{"id":48932859,"url":"https://github.com/kensaurus/mushi-mushi","last_synced_at":"2026-06-13T07:01:36.415Z","repository":{"id":351750066,"uuid":"1212314514","full_name":"kensaurus/mushi-mushi","owner":"kensaurus","description":"🦖The friendly user-friction layer that complements Sentry. LLM-native, auto-fixes via draft PRs.","archived":false,"fork":false,"pushed_at":"2026-06-11T10:24:29.000Z","size":243164,"stargazers_count":1,"open_issues_count":24,"forks_count":0,"subscribers_count":0,"default_branch":"master","last_synced_at":"2026-06-11T11:09:58.906Z","etag":null,"topics":["ai-agents","angular","auto-fix","bug-reporting","bug-tracker","claude-code","error-monitoring","feedback-widget","llm-ops","mcp","observability","react","react-native","sentry","session-replay","supabase","svelte","user-feedback","user-friction","vue"],"latest_commit_sha":null,"homepage":"https://kensaur.us/mushi-mushi/","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/kensaurus.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":"SUPPORT.md","governance":null,"roadmap":".github/ROADMAP.md","authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE","maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null},"funding":{"github":["kensaurus"]}},"created_at":"2026-04-16T08:56:20.000Z","updated_at":"2026-06-11T10:24:30.000Z","dependencies_parsed_at":"2026-04-21T10:03:22.270Z","dependency_job_id":null,"html_url":"https://github.com/kensaurus/mushi-mushi","commit_stats":null,"previous_names":["kensaurus/mushi-mushi"],"tags_count":178,"template":false,"template_full_name":null,"purl":"pkg:github/kensaurus/mushi-mushi","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kensaurus%2Fmushi-mushi","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kensaurus%2Fmushi-mushi/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kensaurus%2Fmushi-mushi/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kensaurus%2Fmushi-mushi/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/kensaurus","download_url":"https://codeload.github.com/kensaurus/mushi-mushi/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kensaurus%2Fmushi-mushi/sbom","scorecard":{"id":1246727,"data":{"date":"2026-04-29T08:30:45Z","repo":{"name":"github.com/kensaurus/mushi-mushi","commit":"edaee6d1334c7e2bccaa0e816de359b2e12ceeb4"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":4.2,"checks":[{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"project was created within the last 90 days. Please review its contents carefully","details":["Warn: Repository was created within the last 90 days."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy"}},{"name":"Code-Review","score":0,"reason":"Found 0/25 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: containerImage not pinned by hash: deploy/Dockerfile.admin:4: pin your Docker image by updating node:22-alpine to node:22-alpine@sha256:8ea2348b068a9544dae7317b4f3aafcdc032df1647bb7d768a05a5cad1a7683f","Warn: containerImage not pinned by hash: deploy/Dockerfile.admin:12: pin your Docker image by updating nginx:alpine to nginx:alpine@sha256:5616878291a2eed594aee8db4dade5878cf7edcb475e59193904b198d9b830de","Warn: containerImage not pinned by hash: deploy/Dockerfile.edge:4: pin your Docker image by updating denoland/deno:2.0.0 to denoland/deno:2.0.0@sha256:675499743d2bc74ad8f4d6c8c65c13b254b8bf039d27769cc840780521d8206d","Info:   0 out of   3 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":9,"reason":"SAST tool is not run on all commits -- score normalized to 9","details":["Warn: 28 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing"}},{"name":"Dependency-Update-Tool","score":0,"reason":"no update tool detected","details":["Warn: no dependency update tool configurations found"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license"}},{"name":"Branch-Protection","score":3,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'master'","Info: 'force pushes' disabled on branch 'master'","Info: 'branch protection settings apply to administrators' is required to merge on branch 'master'","Info: 'stale review dismissal' is required to merge on branch 'master'","Warn: branch 'master' does not require approvers","Warn: codeowners review is not required on branch 'master'","Warn: 'last push approval' is disabled on branch 'master'","Warn: 'up-to-date branches' is disabled on branch 'master'","Info: status check found to merge onto on branch 'master'","Info: PRs are required in order to make changes on branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection"}},{"name":"Contributors","score":3,"reason":"project has 1 contributing companies or organizations -- score normalized to 3","details":["Info: found contributions from: sakuraappworks"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors"}},{"name":"Vulnerabilities","score":9,"reason":"1 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-qx2v-qp2m-jg93"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities"}},{"name":"CI-Tests","score":10,"reason":"30 out of 30 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests"}}]},"last_synced_at":"2026-04-29T15:34:55.419Z","repository_id":351750066,"created_at":"2026-04-29T15:34:55.420Z","updated_at":"2026-04-29T15:34:55.420Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34275068,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-13T02:00:06.617Z","response_time":62,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ai-agents","angular","auto-fix","bug-reporting","bug-tracker","claude-code","error-monitoring","feedback-widget","llm-ops","mcp","observability","react","react-native","sentry","session-replay","supabase","svelte","user-feedback","user-friction","vue"],"created_at":"2026-04-17T10:12:30.618Z","updated_at":"2026-06-13T07:01:34.946Z","avatar_url":"https://github.com/kensaurus.png","language":"TypeScript","funding_links":["https://github.com/sponsors/kensaurus"],"categories":["Development Utilities"],"sub_categories":["AI"],"readme":"\u003cdiv align=\"center\"\u003e\n\n# Mushi Mushi 虫虫\n\n**The user-friction intelligence layer that complements Sentry.**\n\nSentry sees what your code throws. Mushi sees what your users *feel*.\n\n[![npm](https://img.shields.io/npm/v/@mushi-mushi/react?label=%40mushi-mushi%2Freact\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/react)\n[![CI](https://github.com/kensaurus/mushi-mushi/actions/workflows/ci.yml/badge.svg)](https://github.com/kensaurus/mushi-mushi/actions/workflows/ci.yml)\n[![License](https://img.shields.io/badge/SDK-MIT-blue.svg)](./LICENSE)\n[![Server](https://img.shields.io/badge/server-BSL%201.1-orange.svg)](./packages/server/LICENSE)\n[![React 19](https://img.shields.io/badge/React-19-149eca.svg)](https://react.dev)\n[![TypeScript 6](https://img.shields.io/badge/TypeScript-6.0-3178c6.svg)](https://typescriptlang.org)\n[![Vite 8](https://img.shields.io/badge/Vite-8-646cff.svg)](https://vite.dev)\n[![Node ≥22](https://img.shields.io/badge/Node-%E2%89%A522-339933.svg)](https://nodejs.org)\n[![pnpm ≥10](https://img.shields.io/badge/pnpm-%E2%89%A510-f69220.svg)](https://pnpm.io)\n\n[Quick start](#quick-start) · [Live admin demo](https://kensaur.us/mushi-mushi/) · [Docs](./apps/docs) · [Self-hosting](./SELF_HOSTED.md) · [Architecture](#architecture)\n\n\u003ca href=\"https://kensaur.us/mushi-mushi/\"\u003e\n  \u003cimg src=\"./docs/screenshots/report-detail-dark.png\" alt=\"A real classified report inside Mushi Mushi: user description, captured console error, environment, triage thread, and a one-click Dispatch fix button\" width=\"100%\" /\u003e\n\u003c/a\u003e\n\n\u003c/div\u003e\n\n---\n\n## The gap Mushi Mushi closes\n\nYour existing monitoring is excellent at one thing: **what your code threw**. It cannot see:\n\n- A button that *looks* clickable but does nothing\n- A checkout flow that confuses every new user\n- A page that takes 12 seconds to load but never errors\n- A layout that breaks on one specific Android phone\n- A feature that silently regressed two deploys ago\n\nThese are **user-felt bugs**. They never trigger an alert. Users just leave.\n\nMushi Mushi is the missing layer. Drop a small SDK into your app — users press shake-to-report (or click a widget) and Mushi auto-captures screenshot, console, network, device, route, and intent. An LLM-native pipeline (Haiku fast-filter → Sonnet vision + RAG → judge → optional agentic auto-fix) classifies, deduplicates, and turns the friction into actionable bug intelligence — wired into Sentry, Slack, Jira, Linear, and PagerDuty.\n\n| Scenario                              | Sentry / Datadog | **Mushi Mushi** |\n| ------------------------------------- | :--------------: | :-------------: |\n| Unhandled exception                   |        ✅        |        ✅        |\n| Button doesn't respond                |        —         |        ✅        |\n| Page loads in 12 s, no error          |        —         |        ✅        |\n| User can't find the settings panel    |        —         |        ✅        |\n| Layout breaks on iPad Safari          |        —         |        ✅        |\n| Form submits but data doesn't save    |        ~         |        ✅        |\n| Feature regressed since last deploy   |        ~         |        ✅        |\n\n\u003e Designed as a **companion** to your existing monitoring, not a replacement. Reports stream through to Sentry breadcrumbs and link back to the offending session.\n\n---\n\n## Tour\n\n\u003ctable width=\"100%\"\u003e\n\u003ctr\u003e\n  \u003ctd width=\"50%\" valign=\"top\"\u003e\n    \u003ca href=\"./docs/screenshots/dashboard-dark.png\"\u003e\u003cimg src=\"./docs/screenshots/dashboard-dark.png\" alt=\"Admin dashboard showing total/new/classified/dismissed counters\" /\u003e\u003c/a\u003e\n    \u003cp align=\"center\"\u003e\u003cb\u003eDashboard\u003c/b\u003e\u003cbr/\u003eAt-a-glance counters, severity histogram, weekly trend.\u003c/p\u003e\n  \u003c/td\u003e\n  \u003ctd width=\"50%\" valign=\"top\"\u003e\n    \u003ca href=\"./docs/screenshots/reports-dark.png\"\u003e\u003cimg src=\"./docs/screenshots/reports-dark.png\" alt=\"Reports list filtered by status, category, severity\" /\u003e\u003c/a\u003e\n    \u003cp align=\"center\"\u003e\u003cb\u003eReports\u003c/b\u003e\u003cbr/\u003eTriage queue with status / category / severity filters.\u003c/p\u003e\n  \u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n  \u003ctd width=\"50%\" valign=\"top\"\u003e\n    \u003ca href=\"./docs/screenshots/graph-dark.png\"\u003e\u003cimg src=\"./docs/screenshots/graph-dark.png\" alt=\"Knowledge graph linking bug nodes to affected pages\" /\u003e\u003c/a\u003e\n    \u003cp align=\"center\"\u003e\u003cb\u003eKnowledge graph\u003c/b\u003e\u003cbr/\u003eBug ↔ component ↔ page ↔ version, traversable in NL.\u003c/p\u003e\n  \u003c/td\u003e\n  \u003ctd width=\"50%\" valign=\"top\"\u003e\n    \u003ca href=\"./docs/screenshots/health-dark.png\"\u003e\u003cimg src=\"./docs/screenshots/health-dark.png\" alt=\"System health: per-model LLM telemetry, fallback rate, latency p50/p95, cron job status\" /\u003e\u003c/a\u003e\n    \u003cp align=\"center\"\u003e\u003cb\u003eSystem health\u003c/b\u003e\u003cbr/\u003eLive LLM telemetry, fallback rate, latency p50/p95, cron status.\u003c/p\u003e\n  \u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n  \u003ctd width=\"50%\" valign=\"top\"\u003e\n    \u003ca href=\"./docs/screenshots/marketplace-dark.png\"\u003e\u003cimg src=\"./docs/screenshots/marketplace-dark.png\" alt=\"Plugin marketplace with PagerDuty Escalation, Linear Sync, Zapier Bridge\" /\u003e\u003c/a\u003e\n    \u003cp align=\"center\"\u003e\u003cb\u003ePlugin marketplace\u003c/b\u003e\u003cbr/\u003eHMAC-signed webhooks. PagerDuty / Linear / Zapier ship in-tree.\u003c/p\u003e\n  \u003c/td\u003e\n  \u003ctd width=\"50%\" valign=\"top\"\u003e\n    \u003ca href=\"./docs/screenshots/compliance-dark.png\"\u003e\u003cimg src=\"./docs/screenshots/compliance-dark.png\" alt=\"Compliance dashboard: latest control evidence, data residency, retention policies, DSARs\" /\u003e\u003c/a\u003e\n    \u003cp align=\"center\"\u003e\u003cb\u003eCompliance\u003c/b\u003e\u003cbr/\u003eSOC 2 evidence pack, data residency pinning, DSAR workflow.\u003c/p\u003e\n  \u003c/td\u003e\n\u003c/tr\u003e\n\u003c/table\u003e\n\n---\n\n## Seven capabilities, one platform\n\n1. **User-side capture** — Shadow-DOM widget, screenshot, console + network rings, route + intent, offline queue, rage-click / error-spike / slow-page proactive triggers.\n2. **LLM-native classification** — 2-stage pipeline (Haiku fast-filter → Sonnet deep + vision), structured outputs via `response_format`, prompt-cached system instructions, deterministic JSON.\n3. **Knowledge graph + dedup** — Bug ↔ component ↔ page ↔ version edges in Postgres + pgvector. Auto-grouping kills duplicate noise.\n4. **LLM-as-Judge self-improvement** — Weekly Sonnet judge scores classifier outputs; low-scoring runs feed a fine-tuning queue. OpenAI fallback when Anthropic is degraded.\n5. **Agent-agnostic auto-fix** — Orchestrator with `validateResult` gating + GitHub PR creation. Sandbox provider abstraction (`local-noop` for tests, `e2b` / `modal` / `cloudflare` for prod, all four wired through `resolveSandboxProvider`). True MCP client adapter (JSON-RPC 2.0 + SEP-1686 Tasks) so Claude Code, Codex, Cursor, or any future agent plugs in.\n6. **Multi-repo coordinated PRs** — A bug spanning frontend + backend opens linked PRs (`fix_coordinations` table) so reviewers see the full surface.\n7. **Enterprise scaffolding** — SSO config CRUD, audit log ingest, plugin marketplace with HMAC, region-pinned data residency, retention policies, DSAR workflow, Stripe metered billing.\n\n---\n\n## Quick start\n\n```bash\nnpx mushi-mushi\n```\n\nThe wizard auto-detects your framework (Next.js / Nuxt / SvelteKit / Angular / Expo / Capacitor / plain React, Vue, Svelte / vanilla JS), installs the right SDK with your package manager, writes `MUSHI_PROJECT_ID` and `MUSHI_API_KEY` to `.env.local` (with the right framework prefix), and prints the snippet to paste in. Equivalent commands:\n\n```bash\nnpm create mushi-mushi              # via the npm-create convention\nnpx @mushi-mushi/cli init           # if you prefer the scoped name\n```\n\nSkip the wizard and install directly if you already know which SDK you want:\n\n```bash\nnpm install @mushi-mushi/react      # also covers Next.js\n```\n\n```tsx\nimport { MushiProvider } from '@mushi-mushi/react'\n\nfunction App() {\n  return (\n    \u003cMushiProvider config={{ projectId: 'proj_xxx', apiKey: 'mushi_xxx' }}\u003e\n      \u003cYourApp /\u003e\n    \u003c/MushiProvider\u003e\n  )\n}\n```\n\nThat's it. Users now have a shake-to-report widget. Reports land in your admin console, classified within seconds.\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eOther frameworks\u003c/b\u003e — Vue, Svelte, Angular, React Native, Vanilla JS, iOS, Android\u003c/summary\u003e\n\n#### Vue 3 / Nuxt\n```ts\nimport { MushiPlugin } from '@mushi-mushi/vue'\napp.use(MushiPlugin, { projectId: 'proj_xxx', apiKey: 'mushi_xxx' })\n\nimport { Mushi } from '@mushi-mushi/web'\nMushi.init({ projectId: 'proj_xxx', apiKey: 'mushi_xxx' })\n```\n\n#### Svelte / SvelteKit\n```ts\nimport { initMushi } from '@mushi-mushi/svelte'\ninitMushi({ projectId: 'proj_xxx', apiKey: 'mushi_xxx' })\n\nimport { Mushi } from '@mushi-mushi/web'\nMushi.init({ projectId: 'proj_xxx', apiKey: 'mushi_xxx' })\n```\n\n#### Angular 17+\n```ts\nimport { provideMushi } from '@mushi-mushi/angular'\nbootstrapApplication(AppComponent, {\n  providers: [provideMushi({ projectId: 'proj_xxx', apiKey: 'mushi_xxx' })],\n})\n```\n\n#### React Native / Expo\n```tsx\nimport { MushiProvider } from '@mushi-mushi/react-native'\n\u003cMushiProvider projectId=\"proj_xxx\" apiKey=\"mushi_xxx\"\u003e\n  \u003cApp /\u003e\n\u003c/MushiProvider\u003e\n```\n\n#### Vanilla JS / any framework\n```ts\nimport { Mushi } from '@mushi-mushi/web'\nMushi.init({ projectId: 'proj_xxx', apiKey: 'mushi_xxx' })\n```\n\n#### iOS (Swift Package Manager — early dev)\n```swift\n.package(url: \"https://github.com/kensaurus/mushi-mushi.git\", from: \"0.1.0\")\n\nimport Mushi\nMushi.configure(projectId: \"proj_xxx\", apiKey: \"mushi_xxx\")\n```\n\n#### Android (Maven — early dev)\n```kotlin\ndependencies {\n  implementation(\"dev.mushimushi:mushi-android:0.1.0\")\n}\n\nMushi.init(context = this, config = MushiConfig(projectId = \"proj_xxx\", apiKey = \"mushi_xxx\"))\n```\n\n\u003c/details\u003e\n\n\u003e Want a runnable example? Check [`examples/react-demo`](./examples/react-demo) — a minimal Vite + React app with test buttons for dead clicks, thrown errors, failed API calls, and console errors.\n\n---\n\n## Where the project is today\n\n| Wave | Theme                                              | Status |\n| :--: | -------------------------------------------------- | :----: |\n|  A   | Capture, fast-filter, deep classification, dedup   |   ✅    |\n|  B   | Knowledge graph, NL queries, weekly intelligence   |   ✅    |\n|  C   | Vision air-gap, RAG codebase indexer, fix dispatch |   ✅    |\n|  D   | Marketplace, Cloud + Stripe, multi-repo fixes, hardened LLM I/O | ✅ (v1.0.0 prepping) |\n\nReleased today: `v0.8.0`. Next: `v1.0.0` — see [HANDOVER.md](./HANDOVER.md) for the release checklist and the two deferred follow-ups (Node mirror of `sanitize.ts` and the demo video).\n\n**Latest dogfood:** end-to-end PDCA loop validated on a real production webapp ([glot.it](https://github.com/kensaurus/glot.it)) with my own OpenRouter key. Report → Stage 1 + Stage 2 LLM triage → admin \"Dispatch fix\" → `fix-worker` → draft GitHub PR → live in `/fixes`. Sentry, Langfuse and GitHub all probe **Healthy** from the Integrations page. Full writeup with screenshots: [`docs/dogfood-glotit-pdca-2026-04-17.md`](./docs/dogfood-glotit-pdca-2026-04-17.md).\n\n**PDCA full-sweep (2026-04-18):** Stage 2 air-gap closed (only structured Stage 1 evidence reaches Sonnet, never raw user strings) and now contract-tested via `stage2-airgap.test.ts`; pipeline self-heals via `mushi-pipeline-recovery-5m` `pg_cron` + admin \"Recover stranded\" button + `scripts/pipeline-recover.mjs` host fallback (verified 2026-04-18 12:14 UTC: synthetic stranded report `07325681-…` → fast-filter 1.7 s → classify-report 14.1 s → `classified`); SDK now ships `fingerprintHash` (V5 §3c) and `ingestReport` always anti-games when present; Stripe quota gate ships HTTP 402 + `/billing` UI + invoice list + dashboard `QuotaBanner`; Sentry Seer cron poller; GitHub indexer sweep mode; Modal + Cloudflare sandbox adapters; real SAML SSO via Supabase Auth Admin API (OIDC documented as enterprise-tier-only); integrations routing CRUD with masked-secret pass-through; GraphPage a11y (table fallback + ARIA); `usePageData` + `useToast` rolled out across all 24 admin tabs (Playwright sweep 2026-04-18 12:20 UTC: 0 console errors, 0 warnings); `library-modernizer` + `prompt-auto-tune` Edge Functions deployed; 7 Supabase advisor lints cleared. Full handover: [`docs/HANDOVER-2026-04-18.md`](./docs/HANDOVER-2026-04-18.md).\n\n**Admin console overhaul (Apr 2026):** every analytical page now shares the same `charts.tsx` primitives (`KpiTile`, `LineSparkline`, `SeverityStackedBars`, `Histogram`, `StatusPill`, `HealthPill`). Knowledge graph is a real React Flow canvas with cluster layout + side-panel. Judge has live KPIs, distribution histogram and a prompt leaderboard. NL Query has persistent per-user history and sanitised SQL output. Fixes shows a per-attempt Git branch graph plus a 30-day KPI summary. Queue (formerly DLQ) gets pagination, throughput sparkline and stage breakdown. Fine-Tuning was retired in favour of **Prompt Lab** (A/B traffic, dataset preview, clone/activate/delete) — `/fine-tuning` redirects there. Bug Intelligence runs **async** through `intelligence_generation_jobs` so the page no longer hangs on slow LLM calls. Cross-cutting: global `useToast`, StrictMode-safe `usePageData`, paused polling on hidden tabs, and an `IntegrationHealthDot` that reflects real `/v1/admin/health/history` status.\n\n**PDCA cockpit reframing (Apr 2026):** the 23-page admin console is now organised around the Plan → Do → Check → Act loop the README sells, not the previous `Overview / Pipeline / Operations / Configuration` jargon. The sidebar groups every page under its PDCA stage (`Layout.tsx`); the dashboard prepends a 4-tile `PdcaCockpit` with a single living number per stage, a coloured ring on the current bottleneck, and one-click drill-into-stage. The empty dashboard now reads as a 3-step PDCA first-run script. Reports list got a 4 px severity stripe, a `+N similar` dedup badge, and a single primary action per row (`Triage →` or `Dispatch fix →`). Knowledge graph auto-switches to a Sankey-style storyboard when fewer than 12 nodes exist. Judge surfaces report summaries instead of hashes plus column tooltips. Anti-Gaming aggregates identical events by `(reason, fingerprint, ip)`. See [`apps/admin/README.md`](./apps/admin/README.md#information-architecture-pdca-loop) for the new IA + composition.\n\n**Wave I gap-closure (Apr 2026):** closes the audit gap from the PDCA cockpit reframing. Reports list now shows a real `unique_users` blast-radius column (a `COUNT(DISTINCT reporter_token_hash)` Postgres RPC backed by partial covering indexes — `20260420000000_blast_radius_indexes.sql`), a 14-day severity KPI strip (`/v1/admin/reports/severity-stats`), a `StatusStepper` primitive that turns the four-state lifecycle into a visible progression, and group-by-fingerprint collapse with deep-linkable `?expand=\u003cid\u003e` state. Report Detail now opens with a `ScreenshotHero` and a `PdcaReceiptStrip` that pre-fetches `llm_invocations` + `fix_attempts` + `classification_evaluations` in parallel. Per-page polish: Projects shows a `PdcaBottleneckPill` per project (Plan / Do / Check / Act with deep-link), Billing shows a \"on pace to hit limit in N days\" forecast band, Audit gets an `actor_type` filter (human / agent / system), Compliance gets a print-styled \"Export PDF\" button, Storage shows per-project usage, Query gets pinned-question Saved sidebar (`is_saved` column on `nl_query_history` — `20260420000100_nl_query_saved.sql`) plus an SQL hints card. The dashboard `FirstReportHero` promotes \"Send a test report\" the moment the SDK is installed but no report has landed. The shared `EmptyState` primitive is now NN/G-compliant (status line + learning cue + optional bullet hints + direct-path action). Full handover: [`docs/HANDOVER-wave-i-2026-04-20.md`](./docs/HANDOVER-wave-i-2026-04-20.md).\n\n**Wave J real LLM cost (Apr 2026):** promotes LLM dollars from a frontend-side estimate to a first-class column. New `llm_invocations.cost_usd numeric(12, 6)` column (`20260420000200_llm_cost_usd.sql`) is written at insert time by `logLlmInvocation`, backfilled for every historical row, and indexed via a partial covering index for fast monthly rollups. Pricing is centralised in `packages/server/supabase/functions/_shared/pricing.ts` so the SQL backfill, telemetry write, and Health fallback all read the same table. Three surfaces consume it: Health per-function reads the column directly, Billing shows a per-project `LLM $X.XX` chip alongside the report-quota usage bar (real COGS this billing month), Prompt Lab's diff modal shows `Avg $ / eval` next to `Avg judge score` so ops can see \"did the candidate get more accurate AND cheaper?\" without leaving the diff. Also patches two production Sentry issues caught during Wave I rollout: a `toFixed` crash on `/health` (deploy-skew defensive renders) and HMR-noise leakage from React Fast Refresh (`beforeSend` filter in `lib/sentry.ts`). Full handover: [`docs/HANDOVER-wave-j-2026-04-20.md`](./docs/HANDOVER-wave-j-2026-04-20.md).\n\n**Wave K admin polish (Apr 2026):** UX + microinteraction sweep across all 24 admin routes. Pre-setup dashboard now hides the full KPI grid behind a \"Show full dashboard\" reveal so brand-new admins see only `SetupChecklist + HeroIntro` until they've sent their first report. `PageHelp` panels default-open only on the first ever visit (single global `mushi:visited` flag), then default-closed for returning users — first-day learners get the explainer, daily users get the lean header. Outcome copy replaces jargon: \"PDCA cockpit\" → \"Loop status — Plan, Do, Check, Act\"; \"PDCA loop — healthy\" → \"Triage → Fix → Verify — healthy\". `PageHeader` accepts a `projectScope` prop and `Reports / Fixes / Judge / Graph / Health / Compliance` thread the active project name through the header so the admin sees `Reports · glot-it` at a glance. Eight silent / broken UI surfaces fixed (DSAR snake_case contract + `project_id`, Reports KPI strip silent zeros → inline retry, Query / Billing tiny-text errors → `ErrorAlert` with retry, comment mutation toasts, triage bar `\u003cBtn loading\u003e` adoption, Reports empty contradiction, `Conf.` → `\u003cabbr title=\"Confidence\"\u003e`). Loading states are now layout-shaped: `DashboardSkeleton`, `TableSkeleton`, `DetailSkeleton`, `PanelSkeleton` replaced 22 page-level `\u003cLoading /\u003e` spinners so first paint matches the loaded layout. Microinteractions across the app: toasts animate in / out (180 / 140ms), modal scrims fade-in and panels scale-in, Settings page has a sliding underline tab indicator, and a new `\u003cResultChip\u003e` primitive gives every Test / Run / Trigger button a persistent `✓ Connection OK · 2s ago` receipt. Token aliases added in `index.css` so stale class names (`bg-warning-subtle`, `text-fg-primary`, `border-border`) keep rendering correctly without a grep-and-replace risk; zero raw `bg-black / bg-white / text-black / text-white` left in `apps/admin/src`. Full handover: [`docs/HANDOVER-wave-k-2026-04-20.md`](./docs/HANDOVER-wave-k-2026-04-20.md).\n\n### Honest status — what works, what's still partial\n\n| Area                 | Working                                                                                             | Still partial                                                  |\n| -------------------- | --------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- |\n| Classification       | Haiku fast-filter, Sonnet deep, **vision air-gap closed + contract-tested**, structured outputs, prompt-cached prompts, **`pg_cron` self-healing every 5 min** | —                                                              |\n| Judge / self-improve | Sonnet judge with **OpenAI fallback** wired                                                          | Auto-promotion of fine-tuning candidates to a training run     |\n| Fix orchestrator     | Single + multi-repo, `validateResult` gating, GitHub PR creation, **MCP JSON-RPC 2.0** client       | First-party Claude Code / Codex adapters wait on vendor APIs   |\n| Sandbox              | Provider abstraction; `local-noop` (tests) + `e2b` / `modal` / `cloudflare` (prod-ready, deny-by-default egress, audit-event stream) | —                                                              |\n| Verify               | Screenshot diff via Playwright + pixelmatch                                                          | Step interpreter is proof-of-concept (nav + click only)        |\n| Enterprise           | Plugin marketplace + HMAC, audit ingest, region pinning, retention CRUD, Stripe metering + `/billing` UI + invoice list, **SAML SSO via Supabase Auth Admin API** (ACS / Entity ID surfaced for IdP setup), routing-destination CRUD with masked secrets | OIDC SSO writes config but waits on GoTrue admin endpoints     |\n| Streaming            | Fix-dispatch SSE (CVE-2026-29085-safe sanitization)                                                  | Classification reasoning still arrives whole, not token-stream |\n\nThe orchestrator **refuses to run `local-noop` in production** unless you explicitly set `MUSHI_ALLOW_LOCAL_SANDBOX=1`. Pick `e2b` (or implement the `SandboxProvider` interface yourself) before exposing autofix to production traffic.\n\n---\n\n## Architecture\n\n```mermaid\nflowchart LR\n    subgraph App[\"Your app\"]\n        SDK[\"@mushi-mushi/{react,vue,svelte,angular,react-native,web}\u003cbr/\u003eShadow-DOM widget · screenshot · console · network · offline queue\"]\n    end\n\n    subgraph Edge[\"Supabase Edge Functions (Deno + Hono)\"]\n        API[\"api\"]\n        FF[\"fast-filter\u003cbr/\u003eHaiku\"]\n        CR[\"classify-report\u003cbr/\u003eSonnet + vision + RAG\"]\n        JB[\"judge-batch\u003cbr/\u003eSonnet (OpenAI fallback)\"]\n        IR[\"intelligence-report\"]\n        ORCH[\"fix-dispatch\u003cbr/\u003eSSE\"]\n    end\n\n    subgraph DB[\"Postgres + pgvector\"]\n        REP[\"reports\"]\n        KG[\"knowledge graph\"]\n        EVAL[\"judge_evals\"]\n        FIX[\"fix_attempts\u003cbr/\u003e+ coordinations\"]\n    end\n\n    subgraph Agents[\"@mushi-mushi/agents\"]\n        MO[\"MCP client (JSON-RPC 2.0)\"]\n        SBX[\"Sandbox: local-noop / e2b\"]\n        GH[\"GitHub PR creator\"]\n    end\n\n    SDK --\u003e|HTTPS| API\n    API --\u003e FF --\u003e CR\n    CR --\u003e KG\n    CR --\u003e REP\n    KG --\u003e IR\n    REP --\u003e JB --\u003e EVAL\n    REP --\u003e ORCH --\u003e Agents\n    Agents --\u003e GH\n```\n\nSee [`apps/docs/content/concepts/architecture.mdx`](./apps/docs/content/concepts/architecture.mdx) for the full pipeline.\n\n---\n\n## Packages\n\n\u003e Most developers only install **one** SDK package — `npx mushi-mushi` picks the right one for you and pulls in `core` and `web` automatically.\n\n| Install                            | Framework               | What you get                                                                              |\n| ---------------------------------- | ----------------------- | ----------------------------------------------------------------------------------------- |\n| `npx mushi-mushi`                  | **Any** (auto-detects)  | One-command wizard — installs the right SDK, writes env vars, prints the snippet          |\n| `npm i @mushi-mushi/react`         | React / Next.js         | `\u003cMushiProvider\u003e`, `useMushi()`, `\u003cMushiErrorBoundary\u003e` — drop-in for any React app       |\n| `npm i @mushi-mushi/vue`           | Vue 3 / Nuxt            | `MushiPlugin`, `useMushi()` composable, error handler (pair with `web` for the widget UI) |\n| `npm i @mushi-mushi/svelte`        | Svelte / SvelteKit      | `initMushi()`, SvelteKit error hook (pair with `web` for the widget UI)                   |\n| `npm i @mushi-mushi/angular`       | Angular 17+             | `provideMushi()`, `MushiService`, error handler (pair with `web` for the widget UI)       |\n| `npm i @mushi-mushi/react-native`  | React Native / Expo     | Shake-to-report, bottom-sheet widget, navigation capture, offline queue                   |\n| `npm i @mushi-mushi/capacitor`     | Capacitor / Ionic       | iOS + Android via Capacitor — shake-to-report, screenshot, offline queue                  |\n| `npm i @mushi-mushi/web`           | Vanilla / any framework | Framework-agnostic SDK — Shadow-DOM widget, screenshot, console + network capture         |\n\n[![mushi-mushi](https://img.shields.io/npm/v/mushi-mushi?label=mushi-mushi%20(launcher)\u0026color=cb3837)](https://www.npmjs.com/package/mushi-mushi)\n[![@mushi-mushi/react](https://img.shields.io/npm/v/@mushi-mushi/react?label=react\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/react)\n[![@mushi-mushi/vue](https://img.shields.io/npm/v/@mushi-mushi/vue?label=vue\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/vue)\n[![@mushi-mushi/svelte](https://img.shields.io/npm/v/@mushi-mushi/svelte?label=svelte\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/svelte)\n[![@mushi-mushi/angular](https://img.shields.io/npm/v/@mushi-mushi/angular?label=angular\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/angular)\n[![@mushi-mushi/react-native](https://img.shields.io/npm/v/@mushi-mushi/react-native?label=react-native\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/react-native)\n[![@mushi-mushi/capacitor](https://img.shields.io/npm/v/@mushi-mushi/capacitor?label=capacitor\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/capacitor)\n[![@mushi-mushi/web](https://img.shields.io/npm/v/@mushi-mushi/web?label=web\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/web)\n[![@mushi-mushi/cli](https://img.shields.io/npm/v/@mushi-mushi/cli?label=cli\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/cli)\n[![@mushi-mushi/mcp](https://img.shields.io/npm/v/@mushi-mushi/mcp?label=mcp\u0026color=cb3837)](https://www.npmjs.com/package/@mushi-mushi/mcp)\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eInternal \u0026 native packages\u003c/b\u003e\u003c/summary\u003e\n\n| Package                               | Purpose                                                                                                                |\n| ------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- |\n| [`@mushi-mushi/core`](./packages/core) | Shared engine — types, API client, PII scrubber, offline queue, rate limiter, structured logger. Auto-installed.       |\n| [`@mushi-mushi/cli`](./packages/cli)   | CLI for project setup, report listing, triage. `npm i -g @mushi-mushi/cli`                                              |\n| [`@mushi-mushi/mcp`](./packages/mcp)   | MCP server — lets Cursor / Copilot / Claude read and triage bug reports                                                 |\n| [`packages/ios`](./packages/ios)       | Native iOS SDK (Swift Package Manager) — early dev                                                                      |\n| [`packages/android`](./packages/android) | Native Android SDK (Maven `dev.mushimushi:mushi-android`) — early dev                                                  |\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eBackend packages\u003c/b\u003e (BSL 1.1 → Apache 2.0 in 2029)\u003c/summary\u003e\n\n| Package                | Purpose                                                                                                                                              |\n| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `@mushi-mushi/server`  | Edge functions — classification pipeline, knowledge graph, fix dispatch + SSE, RAG indexer, vision air-gap, judge with OpenAI fallback, plugin runtime |\n| `@mushi-mushi/agents`  | Agentic fix orchestrator — `validateResult` gating, GitHub PR creation, sandbox abstraction, MCP JSON-RPC 2.0 client                                  |\n| `@mushi-mushi/verify`  | Playwright fix verification — screenshot visual diff (proof-of-concept step interpreter)                                                              |\n\n\u003c/details\u003e\n\n---\n\n## Connecting to a backend\n\n### A. Hosted (zero-config)\n\n1. Sign up at **[kensaur.us/mushi-mushi](https://kensaur.us/mushi-mushi/)**\n2. Create a project → copy your `projectId` and `apiKey`\n3. Drop the SDK into your app\n\n### B. Self-hosted\n\n```bash\ncd deploy\ncp .env.example .env   # ANTHROPIC_API_KEY, Supabase creds\ndocker compose up -d\n```\n\nOr via Supabase CLI directly — see [SELF_HOSTED.md](./SELF_HOSTED.md). A Helm chart lives at `deploy/helm/` (incomplete — missing migrations ConfigMap).\n\n\u003e Internal edge functions (`judge-batch`, `intelligence-report`, `generate-synthetic`) authenticate via `SUPABASE_SERVICE_ROLE_KEY`. Never expose them with `--no-verify-jwt` in production. Only the public `api` function should face the internet.\n\n---\n\n## Monitoring \u0026 privacy (this repo's deployment)\n\nThe hosted instance reports to two Sentry projects under the [`sakuramoto`](https://sakuramoto.sentry.io) org:\n\n| Project              | What it covers                                                                                                                              | DSN source                                  |\n| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------- |\n| `mushi-mushi-admin`  | Admin console: unhandled errors, React error boundaries, perf traces (10 % sample), errors-only Session Replay (`replaysOnErrorSampleRate: 1.0`, masked text + media) | `VITE_SENTRY_DSN` baked into the build      |\n| `mushi-mushi-server` | All eight edge functions: unhandled exceptions + every `log.error()`/`log.fatal()` forwarded via `_shared/sentry.ts`                        | `SENTRY_DSN_SERVER` Supabase secret         |\n\nPrivacy \u0026 safety:\n\n- `sendDefaultPii: false` on both — no IPs, cookies, or request bodies attached automatically.\n- Token-like query params scrubbed in `beforeSend`. `Authorization`, `Cookie`, `*-api-key` headers redacted server-side.\n- Sourcemaps uploaded by `@sentry/vite-plugin` during `pnpm build` and **deleted from `dist/` before the S3 sync** — the public bucket never serves them.\n- Sentry data scrubbing strips token prefixes (`mushi_*`, `sntryu_*`, JWTs starting with `eyJ`, `ghp_*`, `npm_*`) on top of SDK-side redaction.\n\n\u003e **For SDK consumers and forks:** the published packages **do not initialize Sentry**. The bridge at [`packages/web/src/sentry.ts`](packages/web/src/sentry.ts) only *reads context from your existing Sentry instance* — it never sends data on its own. Self-hosted forks can leave the DSNs unset and the SDKs no-op cleanly.\n\n## Payment \u0026 support operations\n\nThe hosted product wires three feedback loops so the operator hears from paying customers fast:\n\n| Channel                              | Trigger                                                                                                                                                          | Where it shows up                                                              |\n| ------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------ |\n| **Stripe webhooks → operator push**  | `checkout.session.completed`, `invoice.payment_failed`, `customer.subscription.deleted`, `cancel_at_period_end → true`, `invoice.payment_succeeded` (recovery only) | Slack and/or Discord via `OPERATOR_SLACK_WEBHOOK_URL` / `OPERATOR_DISCORD_WEBHOOK_URL` |\n| **Stripe Dashboard email digests**   | Same events natively, plus dispute / refund flows                                                                                                                 | The Stripe Dashboard email recipient list (configured in the Dashboard UI)    |\n| **In-app support inbox**             | Paid (or free) customer submits the BillingPage \"Need help?\" form                                                                                                | `support_tickets` table + operator push + audit log + reply to `SUPPORT_EMAIL` |\n\nHow each piece works:\n\n- **Operator push** (`packages/server/supabase/functions/_shared/operator-notify.ts`): a single helper that knows how to render Slack Block Kit *and* Discord rich embeds. Severity drives colour; `urgent` pings `@here` on Discord. Failures are captured to Sentry but never block the webhook from 200-ing back to Stripe.\n- **In-app support form** (`/v1/support/contact`): JWT-gated, rate-limited to 5 tickets/hour/user, captures plan tier at submit time so paid tickets jump the queue. Customer sees status updates inline on `/billing`. PII (passwords, API keys) explicitly called out as off-limits in the form copy.\n- **Centralised support address** (`SUPPORT_EMAIL` env var, defaults to `support@mushimushi.dev`): used in the Checkout `custom_text`, the BillingPage \"Need help?\" mailto, and the rate-limit error message.\n\nTo enable the operator push for a self-hosted instance:\n\n```bash\n# 1. Create a Slack incoming webhook (api.slack.com/messaging/webhooks)\n#    OR a Discord channel webhook (server settings → integrations → webhooks).\n# 2. Push the secret to Supabase:\nsupabase secrets set OPERATOR_SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...\n# or\nsupabase secrets set OPERATOR_DISCORD_WEBHOOK_URL=https://discord.com/api/webhooks/...\n# 3. Optionally override the support address (defaults to support@mushimushi.dev):\nsupabase secrets set SUPPORT_EMAIL=ops@yourdomain.com\n# 4. Redeploy the api + stripe-webhooks functions:\nsupabase functions deploy api stripe-webhooks\n```\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eRepo structure \u0026 dev commands\u003c/b\u003e\u003c/summary\u003e\n\n#### Development\n\n```bash\ngit clone https://github.com/kensaurus/mushi-mushi.git\ncd mushi-mushi\npnpm install\npnpm build\n```\n\nRequires Node.js ≥ 22 and pnpm ≥ 10.\n\n| Command            |                                                              |\n| ------------------ | ------------------------------------------------------------ |\n| `pnpm dev`         | Run all dev servers (admin on `:6464`, docs, cloud)          |\n| `pnpm build`       | Build all packages                                           |\n| `pnpm test`        | Vitest                                                       |\n| `pnpm typecheck`   | TypeScript checks                                            |\n| `pnpm lint`        | Lint                                                         |\n| `pnpm format`      | Prettier                                                     |\n| `pnpm changeset`   | Create a changeset                                           |\n| `pnpm release`     | Build + publish to npm                                       |\n\n#### Admin console (zero-config)\n\n```bash\ncd apps/admin\npnpm dev    # → http://localhost:6464 — auto-connects to Mushi Cloud\n```\n\nTo self-host with your own Supabase project, copy `apps/admin/.env.example` and fill in your URL + anon key.\n\n#### Backend / edge functions\n\n```bash\ncp .env.example .env   # Supabase + LLM provider keys\ncd packages/server/supabase\nnpx supabase db push\nnpx supabase functions deploy api --no-verify-jwt\n```\n\n#### Repo layout\n\n```\npackages/\n  core, web, react, vue, svelte, angular, react-native   # SDKs (MIT)\n  ios, android                                            # Native SDKs (early dev)\n  cli, mcp                                                # Tooling\n  server, agents, verify                                  # Backend (BSL 1.1)\n  plugin-{sdk,zapier,linear,pagerduty}                    # Plugin marketplace\napps/\n  admin    # React 19 + Tailwind 4 + Vite 8 (dark-only by design)\n  docs     # Nextra v4 documentation site\n  cloud    # Next.js 15 marketing landing + Stripe billing\nexamples/\n  react-demo\ndeploy/    # Docker Compose + Helm chart\ntooling/   # Shared ESLint + TypeScript configs\n```\n\n\u003c/details\u003e\n\n---\n\n## Contributing\n\nIssues and PRs welcome. To get started: `pnpm install \u0026\u0026 pnpm dev`. See individual package READMEs for package-specific setup, and [HANDOVER.md](./HANDOVER.md) for the current state of play.\n\n## License\n\n- **SDK packages** (core, web, react, vue, svelte, angular, react-native, cli, mcp): [MIT](./LICENSE)\n- **Server, agents, verify**: [BSL 1.1](./packages/server/LICENSE) — converts to Apache 2.0 on April 15, 2029\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkensaurus%2Fmushi-mushi","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkensaurus%2Fmushi-mushi","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkensaurus%2Fmushi-mushi/lists"}