Skip to content

feat(elicitation): client-side URL-mode elicitation for tool authorization - #20

Open
gpasquero wants to merge 3 commits into
formulahendry:mainfrom
gpasquero:feat/elicitation-url-mode
Open

gpasquero wants to merge 3 commits into
formulahendry:mainfrom
gpasquero:feat/elicitation-url-mode

Conversation

@gpasquero

@gpasquero gpasquero commented Aug 26, 2026 •

Copy link
Copy Markdown

Motivation

Agents built on @agentclientprotocol/sdk 1.3.0 (e.g. GlobAI) can request tool authorization mid-turn via elicitation/create (URL mode) — for example a 3LO grant. This client was on SDK 0.13.1, which has no elicitation, so it replied METHOD_NOT_FOUND and the flow never completed. This adds client-side support for URL-mode elicitation, bumps the SDK, and keeps everything else working across the bump.

Expected flow

During a turn, if a tool needs authorization the agent sends elicitation/create (URL mode) with a message and a login URL. The client shows a dialog, the user opens the URL and authorizes, and the turn continues on its own — without re-typing the prompt.

Changes

  1. Bump @agentclientprotocol/sdk 0.13.1 → 1.3.0 (matches the server SDK). All existing flows (WebSocket connect, Authentication Required, permissions, modes) are unchanged.
  2. Advertise the capability on initialize: clientCapabilities.elicitation = { url: {} } (unstable_ in the SDK).
  3. Handle elicitation/create (URL mode) — a new ElicitationDialog shows the message and a button to open the authorization URL in a new tab; the user responds { action: "accept" | "decline" | "cancel" }. Non-URL modes are declined.
  4. Handle elicitation/complete — when the agent signals the URL flow finished, the client auto-accepts the matching elicitation so the turn continues without the user clicking.
  5. Model picker migrated to configOptions (second commit). The bump removed NewSessionResponse.models; the model is now a select session config option (category: "model"). The picker now reads from configOptions, changes the model via session/set_config_option, and refreshes on config_option_update. Defensive parsing hides the picker on any unexpected shape. No regression from the bump.

Testing

  • npx vue-tsc --noEmit and npm run build:web pass.
  • Manual: against a GlobAI agent whose tool needs a 3LO grant, prompting it surfaces the elicitation dialog; authorizing in the opened page lets the turn continue with no re-prompt; the model picker lists and switches models.

Bump @agentclientprotocol/sdk 0.13.1 -> 1.3.0 (matching GlobAI servers) and
implement client-side URL-mode elicitation so agents can drive tool
authorization (e.g. 3LO grants) during a turn instead of getting a
METHOD_NOT_FOUND for elicitation/create.

- Advertise clientCapabilities.elicitation = { url: {} } on initialize.
- Handle elicitation/create (URL mode): show a dialog with the message and a
  button to open the authorization URL; respond accept/decline/cancel.
- Handle elicitation/complete: auto-accept the matching elicitation so the
  turn continues without the user re-sending the prompt.
- New ElicitationDialog component; wire pendingElicitation through the bridge,
  session store, and App.

Breaking change from the SDK bump: NewSessionResponse.models was replaced by
the generic configOptions. The model picker is temporarily disabled (cleared)
until it's migrated to configOptions; all other flows (WebSocket connect,
Authentication Required, permissions) are unchanged and the sign-in popup fix
is preserved.

(cherry picked from commit e6b6375)
gpasquero pushed a commit to gpasquero/acp-ui that referenced this pull request Aug 26, 2026
SDK 1.3.0 replaced NewSessionResponse.models with the generic configOptions
list, which had left the model picker disabled after the bump. Restore it by
reading the model selector from the session's config options.

- Identify the model option by category === 'model' (fallback: a select whose
  category/id/name names 'model', excluding 'model_config'); flatten grouped
  select options; map to the existing ModelInfo shape.
- Change the model via session/set_config_option instead of the removed
  session/set_model (bridge: unstable_setSessionConfigOption).
- Refresh the picker on config_option_update notifications and on resume from
  LoadSessionResponse.configOptions. Defensive parsing hides the picker on any
  unexpected shape.

(cherry picked from commit 9806a2a)
gpasquero pushed a commit to gpasquero/acp-ui that referenced this pull request Aug 26, 2026
In a Tauri webview window.open()/<a target=_blank> don't reach the system
browser, so the elicitation authorization link did nothing on desktop. Route
it through a host-aware openExternalUrl() helper (opener plugin on Tauri,
window.open on web).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant