Settings
System Settings
Account
Profile
Dome
dh@gopaxx.de
PAXX_AUTH_MODE=google plus a login OAuth client; see docs/project-brain/AUTH.md. YELLOW applies to switching it on.Test as role
Dev-mode only: masquerades the single owner account as a lower role to test RBAC-gated UI. Never a path to more privilege than owner already has.
13 available · 1 connected · 7 need setup
Integrations
Carrier network
carriers · shipments
Setup required
Mock-only. `carriers` is an aggregation layer, not one provider: a real implementation is one adapter per carrier (DHL, DPD, GLS, Dachser) behind a single connector, selected by PAXX_CARRIER_ADAPTERS with one credential each. Cost realistically arrives from invoice feeds rather than tracking APIs, so the two capabilities above are likely to land separately.
Google Workspace (primary)
inbox-summary · important-emails · calendar · oauth-multi-account
Setup required
In console.cloud.google.com create (or pick) a project, then enable both the Gmail API and the Google Calendar API under APIs & Services → Library.
callback URL to register: https://crm.gopaxx.de/api/integrations/google/callback
Google Workspace (second)
inbox-summary · important-emails · calendar · oauth-multi-account
Setup required
In console.cloud.google.com create (or pick) a project, then enable both the Gmail API and the Google Calendar API under APIs & Services → Library.
callback URL to register: https://crm.gopaxx.de/api/integrations/google/callback
PAXX P1
customers · shipments · returns · inventory · warehouse · goods-flow · tickets · sla
Setup required
Mock-only, and blocked a step earlier than the others: P1 publishes no API surface for shipments, warehouse topology or tickets today. BUSINESS_OPERATIONS.md §6 is written as the specification for that work. Nothing an administrator can paste shortens this.
Shopify
orders
Setup required
Mock-only: `business/mock/shopify.ts` serves fixtures. Beyond writing the client, this provider needs a credential *per storefront* — one tenant per shop — so it becomes a multi-credential provider like Google's two account slots rather than a single token field. That design decision is why no operator form is offered yet.
Spotify
now-playing · transport · volume · devices · queue
Setup required
developer.spotify.com/dashboard → Create app. Add exactly the redirect URI shown here under Redirect URIs — Spotify matches it exactly, and a mismatch returns only “INVALID_CLIENT: Invalid redirect URI” with no hint about which value was sent.
callback URL to register: https://crm.gopaxx.de/api/integrations/spotify/callback
Xentral
customers · orders · inventory · goods-flow · sla · commercial
Setup required
This provider is mock-only: `packages/connectors/src/business/mock/xentral.ts` serves deterministic fixtures and there is no code that talks to Xentral. No value an administrator could paste changes that, which is why this step offers no form. The reads a real implementation must satisfy are specified in docs/project-brain/BUSINESS_OPERATIONS.md §6; it would then read XENTRAL_API_URL and XENTRAL_API_TOKEN. Until it exists, every figure sourced here carries a MOCK badge.
ClickUp
tasks · deadlines · workspaces
GitHub
list-repositories · pull-requests · branches · import-request
Obsidian
knowledge-search · recent-notes · pinned-notes · quick-capture · daily-notes
Paperclip
agent-roster · company · projects
Weather
current-conditions · forecast · favorites
Granted
- readRead forecastsPublic forecast data for the places you pick.
PAXX
projects · approvals
Setup required
Google Workspace
Google OAuth is not configured on this server
The integration is fully implemented — connecting an account needs credentials that only an administrator can create, and a server restart to pick them up. Each step below is one-time. Secrets belong in .env.local, which is gitignored; never commit them.
- 1
A Google Cloud project with the Gmail and Calendar APIs enabled
In console.cloud.google.com, create (or pick) a project, then enable both the Gmail API and the Google Calendar API under APIs & Services → Library.
- 2
OAuth consent screen configured
Google Auth Platform → Audience and → Data access (formerly "APIs & Services → OAuth consent screen"). "Internal" is enough for a Workspace domain. An External app must stay in Testing with each Google account added under Test users — note that Testing authorizations expire 7 days after consent, taking the refresh token with them, so Internal is strongly preferred for a daily-use tool. Add the six read-only scopes listed below. gmail.metadata is a RESTRICTED scope (not merely sensitive): an External app in Production would need Google verification plus a recurring third-party CASA security assessment. Testing mode avoids both.
- 3
An OAuth 2.0 Client ID of type "Web application"
Google Auth Platform → Clients → Create client (formerly "APIs & Services → Credentials"). Add exactly this Authorized redirect URI — Google matches it byte-for-byte, including scheme, case and trailing slash: https://crm.gopaxx.de/api/integrations/google/callback
- 4
Client ID available to the server
GOOGLE_OAUTH_CLIENT_IDSet GOOGLE_OAUTH_CLIENT_ID in the server environment (.env.local — never committed).
- 5
Client secret available to the server
GOOGLE_OAUTH_CLIENT_SECRETSet GOOGLE_OAUTH_CLIENT_SECRET in the server environment. It is read server-side only and is never sent to the browser.
- ✓
Token encryption key
PAXX_TOKEN_ENCRYPTION_KEYSet PAXX_TOKEN_ENCRYPTION_KEY to a 32-byte key (openssl rand -base64 32). Refresh tokens are encrypted with AES-256-GCM before they reach the database; without this key PAXX refuses to store them rather than storing them in plaintext.
- ✓
Public base URL (only if PAXX is not on http://localhost:3000)
PAXX_PUBLIC_URLSet PAXX_PUBLIC_URL (e.g. https://command.gopaxx.de) so the redirect URI PAXX generates matches the one registered with Google. Alternatively set GOOGLE_OAUTH_REDIRECT_URI directly.
Authorized redirect URI — must match exactly
https://crm.gopaxx.de/api/integrations/google/callbackStill missing: GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET
Permissions PAXX will request — all read-only
- Sign-in identityread
Identifies which Google account granted access, so the two account slots can be told apart.
- Email addressread
Labels the connected account in Settings and tags every mail/calendar item with its source account.
- Name and profile pictureread
Shows a recognisable account identity instead of a bare email address.
- Gmail headers and labels — no message bodiesread
Reads sender, subject, timestamp, labels and thread structure. Google will not return message bodies or attachments under this scope.
- List of your calendarsread
Lets PAXX show which calendar an event came from when several are connected.
- Calendar eventsread
Reads today's schedule, upcoming events, attendees and meeting links.
Until OAuth is configured, Gmail and Calendar panels across the Command Center are served by the mock connectors and carry a MOCK provenance badge. No Google account is contacted and no credential exists.
Primary Google account
No account connected to this slot. Two Google accounts are supported — connect them one at a time; Google's account chooser is shown each time, so the second connection can use a different account.
Picking an account that already occupies the other slot moves it here and leaves that slot empty — one Google identity can only be connected once.
Second Google account
No account connected to this slot. Two Google accounts are supported — connect them one at a time; Google's account chooser is shown each time, so the second connection can use a different account.
Picking an account that already occupies the other slot moves it here and leaves that slot empty — one Google identity can only be connected once.
Security boundary
What PAXX can and cannot do with these accounts
GREEN Read mail metadata and calendar events. Active. Headers, labels, thread structure, events, attendees. No message bodies — the gmail.metadata scope does not return them.
YELLOW Connect, reconnect, disconnect, toggle a capability. Requires the integrations:configure capability (admin or owner) and is recorded in the audit log with the scopes granted. Google's own consent screen is a mandatory human approval step inside the flow, which is why this is YELLOW rather than RED despite storing a credential.
RED Send email, create a draft in Gmail, or modify a calendar. Not implemented and not reachable: no send/compose/modify scope is requested (a unit test fails if one is added to the scope table), and the send helper throws unconditionally. Enabling it would be a deliberate, reviewable change requiring per-message human approval.
Refresh tokens are encrypted with AES-256-GCM before they reach the database and live in a separate table from the account record, so listing accounts never reads ciphertext. No token is ever sent to the browser. Disconnecting revokes the grant at Google first, then deletes the local credential.
Preferences
Command Center
0 recent
Command history
No commands run yet.
Policy
Security classes
RBAC matrix
Role capabilities
| Capability | owner | admin | member | viewer |
|---|---|---|---|---|
| Approve YELLOW actions | ✓ | ✓ | ✓ | — |
| Approve RED actions | ✓ | ✓ | — | — |
| Configure integrations | ✓ | ✓ | — | — |
| Manage settings | ✓ | ✓ | — | — |
| View audit log | ✓ | ✓ | ✓ | — |
| Manage users | ✓ | — | — | — |
0 shown
Recent audit events
No audited actions yet.
Obsidian · Knowledge Gateway
Knowledge access
Backend
mock
Mode
MOCK
Health
healthy2ms
in-memory fixture vault
No vault is connected — this is the mock gateway. Notes you see are fixtures, and captures are stored in the Command Center instead of your vault.
Connect ObsidianWho may touch the vault
Grants
Your grant
Command Center (owner)
ui:ownerread+write whole vault
Agent grants5
Chief of Staff agent
agent:chief-of-staffread Operations/read Product/read+write Daily/Research agent
agent:researchread+write Research/read Product/Operations agent
agent:operationsread+write Operations/Sales agent
agent:salesread Sales/Marketing agent
agent:marketingread Marketing/
Agents get narrow grants, never the whole vault. The Knowledge Gateway authorizes every path against the named grant and refuses anything outside it — a refusal, not a quietly empty result.
3 favorites
Weather locations
- 1BerlinGermany
- 2LisbonPortugal
- 3ZurichSwitzerland
AI
Command resolution
The ⌘K command palette resolves input with simple pattern matching today (command-engine.ts), not a real LLM call. Every command still gets recorded to history and the audit log, so swapping in a real AI command service later (ROADMAP.md Phase 4) won't change this UI — only what answers the question.
8 roster
Engineering agents
- CTOrunning
- Principal Architectwaiting
- Backendrunning
- Frontendrunning
- QAblocked
- Securityidle
- Code Reviewrunning
- DevOpsidle
Database
Persistence
PostgreSQL via Drizzle ORM. Dev/local runs against a file-backed PGlite store by default (no server needed); set DATABASE_URL to point at a real Postgres instance instead — see RUNBOOK.md. User-authored state (approvals, knowledge captures, weather favorites, settings, command history, audit log) persists across restarts either way.
Live
System health
- Command Center8ms
- Database4ms
- Worker12ms
- OmniRoute55ms
- Obsidian Sync20ms
- Paperclip42ms
- GitHub110ms
- Google Workspace (primary)180ms
- Google Workspace (second)143ms
- ClickUp95ms
- PAXX30ms
- Obsidian2ms
- Spotify60ms
- Weather12ms
- Xentral42ms
- Shopify38ms
- PAXX P127ms
- Carrier network61ms