DashClaw Platform Intelligence
Shape snapshot: sha1:22c84d9f7ccd4188bead232ffdde419e68578ba3
This file is auto-generated. Do not edit by hand — regenerate with:
python -m livingcode emit skill --output <path-to-SKILL.md>
Prefer Live Queries
The facts below are a snapshot. Before answering any question about DashClaw's current
structure, routes, env vars, or schema — run a live query:
python -m livingcode query summary # High-level shape
python -m livingcode query routes # Current API surface
python -m livingcode query env # Current env vars
python -m livingcode query tables # Current schema
python -m livingcode query all --json # Full machine-readable shape
If the snapshot below disagrees with a live query, trust the live query.
Fallback: no Python, livingcode, or repo checkout
python -m livingcode only works where the livingcode package and the repo
checkout are present (e.g. a developer machine). In OpenClaw / the Claude app
neither exists. When you cannot run the queries above, fall back in this order:
GET {baseUrl}/api/doctor — live route/shape health straight from the running
instance. Requires the workspace API key (x-api-key: <key>); returns 401/403
without it. This is the authoritative live source when the CLI is unavailable.
- Read the committed static shape if a repo checkout is reachable:
app/lib/doctor/generated/shape.json (full machine-readable shape) and
docs/api-inventory.json (route inventory). These are regenerated on every
npm run livingcode:refresh, so they track the same facts the queries return.
- Otherwise, treat the snapshot in this SKILL.md as authoritative — it is the
best available source when neither the API nor the repo can be reached.
At a Glance
- 226 active API routes across 57 categories
- 4 required + 137 optional environment variables
- 89 database tables
API Surface
actions
DELETE, GET, POST /api/actions
GET, PATCH /api/actions/[actionId]
GET /api/actions/[actionId]/artifacts
GET /api/actions/[actionId]/graph
GET /api/actions/[actionId]/messages
GET, POST /api/actions/[actionId]/outcome
GET /api/actions/[actionId]/trace
GET /api/actions/costs
GET, POST /api/actions/loops
GET, PATCH /api/actions/loops/[loopId]
GET /api/actions/stats
activity
admin
POST /api/admin/trigger-outcome-sweep
agents
GET /api/agents
GET /api/agents/[agentId]
GET /api/agents/[agentId]/profile
GET, POST /api/agents/connections
POST /api/agents/heartbeat
analytics
approvals
POST /api/approvals/[actionId]
artifacts
GET, POST /api/artifacts
DELETE, GET /api/artifacts/[artifactId]
POST /api/artifacts/evidence-bundle
assumptions
GET, POST /api/assumptions
GET, PATCH /api/assumptions/[assumptionId]
auth
- /api/auth/[...nextauth]
GET /api/auth/config
DELETE, POST /api/auth/local
behavior
GET, POST /api/behavior/recorder
GET /api/behavior/samples
POST /api/behavior/simulate
GET, POST /api/behavior/suggestions
billing
POST /api/billing/checkout
GET /api/billing/portal
capabilities
GET, POST /api/capabilities
DELETE, GET, PATCH /api/capabilities/[capabilityId]
GET, POST /api/capabilities/[capabilityId]/access
DELETE /api/capabilities/[capabilityId]/access/[ruleId]
GET /api/capabilities/[capabilityId]/access/check
GET /api/capabilities/[capabilityId]/health
GET /api/capabilities/[capabilityId]/history
POST /api/capabilities/[capabilityId]/invoke
POST /api/capabilities/[capabilityId]/test
GET /api/capabilities/health
code-sessions
GET /api/code-sessions/alerts
POST /api/code-sessions/alerts/read-all
POST /api/code-sessions/ingest-jsonl
POST /api/code-sessions/ingest-live
GET /api/code-sessions/manifests/[manifestId]
GET /api/code-sessions/memos
POST /api/code-sessions/memos/regenerate
GET /api/code-sessions/projects
GET /api/code-sessions/projects/[projectId]/sessions
GET /api/code-sessions/sessions/[sessionId]
GET /api/code-sessions/sessions/[sessionId]/autopsy
GET /api/code-sessions/sessions/[sessionId]/insights
POST /api/code-sessions/sessions/[sessionId]/optimal-files/manifest
POST /api/code-sessions/sessions/[sessionId]/optimal-files/merge-preview
POST /api/code-sessions/sessions/[sessionId]/optimal-files/preview
GET /api/code-sessions/subagent-roi
compliance
GET /api/compliance/evidence
GET, POST /api/compliance/exports
DELETE, GET /api/compliance/exports/[exportId]
GET /api/compliance/exports/[exportId]/download
GET /api/compliance/frameworks
GET /api/compliance/gaps
GET /api/compliance/map
GET /api/compliance/report
GET, POST /api/compliance/schedules
DELETE, PATCH /api/compliance/schedules/[scheduleId]
GET /api/compliance/trends
cron
GET /api/cron/code-session-cache-crater
GET /api/cron/code-session-weekly-memo
GET /api/cron/integration-health
GET /api/cron/jti-sweep
GET /api/cron/learning-episodes-backfill
GET /api/cron/learning-recommendations
GET /api/cron/memory-maintenance
GET /api/cron/outcome-sweep
GET /api/cron/policy-suggestions
GET /api/cron/reset-meters
POST /api/cron/routing-maintenance
GET /api/cron/signals
discord
POST /api/discord/interactions
docs
doctor
GET /api/doctor
POST /api/doctor/fix
drift
GET, POST /api/drift/alerts
DELETE, PATCH /api/drift/alerts/[alertId]
GET /api/drift/metrics
GET /api/drift/snapshots
GET /api/drift/stats
evaluations
GET, POST /api/evaluations
GET, POST /api/evaluations/runs
GET, PATCH /api/evaluations/runs/[runId]
GET, POST /api/evaluations/scorers
DELETE, PATCH /api/evaluations/scorers/[scorerId]
POST /api/evaluations/scorers/preview
GET /api/evaluations/stats
guard
GET, POST /api/guard
GET /api/guard/decisions
handoffs
GET, POST /api/handoffs
GET /api/handoffs/[id]
POST /api/handoffs/[id]/consume
GET /api/handoffs/latest
health
hosted
POST /api/hosted/cleanup
GET, POST /api/hosted/workspaces
DELETE, GET /api/hosted/workspaces/[workspaceId]
identities
GET, POST /api/identities
DELETE /api/identities/[agentId]
integrations
GET /api/integrations/health
POST /api/integrations/health/refresh
integrity
GET /api/integrity/jwks
POST /api/integrity/verify
invite
GET, POST /api/invite/[token]
keys
DELETE, GET, POST /api/keys
GET /api/keys/reveal
knowledge
GET, POST /api/knowledge/collections
DELETE, GET, PATCH /api/knowledge/collections/[collectionId]
GET, POST /api/knowledge/collections/[collectionId]/items
POST /api/knowledge/collections/[collectionId]/search
POST /api/knowledge/collections/[collectionId]/sync
learning
GET, POST /api/learning
GET, POST /api/learning/analytics/curves
GET /api/learning/analytics/maturity
GET /api/learning/analytics/summary
GET, POST /api/learning/analytics/velocity
GET /api/learning/code-signals
GET /api/learning/lessons
GET, POST /api/learning/recommendations
PATCH /api/learning/recommendations/[recommendationId]
POST /api/learning/recommendations/events
GET /api/learning/recommendations/metrics
GET, POST /api/learning/suggestions
marketing
POST /api/marketing/event
mcp
messages
GET, PATCH, POST /api/messages
GET /api/messages/attachments
GET, PATCH, POST /api/messages/threads
GET /api/messages/threads/[threadId]
model-strategies
GET, POST /api/model-strategies
DELETE, GET, PATCH /api/model-strategies/[strategyId]
POST /api/model-strategies/[strategyId]/complete
oauth
GET, POST /api/oauth/authorize
GET /api/oauth/metadata/authorization-server
GET /api/oauth/metadata/protected-resource
POST /api/oauth/register
POST /api/oauth/token
operations
GET /api/operations/feed
GET /api/operations/summary
orgs
GET, POST /api/orgs
GET, PATCH /api/orgs/[orgId]
DELETE, GET, POST /api/orgs/[orgId]/keys
pairings
GET, POST /api/pairings
GET, PATCH /api/pairings/[pairingId]
POST /api/pairings/[pairingId]/approve
policies
DELETE, GET, PATCH, POST /api/policies
POST /api/policies/generate
POST /api/policies/import
GET /api/policies/proof
POST /api/policies/simulate
GET /api/policies/templates
POST /api/policies/test
prompts
GET /api/prompts/agent-connect/raw
POST /api/prompts/render
GET /api/prompts/runs
GET /api/prompts/sdk-coverage/raw
GET /api/prompts/server-setup/raw
GET /api/prompts/stats
GET, POST /api/prompts/templates
DELETE, GET, PATCH /api/prompts/templates/[templateId]
GET, POST /api/prompts/templates/[templateId]/versions
GET, POST /api/prompts/templates/[templateId]/versions/[versionId]
scoring
POST /api/scoring/calibrate
GET, POST /api/scoring/profiles
DELETE, GET, PATCH /api/scoring/profiles/[profileId]
POST /api/scoring/profiles/[profileId]/dimensions
DELETE, PATCH /api/scoring/profiles/[profileId]/dimensions/[dimensionId]
GET, POST /api/scoring/risk-templates
DELETE, PATCH /api/scoring/risk-templates/[templateId]
GET, POST /api/scoring/score
secrets
GET, POST /api/secrets
DELETE, PATCH /api/secrets/[id]
GET /api/secrets/rotation-due
security
GET, POST /api/security/prompt-injection
POST /api/security/scan
GET /api/security/status
session
GET /api/session/effective
sessions
GET, POST /api/sessions
GET, PATCH /api/sessions/[sessionId]
GET /api/sessions/[sessionId]/events
settings
DELETE, GET, POST /api/settings
GET /api/settings/llm-status
POST /api/settings/test
setup
POST /api/setup/live-proof
POST /api/setup/migrate
POST /api/setup/ping
GET /api/setup/proof
GET /api/setup/status
signals
skills
POST /api/skills/scan
GET /api/skills/scans/[id]
stream
swarm
GET /api/swarm/graph
GET /api/swarm/link
team
GET /api/team
DELETE, PATCH /api/team/[userId]
DELETE, GET, POST /api/team/invite
telegram
POST /api/telegram/webhook
usage
GET /api/usage
GET /api/usage/costs
webhooks
DELETE, GET, POST /api/webhooks
GET /api/webhooks/[webhookId]/deliveries
POST /api/webhooks/[webhookId]/test
POST /api/webhooks/stripe
workflows
POST /api/workflows/draft
GET, POST /api/workflows/templates
DELETE, GET, PATCH /api/workflows/templates/[templateId]
POST /api/workflows/templates/[templateId]/duplicate
POST /api/workflows/templates/[templateId]/execute
POST /api/workflows/templates/[templateId]/launch
GET /api/workflows/templates/[templateId]/runs
GET /api/workflows/templates/[templateId]/runs/[runActionId]
POST /api/workflows/templates/[templateId]/runs/[runActionId]/cancel
POST /api/workflows/templates/[templateId]/runs/[runActionId]/resume
Required Environment Variables
These must be set — DashClaw will fail to start without them.
DASHCLAW_API_KEY - referenced in 56 file(s)
DATABASE_URL - referenced in 87 file(s)
ENCRYPTION_KEY - referenced in 4 file(s)
NEXTAUTH_SECRET - referenced in 5 file(s)
Optional Environment Variables
These have fallbacks or only activate specific features.
AGENT_ONLINE_WINDOW_MS (undocumented)
AGENT_PRIVATE_KEY (undocumented)
AGENT_PRIVATE_KEY_JWK (undocumented)
ALERT_FROM_EMAIL (undocumented)
ALLOWED_ORIGIN (undocumented)
ANTHROPIC_API_KEY (undocumented)
ANTHROPIC_MODEL (undocumented)
API_INVENTORY_VERIFIED_DATE (undocumented)
API_SECRET (undocumented)
BASE_URL (undocumented)
CI (undocumented)
CONVERGENCE_BENCH_CONCURRENCY (undocumented)
CONVERGENCE_BENCH_ITERATIONS (undocumented)
CONVERGENCE_REPLAY_CONNECT_TIMEOUT_MS (undocumented)
CONVERGENCE_RETRY_429_MAX (undocumented)
CONVERGENCE_RETRY_429_WAIT_MS (undocumented)
CONVERGENCE_SSE_SEND_COUNT (undocumented)
CONVERGENCE_VERBOSE (undocumented)
CRON_SECRET (undocumented)
DASHCLAW_ACT_BINDING (undocumented)
DASHCLAW_ACT_BINDING_TYP (undocumented)
DASHCLAW_AGENT_ID (undocumented)
DASHCLAW_ALERTS_DISCORD (undocumented)
DASHCLAW_ALERTS_TELEGRAM (undocumented)
DASHCLAW_ALLOWED_ISSUER (undocumented)
DASHCLAW_API_KEY_ORG (undocumented)
DASHCLAW_BASE_URL (undocumented)
DASHCLAW_BEHAVIOR_SAMPLES_DIR (undocumented)
DASHCLAW_BEHAVIOR_SAMPLES_ENABLED (undocumented)
DASHCLAW_CLOSED_ENROLLMENT (undocumented)
DASHCLAW_DB_DRIVER (undocumented)
DASHCLAW_DB_POOL_MAX (undocumented)
DASHCLAW_DISABLE_RATE_LIMIT (undocumented)
DASHCLAW_GUARD_FALLBACK (undocumented)
DASHCLAW_GUARD_UNAVAILABLE_POLICY (undocumented)
DASHCLAW_HOSTED (undocumented)
DASHCLAW_JTI_MAX_TTL_SECONDS (undocumented)
DASHCLAW_JTI_REPLAY_PROTECTION (undocumented)
DASHCLAW_JWT_AUDIENCE (undocumented)
DASHCLAW_LOCAL_ADMIN_PASSWORD (undocumented)
DASHCLAW_MAX_ORG_ATTACHMENT_BYTES (undocumented)
DASHCLAW_MODE (undocumented)
DASHCLAW_NEW_CONNECT_WEBHOOK (undocumented)
DASHCLAW_PAIRING_TTL_MINUTES (undocumented)
DASHCLAW_RATE_LIMIT_MAX (undocumented)
DASHCLAW_RATE_LIMIT_WINDOW_MS (undocumented)
DASHCLAW_SIGNING_KEY_JWK (undocumented)
DASHCLAW_URL (undocumented)
DISABLE_PROMPT_INJECTION_SCAN (undocumented)
DISCORD_APPROVER_ORG_ID (undocumented)
DISCORD_APPROVER_USER_ID (undocumented)
DISCORD_BOT_TOKEN (undocumented)
DISCORD_PUBLIC_KEY (undocumented)
ENFORCE_AGENT_SIGNATURES (undocumented)
GITHUB_CLIENT_ID (undocumented)
GITHUB_CLIENT_SECRET (undocumented)
GITHUB_ID (undocumented)
GITHUB_REPO_NAME (undocumented)
GITHUB_REPO_OWNER (undocumented)
GITHUB_SECRET (undocumented)
GITHUB_TOKEN (undocumented)
GOOGLE_AI_API_KEY (undocumented)
GOOGLE_CLIENT_ID (undocumented)
GOOGLE_CLIENT_SECRET (undocumented)
GOOGLE_ID (undocumented)
GOOGLE_SECRET (undocumented)
GUARD_LLM_BASE_URL (undocumented)
GUARD_LLM_KEY (undocumented)
GUARD_LLM_MODEL (undocumented)
GUARD_WEBHOOK_SECRET (undocumented)
HOSTED_CLEANUP_SECRET (undocumented)
HOSTED_PROVISION_MAX_PER_IP_PER_DAY (undocumented)
HOSTED_SMOKE_BASE_URL (undocumented)
HOSTED_TRIAL_ACTION_CAP (undocumented)
HOSTED_TRIAL_DAYS (undocumented)
INTEGRATION_DATABASE_URL (undocumented)
MOONSHOT_API_KEY (undocumented)
NEXTAUTH_URL
NEXT_PUBLIC_ (undocumented)
NEXT_PUBLIC_APP_URL (undocumented)
NEXT_PUBLIC_DASHCLAW_MODE (undocumented)
NEXT_PUBLIC_DASHCLAW_VERSION (undocumented)
NEXT_PUBLIC_ENABLE_VERCEL_ANALYTICS (undocumented)
NEXT_PUBLIC_PLUGIN_MANIFEST_VERSION (undocumented)
NEXT_PUBLIC_SDK_NODE_VERSION (undocumented)
NEXT_PUBLIC_SDK_PYTHON_VERSION (undocumented)
NEXT_PUBLIC_TURNSTILE_SITE_KEY (undocumented)
NODE_ENV (undocumented)
OIDC_AUTHORIZATION_URL (undocumented)
OIDC_CLIENT_ID (undocumented)
OIDC_CLIENT_SECRET (undocumented)
OIDC_DISPLAY_NAME (undocumented)
OIDC_ISSUER_URL (undocumented)
OIDC_TOKEN_URL (undocumented)
OIDC_USERINFO_URL (undocumented)
OPENAI_API_KEY (undocumented)
ORG_ID (undocumented)
PORT (undocumented)
PW_BASE_URL (undocumented)
PW_SMOKE_PORT (undocumented)
PYTHON (undocumented)
PYTHONPATH (undocumented)
REALTIME_BACKEND (undocumented)
REALTIME_ENFORCE_REDIS (undocumented)
REALTIME_MAX_LISTENERS (undocumented)
REALTIME_MEMORY_MAX_LISTENERS (undocumented)
REALTIME_REDIS_URL (undocumented)
REALTIME_REPLAY_MAX_EVENTS (undocumented)
REALTIME_REPLAY_WINDOW_SECONDS (undocumented)
REDIS_URL (undocumented)
RESEARCH_API_KEY (undocumented)
RESEARCH_API_URL (undocumented)
RESEND_API_KEY (undocumented)
S (undocumented)
SERVICE_NAME (undocumented)
STARTUP_SMOKE_BASE_URL (undocumented)
STARTUP_SMOKE_INTERVAL_MS (undocumented)
STARTUP_SMOKE_TIMEOUT_MS (undocumented)
STRIPE_PRICE_BUSINESS (undocumented)
STRIPE_PRICE_PRO (undocumented)
STRIPE_SECRET_KEY (undocumented)
STRIPE_WEBHOOK_SECRET (undocumented)
TARGET_ENV (undocumented)
TELEGRAM_ADMIN_CHAT_ID (undocumented)
TELEGRAM_APPROVER_ORG_ID (undocumented)
TELEGRAM_BOT_TOKEN (undocumented)
TELEGRAM_WEBHOOK_SECRET (undocumented)
TEST_BASE_URL (undocumented)
TRUST_PROXY (undocumented)
TURNSTILE_SECRET_KEY (undocumented)
UPSTASH_REDIS_REST_TOKEN (undocumented)
UPSTASH_REDIS_REST_URL (undocumented)
VERCEL (undocumented)
VERCEL_PROJECT_PRODUCTION_URL (undocumented)
VERCEL_URL (undocumented)
WEBHOOK_ALLOWED_DOMAINS (undocumented)
X (undocumented)
Database Tables
All 89 tables defined in schema/schema.js (Drizzle ORM):
action_embeddings
action_records
activity_logs
agent_connections
agent_identities
agent_messages
agent_pairings
agent_presence
agent_schedules
agent_sessions
api_keys
assumptions
calendar_events
code_optimal_file_manifests
code_projects
code_session_alerts
code_session_handoffs
code_session_memos
code_session_messages
code_session_signals
code_session_tool_uses
code_sessions
compliance_snapshots
contacts
content
context_entries
context_points
daily_totals
decisions
drift_alerts
drift_baselines
drift_snapshots
entities
eval_runs
eval_scores
executions
feedback
goals
governed_secrets
guard_decisions
guard_policies
guardrails_test_runs
health_snapshots
ideas
interactions
jwt_replay_log
learning_curves
learning_episodes
learning_recommendation_events
learning_recommendations
learning_velocity
message_threads
milestones
notification_preferences
oauth_access_tokens
oauth_authorization_codes
oauth_clients
open_loops
organizations
profile_scores
prompt_runs
prompt_templates
prompt_versions
risk_templates
routing_agent_metrics
routing_agents
routing_decisions
routing_tasks
scheduled_jobs
scoring_dimensions
scoring_profiles
server_signing_keys
session_events
shared_docs
skill_scan_results
snippets
token_budgets
token_snapshots
topics
usage_meters
user_approaches
user_moods
user_observations
user_preferences
users
waitlist
webhook_deliveries
webhooks
workflows
Configuration Knobs
Per-org settings stored in the settings table. Set via PUT /api/settings/:key or the web Settings/Integrations UI. Keys marked sensitive are auto-encrypted at rest.
AI Providers
OPENAI_API_KEY
OPENAI_ORG_ID
ANTHROPIC_API_KEY
GROQ_API_KEY
TOGETHER_API_KEY
REPLICATE_API_TOKEN
HUGGINGFACE_API_KEY
PERPLEXITY_API_KEY
ELEVENLABS_API_KEY
ELEVENLABS_VOICE_ID
Databases
DATABASE_URL
SUPABASE_URL
SUPABASE_ANON_KEY
SUPABASE_SERVICE_KEY
PLANETSCALE_URL
MONGODB_URI
REDIS_URL
PINECONE_API_KEY
PINECONE_ENVIRONMENT
Communication
TELEGRAM_BOT_TOKEN
TELEGRAM_ADMIN_CHAT_ID
DASHCLAW_ALERTS_TELEGRAM
DISCORD_BOT_TOKEN
DISCORD_CLIENT_ID
DISCORD_GUILD_ID
SLACK_BOT_TOKEN
SLACK_SIGNING_SECRET
SLACK_APP_TOKEN
TWILIO_ACCOUNT_SID
TWILIO_AUTH_TOKEN
TWILIO_PHONE_NUMBER
RESEND_API_KEY
SENDGRID_API_KEY
Productivity
GOOGLE_ACCOUNT
GOOGLE_CREDENTIALS_PATH
NOTION_API_KEY
NOTION_PARENT_PAGE_ID
LINEAR_API_KEY
AIRTABLE_API_KEY
AIRTABLE_BASE_ID
CALENDLY_API_KEY
Development
GITHUB_TOKEN
GITHUB_USERNAME
VERCEL_TOKEN
VERCEL_PROJECT_ID
RAILWAY_TOKEN
CLOUDFLARE_API_TOKEN
CLOUDFLARE_ACCOUNT_ID
SENTRY_DSN
SENTRY_AUTH_TOKEN
Social
TWITTER_API_KEY
TWITTER_API_SECRET
TWITTER_ACCESS_TOKEN
TWITTER_ACCESS_SECRET
BRAVE_API_KEY
MOLTBOOK_API_KEY
Payments
STRIPE_SECRET_KEY
STRIPE_PUBLISHABLE_KEY
STRIPE_WEBHOOK_SECRET
LEMONSQUEEZY_API_KEY
Native governance alert settings
DASHCLAW_ALERTS_SLACK
DASHCLAW_ALERTS_DISCORD
DASHCLAW_ALERTS_LINEAR
DASHCLAW_ALERTS_GITHUB
DASHCLAW_ALERTS_EMAIL
DASHCLAW_ALERT_EMAIL
SLACK_CHANNEL_ID
SLACK_WEBHOOK_URL
DISCORD_WEBHOOK_URL
GITHUB_REPO
SENDGRID_DEFAULT_TO
SENDGRID_FROM_EMAIL
webhooks + native adapters deliver a signal. Empty/unset = disabled.
DASHCLAW_ACTION_COST_THRESHOLD
System configuration
MODEL_PRICING
ENFORCE_AGENT_SIGNATURES
Predictive risk scoring
PREDICTIVE_RISK_ENABLED
PREDICTIVE_RISK_THRESHOLD
docs/architecture/durable-execution-finality.md.
DASHCLAW_OUTCOME_TIMEOUT_MINUTES
DASHCLAW_BEHAVIOR_SAMPLES_ENABLED env var still overrides them.
BEHAVIOR_RECORDER_ENABLED
BEHAVIOR_RECORDER_UNTIL
content contains a detected secret/credential. Default (unset) = warn only.
Realtime & Webhook Events
Every mutation that Mission Control reflects and every webhook delivery is keyed on these event strings. Subscribe via GET /api/events (SSE) or register a webhook with the matching events: [...] array.
| Constant |
Event |
ACTION_COST_EXCEEDED |
action.cost_exceeded |
ACTION_CREATED |
action.created |
ACTION_UPDATED |
action.updated |
DECISION_CREATED |
decision.created |
GOAL_CREATED |
goal.created |
GOAL_UPDATED |
goal.updated |
GUARD_DECISION_CREATED |
guard.decision.created |
LOOP_CREATED |
loop.created |
LOOP_UPDATED |
loop.updated |
MESSAGE_CREATED |
message.created |
POLICY_UPDATED |
policy.updated |
SIGNAL_DETECTED |
signal.detected |
TASK_ASSIGNED |
task.assigned |
TASK_COMPLETED |
task.completed |
TOKEN_USAGE |
token.usage |
Signal Types
These are the type strings emitted through fireWebhooksForOrg and deliverNativeNotifications. Webhooks can subscribe to any subset by putting the type in their events: [...] array (or use ['all'] for everything).
autonomy_spike
branch_stale
cost_exceeded
green_insufficient
integration_health_changed
integration_mismatch
lost_confirmation
mcp_degraded
stale_action
test
Native Notification Adapters
Each adapter delivers integration_mismatch, integration_health_changed, and cost_exceeded signals when at least one of its required credential keys is configured. Per-channel opt-out via DASHCLAW_ALERTS_<NAME>=false.
| Adapter |
Required credential (any one) |
org_id |
DISCORD_WEBHOOK_URL |
email |
RESEND_API_KEY, SENDGRID_API_KEY |
github |
GITHUB_TOKEN |
linear |
LINEAR_API_KEY |
slack |
SLACK_BOT_TOKEN, SLACK_WEBHOOK_URL |
Detecting Drift
To check whether this snapshot matches the current codebase:
python -m livingcode diff
If the diff shows changes, this skill is stale — regenerate it.
1---2name: dashclaw-platform-intelligence3description: DashClaw platform expert for integration, troubleshooting, and governance. Snapshot-based — prefer live queries via `python -m livingcode query`, or `GET {baseUrl}/api/doctor` when Python/livingcode/the repo are unavailable.4---56# DashClaw Platform Intelligence78**Shape snapshot:** `sha1:22c84d9f7ccd4188bead232ffdde419e68578ba3`9**This file is auto-generated.** Do not edit by hand — regenerate with:1011```bash12python -m livingcode emit skill --output <path-to-SKILL.md>13```1415## Prefer Live Queries1617The facts below are a snapshot. Before answering any question about DashClaw's current18structure, routes, env vars, or schema — run a live query:1920```bash21python -m livingcode query summary # High-level shape22python -m livingcode query routes # Current API surface23python -m livingcode query env # Current env vars24python -m livingcode query tables # Current schema25python -m livingcode query all --json # Full machine-readable shape26```2728If the snapshot below disagrees with a live query, **trust the live query**.2930### Fallback: no Python, livingcode, or repo checkout3132`python -m livingcode` only works where the livingcode package and the repo33checkout are present (e.g. a developer machine). In OpenClaw / the Claude app34neither exists. When you cannot run the queries above, fall back **in this order**:35361. **`GET {baseUrl}/api/doctor`** — live route/shape health straight from the running37 instance. Requires the workspace API key (`x-api-key: <key>`); returns 401/40338 without it. This is the authoritative live source when the CLI is unavailable.392. **Read the committed static shape** if a repo checkout is reachable:40 `app/lib/doctor/generated/shape.json` (full machine-readable shape) and41 `docs/api-inventory.json` (route inventory). These are regenerated on every42 `npm run livingcode:refresh`, so they track the same facts the queries return.433. **Otherwise, treat the snapshot in this SKILL.md as authoritative** — it is the44 best available source when neither the API nor the repo can be reached.4546## At a Glance4748- **226** active API routes across **57** categories49- **4** required + **137** optional environment variables50- **89** database tables5152## API Surface5354### `actions`5556- `DELETE, GET, POST` `/api/actions`57- `GET, PATCH` `/api/actions/[actionId]`58- `GET` `/api/actions/[actionId]/artifacts`59- `GET` `/api/actions/[actionId]/graph`60- `GET` `/api/actions/[actionId]/messages`61- `GET, POST` `/api/actions/[actionId]/outcome`62- `GET` `/api/actions/[actionId]/trace`63- `GET` `/api/actions/costs`64- `GET, POST` `/api/actions/loops`65- `GET, PATCH` `/api/actions/loops/[loopId]`66- `GET` `/api/actions/stats`6768### `activity`6970- `GET` `/api/activity`7172### `admin`7374- `POST` `/api/admin/trigger-outcome-sweep`7576### `agents`7778- `GET` `/api/agents`79- `GET` `/api/agents/[agentId]`80- `GET` `/api/agents/[agentId]/profile`81- `GET, POST` `/api/agents/connections`82- `POST` `/api/agents/heartbeat`8384### `analytics`8586- `GET` `/api/analytics`8788### `approvals`8990- `POST` `/api/approvals/[actionId]`9192### `artifacts`9394- `GET, POST` `/api/artifacts`95- `DELETE, GET` `/api/artifacts/[artifactId]`96- `POST` `/api/artifacts/evidence-bundle`9798### `assumptions`99100- `GET, POST` `/api/assumptions`101- `GET, PATCH` `/api/assumptions/[assumptionId]`102103### `auth`104105- `-` `/api/auth/[...nextauth]`106- `GET` `/api/auth/config`107- `DELETE, POST` `/api/auth/local`108109### `behavior`110111- `GET, POST` `/api/behavior/recorder`112- `GET` `/api/behavior/samples`113- `POST` `/api/behavior/simulate`114- `GET, POST` `/api/behavior/suggestions`115116### `billing`117118- `POST` `/api/billing/checkout`119- `GET` `/api/billing/portal`120121### `capabilities`122123- `GET, POST` `/api/capabilities`124- `DELETE, GET, PATCH` `/api/capabilities/[capabilityId]`125- `GET, POST` `/api/capabilities/[capabilityId]/access`126- `DELETE` `/api/capabilities/[capabilityId]/access/[ruleId]`127- `GET` `/api/capabilities/[capabilityId]/access/check`128- `GET` `/api/capabilities/[capabilityId]/health`129- `GET` `/api/capabilities/[capabilityId]/history`130- `POST` `/api/capabilities/[capabilityId]/invoke`131- `POST` `/api/capabilities/[capabilityId]/test`132- `GET` `/api/capabilities/health`133134### `code-sessions`135136- `GET` `/api/code-sessions/alerts`137- `POST` `/api/code-sessions/alerts/read-all`138- `POST` `/api/code-sessions/ingest-jsonl`139- `POST` `/api/code-sessions/ingest-live`140- `GET` `/api/code-sessions/manifests/[manifestId]`141- `GET` `/api/code-sessions/memos`142- `POST` `/api/code-sessions/memos/regenerate`143- `GET` `/api/code-sessions/projects`144- `GET` `/api/code-sessions/projects/[projectId]/sessions`145- `GET` `/api/code-sessions/sessions/[sessionId]`146- `GET` `/api/code-sessions/sessions/[sessionId]/autopsy`147- `GET` `/api/code-sessions/sessions/[sessionId]/insights`148- `POST` `/api/code-sessions/sessions/[sessionId]/optimal-files/manifest`149- `POST` `/api/code-sessions/sessions/[sessionId]/optimal-files/merge-preview`150- `POST` `/api/code-sessions/sessions/[sessionId]/optimal-files/preview`151- `GET` `/api/code-sessions/subagent-roi`152153### `compliance`154155- `GET` `/api/compliance/evidence`156- `GET, POST` `/api/compliance/exports`157- `DELETE, GET` `/api/compliance/exports/[exportId]`158- `GET` `/api/compliance/exports/[exportId]/download`159- `GET` `/api/compliance/frameworks`160- `GET` `/api/compliance/gaps`161- `GET` `/api/compliance/map`162- `GET` `/api/compliance/report`163- `GET, POST` `/api/compliance/schedules`164- `DELETE, PATCH` `/api/compliance/schedules/[scheduleId]`165- `GET` `/api/compliance/trends`166167### `cron`168169- `GET` `/api/cron/code-session-cache-crater`170- `GET` `/api/cron/code-session-weekly-memo`171- `GET` `/api/cron/integration-health`172- `GET` `/api/cron/jti-sweep`173- `GET` `/api/cron/learning-episodes-backfill`174- `GET` `/api/cron/learning-recommendations`175- `GET` `/api/cron/memory-maintenance`176- `GET` `/api/cron/outcome-sweep`177- `GET` `/api/cron/policy-suggestions`178- `GET` `/api/cron/reset-meters`179- `POST` `/api/cron/routing-maintenance`180- `GET` `/api/cron/signals`181182### `discord`183184- `POST` `/api/discord/interactions`185186### `docs`187188- `GET` `/api/docs/raw`189190### `doctor`191192- `GET` `/api/doctor`193- `POST` `/api/doctor/fix`194195### `drift`196197- `GET, POST` `/api/drift/alerts`198- `DELETE, PATCH` `/api/drift/alerts/[alertId]`199- `GET` `/api/drift/metrics`200- `GET` `/api/drift/snapshots`201- `GET` `/api/drift/stats`202203### `evaluations`204205- `GET, POST` `/api/evaluations`206- `GET, POST` `/api/evaluations/runs`207- `GET, PATCH` `/api/evaluations/runs/[runId]`208- `GET, POST` `/api/evaluations/scorers`209- `DELETE, PATCH` `/api/evaluations/scorers/[scorerId]`210- `POST` `/api/evaluations/scorers/preview`211- `GET` `/api/evaluations/stats`212213### `guard`214215- `GET, POST` `/api/guard`216- `GET` `/api/guard/decisions`217218### `handoffs`219220- `GET, POST` `/api/handoffs`221- `GET` `/api/handoffs/[id]`222- `POST` `/api/handoffs/[id]/consume`223- `GET` `/api/handoffs/latest`224225### `health`226227- `GET` `/api/health`228229### `hosted`230231- `POST` `/api/hosted/cleanup`232- `GET, POST` `/api/hosted/workspaces`233- `DELETE, GET` `/api/hosted/workspaces/[workspaceId]`234235### `identities`236237- `GET, POST` `/api/identities`238- `DELETE` `/api/identities/[agentId]`239240### `integrations`241242- `GET` `/api/integrations/health`243- `POST` `/api/integrations/health/refresh`244245### `integrity`246247- `GET` `/api/integrity/jwks`248- `POST` `/api/integrity/verify`249250### `invite`251252- `GET, POST` `/api/invite/[token]`253254### `keys`255256- `DELETE, GET, POST` `/api/keys`257- `GET` `/api/keys/reveal`258259### `knowledge`260261- `GET, POST` `/api/knowledge/collections`262- `DELETE, GET, PATCH` `/api/knowledge/collections/[collectionId]`263- `GET, POST` `/api/knowledge/collections/[collectionId]/items`264- `POST` `/api/knowledge/collections/[collectionId]/search`265- `POST` `/api/knowledge/collections/[collectionId]/sync`266267### `learning`268269- `GET, POST` `/api/learning`270- `GET, POST` `/api/learning/analytics/curves`271- `GET` `/api/learning/analytics/maturity`272- `GET` `/api/learning/analytics/summary`273- `GET, POST` `/api/learning/analytics/velocity`274- `GET` `/api/learning/code-signals`275- `GET` `/api/learning/lessons`276- `GET, POST` `/api/learning/recommendations`277- `PATCH` `/api/learning/recommendations/[recommendationId]`278- `POST` `/api/learning/recommendations/events`279- `GET` `/api/learning/recommendations/metrics`280- `GET, POST` `/api/learning/suggestions`281282### `marketing`283284- `POST` `/api/marketing/event`285286### `mcp`287288- `POST` `/api/mcp`289290### `messages`291292- `GET, PATCH, POST` `/api/messages`293- `GET` `/api/messages/attachments`294- `GET, PATCH, POST` `/api/messages/threads`295- `GET` `/api/messages/threads/[threadId]`296297### `model-strategies`298299- `GET, POST` `/api/model-strategies`300- `DELETE, GET, PATCH` `/api/model-strategies/[strategyId]`301- `POST` `/api/model-strategies/[strategyId]/complete`302303### `oauth`304305- `GET, POST` `/api/oauth/authorize`306- `GET` `/api/oauth/metadata/authorization-server`307- `GET` `/api/oauth/metadata/protected-resource`308- `POST` `/api/oauth/register`309- `POST` `/api/oauth/token`310311### `operations`312313- `GET` `/api/operations/feed`314- `GET` `/api/operations/summary`315316### `orgs`317318- `GET, POST` `/api/orgs`319- `GET, PATCH` `/api/orgs/[orgId]`320- `DELETE, GET, POST` `/api/orgs/[orgId]/keys`321322### `pairings`323324- `GET, POST` `/api/pairings`325- `GET, PATCH` `/api/pairings/[pairingId]`326- `POST` `/api/pairings/[pairingId]/approve`327328### `policies`329330- `DELETE, GET, PATCH, POST` `/api/policies`331- `POST` `/api/policies/generate`332- `POST` `/api/policies/import`333- `GET` `/api/policies/proof`334- `POST` `/api/policies/simulate`335- `GET` `/api/policies/templates`336- `POST` `/api/policies/test`337338### `prompts`339340- `GET` `/api/prompts/agent-connect/raw`341- `POST` `/api/prompts/render`342- `GET` `/api/prompts/runs`343- `GET` `/api/prompts/sdk-coverage/raw`344- `GET` `/api/prompts/server-setup/raw`345- `GET` `/api/prompts/stats`346- `GET, POST` `/api/prompts/templates`347- `DELETE, GET, PATCH` `/api/prompts/templates/[templateId]`348- `GET, POST` `/api/prompts/templates/[templateId]/versions`349- `GET, POST` `/api/prompts/templates/[templateId]/versions/[versionId]`350351### `scoring`352353- `POST` `/api/scoring/calibrate`354- `GET, POST` `/api/scoring/profiles`355- `DELETE, GET, PATCH` `/api/scoring/profiles/[profileId]`356- `POST` `/api/scoring/profiles/[profileId]/dimensions`357- `DELETE, PATCH` `/api/scoring/profiles/[profileId]/dimensions/[dimensionId]`358- `GET, POST` `/api/scoring/risk-templates`359- `DELETE, PATCH` `/api/scoring/risk-templates/[templateId]`360- `GET, POST` `/api/scoring/score`361362### `secrets`363364- `GET, POST` `/api/secrets`365- `DELETE, PATCH` `/api/secrets/[id]`366- `GET` `/api/secrets/rotation-due`367368### `security`369370- `GET, POST` `/api/security/prompt-injection`371- `POST` `/api/security/scan`372- `GET` `/api/security/status`373374### `session`375376- `GET` `/api/session/effective`377378### `sessions`379380- `GET, POST` `/api/sessions`381- `GET, PATCH` `/api/sessions/[sessionId]`382- `GET` `/api/sessions/[sessionId]/events`383384### `settings`385386- `DELETE, GET, POST` `/api/settings`387- `GET` `/api/settings/llm-status`388- `POST` `/api/settings/test`389390### `setup`391392- `POST` `/api/setup/live-proof`393- `POST` `/api/setup/migrate`394- `POST` `/api/setup/ping`395- `GET` `/api/setup/proof`396- `GET` `/api/setup/status`397398### `signals`399400- `GET` `/api/signals`401402### `skills`403404- `POST` `/api/skills/scan`405- `GET` `/api/skills/scans/[id]`406407### `stream`408409- `GET` `/api/stream`410411### `swarm`412413- `GET` `/api/swarm/graph`414- `GET` `/api/swarm/link`415416### `team`417418- `GET` `/api/team`419- `DELETE, PATCH` `/api/team/[userId]`420- `DELETE, GET, POST` `/api/team/invite`421422### `telegram`423424- `POST` `/api/telegram/webhook`425426### `usage`427428- `GET` `/api/usage`429- `GET` `/api/usage/costs`430431### `webhooks`432433- `DELETE, GET, POST` `/api/webhooks`434- `GET` `/api/webhooks/[webhookId]/deliveries`435- `POST` `/api/webhooks/[webhookId]/test`436- `POST` `/api/webhooks/stripe`437438### `workflows`439440- `POST` `/api/workflows/draft`441- `GET, POST` `/api/workflows/templates`442- `DELETE, GET, PATCH` `/api/workflows/templates/[templateId]`443- `POST` `/api/workflows/templates/[templateId]/duplicate`444- `POST` `/api/workflows/templates/[templateId]/execute`445- `POST` `/api/workflows/templates/[templateId]/launch`446- `GET` `/api/workflows/templates/[templateId]/runs`447- `GET` `/api/workflows/templates/[templateId]/runs/[runActionId]`448- `POST` `/api/workflows/templates/[templateId]/runs/[runActionId]/cancel`449- `POST` `/api/workflows/templates/[templateId]/runs/[runActionId]/resume`450451## Required Environment Variables452453These must be set — DashClaw will fail to start without them.454455- **`DASHCLAW_API_KEY`** - referenced in 56 file(s)456- **`DATABASE_URL`** - referenced in 87 file(s)457- **`ENCRYPTION_KEY`** - referenced in 4 file(s)458- **`NEXTAUTH_SECRET`** - referenced in 5 file(s)459460## Optional Environment Variables461462These have fallbacks or only activate specific features.463464- `AGENT_ONLINE_WINDOW_MS` *(undocumented)*465- `AGENT_PRIVATE_KEY` *(undocumented)*466- `AGENT_PRIVATE_KEY_JWK` *(undocumented)*467- `ALERT_FROM_EMAIL` *(undocumented)*468- `ALLOWED_ORIGIN` *(undocumented)*469- `ANTHROPIC_API_KEY` *(undocumented)*470- `ANTHROPIC_MODEL` *(undocumented)*471- `API_INVENTORY_VERIFIED_DATE` *(undocumented)*472- `API_SECRET` *(undocumented)*473- `BASE_URL` *(undocumented)*474- `CI` *(undocumented)*475- `CONVERGENCE_BENCH_CONCURRENCY` *(undocumented)*476- `CONVERGENCE_BENCH_ITERATIONS` *(undocumented)*477- `CONVERGENCE_REPLAY_CONNECT_TIMEOUT_MS` *(undocumented)*478- `CONVERGENCE_RETRY_429_MAX` *(undocumented)*479- `CONVERGENCE_RETRY_429_WAIT_MS` *(undocumented)*480- `CONVERGENCE_SSE_SEND_COUNT` *(undocumented)*481- `CONVERGENCE_VERBOSE` *(undocumented)*482- `CRON_SECRET` *(undocumented)*483- `DASHCLAW_ACT_BINDING` *(undocumented)*484- `DASHCLAW_ACT_BINDING_TYP` *(undocumented)*485- `DASHCLAW_AGENT_ID` *(undocumented)*486- `DASHCLAW_ALERTS_DISCORD` *(undocumented)*487- `DASHCLAW_ALERTS_TELEGRAM` *(undocumented)*488- `DASHCLAW_ALLOWED_ISSUER` *(undocumented)*489- `DASHCLAW_API_KEY_ORG` *(undocumented)*490- `DASHCLAW_BASE_URL` *(undocumented)*491- `DASHCLAW_BEHAVIOR_SAMPLES_DIR` *(undocumented)*492- `DASHCLAW_BEHAVIOR_SAMPLES_ENABLED` *(undocumented)*493- `DASHCLAW_CLOSED_ENROLLMENT` *(undocumented)*494- `DASHCLAW_DB_DRIVER` *(undocumented)*495- `DASHCLAW_DB_POOL_MAX` *(undocumented)*496- `DASHCLAW_DISABLE_RATE_LIMIT` *(undocumented)*497- `DASHCLAW_GUARD_FALLBACK` *(undocumented)*498- `DASHCLAW_GUARD_UNAVAILABLE_POLICY` *(undocumented)*499- `DASHCLAW_HOSTED` *(undocumented)*500- `DASHCLAW_JTI_MAX_TTL_SECONDS` *(undocumented)*501- `DASHCLAW_JTI_REPLAY_PROTECTION` *(undocumented)*502- `DASHCLAW_JWT_AUDIENCE` *(undocumented)*503- `DASHCLAW_LOCAL_ADMIN_PASSWORD` *(undocumented)*504- `DASHCLAW_MAX_ORG_ATTACHMENT_BYTES` *(undocumented)*505- `DASHCLAW_MODE` *(undocumented)*506- `DASHCLAW_NEW_CONNECT_WEBHOOK` *(undocumented)*507- `DASHCLAW_PAIRING_TTL_MINUTES` *(undocumented)*508- `DASHCLAW_RATE_LIMIT_MAX` *(undocumented)*509- `DASHCLAW_RATE_LIMIT_WINDOW_MS` *(undocumented)*510- `DASHCLAW_SIGNING_KEY_JWK` *(undocumented)*511- `DASHCLAW_URL` *(undocumented)*512- `DISABLE_PROMPT_INJECTION_SCAN` *(undocumented)*513- `DISCORD_APPROVER_ORG_ID` *(undocumented)*514- `DISCORD_APPROVER_USER_ID` *(undocumented)*515- `DISCORD_BOT_TOKEN` *(undocumented)*516- `DISCORD_PUBLIC_KEY` *(undocumented)*517- `ENFORCE_AGENT_SIGNATURES` *(undocumented)*518- `GITHUB_CLIENT_ID` *(undocumented)*519- `GITHUB_CLIENT_SECRET` *(undocumented)*520- `GITHUB_ID` *(undocumented)*521- `GITHUB_REPO_NAME` *(undocumented)*522- `GITHUB_REPO_OWNER` *(undocumented)*523- `GITHUB_SECRET` *(undocumented)*524- `GITHUB_TOKEN` *(undocumented)*525- `GOOGLE_AI_API_KEY` *(undocumented)*526- `GOOGLE_CLIENT_ID` *(undocumented)*527- `GOOGLE_CLIENT_SECRET` *(undocumented)*528- `GOOGLE_ID` *(undocumented)*529- `GOOGLE_SECRET` *(undocumented)*530- `GUARD_LLM_BASE_URL` *(undocumented)*531- `GUARD_LLM_KEY` *(undocumented)*532- `GUARD_LLM_MODEL` *(undocumented)*533- `GUARD_WEBHOOK_SECRET` *(undocumented)*534- `HOSTED_CLEANUP_SECRET` *(undocumented)*535- `HOSTED_PROVISION_MAX_PER_IP_PER_DAY` *(undocumented)*536- `HOSTED_SMOKE_BASE_URL` *(undocumented)*537- `HOSTED_TRIAL_ACTION_CAP` *(undocumented)*538- `HOSTED_TRIAL_DAYS` *(undocumented)*539- `INTEGRATION_DATABASE_URL` *(undocumented)*540- `MOONSHOT_API_KEY` *(undocumented)*541- `NEXTAUTH_URL`542- `NEXT_PUBLIC_` *(undocumented)*543- `NEXT_PUBLIC_APP_URL` *(undocumented)*544- `NEXT_PUBLIC_DASHCLAW_MODE` *(undocumented)*545- `NEXT_PUBLIC_DASHCLAW_VERSION` *(undocumented)*546- `NEXT_PUBLIC_ENABLE_VERCEL_ANALYTICS` *(undocumented)*547- `NEXT_PUBLIC_PLUGIN_MANIFEST_VERSION` *(undocumented)*548- `NEXT_PUBLIC_SDK_NODE_VERSION` *(undocumented)*549- `NEXT_PUBLIC_SDK_PYTHON_VERSION` *(undocumented)*550- `NEXT_PUBLIC_TURNSTILE_SITE_KEY` *(undocumented)*551- `NODE_ENV` *(undocumented)*552- `OIDC_AUTHORIZATION_URL` *(undocumented)*553- `OIDC_CLIENT_ID` *(undocumented)*554- `OIDC_CLIENT_SECRET` *(undocumented)*555- `OIDC_DISPLAY_NAME` *(undocumented)*556- `OIDC_ISSUER_URL` *(undocumented)*557- `OIDC_TOKEN_URL` *(undocumented)*558- `OIDC_USERINFO_URL` *(undocumented)*559- `OPENAI_API_KEY` *(undocumented)*560- `ORG_ID` *(undocumented)*561- `PORT` *(undocumented)*562- `PW_BASE_URL` *(undocumented)*563- `PW_SMOKE_PORT` *(undocumented)*564- `PYTHON` *(undocumented)*565- `PYTHONPATH` *(undocumented)*566- `REALTIME_BACKEND` *(undocumented)*567- `REALTIME_ENFORCE_REDIS` *(undocumented)*568- `REALTIME_MAX_LISTENERS` *(undocumented)*569- `REALTIME_MEMORY_MAX_LISTENERS` *(undocumented)*570- `REALTIME_REDIS_URL` *(undocumented)*571- `REALTIME_REPLAY_MAX_EVENTS` *(undocumented)*572- `REALTIME_REPLAY_WINDOW_SECONDS` *(undocumented)*573- `REDIS_URL` *(undocumented)*574- `RESEARCH_API_KEY` *(undocumented)*575- `RESEARCH_API_URL` *(undocumented)*576- `RESEND_API_KEY` *(undocumented)*577- `S` *(undocumented)*578- `SERVICE_NAME` *(undocumented)*579- `STARTUP_SMOKE_BASE_URL` *(undocumented)*580- `STARTUP_SMOKE_INTERVAL_MS` *(undocumented)*581- `STARTUP_SMOKE_TIMEOUT_MS` *(undocumented)*582- `STRIPE_PRICE_BUSINESS` *(undocumented)*583- `STRIPE_PRICE_PRO` *(undocumented)*584- `STRIPE_SECRET_KEY` *(undocumented)*585- `STRIPE_WEBHOOK_SECRET` *(undocumented)*586- `TARGET_ENV` *(undocumented)*587- `TELEGRAM_ADMIN_CHAT_ID` *(undocumented)*588- `TELEGRAM_APPROVER_ORG_ID` *(undocumented)*589- `TELEGRAM_BOT_TOKEN` *(undocumented)*590- `TELEGRAM_WEBHOOK_SECRET` *(undocumented)*591- `TEST_BASE_URL` *(undocumented)*592- `TRUST_PROXY` *(undocumented)*593- `TURNSTILE_SECRET_KEY` *(undocumented)*594- `UPSTASH_REDIS_REST_TOKEN` *(undocumented)*595- `UPSTASH_REDIS_REST_URL` *(undocumented)*596- `VERCEL` *(undocumented)*597- `VERCEL_PROJECT_PRODUCTION_URL` *(undocumented)*598- `VERCEL_URL` *(undocumented)*599- `WEBHOOK_ALLOWED_DOMAINS` *(undocumented)*600- `X` *(undocumented)*601602## Database Tables603604All 89 tables defined in `schema/schema.js` (Drizzle ORM):605606- `action_embeddings`607- `action_records`608- `activity_logs`609- `agent_connections`610- `agent_identities`611- `agent_messages`612- `agent_pairings`613- `agent_presence`614- `agent_schedules`615- `agent_sessions`616- `api_keys`617- `assumptions`618- `calendar_events`619- `code_optimal_file_manifests`620- `code_projects`621- `code_session_alerts`622- `code_session_handoffs`623- `code_session_memos`624- `code_session_messages`625- `code_session_signals`626- `code_session_tool_uses`627- `code_sessions`628- `compliance_snapshots`629- `contacts`630- `content`631- `context_entries`632- `context_points`633- `daily_totals`634- `decisions`635- `drift_alerts`636- `drift_baselines`637- `drift_snapshots`638- `entities`639- `eval_runs`640- `eval_scores`641- `executions`642- `feedback`643- `goals`644- `governed_secrets`645- `guard_decisions`646- `guard_policies`647- `guardrails_test_runs`648- `health_snapshots`649- `ideas`650- `interactions`651- `jwt_replay_log`652- `learning_curves`653- `learning_episodes`654- `learning_recommendation_events`655- `learning_recommendations`656- `learning_velocity`657- `message_threads`658- `milestones`659- `notification_preferences`660- `oauth_access_tokens`661- `oauth_authorization_codes`662- `oauth_clients`663- `open_loops`664- `organizations`665- `profile_scores`666- `prompt_runs`667- `prompt_templates`668- `prompt_versions`669- `risk_templates`670- `routing_agent_metrics`671- `routing_agents`672- `routing_decisions`673- `routing_tasks`674- `scheduled_jobs`675- `scoring_dimensions`676- `scoring_profiles`677- `server_signing_keys`678- `session_events`679- `shared_docs`680- `skill_scan_results`681- `snippets`682- `token_budgets`683- `token_snapshots`684- `topics`685- `usage_meters`686- `user_approaches`687- `user_moods`688- `user_observations`689- `user_preferences`690- `users`691- `waitlist`692- `webhook_deliveries`693- `webhooks`694- `workflows`695696## Configuration Knobs697698Per-org settings stored in the `settings` table. Set via `PUT /api/settings/:key` or the web Settings/Integrations UI. Keys marked sensitive are auto-encrypted at rest.699700### AI Providers701702- `OPENAI_API_KEY`703- `OPENAI_ORG_ID`704- `ANTHROPIC_API_KEY`705- `GROQ_API_KEY`706- `TOGETHER_API_KEY`707- `REPLICATE_API_TOKEN`708- `HUGGINGFACE_API_KEY`709- `PERPLEXITY_API_KEY`710- `ELEVENLABS_API_KEY`711- `ELEVENLABS_VOICE_ID`712713### Databases714715- `DATABASE_URL`716- `SUPABASE_URL`717- `SUPABASE_ANON_KEY`718- `SUPABASE_SERVICE_KEY`719- `PLANETSCALE_URL`720- `MONGODB_URI`721- `REDIS_URL`722- `PINECONE_API_KEY`723- `PINECONE_ENVIRONMENT`724725### Communication726727- `TELEGRAM_BOT_TOKEN`728- `TELEGRAM_ADMIN_CHAT_ID`729- `DASHCLAW_ALERTS_TELEGRAM`730- `DISCORD_BOT_TOKEN`731- `DISCORD_CLIENT_ID`732- `DISCORD_GUILD_ID`733- `SLACK_BOT_TOKEN`734- `SLACK_SIGNING_SECRET`735- `SLACK_APP_TOKEN`736- `TWILIO_ACCOUNT_SID`737- `TWILIO_AUTH_TOKEN`738- `TWILIO_PHONE_NUMBER`739- `RESEND_API_KEY`740- `SENDGRID_API_KEY`741742### Productivity743744- `GOOGLE_ACCOUNT`745- `GOOGLE_CREDENTIALS_PATH`746- `NOTION_API_KEY`747- `NOTION_PARENT_PAGE_ID`748- `LINEAR_API_KEY`749- `AIRTABLE_API_KEY`750- `AIRTABLE_BASE_ID`751- `CALENDLY_API_KEY`752753### Development754755- `GITHUB_TOKEN`756- `GITHUB_USERNAME`757- `VERCEL_TOKEN`758- `VERCEL_PROJECT_ID`759- `RAILWAY_TOKEN`760- `CLOUDFLARE_API_TOKEN`761- `CLOUDFLARE_ACCOUNT_ID`762- `SENTRY_DSN`763- `SENTRY_AUTH_TOKEN`764765### Social766767- `TWITTER_API_KEY`768- `TWITTER_API_SECRET`769- `TWITTER_ACCESS_TOKEN`770- `TWITTER_ACCESS_SECRET`771- `BRAVE_API_KEY`772- `MOLTBOOK_API_KEY`773774### Payments775776- `STRIPE_SECRET_KEY`777- `STRIPE_PUBLISHABLE_KEY`778- `STRIPE_WEBHOOK_SECRET`779- `LEMONSQUEEZY_API_KEY`780781### Native governance alert settings782783- `DASHCLAW_ALERTS_SLACK`784- `DASHCLAW_ALERTS_DISCORD`785- `DASHCLAW_ALERTS_LINEAR`786- `DASHCLAW_ALERTS_GITHUB`787- `DASHCLAW_ALERTS_EMAIL`788- `DASHCLAW_ALERT_EMAIL`789- `SLACK_CHANNEL_ID`790- `SLACK_WEBHOOK_URL`791- `DISCORD_WEBHOOK_URL`792- `GITHUB_REPO`793- `SENDGRID_DEFAULT_TO`794- `SENDGRID_FROM_EMAIL`795796### webhooks + native adapters deliver a signal. Empty/unset = disabled.797798- `DASHCLAW_ACTION_COST_THRESHOLD`799800### System configuration801802- `MODEL_PRICING`803- `ENFORCE_AGENT_SIGNATURES`804805### Predictive risk scoring806807- `PREDICTIVE_RISK_ENABLED`808- `PREDICTIVE_RISK_THRESHOLD`809810### docs/architecture/durable-execution-finality.md.811812- `DASHCLAW_OUTCOME_TIMEOUT_MINUTES`813814### DASHCLAW_BEHAVIOR_SAMPLES_ENABLED env var still overrides them.815816- `BEHAVIOR_RECORDER_ENABLED`817- `BEHAVIOR_RECORDER_UNTIL`818819### content contains a detected secret/credential. Default (unset) = warn only.820821- `DASHCLAW_AUTOSCAN_BLOCK`822823## Realtime & Webhook Events824825Every mutation that Mission Control reflects and every webhook delivery is keyed on these event strings. Subscribe via `GET /api/events` (SSE) or register a webhook with the matching `events: [...]` array.826827| Constant | Event |828| --- | --- |829| `ACTION_COST_EXCEEDED` | `action.cost_exceeded` |830| `ACTION_CREATED` | `action.created` |831| `ACTION_UPDATED` | `action.updated` |832| `DECISION_CREATED` | `decision.created` |833| `GOAL_CREATED` | `goal.created` |834| `GOAL_UPDATED` | `goal.updated` |835| `GUARD_DECISION_CREATED` | `guard.decision.created` |836| `LOOP_CREATED` | `loop.created` |837| `LOOP_UPDATED` | `loop.updated` |838| `MESSAGE_CREATED` | `message.created` |839| `POLICY_UPDATED` | `policy.updated` |840| `SIGNAL_DETECTED` | `signal.detected` |841| `TASK_ASSIGNED` | `task.assigned` |842| `TASK_COMPLETED` | `task.completed` |843| `TOKEN_USAGE` | `token.usage` |844845## Signal Types846847These are the `type` strings emitted through `fireWebhooksForOrg` and `deliverNativeNotifications`. Webhooks can subscribe to any subset by putting the type in their `events: [...]` array (or use `['all']` for everything).848849- `autonomy_spike`850- `branch_stale`851- `cost_exceeded`852- `green_insufficient`853- `integration_health_changed`854- `integration_mismatch`855- `lost_confirmation`856- `mcp_degraded`857- `stale_action`858- `test`859860## Native Notification Adapters861862Each adapter delivers `integration_mismatch`, `integration_health_changed`, and `cost_exceeded` signals when at least one of its required credential keys is configured. Per-channel opt-out via `DASHCLAW_ALERTS_<NAME>=false`.863864| Adapter | Required credential (any one) |865| --- | --- |866| `org_id` | `DISCORD_WEBHOOK_URL` |867| `email` | `RESEND_API_KEY`, `SENDGRID_API_KEY` |868| `github` | `GITHUB_TOKEN` |869| `linear` | `LINEAR_API_KEY` |870| `slack` | `SLACK_BOT_TOKEN`, `SLACK_WEBHOOK_URL` |871872## Detecting Drift873874To check whether this snapshot matches the current codebase:875876```bash877python -m livingcode diff878```879880If the diff shows changes, this skill is stale — regenerate it.