openclaw/docs/plugins
RoboClaw 6046d4fcb6
feat: use MCP plugin apps across conversations and workspace files (#161747)
* feat: use MCP plugin apps across conversations and workspace files

Extend the opt-in MCP Apps host with discovery and entrypoints, settings, rich forms, scoped file editing, multimodal context, deep links, and native Codex session preparation. Preserve existing requester, approval, runtime, and file authority owners.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix: keep app context compact and review large tool payloads

Reuse the canonical bounded plugin approval preview without rejecting otherwise valid large App arguments. Keep the same one-shot approval and live-authority gates. Bound context-strip icons and scrolling so attachments leave the composer usable.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix: reveal pending input above fullscreen MCP apps

Keep App fullscreen rendering in the existing browser top layer and return to inline for same-conversation questions or approvals without replacing the iframe. Consolidate host-context, resource, and input notifications under the existing bridge lifetime.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test: preserve full attempt inputs in native assignment fixtures

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix: release session access when MCP app launch preparation fails

Preserve the upstream optional ifMatch contract and document unconditional-save semantics explicitly.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): defer question controls and preserve canonical keyboard values

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(mcp): preserve app authority through startup and user turns

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(codex): share native app startup across concurrent discoveries

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* docs(mcp): explain native app prompting and request limits

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* feat: use MCP plugin apps across conversations and workspace files

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: f2f8d735-c1ac-4a0d-84f3-1576113c1baf

* fix(mcp): keep form contracts and test helpers with their owners

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* feat: use MCP plugin apps across conversations and workspace files

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 2513c3ef-4af8-4722-b802-ffa426df486a

* fix(codex): revalidate MCP App authority before native retries

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(ui): provide chat identity fixture context dependencies

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* feat: use MCP plugin apps across conversations and workspace files

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 85c132dc-d926-46ca-b57e-2d9e01f15487

* fix: integrate MCP app owners with current main

* fix(gateway): accept option labels from installed clients for rich forms

* chore(format): anchor the native apps formatter ignore

* perf(ui): load the MCP app link parser on demand

Keep startup click interception parser-free and capture the normalized href before lazy navigation. Preserve ordinary, modified and download links; drop malformed plugin links and cancel pending navigation on disposal. Router/parser proof: 17 tests passed in 4.50s wall. Startup gzip: 374086 -> 373613 B; 159 B still above the unchanged 373454 B limit.

* perf(ui): register MCP app English with lazy consumers

Move the MCP App catalog out of startup English and register it synchronously at every consumer. Keep the shared namespace anchor and host catalog composition so all text and source order remain byte-identical. i18n verification passes without baseline changes. Startup gzip: 373613 -> 373103 B, 351 B below the unchanged 373454 B limit.

* fix(ui): intercept only well-formed MCP app links

Require the plugin/app/tool shape before cancelling browser navigation so ordinary ChatGPT plugin pages keep their default behavior. Preserve lazy strict parsing and accepted native and web app links.

* fix(gateway): watch MCP app files directly so loaded macOS hosts still notify

Watch the bound file to avoid FSEvents directory event drops under load. Re-arm on atomic replacement, retry ENOENT once on the next immediate turn, and retain subscription authority and cleanup. Cover replacement followed by a plain write through the registered resource routes.

* fix(gateway): use the errno guard when rearming MCP app watches

Use the shared filesystem error guard instead of an unchecked type assertion. Keep the single immediate ENOENT retry and all subscription behavior unchanged.

* fix(codex): read the canonical MCP transport field

Main migrates MCP transport aliases before runtime (#162256) and retired the SDK re-export of the alias resolver, so the native app catalog reads the canonical server.transport field the same way the agentsapi plugin does.

* fix(gateway): keep MCP app file subscriptions alive across rename gaps

Keep resource subscriptions alive while editors move the old file aside before installing its replacement. Poll missing paths at 250 ms, return to the inode watcher when the file reappears, and release polling on subscription close. Recheck after polling registration to cover replacement before its first stat; share the rearm guard so late callbacks cannot leak watchers.

* test(codex): type the rooted thread policy support from attempt fixtures

The rooted policy support that main added types its lifecycle input from the raw thread signature, while this branch's binding fixtures carry full attempt params. Derive it from the shared attempt-thread fixture type, as the sibling policy-refresh support already does.

* test(ui): exercise the MCP app link probe through the click boundary

The eager link probe was exported only for its unit test, which the production dead-export scan rejects. Keep it module-private and assert the same accepted and rejected links through real click interception.

* style(lint): clear MCP app lint errors

CI run 36988865432 jobs check-lint-core-1 and check-lint-core-2 rejected shadowed stat callback variables, a returning Promise executor, and reassigned projection parameters. Rename the inner variables and use local projection bindings and an executor block without changing behavior.

* test(agents): align bundle MCP fixture ownership

CI run 36988865432 job checks-node-changed-compact-large-14 failed seven merge cases because the fixture omitted the loader-required pluginIdsByServer map. Type the fixture against the producer contract and verify ownership survives only for unshadowed enabled bundle servers, preserving the migrated transport behavior.

* fix(auto-reply): register turns before MCP context leasing

CI run 36988865432 job checks-node-changed-compact-large-33-2 exposed an asynchronous MCP lease before synchronous run registration. Prepare App context after ownership registration and image admission, revalidate requester authority around the lease, and retain commit and rollback settlement with the execution outcome owner.

* test(gateway): admit MCP shutdown requests through current policy

CI run 36988865432 job checks-node-changed-compact-large-9 timed out because the fixture ignored an admission rejection before its upstream call. Publish matching Gateway and runtime config, create the session through its RPC owner, and observe early request settlement while preserving all shutdown ordering and cleanup assertions.

* refactor(apple): drop the label-only question toggle

Periphery flagged toggleOption(questionID🏷️) as dead: production selects by canonical value since the rich-form change, and only tests still called the label overload. Tests now toggle by value; the ambiguous-label case becomes an unknown-value no-op.

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-10-02 07:02:35 -05:00
..
architecture-internals refactor(plugin-sdk)!: retire unused command-auth, discord, and telegram-account facades (#163366) 2026-10-02 02:09:07 -07:00
codex-harness feat: use MCP plugin apps across conversations and workspace files (#161747) 2026-10-02 07:02:35 -05:00
codex-harness-reference feat(codex): request Ultrafast by default when the catalog advertises it (#163320) 2026-10-02 06:53:00 +00:00
codex-harness-runtime fix(codex): stop replaying diagnostic-log notices in chat (#161657) 2026-09-30 19:51:11 -07:00
google-meet feat(meetings): add durable participation foundation (#152327) 2026-09-25 14:28:23 -07:00
hooks test(config): author canonical agent rosters in fixtures and docs examples (#163475) 2026-10-02 04:42:31 -07:00
manifest feat: back up to external disks and Cloudflare R2 with storage locations (#161913) 2026-10-01 02:05:44 -07:00
reference feat: back up to external disks and Cloudflare R2 with storage locations (#161913) 2026-10-01 02:05:44 -07:00
sdk-agent-harness test(config): author canonical agent rosters in fixtures and docs examples (#163475) 2026-10-02 04:42:31 -07:00
sdk-channel-plugins refactor(channels): share draft rotation and retirement policies 2026-09-30 18:18:22 -07:00
sdk-entrypoints fix: preview files in remotely hosted workspaces (#159895) 2026-09-27 22:47:43 -07:00
sdk-migration refactor(plugin-sdk)!: retire unused command-auth, discord, and telegram-account facades (#163366) 2026-10-02 02:09:07 -07:00
sdk-overview refactor(plugin-sdk)!: retire unused command-auth, discord, and telegram-account facades (#163366) 2026-10-02 02:09:07 -07:00
sdk-provider-plugins refactor(providers): deslop provider adapters (#162488) 2026-10-01 05:41:53 -07:00
sdk-runtime fix(storage): join WAL maintenance before database retirement (#162166) 2026-10-02 02:50:33 +00:00
voice-call refactor(voice-call): decode legacy call logs only in Doctor (#162538) 2026-10-01 05:30:36 -07:00
adding-capabilities.md
admin-http-rpc.md refactor: remove Tasks and TaskFlow runtime (#159179) 2026-09-27 10:40:29 -07:00
agentsapi.md fix(agentsapi): identify OpenClaw in API requests (#162426) 2026-09-30 22:28:53 -07:00
apple-fm.md docs: fix utility model migration links (#157441) 2026-09-30 17:00:40 -07:00
architecture-internals.md
architecture.md fix(plugins): preserve SDK host identity in deferred Bun imports (#163360) 2026-10-02 04:29:15 -05:00
beam.md perf(beam): reuse session catalog metadata between polls (#158394) 2026-09-25 15:43:31 -07:00
building-plugins.md chore(deps): refresh dependencies with seven-day cutoff (#158298) 2026-09-26 20:42:53 -07:00
bundles.md fix: remote MCP plugins fail to start in native agent sessions (#162376) 2026-10-01 16:43:44 -07:00
cli-backend-plugins.md
cloudflare.md feat: back up to external disks and Cloudflare R2 with storage locations (#161913) 2026-10-01 02:05:44 -07:00
codex-computer-use.md fix: update managed Codex catalog and protocol to 0.159.1 (#161446) 2026-10-01 17:12:45 -06:00
codex-harness-reference.md fix: keep Codex chats working during slow model discovery (#160363) 2026-09-28 11:43:38 -07:00
codex-harness-runtime.md fix(codex): restore persona on remote app-server connections (#162156) 2026-09-30 16:05:21 -07:00
codex-harness.md fix(codex): avoid startup app-server bursts for idle agents (#163129) 2026-10-02 09:30:25 +08:00
codex-native-plugins.md fix: update managed Codex catalog and protocol to 0.159.1 (#161446) 2026-10-01 17:12:45 -06:00
codex-supervision.md
community.md
compatibility.md fix(plugins): record unmet compatibility removal conditions (#163158) 2026-10-01 21:28:17 -05:00
copilot.md refactor(providers): deslop model-provider plugins third pass (#161162) 2026-09-29 05:03:39 -07:00
dependency-resolution.md perf(build): avoid redundant plugin inventory probes (#162384) 2026-09-30 23:46:49 -07:00
facetime-recovery.md
facetime.md
feature-plugins.md feat: return to Discord and Slack from session headers (#158742) 2026-10-01 18:52:16 -07:00
geolocation.md feat: let agents query online people and device activity (#159117) 2026-09-27 11:38:53 +00:00
github.md perf(github): share one two-second upstream budget across a preview (#161653) 2026-09-30 05:48:35 +00:00
google-meet.md
hooks.md fix(plugins): let session_end hooks read ended transcripts (#161451) 2026-09-30 16:33:04 -07:00
install-overrides.md
llama-cpp.md fix(setup): validate LM Studio and llama.cpp server URLs inline (#160720) 2026-09-28 21:36:22 -07:00
logbook.md
manage-plugins.md docs: clarify when plugin reload requires a restart (#157052) 2026-09-23 22:57:18 -07:00
manifest.md fix: plugin configuration rejects encoded schema reference separators (#161954) 2026-10-01 02:10:33 +08:00
meeting-plugins.md feat(slack-huddles): join Slack huddles as a signed-in Slack user (#159879) 2026-09-28 17:34:03 -07:00
memory-lancedb.md fix(memory): restore embeddings with Codex OAuth (#160878) 2026-10-01 17:53:09 -07:00
memory-wiki.md test(config): author canonical agent rosters in fixtures and docs examples (#163475) 2026-10-02 04:42:31 -07:00
message-presentation.md
oc-path.md
onepassword.md fix(onepassword): move pending authorization onto SQLite worker (#156000) 2026-09-23 11:24:06 -07:00
onnx.md
plugin-inventory.md feat: back up to external disks and Cloudflare R2 with storage locations (#161913) 2026-10-01 02:05:44 -07:00
plugin-permission-requests.md refactor(compat): deslop expired approval timeout contract (#163333) 2026-10-02 00:16:29 -07:00
reference.md feat: back up to external disks and Cloudflare R2 with storage locations (#161913) 2026-10-01 02:05:44 -07:00
sdk-agent-harness.md
sdk-channel-inbound.md fix: preserve bot reply context and enable bot messages by default (#157091) 2026-09-24 07:58:36 +00:00
sdk-channel-ingress.md docs: fix 12 concrete defects from the ux audit remainder (#144128) 2026-09-25 17:28:14 +08:00
sdk-channel-outbound.md refactor(plugin-sdk)!: retire deprecated compatibility facades (#162333) 2026-10-01 04:12:01 -07:00
sdk-channel-plugins.md feat: return to Discord and Slack from session headers (#158742) 2026-10-01 18:52:16 -07:00
sdk-entrypoints.md feat: use MCP plugin apps across conversations and workspace files (#161747) 2026-10-02 07:02:35 -05:00
sdk-migration.md refactor(plugin-sdk)!: retire deprecated compatibility facades (#162333) 2026-10-01 04:12:01 -07:00
sdk-overview.md feat: back up to external disks and Cloudflare R2 with storage locations (#161913) 2026-10-01 02:05:44 -07:00
sdk-provider-plugins.md fix: restart abandoned provider sign-ins with shared OAuth handling (#160574) 2026-09-28 19:40:37 -07:00
sdk-runtime.md fix(plugins): distinguish settled disposal faults from retained cleanup 2026-09-30 17:36:35 -07:00
sdk-setup.md chore(deps): refresh dependencies with seven-day cutoff (#158298) 2026-09-26 20:42:53 -07:00
sdk-subpaths.md refactor(plugin-sdk)!: retire unused command-auth, discord, and telegram-account facades (#163366) 2026-10-02 02:09:07 -07:00
sdk-testing.md fix(test): remaining suites time out on their first test or hook while compiled worker subprocesses prepare (#163254) 2026-10-02 03:37:13 -05:00
session-share.md perf(session-share): keep chat catalog startup responsive (#156400) 2026-09-23 11:49:31 +00:00
slack-huddles.md feat(slack-huddles): join Slack huddles as a signed-in Slack user (#159879) 2026-09-28 17:34:03 -07:00
team-reports.md perf(team-reports): keep collection off the Gateway event loop (#159101) 2026-09-26 12:32:24 -07:00
teams-meetings.md
tool-plugins.md feat(gateway): let operators disable client file and image uploads (#158567) 2026-09-27 18:40:36 -07:00
typesafe.md fix(decisions): preserve fallback on provider input rejection (#156746) 2026-09-24 00:45:00 +00:00
vault.md
voice-call.md
workboard.md feat(workboard): add a people view filter to Sessions boards (#162283) 2026-09-30 21:02:35 -07:00
zalouser.md
zoom-meetings.md