Clippy Chat 📎
Clippy Chat is a small but complete, self-hosted AI chat web app — built to serve as a realistic target for writing and testing a Palo Alto AI Red Teaming custom adapter.
The chat app is real and works end to end: a browser UI, three authentication modes, a
streaming inference backend, and full conversation logging. But the whole reason it exists is
the file at redteam/clippy_redteam_adapter.py — a worked, heavily
annotated example of a custom target adapter that lets an AI red-teaming platform drive the
app's authenticated, server-sent-events chat endpoint as if it were any other model target.
:::tip The point of this project If you are here to learn how to write a custom red-team target adapter for a bespoke, authenticated, streaming chat API — start with the Red-Team Adapter section. Everything else documents the target it drives. :::
What's in the box
| Piece | What it is |
|---|---|
| Red-team adapter | A Python adapter (authenticate / pre_process / post_process) that fetches an OAuth token, posts a probe to the chat API, and parses the SSE reply back into plain text. The centerpiece. |
| Chat web app | TanStack Start (React 19 + Nitro on Node 22) with file-based API routes. |
| Three auth modes | OIDC (auth-code + PKCE) for humans, a local break-glass admin, and machine-to-machine bearer JWTs for service accounts and red-team runners. |
| Streaming inference | vLLM chat completions relayed to the browser as Server-Sent Events. |
| Persistence | Postgres 17 via Drizzle ORM; every conversation and message is logged. |
| Admin panel | A conversation-log table with a per-conversation transcript flyout. |
| Secured MCP tools | Cluster-internal MCP plus an AIRS route with two-stage gateway/identity authentication and destination enforcement. |
Architecture at a glance
red-team runner ─┐
browser ─────────┤
▼
Ingress (TLS, rate-limit)
▼
clippy-chat (TanStack Start, Node 22)
├──► vLLM (chat completions, stream: true)
├──► clippy-mcp (scoped machine JWT)
└──► Postgres (conversations + messages)
Auth is enforced inside the app, not just at the edge: web sessions come from an OIDC
provider, and machine callers present a bearer JWT whose scope claim must include the
API scope. The red-team adapter uses exactly that machine path.
Where to go next
- Red-Team Adapter → Overview — why the adapter exists and how it maps to the app.
- Red-Team Adapter → The Adapter — a line-by-line walkthrough of the code.
- Red-Team Adapter → Running a Scan — configure vars/secrets and drive it.
- Getting Started — run the whole app locally.
- Architecture — the full request flow and stack.
- AI Gateway & MCP Security — production OAuth headers, claims, architecture, E2E tests, and evidence for AI Security review.
:::note Examples and production evidence General setup pages use placeholders. The security handoff names real production endpoints and non-secret policy values so reviewers can reproduce tests; every credential remains redacted. :::