diff --git a/.github/ISSUE_TEMPLATE/bug_report.yml b/.github/ISSUE_TEMPLATE/bug_report.yml index 6722c509..6665b499 100644 --- a/.github/ISSUE_TEMPLATE/bug_report.yml +++ b/.github/ISSUE_TEMPLATE/bug_report.yml @@ -46,7 +46,7 @@ body: - Web dashboard - The API / proxy - Self-hosted server - - Hosted (treg.superdesign.dev) + - Hosted (treg.to) - Other / not sure validations: required: true diff --git a/README.md b/README.md index e0d7ec68..5d6a6b03 100644 --- a/README.md +++ b/README.md @@ -11,7 +11,7 @@ agent without the credential ever leaving the server. **Ask for the task, not the tool.** You do not need to know which vendor sells backlink data, or to hold an account with them. Search for what you want to do, read the price, call it. -Built for the Superdesign team, live at [treg.superdesign.dev](https://treg.superdesign.dev) — anyone can self-host. +Built for the Superdesign team, live at [treg.to](https://treg.to) — anyone can self-host. ## Why it exists @@ -44,7 +44,7 @@ The vocabulary for the second half: # Part 1 · Using the registry -Visit [**treg.superdesign.dev**](https://treg.superdesign.dev) (hosted on Render) — the dashboard, +Visit [**treg.to**](https://treg.to) (hosted on Render) — the dashboard, sign-in, and every URL below live there. ## Quickstart @@ -53,7 +53,7 @@ Same flow as the dashboard's **Getting started** guide: ```bash # 1. install the CLI — also points it at the registry -curl -fsSL https://treg.superdesign.dev/install.sh | sh +curl -fsSL https://treg.to/install.sh | sh # 2. sign in (GitHub default · --email for a one-time code · --token for agents/CI) treg login @@ -132,7 +132,7 @@ treg resolves the tool by host, injects the credential, and relays everything el ``` Real request: GET https://api.intercom.io/conversations?per_page=5 -Through treg: GET https://treg.superdesign.dev/call/https://api.intercom.io/conversations?per_page=5 +Through treg: GET https://treg.to/call/https://api.intercom.io/conversations?per_page=5 header: X-Treg-Token: ``` @@ -212,9 +212,9 @@ treg org access --tools a,b # per-member tool access (admin+) ## Going deeper - [`USAGE.md`](USAGE.md) — the full `treg` CLI reference. -- [`/llms.txt`](https://treg.superdesign.dev/llms.txt) — the agent-onboarding file: call +- [`/llms.txt`](https://treg.to/llms.txt) — the agent-onboarding file: call protocol, discovery, auth, CLI, skills. One fetch teaches an agent the whole registry. -- **The dashboard** at [treg.superdesign.dev](https://treg.superdesign.dev) — full CRUD, a guided +- **The dashboard** at [treg.to](https://treg.to) — full CRUD, a guided tutorial (Help → Tutorial), and copyable setup instructions for your agents. - **The API** — everything the CLI does is plain HTTP; interactive OpenAPI docs live at `/docs`. The proxy endpoint is `/call/{...}`; all endpoints take the `X-Treg-Token` header. @@ -253,7 +253,7 @@ uv run python -m treg keygen # print a fresh Fernet key for TREG_SECRET_KEY > database drivers, and encryption. `pip install tools-registry` alone gives just the `treg` command for > talking to an existing registry. -The team instance is hosted on **Render** (web service + Postgres) at `treg.superdesign.dev`. +The team instance is hosted on **Render** (web service + Postgres) at `treg.to`. ## Configuration @@ -264,7 +264,7 @@ Environment variables (prefix `TREG_`, read from `.env`): | ----------------------------------------- | ------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `TREG_DATABASE_URL` | `sqlite+aiosqlite:///./treg.db` | DB URL (SQLite for dev, Postgres in prod) | | `TREG_SECRET_KEY` | *(empty)* | Fernet key for secrets-at-rest; empty → an ephemeral key is minted (secrets won't survive a restart) | -| `TREG_PUBLIC_URL` | `https://treg.superdesign.dev` | treg's public base, used to build the OAuth callback URI | +| `TREG_PUBLIC_URL` | `https://treg.to` | treg's public base, used to build the OAuth callback URI | | `TREG_SESSION_SECRET` | *(empty)* | signs the dashboard session cookie; falls back to `TREG_SECRET_KEY`. Set a real value in prod | | `TREG_GITHUB_CLIENT_ID` / `_SECRET` | *(empty)* | GitHub OAuth sign-in (callback `/auth/github/callback`); empty hides the button | | `TREG_GOOGLE_CLIENT_ID` / `_SECRET` | *(empty)* | Google OAuth sign-in (redirect `/auth/google/callback`); empty hides the button | diff --git a/USAGE.md b/USAGE.md index c0cff80f..562bf790 100644 --- a/USAGE.md +++ b/USAGE.md @@ -2,7 +2,7 @@ `treg` is the command-line client for **tools-registry**: call shared team tools without holding their credentials, and turn your local skills into shareable tools. It's a thin client over the -API (`https://treg.superdesign.dev`); the API is the only brain. +API (`https://treg.to`); the API is the only brain. Every command reads `~/.treg/config.json` for the endpoint + your token. Get per-command detail with `treg --help` (e.g. `treg secret --help`, not `treg "secret add"`). @@ -54,7 +54,7 @@ present a per-org token directly. | `treg onboard` | `--mode guided\|quick` · `--name N` · `--yes` · `--reset` | colourful guided first-run — pick **guided build** (you create the team + invite a teammate, step by step) or **quick demo** (we seed a full demo team + tool + activity), ending on a no-key call. Offered `[Y/n]` after your first login; `--reset` removes demo teammates | ```bash -treg config --base-url https://treg.superdesign.dev +treg config --base-url https://treg.to treg login # GitHub; or: treg login --email you@example.com # emailed 6-digit code (register-or-login) ``` @@ -82,7 +82,7 @@ treg org create "Team A" # active org is now team-a treg org invite bob@company.com --role member # prints e.g. inv_7Kd9x2LmQpR4 — send it to Bob # Bob's side (no email is sent; he gets the code over Slack/DM) -treg config --base-url https://treg.superdesign.dev +treg config --base-url https://treg.to treg org join inv_7Kd9x2LmQpR4 --email bob@company.com # joins + mints HIS own token treg tool ls # sees only Team A's tools treg org use team-a # switch orgs anytime; one token per org, never mixed @@ -188,7 +188,7 @@ treg call posthog api/projects --method POST --data '{"name":"x"}' **Agent-native (raw HTTP) form** — build the real upstream URL and prefix it; no CLI needed: ``` -GET https://treg.superdesign.dev/call/https://api.intercom.io/conversations?per_page=5 +GET https://treg.to/call/https://api.intercom.io/conversations?per_page=5 + header: X-Treg-Token: ``` @@ -376,7 +376,7 @@ Idempotent — re-run any time (skips what's registered; `--replace` updates). N | `treg health` | `--run` | show every credential's status; `--run` re-checks now (refresh oauth, probe tools, alert owners) | ```bash -# one-time: add https://treg.superdesign.dev/oauth/callback to your OAuth app's redirect URIs +# one-time: add https://treg.to/oauth/callback to your OAuth app's redirect URIs treg oauth connect gads --client-secret ./client_secret.json \ --scopes https://www.googleapis.com/auth/adwords treg health --run diff --git a/docs/DASHBOARD-TOUR.md b/docs/DASHBOARD-TOUR.md index 5db3f6e3..42f7c5fb 100644 --- a/docs/DASHBOARD-TOUR.md +++ b/docs/DASHBOARD-TOUR.md @@ -1,8 +1,8 @@ # tools-registry — dashboard tour Everything you can do in the web UI, with a screenshot per step. The interactive version (Ledger style, -prev/next, theme toggle) is served at `https://treg.superdesign.dev/dashboard-tour/` (Help → Dashboard tour); the CLI walkthrough is -[`docs/TUTORIAL.md`](TUTORIAL.md) / `https://treg.superdesign.dev/tutorial`. +prev/next, theme toggle) is served at `https://treg.to/dashboard-tour/` (Help → Dashboard tour); the CLI walkthrough is +[`docs/TUTORIAL.md`](TUTORIAL.md) / `https://treg.to/tutorial`. Screenshots are generated by `docs/dash-tour/capture.py` (Playwright) — re-run it after UI changes. diff --git a/docs/ONBOARDING.md b/docs/ONBOARDING.md index 2c6ae3e8..0d9c77f5 100644 --- a/docs/ONBOARDING.md +++ b/docs/ONBOARDING.md @@ -1,12 +1,12 @@ # tools-registry — onboarding The bootstrap an agent (or human) follows to start calling shared tools and to share its own. -The CLI is a thin client over the API at `https://treg.superdesign.dev`; the API is the only brain. +The CLI is a thin client over the API at `https://treg.to`; the API is the only brain. ## 1. Install the CLI ```bash -curl -fsSL https://treg.superdesign.dev/install.sh | sh # installs `treg`, points it at the registry +curl -fsSL https://treg.to/install.sh | sh # installs `treg`, points it at the registry ``` (Working from a clone instead? `uv sync && uv run treg --help`.) diff --git a/docs/PLUGIN-SUBMISSION.md b/docs/PLUGIN-SUBMISSION.md index 34cff21d..bcaf9cb4 100644 --- a/docs/PLUGIN-SUBMISSION.md +++ b/docs/PLUGIN-SUBMISSION.md @@ -38,7 +38,7 @@ and all three normal doors fail that test: GitHub OAuth, Google OAuth, and an em The way through already exists: ```bash -curl -fsSL https://treg.superdesign.dev/install.sh | sh +curl -fsSL https://treg.to/install.sh | sh treg login --token # the agents/CI door — no browser, no email ``` @@ -55,10 +55,10 @@ whatever balance it can reach, and the token goes into a form. | Long Description | *(use `interface.longDescription` from the manifest, verbatim)* | | Logo | `plugin/assets/logo.png` (1024×1024) | | Category | **Developer Tools** | -| Website URL | `https://treg.superdesign.dev` | +| Website URL | `https://treg.to` | | Support URL | **decide — see above** | -| Privacy Policy URL | `https://treg.superdesign.dev/privacy` | -| Terms URL | `https://treg.superdesign.dev/terms` | +| Privacy Policy URL | `https://treg.to/privacy` | +| Terms URL | `https://treg.to/terms` | | Developer Identity | the verified `superdesign` business identity | ## Skills tab @@ -135,7 +135,7 @@ rather than jurisdiction-specific, so start narrow rather than selecting everywh > > To test: install the CLI and sign in with the reviewer token, which needs no browser or email: > -> curl -fsSL https://treg.superdesign.dev/install.sh | sh +> curl -fsSL https://treg.to/install.sh | sh > treg login --token > > That account has a prepaid balance, so calls in the test cases will complete. `treg catalog search diff --git a/docs/TUTORIAL.md b/docs/TUTORIAL.md index 7766bd06..b7b15564 100644 --- a/docs/TUTORIAL.md +++ b/docs/TUTORIAL.md @@ -6,8 +6,8 @@ The whole registry, end to end. Every step shows the **exact command**, the **ex There are two companion versions of this same walkthrough, generated from one source (`src/treg/web/tutorial.js`): -- **In the dashboard** → sign in at `https://treg.superdesign.dev/` and open **Help → Tutorial**. -- **Standalone** → `https://treg.superdesign.dev/tutorial`. +- **In the dashboard** → sign in at `https://treg.to/` and open **Help → Tutorial**. +- **Standalone** → `https://treg.to/tutorial`. ### Two focused, deep-dive tutorials @@ -15,12 +15,12 @@ This main walkthrough covers the whole registry. Two features have their own det those for the full, step-by-step treatment (each shows the exact commands, real output, and how it was tested): -- **Import & shell** → `https://treg.superdesign.dev/tutorial-import-shell.md` — turn the CLIs already on your +- **Import & shell** → `https://treg.to/tutorial-import-shell.md` — turn the CLIs already on your machine into team tools in one command (`treg upload clis`), and open a shell (`treg shell`) where `stripe`, `gh`, `gcloud` … just work with the team key injected. Includes the local-run **security sandbox** (the CLI runs as a locked-down user, can reach only its own API, and can't leave the key on disk). -- **Team access control** → `https://treg.superdesign.dev/tutorial-access.md` — choose **which tools each member +- **Team access control** → `https://treg.to/tutorial-access.md` — choose **which tools each member may use**, and whether they may run CLIs **locally** — set at invite time, changed any time. --- @@ -70,7 +70,7 @@ the `HOME=` prefix. ```bash for u in tom bob alice; do mkdir -p ~/.treg-personas/$u - HOME=~/.treg-personas/$u treg config --base-url https://treg.superdesign.dev + HOME=~/.treg-personas/$u treg config --base-url https://treg.to done ``` @@ -478,7 +478,7 @@ token header — any language, any agent, `curl`. ```bash ATOK=$(python3 -c "import json;print(json.load(open('/Users/you/.treg-personas/alice/.treg/config.json'))['token'])") curl -s -H "X-Treg-Token: $ATOK" \ - "https://treg.superdesign.dev/call/https://postman-echo.com/get" + "https://treg.to/call/https://postman-echo.com/get" ``` ``` # the postman-echo JSON again, "authorization": "Bearer sk-demo-secret-123" injected — @@ -843,13 +843,13 @@ Admin panel lights up for him. ## Step 33 — The same registry, in the browser -Open **treg.superdesign.dev** and sign in with the **email code** door (the same one you used in the terminal): +Open **treg.to** and sign in with the **email code** door (the same one you used in the terminal): type your email → click **Email me a sign-in code** → **check your inbox** for the 6-digit code → paste it in and **Sign in**. You land on your team org — Tools shows the `echo` tool, Activity shows the call, and (since Tom is now super-admin) an **Admin** panel appears. ```bash -open https://treg.superdesign.dev/ +open https://treg.to/ ``` ``` # Sign in with email → land on Superdesign diff --git a/docs/VENDORS.md b/docs/VENDORS.md index 09efe34c..b3c1d19a 100644 --- a/docs/VENDORS.md +++ b/docs/VENDORS.md @@ -41,7 +41,7 @@ Strongly preferred (each one directly improves your listing): The fastest route: paste the prompt from the **"List as vendor"** button on the dashboard's Catalog page into your coding agent — it follows the hosted instructions at -[`/vendor-listing`](https://treg.superdesign.dev/vendor-listing) and opens the PR for you. +[`/vendor-listing`](https://treg.to/vendor-listing) and opens the PR for you. Or open an issue or PR on this repo yourself, with: 0. **A contact email in the PR/issue description** (e.g. `Contact: partnerships@yourapi.com`) — diff --git a/docs/context/foundation/charter.md b/docs/context/foundation/charter.md index a34f6d05..4f5f4ee7 100644 --- a/docs/context/foundation/charter.md +++ b/docs/context/foundation/charter.md @@ -36,7 +36,7 @@ What this means for anyone reading this fragment: Money and metering: [money](../architecture/money.md). The endpoint data and its pricing rules: [catalog](../architecture/catalog.md). -> **Status:** shipped and live on `treg.superdesign.dev` (Render, multi-tenant). This fragment records +> **Status:** shipped and live on `treg.to` (Render, multi-tenant; `treg.superdesign.dev` is the legacy alias). This fragment records > the ORIGINAL vision from the 2026-06-30 kickoff and the "why" behind the proxy; the shipped detail > lives in the architecture/interface fragments. > diff --git a/docs/context/interface/api.md b/docs/context/interface/api.md index 5293b776..d568b523 100644 --- a/docs/context/interface/api.md +++ b/docs/context/interface/api.md @@ -419,6 +419,11 @@ helpers `_secret_view` / `_tool_view` / `_bundle_view` never leak secret values surfaced by `GET /tools` / `/bundles/{id}`). ## Cross-cutting hardening (bug-hunt) +- **Legacy-host redirect:** `_legacy_host_redirect` 301s GET/HEAD marketing pages (`_REDIRECT_PATHS`) + from `treg.superdesign.dev` (`_LEGACY_HOSTS`) to the canonical `public_url` host (`treg.to`). + Everything else is served in place on BOTH hosts, forever: installed CLIs/skills hold tokens + pointed at the legacy host, HTTP clients strip `Authorization` on a cross-host redirect, and + `curl {BASE}/install.sh | sh` runs without `-L`. Never remove the legacy domain from Render. - **Security headers:** a `@app.middleware` adds `X-Content-Type-Options: nosniff`, `X-Frame-Options: DENY`, `Referrer-Policy: no-referrer`, and HSTS to every response (`setdefault`, so the `/call` proxy's stricter CSP/nosniff wins). diff --git a/docs/context/ops/deploy.md b/docs/context/ops/deploy.md index 1a4ca822..207cb806 100644 --- a/docs/context/ops/deploy.md +++ b/docs/context/ops/deploy.md @@ -36,7 +36,8 @@ keygen` prints a Fernet key for `TREG_SECRET_KEY`. Render's `fromDatabase`-injected URL works unedited (the async engine needs the asyncpg driver). - `secret_key` — the Fernet key; empty → an ephemeral key is minted at startup (secrets won't survive a restart). See [auth-secrets](../architecture/auth-secrets.md). -- `public_url` — default `https://treg.superdesign.dev` (the reference deployment); self-hosters set +- `public_url` — default `https://treg.to` (the reference deployment; `treg.superdesign.dev` is the + legacy host — still served in full, marketing pages 301 to the canonical host); self-hosters set `TREG_PUBLIC_URL`. Used to build the OAuth callback URI. - `api_token` — a bootstrap caller token (MVP leftover; per-user tokens are the real auth). - `admin_token` — the cross-tenant **super-admin** bearer (`TREG_ADMIN_TOKEN`); empty disables the env @@ -107,8 +108,8 @@ keygen` prints a Fernet key for `TREG_SECRET_KEY`. - `resend_api_key` / `email_from` — transactional email via **Resend** (`src/treg/email.py`): the OTP sign-in code + team invitations. Empty key = no real send (dev mode still returns the code; prod without a key silently skips — best-effort, never breaks the flow). `email_from` **must** be a - Resend-verified domain — `treg.superdesign.dev` is **verified** (DKIM `resend._domainkey.treg`, SPF - MX+TXT on `send.treg`), so the default is `no-reply@treg.superdesign.dev`. **On Render:** set + Resend-verified domain — `treg.to` is **verified** (DKIM + SPF records on the treg.to zone; + `treg.superdesign.dev` stays verified as a fallback), so the default is `no-reply@treg.to`. **On Render:** set `TREG_RESEND_API_KEY`, optionally `TREG_EMAIL_FROM`, and leave `TREG_EMAIL_DEV_MODE` false. ## Web dashboard @@ -118,7 +119,8 @@ lives inside the `treg` package (the `packages` inclusion covers non-.py assets) [dashboard](../interface/dashboard.md). ## Current hosting (shipped) -Deployed on **Render** at `https://treg.superdesign.dev` via the Blueprint below (one web service + a +Deployed on **Render** at `https://treg.to` (with `treg.superdesign.dev` attached as the legacy +alias — never remove it: installed CLIs/skills point there with tokens) via the Blueprint below (one web service + a managed Postgres). The Fernet key lives only in the service's environment — **back it up**; losing it makes every stored secret unrecoverable. For local dev, `scripts/dev-local.sh up` runs the server with its own sqlite DB and email dev mode. diff --git a/docs/tutorial.html b/docs/tutorial.html index 078a466c..b0bdb619 100644 --- a/docs/tutorial.html +++ b/docs/tutorial.html @@ -4,7 +4,7 @@ tools-registry — Tutorial (moved) - +