Team Chat API Platform (planned)
Status: In-development (architecture documented, no OAuth2 layer built yet). Registered as unreleased feature team-chat-api-platform.
What it is
Status: In-development (architecture documented, no OAuth2 layer built yet). Registered as unreleased feature team-chat-api-platform.
Why it matters
Third-party integrations (bots, workflow tools, monitoring dashboards) currently cannot access Team Chat programmatically. The internal CLI routes are fully functional but restricted to same-machine bearer-token auth, making them inaccessible to external services.
Current state
The feature is registered in UNRELEASED_FEATURES with setting key teamChatApiPlatformEnabled and gated via the standard unreleased-feature mechanism. No OAuth2 code exists yet.
Where to find it
Nothing to open — this is planned work with no screen in the product. The Team Chat routes it would expose are reachable today only through the local control server.
How it behaves
What it will do
Expose Team Chat's existing 13+ CLI messaging routes to third-party integrations via an OAuth2 authorization layer with scoped access tokens. The routes themselves are production-grade today (Zod validation, typed errors, pagination, idempotency, content deduplication) -- the gap is solely the auth surface for external consumption.
Current readiness
The following infrastructure is already in place on the CLI control server (loopback bearer-token auth):
- Channel CRUD: create, list, edit, archive, delete channels.
- Message CRUD: send, list (paginated), get by id, edit, delete.
- Reactions: add/remove emoji reactions.
- Threading: send with parentId, list threads.
- Pin/Save: pin/unpin, save/unsave messages.
- Search: full-text message search via Cloud Function.
- Read state: get unread count, mark channel as read.
- DM inbox: list DM conversations.
- Members: list org members (mention resolution).
All mutation routes enforce source provenance (X-AMC-Source-Session-Id) and agent-write gating (D22 Layer 2).
What is needed
- OAuth2 provider implementation -- register an authorization server (likely Firebase Auth custom tokens + OAuth2 consent screen) that issues scoped access tokens for third-party apps.
- Scope definitions -- define granular scopes (e.g.
team-chat:read,team-chat:write,team-chat:admin) that map to route groups. - Token validation middleware -- replace/augment the current loopback bearer-token check with OAuth2 token introspection for external callers.
- Rate limiting -- per-app rate limits (the current per-user pacing is insufficient for a platform API).
- Developer portal -- app registration, API key management, webhook subscriptions.
Related
- team-chat.md — the product these routes serve.
- team-chat-export.md — the other planned Team Chat capability.
- team-chat-dead-letter-recovery.md — re-filing messages that could not be delivered.
Last verified 2026-09-23