Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
"plugins": [
{
"name": "kbagent",
"version": "0.94.0",
"version": "0.95.0",
"source": "./plugins/kbagent",
"description": "DEPRECATED — install from keboola/ai-kit: /plugin marketplace add keboola/ai-kit && /plugin install kbagent@keboola-claude-kit — AI-friendly interface to Keboola Connection projects — explore configs, jobs, lineage, sync configs as files, manage dev branches, and debug SQL in workspaces",
"category": "development"
Expand Down
2 changes: 1 addition & 1 deletion CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -450,7 +450,7 @@ kbagent auth register-projects [--stack URL|alias] [--all] [--project-id ID ...]
# See docs/web-server.md.

kbagent project create --url URL [--project ALIAS] [--name NAME] [--backend snowflake|bigquery] [--sync-backend-init]
# project create (since vNEXT, DMD-1940): the ONLY kbagent command that works from nothing --
# project create (since 0.95.0, DMD-1940): the ONLY kbagent command that works from nothing --
# no account, no token, no `auth login`. POSTs the unauthenticated provisioning endpoint
# (`/manage/programmatic-projects`, gated by the `agent-provisioning` stack feature
# / `STACK_FEATURES__AGENT_PROVISIONING`, off on most stacks -- the COMMAND is always
Expand Down
2 changes: 1 addition & 1 deletion docs/auth.md
Original file line number Diff line number Diff line change
Expand Up @@ -97,7 +97,7 @@ The reverse direction *is* possible, because it is an explicit request — see

### `project create` -- starting from nothing

*(since vNEXT)*
*(since 0.95.0)*

```bash
kbagent project create --url URL [--project ALIAS] [--name NAME] \
Expand Down
2 changes: 1 addition & 1 deletion plugins/kbagent/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "kbagent",
"version": "0.94.0",
"version": "0.95.0",
"description": "AI-friendly interface to Keboola Connection projects — explore configs, jobs, lineage, sync configs as files, manage dev branches, and debug SQL in workspaces",
"author": {
"name": "Keboola",
Expand Down
6 changes: 3 additions & 3 deletions plugins/kbagent/agents/keboola-expert.md
Original file line number Diff line number Diff line change
Expand Up @@ -154,7 +154,7 @@ been retired, so its absence is NOT a promise (see §1 Rule 6).
| Read a semantic-layer model (models, metrics, datasets, constraints) | `kbagent --json semantic-layer show --project P [--model M] [--type metric\|dataset\|relationship\|constraint\|glossary]`; `model list`; `search-context` / `get-context` for glob/id lookup; `validate [--deep]` before trusting one. The WHOLE `semantic-layer` family needs a MASTER token: a valid non-master token gets `MISSING_MASTER_TOKEN` (0.92.0+, #711; the Metastore's opaque 401 "Failed to create project scope") -- register a master token, do not escalate | -- | hand-rolled `httpx` loops against `metastore.*.keboola.com` (bypasses retry/backoff and the kbagent error envelope) |
| ANY semantic-layer write (add / edit / remove / import / promote / build) | `kbagent semantic-layer export` FIRST (the metastore has no soft-delete and no version history -- the snapshot is the only restore path), then the write, `--dry-run` where offered. `Read` [semantic-layer-workflow.md](../skills/kbagent/references/semantic-layer-workflow.md) before starting: it carries the per-verb recipes, the rename cascade and the promote classification | `semantic-layer diff` (`--project-a/-b` or `--file-a/-b`) to confirm what a write would change | raw metastore REST (no rollback, no orphan scan, no modelUUID rewrite); a write with no export taken |
| User asks to "log in" / authenticate via browser / register a session's projects | ATTENDED session + a background shell: run `kbagent auth login --device-code --stack URL --register-projects` in a **BACKGROUND** shell (capture stdout+stderr, human mode -- `--json` puts the panel on stderr), relay the verification URL + user code to the user, then poll `kbagent --json auth status` (exit 0 = signed in, exit 3 = not yet). The human's part is approving in the browser, not typing the command. No background shell -> hand the plain `auth login --stack URL --register-projects` to the user's terminal. To register projects from an EXISTING session, `kbagent auth register-projects --all` or `--project-id ID` is non-interactive and agent-safe | -- | running `auth login` in a FOREGROUND tool shell (~120 s timeout kills it mid-flight); running it unattended (nobody can approve); re-running it blind without checking `auth status` first (orphans a session); the flagless `register-projects` picker unattended; reading the token out of `auth.json`; using a numeric project id as an alias |
| User has NO Keboola account / project at all and asks to get started | `kbagent project create --url URL [--project ALIAS] [--name NAME] [--backend snowflake\|bigquery]` (vNEXT+) -- provisions a real project, stores its session and registers the alias in one call, agent-runnable. **Then relay the result's `confirm_url` to the human verbatim and say the project is owned by nobody until they open it**; after they confirm, the agent session is revoked by design -> `kbagent auth login --stack URL` | the user creating the project in the Keboola UI, then `auth login` / `project add --token` | calling it on a stack where a session already exists (exit 5 -- one session per stack); reporting success without the confirm link (an unclaimed project is a billable orphan); retrying it after a 5xx/429/503 without being asked (each success creates a new organization + project + credit grant) |
| User has NO Keboola account / project at all and asks to get started | `kbagent project create --url URL [--project ALIAS] [--name NAME] [--backend snowflake\|bigquery]` (0.95.0+) -- provisions a real project, stores its session and registers the alias in one call, agent-runnable. **Then relay the result's `confirm_url` to the human verbatim and say the project is owned by nobody until they open it**; after they confirm, the agent session is revoked by design -> `kbagent auth login --stack URL` | the user creating the project in the Keboola UI, then `auth login` / `project add --token` | calling it on a stack where a session already exists (exit 5 -- one session per stack); reporting success without the confirm link (an unclaimed project is a billable orphan); retrying it after a 5xx/429/503 without being asked (each success creates a new organization + project + credit grant) |
| CI task has account credentials | `kbagent auth login-password --email E (--password-stdin \| --password P) [--totp-secret SEED]` (0.84.0+), agent-runnable | a static Storage token | `auth login` unattended |

If the table does not cover the user's task, **ask clarifying
Expand Down Expand Up @@ -395,7 +395,7 @@ its absence is NOT a promise the entry is version-independent (see §1 Rule 6).
hand the plain command to the user, then `auth status`/`auth logout` as usual.
**`auth login-password` (0.84.0+) IS the headless path** -- email + password
(+ TOTP seed), agent-runnable; WebAuthn-only -> `AUTH_MFA_INVALID`.
- **`project create` (vNEXT+) is the only command that works from nothing**
- **`project create` (0.95.0+) is the only command that works from nothing**
-- no account, no token, no `auth login` first; it needs the
`agent-provisioning` stack feature (`STACK_FEATURES__AGENT_PROVISIONING`),
which is OFF on most stacks. The COMMAND is always registered, so its
Expand Down Expand Up @@ -450,7 +450,7 @@ its absence is NOT a promise the entry is version-independent (see §1 Rule 6).
(`fallback_used: "heuristic"`), not the full AI wizard (that is the `sl-build`
skill).
- dataset `fqn` = the table's Storage location (`storage table-detail` ->
`sql_path`), since vNEXT: `add dataset` fails on a table that does not exist
`sql_path`), since 0.95.0: `add dataset` fails on a table that does not exist
unless `--fqn` is given. Older kbagent wrote a `"KEBOOLA"` database that
resolves nowhere -- `validate --deep` flags those as `FQN_MISMATCH`; never
hand-build an fqn from the tableId (a linked bucket lives in the SOURCE
Expand Down
4 changes: 2 additions & 2 deletions plugins/kbagent/skills/kbagent/references/auth-workflow.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
> once, understand what got stored where, and know how to check on / tear
> down the session later.
> Since v0.80.0 (browser login), v0.84.0 (unattended `login-password`),
> vNEXT (`project create` -- no Keboola account needed at all).
> 0.95.0 (`project create` -- no Keboola account needed at all).
> Full command reference: `commands-reference.md` > "Programmatic Auth
> (Browser Login)". Gotchas: `gotchas.md` > "Programmatic auth (browser
> login) needs a human to approve; sentinel tokens; session scope" and > "`auth
Expand Down Expand Up @@ -81,7 +81,7 @@ path is unchanged by either feature.

## No Keboola account at all: `project create`

*(since vNEXT, DMD-1940)*
*(since 0.95.0, DMD-1940)*

Everything else in this file assumes the user already has a Keboola account.
`kbagent project create --url URL` is the one path that does not: it
Expand Down
Loading
Loading