Skip to content

catalogue: add io.pilot.firecrawl v0.1.0, drop io.pilot.insforge, fix agentphone metadata pin - #447

Open
Alexgodoroja wants to merge 2 commits into
mainfrom
catalogue/firecrawl-v0.1.0
Open

catalogue: add io.pilot.firecrawl v0.1.0, drop io.pilot.insforge, fix agentphone metadata pin#447
Alexgodoroja wants to merge 2 commits into
mainfrom
catalogue/firecrawl-v0.1.0

Conversation

@Alexgodoroja

Copy link
Copy Markdown
Collaborator

Three catalogue changes, one re-sign.

1. Add io.pilot.firecrawl v0.1.0

The complete Firecrawl v2 API — all 50 operations generated 1:1 from Firecrawl's published OpenAPI spec, plus firecrawl.help and the auto firecrawl.balance (51 methods). Keyless/managed: the broker holds one partner key, verifies each caller's ed25519 identity, meters per user, and enforces per-user resource ownership.

Submission merged as pilot-protocol/app-template#95. Bundle released at pilot-protocol/catalog@firecrawl-v0.1.0.

Verified end to end against this exact bundle, via a locally-signed catalogue pointing at the released URL:

  • install fetched the released tarball, bundle_sha256 matched, product_demo printed at install;
  • the daemon supervised it to ready and registered all 51 methods;
  • real calls succeeded (scrape, map, search, crawl, crawl_status, research_papers, docs_search, balance);
  • cross-tenant isolation holds: a second Pilot identity gets 404 on another user's job id, and on a cancel attempt;
  • the next_steps graph renders correctly, including a match-on-success-body edge ("status":"scraping" → keep polling).

Note: publish-on-merge could not do any of this automatically — it failed with HTTP 401 against pilot-protocol/catalog, so the CATALOG_PUBLISH_TOKEN secret needs rotating. The release and this PR were produced by hand following scripts/publish-submission.sh. The same 401 killed agentphone's publish on 2026-07-29.

2. Remove io.pilot.insforge

Dropped from apps[] as requested.

3. Fix io.pilot.agentphone's metadata pin

io.pilot.agentphone is currently broken for every client:

$ pilotctl appstore view io.pilot.agentphone
warn: could not load detail metadata: metadata sha256 mismatch for io.pilot.agentphone:
      want=d1b5fea717be1a3c21fc3fcf38c23362b8a727502e822c23dd3c831dab950823
      got=452d988a4814c3e92f2af095e7a02466a150f088478dda819fec2d6c724fbb9a

catalogue.json and catalogue/apps/io.pilot.agentphone/metadata.json were changed in the same commit (#438, 216bcfc), but the recorded metadata_sha256 was computed from a different revision of the file than the one committed. The served bytes have hashed to 452d988a… ever since, so the store page fails its integrity check.

Fixed by pinning the sha of the metadata actually being served. No metadata content change.

Signature

catalogue.json re-signed with CATALOG_SIGN_KEY; verified against the embedded trust anchor (iHdBWayA/hYjkwUOZopTXY70qOlR90d6ii/hin0ZMdI=) before pushing. Still version: 2.

🤖 Generated with Claude Code

… agentphone metadata pin

- add io.pilot.firecrawl v0.1.0 (full Firecrawl v2 API, 51 methods, managed/keyless)
- remove io.pilot.insforge
- fix io.pilot.agentphone metadata_sha256: the pin has been wrong since #438, so
  every client fails the integrity check on its store page
- catalogue.json re-signed with CATALOG_SIGN_KEY

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The store page and the install-time demo were publishing our cost basis with
Firecrawl: the micro-USD ledger unit, the 1 credit ~= 830 micro-USD conversion,
per-operation dollar prices, and that Pilot runs one shared Firecrawl team.

Restated as the published per-user limits: 1000 credits, 2 concurrent calls.
metadata_sha256 recomputed and catalogue.json re-signed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant