Skip to content

feat(integrations): add saved Ramp and Vanta credentials - #8802

Merged
waleedlatif1 merged 5 commits into
stagingfrom
codex/ramp-vanta-credentials
Oct 8, 2026
Merged

waleedlatif1 merged 5 commits into
stagingfrom
codex/ramp-vanta-credentials

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Connect Ramp and Vanta with a saved client ID and secret, reuse those credentials in blocks and tools, and keep setup available without deployment-wide OAuth configuration.

  • Coordinate Vanta's single active token across connections and workers with encrypted storage, stable application permissions, precise invalidation, and one authorized retry after rejection. Replace inline Vanta auth fields with the saved credential picker.

  • Preserve Vanta permissions and deployment on reconnect, correct reconnect labels and API output metadata, and document authentication choices and credential-backed selectors in the integration skill.

  • Use the Ramp brand mark with its lime background and simplify Ramp/Vanta credential forms by removing helper copy.

Type of Change

  • Feature
  • Bug fix

Testing

  • Passed the full root test suite across all workspaces, affected credential and tool suites, lint, all workspace type checks, 58 audits, block registry, docs manifest, and actionlint.
  • 12 PostgreSQL token lifecycle integration checks and independent mutation checks for renewal, permission lifetime, authorization, retries, and cancellation; 9 HTTP checks through real credential routes and encrypted persistence; browser create/reconnect verification with isolated provider fixtures.
  • Additive migration applied to PostgreSQL; migration safety passed; Drizzle regeneration produced no changes.
  • Live provider authentication remains unverified because provider credentials were unavailable. No production credentials were changed.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 8, 2026 2:48pm UTC

Request Review

@gitguardian

gitguardian Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

️✅ There are no secrets present in this pull request anymore.

If these secrets were true positive and are still valid, we highly recommend you to revoke them.
While these secrets were previously flagged, we no longer have a reference to the
specific commits where they were detected. Once a secret has been leaked into a git
repository, you should consider it compromised, even if it was deleted immediately.
Find here more information about risks.


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@waleedlatif1
waleedlatif1 force-pushed the codex/ramp-vanta-credentials branch from b494df7 to 09e89b8 Compare October 8, 2026 09:04
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@greptile-apps

greptile-apps Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Adds saved credentials for Ramp and Vanta integrations.

The PR appears safe to merge; no new actionable issues remain.

What we checked:

  • Blank reconnect fields keep settings: The form omits blank fields. The server reads the saved values and carries them into the replacement credential.
  • Ramp tiles keep readable icons: The tile gives light backgrounds a black foreground. Bare brand icons use the theme’s icon color when no brand foreground is registered.

Summary

Adds saved Ramp and Vanta application credentials for blocks and tools without requiring deployment-wide OAuth settings.

  • Vanta shares encrypted tokens across workers, keeps application permissions after expiry, and retries one rejected request through the authorized credential path.
  • Reconnect preserves saved permissions and deployment. Credential waits can end on cancellation without stopping shared renewal.
  • The latest changes replace the Ramp icon and intentionally remove form helper copy.
  • Earlier permission-lifetime, retry, Ramp-picker, and cancellation findings are addressed. The report-artifact concern was correctly disputed by waleedlatif1: the shared integration runner writes JSON reports, and CI uploads them.
  • No new actionable issues found. No runtime tests were run during this review.
Diagram
sequenceDiagram
  participant Caller as Workflow or tool
  participant Sim as Authorized credential path
  participant DB as Shared encrypted storage
  participant Vanta
  Caller->>Sim: Resolve saved credential
  Sim->>DB: Lock application and check permissions
  DB-->>Sim: Current token or renewal needed
  opt Renewal needed
    Sim->>Vanta: Exchange saved client credentials
    Vanta-->>Sim: New token
    Sim->>DB: Save encrypted application state
  end
  Sim-->>Caller: Token and trusted API origin
  Caller->>Vanta: Run operation
  opt First request returns 401
    Caller->>DB: Expire only rejected token
    Caller->>Sim: Re-authorize same saved credential
    Sim-->>Caller: Current token and API origin
    Caller->>Vanta: Retry once under original deadline
  end
Loading

Reviews (6) · Last reviewed commit: "improvement(integrations): refresh Ramp ..." · Reviewed by Greptile

Comment thread apps/sim/lib/credentials/client-credential-accounts/vanta-token.ts Outdated
Comment thread apps/sim/lib/internal/vanta/client.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 85 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/oauth/credential-service.ts Outdated
Comment thread apps/sim/lib/credentials/client-credential-accounts/vanta-token.ts Outdated
Comment thread apps/sim/lib/credentials/client-credential-accounts/minters/ramp.ts
Comment thread .agents/skills/add-integration/SKILL.md
Comment thread packages/deployment-config/src/integration-availability.ts Outdated
Comment thread apps/sim/blocks/blocks/ramp.ts
Comment thread apps/sim/tools/vanta/list_frameworks.ts Outdated
Comment thread apps/sim/lib/internal/vanta/client.ts
Comment thread apps/sim/lib/credentials/client-credential-accounts/vanta-token.ts Outdated
Comment thread apps/sim/lib/internal/vanta/client.ts
Comment thread apps/sim/blocks/blocks/ramp.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/tools/index.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 89 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/tools/index.ts
Comment thread .agents/skills/add-integration/SKILL.md Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 90 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread .agents/skills/add-integration/SKILL.md
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 90 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 92 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit d2bbd34 into staging Oct 8, 2026
37 of 38 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/ramp-vanta-credentials branch October 8, 2026 14:51

This branch was successfully deployed

1 active deployment
Preview — 24f87103 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant