{"_id":"@5dive/telegram-pi-bridge","name":"@5dive/telegram-pi-bridge","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.1":{"name":"@5dive/telegram-pi-bridge","version":"0.1.1","description":"Telegram channel for the pi CLI (earendil-works/pi-coding-agent) — a long-running relay that hosts pi in-process via its SDK, with pairing/access control, streaming edit-in-place, and a sandboxed-by-default permission gate (bash/write/edit are tapped once","license":"Apache-2.0","type":"module","author":{"name":"5dive","email":"support@5dive.com"},"homepage":"https://github.com/5dive-ai/5dive-plugins/tree/main/plugins/telegram-pi","repository":{"type":"git","url":"git+https://github.com/5dive-ai/5dive-plugins.git","directory":"plugins/telegram-pi"},"keywords":["telegram","pi","pi-coding-agent","coding-agent","relay","bridge","sandbox","permission-gating"],"bin":{"telegram-pi-bridge":"server.ts"},"scripts":{"start":"bun server.ts"},"dependencies":{"grammy":"^1.21.0","@earendil-works/pi-coding-agent":"^0.80.6"},"_id":"@5dive/telegram-pi-bridge@0.1.1","bugs":{"url":"https://github.com/5dive-ai/5dive-plugins/issues"},"_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-e/7fMEYX3WFbv4flTQjZJKlR7C2N5xJzRD0Bi0/oazbNddRTA+eT4GYZUvbTNBTcqOrQN6eDwvcoPW22N1vcGQ==","shasum":"005f1c8f0f74505f4f8f2418c6ec4d64ce1ca98b","tarball":"https://registry.npmjs.org/@5dive/telegram-pi-bridge/-/telegram-pi-bridge-0.1.1.tgz","fileCount":5,"unpackedSize":74981,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIE2uDuOL8bv67xubnsjqUp1IRGspDASmluCvUYweLRnKAiByF00mhMcj9Tf/OMsnFnc6KbEPZdPx8iq3nl9eDJtxhw=="}]},"_npmUser":{"name":"lodar","email":"info@5dive.com"},"directories":{},"maintainers":[{"name":"lodar","email":"info@5dive.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/telegram-pi-bridge_0.1.1_1784248746971_0.03703268413666927"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-17T00:39:06.792Z","0.1.1":"2026-07-17T00:39:07.123Z","modified":"2026-07-17T00:39:07.293Z"},"maintainers":[{"name":"lodar","email":"info@5dive.com"}],"description":"Telegram channel for the pi CLI (earendil-works/pi-coding-agent) — a long-running relay that hosts pi in-process via its SDK, with pairing/access control, streaming edit-in-place, and a sandboxed-by-default permission gate (bash/write/edit are tapped once","homepage":"https://github.com/5dive-ai/5dive-plugins/tree/main/plugins/telegram-pi","keywords":["telegram","pi","pi-coding-agent","coding-agent","relay","bridge","sandbox","permission-gating"],"repository":{"type":"git","url":"git+https://github.com/5dive-ai/5dive-plugins.git","directory":"plugins/telegram-pi"},"author":{"name":"5dive","email":"support@5dive.com"},"bugs":{"url":"https://github.com/5dive-ai/5dive-plugins/issues"},"license":"Apache-2.0","readme":"# telegram-pi\n\nA Telegram channel for the [pi](https://github.com/earendil-works/pi) CLI\n(`@earendil-works/pi-coding-agent`).\n\n**This is not an MCP fork, and not an HTTP relay either.** pi has no MCP/hooks\nconfig surface (DIVE-1198 spike) — it is extension-based and ships a first-class\nin-process SDK. So this plugin is a **long-running relay that HOSTS pi directly**\nvia `createAgentSession()`, a fourth run-model:\n\n```\nTelegram inbound ─▶ session.prompt(text) ─▶ text_delta stream ─▶ Telegram (edit in place)\npi tool_call hook (bash/write/edit) ─▶ 🔐 once/always/reject buttons ─▶ { block:true } on reject\n```\n\n## Sandboxed by default\n\npi ships **no permission system of its own** — open filesystem/process/network by\ndefault (DIVE-1198). So this bridge is the sandbox boundary: every **mutating**\ntool (`bash`, `write`, `edit`) is gated behind a Telegram **once / always /\nreject** tap, implemented with pi's extension `tool_call` block-hook (which can\nreturn `{ block: true }`). Read-only tools (`read`, `ls`, `grep`, `find`) run\nsilently. A never-answered gate blocks after 10 minutes; a Telegram send-failure\nfails **closed**. This is why the bridge hosts pi via the SDK rather than letting\npi consume our Telegram MCP server — an MCP server can only gate MCP tools, never\npi's own internal tools.\n\n## Run\n\n```sh\n# token lives in ~/.pi/channels/telegram/.env\n#   TELEGRAM_BOT_TOKEN=123456789:AAH...\n# the provider key is read from the environment (pi's default auth), e.g.\n#   ANTHROPIC_API_KEY=sk-ant-...\n# the model comes from ~/.pi/agent/settings.json {defaultProvider, defaultModel}\nbun start          # = bun install + bun server.ts\nbun pair.ts        # allowlist your Telegram user id (run while the relay is DOWN)\n```\n\n## Commands\n\n`/help /status /stop /restart /agents /tasks /task /org /model /ping /start` —\nsame menu as the sibling forks. `/stop` aborts the current turn\n(`session.abort()`); `/model <provider>/<modelId>` writes the pin to\n`~/.pi/agent/settings.json` and rebuilds your chat's session so it applies to\nyour next message; `/status` shows the model, active chats, and pi version.\n\n## v1 limitations\n\n- Per-chat pi sessions are held **in memory** for the relay's lifetime; a relay\n  restart starts fresh conversations. pi still persists each turn to\n  `~/.pi/agent/sessions/`, so history isn't lost — it's just not auto-resumed\n  into the chat yet.\n- Image/document inbound is forwarded as a caption note, not yet fed to the model\n  as vision input.\n\n## Notes\n\n- One continuous pi `AgentSession` per Telegram chat, hosted in-process.\n- Access control / pairing / streaming edit-in-place / inline-button transport\n  are reused verbatim from the telegram-opencode fork — the divergence is only\n  the engine (in-process pi SDK) and the permission gate (pi extension hook).\n","readmeFilename":"README.md","_rev":"1-215b834a00ff5487b16038d1484131d7"}