claude Sonnet 5.5 to set up release-notes automation on every GitHub release and answered as the user.

  1. Unprompted, the agent asked for the secret before creating anything:
    Pending secret card: title, reason, field with Save securely, privacy line
  2. The value is masked while typing:
    Secret typed into the card, shown masked
  3. The card collapsed to "Saved securely and kept private". The agent created the task with the ref and replied with the public URL and the GitHub settings. This task's URL token has since been rotated, so the URL shown is dead.
    Saved card, agent reply with URL and GitHub settings
  4. An unsigned request got 401. A request signed with the secret from the card got 202 and started one subagent:
    Triggered run with one subagent started

After the run, a database search found the value in no messages, events, turn items or outbox rows; it's only on the task. No secret-request files were left in the store.

Recording: https://gh-file-drop-api-prod-mi5fy3sowv63ufte.pinglabs.workers.dev/f/de0a759f6dd72013/recording.mp4

The mobile card typechecks and its logic is tested, but I haven't run it on a device.

Old clients can't decode the new turn item type, so they fail to load a thread that has one. #15951 makes clients skip turn item types they don't know, and should ship before this.

Opus 5.5 via Claude Code

🤖 Generated with Claude Code

@github-actions github-actions Bot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Oct 5, 2026
@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 5, 2026
@github-actions github-actions Bot added the size:XL 500-999 changed lines (additions + deletions). label Oct 5, 2026
Comment thread packages/client-runtime/src/state/server.ts Outdated
Comment thread apps/server/src/orchestration-v2/Orchestrator.ts Outdated
Comment thread apps/server/src/scheduledTasks/ScheduledTaskService.ts Outdated
Comment thread apps/server/src/mcp/OrchestratorMcpService.ts
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 5.0 KiB 5.0 KiB 0 B (0.0%) 6.8 KiB ✅
Codex Thread snapshot wire 3.8 KiB 3.8 KiB 0 B (0.0%) 4.9 KiB ✅
Codex Live turn WebSocket wire 1.2 KiB 1.2 KiB 0 B (0.0%) 2.0 KiB ✅
Codex Live turn WebSocket decoded 20.9 KiB 20.9 KiB 0 B (0.0%) 29.3 KiB ✅
Codex Live turn messages 2 2 0 (0.0%) 8 ✅
Claude Total thread wire 5.0 KiB 5.0 KiB 0 B (0.0%) 6.8 KiB ✅
Claude Thread snapshot wire 3.8 KiB 3.8 KiB 0 B (0.0%) 4.9 KiB ✅
Claude Live turn WebSocket wire 1.2 KiB 1.2 KiB 0 B (0.0%) 2.0 KiB ✅
Claude Live turn WebSocket decoded 21.2 KiB 21.2 KiB 0 B (0.0%) 29.3 KiB ✅
Claude Live turn messages 2 2 0 (0.0%) 8 ✅

Baseline: 25d5c7c · PR result: cae32ed · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 108.5 KiB
  • Claude decoded thread snapshot: 108.8 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@macroscopeapp

macroscopeapp Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR introduces a new cross-platform workflow for collecting and consuming user secrets, spanning MCP, orchestration, persistence, WebSockets, authorization, and scheduled webhooks. Because it changes authentication-sensitive code and handles credentials, the security and lifecycle implications require human review.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge juliusmarminge changed the title feat: agents ask the user for a webhook signing secret through a private card feat: agents ask the user for a secret through a private card Oct 5, 2026
@github-actions github-actions Bot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Oct 5, 2026
Comment thread packages/contracts/src/scheduledTask.ts
Comment thread apps/server/src/secrets/SecretRequests.ts Outdated
Comment thread apps/server/src/secrets/SecretRequests.ts Outdated
Comment thread packages/client-runtime/src/secretRequest.ts
Comment thread packages/contracts/src/scheduledTask.ts
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-mailbox branch from 21c3da4 to b416cf3 Compare October 5, 2026 07:03
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-agent-secrets branch from 084cb62 to 7c08078 Compare October 5, 2026 07:03
Comment thread apps/server/src/secrets/SecretRequests.ts
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-agent-secrets branch from 7c08078 to 83d918d Compare October 5, 2026 07:07
Comment thread apps/server/src/mcp/OrchestratorMcpService.ts Outdated
Comment thread apps/server/src/orchestration-v2/Orchestrator.ts Outdated
Comment thread apps/server/src/secrets/SecretRequests.ts
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-agent-secrets branch 2 times, most recently from bf4e846 to bb4ea55 Compare October 5, 2026 07:19
Comment thread apps/server/src/scheduledTasks/ScheduledTaskService.ts Outdated
Comment thread apps/server/src/orchestration-v2/Orchestrator.ts Outdated
Comment thread apps/server/src/secrets/SecretRequests.ts Outdated
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-mailbox branch from 24686d8 to 0e33197 Compare October 5, 2026 07:22
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-agent-secrets branch 2 times, most recently from 900aa2e to 649c251 Compare October 5, 2026 07:34
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-mailbox branch from b399bb4 to 7ed3278 Compare October 5, 2026 16:46
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-agent-secrets branch from 649c251 to 5d4d099 Compare October 5, 2026 16:46
Comment thread apps/server/src/mcp/OrchestratorMcpService.ts Outdated
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-agent-secrets branch 2 times, most recently from 8d57657 to 0e5c927 Compare October 5, 2026 19:00
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-mailbox branch from 2cb863d to a5ba9b9 Compare October 5, 2026 19:13
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-agent-secrets branch 2 times, most recently from 48a6085 to cc548e8 Compare October 5, 2026 19:41
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-mailbox branch from 52ae78d to 57ee257 Compare October 5, 2026 19:53
juliusmarminge and others added 13 commits October 5, 2026 15:50
…ead feed

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
request_secret was built around webhook tasks: it took a scheduledTaskId,
its card targeted "scheduled_task_webhook_signature", and answering it
was a scheduled-task RPC. Agents need secrets for more than webhooks.

- request_secret takes only a label, reason and placeholder. Saving
  stores the value under a one-use secretRef, which the tool returns
  instead of the value.
- A tool that needs a secret accepts a secretRef and consumes it.
  Webhook signatures do (signature.secretRef). A ref works once, only in
  the project it was entered for.
- Answering is secrets.answerRequest, owned by a new SecretRequests
  service, not the scheduled-task service.
- The pending-secret webhook state (allowPendingSecret, secret_pending)
  is gone: the agent asks first, then saves the task with the ref.
- The card follows a title, description, field with "Save securely",
  then "Stored securely, never shown to the agent" layout, with Decline
  as a quiet action, on web and mobile.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Spans on request_secret, answering and consuming a ref, carrying only
statuses. t3_secret_requests_total counts how each request ended
(saved, declined, cancelled, timed_out) and t3_secret_refs_consumed_total
counts refs used or rejected. A test checks that no span records the
value.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
From the final review of the secret request flow:

- Saving failed in delegated-subagent threads: the ref mapping's file
  name grew with the thread id and passed the 255-byte limit, leaving the
  value file behind. Each request now has one ref, derived from its thread
  and turn item with a server salt, so names are fixed-length and there
  is no second file.
- A save is a create, so two racing answers cannot both store a value.
- A request is closed as cancelled when the wait times out or the tool
  call is interrupted, and an answer is refused once the run that asked
  has ended, so a value is never saved where no agent will receive it.
  The tool reports timed_out instead of an open "pending" card.
- Values nobody used expire after 24 hours.
- secret_request.record is an internal orchestration command, so the
  client dispatch type no longer carries it and ws.ts needs no special
  case.
- Web: typing or pasting near a pending card no longer falls through to
  the composer draft, a click on the card focuses its field, and the
  privacy note describes the field. Mobile announces errors on iOS too.
- The integration test checks the tool result without JSON.stringify,
  which failed typecheck.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The shell reports a pending secret request the way it reports a question,
so the sidebar, inbox, notifications and Live Activity show the agent is
blocked on the user instead of working.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
request_secret takes a clientRequestId, so a retried call returns the same
card and ref. A retried schedule_task whose secretRef was already used by
the first save keeps the secret that save stored. The web field is masked
text rather than a password field, so browsers do not offer to save it,
and mobile's Decline is quiet like the web card's.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A ref nobody consumed kept the user's value on disk until something tried
to use it. The service now sweeps expired values at startup and hourly.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…secret

- A webhook save that names a secretRef never falls back to a plain
  secret sent alongside it, so a replay keeps the secret it stored.
- Recording a secret request again leaves an open card as it was asked,
  and refuses to move it to another run.
- A used or expired value that cannot be deleted is logged; a used one is
  not handed out, so a ref is never used twice.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ted as declined

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e text

SecretRequestError now has a fixed reason and keeps the underlying failure
as its cause; the user-facing message comes from the reason. The runtime
layer imports SecretRequests as a namespace, and the webhook skip is caught
with catchTags.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
consume read the stored value and deleted it in two store calls, so two
concurrent calls with one ref could both read it. Consumption is now
serialized. The client's single-flight key for answering a card encodes its
ids structurally, so ids containing a colon can't collide.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@juliusmarminge
juliusmarminge force-pushed the t3code/webhooks-agent-secrets branch from 6a72454 to 0afd06f Compare October 5, 2026 22:53
juliusmarminge and others added 2 commits October 5, 2026 15:56
…ly on timeout

A failed read while waiting returned without closing the card, so the user
could still save a value nobody would receive. The card now closes on every
exit except an answer, and a failed close is logged instead of ignored.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s no value

Restart recovery cancelled an open secret request but left its form open, so
the user could still try to answer it. It now closes the form too. A save
that lands just after the agent's wait closed the card changed nothing, but
its value stayed stored until it expired; the save now checks its record and
deletes the value if the card was already closed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Comment thread apps/server/src/secrets/SecretRequests.ts Outdated
If recording a saved answer failed, the stored value stayed behind and the
user's retry was refused as already answered; the value is now removed so the
card can be saved again. The secret card guards against a double submit
synchronously on web and mobile. request_secret's docs say a new
clientRequestId asks again after timed_out or cancelled.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@juliusmarminge

Copy link
Copy Markdown
Member Author

CodeRabbit nitpicks, handled in 6eee1e7:

  • Double submit: the secret card now has a synchronous in-flight guard on both web and mobile.
  • secretsByRef: it's created per test inside withService.
  • Concurrent redemption: already covered in 6a72454 by SecretRequests.test.ts ("two concurrent uses of one ref hand the value out once"). Its store read yields, so the two calls really interleave, and the test fails without the lock.

…th failed

If recording a save failed and its stored value couldn't be removed either,
the next save found the value and was refused as already answered. A value
already stored for a card that is still pending is now treated as that
earlier save, and recording it finishes the save.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Comment thread apps/web/src/components/chat/SecretRequestCard.tsx
Comment thread packages/contracts/src/orchestratorMcp.ts Outdated
The result schema allowed status saved without a secretRef, so an agent could
be told a secret was saved with nothing to pass on. Saved now requires the
ref, and a saved card whose value can't be read fails the call instead.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@juliusmarminge
juliusmarminge merged commit 9f61ba6 into main Oct 5, 2026
30 of 31 checks passed
@juliusmarminge
juliusmarminge deleted the t3code/webhooks-agent-secrets branch October 5, 2026 23:14
sheehanmunim added a commit to munimtechnologies/mtcode that referenced this pull request Oct 6, 2026
Upstream: choose where new worktrees are created (pingdotgg#16231), secret requests
through a private card (pingdotgg#15907), PR watch details/stop, webhook service
refactor, outbox/PR-cache pruning, fewer git processes.

Fork reconciliation (prefer upstream): the fork's `worktreeBaseDirectory`
setting, capability and Worktrees row are removed in favor of upstream's
`worktreesDirectory` (Settings → Storage). No machine had the fork setting
set, so nothing is migrated. Kept from the fork: the home-containment check
(now on worktreesDirectory), relative worktree paths resolved against the
repo cwd, and the agent-session scanner treating every managed worktree root
as T3-owned. Upstream's review test uses a root symlink since "/" is refused.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
sandscooling pushed a commit to sandscooling/t3code that referenced this pull request Oct 6, 2026
44 upstream commits. The fork's plan progress meter collided with upstream
pingdotgg#15907 and is deleted whole (Kevin ruled it expendable). Carried pingdotgg#15315 is
closed upstream but kept: its held commands compose with pingdotgg#16204's PR-watch
holds. ThreadNotificationCoordinator gains awaitsAnswer so pingdotgg#15033's
unchanged-shell skip no longer closes standing answer toasts. Fork files move
from effect/unstable/* to effect/* for Effect 4.0.1.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
github-actions Bot added a commit to omarcresp/t3code-flake that referenced this pull request Oct 6, 2026
## What's Changed
* chore(deps): upgrade Effect to stable 4.0.1 by @juliusmarminge in pingdotgg/t3code#16138
* fix(server): worktree threads survive a local branch named t3code by @juliusmarminge in pingdotgg/t3code#16167
* chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 by @juliusmarminge in pingdotgg/t3code#16170
* fix(web): match subagent timestamp fonts to chat by @StiensWout in pingdotgg/t3code#16151
* fix(web): wrap full status text in composer hover details by @UtkarshUsername in pingdotgg/t3code#16158
* ci: run the transfer report job on Blacksmith by @juliusmarminge in pingdotgg/t3code#16178
* fix(server): Stop also stops delegated tasks and pull request watches by @t3dotgg in pingdotgg/t3code#16002
* feat: native /goal for Codex and Claude, with goal status in the UI by @t3dotgg in pingdotgg/t3code#15592
* fix(server): name the cause of a failed git command by @walid-baharwal in pingdotgg/t3code#8645
* fix(server): PR watch wakes the agent when a bot edits its review comment by @Gigioxx in pingdotgg/t3code#15415
* feat(source-control): omit agent credits from PR merge messages by @juliusmarminge in pingdotgg/t3code#16192
* fix(clients): dropped connections say why in the client trace by @t3dotgg in pingdotgg/t3code#16200
* fix(server): PR watch reports a required check that first appears already passed by @ScottN-PV in pingdotgg/t3code#15804
* fix: a failed DPoP key load and a fresh maintenance read are no longer cached by @juliusmarminge in pingdotgg/t3code#15500
* fix: tool screenshots show as images, not base64 text by @t3dotgg in pingdotgg/t3code#16199
* docs(mcp): thread tools reach threads in any project by @t3dotgg in pingdotgg/t3code#15947
* fix(threads): threads watching a PR stay in Working instead of bouncing to the inbox by @t3dotgg in pingdotgg/t3code#16204
* chore(deps): bump cursor sdk and astro to clear vulnerable transitives by @juliusmarminge in pingdotgg/t3code#16214
* fix(server): PR sync waits out a GitHub rate limit pause instead of failing every PR by @t3dotgg in pingdotgg/t3code#16203
* feat(server): scheduled tasks can run on a webhook by @juliusmarminge in pingdotgg/t3code#15085
* feat(relay): forward webhook requests to the environment's tunnel by @juliusmarminge in pingdotgg/t3code#15086
* feat(mobile): create and copy webhook automations by @juliusmarminge in pingdotgg/t3code#15087
* feat(web): create webhook automations and inspect their deliveries by @juliusmarminge in pingdotgg/t3code#15088
* feat(relay,server,web,mobile): opt-in to hold webhooks while offline by @juliusmarminge in pingdotgg/t3code#15487
* fix(server): PR watches stop burning GitHub's rate limit and giving up by @t3dotgg in pingdotgg/t3code#16208
* fix(server): delegation sees a fixed provider without the app open by @t3dotgg in pingdotgg/t3code#16219
* feat: new branches use the shorter t3/ prefix by @t3dotgg in pingdotgg/t3code#16220
* perf: cheaper shell refreshes, one copy of Codex streaming text, no MCP wait polling by @t3dotgg in pingdotgg/t3code#15033
* feat: agents can show HTML pages inline in threads by @t3dotgg in pingdotgg/t3code#15968
* chore(relay): match Alchemy to the PS-80 Postgres cluster by @juliusmarminge in pingdotgg/t3code#16228
* feat: agents ask the user for a secret through a private card by @juliusmarminge in pingdotgg/t3code#15907
* feat(web): see and stop pull request watches in the thread details card by @t3dotgg in pingdotgg/t3code#16235
* fix(server): ACP mode states with null descriptions are no longer dropped by @juliusmarminge in pingdotgg/t3code#16218
* fix(server): finished outbox rows and old PR cache files are pruned by @juliusmarminge in pingdotgg/t3code#16247
* fix(relay): releasing a tunnel that still has a connector no longer 500s by @juliusmarminge in pingdotgg/t3code#16250

## New Contributors
* @ScottN-PV made their first contribution in pingdotgg/t3code#15804

**Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261005.2689...v0.0.46-nightly.20261005.2702

Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261005.2702
github-actions Bot added a commit to davidvanderklay/t3code-flake that referenced this pull request Oct 6, 2026
## What's Changed
* chore(deps): upgrade Effect to stable 4.0.1 by @juliusmarminge in pingdotgg/t3code#16138
* fix(server): worktree threads survive a local branch named t3code by @juliusmarminge in pingdotgg/t3code#16167
* chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 by @juliusmarminge in pingdotgg/t3code#16170
* fix(web): match subagent timestamp fonts to chat by @StiensWout in pingdotgg/t3code#16151
* fix(web): wrap full status text in composer hover details by @UtkarshUsername in pingdotgg/t3code#16158
* ci: run the transfer report job on Blacksmith by @juliusmarminge in pingdotgg/t3code#16178
* fix(server): Stop also stops delegated tasks and pull request watches by @t3dotgg in pingdotgg/t3code#16002
* feat: native /goal for Codex and Claude, with goal status in the UI by @t3dotgg in pingdotgg/t3code#15592
* fix(server): name the cause of a failed git command by @walid-baharwal in pingdotgg/t3code#8645
* fix(server): PR watch wakes the agent when a bot edits its review comment by @Gigioxx in pingdotgg/t3code#15415
* feat(source-control): omit agent credits from PR merge messages by @juliusmarminge in pingdotgg/t3code#16192
* fix(clients): dropped connections say why in the client trace by @t3dotgg in pingdotgg/t3code#16200
* fix(server): PR watch reports a required check that first appears already passed by @ScottN-PV in pingdotgg/t3code#15804
* fix: a failed DPoP key load and a fresh maintenance read are no longer cached by @juliusmarminge in pingdotgg/t3code#15500
* fix: tool screenshots show as images, not base64 text by @t3dotgg in pingdotgg/t3code#16199
* docs(mcp): thread tools reach threads in any project by @t3dotgg in pingdotgg/t3code#15947
* fix(threads): threads watching a PR stay in Working instead of bouncing to the inbox by @t3dotgg in pingdotgg/t3code#16204
* chore(deps): bump cursor sdk and astro to clear vulnerable transitives by @juliusmarminge in pingdotgg/t3code#16214
* fix(server): PR sync waits out a GitHub rate limit pause instead of failing every PR by @t3dotgg in pingdotgg/t3code#16203
* feat(server): scheduled tasks can run on a webhook by @juliusmarminge in pingdotgg/t3code#15085
* feat(relay): forward webhook requests to the environment's tunnel by @juliusmarminge in pingdotgg/t3code#15086
* feat(mobile): create and copy webhook automations by @juliusmarminge in pingdotgg/t3code#15087
* feat(web): create webhook automations and inspect their deliveries by @juliusmarminge in pingdotgg/t3code#15088
* feat(relay,server,web,mobile): opt-in to hold webhooks while offline by @juliusmarminge in pingdotgg/t3code#15487
* fix(server): PR watches stop burning GitHub's rate limit and giving up by @t3dotgg in pingdotgg/t3code#16208
* fix(server): delegation sees a fixed provider without the app open by @t3dotgg in pingdotgg/t3code#16219
* feat: new branches use the shorter t3/ prefix by @t3dotgg in pingdotgg/t3code#16220
* perf: cheaper shell refreshes, one copy of Codex streaming text, no MCP wait polling by @t3dotgg in pingdotgg/t3code#15033
* feat: agents can show HTML pages inline in threads by @t3dotgg in pingdotgg/t3code#15968
* chore(relay): match Alchemy to the PS-80 Postgres cluster by @juliusmarminge in pingdotgg/t3code#16228
* feat: agents ask the user for a secret through a private card by @juliusmarminge in pingdotgg/t3code#15907
* feat(web): see and stop pull request watches in the thread details card by @t3dotgg in pingdotgg/t3code#16235
* fix(server): ACP mode states with null descriptions are no longer dropped by @juliusmarminge in pingdotgg/t3code#16218
* fix(server): finished outbox rows and old PR cache files are pruned by @juliusmarminge in pingdotgg/t3code#16247
* fix(relay): releasing a tunnel that still has a connector no longer 500s by @juliusmarminge in pingdotgg/t3code#16250

## New Contributors
* @ScottN-PV made their first contribution in pingdotgg/t3code#15804

**Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261005.2689...v0.0.46-nightly.20261005.2702

Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261005.2702
aorwall pushed a commit to aorwall/t3code that referenced this pull request Oct 7, 2026
* chore: docs, dev scripts and CI catch up with orchestration V2 (pingdotgg#15041)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): Claude V2 turns start on Windows with the default binary path (pingdotgg#15021)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(web): diff panel opens on all branch changes, not just uncommitted (pingdotgg#15005)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): threads stay working while Claude starts a wake turn (pingdotgg#15055)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): mod+alt+enter on an existing thread sends and opens a new thread (pingdotgg#15050)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(chat): sending on an older thread no longer jumps to the top (pingdotgg#15059)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: add bmdavis419 to triage exemptions (pingdotgg#15062)

* fix(server): runs no longer get stuck (pingdotgg#15048)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(usage): Codex Fast and Ultrafast now cost what they bill (pingdotgg#15101)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(clients): a dev server left running no longer says the thread is waiting (pingdotgg#15114)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): a thread that left a shell running shows its unseen completion (pingdotgg#14910)

Co-authored-by: Theo Browne <me@t3.gg>

* fix(web): mod+enter starts a new thread in the background again (pingdotgg#15060)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(usage): show cost by token type, speed, and model detail (pingdotgg#15108)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): agents can watch a PR and get woken when checks, reviews, or conflicts need them (pingdotgg#15057)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): keep delegated review rounds on the task API (pingdotgg#15115)

* fix(shared): classify workspace previews by literal filenames (pingdotgg#10311)

Co-authored-by: yashranaway <yashranaway@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(mobile): iOS threads no longer jump to the top (pingdotgg#14808)

* fix(web): reduce the gap above the draft composer (pingdotgg#15196)

* fix(mobile): a dev server left running no longer shows the waiting bolt (pingdotgg#15194)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): a Claude command you stop shows as interrupted (pingdotgg#14896)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): editors appear once a slow discovery scan finishes (pingdotgg#13917)

* fix(server): Claude threads no longer stay stuck in plan mode Claude entered itself (pingdotgg#15224)

* fix(mobile): show complete subagent details (pingdotgg#15189)

* fix(mobile): an expired Live Activity no longer leaves a second card (pingdotgg#15254)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test(web): remove redundant thread sort fallback tests (pingdotgg#15095)

Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>

* fix(web): thinking row after a failed tool expands the run's tool calls (pingdotgg#15056)

* perf(web): DOM changes no longer restyle the whole page (pingdotgg#15265)

* perf(usage): cut warm usage scans from seconds to milliseconds on large histories (pingdotgg#15149)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf(web): virtualize command palette results (pingdotgg#15266)

* chore(lint): flag :has() variants that restyle the whole page (pingdotgg#15274)

* fix(web): workspace card docks beside chat when the window is narrow (pingdotgg#14992)

Chat stays centered while the workspace card fits beside it with 32px to spare. When it does not fit, chat moves left only as far as needed, narrows only after it reaches the left padding, and the card becomes a popover below a 640px chat. The card is lighter: 280px wide, 32px rows, no section labels, no "Project folder" hint.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): render mermaid code blocks as diagrams (pingdotgg#15067)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* feat(web): Nightly tells you to get the beta mobile app (pingdotgg#15070)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test(server): ACP adapter tests no longer race the prompt settle (pingdotgg#15330)

Takes over pingdotgg#14876.

Co-authored-by: tris203 <admin@snappeh.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(usage): fold preview model IDs into the model they belong to (pingdotgg#15333)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(server): check RPC scopes in group middleware (pingdotgg#15324)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(mobile): beta Working section hides busy threads until they need you (pingdotgg#15346)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(settings): symlinked settings files stay linked when saved (pingdotgg#15009)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* fix(server): Stop ends a dev server left running before a provider switch (pingdotgg#15355)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): merged threads settle even after the agent wakes on its own (pingdotgg#15388)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): no-project drafts can switch machines (pingdotgg#15356)

* fix(web): highlight tool inputs and remove nested work log indentation (pingdotgg#15384)

* fix(server): restarts keep delegated tasks, queued threads, and stops intact (pingdotgg#15323)

* fix(web): sending past the resume banner compacts first (pingdotgg#15290)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(codex): resume archived native sessions (pingdotgg#15389)

* feat(web): morph composer and panel action icons (pingdotgg#14924)

Co-authored-by: maria-rcks <maria@kuuro.net>

* fix(web): subagents sent a follow-up show as running in Lineage (pingdotgg#15334)

Co-authored-by: scratchyone <11479077+scratchyone@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): clear stale chat action shortcuts (pingdotgg#15394)

* fix(orchestration-v2): restore earlier app agent transcript pages (pingdotgg#14104)

* fix(web): remove the square thread info panel shadow (pingdotgg#15069)

* fix(mobile): Android usage widget no longer sticks on "Loading widget" in release builds (pingdotgg#15142)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): size the model picker to its content (pingdotgg#15152)

Co-authored-by: saphid <saphid@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test(server): replay checks a Claude subagent's thread takes its reported model (pingdotgg#15022)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): subagent finish notifications look like subagent cards (pingdotgg#15281)

* fix(web): thread status dot has an accessible name (pingdotgg#14587)

* fix(web): legacy sidebar options button has a label (pingdotgg#14602)

* fix(web): imported themes keep switches and focus rings visible (pingdotgg#14498)

* fix(web): links to issues no longer strand the pull request viewer (pingdotgg#14242)

* fix(web): repo/task breadcrumb no longer bounces when the sidebar collapses (pingdotgg#15046)

* fix(web): Pull request panel entry works for linked PRs (pingdotgg#15061)

* fix(web): add context menu to draft threads in the sidebar (pingdotgg#10637)

* fix(web): keep sidebar branding and build pills from clipping at varying font sizes and zoom levels (pingdotgg#12141)

* fix(usage): model shares and order follow the selected metric (pingdotgg#11391)

* feat(web): sweep sidebar buttons to settle, un-settle, and wake threads (pingdotgg#14768)

Co-authored-by: maria-rcks <maria@kuuro.net>

* feat: retry a failed workspace preparation (pingdotgg#15326)

* fix(server): registry test stubs no longer outlive the test run (pingdotgg#15457)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* test(server): the registry's fake Claude CLI is a fixture file, not a generated string (pingdotgg#15463)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* refactor(clients): share opening a machine's No project folder (pingdotgg#14759)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* test(server): the git-ssh wrapper's fake SSH script is a fixture file, not a generated string (pingdotgg#15480)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* test(server): the ACP registry's fake npm is a fixture file, not a generated string (pingdotgg#15483)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* test(server): the ACP registry's fake uv is a fixture file, not a generated string (pingdotgg#15484)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* feat(clients): step a new thread to the next machine from the keyboard (pingdotgg#15391)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): promoting a draft thread no longer logs a React key warning (pingdotgg#15458)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* test(server): the text generation's fake Claude CLI is a fixture file, not a generated string (pingdotgg#15479)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* fix(mobile): keep dictation running across navigation behind an edge pill (pingdotgg#15502)

Co-authored-by: Bil0000 <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(client-runtime): relay disconnects no longer show as thread errors (pingdotgg#15470)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): subagent cards name the provider account (pingdotgg#15493)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): read paginated review replies when watching PRs (pingdotgg#15427)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(server): offer one-click provider updates for every install (pingdotgg#15416)

* fix(mobile): keep the dictation timer from shifting width (pingdotgg#15504)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(relay): T3 Connect links no longer fail on colliding prepared statements (pingdotgg#15411)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): sqlite transactions wait for the write lock instead of failing (pingdotgg#15488)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): unpin button shows the pin-off icon on hover (pingdotgg#15425)

* fix(mobile): make queued message removal tappable (pingdotgg#15417)

* fix(web): keep workspace panels below dialogs (pingdotgg#15454)

* fix(clients): Working section keeps its order while agents finish and wake (pingdotgg#15418)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(mobile): full-screen simulator viewer with on-demand controls (pingdotgg#15551)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(client-runtime): closing a busy stream no longer drops the connection (pingdotgg#15563)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): add shift-held pull request quick actions (pingdotgg#15549)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix: expanded tool calls show their output, empty ones don't expand (pingdotgg#15505)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(web): show device diagnostics before hub readiness (pingdotgg#15435)

* fix(web): open thread picker for unsent drafts (pingdotgg#15436)

* fix(desktop): print version before initializing the app (pingdotgg#15440)

* fix(server): recover claude skill scalar frontmatter (pingdotgg#15452)

* fix(server): keep settled threads asleep after restarts (pingdotgg#15604)

* fix(server): avoid inferring forgejo conflicts from mergeability (pingdotgg#15441)

* fix(web): dismiss hovered timeline tooltips on scroll (pingdotgg#15455)

* fix(server): discover Claude commands in each workspace (pingdotgg#15462)

* fix(web): restore project action preview opening (pingdotgg#15490)

* fix(desktop): keep titlebar controls inset when zoomed (pingdotgg#15496)

* fix(source-control): use the Azure DevOps mark (pingdotgg#15512)

* fix(web): open provider update details from both icons (pingdotgg#15501)

* fix(web): reveal sidebar actions for secondary hovering pointers (pingdotgg#15536)

* fix(markdown): preserve descriptive file-link labels (pingdotgg#15509)

* feat(clients): tool calls show the call above a muted result, without cards (pingdotgg#15506)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(chat): repair unclosed local file links in assistant responses (pingdotgg#15520)

* fix(server): match manual update commands to installed cli (pingdotgg#15539)

* fix(server): preserve staging during commit message generation (pingdotgg#15532)

* fix(mobile): Keep the last line of iOS markdown replies visible (pingdotgg#15737)

* feat(release): include nightly changelogs in Discord announcements (pingdotgg#15754)

* revert(web): remove automatic compaction before resume (pingdotgg#15771)

* fix(server): Claude threads no longer get stuck after background commands (pingdotgg#15770)

* fix(cli): reject accidental server launches (pingdotgg#15795)

* feat(clients): reach one environment over several routes (pingdotgg#15467)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(clients): learn an environment's LAN and tailnet addresses (pingdotgg#15468)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): share MCP tool presentation across providers (pingdotgg#15475)

Co-authored-by: Bil0000 <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* revert(chat): remove automatic file-link repair (pingdotgg#15824)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* perf(web): validate monospace fonts when selected (pingdotgg#15642)

* fix(server): expand home-relative media paths (pingdotgg#15618)

* fix(server): recover Linux runtime directory for device hub (pingdotgg#12402)

* fix(web): center icons in thread details icon buttons (pingdotgg#15669)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(mobile): back from an agent's thread returns to its parent (pingdotgg#15068)

* fix(dev): worktree setup never deletes a real env file (pingdotgg#15845)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): drop the duplicate Option import that breaks main CI (pingdotgg#15847)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(dev): write bootstrap warnings directly to stderr (pingdotgg#15865)

* fix(mobile): a message that fails to send now says why in the thread (pingdotgg#15807)

Co-authored-by: T3 Code Test <t3code-test@example.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): queue background notifications during active tools (pingdotgg#15892)

* refactor(server): share one keyed lock that releases idle keys (pingdotgg#15577)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): T3 MCP tools take explicit thread and project targets (pingdotgg#15219)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(desktop): V2 imports stashed prompts and drafts from the V1 profile (pingdotgg#15072)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): shell commands in the timeline are syntax highlighted (pingdotgg#15037)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>

* fix(mobile): upgrade Uniwind and remove local patch (pingdotgg#14597)

* fix(server): Stop ends a Codex command after its thread was settled (pingdotgg#15546)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): subagents no longer inherit parent pull-request links (pingdotgg#14918)

Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>

* fix(prs): queue fast actions and close batches by dragging (pingdotgg#15851)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* perf(prs): share concurrent github routing metadata probes (pingdotgg#15853)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(mobile): back from a finished subagent in the feed returns to its parent (pingdotgg#15844)

* fix(desktop): bound preview inspector retention and record renderer identity (pingdotgg#16032)

* fix(web): show fast mode beside reasoning as text (pingdotgg#16069)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(mobile): make the routes list match the other settings rows (pingdotgg#15958)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(threads): stop pull request watches when settling (pingdotgg#16095)

* feat(contracts): clients tolerate union members they don't know yet (pingdotgg#15951)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(contracts): project icons decode forward-compatibly instead of encoding a fallback (pingdotgg#16118)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Removed an unused helper from the Android push payload builder (pingdotgg#16116)

* perf(mobile): reduce shell cache encoding work (pingdotgg#15096)

* perf(mobile): defer audio recorder creation until dictation (pingdotgg#15248)

* feat(server): bump Antigravity ACP agent to 1.3.0 (pingdotgg#15746)

* feat(acp): support local provider commands (pingdotgg#16021)

* fix(server): honor submodule settings when creating worktrees (pingdotgg#15594)

* chore(deps): upgrade Effect to stable 4.0.1 (pingdotgg#16138)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): worktree threads survive a local branch named t3code (pingdotgg#16167)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (pingdotgg#16170)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): match subagent timestamp fonts to chat (pingdotgg#16151)

* fix(web): wrap full status text in composer hover details (pingdotgg#16158)

* ci: run the transfer report job on Blacksmith (pingdotgg#16178)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): Stop also stops delegated tasks and pull request watches (pingdotgg#16002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: native /goal for Codex and Claude, with goal status in the UI (pingdotgg#15592)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): use current SQL import in thread stop tests

* fix(server): name the cause of a failed git command (pingdotgg#8645)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): PR watch wakes the agent when a bot edits its review comment (pingdotgg#15415)

* feat(source-control): omit agent credits from PR merge messages (pingdotgg#16192)

* fix(clients): dropped connections say why in the client trace (pingdotgg#16200)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): PR watch reports a required check that first appears already passed (pingdotgg#15804)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: a failed DPoP key load and a fresh maintenance read are no longer cached (pingdotgg#15500)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: tool screenshots show as images, not base64 text (pingdotgg#16199)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs(mcp): thread tools reach threads in any project (pingdotgg#15947)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(threads): threads watching a PR stay in Working instead of bouncing to the inbox (pingdotgg#16204)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): bump cursor sdk and astro to clear vulnerable transitives (pingdotgg#16214)

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix(server): PR sync waits out a GitHub rate limit pause instead of failing every PR (pingdotgg#16203)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): scheduled tasks can run on a webhook (pingdotgg#15085)

* feat(relay): forward webhook requests to the environment's tunnel (pingdotgg#15086)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(mobile): create and copy webhook automations (pingdotgg#15087)

* feat(web): create webhook automations and inspect their deliveries (pingdotgg#15088)

* feat(relay,server,web,mobile): opt-in to hold webhooks while offline (pingdotgg#15487)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): PR watches stop burning GitHub's rate limit and giving up (pingdotgg#16208)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): delegation sees a fixed provider without the app open (pingdotgg#16219)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: new branches use the shorter t3/ prefix (pingdotgg#16220)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf: cheaper shell refreshes, one copy of Codex streaming text, no MCP wait polling (pingdotgg#15033)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agents can show HTML pages inline in threads (pingdotgg#15968)

Co-authored-by: Ben Davis <45952064+bmdavis419@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* chore(relay): match Alchemy to the PS-80 Postgres cluster (pingdotgg#16228)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: agents ask the user for a secret through a private card (pingdotgg#15907)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): see and stop pull request watches in the thread details card (pingdotgg#16235)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): ACP mode states with null descriptions are no longer dropped (pingdotgg#16218)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): finished outbox rows and old PR cache files are pruned (pingdotgg#16247)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(relay): releasing a tunnel that still has a connector no longer 500s (pingdotgg#16250)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(server,relay): webhook capabilities live in services, not handlers (pingdotgg#16232)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): a T3 Connect preferences save finishes even if the client disconnects (pingdotgg#16266)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(server): import service modules as namespaces, not aliased layers (pingdotgg#16267)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): log how long PR watches stay quiet before they end (pingdotgg#16262)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server,web): choose where new worktrees are created (pingdotgg#16231)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf(server): idle status polls and PR sweeps start fewer git processes (pingdotgg#16272)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf(server): PR watches spend ~90% fewer GitHub points by checking a 1-point fingerprint first (pingdotgg#16270)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(pull-requests): PR detail reads no longer drain the GitHub quota (pingdotgg#16280)

Takes over pingdotgg#13841. A PR query refreshes on the server's refresh signal only while something reads it, and the server shares detail, activity, and preview for 60 seconds, or 10 minutes once merged.

Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: layer variables are named layer or layerXyz (pingdotgg#16282)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(server): T3 Connect link capabilities live in a CloudLink service (pingdotgg#16265)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): sidebar drag and drop no longer snaps back (pingdotgg#16291)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): inline HTML renders no longer trap the thread's scroll (pingdotgg#16283)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(server): one module per service instead of Services/ and Layers/ folders (pingdotgg#16295)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(review): configure CodeRabbit in TypeScript (pingdotgg#16281)

* docs: put the Effect and web UI review rules in the docs (pingdotgg#16286)

* chore(lint): require a reason on every lint and type-checker suppression (pingdotgg#16294)

* refactor(relay): import HookInboxObject once, as a namespace (pingdotgg#16307)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): a rejected desktop-local credential is not retried every poll (pingdotgg#16273)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(desktop): the renderer's bootstrap token rotates every 12 hours (pingdotgg#16275)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): recover from a closed IndexedDB connection (pingdotgg#16311)

Co-authored-by: Lakshmi Tanmay <lakshmi@voltcrash.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(relay): stop forcing manual relay deploys by default (pingdotgg#13563)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(relay): measure the managed tunnel backlog (pingdotgg#13564)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(relay): clean up tunnels of hosts that never registered recovery (pingdotgg#13565)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf(relay): delete expired tunnels four at a time within a time budget (pingdotgg#13566)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(connect): tell users when an idle tunnel was removed (pingdotgg#13567)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs(relay): add the legacy tunnel cleanup rollout runbook (pingdotgg#13568)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(review): point CodeRabbit at the web UI conventions (pingdotgg#16324)

* chore(review): turn off CodeRabbit's docstring coverage check (pingdotgg#16328)

* refactor(server): CloudLink keeps only the link lifecycle; pure checks live beside it (pingdotgg#16340)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(server): CloudLink fails with its own errors; the connect routes map them to HTTP (pingdotgg#16341)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(server): replay guards stay in CloudLink (pingdotgg#16349)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): forks no longer merge into their upstream repo's project group (pingdotgg#16353)

Fixes pingdotgg#4880. Originally pingdotgg#14639 by @Project516.

Co-authored-by: Project516 <138796702+Project516@users.noreply.github.com>

* fix(server): stop the startup project sync from delaying the app window (pingdotgg#14912)

* fix(web): avoid blocking image preparation conversions (pingdotgg#13342)

* fix(server): return partial workspace index on timeout (pingdotgg#11500)

* fix(server): probe project favicon candidates concurrently (pingdotgg#12543)

* fix(observability): a failing trace disk no longer stalls the server (pingdotgg#13758)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): status polling no longer locks the git index (pingdotgg#14718)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf(shared): scan PATH once per command before spawning, not on every spawn (pingdotgg#12600)

* fix(server): main's startup auto-pull test compiles again (pingdotgg#16357)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): project favicons stop being rescanned every minute (pingdotgg#16206)

Favicons in ProjectEnrichmentService now keep for 15 minutes. Repository identity keeps its 1-minute TTL, so remote changes still show within a minute.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): Claude limits load again for users with large transcript histories (pingdotgg#16358)

The Claude capabilities probe now asks for usage with skipBehaviors, so it no longer scans every local transcript and misses its 4 s deadline. Takes over pingdotgg#14456.

Co-authored-by: Ashkaan <a@ashkaan.me>

* Add esthor to the list of GitHub users

* fix(server): caches and ids are written atomically (pingdotgg#16242)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): one-shot initializers no longer race (pingdotgg#16260)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): the PR cache sweep only removes real entry files (pingdotgg#16285)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: keep one copy each of undici 8 and ws 8 (pingdotgg#16211)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(shared): DrainableWorker keeps running after a failed item (pingdotgg#16223)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): metrics count interrupted work on the monotonic clock (pingdotgg#16207)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(web): import connection storage as a namespace in its test (pingdotgg#16315)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(contracts): trimmed IDs round-trip (pingdotgg#16300)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): main's settings, keybindings and session tests compile again (pingdotgg#16363)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(lint): catch known tags with Effect.catchTags (pingdotgg#16361)

* fix(observability): T3 Connect tracing stops at the relay boundary (pingdotgg#16314)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(relay): error and deadline responses carry CORS headers (pingdotgg#16253)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): bring back the live shimmer on work log rows (pingdotgg#16372)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto (pingdotgg#16377)

* fix(relay): export traces through one tracer, one request span each (pingdotgg#16382)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(contracts): take the Moatless V2 backend into the upstream merge

Regenerate the threads.getShell fixture as a V2 row, decode it as the RPC
layer does, drop four UnsupportedMethodError entries the V2 backend now
serves, and reconcile docs/fork/gaps.md with soaplabs/moatless#1068.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(contracts): decode a Moatless V2 thread projection fixture

The fixture comes from the moatless feat/t3code-v2-timeline-and-sessions
branch and holds every timeline item kind it translates tool calls into,
its plans, and the provider rows that let a client steer a running turn.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* ci: run the contracts tests in the Typecheck workflow

Its Moatless fixtures are the one check that a backend response decodes
against the schemas the client reads, and the package is small enough for
the 4 CPU / 8 GiB runner.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* ci: run the contracts tests before the typecheck

The runner loses contact during pnpm typecheck, which skipped the
fixture decodes queued after it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(contracts): decode the V2 projection's node rows

Regenerated from soaplabs/moatless#1071 at ed50318e, which backs every
rootNodeId and nodeId with a node row.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(fork): narrow the V2 gap to what moatless#1071 still refuses

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Ben Davis <45952064+bmdavis419@users.noreply.github.com>
Co-authored-by: Igor Makowski <56691628+Mnigos@users.noreply.github.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: yashranaway <yashranaway@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Noé <znoraka@gmail.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Jake Leventhal <jakeleventhal@me.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Bob Fowler <bob@rjf.ca>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: tris203 <admin@snappeh.com>
Co-authored-by: Yordis Prieto <yordis.prieto@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: scratchyone <scratchywon@gmail.com>
Co-authored-by: scratchyone <11479077+scratchyone@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: Alex Southwell <saphid@gmail.com>
Co-authored-by: saphid <saphid@users.noreply.github.com>
Co-authored-by: Ryan Ilano <ryanilano@users.noreply.github.com>
Co-authored-by: Argo <126553318+argofowl@users.noreply.github.com>
Co-authored-by: eimexdev <130890337+eimexdev@users.noreply.github.com>
Co-authored-by: Mike Olson <mwolson@member.fsf.org>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com>
Co-authored-by: AKolenda <akole779@mtroyal.ca>
Co-authored-by: T3 Code Test <t3code-test@example.com>
Co-authored-by: Hubert Bieszczad <48803618+Brentlok@users.noreply.github.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: Kriday Dave <technocratix902@gmail.com>
Co-authored-by: Dipangshu Roy <57279309+Droyder7@users.noreply.github.com>
Co-authored-by: Rahul Mishra <blankparticle@gmail.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <75276669+Gigioxx@users.noreply.github.com>
Co-authored-by: Scott Norteman <snorteman@gmail.com>
Co-authored-by: Erik Thorelli <ethorelli@gmail.com>
Co-authored-by: Lakshmi Tanmay <lakshmi@voltcrash.com>
Co-authored-by: Project516 <138796702+Project516@users.noreply.github.com>
Co-authored-by: Michel Liao <107891771+Michel-Liao@users.noreply.github.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: ahalekelly <7078138+ahalekelly@users.noreply.github.com>
Co-authored-by: SkiTee3000 <39069192+SkiTee3000@users.noreply.github.com>
Co-authored-by: Ashkaan <a@ashkaan.me>
Co-authored-by: soap-agentops[bot] <310870250+soap-agentops[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:XXL 1,000+ changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant