Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion app/api/mcp/route.ts
Original file line number Diff line number Diff line change
Expand Up @@ -547,7 +547,7 @@ const handler = createMcpHandler(
serverInfo: { name: "gapwise-ai", version: "0.4.0" },
capabilities: { tools: {} },
instructions:
"Treat Gapwise as source-backed timetable and campus context for students at supported Canadian universities. Delegated schedules may contain meetings from any supported university, including UTM, UTSG, UTSC, or mixed-campus U of T schedules; the current stateless public building, place, route, and gap-window tools are explicitly UTM-scoped. For an exact course/class/building reference, search first instead of guessing: use search_my_schedule for delegated classes and search_utm_buildings only for UTM campus places, then use get_my_course_context/get_utm_building when deeper context is needed. For date-specific questions use get_my_day or get_my_schedule_range; for a generic term view use get_my_week. For ACORN imports, RES/isReservedAssessmentWindow entries are recurring assessment placeholders: never call them weekly classes, never count them as hard commitments, never let them block availability, and never route to them unless the user separately provides a confirmed assessment occurrence. A normal academic meeting whose locationType is tba is still a real commitment and must block time; only its location is unresolved. For broad planning start with get_my_decision_context. For usable time use find_my_available_windows or find_my_weekly_opportunities rather than doing free-time subtraction yourself. Validate exact proposed intervals with check_my_plan_feasibility. Preserve Gapwise route status, confidence, activity budget, leave-by time and warnings exactly; use route_between_utm_buildings only for UTM location-specific route claims and do not turn approximate/unavailable routes into certainty. Personal Items are retired: do not ask to create, edit, delete, read, or plan around them. Academic schedule data is read-only. The only current private write is update_gap_preferences, which requires explicit permission and the current revision. Do not invent missing classes, course matches, rooms, buildings, routes, availability, assessment dates, or permissions. If a search/context tool reports ambiguity or no match, surface that uncertainty and ask for disambiguation only when needed. Read-tool text contains essential facts for clients that do not expose structuredContent; structured content is authoritative and includes snapshot revision/freshness context.",
"Treat Gapwise as source-backed timetable and campus context for students at supported Canadian universities. Delegated schedules may contain meetings from any supported university, including UTM, UTSG, UTSC, or mixed-campus U of T schedules; use the canonical public campus tools with the student's university and campus; the seven legacy UTM tools are deprecated compatibility aliases. For an exact course/class/building reference, search first instead of guessing: use search_my_schedule for delegated classes and search_campus_buildings or search_campus_places with the correct university and campus for public locations, then use get_my_course_context/get_campus_building/get_campus_place when deeper context is needed. For date-specific questions use get_my_day or get_my_schedule_range; for a generic term view use get_my_week. For ACORN imports, RES/isReservedAssessmentWindow entries are recurring assessment placeholders: never call them weekly classes, never count them as hard commitments, never let them block availability, and never route to them unless the user separately provides a confirmed assessment occurrence. A normal academic meeting whose locationType is tba is still a real commitment and must block time; only its location is unresolved. For broad planning start with get_my_decision_context. For usable time use find_my_available_windows or find_my_weekly_opportunities rather than doing free-time subtraction yourself. Validate exact proposed intervals with check_my_plan_feasibility. Preserve Gapwise route status, confidence, activity budget, leave-by time and warnings exactly; use route_between_campus_buildings with the correct university and campus for location-specific route claims and do not turn approximate/unavailable routes into certainty. Personal Items are retired: do not ask to create, edit, delete, read, or plan around them. Academic schedule data is read-only. The only current private write is update_gap_preferences, which requires explicit permission and the current revision. Do not invent missing classes, course matches, rooms, buildings, routes, availability, assessment dates, or permissions. If a search/context tool reports ambiguity or no match, surface that uncertainty and ask for disambiguation only when needed. Read-tool text contains essential facts for clients that do not expose structuredContent; structured content is authoritative and includes snapshot revision/freshness context.",
verboseLogs: false,
},
);
Expand Down
2 changes: 1 addition & 1 deletion docs/ANTHROPIC_SUBMISSION.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ Gapwise should demonstrate that:
Against the exact release SHA, complete:

1. add `https://ai.gapwise.ca/api/mcp` as a custom remote connector;
2. verify all 20 tools are discovered with the correct public/private authorization metadata;
2. verify all 30 tools are discovered with the correct public/private authorization metadata;
3. exercise public building/routing tools before private authorization;
4. connect the synthetic reviewer Gapwise account through the normal OAuth/consent flow;
5. exercise private day/week/decision/availability/gap/feasibility reads;
Expand Down
6 changes: 3 additions & 3 deletions docs/DIRECTORY_METADATA.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ Use your Gapwise timetable and available campus intelligence with an AI assistan

## Full description

Gapwise connects your explicitly delegated timetable context and deterministic campus intelligence to compatible AI assistants through a secure remote MCP integration. Ask about your day or week, find realistic study opportunities between classes, check whether a proposed plan fits, and reason over Gapwise route and gap assessments. Public MCP campus tools currently cover UTM; when you explicitly allow writes, the integration can queue selected gap-preference changes.
Gapwise connects your explicitly delegated timetable context and deterministic campus intelligence to compatible AI assistants through a secure remote MCP integration. Ask about your day or week, find realistic study opportunities between classes, check whether a proposed plan fits, and reason over Gapwise route and gap assessments. Public MCP campus tools cover all supported universities; seven deprecated UTM aliases remain for compatibility. When you explicitly allow writes, the integration can queue selected gap-preference changes.

Gapwise remains the source of deterministic schedule and campus facts; the connected AI assistant provides natural-language reasoning. Imported academic meetings are always read-only. The connector does not expose friend data, precise live/background location, account credentials, raw imported timetable files, or Gapwise private-data encryption keys.

Expand All @@ -38,7 +38,7 @@ Gapwise is an independent project and is not an official service of, or endorsed
- Find source-backed free windows and weekly study opportunities.
- Use deterministic Gapwise gap assessments rather than model-side timetable arithmetic.
- Check proposed personal blocks against hard schedule conflicts and known Gapwise transition constraints.
- Resolve UTM buildings and reason over Gapwise campus routes when public campus tools are enabled.
- Resolve buildings and reason over supported campus routes with the correct university and campus context.
- Update selected delegated gap preferences when write permission is enabled.
- Revoke AI access from Gapwise at any time.

Expand All @@ -48,7 +48,7 @@ Gapwise is an independent project and is not an official service of, or endorsed
- Find me a 90-minute study opportunity this week.
- What is the best use of my gap after class on Tuesday?
- Can I fit a gym session from 3 to 4 PM Wednesday?
- How do I get from MN to DH at UTM?
- How do I get from TB to ML at Carleton?

## Safety / privacy statements

Expand Down
8 changes: 4 additions & 4 deletions docs/OPENAI_SUBMISSION.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,9 +22,9 @@ When OpenAI supplies a domain-verification token, set it only in production as `

## Tool review assertions

The current release surface contains **20 tools**:
The current release surface contains **30 tools**:

- **7 public stateless UTM campus-intelligence tools** with no private OAuth security declaration and `openWorldHint: true`;
- **17 public stateless campus-intelligence tools** with no private OAuth security declaration and `openWorldHint: true` (10 canonical multi-university tools and 7 deprecated UTM compatibility aliases);
- **12 OAuth-protected private read/status/planning tools**; and
- **1 OAuth-protected bounded write tool**, `update_gap_preferences`.

Expand Down Expand Up @@ -64,7 +64,7 @@ Use the three canonical negative tests in `OPENAI_TEST_CASES.md`:
2. Supabase OAuth Server and Gapwise `/oauth/consent` are active with the intended MCP client-registration flow.
3. Approved OAuth tokens contain the exact MCP audience; browser/unapproved/wrong-audience tokens do not.
4. Production protected-resource metadata identifies `https://ai.gapwise.ca/api/mcp` and the supported `email` scope.
5. MCP initialization and `tools/list` expose all 20 tools with seven public tools lacking OAuth declarations and 13 private tools carrying them.
5. MCP initialization and `tools/list` expose all 30 tools with 17 public tools lacking OAuth declarations and 13 private tools carrying them.
6. Public tools advertise `openWorldHint: true`; bounded private-account tools remain `openWorldHint: false`.
7. The production OpenAI domain challenge is configured only if/when the current submission portal supplies a token.
8. The real ChatGPT OAuth/read/write/revoke and negative-path matrix in `CLIENT_VALIDATION.md` passes against the exact release SHA.
Expand All @@ -76,4 +76,4 @@ Use the three canonical negative tests in `OPENAI_TEST_CASES.md`:

## Release notes template

> Gapwise provides a remote MCP integration that combines stateless UTM campus intelligence with explicitly delegated private timetable/planning context. Connected users can ask about schedules, availability, routes, campus places, and Gapwise gap assessments and may queue a bounded gap-preference update when that permission is enabled. Academic course meetings remain source-backed and read-only. Personal Items are retired. Private OAuth credentials are user-scoped, resource-bound, and protected by Gapwise's approval, RLS, ownership, encryption, and revocation boundaries.
> Gapwise provides a remote MCP integration that combines stateless campus intelligence across supported universities with explicitly delegated private timetable/planning context. Connected users can ask about schedules, availability, routes, campus places, and Gapwise gap assessments and may queue a bounded gap-preference update when that permission is enabled. Academic course meetings remain source-backed and read-only. Personal Items are retired. Private OAuth credentials are user-scoped, resource-bound, and protected by Gapwise's approval, RLS, ownership, encryption, and revocation boundaries.
Loading