Use Hopya

Using Hopya

Learn workspaces, tasks, five views, Documents, Tables, collaboration, and account settings.

v0.3.0 referenceReviewed

On this page

Hopya stores work on your operator’s instance. Early implementation: report errors with action/time, never a password or token.

Sign In

Sign In: reference table
SituationNext step
Fresh instanceOperator uses private setup token to create first administrator
Existing userOpen /login; admin-created account, enabled self-registration, or configured SSO
Need workspace accessAsk workspace Owner; SSO alone does not add membership
Password/IdP unavailableContact operator; no public demo login; never clear data/repeat setup as password reset

Organize Work

  1. Open Work (/app), create/select a workspace. First created workspace selects automatically.
  2. Use + beside Structure to add a project or standalone list.
  3. Add tasks to lists; select a list, project/folder descendants, or All tasks.
Organize Work: reference table
ResourcePlacement / behavior
Project / standalone ListWorkspace root allowed
FolderWithin project/folder
Nested ListWithin project/folder; tasks always belong to a List
Document / TableRoot/project/folder; first-class entries, not task Lists
ManageRename/move folder/list/Table within workspace; content/access preserved; cycles/depth overflow rejected; stale move asks reload
Delete structureEmpty only, never recursive purge; containing Document/Table makes parent nonempty

Workspaces are permission boundaries. Site admin status does not expose all workspace work.

Documents and pages

Documents and pages: reference table
ControlAction
Hierarchy createDocument title + Markdown body
Pages header +Another top-level page inside Document
Page row +True nested child
Select pageSame editor; grouped beneath main Document in hierarchy
Page optionsOpen/rename/delete; deletion also removes nested document subpages

Peer pages/subpages have distinct indentation/collapse behavior. Existing task-page links and tasks remain preserved.

Tables

Tables: reference table
AreaHow to use it
CreateHierarchy → Table → typed columns → records/cells
TypesText, number, date, date/time, checkbox, select; select options fixed at creation
CheckboxEmpty / Checked / Unchecked; Clear value returns Empty
Column title menuTyped ordering/reverse, clear order, permitted local rename/delete; column letter/type in menu, badge beside title, arrow marks active order
FiltersMatch all filters → typed AND conditions → Apply filters; Clear restores rows
Full dataSort/filter/calculations include unloaded and live-source rows; empty values last; exports ignore view filters
Number displayAutomatic or 0–10 decimals; dot/comma/space separators; preview then apply; per-account/browser preference also formats calculations
PrecisionDisplay rounding only; edit/copy/export/tooltip retain stored value; Reset means full precision/no thousands separator
ToolbarFilters left; Add record/Refresh/… right; record count below
…Add column, Import/export, Clear ordering when sorted, Source details for live Table

Finish/cancel edits before view changes/Refresh. A changed/new empty record may leave filtered view; clear filters first. Preferences persist while Table stays open; Refresh resolves externally changed page position. Wide grids scroll; batches load explicitly; Cancel/Escape returns cell focus. Conflicts retain drafts and offer reload.

Deletion has no undo. Column deletion needs Table write + delete and removes that value everywhere; record/Table deletion is permanent. Write-only roles can create columns/empty records on a create-only page, but need read permission to see/enter existing values.

Create And Edit

  1. Choose New task, a destination list, and title. Starting from a list fixes/hides destination; project/folder creation defaults inside that location.
  2. Add optional fields/body, then save. If location has no list, use Add a list here when allowed or ask manager.
  3. Open saved task to edit; explicit save persists work. Existing edits retain actual list; assistant review can choose any authorized workspace list.
Create And Edit: reference table
Field / controlBehavior
BodyTipTap rich text stored as Markdown; bold/italic/strike/code/headings/lists/quotes/code blocks/links; edit/remove links; history shortcuts
Plain typing / previewPlain Markdown; Board/List previews plain text; control chars normalized; formatting retained ≤50,000 characters
Optional fieldsPriority, tags, dates, workspace assignee, configured custom fields; checklist initially collapsed
ImagesAdd image/paste/drop; PNG/JPEG/GIF/WebP ≤10 MiB, including before first save; descriptions/removal and tab drafts; recovery details
Status / priorityInitial To do/Backlog/In progress/Review/Done; project inheritance or list override; None/Low/Medium/High/Urgent
DatesCalendar dates, not promised timed reminders; custom DateTime stores time
Destination labelFull ancestry; same-path choices also show ID
Disabled/missing creationMay mean no list or missing role permission
SearchTitles/descriptions/tags in current workspace selection; hierarchy/status filters also apply

Clear filters before deciding a task disappeared. Failed/pending image files have retry controls across composer reopen but bytes do not survive reload; unsaved uploads expire in 24 hours.

Version conflict: draft stays open. Reload current task asks before replacing it; cancel keeps draft, failed reload preserves it. Reapply only intended changes; never silently retry stale writes. Deletion has separate permission/confirmation, no promised trash/undo.

Mentions and discussion

Mentions and discussion: reference table
ActionResult
@ memberActive workspace task readers only; notifies
@@ task / @@@ project, folder, listNavigation only, no notification
InboxBelow workspace picker; assignments/user mentions; hidden badge at zero; open/read/unread/delete
Comments panelMarkdown posts, replies, reactions; comments:create + resource read
Comment on selectionOne unambiguous saved plain-text segment; narrow formatting-crossing/duplicate selections
Edited/deleted selected textReattach when unambiguous, otherwise retain quote/orphaned thread
Delete commentAuthor own entry or moderator comments:manage; parent tombstone preserves reply threads

Views

Views: reference table
ViewUse / initial display bound
ListText/number selection → Enter/F2; choices/dates direct; title details/pencil rename; 100 tasks shared across actual list sections
BoardStatus columns; drag optional, Move to works keyboard/touch; 100 per column
CalendarDue date else start; arrows/Today/Jump; 100 per day and each undated/outside list
GalleryFirst body image cover, prev/next; Auto-fit or 2–5 columns; browser remembers workspace, narrow screen one column; 100 matches
TimelineMonth start–due spans, one-date milestone; Jump; 100 scheduled + 100 outside/unscheduled; not dependency/critical-path scheduling

Changing views never copies/moves tasks. Workspace/hierarchy/search/status carry across; Calendar/Timeline edit through task dialog, not mandatory dragging.

Display bounds do not truncate search/totals/exports. Task loading uses bounded pages/progress; incomplete loads are not called complete, and failure offers retry. Each view shows complete totals/reveal-more after successful loading. Expanded batches survive save/refresh, reset on view/filter/month changes. Browser holds full dataset, so expanding all rows can be expensive.

View navigation, hierarchy, and keyboard controls
  • List sections follow actual nested/empty lists, each with unambiguous Add task. Board/List/Timeline scroll internally when wide; Gallery responds. Project description appears under title.
  • Sidebar branches collapse/expand, persisted per browser/workspace. Heading icon opens shared searchable icon picker; title renames. Project/Folder/List need structure management; Document/Table use own write permissions. Shared metadata/colors visible to members.
  • Narrow screens use navigation toggle and horizontal scroll for wide grids/boards/calendars. Tab traverses controls; view tabs support arrows/Home/End. Keyboard opens cards; Move to changes status; dialogs support focus/Escape. Save before closing.

Settings

Open sidebar account menu (keyboard activation/Escape supported).

Settings: reference table
DestinationPurpose
Account settings (/account)Profile/photo, sign-in, personal tokens, Appearance
Workspace settings (/settings)Selected-workspace name, existing-user memberships, roles, fields, export, Owner deletion
Field managementFull-page field assignment workspace
Import & exportTask/Table/live SQL transfer
Webhooks & automationsWorkspace integrations
API docs / HelpInstance API/use guidance
Administration (/admin)Site administrators only
Sign outEnd session

Appearance has dark-mode control and Use system theme reset, remembered in browser and on login. Credential changes require current password and revoke other sessions/tokens/pending reset links; reconnect clients.

Delete workspace is permanent: Owner enters exact name; tasks, Documents, Tables, hierarchy, members, fields, automation history removed. Export important data before deleting field definitions or workspace.

Project and Standalone List Fields

  1. Select project/list → List Add fields (also task options without losing draft). All tasks asks for explicit target.
  2. Select catalog/custom or optional built-ins → Apply fields, or Create field and add.
  3. Configure statuses/date presentation for selected field owner/list.
Project and Standalone List Fields: reference table
Ownership / choiceBehavior
Root projectOwns field assignment for descendant lists
Standalone root listOwns optional built-ins/custom fields/date format and explicit statuses
Project-owned listAdd fields edits project assignments; status section edits only list
Status inheritanceUse project statuses or explicit list override; first effective status is new-task default
Existing-task destination changeRetain supported status, otherwise destination first; new draft always resets to destination first
Remove statusRejected while used; move tasks first; cross-project moves need supported destination workflow
Order statusesMove up/down; Board/filter combine current lists, including empty statuses; same-name incompatible definitions labeled with list paths, drag targets disabled
Core columnsTask, Status, Assignee, Due date
Optional columnsPriority, Start date, Tags, Body, List, Created, Updated; new owners start without optional fields, existing migrated visibility retained
TemplatesEstimate/Effort/Progress/Reference are ordinary fields, not automatic units/ranges
TypesText/number/date/datetime/checkbox/dropdown/checklist/rating/formula; dropdown single, checklist multi; rating max 1–10
Date presentationISO, short/long month, day/month/year; individual fields may override; never rewrites values; DateTime edited locally/stored ISO
Field config editNames/options/rating limits; invalidating values or formula-referenced rename rejected
Unassign / moveSaved values retained; Other saved fields shows hidden data; reassign restores; All tasks union leaves unassigned cells blank
ColorsPriority Low green/Medium amber/High orange/Urgent dark red; per-list ≤30 exact-tag color assignments
Inline editing, filtering, selection, and shortcuts
Project and Standalone List Fields: reference table
ControlBehavior
Text/number cellClick selects; Enter/F2/double-click edits
Choice/checkbox/date cellOpens directly
Tab / another cell / outside gridSave and move, or save/clear selection
Escape / errorCancel; failed draft retained; conflict needs explicit discard/reload
ColumnsOrder/visibility; per-account/workspace/project saved settings and sorting
Filter & groupAND filters or group within each list by any built-in/custom field, including hidden columns
Row checkboxesCurrently displayed tasks; permission-aware Archive/Delete; parents need selected subtasks
ArchiveRemoves ordinary views; complete workspace exports retain records
Unmodified COutside inputs/dialogs, create task in selected/first available list

Formula Examples

Exact field names, not spreadsheet addresses; function names case-insensitive, leading equals optional.

=SUM({{Estimate}}, {{Buffer}})
=IF({{Qty}}>0, ROUND({{Qty}}*{{Price}}, 2), 0)
=CONCAT("Task: ", {{Reference}})
Formula Examples: reference table
RuleMeaning
FunctionsSUM, AVERAGE, MIN, MAX, ROUND, ABS, IF, CONCAT
ScopeBounded display calculator, not Excel/code/network/ranges/recursive formula evaluation
Null vs missingStored null becomes numeric zero/empty text; missing field is not assumed zero
Invalid/non-finite/missing inputDisplay raw expression
Cleared valuesEmpty text/number/date/select unset; checkbox No vs Not set; Clear unsets
Read-only userCan focus/select/scroll description/text, no edit permission
AI hidden columnsProposed priority remains in review even if column hidden; hiding never skips approval

Owner cannot be removed last; delegated roles cannot escalate. Ask Owner to review access rather than trying another UI/token; API enforces same boundary.

Workspace JSON export

Workspace JSON export: reference table
Included with current permissionsNot included
v8 tasks/hierarchy/attributed Documents/pages, local Tables/columns/records, discussion/reactions, root field owners/list config, custom fields, attachment/committed-image metadataFile bytes, pending drafts, accounts, credentials, all site state
Tables with tables:read; safe tableSources describes live sourcesRemote rows: use per-Table export
Historical projectFields[].projectId identifies project or standalone root listA restore point; private image links still need original instance

Keep file private. Wait for stream to finish; interrupted/revoked/slow/excess downloads are failed, not complete exports. Close redundant downloads/retry while authorized. Operator needs full backup.

Account Settings

Account Settings: reference table
Account actionBehavior
Name/email/local passwordAccount settings; email/password need current local password, revoke other sessions/tokens/reset links
SSO-only accountEdit display name here; manage IdP email/credentials at provider
Profile pictureUpload/replace/remove PNG/JPEG/WebP ≤10 MiB; centered square ≤512px; private shared-member/admin access; initial fallback; drafts retained; details
Forgot passwordAppears with configured mail; same response for every email; eligible local accounts receive one-use 30-minute link; completion revokes all sessions/tokens
No mail recoveryContact operator without sharing password

Personal Tokens

  1. Account settings → Personal access tokens → recognizable name → create.
  2. Store one-time value in script/MCP client’s private environment. It acts as you with current permissions.
  3. Lost value cannot be revealed again; replace it. Revoke stops its clients immediately.

Never share in chat, commit, or put in URLs. MCP client—not ordinary terminal conversation—launches stdio. Admin may enable bearer-auth SSE /api/v1/mcp/sse. Writes default off; process HOPYA_MCP_ALLOW_WRITES=true only exposes tools, and each mutation still needs human approval. See MCP setup.

Attachments And AI

Attachments And AI: reference table
WorkflowSafe use
AttachmentSave task first; upload ≤10 MiB; permission-checked download URL never public; proxy/app may impose size errors
File safety / retentionNo execution/malware-scan guarantee; removal revokes access, physical cleanup/S3 retention may lag; ask operator
Failed attachment listingRetry attachments, never assume empty; wait before changes; failed post-upload refresh needs listing retry before duplicate upload
AssistantConfigured AI + agent:use; sends authorized context/message to selected provider; no secrets without understanding policy
Proposed taskReview actual fields/list/workspace and explicitly save; chat alone never mutates; decline/close unwanted proposals; manual editing fallback
Close / workspace switchCancels request/discards panel conversation; window resize does not
Deadline / busy45 seconds, asks retry when busy, never automatically creates task

Remote cancellation/billing/context retraction is not guaranteed; API stops HTTP when disconnect reaches it. AI can be wrong/unavailable.

Administration

Administration: reference table
Operator areaBoundary
/adminLocal users, admin/disabled status, service status, restricted audits
SuspensionRevokes access/clears assignments even sole workspace Owner; ownership retained for recovery; last active site admin protected
Workspace membershipStill required; admin is not a bypass
Environment onlyProvider keys, APP_URL, registration/SSO provisioning, operator landing gate
Configured status flagNot proof of reachable/tested integration
BrandingOptional landing gate requires LANDING_ENABLED=true; logo PNG/JPEG/WebP/SVG ≤300 KB; By WNZN watermark default shown, hidden applies to all workspaces/accounts
Landing templateOperator apps/web/src/landing.json, separate from this site

Integrations And Automations

Integrations And Automations: reference table
PermissionOperation
workspace:manageWebhooks
automations:manage + items:readAll automation work, including legacy, graph, preview/test/runs
credentials:manageAuthentication profiles / OAuth
Either management permissionSafe profile metadata, no extra task-read

Former workspace managers initially received both new management rights; Owners should review delegation.

Webhooks and graph workflow

Webhooks and graph workflow: reference table
Step / actionResult
Workspace hookUp to 20 endpoints; item/node/field events; new/rotated secret shown once, HMAC-SHA256 v2 over exact body
Legacy hookHistorical v1 digest until rotation; coordinate receiver verification
Final URLAll outbound redirects rejected, including legacy linear/hooks; old digest does not restore redirects
New automationPaused starter → Edit graph
Save draftRetains draft, optimistic revision; does not activate
ValidateStructure, typed references, credentials, destination issues
PublishExplicit confirmation; immutable version for future runs; keep draft/increment revision; enable/pause separate
ConflictUnsaved draft retained; reload before changes; revisions never reset, queued/active runs retain version
Preview pathDry event JSON, validation/path only; no HTTP/email/log/task mutation
Test runConfirmation queues real effects; rejects any Update task node before queue (no synthetic triggering task); Email needs SMTP_URL
Webhooks and graph workflow: reference table
Graph / editorBehavior
NodesOne trigger; HTTP/Webhook/Email/Log/Update task actions; Condition/Switch controls
BranchesTrue/false or ≤20 cases/default; one path at a time; no cycles/unreachable/ordinary parallel fan-out
Limits≤50 nodes/75 edges plus bounded graph/config/execution
Pointer alternativeSearchable palette, accessible outline, inspector add/delete/target/move; narrow Palette/Canvas/Inspector tabs
Data pickerTrigger/upstream guaranteed fields; {{event.item.status}}, stable-ID {{nodes.http-<id>.output.status}}; no unknown/downstream/optional references
Legacy1–20 ordered steps, {{steps.1.output}}; migration 0002 preserves oversized linear representations/whole-event repair without changing steps/runs/published graphs/drafts; graph publish retains graph limits

Publisher access is checked before every node. Removed publisher/task-read access fails run; Update task targets only triggering task as publisher, with immediate read/write check. Nested depth ≤5, no same-automation re-entry. Later node failure never undoes originating action.

Run monitoring, profiles, OAuth, and destination restrictions
  • Run monitor filters status/automation, refreshes active work, expands node/legacy-step results; unselected branches skipped. Durable versions/runs, bounded sanitized output/logs; never add secrets.
  • Expired graph/linear/webhook leases fail without replay. A successful remote action may precede local failure/timeout; inspect destination before retry.
  • Profiles: bearer/API-key/basic/custom headers/OAuth, workspace-scoped/write-only, exact origin/optional path. Replace supplies full new secret/version; Revoke can break published nodes. Authorization/cookie/API-key/hop-by-hop headers belong in profiles, not public headers.
  • Connect/reconnect uses encrypted authorization-code PKCE S256; external consent/token/revocation unverified. Missing automation keyring explicitly fails credential work, not ordinary tasks.
  • Credentials dispatch only to exact scheme/host/port/path or descendant. RFC1918/ULA private allowed; special addresses blocked; public authenticated destination HTTPS, no redirects; exact-origin operator exception never bypasses credential binding.
  • Instance /api/v1/openapi.json and API docs have method/category/search controls. See graph REST reference; browser/OAuth-provider behavior not certified here.

Field Management

  1. Open account menu → Field management.
  2. Pick workspace, filter kind/path tree, select target; summary confirms.
  3. Right panel shares assignment/create/status/concurrency rules and permission notice. Folder targets resolve to owner project; lists retain status overrides.

Import And Export

Import And Export: reference table
ResourceTransfer behavior
TasksTemplate → ≤500 rows → one destination list → map exactly one title, description/status/priority/dates/tags/assignee/custom/keep-as-is/ignore
Task validationAll rows before any write; failure creates zero tasks; unmapped custom-name columns pass through and fail if field absent
Task exportWorkspace/scope/status/search/format; hopya-export-*; CSV custom-name columns, JSON field-ID-keyed custom map
TablesCreate local/append atomic ≤500 records / 1 MB; CSV exact names, new text columns; JSON types/options/null/empty/false preserved; all rows regardless filters/pages
Large transferSplit bounded batches; CSV flattens null/empty, use JSON for exact values
Live SQLOperator allowlists source; credential manager tests/saves/browses/links with Table read/write; source password write-only
Table keyboard editing and whole-data calculations
  • Row numbers/sticky compact headers/type badges; column letters in menu. Click selects, arrows navigate, Enter/F2/double-click edits; touch selected cell edits; typing replaces text/number draft.
  • Enter saves vertically; Tab saves text-like editor/moves; Escape cancels; single text/number cell copy/paste; explicit Save/Cancel. Failed/conflicting drafts stay. Refresh latest; Load more extends grid.
  • Calculate: Count filled/Count all/Empty; numbers Sum/Average/Min/Max; dates Earliest/Latest; checkboxes Checked/Unchecked. All matching loaded/unloaded/live rows; no filter means whole Table. Null/missing/empty are empty, zero/unchecked filled.
  • Results refresh after saves/imports/filters/Refresh; None clears, selection lasts open Table. Failure shows retry, never partial total.

Live cells write immediately to existing source rows. Primary/generated/unsupported fields read-only; source insert/delete/schema via database tools. Removing link leaves source intact; changed schema requires reconnect, conflict keeps draft/offers reload. See live deployment.

OIDC identity management

Admin chooses intended account, verifies exact trusted issuer/subject (never email), then confirms link. Provider subjects differ; supplied Ory uses public Kratos identity ID subjects.

Unlink revokes every session/token. Local password survives; passwordless account must retain identity for current exact issuer/configured SSO. Inactive issuer/disabled SSO is not recovery. Verify new sign-in first; API cannot prove linked subject exists. Self-unlink signs out; quarantine by disabling Hopya/upstream account and reviewing provisioning, not unlink alone.

Troubleshooting

Troubleshooting: reference table
SymptomCheck
Origin not allowedExact configured scheme/port; localhost ≠ 127.0.0.1
Permission deniedIntended workspace/member/role; token never bypasses
Too many attemptsWait retry; account and IP aggregate limits; NAT/outer proxy may share login/SSO bucket; ask operator
No tasks visibleWorkspace/hierarchy/search/status/month
New SSO rejectedProvisioning disabled or local email collision; email is not linking proof
Service failureReport action/time privately; no cookies/tokens/full prompts