Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
99 changes: 98 additions & 1 deletion .oagen-manifest.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
{
"version": 2,
"language": "node",
"generatedAt": "2026-06-16T18:02:10.415Z",
"files": [
"src/api-keys/interfaces/create-validation-options.interface.ts",
"src/api-keys/interfaces/delete-api-key-options.interface.ts",
Expand Down Expand Up @@ -82,47 +81,145 @@
"src/groups/serializers/index.ts",
"src/groups/serializers/update-group.serializer.ts",
"src/groups/serializers/user-organization-membership-base-list-data.serializer.ts",
"src/pipes/fixtures/api-key-installation.json",
"src/pipes/fixtures/connected-account-input.json",
"src/pipes/fixtures/connected-account.json",
"src/pipes/fixtures/create-data-integration.json",
"src/pipes/fixtures/custom-provider-definition.json",
"src/pipes/fixtures/data-integration-access-token-response-access-token.json",
"src/pipes/fixtures/data-integration-access-token-response.json",
"src/pipes/fixtures/data-integration-authorize-url-response.json",
"src/pipes/fixtures/data-integration-credential.json",
"src/pipes/fixtures/data-integration-credentials-input.json",
"src/pipes/fixtures/data-integration-credentials-response.json",
"src/pipes/fixtures/data-integration-custom-provider.json",
"src/pipes/fixtures/data-integration-installation.json",
"src/pipes/fixtures/data-integration.json",
"src/pipes/fixtures/data-integrations-get-data-integration-authorize-url-request.json",
"src/pipes/fixtures/data-integrations-get-user-token-request.json",
"src/pipes/fixtures/data-integrations-list-response-data-connected-account.json",
"src/pipes/fixtures/data-integrations-list-response-data.json",
"src/pipes/fixtures/data-integrations-list-response.json",
"src/pipes/fixtures/data-integrations-upsert-api-key-request.json",
"src/pipes/fixtures/data-integrations-upsert-client-credentials-request.json",
"src/pipes/fixtures/data-integrations-vend-credentials-request.json",
"src/pipes/fixtures/list-data-integration.json",
"src/pipes/fixtures/organization-connected-account.json",
"src/pipes/fixtures/update-custom-provider-definition.json",
"src/pipes/fixtures/update-data-integration.json",
"src/pipes/interfaces/api-key-installation.interface.ts",
"src/pipes/interfaces/authorize-data-integration-options.interface.ts",
"src/pipes/interfaces/connected-account-auth-method.interface.ts",
"src/pipes/interfaces/connected-account-connection-role.interface.ts",
"src/pipes/interfaces/connected-account-input-state.interface.ts",
"src/pipes/interfaces/connected-account-input.interface.ts",
"src/pipes/interfaces/connected-account-state.interface.ts",
"src/pipes/interfaces/connected-account.interface.ts",
"src/pipes/interfaces/create-connected-account-state.interface.ts",
"src/pipes/interfaces/create-connected-account.interface.ts",
"src/pipes/interfaces/create-data-integration-api-key-options.interface.ts",
"src/pipes/interfaces/create-data-integration-auth-methods.interface.ts",
"src/pipes/interfaces/create-data-integration-client-credential-options.interface.ts",
"src/pipes/interfaces/create-data-integration-ownership.interface.ts",
"src/pipes/interfaces/create-data-integration-token-options.interface.ts",
"src/pipes/interfaces/create-data-integration.interface.ts",
"src/pipes/interfaces/create-organization-connected-account-options.interface.ts",
"src/pipes/interfaces/create-organization-connected-account-state.interface.ts",
"src/pipes/interfaces/create-organization-connected-account.interface.ts",
"src/pipes/interfaces/custom-provider-definition-authenticate-via.interface.ts",
"src/pipes/interfaces/custom-provider-definition.interface.ts",
"src/pipes/interfaces/data-integration-access-token-response-access-token.interface.ts",
"src/pipes/interfaces/data-integration-access-token-response-error.interface.ts",
"src/pipes/interfaces/data-integration-access-token-response.interface.ts",
"src/pipes/interfaces/data-integration-auth-methods.interface.ts",
"src/pipes/interfaces/data-integration-authorize-url-response.interface.ts",
"src/pipes/interfaces/data-integration-credential-type.interface.ts",
"src/pipes/interfaces/data-integration-credential.interface.ts",
"src/pipes/interfaces/data-integration-credentials-input-type.interface.ts",
"src/pipes/interfaces/data-integration-credentials-input.interface.ts",
"src/pipes/interfaces/data-integration-credentials-response-error.interface.ts",
"src/pipes/interfaces/data-integration-credentials-response.interface.ts",
"src/pipes/interfaces/data-integration-custom-provider-authenticate-via.interface.ts",
"src/pipes/interfaces/data-integration-custom-provider.interface.ts",
"src/pipes/interfaces/data-integration-installation-connection-role.interface.ts",
"src/pipes/interfaces/data-integration-installation.interface.ts",
"src/pipes/interfaces/data-integration-ownership.interface.ts",
"src/pipes/interfaces/data-integration-state.interface.ts",
"src/pipes/interfaces/data-integration-vended-credential.interface.ts",
Comment thread
devin-ai-integration[bot] marked this conversation as resolved.
"src/pipes/interfaces/data-integration.interface.ts",
"src/pipes/interfaces/data-integrations-create-api-key-connection-request-connection-owner.interface.ts",
"src/pipes/interfaces/data-integrations-create-api-key-connection-request.interface.ts",
"src/pipes/interfaces/data-integrations-create-client-credentials-connection-request-connection-owner.interface.ts",
"src/pipes/interfaces/data-integrations-create-client-credentials-connection-request.interface.ts",
"src/pipes/interfaces/data-integrations-get-data-integration-authorize-url-request-connection-owner.interface.ts",
"src/pipes/interfaces/data-integrations-get-data-integration-authorize-url-request.interface.ts",
"src/pipes/interfaces/data-integrations-get-user-token-request-connection-owner.interface.ts",
"src/pipes/interfaces/data-integrations-get-user-token-request.interface.ts",
"src/pipes/interfaces/data-integrations-list-response-data-auth-methods.interface.ts",
"src/pipes/interfaces/data-integrations-list-response-data-connected-account-auth-method.interface.ts",
"src/pipes/interfaces/data-integrations-list-response-data-connected-account-connection-role.interface.ts",
"src/pipes/interfaces/data-integrations-list-response-data-connected-account-state.interface.ts",
"src/pipes/interfaces/data-integrations-list-response-data-connected-account.interface.ts",
"src/pipes/interfaces/data-integrations-list-response-data-connection-owner.interface.ts",
"src/pipes/interfaces/data-integrations-list-response-data-ownership.interface.ts",
"src/pipes/interfaces/data-integrations-list-response-data.interface.ts",
"src/pipes/interfaces/data-integrations-list-response.interface.ts",
"src/pipes/interfaces/data-integrations-upsert-api-key-request-connection-owner.interface.ts",
"src/pipes/interfaces/data-integrations-upsert-api-key-request.interface.ts",
"src/pipes/interfaces/data-integrations-upsert-client-credentials-request-connection-owner.interface.ts",
"src/pipes/interfaces/data-integrations-upsert-client-credentials-request.interface.ts",
"src/pipes/interfaces/data-integrations-vend-credentials-request-connection-owner.interface.ts",
"src/pipes/interfaces/data-integrations-vend-credentials-request.interface.ts",
"src/pipes/interfaces/delete-organization-connected-account-options.interface.ts",
"src/pipes/interfaces/delete-organization-data-integration-options.interface.ts",
"src/pipes/interfaces/delete-user-connected-account-options.interface.ts",
"src/pipes/interfaces/get-organization-connected-account-options.interface.ts",
"src/pipes/interfaces/get-organization-data-integration-options.interface.ts",
"src/pipes/interfaces/get-user-connected-account-options.interface.ts",
"src/pipes/interfaces/index.ts",
"src/pipes/interfaces/list-organization-data-providers-options.interface.ts",
"src/pipes/interfaces/list-user-data-providers-options.interface.ts",
"src/pipes/interfaces/organization-connected-account-state.interface.ts",
"src/pipes/interfaces/organization-connected-account.interface.ts",
"src/pipes/interfaces/pipes-ownership.interface.ts",
"src/pipes/interfaces/update-custom-provider-definition-authenticate-via.interface.ts",
"src/pipes/interfaces/update-custom-provider-definition.interface.ts",
"src/pipes/interfaces/update-data-integration-client-credentials-options.interface.ts",
"src/pipes/interfaces/update-data-integration.interface.ts",
"src/pipes/interfaces/update-organization-connected-account-options.interface.ts",
"src/pipes/interfaces/update-organization-data-integration-options.interface.ts",
"src/pipes/pipes.spec.ts",
"src/pipes/pipes.ts",
"src/pipes/serializers.spec.ts",
"src/pipes/serializers/api-key-installation.serializer.ts",
"src/pipes/serializers/connected-account-input.serializer.ts",
"src/pipes/serializers/connected-account.serializer.ts",
"src/pipes/serializers/create-connected-account.serializer.ts",
"src/pipes/serializers/create-organization-connected-account.serializer.ts",
"src/pipes/serializers/custom-provider-definition.serializer.ts",
"src/pipes/serializers/data-integration-access-token-response-access-token.serializer.ts",
"src/pipes/serializers/data-integration-access-token-response.serializer.ts",
"src/pipes/serializers/data-integration-authorize-url-response.serializer.ts",
"src/pipes/serializers/data-integration-credential.serializer.ts",
"src/pipes/serializers/data-integration-credentials-input.serializer.ts",
"src/pipes/serializers/data-integration-credentials-response.serializer.ts",
"src/pipes/serializers/data-integration-custom-provider.serializer.ts",
"src/pipes/serializers/data-integration-installation.serializer.ts",
"src/pipes/serializers/data-integration-vended-credential.serializer.ts",
"src/pipes/serializers/data-integration.serializer.ts",
"src/pipes/serializers/data-integrations-create-api-key-connection-request.serializer.ts",
"src/pipes/serializers/data-integrations-create-client-credentials-connection-request.serializer.ts",
"src/pipes/serializers/data-integrations-get-data-integration-authorize-url-request.serializer.ts",
"src/pipes/serializers/data-integrations-get-user-token-request.serializer.ts",
"src/pipes/serializers/data-integrations-list-response-data-connected-account.serializer.ts",
"src/pipes/serializers/data-integrations-list-response-data.serializer.ts",
"src/pipes/serializers/data-integrations-list-response.serializer.ts",
"src/pipes/serializers/data-integrations-upsert-api-key-request.serializer.ts",
"src/pipes/serializers/data-integrations-upsert-client-credentials-request.serializer.ts",
"src/pipes/serializers/data-integrations-vend-credentials-request.serializer.ts",
"src/pipes/serializers/index.ts",
"src/pipes/serializers/organization-connected-account.serializer.ts",
"src/pipes/serializers/update-custom-provider-definition.serializer.ts",
"src/radar/fixtures/radar-list-entry-already-present-response.json",
"src/radar/fixtures/radar-standalone-assess-request.json",
"src/radar/fixtures/radar-standalone-delete-radar-list-entry-request.json",
Expand Down
146 changes: 146 additions & 0 deletions docs/PIPES_COMPATIBILITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,146 @@
# Pipes compatibility notes

## Public types and release review

The credential-schema refactoring preserves the API's JSON contract, but the
expanded SDK types are not a blanket source-compatible replacement for older
versions:

- `DataIntegration.credentials` can be `null` for API-key and client-credentials
integrations. Check for credentials before accessing `clientId` or
`redactedClientSecret`; do not substitute invented OAuth credentials.
- Credential responses distinguish active and inactive results. Typed response
fixtures must include `active` and the matching `credential` or `error`.
- API-key credentials have no OAuth expiry or scope fields. Code that assumes
every credential has a scope array needs to check `authMethod`, or use optional
access such as `result.credential?.scopes?.includes('repo')`.
- Authentication-method and connected-account-state unions have additional
values. Exhaustive consumer switches may need additional cases.
- Credential types that were interfaces are now union types. Custom types should
use an intersection rather than an interface extending the union.

Existing reads such as `result.error` and `result.credential?.value` remain
supported without first narrowing on `active`. `CreateDataIntegrationOptions`
remains an interface that consumers can augment.

The previous `DataIntegrationCredentialsResponseCredential` and
`DataIntegrationCredentialsResponseCredentialResponse` names remain exported as
aliases of `DataIntegrationVendedCredential` and its wire type. The existing
credential deserializer name also remains available. These are not removed or
renamed imports, even though the underlying response types are more precise.

The new organization-integration methods are
`getOrganizationDataIntegration`, `updateOrganizationDataIntegration`, and
`deleteOrganizationDataIntegration`. No previously released method was renamed.

Maintainers must resolve the remaining type-compatibility changes before deciding
on a release version. With this repository's default release-please versioning,
`!` or a `BREAKING CHANGE` footer in the commit that lands on `main` requests a
major release. Removing that metadata alone does not make these changes
compatible. Release-please owns the version and changelog updates.

## Ownership values

Provider-list responses retain the legacy `ownership` field:

| Legacy provider `ownership` | Preferred `connectionOwner` |
| --------------------------- | --------------------------- |
| `userland_user` | `user` |
| `organization` | `organization` |

Existing consumers do not need to rewrite the legacy response value. New code
should prefer `connectionOwner`, falling back to the mapping above when reading
an older response that omits it.

Integration creation and listing use `ownership: 'user' | 'organization'`.
Connection authorization, credential vending, and credential rotation instead
use `connectionOwner`, which defaults to `user`. Organization-owned requests need
an `organizationId`; the supplied `userId` identifies the acting member rather
than making that member the owner.

## Multiple connections are opt-in

Omitting `supportsMultipleConnections`, or passing `false`, keeps the
compatibility-connection behavior. Opt in with `true` to work with multiple
connections:

1. Use `listUserDataProviders` or `listOrganizationDataProviders` with
`supportsMultipleConnections: true` to obtain `connectedAccounts`.
2. Select a connection by its `id`, not its display name or account identifier.
3. Pass that ID as `connectedAccountId` on reads, updates, deletes, or credential
vending. Continue sending the plural opt-in where the operation supports it.

The legacy `connectedAccount` field still represents only the compatibility
connection and may be `null` even when standard connections exist. With plural
opt-in, credential vending without an account selector can return HTTP 409
`account_selection_required` when several connections match.

## Explicit connection creation and reauthorization

Use `createDataIntegrationApiKey` or
`createDataIntegrationClientCredential` to POST an API-key or client-credentials
connection. Both require `connectionIntent: 'add'` and take no account selector.
POST requests use the SDK's existing idempotency-key handling for retries once
the API honors `Idempotency-Key` on these routes.

The existing `updateDataIntegrationApiKey` and
`updateDataIntegrationClientCredentials` methods still use PUT. They keep
compatibility upsert behavior when intent and selector are omitted. To update
an exact connection, supply `connectedAccountId`; an explicit
`connectionIntent: 'reauthorize'` is optional, but requires that selector.
Do not send `add` intent to PUT.

OAuth imports (`createUserConnectedAccount` and
`createOrganizationConnectedAccount`) accept `connectionIntent: 'add'` in the
body. Omitting it keeps compatibility behavior. Their update counterparts accept
`connectionIntent: 'reauthorize'` and the account selector in the query.
`supportsMultipleConnections` remains accepted on updates, but it does not select
the update target.

Creating additional connections is still subject to API availability. The
current contract allows `add` for the owner's first connection and otherwise
returns HTTP 404 `multiple_connections_unavailable` until additional creation is
enabled. The SDK propagates that error; it does not fall back to rotating an
existing connection.

## Provider configuration

`createDataIntegrationCredential` preserves `credential.config` for OAuth,
API-key, and client-credentials results. It contains provider-declared,
non-secret integration- and installation-scope snapshot values plus current
defaults. It is separate from client-credentials token `metadata`.

Connected-account detail and provider-list results also preserve `config` for
all authentication methods. Those maps contain stored, non-secret
installation-scope values, rather than the combined/defaulted credential config.
Secret and undeclared values are filtered by the API, not guessed or filtered by
the SDK. An empty map stays empty; missing config from older API responses stays
`undefined`. The legacy `getAccessToken` response is unchanged.

## Generation boundaries

`ConnectedAccountDto` and `DataIntegrationCredentialsDto` remain published
compatibility interfaces. Their legacy serializers delegate to the generated
`ConnectedAccountInput` and `DataIntegrationCredentialsInput` serializers. The
four legacy TypeScript files are explicitly protected with `@oagen-ignore-file`.
Their two JSON fixtures remain inputs to compatibility tests.

Those legacy DTO files and fixtures intentionally stay outside
`.oagen-manifest.json`: the manifest records generated-file ownership, not every
SDK file. Adding obsolete generated paths would make them candidates for pruning
when the current spec no longer emits them. Preserve compatibility files rather
than deleting them to make the directory match the manifest.

The credential response types retain hand-maintained compatibility fields and
metadata typing. The `DataIntegrationCredentialsResponseCredential` alias files
(interface, serializer, and fixture) re-export the generated
`DataIntegrationVendedCredential` component under its published name and, like
the legacy DTOs, stay outside the manifest. The two direct-query DELETE methods are protected with
`@oagen-ignore` regions until the Node emitter's helper-signature fix is available.

API-key and client-credentials PUT options also retain their published flat
interfaces and explicit snake_case serializers. The current emitter passes the
new union request bodies through unchanged, which would send camelCase keys from
the SDK. These interfaces, serializers, and method regions are protected until
that emission path is fixed. They remain in the manifest where the spec still
emits the corresponding paths.
5 changes: 5 additions & 0 deletions src/pipes/fixtures/api-key-installation.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
{
"secret": "sk-1234567890abcdef",
"user_id": "user_01EHZNVPK3SFK441A1RGBFSHRT",
"organization_id": "org_01EHZNVPK3SFK441A1RGBFSHRT"
}
7 changes: 7 additions & 0 deletions src/pipes/fixtures/connected-account-input.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{
"access_token": "gho_16C7e42F292c6912E7710c838347Ae178B4a",
"refresh_token": "ghr_xxxxxxxxxxxxxxxxxxxx",
"expires_at": "2025-12-31T23:59:59.000Z",
"scopes": ["repo", "user:email"],
"state": "connected"
}
Loading
Loading