Problem
The new Plugins directory lists every integrations.sh service and lets a bot connect to any of them. The first version had server-side gaps: a saved API key was not tied to the MCP endpoint it was approved for, OAuth services reported connected when access had failed or the key was removed, a catalog refresh that failed while offline left the directory broken until restart, and names, search results, and the featured list were rough.
Goal
- A saved MCP credential is bound to the approved endpoint. It is never sent to a different endpoint, it is removed with its server, and reuse only happens on the same endpoint.
- Access state is real: an OAuth failure or a removed key shows as not connected, using access health rather than "a key exists".
- After an offline or failed refresh, the directory recovers on the next periodic refresh, and concurrent searches during recovery share one refresh.
- Service names read as product names, search ignores noise, and each card notes the service's capabilities.
- Six featured services, in order: Gmail, Composio, Context.dev, Google Calendar, Notion, GitHub. Cards show their discovery badges.
Acceptance criteria
How to verify
vp test run apps/server/src/integrations
Then, on an isolated dev server from the branch, open Plugins, connect a featured key-based service, remove its key, and confirm the card returns to not connected. Repeat with the network off during a refresh and confirm the directory recovers.
Out of scope
- The Plugins page layout and design (owned by the parent integrations.sh work)
- Choosing between Executor and a generic OpenAPI tool for integration calls
Context
- Work lives on the local branch
cos/integrations-sh on Leo's machine (17 commits ahead of main, not pushed, no PR). The server fixes are commit 36ea9e212 fix(server): bind integration keys and report real access. Later commits on the same branch tidy the web directory, strip markup from integrations.sh descriptions, label Composio's card as an API key, and say plainly when sign-in services don't reach OpenCode bots.
- Verification on 2026-10-05: 84 focused tests in nine suites passed; targeted lint and server and web
tsgo passed. Before the fix, the same run reproduced 13 regression failures. Not checked: merged live clients and real account sign-in, which belong to the parent task because the worker was told not to start dev servers.
- Code:
apps/server/src/integrations/ (IntegrationsCatalog.ts, model.ts with the featured list). User docs: docs/user/plugins.md on the branch.
Created with Claude Opus 5.5 in Claude Code.
Problem
The new Plugins directory lists every integrations.sh service and lets a bot connect to any of them. The first version had server-side gaps: a saved API key was not tied to the MCP endpoint it was approved for, OAuth services reported connected when access had failed or the key was removed, a catalog refresh that failed while offline left the directory broken until restart, and names, search results, and the featured list were rough.
Goal
Acceptance criteria
How to verify
vp test run apps/server/src/integrationsThen, on an isolated dev server from the branch, open Plugins, connect a featured key-based service, remove its key, and confirm the card returns to not connected. Repeat with the network off during a refresh and confirm the directory recovers.
Out of scope
Context
cos/integrations-shon Leo's machine (17 commits ahead ofmain, not pushed, no PR). The server fixes are commit36ea9e212fix(server): bind integration keys and report real access. Later commits on the same branch tidy the web directory, strip markup from integrations.sh descriptions, label Composio's card as an API key, and say plainly when sign-in services don't reach OpenCode bots.tsgopassed. Before the fix, the same run reproduced 13 regression failures. Not checked: merged live clients and real account sign-in, which belong to the parent task because the worker was told not to start dev servers.apps/server/src/integrations/(IntegrationsCatalog.ts,model.tswith thefeaturedlist). User docs:docs/user/plugins.mdon the branch.Created with Claude Opus 5.5 in Claude Code.