ship’s manual · guide
Connections
A connection is a host-owned broker, not a secret copied into every resident's shell.
Gmail
When Gmail OAuth accounts exist on the 1Helm host, Captain-authorized Skipper can grant a resident access to named accounts. Current resident operations are account listing, search, message retrieval, and draft creation. Sending is disabled by default.
Photon and iMessage
The connector uses Photon's device-code login and Dashboard/Spectrum APIs to create or reuse a 1Helm project, rotate its one-time secret, register the operator, discover the assigned line, and start a long-lived spectrum-ts gRPC stream in a supervised loopback sidecar.
Only the configured Captain phone is accepted. Its first inbound text opens a durable conversation with Skipper in the Captain's private #main Texts tab; replies return to that same phone conversation. The context survives connector restarts and Photon space-ID changes until the Captain sends /new. The Captain can continue any saved Texts thread on desktop, and desktop-only turns are not replayed as iMessages. Credentials never enter a resident computer.
Current limitation: the reliable contract is text. Attachment events are represented conservatively and full attachment fidelity is still being verified.
Connector standard
New native connections must provide least-privilege scoping, secret isolation, reconnect/recovery, deduplication, an audit trail, deterministic tests, and honest capability status. A prompt saying “use Slack” is not a connector.