Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 46 additions & 0 deletions content/docs/configuration/dotenv.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -1582,6 +1582,52 @@ Each Agent can scope its stateful workspace to the signed-in user, the user and

Named attached environments can also expose a self-service pairing control plane with `pairing.allowPrincipalWorkers: true`. Authorized users manage those owner-bound workers under **Settings > Code environments**; pairing-only entries do not replace `LIBRECHAT_CODE_BASEURL_STATEFUL` and cannot serve as the deployment default.

## Conversation Pull Requests

Settings for showing a conversation's GitHub pull request. See [Conversation Pull Requests](/docs/features/pull_requests) and [`endpoints.agents.pullRequests`](/docs/configuration/librechat_yaml/object_structure/agents#pullrequests).

<Callout type="important" title="Pending: not yet released">
The three fallback token variables are part of LibreChat-AI/LibreChat#16876. In older versions,
set the variable that `token: "${NAME}"` refers to.
</Callout>

<OptionTable
options={[
[
'GITHUB_PULL_REQUEST_TOKEN',
'string',
'Pending. Fallback read-only GitHub token when `pullRequests.token` is not set. Tried first. Set on the LibreChat server.',
'# GITHUB_PULL_REQUEST_TOKEN=your-read-only-token',
],
[
'GITHUB_TOKEN',
'string',
'Pending. Fallback token, tried second. It is a common name: if your deployment already uses it for something else, the fallback starts using it here as soon as a repository scope is set.',
'# GITHUB_TOKEN=your-read-only-token',
],
[
'GH_TOKEN',
'string',
'Pending. Fallback token, tried third.',
'# GH_TOKEN=your-read-only-token',
],
[
'Any name you choose',
'string',
'The variable that `pullRequests.token: "${NAME}"` refers to. Set on the LibreChat server.',
'# MY_GITHUB_TOKEN=your-read-only-token',
],
[
'CODEAPI_BRIDGE_LANE_GIT',
'boolean',
'Set on the Code API, not on LibreChat. Makes attached workers report their git branch and head. Required for any pull request to be found.',
'CODEAPI_BRIDGE_LANE_GIT=true',
],
]}
/>

GitHub requests use the deployment's proxy settings (`PROXY`, `HTTP_PROXY`, `HTTPS_PROXY`, `NO_PROXY`, and their lowercase forms), and `NO_PROXY` is honored. These are shared with other LibreChat outbound traffic and are not specific to this feature.

## Artifacts

Artifacts leverage the CodeSandbox library for secure rendering of HTML/JS code. By default, the public CDN hosted by CodeSandbox is used.
Expand Down
129 changes: 129 additions & 0 deletions content/docs/configuration/librechat_yaml/object_structure/agents.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -550,6 +550,135 @@ eventDriven:

Event Actor detached Action completion is selected automatically from the built-in generation store. In-memory execution is process-local; Redis generation streams add durable restart recovery and replica handoff. No `librechat.yaml` switch or environment feature flag is required. See [Agent Event Runtime](/docs/configuration/dotenv#agent-event-runtime).

## pullRequests

{/* Pending items (LibreChat-AI/LibreChat#16876): delete the "Older versions" notes and Pending markers once it merges. Re-verify defaults and ranges against packages/data-provider/src/config.ts. */}

Shows the GitHub pull request for a conversation's attached code workspace in the chat header and sidebar. See [Conversation Pull Requests](/docs/features/pull_requests) for setup, behavior and troubleshooting. Every key is optional.

Most administrators set only a token, a repository scope, and possibly `enabled: false`. The remaining keys are for tuning, and their defaults are fine.

<Callout type="important" title="Pending: not yet released">
Default-on behavior, the environment variable token fallback, and `allowAllRepositories` are part
of LibreChat-AI/LibreChat#16876. In older versions `enabled` defaults to `false` and `token` is
required.
</Callout>

<OptionTable
options={[
[
'enabled',
'Boolean',
'Set `false` to turn the feature off. Pending: it is on once a token and a repository scope exist. Older versions: defaults to `false`, and `true` requires `token` and a non-empty `allowedRepositories`.',
'enabled: false',
],
[
'token',
'String',
'Reference to an environment variable that holds a read-only GitHub token, in the form `${NAME}`. Never the token itself. Pending: when unset, the server uses the first of `GITHUB_PULL_REQUEST_TOKEN`, `GITHUB_TOKEN`, `GH_TOKEN` that is set. A `token` that does not resolve fails with `NOT_CONFIGURED` and does not fall back. Older versions: required.',
'token: "${GITHUB_PULL_REQUEST_TOKEN}"',
],
[
'allowedRepositories',
'Array of Strings',
'Repositories the token may be used for, as `owner/name` or `owner/*` (up to 256 entries, case-insensitive). `*/*`, `*`, `owner`, and entries containing `..` are rejected.',
'allowedRepositories: ["LibreChat-AI/LibreChat", "my-org/*"]',
],
[
'allowAllRepositories',
'Boolean',
'Pending. Look up any repository the token can read. Default: `false`. See the warning below.',
'allowAllRepositories: false',
],
[
'cacheTtlSeconds',
'Number',
'Seconds a result is reused before GitHub is asked again (5-3600). Failures are remembered for at most 10 seconds. Default: 30.',
'cacheTtlSeconds: 30',
],
[
'cacheMaxEntries',
'Number',
'Results cached per credential before the oldest is evicted (10-100000). Size it to the distinct repository and branch combinations seen within one cache lifetime. When principals set different values for one token, the largest applies. Default: 500.',
'cacheMaxEntries: 500',
],
[
'cacheMaxCredentials',
'Number',
'Credentials cached at once, deployment-wide (1-10000). The one idle longest is dropped past it. When principals set different values, the largest applies. Raise it when many tenants each use their own token. Default: 256.',
'cacheMaxCredentials: 256',
],
[
'maxConcurrentLookups',
'Number',
'Lookups one sidebar request runs at once (1-16), counted per credential across requests. Each lookup is a few GitHub requests. Default: 4.',
'maxConcurrentLookups: 4',
],
[
'batchTimeoutSeconds',
'Number',
'Longest one sidebar request stays open (1-120). Entries still waiting then answer with an upstream error, and their rows show the warning icon with a retry button. Default: 20.',
'batchTimeoutSeconds: 20',
],
[
'requestTimeoutSeconds',
'Number',
'Longest one GitHub request may take (1-60). Raise it behind a slow proxy. Default: 10.',
'requestTimeoutSeconds: 10',
],
[
'lookupTimeoutSeconds',
'Number',
'Longest a whole lookup (every request together) may take (1-120). Default: 30.',
'lookupTimeoutSeconds: 30',
],
[
'maxCheckRunPages',
'Number',
'Pages of 100 check runs read before the rollup is reported as still running (1-50). Default: 10.',
'maxCheckRunPages: 10',
],
[
'maxCandidatePullRequests',
'Number',
"Pull requests listed per state when matching a branch's history (1-100). Raise it for branch names that are reused many times. Default: 10.",
'maxCandidatePullRequests: 10',
],
[
'maxCandidatePages',
'Number',
'Pages of those candidates read per state (1-10). Each page is one more request. Use it for branch names reused more often than one page holds. Default: 1.',
'maxCandidatePages: 1',
],
[
'maxHeadComparisons',
'Number',
'Candidates compared with the commit the chat last ran at before the search gives up (0-20). Each comparison is one request. `0` disables comparing. Default: 3.',
'maxHeadComparisons: 3',
],
]}
/>

<Callout type="warning" title="Security: allowAllRepositories">
With this on, any user who can run code can point the server's token at any repository that token
can read, and see the pull request title, size and check status. Use a read-only token scoped to
the repositories you are willing to show.
</Callout>

```yaml filename="endpoints / agents / pullRequests"
endpoints:
agents:
pullRequests:
token: '${GITHUB_PULL_REQUEST_TOKEN}'
allowedRepositories:
- 'LibreChat-AI/LibreChat'
- 'my-org/*'
cacheTtlSeconds: 30
maxConcurrentLookups: 4
```

On older versions, add `enabled: true`.

## backgroundTasks

Controls whether supported completed background tools and detached Subagents automatically resume their saved parent Agent.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1515,6 +1515,8 @@ see: [Model Specs Object Structure](/docs/configuration/librechat_yaml/object_st

> **Note:** Endpoints support [Shared Endpoint Settings](/docs/configuration/librechat_yaml/object_structure/shared_endpoint_settings) such as `streamRate`, `headers`, `titleModel`, `titleMethod`, `titlePrompt`, `titlePromptTemplate`, `titleEndpoint`, and `maxToolResultChars`. These can be configured individually per endpoint or globally using the `all` key. `headers` are merged with endpoint-level values winning on key collisions. The `all` key does not accept `baseURL`.

> **Note:** `endpoints.agents.pullRequests` configures the conversation pull request chip and sidebar mark. See [`pullRequests`](/docs/configuration/librechat_yaml/object_structure/agents#pullrequests).

> **Note:** `endpoints.allowedAddresses` applies to user-provided `baseURL` values (when an admin configures a custom endpoint with `apiKey: 'user_provided'` and `baseURL: 'user_provided'`). Each user-supplied baseURL is validated against the SSRF block at request time; entries listed here are exempted. See [`mcpSettings.allowedAddresses`](/docs/configuration/librechat_yaml/object_structure/mcp_settings#allowedaddresses) for the field semantics — same rules apply (private IP space only, port required, no URLs/paths/CIDR/bare hosts/public IP literals).

## mcpSettings
Expand Down
2 changes: 2 additions & 0 deletions content/docs/features/code_interpreter.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -125,6 +125,8 @@ Agents using an attached workspace can list its directory tree, read files, sear

In the chat, a failed attached-workspace Bash command shows its exit code, terminating signal, or timeout, and its stderr is styled separately from stdout. See [Activity Groups](/docs/features/agents#activity-groups) for how Bash output is displayed.

To show a conversation's GitHub pull request in the chat header and sidebar, the attached worker must report its git branch. That needs a worker built from `LibreChat-AI/code-interpreter` PR #311 or later and `CODEAPI_BRIDGE_LANE_GIT=true` set on the Code API (not on LibreChat). See [Conversation Pull Requests](/docs/features/pull_requests).

An attached worker advertises the workspace roots it makes available. The composer lets the user select one workspace for each attached environment reachable through the Agent or its Subagents; a single unambiguous workspace is selected automatically for a new conversation. LibreChat stores these selections on the conversation, revalidates them against the live worker before execution, and keeps them fixed through approval pauses and resumed runs. Sending is blocked when a required selection is missing or unavailable, and LibreChat never silently substitutes another workspace. At the start of a run, LibreChat can load repository instructions from the selected workspace so the Agent follows that repository's guidance; administrators can bound discovery with [`repositoryInstructions.timeoutMs`](/docs/configuration/librechat_yaml/object_structure/agents#repositoryinstructions). Native file and Bash workspace tools can use an advertised root even when the worker does not support reusable runtime sessions. Workspace-aware Programmatic Bash is available on compatible Code API and worker builds when the Agent's programmatic-tool configuration permits it, the authorized attached worker is ready and advertises `programmaticLanguages: ['bash']`, and both the selected workspace and worker allow `execute_command`. LibreChat passes the server-validated workspace ID and conversation workspace-instance ID, when present, to the programmatic tool; model arguments cannot replace that selection. Without these capabilities, Programmatic Bash is disabled; use direct Bash for workspace-aware commands. When the worker supports file relay, chat uploads are staged separately under `$LIBRECHAT_CODE_DATA_DIR` for the programmatic run, not copied into the selected workspace. **Stop** cancels a signal-aware in-flight BYOM command without invalidating the workspace for later commands; detached work retains its separate cancellation lifecycle.

For an attached execution environment, the Agent Builder can set a **Workspace default** to one currently advertised root. It is validated against that attached environment and used to initialize new conversations for that Agent. Choose **Last used** to use the signed-in user's browser-local preference for that Agent and environment; it is only a convenience hint, never an authorization grant or conversation binding. Changing the execution environment clears an explicit default, and a saved root that is no longer advertised remains visible but cannot be selected until it is reconfigured.
Expand Down
1 change: 1 addition & 0 deletions content/docs/features/meta.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@
"agents_api",
"artifacts",
"code_interpreter",
"pull_requests",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep the gated page out of navigation

If this commit is merged before LibreChat#16876 and the unresolved workspace-repository setup requirement are completed, this entry makes the page publicly discoverable even though the page's own publishing gate explicitly says not to publish it yet. Users can consequently follow examples that depend on unsupported default-on, token-fallback, and allowAllRepositories behavior; defer this navigation entry and the associated cross-links until those prerequisites land and the pending guidance is reverified.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed that the page must not go live early, which is why the PR body says not to merge until LibreChat#16876 lands and the page opens with a publishing-gate comment. Keeping the nav entry in this PR lets the page be reviewed in the built site, and removing it is a one-line change. Leaving this open for the maintainer to decide whether to drop the entry or hold the merge.

"---Search & Knowledge---",
"web_search",
"search",
Expand Down
Loading
Loading