47 Commits

Author SHA1 Message Date
jkomyno 43ebe6c24e feat(py): expose the owned client surface on composio-client 2.0.0rc7
Add composio.webhooks, composio.logs, composio.keyring,
experimental.usage and experimental.custom_toolkits, plus
connected_accounts.revoke()/complete_auth(), toolkits get_many/changelog/
recommend_scopes/list_grant_contexts and session config history.

Forward composio_client records into the SDK logger, keeping its
per-request records at DEBUG, and raise client deprecation notices as
ComposioDeprecationWarning.
2026-09-11 18:31:12 +02:00
jkomyno cf25f25363 fix(python): preserve nullable file upload arguments 2026-08-25 04:09:41 +02:00
jkomyno fe66cbeb77 fix(sdk): omit empty file-uploadable arguments from tool execution
Both SDKs forwarded "" for a file_uploadable parameter (e.g. Gmail
attachment) verbatim to the backend, which rejected it with a Pydantic
validation error. Python only dropped it inside the opt-in auto-upload
walker; TypeScript never did, and with auto-upload on it tried to upload
the empty string.

Run a schema-aware, upload-free pass on the default execute path that
omits empty file values, and reuse the same walker for staging when
auto-upload is enabled.

Closes #4233
2026-08-25 01:58:52 +02:00
Alberto Schiabel a14f9d537f fix(py): normalize toolkit-less tool metadata (#4178)
This PR:

- closes #4152
- normalizes model- and mapping-shaped tool responses at the Python SDK
boundary
- uses `unknown` for direct/schema modifiers and `composio` for Tool
Router execution, matching TypeScript
- caches the untouched fetched tool before schema modifiers so execution
keeps the original toolkit version metadata
- reuses the cached tool during execution instead of retrieving the same
schema twice
- adds behavior regressions for schema, before/after execution,
single-fetch execution, raw metadata preservation, and TypeScript parity
- verifies the Python regressions against both the current Stainless
client and `ComposioHQ/composio-client` at `605f508e`
2026-08-20 15:00:47 +02:00
Alberto Schiabel 09b552aa03 fix(py): disable retries on non-idempotent tool writes to prevent duplicate side effects (#3657)
This PR:

- stops the Python SDK from silently retrying `tools.execute` and
`tools.proxy`, which are non-idempotent POST writes. The
Stainless-generated client retries POSTs by default (`max_retries=2`) on
read timeouts, 429, 5xx, and connection errors. A read timeout is unsafe
to retry — the request may already be in flight on the backend — so a
retry can duplicate the side effect, e.g. send an email twice. Reported
in https://github.com/ComposioHQ/composio/issues/3586
- routes both write paths through a new `client.without_retries` — a
cached, retry-disabled (`max_retries=0`) clone of the `HttpClient`.
Reads and lists keep the default retries, so resilience is unchanged for
idempotent calls
- overrides `HttpClient.copy()` to re-inject the required `provider`
keyword and re-aliases `with_options`, since the generated `copy()`
rebuilds via `self.__class__(...)` without `provider` — previously
`with_options(max_retries=0)` raised `TypeError` on the subclass
- caches the no-retry sibling instead of cloning per call: each clone
creates a new `ContextVar`, and dynamically-created `ContextVar`s are
never garbage-collected
- adds `tests/test_no_retry_writes.py`: writes hit the transport exactly
once on a retryable 5xx, reads still retry-then-succeed (proving the
scoping), and a regression guard for the `copy()` override
- interim fix only — the durable solution is idempotency keys, tracked
in https://github.com/ComposioHQ/composio/issues/3654 (gated on backend
support), which supersedes this once available

No changeset (Python-only change; changesets are TypeScript-only).
2026-06-25 02:24:27 +04:00
Alberto Schiabel 2758287c87 feat(py): remove legacy custom tools (#3508)
This PR is **part 1 of 3** splitting
https://github.com/ComposioHQ/composio/pull/3505 to make the removal of
the old 2025 custom tools easier to review. It carries the **Python**
slice.

- removes the legacy `composio.tools.custom_tool` registry path:
`core.models.custom_tools`, `ExecuteRequestFn`, the old fallback
execution wiring, the security tests, and the example
- preserves the 2026 tool-router APIs: `composio.experimental.tool()`,
`composio.experimental.Toolkit`, inline custom-tool execution,
preload/attach/use flows, and `session.custom_tools()`
- bumps the Python workspace and all provider packages `0.13.1` →
`0.14.0`

## Notes

- This slice is a byte-identical subset of #3505 — the three split
branches recombine to that PR's exact tree. See #3505 for the original
local verification logs (`uv run --frozen nox -s chk`, targeted pytest);
CI re-runs per PR.
2026-06-04 23:53:26 -07:00
Dhawal Upadhyay eae717ac20 Clean up inline custom tools payload typing 2026-05-06 18:44:40 +05:30
Dhawal Upadhyay 490332887d Tighten inline custom execute typing 2026-05-06 18:23:53 +05:30
Dhawal Upadhyay d97fc8e17d Pass inline custom tools on session execute 2026-05-06 18:17:43 +05:30
Dhawal Upadhyay 82e0038c7c bump generated clients for v3.1 2026-05-05 14:44:43 +05:30
Dhawal Upadhyay fed23cdc56 fix(tool-router): use generated execute offload params 2026-04-30 17:52:44 +05:30
Dhawal Upadhyay 42035c835c fix(tool-router): opt agentic sessions into direct offload 2026-04-29 23:33:56 +05:30
Dhawal Upadhyay f846993a4d Add tool router preload support to Python SDK 2026-04-29 03:24:48 +05:30
Musthaq Ahamad ebc9778595 feat(sdk): default-off auto file upload/download; add dangerouslyAllowAutoUploadDownloadFiles (#3260)
## Summary

Automatic tool file upload/download for `file_uploadable` fields is
**off by default** in TypeScript and Python. Callers must explicitly opt
in, and uploads from local paths are constrained by a fail-closed
allowlist.

## Changes

- **Removed (breaking):** `autoUploadDownloadFiles` (TS) /
`auto_upload_download_files` (Python) — the legacy default-on flag is
gone, not just deprecated.
- **New opt-in:** `dangerouslyAllowAutoUploadDownloadFiles` (TS) /
`dangerously_allow_auto_upload_download_files` (Python). When `true`,
`tools.get(...)` collapses `file_uploadable` schemas to `{ type:
'string', format: 'path' }` and the SDK stages local paths/URLs at
execute time.
- **New:** `fileUploadDirs?: string[] | false` — fail-closed allowlist
for local upload paths. `undefined` → `[<home>/.composio/temp]`; `false`
→ reject all local paths (URLs / `File` objects unaffected); explicit
`string[]` replaces the default. Components are matched on a path
boundary after `realpath`.
- **New:** `fileDownloadDir?: string` — directory where
`file_downloadable` results are staged.
- **New:** `beforeFileUpload` hook receives `source: 'path' | 'url' |
'file'` (TS) / `'path' | 'url'` (Python) so it can branch on input type.
- **New (TS):** when auto-upload is **off** and an LLM-driven
`tools.execute` is called against a tool with `file_uploadable` inputs,
the SDK emits a one-shot warning per tool slug pointing at
`composio.files.upload()` for manual staging.

## Migration

To restore previous behavior:

```ts
new Composio({
  apiKey: process.env.COMPOSIO_API_KEY!,
  dangerouslyAllowAutoUploadDownloadFiles: true,
  // Optional: tighten the allowlist beyond the default ~/.composio/temp
  fileUploadDirs: ['/srv/uploads'],
});
```

```python
Composio(api_key="...", dangerously_allow_auto_upload_download_files=True)
```

If you previously passed the legacy flag, remove it. There is no
transitional warning — TS and Python both reject the unknown property at
the type/keyword-arg level.

## Versioning

| Package | Bump |
| ------- | ---- |
| `@composio/core` | minor |
| `composio` (Python) | minor |
| Other `@composio/*` packages | patch (via changesets
`updateInternalDependencies: "patch"`) |

See
`docs/content/changelog/04-24-26-legacy-auto-upload-config-removal.mdx`
for the full migration writeup.
2026-04-28 10:55:03 +05:30
Musthaq Ahamad 27ed0c9bd6 security(core): sensitive path blocklist + beforeFileUpload hook (patch) (#3262)
## Summary

Security-hardening for automatic file upload in `@composio/core` (patch
release per changeset).

### Changes
- **Default denylist** for local paths before auto-upload /
`files.upload`: blocks common credential directories (e.g. `.ssh`,
`.aws`) and credential-like filenames (e.g. `.env`, default SSH private
keys). Resolves symlinks when the path exists.
- **Config:** `sensitiveFileUploadProtection`,
`fileUploadPathDenySegments` on `Composio`.
- **`beforeFileUpload`** hook (e.g. with `composio.tools.get` /
`tools.execute`): rewrite path, return `false` to abort, or throw.
- **Errors:** `ComposioSensitiveFilePathBlockedError`,
`ComposioFileUploadAbortedError`; file modifier errors exported from
`@composio/core` errors entry.
- **Changeset:** patch bump for `@composio/core`.

### Notes
- URLs and `File` blobs are not subject to the path denylist
(unchanged).
- Opt out of path checks only if required:
`sensitiveFileUploadProtection: false`.

### Tests
- `pnpm test` in `ts/packages/core` (799 tests) passed locally before
commit.

Made with [Cursor](https://cursor.com)
2026-04-23 18:42:16 +05:30
jkomyno c04d6724ab fix(py): fix nested pydantic serialization 2026-02-11 21:23:33 +04:00
jkomyno c619487bf7 chore: fix conflicts 2026-02-09 14:42:16 +04:00
Alberto Schiabel ff1e89b7c2 feat(py): support type-safe generic get_tools() based on given provider (#2469)
Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-02-09 15:55:51 +05:30
jkomyno ee738a6b93 fix(py): cursorbot 2026-02-06 02:08:50 +04:00
Musthaq Ahamad c7e121706f Fix. Use dedicated tools endpoint for tool router (#2368) 2026-01-12 20:37:54 +05:30
Alberto Schiabel 2f879e8486 core(py): add auto_upload_download_files boolean flag to Composio() (#2334)
Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-01-12 16:31:29 +05:30
Musthaq Ahamad a76b002705 Feat: Add support for enable/disable tags and search in toolkits (#2305) 2025-12-24 16:36:17 +05:30
Musthaq Ahamad f97d191cc6 Add native tool execution support for tool router in python (#2266) 2025-12-12 22:17:10 +05:30
Musthaq Ahamad 3b10fafc03 Fix provider tool execution in py sdk (#2203) 2025-11-26 15:14:59 +05:30
Karan Vaidya e0bde197c7 Fix non-agentic tool execution (#2190)
Non-agentic providers now execute tools via a partial that skips version checks, aligning with agentic behavior while keeping direct calls strict.

Core tools (python/composio/core/models/tools.py):
Non-agentic providers: set_execute_tool_fn now passes functools.partial(self.execute, dangerously_skip_version_check=True) to skip version checks during provider-invoked executions, mirroring _wrap_execute_tool behavior for agentic providers.
2025-11-22 21:14:03 +05:30
Musthaq Ahamad 157bf7ba4e Fix Throw error when explicit toolkit version is not provided for manual execute (#2070) 2025-10-22 11:01:50 +05:30
prateek 65e4f94a1c Make tools proxy fail if wrong params (#2052) 2025-10-10 15:39:36 +05:30
Prateek d24a0433db Lint fixes 2025-10-03 13:21:03 +05:30
haxzie d7e13036c0 Fix formatting 2025-10-01 17:01:14 +05:30
Prateek 8286f20092 Solve all omit related issues 2025-10-01 16:12:21 +05:30
Musthaq Ahamad b750b06c60 Fix python sdk type issues (#1949) 2025-09-17 00:50:09 +05:30
Musthaq Ahamad 7077cee688 [WIP] Feat: Add versioning support for tools (#1926)
Co-authored-by: Jayesh Sharma <wjayesh@outlook.com>
2025-09-16 12:15:32 +05:30
angrybayblade 8829c6ce72 fix: sentinal value check 2025-08-27 16:49:24 +05:30
angrybayblade 63a28ccadd fix: user_id delegation in custom tool execution 2025-08-26 11:11:38 +05:30
angrybayblade 0b32a62304 fix: custom tool cache creation 2025-08-06 14:16:13 +05:30
angrybayblade 85fb5ef63c fix: custom tool fetching in tools.execute 2025-07-24 14:20:14 +05:30
angrybayblade 3b5585d126 fix: custom tool registry usage 2025-07-23 17:18:30 +05:30
lingalarahul7 cea1b4881d feat: support custom connection data arg in execute proxy and tool (#1766) 2025-07-21 17:14:47 +05:30
angrybayblade 8c69fa1e63 feat: make the file downloadable path configuerable 2025-07-21 13:05:38 +05:30
angrybayblade e8fc4dd225 fix: custom tools lookup before execution 2025-07-15 15:22:39 +05:30
angrybayblade 6493616bb5 fix: make deep copy of pydantic models when caching Tool objects 2025-07-03 13:17:50 +05:30
angrybayblade 92a64588cc feat: add scopes and limit filter on composio.tool.get 2025-06-20 19:40:52 +05:30
Viraj 8a4b5bc28a feat: add file upload/download utilities (#1669) 2025-06-19 19:00:47 +05:30
angrybayblade df8f1b7404 fix: python quickstart snippet 2025-06-18 14:24:15 +05:30
angrybayblade 5c5abceec9 feat: add get_raw_composio_tools and get_raw_composio_tool_by_slug 2025-06-18 12:17:56 +05:30
angrybayblade e6c3d3f063 chore: linters and formatting 2025-06-17 13:59:52 +05:30
angrybayblade 860b1c444a chore: port python sdk to python/ 2025-06-17 12:58:00 +05:30