Skip to content

Add personal API keys and agent access to user workflows - #54

Open
t8 wants to merge 1 commit into
mainfrom
feat/personal-api-keys
Open

t8 wants to merge 1 commit into
mainfrom
feat/personal-api-keys

Conversation

@t8

@t8 t8 commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Agents currently have to send users back to the website to register rigs and custom runtimes before submitting benchmarks. This adds personal API keys and a versioned HTTP API so an agent can complete the whole workflow after one setup step: create a key at /settings/api-keys, configure INTELINSIDE_API_KEY, and supply /docs/agents.md.

  • Covers catalog/profile discovery, rig and custom runtime management, result CRUD and atomic batches, confirmations/flags, and signed rig-photo uploads.
  • Shows new keys once, stores only hashes, supports permissions/expiry/revocation, and displays recent agent changes. Key management requires a verified browser session; personal keys cannot mint other keys.
  • Runs content operations under the existing authenticated-user RLS policies through a dedicated NOLOGIN/NOBYPASSRLS executor. Adds per-account rate limits, transactional idempotency receipts, and version checks for edits/deletions.
  • Generates the agent route/field documentation and OpenAPI reference from the validation contract. Reuses browser text moderation and links the new setup from the homepage/account menu while retaining PR-based ingestion.
  • Uses the existing Vercel/Supabase deployment. No MCP service, paid connector, or new user fee.

Validation

  • HTTP/database integration tests cover the eleven-node fleet → custom build → result batch workflow, retries, atomic rollback, ownership violations, hidden results, stale edits, result-verification reset, permission restrictions, photo allocation/attachment, expiry, revocation, and rate limits.
  • Playwright drives real key creation in the settings page, uses that key to register a fleet/build and submit/retry results, then revokes it and verifies HTTP 401. Desktop/mobile layouts and directly readable docs are checked; screenshots and failure traces are CI artifacts.
  • All migrations also passed on native PostgreSQL 17 under a non-superuser migration role, including the limited executor, idempotency, and browser-role RPC denial.
  • All 39 Node tests and both Playwright scenarios pass locally, along with typecheck, production build, catalog validation, and generated-documentation checks. A new PR workflow repeats the browser/API checks.

Deployment and review

Apply supabase/migrations/20260928090000_personal_api_keys.sql and configure a server-only SUPABASE_SECRET_KEY in Vercel (legacy SUPABASE_SERVICE_ROLE_KEY also works). The API reuses VITE_SUPABASE_URL or accepts SUPABASE_URL. Missing configuration fails closed with HTTP 503. Production data and deployment secrets have not been changed.

Review frontend/src/agent-api/server.ts for authentication/routing and the migration's agent_request / agent_dispatch boundary for authorization. docs/AGENT_API_OPERATIONS.md explains the role/grant design, deployment order, rollback, and exact test commands.

Local integration tests use the real handlers, migrations, and Postgres engine; hosted Auth verification and Storage transport are stand-ins. A staging smoke test with real GitHub sign-in and Storage is still required after configuration. Already issued signed upload URLs remain valid for their two-hour lifetime after key revocation, but cannot attach an image to a rig without a valid key.

Vercel preview deployed successfully, but it requires Vercel SSO, so anonymous deployed-route smoke tests could not pass its access gate.

This branch is based directly on main and does not depend on the Inkling catalog/results or rig-image PRs.

@vercel

vercel Bot commented Sep 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
intelinside Ready Ready Preview Sep 27, 2026 11:05pm UTC

Request Review

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
No result files to import.

Site / sign up · Workflow details and retry

This branch was successfully deployed

1 active deployment
Preview — 62846b8d Deployed Sep 27, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant