feat(connect): a connection carries the name of the account it reaches (#127)
## Summary
Listing accounts could only name them by provider, so a customer holding
two Cloudflare accounts read "Cloudflare" twice and had to open one to
tell them apart. A provider now names the account when it issues a
credential, DomainKit stores that name at connect time, and every
listing of accounts carries it.
## API
```ts
const listing = yield* Connect.zones()
for (const account of listing.connections) {
// ↓ "Acme Inc" when the provider named the account, null when it named none
render(account.label ?? providerName(account.provider), account.status)
}
```
The same field crosses the wire on `GET /zones`, so
`Transport.Zones["connections"][number]` and `@domainkit/react`'s
`Connect.Account` read it without a second call:
```tsx
const accounts = Connect.useAccounts()
accounts.connections.map((account) => (
<Button key={account.connectionId} onClick={() => accounts.reconnect({ ... })}>
{messages.reconnectAccount(account.label ?? named(account.provider))}
</Button>
))
```
A provider fills it from whatever names an account for it:
```ts
// packages/domainkit/src/Cloudflare.ts — one account across the zones the credential sees
const discovered = yield* discoverAccount(raw)
return {
secret: token,
context: { accountId: discovered?.id ?? null, tokenKind: verified.kind },
label: discovered?.name ?? null, // zone.account.name; null when the token spans accounts
expiresAt: verified.expiresAt,
}
```
## Changes
| Surface | Change |
| ----------------------------- |
------------------------------------------------------------------------------------------
|
| `Provider.IssuedCredential` | Optional `label`; a provider that
returns none keeps compiling |
| `Storage.Authorization` | Required nullable `label`, written by
`Connect` at connect and reconnect |
| `Connect.zones` / wire `Zones` | Each connection carries `label` |
| `Server.Connected` | Prefers the account label over the provider name
when the start attached no domain |
| Cloudflare | Names the account from its zones; a token pinned with
`accountId` is named from that account |
| `Testing.provider` | `accountLabel` option, default none |
| `@domainkit/capsuledb` | Nullable `label` column on
`domainkit_authorizations`; earlier rows read as null |
## Review notes
- Additive for provider authors and for the wire.
`Storage.Authorization` now requires `label`, so a host that implements
`Storage` itself supplies it; the storage conformance suite asserts it
survives the round trip.
- A pinned Cloudflare token costs one extra zone listing at connect to
learn the name, and connects unnamed rather than failing when that
listing does not answer.
- Release note `.tegami/account-label.md` is a MINOR on `domainkit`. S
Saatvik Arya committed
8596c2b45931d2136f02166490fb3d7de27ac3ec
Parent: 7fcb86f
Committed by GitHub <noreply@github.com>
on 9/19/2026, 7:57:54 AM