| Filename | Latest commit message | Latest commit date |
|---|---|---|
hive-matrix-daemon now learns which external matrix accounts it has from the swarm secret store, under the agent's own certificate, and the hive push chain for matrix is gone. The daemon lists swarm/agents/<agent>/matrix/ (the `list` its policy grants on its own metadata subtree), reads each account's homeserver from its credential, and brings the accounts up with their tokens from the store. Every two minutes it lists again and exits with 75 when the set of linked accounts changed; the unit restarts on 75 without counting a failure. A listed name whose credential reads as absent is skipped and logged once. At start it removes the matrix-token-<a> / matrix-account-<a>.json pairs a hive delivered (a sidecar marks a pair as delivered; a declared tokenFile keeps its token). Removed: CredentialNotice and the $SWARM.credential.* subject and NATS grant, the controller's publish and its queue precondition on the PUT route, hive-c0re's credential subscription arm and workers/credential.rs, priv_client::write_agent_matrix_token, hive-priv's WriteAgentMatrixToken and its helpers, and the daemon's state-dir account discovery. Kept: WriteAgentGithubToken and the external-forge path (WriteAgentExtraForgeAccount, extra_forges.rs) are untouched, and a declared matrixAccounts tokenFile is still read when the store has no token for that account. Refs #4348 |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-matrix-mcp
Per-agent matrix integration: a long-running daemon
(hive-matrix-daemon) that holds a matrix-sdk Client + sync loop per
configured account and serves the matrix tool surface (send_message,
send_dm, list_rooms, read_room, …) directly over streamable-http.
No stdio bridge, no per-turn respawn — claude reconnects to the same
stable URL every turn.
When to use it
Look here when changing matrix tool behaviour, multi-account handling,
or the incoming-event → todo/wake path. The daemon owns the whole
lifecycle: per-account bring-up (accounts.rs, client.rs), the sync
loop that sweeps invites/unread rooms into the harness's in-agent todo
socket (timeline.rs, wake.rs), and the MCP tool router itself
(mcp.rs).
Shape
One bin (hive-matrix-daemon, src/main.rs) built from the crate's
own lib (src/lib.rs):
accounts.rs— multi-account config + the account→Clientdispatch registry (mainis always the hive-internal primary; extras come fromHIVE_MATRIX_ACCOUNTS).client.rs— session restore, stale-token recovery, avatar sync, cross-signing bootstrap.timeline.rs/wake.rs— per-sync-callback invite/unread sweeps that push todos ontoHIVE_AGENT_SOCKET.handlers.rs— per-tool dispatch, returnsprotocol::DaemonResponse.mcp.rs— thermcptool router +serve_http, resolving each call's optionalaccountarg against the registry before calling intohandlers.paths.rs— per-agent path resolution (token file, matrix-sdk state dir, homeserver URL, accounts snapshot).