Skip to content

docs(pi): add integration docs and example (not intended to merge) - #5796

Draft
eersnington wants to merge 2 commits into
feat/headless-pi-actorfrom
docs/headless-pi-actor
Draft

eersnington wants to merge 2 commits into
feat/headless-pi-actorfrom
docs/headless-pi-actor

Conversation

@eersnington

@eersnington eersnington commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Adds the Pi page at /integrations/pi, its quickstart snippets, and examples/pi-credentials.

  • Quickstart: install, define the actor, add a sandbox, send a prompt, deploy.
  • Configuration table and tracing.
  • Bring your subscription: credentials backed by a credentials actor.
  • examples/pi-credentials: a credentials actor that stores and refreshes each user's logins, and pnpm provider-login to try it.

@claude

claude Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review: docs(pi): add integration docs and example

The example is small and reads well. A few things to look at before merge.

Scope and description mismatch

  • The title and description mention the /integrations/pi page and quickstart snippets. This diff only has examples/pi-credentials, a lockfile change, and one docs edit. If those pages are in another PR in the stack, the description should say so.
  • docs/general/content/index.mdx un-hides the Agents card. The comment it removes says "Agents is built but unlaunched (see HIDDEN.md)". This is a launch decision unrelated to Pi. Please confirm it is intended, and if so put it in its own change and update HIDDEN.md.

pnpm-lock.yaml

  • The lockfile has about 300 lines of unrelated churn: aws-sdk, smithy, undici and semver bumps and dedupes. It looks regenerated rather than scoped to the new importer. Please limit it to the examples/pi-credentials importer and its new transitive dependencies, or say why the wider bump is needed.

examples/pi-credentials/src/actors.ts

  • Concurrent refresh. refresh is async and writes c.state.saved[provider] after several awaits. If two Pi actors for the same user call it at once, both can refresh with the same refresh token. Providers that rotate refresh tokens reject the second use, so the loser can store a stale token. Serialize per provider (for example an in-flight promise map) or note the limitation.
  • read on expired tokens. read returns the access token without checking expiry, so it only works if the caller calls refresh first. Please confirm how pi({ credentials }) uses these actions and document it if the caller has to do it.
  • Unauthenticated actor. The README says to add authentication. Since this is copy-paste code that stores OAuth tokens, add an onBeforeConnect or createConnState stub showing where the check goes, including that the caller matches the actor key.
  • Plaintext state. Credentials are stored in plaintext actor state. Fine for an example, but a one-line comment would help.

scripts/provider-login.ts

  • The select prompt falls back to the raw answer when the number is out of range, so a typo silently sends an arbitrary string as an option id.
  • The readline interface is never closed and the script relies on process.exit(0). terminal.close() in a finally is cleaner and covers login failures.
  • provider is not validated. An empty string gives an obscure error from runtime.login.

package.json

  • Check "stableVersion": "0.8.0" and "version": "2.0.21" against the neighbouring examples/*/package.json.
  • The scripts run .ts files directly with node, which needs Node 22.6+. Consider an engines field.

Tests

  • There is no coverage for the credentials actor, for example that read never returns refresh and that refresh persists the rotated credential. The repo forbids module mocks, so this would need a real registry or driver test.

@eersnington
eersnington marked this pull request as ready for review September 25, 2026 15:53

@the-company-company the-company-company Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 2 medium · 🔵 1 low

Reviewed commit e5040f4.

Comment thread examples/pi-credentials/src/actors.ts
Comment thread examples/pi-credentials/package.json Outdated
Comment thread docs/integrations/content/docs/pi.mdx Outdated

@the-company-company the-company-company Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 2 medium · 🔵 1 low

Reviewed commit 89a5bd7.

Comment on lines +29 to +30
withoutRefreshToken(c.state.saved[provider]),
refresh: async (c, provider: string) => {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Medium · Credential actions expose provider tokens to every caller

read returns the stored API key or OAuth access token, and save also lets an unauthenticated caller replace it. Because this actor has no connection or action authorization, anyone who can reach it and select a user's actor key can steal or overwrite that user's login; the README warning does not enforce the boundary. Make the credential store inaccessible to public actor clients, or add authentication and actor-key authorization to the example before exposing these actions.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

no shit?

Comment thread examples/pi-credentials/package.json Outdated
Comment thread docs/integrations/content/docs/pi.mdx Outdated
@eersnington
eersnington force-pushed the docs/headless-pi-actor branch 2 times, most recently from dc9d5b1 to 3e2a18d Compare September 25, 2026 20:32
@eersnington
eersnington force-pushed the feat/headless-pi-actor branch from b004815 to 1e7248d Compare September 25, 2026 22:24
@eersnington
eersnington force-pushed the docs/headless-pi-actor branch from 3e2a18d to 4a970f3 Compare September 25, 2026 22:24
@eersnington
eersnington force-pushed the feat/headless-pi-actor branch from 1e7248d to 1448347 Compare September 25, 2026 23:40
@eersnington
eersnington force-pushed the docs/headless-pi-actor branch 2 times, most recently from 3f92a6f to b2d96c4 Compare September 26, 2026 00:04
@eersnington
eersnington force-pushed the feat/headless-pi-actor branch from 1448347 to 5719ca6 Compare September 26, 2026 00:04
@eersnington
eersnington force-pushed the docs/headless-pi-actor branch from b2d96c4 to 04872eb Compare September 29, 2026 18:22
@eersnington
eersnington force-pushed the feat/headless-pi-actor branch from 5719ca6 to ff2b289 Compare September 29, 2026 18:23
@eersnington
eersnington force-pushed the feat/headless-pi-actor branch from ff2b289 to 62c3383 Compare September 29, 2026 20:44
@eersnington
eersnington force-pushed the docs/headless-pi-actor branch from 04872eb to 8742b4b Compare September 29, 2026 20:44
@eersnington eersnington changed the title docs(pi): add integration docs and example docs(pi): add integration docs and example (not intended to merge) Sep 29, 2026
@eersnington
eersnington marked this pull request as draft September 29, 2026 20:47
NathanFlurry pushed a commit to rivet-dev/website that referenced this pull request Oct 1, 2026
- Drop unlaunched from Agents (still hidden from the Products menu), remove
  the homepage Actors stand-in, and restore the Actors overview link.
- Agents docs: Overview, Pi (ported from rivet-dev/rivet#5796, now "this
  agent is in beta" and hosted agentOS), Sandboxes, Credentials, Durability,
  Tracing, and beta how-to connectors for Slack, Discord, GitHub, and Linear.
  Examples live in agents/examples and type-check against #5767/#5799, except
  the future no-argument agentOSProvider().
- Sidebar logos: Pi and connector marks, with a monochrome opt-out and a
  fixed icon box so labels align.
- agentOS is only the sandbox now: remove the agent logo cycle and cards, the
  orchestration section and its Pi samples, and agent packages from the
  registry marquee; link agents to /agents/docs.
- integrations.ts: point Flue, Eve, and Rivet Actors at the rivet repo instead
  of agentOS packages that are being deleted.

Amp-Thread-ID: https://ampcode.com/threads/T-0a7b4868-7c1f-4d1b-b5df-238bc41983d6
Co-authored-by: Amp <amp@ampcode.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant