Use Hopya
Using Hopya
Learn workspaces, tasks, five views, Documents, Tables, collaboration, and account settings.
v0.3.0 referenceReviewed
On this page
Hopya stores work on your operator’s instance. Early implementation: report errors with action/time, never a password or token.
Sign In
| Situation | Next step |
|---|---|
| Fresh instance | Operator uses private setup token to create first administrator |
| Existing user | Open /login; admin-created account, enabled self-registration, or configured SSO |
| Need workspace access | Ask workspace Owner; SSO alone does not add membership |
| Password/IdP unavailable | Contact operator; no public demo login; never clear data/repeat setup as password reset |
Organize Work
- Open Work (
/app), create/select a workspace. First created workspace selects automatically. - Use + beside Structure to add a project or standalone list.
- Add tasks to lists; select a list, project/folder descendants, or All tasks.
| Resource | Placement / behavior |
|---|---|
| Project / standalone List | Workspace root allowed |
| Folder | Within project/folder |
| Nested List | Within project/folder; tasks always belong to a List |
| Document / Table | Root/project/folder; first-class entries, not task Lists |
| Manage | Rename/move folder/list/Table within workspace; content/access preserved; cycles/depth overflow rejected; stale move asks reload |
| Delete structure | Empty only, never recursive purge; containing Document/Table makes parent nonempty |
Workspaces are permission boundaries. Site admin status does not expose all workspace work.
Documents and pages
| Control | Action |
|---|---|
| Hierarchy create | Document title + Markdown body |
| Pages header + | Another top-level page inside Document |
| Page row + | True nested child |
| Select page | Same editor; grouped beneath main Document in hierarchy |
| Page options | Open/rename/delete; deletion also removes nested document subpages |
Peer pages/subpages have distinct indentation/collapse behavior. Existing task-page links and tasks remain preserved.
Tables
| Area | How to use it |
|---|---|
| Create | Hierarchy → Table → typed columns → records/cells |
| Types | Text, number, date, date/time, checkbox, select; select options fixed at creation |
| Checkbox | Empty / Checked / Unchecked; Clear value returns Empty |
| Column title menu | Typed ordering/reverse, clear order, permitted local rename/delete; column letter/type in menu, badge beside title, arrow marks active order |
| Filters | Match all filters → typed AND conditions → Apply filters; Clear restores rows |
| Full data | Sort/filter/calculations include unloaded and live-source rows; empty values last; exports ignore view filters |
| Number display | Automatic or 0–10 decimals; dot/comma/space separators; preview then apply; per-account/browser preference also formats calculations |
| Precision | Display rounding only; edit/copy/export/tooltip retain stored value; Reset means full precision/no thousands separator |
| Toolbar | Filters left; Add record/Refresh/… right; record count below |
| … | Add column, Import/export, Clear ordering when sorted, Source details for live Table |
Finish/cancel edits before view changes/Refresh. A changed/new empty record may leave filtered view; clear filters first. Preferences persist while Table stays open; Refresh resolves externally changed page position. Wide grids scroll; batches load explicitly; Cancel/Escape returns cell focus. Conflicts retain drafts and offer reload.
Deletion has no undo. Column deletion needs Table write + delete and removes that value everywhere; record/Table deletion is permanent. Write-only roles can create columns/empty records on a create-only page, but need read permission to see/enter existing values.
Create And Edit
- Choose New task, a destination list, and title. Starting from a list fixes/hides destination; project/folder creation defaults inside that location.
- Add optional fields/body, then save. If location has no list, use Add a list here when allowed or ask manager.
- Open saved task to edit; explicit save persists work. Existing edits retain actual list; assistant review can choose any authorized workspace list.
| Field / control | Behavior |
|---|---|
| Body | TipTap rich text stored as Markdown; bold/italic/strike/code/headings/lists/quotes/code blocks/links; edit/remove links; history shortcuts |
| Plain typing / preview | Plain Markdown; Board/List previews plain text; control chars normalized; formatting retained ≤50,000 characters |
| Optional fields | Priority, tags, dates, workspace assignee, configured custom fields; checklist initially collapsed |
| Images | Add image/paste/drop; PNG/JPEG/GIF/WebP ≤10 MiB, including before first save; descriptions/removal and tab drafts; recovery details |
| Status / priority | Initial To do/Backlog/In progress/Review/Done; project inheritance or list override; None/Low/Medium/High/Urgent |
| Dates | Calendar dates, not promised timed reminders; custom DateTime stores time |
| Destination label | Full ancestry; same-path choices also show ID |
| Disabled/missing creation | May mean no list or missing role permission |
| Search | Titles/descriptions/tags in current workspace selection; hierarchy/status filters also apply |
Clear filters before deciding a task disappeared. Failed/pending image files have retry controls across composer reopen but bytes do not survive reload; unsaved uploads expire in 24 hours.
Version conflict: draft stays open. Reload current task asks before replacing it; cancel keeps draft, failed reload preserves it. Reapply only intended changes; never silently retry stale writes. Deletion has separate permission/confirmation, no promised trash/undo.
Mentions and discussion
| Action | Result |
|---|---|
@ member | Active workspace task readers only; notifies |
@@ task / @@@ project, folder, list | Navigation only, no notification |
| Inbox | Below workspace picker; assignments/user mentions; hidden badge at zero; open/read/unread/delete |
| Comments panel | Markdown posts, replies, reactions; comments:create + resource read |
| Comment on selection | One unambiguous saved plain-text segment; narrow formatting-crossing/duplicate selections |
| Edited/deleted selected text | Reattach when unambiguous, otherwise retain quote/orphaned thread |
| Delete comment | Author own entry or moderator comments:manage; parent tombstone preserves reply threads |
Views
| View | Use / initial display bound |
|---|---|
| List | Text/number selection → Enter/F2; choices/dates direct; title details/pencil rename; 100 tasks shared across actual list sections |
| Board | Status columns; drag optional, Move to works keyboard/touch; 100 per column |
| Calendar | Due date else start; arrows/Today/Jump; 100 per day and each undated/outside list |
| Gallery | First body image cover, prev/next; Auto-fit or 2–5 columns; browser remembers workspace, narrow screen one column; 100 matches |
| Timeline | Month start–due spans, one-date milestone; Jump; 100 scheduled + 100 outside/unscheduled; not dependency/critical-path scheduling |
Changing views never copies/moves tasks. Workspace/hierarchy/search/status carry across; Calendar/Timeline edit through task dialog, not mandatory dragging.
Display bounds do not truncate search/totals/exports. Task loading uses bounded pages/progress; incomplete loads are not called complete, and failure offers retry. Each view shows complete totals/reveal-more after successful loading. Expanded batches survive save/refresh, reset on view/filter/month changes. Browser holds full dataset, so expanding all rows can be expensive.
View navigation, hierarchy, and keyboard controls
- List sections follow actual nested/empty lists, each with unambiguous Add task. Board/List/Timeline scroll internally when wide; Gallery responds. Project description appears under title.
- Sidebar branches collapse/expand, persisted per browser/workspace. Heading icon opens shared searchable icon picker; title renames. Project/Folder/List need structure management; Document/Table use own write permissions. Shared metadata/colors visible to members.
- Narrow screens use navigation toggle and horizontal scroll for wide grids/boards/calendars. Tab traverses controls; view tabs support arrows/Home/End. Keyboard opens cards; Move to changes status; dialogs support focus/Escape. Save before closing.
Settings
Open sidebar account menu (keyboard activation/Escape supported).
| Destination | Purpose |
|---|---|
Account settings (/account) | Profile/photo, sign-in, personal tokens, Appearance |
Workspace settings (/settings) | Selected-workspace name, existing-user memberships, roles, fields, export, Owner deletion |
| Field management | Full-page field assignment workspace |
| Import & export | Task/Table/live SQL transfer |
| Webhooks & automations | Workspace integrations |
| API docs / Help | Instance API/use guidance |
Administration (/admin) | Site administrators only |
| Sign out | End session |
Appearance has dark-mode control and Use system theme reset, remembered in browser and on login. Credential changes require current password and revoke other sessions/tokens/pending reset links; reconnect clients.
Delete workspace is permanent: Owner enters exact name; tasks, Documents, Tables, hierarchy, members, fields, automation history removed. Export important data before deleting field definitions or workspace.
Project and Standalone List Fields
- Select project/list → List Add fields (also task options without losing draft). All tasks asks for explicit target.
- Select catalog/custom or optional built-ins → Apply fields, or Create field and add.
- Configure statuses/date presentation for selected field owner/list.
| Ownership / choice | Behavior |
|---|---|
| Root project | Owns field assignment for descendant lists |
| Standalone root list | Owns optional built-ins/custom fields/date format and explicit statuses |
| Project-owned list | Add fields edits project assignments; status section edits only list |
| Status inheritance | Use project statuses or explicit list override; first effective status is new-task default |
| Existing-task destination change | Retain supported status, otherwise destination first; new draft always resets to destination first |
| Remove status | Rejected while used; move tasks first; cross-project moves need supported destination workflow |
| Order statuses | Move up/down; Board/filter combine current lists, including empty statuses; same-name incompatible definitions labeled with list paths, drag targets disabled |
| Core columns | Task, Status, Assignee, Due date |
| Optional columns | Priority, Start date, Tags, Body, List, Created, Updated; new owners start without optional fields, existing migrated visibility retained |
| Templates | Estimate/Effort/Progress/Reference are ordinary fields, not automatic units/ranges |
| Types | Text/number/date/datetime/checkbox/dropdown/checklist/rating/formula; dropdown single, checklist multi; rating max 1–10 |
| Date presentation | ISO, short/long month, day/month/year; individual fields may override; never rewrites values; DateTime edited locally/stored ISO |
| Field config edit | Names/options/rating limits; invalidating values or formula-referenced rename rejected |
| Unassign / move | Saved values retained; Other saved fields shows hidden data; reassign restores; All tasks union leaves unassigned cells blank |
| Colors | Priority Low green/Medium amber/High orange/Urgent dark red; per-list ≤30 exact-tag color assignments |
Inline editing, filtering, selection, and shortcuts
| Control | Behavior |
|---|---|
| Text/number cell | Click selects; Enter/F2/double-click edits |
| Choice/checkbox/date cell | Opens directly |
| Tab / another cell / outside grid | Save and move, or save/clear selection |
| Escape / error | Cancel; failed draft retained; conflict needs explicit discard/reload |
| Columns | Order/visibility; per-account/workspace/project saved settings and sorting |
| Filter & group | AND filters or group within each list by any built-in/custom field, including hidden columns |
| Row checkboxes | Currently displayed tasks; permission-aware Archive/Delete; parents need selected subtasks |
| Archive | Removes ordinary views; complete workspace exports retain records |
| Unmodified C | Outside inputs/dialogs, create task in selected/first available list |
Formula Examples
Exact field names, not spreadsheet addresses; function names case-insensitive, leading equals optional.
=SUM({{Estimate}}, {{Buffer}})
=IF({{Qty}}>0, ROUND({{Qty}}*{{Price}}, 2), 0)
=CONCAT("Task: ", {{Reference}})
| Rule | Meaning |
|---|---|
| Functions | SUM, AVERAGE, MIN, MAX, ROUND, ABS, IF, CONCAT |
| Scope | Bounded display calculator, not Excel/code/network/ranges/recursive formula evaluation |
| Null vs missing | Stored null becomes numeric zero/empty text; missing field is not assumed zero |
| Invalid/non-finite/missing input | Display raw expression |
| Cleared values | Empty text/number/date/select unset; checkbox No vs Not set; Clear unsets |
| Read-only user | Can focus/select/scroll description/text, no edit permission |
| AI hidden columns | Proposed priority remains in review even if column hidden; hiding never skips approval |
Owner cannot be removed last; delegated roles cannot escalate. Ask Owner to review access rather than trying another UI/token; API enforces same boundary.
Workspace JSON export
| Included with current permissions | Not included |
|---|---|
| v8 tasks/hierarchy/attributed Documents/pages, local Tables/columns/records, discussion/reactions, root field owners/list config, custom fields, attachment/committed-image metadata | File bytes, pending drafts, accounts, credentials, all site state |
Tables with tables:read; safe tableSources describes live sources | Remote rows: use per-Table export |
Historical projectFields[].projectId identifies project or standalone root list | A restore point; private image links still need original instance |
Keep file private. Wait for stream to finish; interrupted/revoked/slow/excess downloads are failed, not complete exports. Close redundant downloads/retry while authorized. Operator needs full backup.
Account Settings
| Account action | Behavior |
|---|---|
| Name/email/local password | Account settings; email/password need current local password, revoke other sessions/tokens/reset links |
| SSO-only account | Edit display name here; manage IdP email/credentials at provider |
| Profile picture | Upload/replace/remove PNG/JPEG/WebP ≤10 MiB; centered square ≤512px; private shared-member/admin access; initial fallback; drafts retained; details |
| Forgot password | Appears with configured mail; same response for every email; eligible local accounts receive one-use 30-minute link; completion revokes all sessions/tokens |
| No mail recovery | Contact operator without sharing password |
Personal Tokens
- Account settings → Personal access tokens → recognizable name → create.
- Store one-time value in script/MCP client’s private environment. It acts as you with current permissions.
- Lost value cannot be revealed again; replace it. Revoke stops its clients immediately.
Never share in chat, commit, or put in URLs. MCP client—not ordinary terminal conversation—launches stdio. Admin may enable bearer-auth SSE /api/v1/mcp/sse. Writes default off; process HOPYA_MCP_ALLOW_WRITES=true only exposes tools, and each mutation still needs human approval. See MCP setup.
Attachments And AI
| Workflow | Safe use |
|---|---|
| Attachment | Save task first; upload ≤10 MiB; permission-checked download URL never public; proxy/app may impose size errors |
| File safety / retention | No execution/malware-scan guarantee; removal revokes access, physical cleanup/S3 retention may lag; ask operator |
| Failed attachment listing | Retry attachments, never assume empty; wait before changes; failed post-upload refresh needs listing retry before duplicate upload |
| Assistant | Configured AI + agent:use; sends authorized context/message to selected provider; no secrets without understanding policy |
| Proposed task | Review actual fields/list/workspace and explicitly save; chat alone never mutates; decline/close unwanted proposals; manual editing fallback |
| Close / workspace switch | Cancels request/discards panel conversation; window resize does not |
| Deadline / busy | 45 seconds, asks retry when busy, never automatically creates task |
Remote cancellation/billing/context retraction is not guaranteed; API stops HTTP when disconnect reaches it. AI can be wrong/unavailable.
Administration
| Operator area | Boundary |
|---|---|
/admin | Local users, admin/disabled status, service status, restricted audits |
| Suspension | Revokes access/clears assignments even sole workspace Owner; ownership retained for recovery; last active site admin protected |
| Workspace membership | Still required; admin is not a bypass |
| Environment only | Provider keys, APP_URL, registration/SSO provisioning, operator landing gate |
| Configured status flag | Not proof of reachable/tested integration |
| Branding | Optional landing gate requires LANDING_ENABLED=true; logo PNG/JPEG/WebP/SVG ≤300 KB; By WNZN watermark default shown, hidden applies to all workspaces/accounts |
| Landing template | Operator apps/web/src/landing.json, separate from this site |
Integrations And Automations
| Permission | Operation |
|---|---|
workspace:manage | Webhooks |
automations:manage + items:read | All automation work, including legacy, graph, preview/test/runs |
credentials:manage | Authentication profiles / OAuth |
| Either management permission | Safe profile metadata, no extra task-read |
Former workspace managers initially received both new management rights; Owners should review delegation.
Webhooks and graph workflow
| Step / action | Result |
|---|---|
| Workspace hook | Up to 20 endpoints; item/node/field events; new/rotated secret shown once, HMAC-SHA256 v2 over exact body |
| Legacy hook | Historical v1 digest until rotation; coordinate receiver verification |
| Final URL | All outbound redirects rejected, including legacy linear/hooks; old digest does not restore redirects |
| New automation | Paused starter → Edit graph |
| Save draft | Retains draft, optimistic revision; does not activate |
| Validate | Structure, typed references, credentials, destination issues |
| Publish | Explicit confirmation; immutable version for future runs; keep draft/increment revision; enable/pause separate |
| Conflict | Unsaved draft retained; reload before changes; revisions never reset, queued/active runs retain version |
| Preview path | Dry event JSON, validation/path only; no HTTP/email/log/task mutation |
| Test run | Confirmation queues real effects; rejects any Update task node before queue (no synthetic triggering task); Email needs SMTP_URL |
| Graph / editor | Behavior |
|---|---|
| Nodes | One trigger; HTTP/Webhook/Email/Log/Update task actions; Condition/Switch controls |
| Branches | True/false or ≤20 cases/default; one path at a time; no cycles/unreachable/ordinary parallel fan-out |
| Limits | ≤50 nodes/75 edges plus bounded graph/config/execution |
| Pointer alternative | Searchable palette, accessible outline, inspector add/delete/target/move; narrow Palette/Canvas/Inspector tabs |
| Data picker | Trigger/upstream guaranteed fields; {{event.item.status}}, stable-ID {{nodes.http-<id>.output.status}}; no unknown/downstream/optional references |
| Legacy | 1–20 ordered steps, {{steps.1.output}}; migration 0002 preserves oversized linear representations/whole-event repair without changing steps/runs/published graphs/drafts; graph publish retains graph limits |
Publisher access is checked before every node. Removed publisher/task-read access fails run; Update task targets only triggering task as publisher, with immediate read/write check. Nested depth ≤5, no same-automation re-entry. Later node failure never undoes originating action.
Run monitoring, profiles, OAuth, and destination restrictions
- Run monitor filters status/automation, refreshes active work, expands node/legacy-step results; unselected branches skipped. Durable versions/runs, bounded sanitized output/logs; never add secrets.
- Expired graph/linear/webhook leases fail without replay. A successful remote action may precede local failure/timeout; inspect destination before retry.
- Profiles: bearer/API-key/basic/custom headers/OAuth, workspace-scoped/write-only, exact origin/optional path. Replace supplies full new secret/version; Revoke can break published nodes. Authorization/cookie/API-key/hop-by-hop headers belong in profiles, not public headers.
- Connect/reconnect uses encrypted authorization-code PKCE S256; external consent/token/revocation unverified. Missing automation keyring explicitly fails credential work, not ordinary tasks.
- Credentials dispatch only to exact scheme/host/port/path or descendant. RFC1918/ULA private allowed; special addresses blocked; public authenticated destination HTTPS, no redirects; exact-origin operator exception never bypasses credential binding.
- Instance
/api/v1/openapi.jsonand API docs have method/category/search controls. See graph REST reference; browser/OAuth-provider behavior not certified here.
Field Management
- Open account menu → Field management.
- Pick workspace, filter kind/path tree, select target; summary confirms.
- Right panel shares assignment/create/status/concurrency rules and permission notice. Folder targets resolve to owner project; lists retain status overrides.
Import And Export
| Resource | Transfer behavior |
|---|---|
| Tasks | Template → ≤500 rows → one destination list → map exactly one title, description/status/priority/dates/tags/assignee/custom/keep-as-is/ignore |
| Task validation | All rows before any write; failure creates zero tasks; unmapped custom-name columns pass through and fail if field absent |
| Task export | Workspace/scope/status/search/format; hopya-export-*; CSV custom-name columns, JSON field-ID-keyed custom map |
| Tables | Create local/append atomic ≤500 records / 1 MB; CSV exact names, new text columns; JSON types/options/null/empty/false preserved; all rows regardless filters/pages |
| Large transfer | Split bounded batches; CSV flattens null/empty, use JSON for exact values |
| Live SQL | Operator allowlists source; credential manager tests/saves/browses/links with Table read/write; source password write-only |
Table keyboard editing and whole-data calculations
- Row numbers/sticky compact headers/type badges; column letters in menu. Click selects, arrows navigate, Enter/F2/double-click edits; touch selected cell edits; typing replaces text/number draft.
- Enter saves vertically; Tab saves text-like editor/moves; Escape cancels; single text/number cell copy/paste; explicit Save/Cancel. Failed/conflicting drafts stay. Refresh latest; Load more extends grid.
- Calculate: Count filled/Count all/Empty; numbers Sum/Average/Min/Max; dates Earliest/Latest; checkboxes Checked/Unchecked. All matching loaded/unloaded/live rows; no filter means whole Table. Null/missing/empty are empty, zero/unchecked filled.
- Results refresh after saves/imports/filters/Refresh; None clears, selection lasts open Table. Failure shows retry, never partial total.
Live cells write immediately to existing source rows. Primary/generated/unsupported fields read-only; source insert/delete/schema via database tools. Removing link leaves source intact; changed schema requires reconnect, conflict keeps draft/offers reload. See live deployment.
OIDC identity management
Admin chooses intended account, verifies exact trusted issuer/subject (never email), then confirms link. Provider subjects differ; supplied Ory uses public Kratos identity ID subjects.
Unlink revokes every session/token. Local password survives; passwordless account must retain identity for current exact issuer/configured SSO. Inactive issuer/disabled SSO is not recovery. Verify new sign-in first; API cannot prove linked subject exists. Self-unlink signs out; quarantine by disabling Hopya/upstream account and reviewing provisioning, not unlink alone.
Troubleshooting
| Symptom | Check |
|---|---|
| Origin not allowed | Exact configured scheme/port; localhost ≠ 127.0.0.1 |
| Permission denied | Intended workspace/member/role; token never bypasses |
| Too many attempts | Wait retry; account and IP aggregate limits; NAT/outer proxy may share login/SSO bucket; ask operator |
| No tasks visible | Workspace/hierarchy/search/status/month |
| New SSO rejected | Provisioning disabled or local email collision; email is not linking proof |
| Service failure | Report action/time privately; no cookies/tokens/full prompts |