Environment
environmentManage project environments and login credentials: create, update, list, delete, inspect or clear authenticated sessions, and handle cross-domain SSO hosts.
Instructions
Manage environments (and their login credentials) under a project. Pass an "action":
"get" {uuid, projectUuid?} → one environment with credentials inline (passwords never returned).
"list" {projectUuid?, q?, page?, pageSize?} → paginated environments. projectUuid auto-resolves from the git repo if omitted.
"create" {name, url, description?, projectUuid?, credentials?, authorizedCredentialHosts?} → create an env, optionally seeding credentials.
"update" {uuid, name?, url?, description?, addCredentials?, updateCredentials?, removeCredentialIds?, authorizedCredentialHosts?} → patch env + manage credentials.
"delete" {uuid, projectUuid?, confirm?} → delete env (DESTRUCTIVE; requires confirmation).
"sessions" {uuid, username?, credentialId?} → captured login sessions this env is holding, and whether each would be reused.
"clearSessions" {uuid, username?, credentialId?, confirm?} → invalidate them so the next run logs in for real.
CROSS-DOMAIN SSO: a run only types this environment's credentials on the app's own host (and its subdomains); a login on any other host is refused as offscope_host. If your identity provider lives on a different domain than the app, add the IdP host to authorizedCredentialHosts — bare hostnames like "auth.example.com", no scheme/path/port/wildcard. The response echoes the saved list; if it reports authorizedCredentialHostsWarning, the server did not persist it.
SESSIONS: runs reuse a warm authenticated session per account instead of logging in every time. That is why a check can report "no login form" — it was already signed in. Use "sessions" to see whose session is held, "clearSessions" to drop it, or pass freshSession:true on a single check_app_in_browser call to bypass reuse without clearing anything.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| q | No | [list] Free-text search over env name. | |
| url | No | [create/update] Base URL. | |
| name | No | [create/update] Environment name. | |
| page | No | [list] Page (1-indexed). | |
| uuid | No | [get/update/delete] Environment UUID. | |
| action | Yes | Operation to perform. | |
| confirm | No | [delete/clearSessions] Set true to confirm (when the client cannot prompt). clearSessions only needs it when no username/credentialId narrows it. | |
| pageSize | No | [list] Page size (1..200). | |
| username | No | [sessions/clearSessions] Narrow to one account. Matched case-insensitively. | |
| credentials | No | [create] Seed login credentials. | |
| description | No | [create/update] Free-text description. | |
| projectUuid | No | Target project (defaults to git auto-detect). | |
| credentialId | No | [sessions/clearSessions] Narrow to one stored credential by UUID. | |
| addCredentials | No | [update] Add credentials. | |
| updateCredentials | No | [update] Patch credentials by UUID. | |
| removeCredentialIds | No | [update] Delete credentials by UUID. | |
| authorizedCredentialHosts | No | [create/update] Hosts where the run may enter this environment's credentials besides the app's own host, e.g. your identity provider for cross-domain SSO. Bare hostnames only (auth.example.com). On update this REPLACES the list; [] clears it. |