9cc881ce5b
Remote OAuth MCP servers dropped out of /mcp under `omp auth-broker serve` once their access token expired: neither the client nor the broker could complete the refresh. - Client: the MCP manager threw on the broker-redacted refresh sentinel (REMOTE_REFRESH_SENTINEL) instead of asking the broker to refresh. It now routes redacted MCP refreshes through AuthStorage.forceRefreshCredentialById, which calls back to the broker (the real refresh token never leaves the broker host). - Broker: the serve process had no mcp_oauth:* refresh path, so POST /v1/credential/:id/refresh answered "Unknown OAuth provider". Its AuthStorage is now built with a refreshOAuthCredential override that refreshes MCP credentials with a generic refresh_token grant from the credential's embedded token endpoint and client id. The background refresher keeps MCP tokens live through the same path. Extract shared refreshManagedMcpOAuthCredential and mcpOAuthServerUrlFromCredentialId helpers so both paths use identical refresh material selection and RFC 8707 fallback-resource logic. Fixes #8933
@oh-my-pi/pi-coding-agent
Core implementation package for the omp coding agent in the oh-my-pi monorepo.
For installation, setup, provider configuration, model roles, slash commands, and full CLI reference, see:
Package-specific references:
Memory backends
The agent supports three mutually-exclusive memory backends, selected via the memory.backend setting (Settings → Memory tab, or ~/.omp/config.yml):
off(default) — no memory subsystem runs.local— existing rollout-summarisation pipeline; writesmemory_summary.mdand consolidated artifacts under the agent dir.hindsight— talks to a Hindsight server (Cloud or self-hosted Docker), retains transcripts every Nth user turn, recalls memories on the first turn of a session, and exposesretain,recall, andreflect.
Hindsight quickstart
- Run a Hindsight server (Cloud or
docker run -p 8888:8888 ghcr.io/vectorize-io/hindsight:latest). - Set
memory.backend = "hindsight"andhindsight.apiUrl = "http://localhost:8888"(or your Cloud URL). - Optional environment overrides (env wins over settings):
HINDSIGHT_API_URL,HINDSIGHT_API_TOKEN— connectionHINDSIGHT_BANK_ID,HINDSIGHT_DYNAMIC_BANK_ID,HINDSIGHT_AGENT_NAME— bank addressingHINDSIGHT_AUTO_RECALL,HINDSIGHT_AUTO_RETAIN,HINDSIGHT_RETAIN_MODE— lifecycleHINDSIGHT_RECALL_BUDGET,HINDSIGHT_RECALL_MAX_TOKENS— recall sizingHINDSIGHT_BANK_MISSION,HINDSIGHT_DEBUG
Switching backends mid-session immediately replaces the live backend, memory tools, listeners, and system-prompt context. Existing users with memories.enabled = true|false are migrated to memory.backend = "local"|"off" exactly once on first launch; afterward, memory.backend is the sole runtime selector.