Skip to content

fix(tools): check usage limits before running hosted-key tools via the API - #8602

Merged
waleedlatif1 merged 5 commits into
stagingfrom
fix/tool-execute-usage-gate
Oct 3, 2026
Merged

waleedlatif1 merged 5 commits into
stagingfrom
fix/tool-execute-usage-gate

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • Check the workspace's usage limits before running a tool that would use a Sim-hosted key via POST /api/v2/tools/{toolId}/execute, using the same cached execution gate as workflow runs
  • Return 402 USAGE_LIMIT_EXCEEDED when the limit is exceeded, and document it in the OpenAPI spec

Type of Change

  • Bug fix

Testing

  • execute-tool.test.ts and the route test (new cases fail with the fix reverted)
  • bun run lint, bun run type-check, bun run check:audits, docs-manifest:check, block-registry check
  • test:scripts: generate-docs.test.ts times out locally, same on clean staging

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 3, 2026 8:18pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 7 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/docs/openapi-v2-resources.json Outdated
@greptile-apps

greptile-apps Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical risk] Adds usage limit checks to the tool execution API.

The PR appears safe to merge; no new actionable issue or outstanding previous finding remains.

Summary

The PR checks workspace usage limits before direct API tool calls that would use a hosted key, returns a documented 402 response when admission is denied, and adds route and use-case tests. The latest changes align admission with the registry’s resolution of user-only environment references, including provider selection.

Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Authorized tool call] --> B[Resolve user-only references for admission]
  B --> C{Would the tool need an injected key?}
  C -- No --> E[Execute through registry]
  C -- Yes --> D{Usage limit exceeded?}
  D -- Yes --> F[Return 402]
  D -- No --> E
  E --> G[Meter successful hosted-key spend]
Loading

Reviews (5) · Last reviewed commit: "fix(tools): decide hosted-key admission ..."

Comment thread apps/sim/lib/tool-execution/application/execute-tool.ts Outdated
Comment thread apps/sim/lib/tool-execution/application/execute-tool.test.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/lib/tool-execution/application/execute-tool.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 7 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/tool-execution/application/execute-tool.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

Comment thread apps/sim/lib/tool-execution/application/execute-tool.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 4c6be10 into staging Oct 3, 2026
33 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/tool-execute-usage-gate branch October 3, 2026 21:16

This branch was previously deployed

1 inactive deployment
Preview — e9567b63 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant