Unverified identity. Okta login isn't configured in this environment, so the
server trusts X-User-Email (AUTH_TRUST_HEADERS). Fine for local
development — it is not authentication.
Sign in to see your libraries.
What you see comes from your Okta token: your email makes you an owner or a viewer, your groups become squads.
The server still accepts header identity
(AUTH_TRUST_HEADERS) — sign in with Okta anyway.
Your libraries
Libraries you own. Click a slug to query it.
No libraries yet.
Use + New library above, or ask Claude with the
publish-library skill (see About).
Couldn't load your libraries.
| Library | Owners | View squads | View users | Last sync | Actions |
|---|
Browse
Libraries shared with you — click a slug to query it. Search by slug, name,
description, owner, squad, or user. Company-wide (Everyone) libraries hidden by default.
No matches.
Adjust the filter.
Couldn't load Browse.
| Library | Owners | View squads | View users | Last sync |
|---|
New to Wild RAG, or want to use it from Claude? Read the About page — covers what it is, how to query libraries from an agent, and how the permission model works.
What is Wild RAG?
Knowledge libraries as a service. Point a library at Google Drive folders, sync it, and any AI system — Claude Code, autonomous agents, internal tools — can search it and get passages back with citations to the source documents. Who can query what is decided by the library's owners, never by the agent.
How to use a library
Easiest path: just ask Claude. The wild-rag Claude plugin wraps
the MCP server above, adds the query-library and publish-library
skills, and a session hook that reminds Claude to check the libraries before answering from
memory about internal systems.
From Claude
Examples:
- "How do we fail over the payments database?"
- "Search sre-runbooks for Kyverno policy exceptions."
- "Turn this Drive folder into a library for my squad."
- "Sync the sre-runbooks library."
Install the plugin:
/plugin marketplace add git@git.topfreegames.com:sre/wild-rag.git
/plugin install wild-rag@wild-rag
/reload-plugins
/mcp
/mcp runs the Okta login — the agent inherits your access and nothing more.
From this console
The Libraries tab handles create, Drive connect, sync, company-wide access, and delete, plus a query playground to check what an agent would get back.
From the API
Same service, same rules, with an Okta bearer token:
GET /api/v1/libraries
POST /api/v1/libraries
POST /api/v1/libraries/<slug>/connect
POST /api/v1/libraries/<slug>/sync
POST /api/v1/libraries/<slug>/query
Full reference in Swagger.
How a library gets its content
- Create — pick a slug (what agents ask for), a description (how an agent decides the library answers its question), and the Drive folder or file IDs to index.
- Connect Google Drive — approve read access as yourself. The grant is stored in AWS Secrets Manager and never shown back.
- Sync — Bedrock crawls, chunks, and indexes the selection in the background. Sync is manual: documents changed afterwards need another sync.
- Query — ranked passages with title, source link, and last-updated date, optionally limited to documents modified inside a date window.
Permissions in a nutshell
- Owners
- Manage a library (connect, sync, change access, delete) and query it. Owners are emails
(
alice@wildlifestudios.com); the creator is the first one. - View squads
- Squads granted query access (
wlp.prod.<squad>), resolved from thegroupsclaim of your Okta token — without that claim, squad grants don't apply to you. - View users
- Specific emails granted query access — no admin rights.
- Company-wide
- The
Everyonegrant: any Wilder signed in via Okta can query the library.
You only see what you can query. The API, the MCP server and this console return the same filtered list — a library you can't access doesn't exist for you, anywhere.
What this console can do
- List libraries you own + browse everything shared with you.
- Create libraries from Drive folders and files.
- Connect Google Drive, sync, and follow the sync live.
- Toggle company-wide access on libraries you own.
- Query any library you can read, with an optional date window.
- Delete libraries permanently.
Queries return raw, cited passages — composing an answer from them is the agent's job. Per-squad and per-user grants aren't editable from the console yet.