Repository navigation
AI agents in qrypt.chat: invite by email, SMS or link; E2EE chat (0.7.0, qc 0.6.0) - #295
Merged
Merged
Conversation
….0, qc 0.6.0) - Migration 20261007000000 (applied on dev2): account_type 'agent', users.operator_user_id, agent_invites (sha256 of a 256-bit token only). - Settings > AI agents: invite by link, email (Resend) or SMS (Telnyx); list invites and agents; revoke open invites. - /agents/join#<token>: human- and agent-readable instructions; the token lives in the fragment, never in a request line or Referer. - POST /api/agents/redeem: the agent sends only its ML-KEM-1024 public key; the server creates the agent account (operator = inviter), stores the key, opens a direct conversation and returns a session. Claimed atomically and rolled back on failure. - qc agent join <link> [--name --username]: makes the keypair locally, seals the session like qc login; then qc listen / send / mcp. - Chat shows an AI agent badge; an agent's OpenProfile is Kind agent with an Operator section. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ThreatCrush Security Scan13 finding(s) MEDIUM: 9 | LOW: 4
Snippets are redacted; ThreatCrush never prints matched credential material. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Anthony: "we need to be able to chat with our agents in qrypt.chat … a user should be able to invite an agent to qrypt.chat via email or phone or shared link".
Flow
npx -y @profullstack/qryptchat agent join "<link>" [--name Athena] [--username athena_bot].POST /api/agents/redeemgets only the public key. The server creates anagentaccount (operator = the inviter), stores the key, opens a direct conversation with the inviter, and returns a session. qc seals it at rest likeqc login.qc listen/qc send/qc mcp, end to end encrypted like any user.Security
/agents/join#…), so it never appears in a request line, server log or Referer.agent_invitesis RLS-enabled and revoked from anon/authenticated: service role only.Shown in the app
/u/<agent>says "AI agent", and its OpenProfile.md isKind: agentwith an Operator section linking the person's OpenProfile, as the spec asks.DB: migration
20261007000000_agents.sqlis already applied on dev2. It extends the account_type CHECK withagent, addsusers.operator_user_idand theagent_invitestable, and PostgREST has been reloaded.Tests: 707/707. New tests cover tokens and link parsing, a successful redemption, refusing used/revoked/expired invites, bad keys and taken usernames, rollback, and the agent OpenProfile.
next buildpasses.Note: messaging is Preshy's area; Anthony asked for this directly.
🤖 Generated with Claude Code