Skip to content

docs(eve): document authorized approvals, update extension contracts - #1374

Draft
benpankow wants to merge 1 commit into
ben/hitl-v2-subagentsfrom
ben/hitl-v2-docs-contracts
Draft

docs(eve): document authorized approvals, update extension contracts#1374
benpankow wants to merge 1 commit into
ben/hitl-v2-subagentsfrom
ben/hitl-v2-docs-contracts

Conversation

@benpankow

@benpankow benpankow commented Jul 29, 2026

Copy link
Copy Markdown
Collaborator

Summary

Documents responder-authorized approvals for tool authors and client implementers, updates client reducer coverage, and publishes the extension capability metadata required by the new public types/events.

Tool author documentation

The HITL guide now covers the relationship between request-time approval and response-time authorization:

approval: {
  policy: always(),
  async authorizeResponse({ request, responder, session, auth }) {
    const identity = await auth.getToken(approverAuth);

    return await canApprove({ identity, request, responder, session })
      ? "allowed"
      : {
          status: "rejected",
          safeReason: "You are not permitted to approve this action.",
        };
  },
},

It documents:

  • the stable request and verified responder inputs;
  • the narrow getToken / requireAuth capability;
  • private OAuth and safeReason behavior;
  • Approve/Cancel semantics;
  • concurrent candidates, fail-closed errors, and first-winner settlement;
  • candidate and settlement stream events.

Client documentation

The client messages guide now explains that submitting approve creates a candidate rather than immediately closing the shared request:

input.requested
  → submit approve
  → approval.candidate / authorization.required
  → approval.settled

Clients keep shared controls open until approval.settled, while candidate progress and OAuth UI remain private to the responder.

Client reducer coverage

Adds coverage that the default reducer changes a shared approval part only after terminal settlement, not on candidate progress.

Extension capability contracts

The new approval callback types, token subject field, and lifecycle events are reachable from several extension authoring surfaces. This PR:

  • bumps the affected tool, dynamic tool, connection, hook, dynamic skill, and dynamic instruction epochs;
  • retains every previous epoch;
  • adds representative compatibility fixtures for the retained contracts;
  • generates the new immutable API reports.

No previous extension epoch is dropped.

Depends on #1373.

Validation

  • pnpm --filter eve typecheck
  • pnpm --filter eve test:unit (5,627 passed locally on the consolidated stack)
  • pnpm docs:check
  • pnpm guard:invariants

@vercel

vercel Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
eve-docs Ready Ready Preview Jul 30, 2026 6:20pm
eve-docs-4759 Ready Ready Preview, v0 Jul 30, 2026 6:20pm

@github-actions

github-actions Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Bundle + Package Summary: apps/fixtures/weather-agent

Key takeaways

  • No notable deltas vs ben/hitl-v2-subagents (203d7db).

Delta vs ben/hitl-v2-subagents (203d7db)

Area Metric Baseline Current Delta
Package Packed tarball 7.63 MB 7.63 MB +857 B ⚠️
Package Unpacked publish size 28.84 MB 28.84 MB +2.7 kB ⚠️
Package Installed footprint 91.31 MB 91.32 MB +2.7 kB ⚠️
Package Published files 2882 2882 0
Package Installed files 6671 6671 0
Runtime Unique function payloads 2 2 0
Runtime Total function bytes 16.86 MB 16.86 MB +8 B ⚠️
Runtime Public routes 11 11 0
Changed function payloads vs ben/hitl-v2-subagents (203d7db) (2)
Function Status Baseline Current Delta Route changes
functions/__server.func changed 8.43 MB 8.43 MB +4 B ⚠️ none
functions/.well-known/workflow/v1/flow.func changed 8.43 MB 8.43 MB +4 B ⚠️ none

eve init install

Metric Baseline Current Delta
Installed footprint 129.72 MB 129.72 MB +2.7 kB ⚠️
Installed packages 128 128 0
dependencies 4 4 0
devDependencies 2 2 0
Dependency package bytes 43.18 MB 43.18 MB +2.7 kB ⚠️
devDependency package bytes 5.04 MB 5.04 MB 0 B ➖
Build Metadata
  • Preset: vercel
  • Nitro: nitro@3.0.260610-beta
  • Output directory: apps/fixtures/weather-agent/.vercel/output
  • Build metadata timestamp: 2026-07-30T18:21:14.167Z
  • Route aliases: 11 public, 1 internal (12 total aliases)
  • Vercel routes in config: 14
  • Severity legend: 🔴 dominant/large, 🟠 notable, 🟡 watch, ⚪ small
Package Drill-Down

Package Details

  • Package: eve@0.28.0
  • Package directory: packages/eve
  • Tarball: 7.63 MB (eve-0.28.0.tgz)
  • Unpacked payload: 28.84 MB across 2882 published files
  • Installed footprint: 91.32 MB across 6671 installed files
  • Installed root package: 27.49 MB
  • Installed dependencies: 63.83 MB
  • Runtime dependencies: 2
  • Peer dependencies: 5 (4 optional)

Installed footprint is measured from an isolated temporary npm install of the packed tarball.

Heavy installed dependencies

  • eve: 27.49 MB (30.1%)
  • @rolldown/binding-linux-x64-gnu: 19.28 MB (21.1%)
  • @rolldown/binding-wasm32-wasi: 10.66 MB (11.7%)
  • @napi-rs/wasm-runtime: 6.56 MB (7.2%)
  • ai: 6.53 MB (7.2%)
Publish payload breakdown
Published file size
🔴 dist/src/compiled/shadcn-registry/index.js       [########################] 13.15 MB 45.6%
🟠 dist/src/compiled/experimental-ai-sdk-code-mo... [###.....................] 1.51 MB 5.2%
🟡 dist/src/compiled/@vercel/sandbox/index.js       [#.......................] 632.5 kB 2.2%
🟡 dist/src/compiled/_chunks/workflow/undici-DWL... [#.......................] 502.4 kB 1.7%
🟡 dist/src/compiled/@chat-adapter/slack/index.js   [#.......................] 440.5 kB 1.5%
🔴 Other published files                            [#######################.] 12.61 MB 43.7%
Installed footprint breakdown
Installed package size
🔴 eve                             [########################] 27.49 MB 30.1%
🔴 @rolldown/binding-linux-x64-gnu [#################.......] 19.28 MB 21.1%
🔴 @rolldown/binding-wasm32-wasi   [#########...............] 10.66 MB 11.7%
🔴 @napi-rs/wasm-runtime           [######..................] 6.56 MB 7.2%
🔴 ai                              [######..................] 6.53 MB 7.2%
🔴 zod                             [####....................] 5.07 MB 5.5%
🔴 Other installed packages        [##############..........] 15.73 MB 17.2%
Runtime dependencies (2)
Package Range Notes
nitro 3.0.260610-beta
undici 8.9.0
Peer dependencies (5)
Package Range Notes
@opentelemetry/api ^1.0.0 optional peer
ai catalog:
braintrust ^3.0.0 optional peer
just-bash ^3.0.0 optional peer
microsandbox ^0.5.0 optional peer
eve init install drill-down

eve init install details

  • Command: eve init my-agent
  • Package manager: npm
  • Installed footprint: 129.72 MB across 8539 installed files
  • Installed packages: 128 total (122 transitive-only)
  • dependencies: 4 direct packages totaling 43.18 MB
  • devDependencies: 2 direct packages totaling 5.04 MB
  • Other transitive package files: 81.50 MB

Installed footprint is measured from an isolated temporary eve init my-agent using the current packed eve tarball.

Heavy installed dependencies

  • @typescript/typescript-linux-x64: 27.95 MB (21.5%)
  • eve: 27.49 MB (21.2%)
  • @rolldown/binding-linux-x64-gnu: 19.28 MB (14.9%)
  • @rolldown/binding-wasm32-wasi: 10.66 MB (8.2%)
  • zod: 9.02 MB (7.0%)
Installed footprint breakdown
Installed package size
🔴 @typescript/typescript-linux-x64 [########################] 27.95 MB 21.5%
🔴 eve                              [########################] 27.49 MB 21.2%
🔴 @rolldown/binding-linux-x64-gnu  [#################.......] 19.28 MB 14.9%
🔴 @rolldown/binding-wasm32-wasi    [#########...............] 10.66 MB 8.2%
🔴 zod                              [########................] 9.02 MB 7.0%
🔴 @napi-rs/wasm-runtime            [######..................] 6.56 MB 5.1%
🔴 ai                               [######..................] 6.53 MB 5.0%
🔴 Other installed packages         [###################.....] 22.23 MB 17.1%
dependencies (4)
Package Range Installed size Share
@vercel/connect 0.4.2 135.8 kB 0.1%
ai ^7.0.38 6.53 MB 5.0%
eve file:eve-0.28.0.tgz 27.49 MB 21.2%
zod 4.4.3 9.02 MB 7.0%
devDependencies (2)
Package Range Installed size Share
@types/node 24.x 2.54 MB 2.0%
typescript 7.0.2 2.50 MB 1.9%
Function Drill-Down

Payload Size Graph

Unique function payload size and share of total
🔴 functions/.well-known/workflow/v1/flow.func     [########################] 8.43 MB 50.0%
🔴 functions/__server.func                         [########################] 8.43 MB 50.0%

Top Function Payloads

🟠 functions/.well-known/workflow/v1/flow.func • 1 public route • 8.43 MB
Metric Value
Public routes /.well-known/workflow/v1/flow
Runtime nodejs24.x
Handler index.mjs
Payload 8.43 MB
Function files 8.43 MB across 43 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.33 MB (27.7%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                       [########################] 2.33 MB 27.7%
🟠 _chunks/runtime-artifacts.mjs   [################........] 1.59 MB 18.9%
🟡 _libs/undici.mjs                [##########..............] 980.5 kB 11.6%
🟡 _chunks/sandbox.mjs             [########................] 768.8 kB 9.1%
🟡 _libs/@ai-sdk/gateway+[...].mjs [####....................] 432.8 kB 5.1%
🟠 Other bundled files             [########################] 2.32 MB 27.5%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x",
  "maxDuration": "max",
  "experimentalTriggers": [
    {
      "type": "queue/v2beta",
      "topic": "__eve776561746865722d6167656e74_wkf_workflow_*",
      "consumer": "default",
      "retryAfterSeconds": 5,
      "initialDelaySeconds": 0
    }
  ],
  "environment": {
    "WORKFLOW_PRECONDITION_GUARD": "1"
  }
}

🟠 functions/__server.func • 10 public routes, 1 internal alias • 8.43 MB
Metric Value
Public routes /
/eve/v1/callback/[token]
/eve/v1/connections/[name]/callback/[token]
/eve/v1/health
/eve/v1/info
/eve/v1/session
/eve/v1/session/[sessionId]
/eve/v1/session/[sessionId]/cancel
/eve/v1/session/[sessionId]/stream
/eve/v1/session/reset
Internal aliases /__server
Runtime nodejs24.x
Handler index.mjs
Payload 8.43 MB
Function files 8.43 MB across 43 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.33 MB (27.7%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                       [########################] 2.33 MB 27.7%
🟠 _chunks/runtime-artifacts.mjs   [################........] 1.59 MB 18.9%
🟡 _libs/undici.mjs                [##########..............] 980.5 kB 11.6%
🟡 _chunks/sandbox.mjs             [########................] 768.8 kB 9.1%
🟡 _libs/@ai-sdk/gateway+[...].mjs [####....................] 432.8 kB 5.1%
🟠 Other bundled files             [########################] 2.32 MB 27.5%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x"
}

Build Timing: e2e/fixtures/agent-tools-sandbox

This is an informational timing measurement inside eve build, from preflight through publication. Output-size measurement and profile writing are excluded.

Build mode: deployable Vercel build with sandbox template prewarm included.

  • Build pipeline: 1.93 s -> 2.05 s (+113.3 ms) vs ben/hitl-v2-subagents (203d7db).
  • Timing is informational: shared GitHub runners are too variable for a hard timing budget.
Detailed phase timings vs `ben/hitl-v2-subagents (203d7db)`
Phase Baseline Current Delta
extension.check 1.1 ms 6.5 ms +5.4 ms
project.resolve 0.6 ms 3.4 ms +2.8 ms
workspace.create 0.7 ms 1.3 ms +0.6 ms
host.prepare 156.4 ms 284.7 ms +128.3 ms
vercel.service-prefix.resolve 3.4 ms 2.3 ms -1.1 ms
nitro.create 227.9 ms 210.1 ms -17.8 ms
sandbox.prewarm 182.0 ms 170.4 ms -11.6 ms
nitro.cache.prepare 0.3 ms 0.3 ms 0.0 ms
nitro.prepare 0.8 ms 0.9 ms +0.1 ms
nitro.public-assets 0.8 ms 0.8 ms 0.0 ms
nitro.prerender 0.6 ms 0.5 ms -0.1 ms
nitro.bundle 1.33 s 1.34 s +7.9 ms
nitro.cache.write 0.4 ms 0.4 ms 0.0 ms
vercel.workflow-function.materialize 23.6 ms 22.7 ms -0.9 ms
agent-summary.emit 0.5 ms 0.5 ms 0.0 ms
nitro.close 0.2 ms 0.2 ms 0.0 ms
output.publish 3.7 ms 3.5 ms -0.2 ms
workspace.remove 2.3 ms 2.3 ms 0.0 ms

@benpankow
benpankow force-pushed the ben/hitl-v2-docs-contracts branch from f1dad45 to 0e86611 Compare July 29, 2026 22:04
@vercel
vercel Bot temporarily deployed to Preview – eve-docs-4759 July 29, 2026 22:04 Inactive
@benpankow
benpankow force-pushed the ben/hitl-v2-docs-contracts branch from 0e86611 to 3e03d18 Compare July 29, 2026 22:22
@vercel
vercel Bot temporarily deployed to Preview – eve-docs-4759 July 29, 2026 22:22 Inactive
@benpankow benpankow changed the title docs(eve): document authorized approval responses docs(eve): document authorized approvals, update extension contracts Jul 29, 2026
@benpankow
benpankow force-pushed the ben/hitl-v2-docs-contracts branch from 3e03d18 to 993c0b6 Compare July 29, 2026 23:54
@benpankow
benpankow force-pushed the ben/hitl-v2-docs-contracts branch 2 times, most recently from 024aa59 to 7fc1fbc Compare July 30, 2026 00:01
@vercel
vercel Bot temporarily deployed to Preview – eve-docs-4759 July 30, 2026 00:01 Inactive
@benpankow
benpankow force-pushed the ben/hitl-v2-docs-contracts branch from 7fc1fbc to 4f43224 Compare July 30, 2026 00:10
Signed-off-by: benpankow <ben.pankow@vercel.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant