Skip to content

Rename saved OAuth connectors to integrations - #391

Merged
kentcdodds merged 2 commits into
mainfrom
rename-oauth-connectors-to-integrations
May 7, 2026
Merged

kentcdodds merged 2 commits into
mainfrom
rename-oauth-connectors-to-integrations

Conversation

@kentcdodds

@kentcdodds kentcdodds commented May 7, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Rename saved OAuth/user config capabilities, storage/entity prefixes, and search result types from connector to integration (integration_get/list/save/delete, _integration:*, :integration).
  • Update /connect/oauth and /connect/secret UI/API flows to use integration wording and integration secret-binding metadata.
  • Refresh runtime helper/search/server instructions, end-user guides, and focused tests while preserving remote connector protocol/routes/docs.
  • Address AI-reviewer feedback by validating new integration creation errors and covering the new-create path in tests.

Tests

  • npx vitest run --project node-unit packages/worker/src/mcp/capabilities/values/integration-save.node.test.ts packages/worker/src/mcp/tools/search.node.test.ts packages/worker/src/mcp/tools/search-format.node.test.ts packages/worker/src/app/handlers/connect-secret.node.test.ts packages/worker/src/app/handlers/account-secrets.node.test.ts packages/worker/client/routes/connect-oauth.node.test.ts packages/worker/src/mcp/execute-modules/codemode-utils.node.test.ts packages/worker/src/mcp/execute-modules/authenticated-fetch.node.test.ts
  • npm run typecheck
  • npm run lint
  • Browser smoke test for /connect/oauth and /connect/secret?...&integration=linear: integration-oauth-secret-ui-smoke.mp4
Open in Web Open in Cursor 

Summary by CodeRabbit

  • Documentation

    • Replaced “connector” with “integration” across guides, examples, and API docs; clarified OAuth/integration naming and usage.
  • New Features

    • Search, OAuth connect UI, and secret binding flows now surface and reference saved integrations (including an optional integration query param).
  • Bug Fixes

    • Architecture guidance documents clarified host allowlist enforcement for OAuth flows and tightened host-validation guidance to avoid leaking tokens in errors.

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@coderabbitai

coderabbitai Bot commented May 7, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This PR systematically refactors "connector" terminology to "integration" terminology throughout the codebase. It updates documentation guides, replaces connector-specific type definitions and handlers with integration-equivalents, migrates MCP capabilities from connector_* to integration_*, updates search entity types and formatting, and refactors runtime execution helpers to use integration-based OAuth configuration and host allowlisting. All changes preserve the underlying behavior while aligning naming conventions across the system.

Changes

Connector-to-Integration Terminology Refactoring

Layer / File(s) Summary
Documentation and Guides
docs/contributing/architecture/index.md, docs/guides/*, docs/use/*
Guide and architecture documentation updated to reference "integration" instead of "connector" in OAuth flows, naming conventions, bootstrap processes, and API documentation.
Integration Type Definitions and Helpers
packages/worker/src/mcp/capabilities/values/integration-shared.ts
Core type schemas IntegrationConfig, IntegrationSaveInput, and utility functions buildIntegrationValueName, normalizeIntegrationConfig, mergeIntegrationConfig, parseIntegrationConfig, parseIntegrationJson defined, replacing connector equivalents.
MCP Value Capabilities
packages/worker/src/mcp/capabilities/values/integration-*.ts, packages/worker/src/mcp/capabilities/values/domain.ts
MCP domain capabilities for integration_save, integration_get, integration_list, integration_delete created using shared integration types and value name builders, replacing connector_* capabilities.
Integration Host Allowlist Enforcement
packages/worker/src/mcp/execute-modules/integration-host-allowlist.ts
IntegrationHostNotAllowedError, getIntegrationAllowedHosts(), and assertIntegrationHostAllowed() defined for OAuth token attachment validation.
OAuth Connect Routes and Helpers
packages/worker/client/routes/connect-oauth.tsx, packages/worker/client/routes/connect-secret-errors.ts
Routes updated to use StoredIntegrationConfig, integration value naming, mergeConnectOauthConfig with storedIntegration, and integration-specific error formatting.
Secret Binding Handlers
packages/worker/client/routes/connect-secret.tsx, packages/worker/src/app/handlers/account-secrets.ts, packages/worker/src/app/handlers/connect-secret.ts
Handlers updated to process integration query parameters, bind secrets to integration names via _integration-secret: prefix, and use integration-specific error messages.
Search Entity Types and Formatting
packages/worker/src/mcp/tools/search-format.ts
SearchEntityType, SlimSearchMatch, SearchEntityDetail updated to use 'integration' kind with integrationName field and integration-specific usage helpers.
Search Candidate Generation
packages/worker/src/mcp/tools/search.ts
Search module updated to build integration search candidates from persisted values using integration name parsing, config extraction, and integration-specific document generation.
Codemode and Runtime Execution Helpers
packages/worker/src/mcp/execute-modules/codemode-utils.ts, packages/worker/src/mcp/execute-modules/authenticated-fetch.node.test.ts
Execute module helpers updated to read integration_get capability, refresh tokens using integration config, enforce integration host allowlisting, and generate integration-based prelude code.
Tool Definitions and Server Instructions
packages/worker/src/mcp/capabilities/coding/kody-official-guide.ts, packages/worker/src/mcp/server-instructions.ts, packages/worker/src/mcp/tools/execute.ts, packages/worker/src/agent-turn/tools.ts
Tool descriptions and server instruction templates updated to reference integration_get/integration_list and integration entity types.
Test Suite Updates
packages/worker/client/routes/connect-oauth.node.test.ts, packages/worker/src/app/handlers/*.node.test.ts, packages/worker/src/mcp/**/*.node.test.ts
Test files updated to use integration terminology, integration value name builders, integration config fixtures, and integration-specific error expectations.
CSS Formatting Normalization
packages/worker/public/mcp-apps/kody-ui-utils.css
Minor CSS reformatting with unquoted attribute selectors and consistent indentation; no functional style changes.

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant ExecuteSandbox
  participant Codemode as "codemode.integration_get"
  participant Refresh as "refreshAccessToken"
  participant Fetch as "createAuthenticatedFetch"
  participant Allow as "assertIntegrationHostAllowed"

  Client->>ExecuteSandbox: run package requiring OAuth request
  ExecuteSandbox->>Codemode: integration_get(name)
  Codemode-->>ExecuteSandbox: IntegrationConfig
  ExecuteSandbox->>Refresh: refreshAccessToken(integration)
  Refresh-->>ExecuteSandbox: access_token
  ExecuteSandbox->>Fetch: createAuthenticatedFetch(url)
  Fetch->>Allow: assertIntegrationHostAllowed(integration, url)
  Allow-->>Fetch: allowed / IntegrationHostNotAllowedError
  Fetch-->>ExecuteSandbox: network request with Bearer token
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • kentcdodds/kody#130: Adds connector config helpers; this PR renames and refactors those helpers to integration equivalents.
  • kentcdodds/kody#313: Introduces host allowlist enforcement logic; this PR ports that enforcement into integration-based code paths.
  • kentcdodds/kody#139: Modifies search/value handling; this PR replaces connector handling with integration handling in the same search code areas.

Poem

🐰 "I hopped through docs and code tonight,

renamed connectors to make things right,
host checks guard the OAuth door,
search and tests all ask for more,
I nibble bugs and celebrate the light."

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 4.48% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title 'Rename saved OAuth connectors to integrations' accurately summarizes the primary change across the entire changeset—a systematic terminology and API update from connector-based to integration-based naming.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch rename-oauth-connectors-to-integrations

@kentcdodds
kentcdodds marked this pull request as ready for review May 7, 2026 22:27
@github-actions

github-actions Bot commented May 7, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-391.kentcdodds.workers.dev

Worker: kody-pr-391
D1: kody-pr-391-db
KV: kody-pr-391-oauth-kv

Mocks:

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/worker/src/mcp/capabilities/values/integration-save.ts (1)

64-78: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

integrationConfigSchema.parse() will throw an unhandled ZodError when required fields are absent for new integrations.

integrationSaveSchema (the capability's input schema) marks tokenUrl, flow, clientIdValueName, and accessTokenSecretName as .optional(). When an agent calls integration_save for the first time (no pre-existing record) and omits any of those fields, the integrationConfigSchema.parse(...) on line 67 throws a ZodError with no catch in scope. The MCP framework would receive this as an unexpected exception rather than a structured capability error.

Switching to safeParse allows returning a clear error:

🐛 Proposed fix
-			const integration = existingIntegration
-				? mergeIntegrationConfig(existingIntegration, args)
-				: normalizeIntegrationConfig(
-						integrationConfigSchema.parse({
-							name: args.name,
-							tokenUrl: args.tokenUrl,
-							apiBaseUrl: args.apiBaseUrl ?? null,
-							flow: args.flow,
-							clientIdValueName: args.clientIdValueName,
-							clientSecretSecretName: args.clientSecretSecretName ?? null,
-							accessTokenSecretName: args.accessTokenSecretName,
-							refreshTokenSecretName: args.refreshTokenSecretName ?? null,
-							requiredHosts: args.requiredHosts,
-						}),
-					)
+			let integration: ReturnType<typeof normalizeIntegrationConfig>
+			if (existingIntegration) {
+				integration = mergeIntegrationConfig(existingIntegration, args)
+			} else {
+				const newResult = integrationConfigSchema.safeParse({
+					name: args.name,
+					tokenUrl: args.tokenUrl,
+					apiBaseUrl: args.apiBaseUrl ?? null,
+					flow: args.flow,
+					clientIdValueName: args.clientIdValueName,
+					clientSecretSecretName: args.clientSecretSecretName ?? null,
+					accessTokenSecretName: args.accessTokenSecretName,
+					refreshTokenSecretName: args.refreshTokenSecretName ?? null,
+					requiredHosts: args.requiredHosts,
+				})
+				if (!newResult.success) {
+					throw new Error(
+						`Cannot create integration "${args.name}": missing required fields — ${newResult.error.issues.map((i) => i.path.join('.') + ': ' + i.message).join(', ')}`,
+					)
+				}
+				integration = normalizeIntegrationConfig(newResult.data)
+			}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/mcp/capabilities/values/integration-save.ts` around lines
64 - 78, The code calls integrationConfigSchema.parse(...) when building the new
integration which will throw an uncaught ZodError for missing optional fields;
change this to use integrationConfigSchema.safeParse(...) and, when safeParse
returns { success: false }, convert the validation errors into the capability's
structured error response (instead of letting the exception bubble) so new
integrations without required fields produce a clear, handled error; update the
block that sets integration (the ternary using existingIntegration,
mergeIntegrationConfig, and normalizeIntegrationConfig) to perform the safeParse
check before calling normalizeIntegrationConfig and handle the failure path
consistently with other MCP capability errors.
🧹 Nitpick comments (1)
packages/worker/src/mcp/capabilities/values/integration-save.node.test.ts (1)

119-168: ⚡ Quick win

Test suite only covers the upsert (existing record) path — new-creation path is unexercised.

All three tests merge into an existing _integration:spotify entry. There are no tests for:

  1. Creating a brand-new integration (no pre-existing stored value) with all required fields.
  2. Attempting to create a new integration with missing required fields (exposes the ZodError bug in the handler).

Adding these two cases would catch the issue identified in integration-save.ts and guard the new-creation path going forward.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/mcp/capabilities/values/integration-save.node.test.ts`
around lines 119 - 168, Add two tests for the "new-creation" path of
integrationSaveCapability: one that calls integrationSaveCapability.handler with
no pre-existing '_integration:spotify' in createValueTestDb and a full valid
payload (assert result.integration matches the input and that
testDb.entries.get('_integration:spotify') JSON contains the saved fields), and
a second that calls the handler with no pre-existing entry but an
invalid/missing required field (use the same Env and createMcpCallerContext
setup) and assert that the handler throws a ZodError (or the appropriate
validation error) rather than succeeding; place these tests alongside the
existing ones in integration-save.node.test.ts so the new-creation branch in
integration-save.ts and validation logic are exercised.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/worker/public/mcp-apps/kody-ui-utils.css`:
- Around line 10-13: Fix the Stylelint value-keyword-case violations in the
font-family declaration by normalizing casing and quoting where appropriate:
wrap custom font names with special characters/capital letters (e.g.,
SFMono-Regular) in quotes and ensure the generic family token is lowercase
(e.g., monospace) at the end of the list; update the font-family that currently
contains SFMono-Regular, Menlo, Monaco, Consolas to use quoted custom names and
a lowercase generic family to satisfy value-keyword-case.

---

Outside diff comments:
In `@packages/worker/src/mcp/capabilities/values/integration-save.ts`:
- Around line 64-78: The code calls integrationConfigSchema.parse(...) when
building the new integration which will throw an uncaught ZodError for missing
optional fields; change this to use integrationConfigSchema.safeParse(...) and,
when safeParse returns { success: false }, convert the validation errors into
the capability's structured error response (instead of letting the exception
bubble) so new integrations without required fields produce a clear, handled
error; update the block that sets integration (the ternary using
existingIntegration, mergeIntegrationConfig, and normalizeIntegrationConfig) to
perform the safeParse check before calling normalizeIntegrationConfig and handle
the failure path consistently with other MCP capability errors.

---

Nitpick comments:
In `@packages/worker/src/mcp/capabilities/values/integration-save.node.test.ts`:
- Around line 119-168: Add two tests for the "new-creation" path of
integrationSaveCapability: one that calls integrationSaveCapability.handler with
no pre-existing '_integration:spotify' in createValueTestDb and a full valid
payload (assert result.integration matches the input and that
testDb.entries.get('_integration:spotify') JSON contains the saved fields), and
a second that calls the handler with no pre-existing entry but an
invalid/missing required field (use the same Env and createMcpCallerContext
setup) and assert that the handler throws a ZodError (or the appropriate
validation error) rather than succeeding; place these tests alongside the
existing ones in integration-save.node.test.ts so the new-creation branch in
integration-save.ts and validation logic are exercised.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: c675a2ce-f20d-48d0-b859-106bb525526a

📥 Commits

Reviewing files that changed from the base of the PR and between aaa74fe and a4810b3.

📒 Files selected for processing (40)
  • docs/contributing/architecture/index.md
  • docs/contributing/packages-and-manifests.md
  • docs/guides/connect-secret.md
  • docs/guides/generated-ui-oauth.md
  • docs/guides/integration-backed-app-happy-path.md
  • docs/guides/integration-bootstrap.md
  • docs/guides/oauth.md
  • docs/guides/secret-backed-integration.md
  • docs/use/execute.md
  • docs/use/first-steps.md
  • docs/use/search.md
  • docs/use/secrets-and-values.md
  • packages/worker/client/routes/connect-oauth.node.test.ts
  • packages/worker/client/routes/connect-oauth.tsx
  • packages/worker/client/routes/connect-secret-errors.ts
  • packages/worker/client/routes/connect-secret.tsx
  • packages/worker/public/mcp-apps/kody-ui-utils.css
  • packages/worker/src/agent-turn/tools.ts
  • packages/worker/src/app/handlers/account-secrets.node.test.ts
  • packages/worker/src/app/handlers/account-secrets.ts
  • packages/worker/src/app/handlers/connect-secret.node.test.ts
  • packages/worker/src/app/handlers/connect-secret.ts
  • packages/worker/src/mcp/capabilities/coding/kody-official-guide.ts
  • packages/worker/src/mcp/capabilities/values/domain.ts
  • packages/worker/src/mcp/capabilities/values/integration-delete.ts
  • packages/worker/src/mcp/capabilities/values/integration-get.ts
  • packages/worker/src/mcp/capabilities/values/integration-list.ts
  • packages/worker/src/mcp/capabilities/values/integration-save.node.test.ts
  • packages/worker/src/mcp/capabilities/values/integration-save.ts
  • packages/worker/src/mcp/capabilities/values/integration-shared.ts
  • packages/worker/src/mcp/execute-modules/authenticated-fetch.node.test.ts
  • packages/worker/src/mcp/execute-modules/codemode-utils.node.test.ts
  • packages/worker/src/mcp/execute-modules/codemode-utils.ts
  • packages/worker/src/mcp/execute-modules/integration-host-allowlist.ts
  • packages/worker/src/mcp/server-instructions.ts
  • packages/worker/src/mcp/tools/execute.ts
  • packages/worker/src/mcp/tools/search-format.node.test.ts
  • packages/worker/src/mcp/tools/search-format.ts
  • packages/worker/src/mcp/tools/search.node.test.ts
  • packages/worker/src/mcp/tools/search.ts

Comment thread packages/worker/public/mcp-apps/kody-ui-utils.css Outdated
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants