feat: AI Agents - #1025
Draft
nimish-ks wants to merge 90 commits into
Draft
feat: AI Agents#1025nimish-ks wants to merge 90 commits into
nimish-ks wants to merge 90 commits into
Conversation
nimish-ks
marked this pull request as draft
September 20, 2026 09:38
Loads the Agent service definitions in api/utils/agent_config/services/v1 (AWS and PostgreSQL), validates each one when the module is imported, fills in defaults, and publishes the capabilities the CLI negotiates against when a session opens.
Secret fields of an Integration Credential are now write-only. The API returns only the non-sensitive fields (hosts, IDs, regions) plus the names of the stored secrets; leaving a secret blank on edit keeps the stored value. Changing a field that decides where a secret is sent (for example a Postgres host or Vault address) requires re-entering the secret. The AWS External ID gets a Generate/Regenerate action with copy, since the stored value can no longer be shown. Credential updates also check the revision the editor started from, cap the name at 64 characters, validate PostgreSQL fields, move PostgreSQL Agent Connections along with their credential, and refresh live Agent sessions so rotated secrets reach running agents. A credential used by an Agent Connection can't be deleted.
REST API under /v1/agents/ used by the Phase CLI proxy: open, refresh, discover, rotate and revoke sessions, service capabilities and context, proxy activity events, and Agent requests (asking a human to set up or replace a credential). GraphQL queries and mutations back the console: Agents, Workflows, memberships, Connections, grants, tokens, sessions, requests and the activity log. Both live in the open-source tree (api/views/agents, backend/graphene/agents). Sessions last an hour per refresh and at most a day.
The GraphQL SSO middleware finds the organisation from resolver arguments. It now recognises the Agent argument names, Agent session UIDs and Agent tokens, so Agent operations are held to the organisation's SSO requirement. A test fails if any Agent mutation takes no argument that resolves to an organisation.
Removing a member through the REST API, deactivating them through SCIM, or deleting their account now revokes the Agent tokens and sessions they created and their Agent memberships. Members are still soft-deleted.
Every permission section offers the same read/create/update/delete columns, so PermissionSection owns that list instead of each dialog passing it in.
ProviderCredentialCard has no importers since the integrations page moved to the credentials table, and asyncDraftGuard's test outlived its module.
Tests that touch the database (the Agent and sealed-credential tests) need Postgres. The test job now starts a Postgres service container, the same image as the dev compose, which GitHub discards when the job ends. Mocked tests are unaffected, and every migration is applied on each run.
Creating the test database runs migrate, and its post_migrate hook schedules the licence checker as an RQ job, which needs a Redis-compatible server. The test job now starts Valkey 7.2, the release that forked from the Redis 7.2 the compose files run. The Django cache stays in memory.
The server keypair is derived from SERVER_SECRET as hex. conftest set it twice with setdefault, so the first, non-hex value won and the valid 64-character default further down never applied. The database-backed Agent and credential tests are the first to derive the real keypair; the dev env supplies a real secret, which hid this locally.
nimish-ks
force-pushed
the
feat--agents
branch
from
September 25, 2026 15:12
54a096a to
7eb0f77
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds Agents: AI coding agents (Claude Code, Codex, Cursor, and others) can use an organisation's Integration Credentials through the Phase CLI proxy without ever seeing the real secrets. The agent is handed decoy values; the proxy swaps in the real credential on the way out and reports what it did back to the console.
This PR is the console side: data model, APIs, access control and UI. AWS and PostgreSQL are the first supported services.
Backend
0141_agents:Agent,AgentWorkflow,AgentMembership,AgentWorkflowMembership,AgentConnection,AgentWorkflowGrant,AgentToken,AgentSession,AgentDecoy,AgentRequest,AgentEvent. It also addsProviderCredentials.revision(backfilled per row) and three audit-log resource types.api/utils/agent_config): JSON definitions for AWS and PostgreSQL. Each definition is validated when the module loads, and the registry publishes the capabilities a CLI must support./v1/agents/) for the CLI proxy:agent_permissionssection.Integration credentials
Frontend
/[team]/integrations/credentialsis now/[team]/integrations, and the tab is renamed "Integrations". A temporary redirect keeps old links working, including query strings.Reviewer notes
Agents
permissions), app (app_permissions) and agent (agent_permissions).Agents,AgentConnectionsandAgentRequestsare organisation-level.AgentWorkflows,AgentMemberships,AgentTokensandAgentSessionsare agent-level, which leaves room for team-owned Agents later. Seepermission_key_forinapi/utils/access/roles.py.agent_permissionsis optional when creating or updating a role, so existing API clients keep working. A custom role without it grants nothing within Agents. Managed roles come from the Python templates, so no data migration is needed; theirmeta.versionwas bumped.AgentSessions: createplus assignment to that Workflow; Owner and Admin don't need the assignment. Both are re-checked each time credentials are handed to a running session. There is no separateexecutepermission.IsIPAllowedcheck as the rest of the API. The only change is that Agent tokens now resolve to their organisation (3 lines inapi/utils/access/middleware.py, with a test).ee/:api/views/agents/backend/graphene/agents/api/utils/agent_config/services/v1/*.json_same_text_id()inapi/models.pybacks the checks that related Agent rows belong to the same organisation or Workflow. IDs areTextField(default=uuid4), so an unsaved object's id is aUUIDwhile a loaded one is astr, and plain==would say they differ.Integration credentials
api/services.pylists itsnon_sensitive_credentials(shown and editable) andendpoint_credentials(fields that decide where the secret is sent). Every other field is sealed. The frontend reads the same lists from the API (utils/syncing/general.ts).Integrations page
frontend/next.config.js. The docs still use the old "Third-party credentials" wording; update them, then remove the redirect.