Skip to main content

Clippy Chat 📎

Clippy Chat is a small but complete, self-hosted AI chat web app — built to serve as a realistic target for writing and testing a Palo Alto AI Red Teaming custom adapter.

The chat app is real and works end to end: a browser UI, three authentication modes, a streaming inference backend, and full conversation logging. But the whole reason it exists is the file at redteam/clippy_redteam_adapter.py — a worked, heavily annotated example of a custom target adapter that lets an AI red-teaming platform drive the app's authenticated, server-sent-events chat endpoint as if it were any other model target.

:::tip The point of this project If you are here to learn how to write a custom red-team target adapter for a bespoke, authenticated, streaming chat API — start with the Red-Team Adapter section. Everything else documents the target it drives. :::

What's in the box​

PieceWhat it is
Red-team adapterA Python adapter (authenticate / pre_process / post_process) that fetches an OAuth token, posts a probe to the chat API, and parses the SSE reply back into plain text. The centerpiece.
Chat web appTanStack Start (React 19 + Nitro on Node 22) with file-based API routes.
Three auth modesOIDC (auth-code + PKCE) for humans, a local break-glass admin, and machine-to-machine bearer JWTs for service accounts and red-team runners.
Streaming inferencevLLM chat completions relayed to the browser as Server-Sent Events.
PersistencePostgres 17 via Drizzle ORM; every conversation and message is logged.
Admin panelA conversation-log table with a per-conversation transcript flyout.
Secured MCP toolsCluster-internal MCP plus an AIRS route with two-stage gateway/identity authentication and destination enforcement.

Architecture at a glance​

red-team runner ─┐
browser ─────────┤
▼
Ingress (TLS, rate-limit)
▼
clippy-chat (TanStack Start, Node 22)
├──► vLLM (chat completions, stream: true)
├──► clippy-mcp (scoped machine JWT)
└──► Postgres (conversations + messages)

Auth is enforced inside the app, not just at the edge: web sessions come from an OIDC provider, and machine callers present a bearer JWT whose scope claim must include the API scope. The red-team adapter uses exactly that machine path.

Where to go next​

:::note Examples and production evidence General setup pages use placeholders. The security handoff names real production endpoints and non-secret policy values so reviewers can reproduce tests; every credential remains redacted. :::