Commit Graph

1579 Commits

Author SHA1 Message Date
Kshitij Jhunjhunwala 333b067885 Merge branch 'next' into kj/restore-install-plugin-setup 2026-09-14 13:04:15 -07:00
Kshitij Jhunjhunwala 14e81b00b3 fix(cli): restore automatic plugin setup on install 2026-09-14 12:59:56 -07:00
Brendan O'Leary dcd1ac953f Merge branch 'next' into codex/token-custody-architecture 2026-09-14 12:10:16 -07:00
Brendan O'Leary e7c585ead8 Merge branch 'next' into codex/token-custody-architecture 2026-09-14 11:29:38 -07:00
Brendan O'Leary c42fa6ffe6 docs: use Python and TypeScript examples in token custody guide 2026-09-14 18:26:31 +00:00
DakshM on Exe (exe.dev) 0a1464d5e8 perf(cli): move the compiler and tokenizer out of the executable
`composio --version` goes from 288ms to 199ms, peak RSS from 97.8MB to
77.3MB, and the executable from 85.9MB to 79.7MB. Every command benefits.

A compiled Bun binary parses its whole embedded bundle before the first
line of JavaScript runs, and #4468 had already made sure the TypeScript
compiler and the tokenizer rank table were never *evaluated* unless
`generate`, `run`, or a large `execute` response needed them. They were
still *parsed* on every start: the compiler alone was 44% of the
executable's JavaScript and the o200k rank table another 28%, so
`--version` spent ~75ms reading code it could never call.

Both now ship as companion modules next to the executable, through the
mechanism `composio run` already uses for its own runtime helpers:

- `generation-runtime.mjs` carries `src/generation/*`, the `composio run`
  source rewrites, `typescript`, `@composio/ts-builders` and
  `openapi-typescript`. `generate ts`, `generate py` and `run` load it
  with `loadInstalledCompanionModule`; from a source checkout the loader
  resolves the `.ts` next to `run-companion-modules.ts` instead, so tests
  and `bun run src/bin.ts` need no build step.
- `execute-output-encoder-runtime.mjs` carries `js-tiktoken/lite` and the
  rank table. `execute` loads it only once a response exceeds the 10KB
  byte pre-filter.

A companion bundles its own copy of `effect`, and a fiber cannot run
primitives built by another copy of the runtime, so nothing Effect-shaped
crosses the boundary: the generation companion exposes plain functions
and promises, runs its pipelines on its own runtime, and returns failures
as values that `src/generation/errors.ts` rebuilds as the CLI's own error
classes, stack included. Generated output is byte-identical to #4468 for
`generate ts`, `generate ts --transpiled` and `generate py`.

Both modules join `RUN_COMPANION_MODULE_BASENAMES`, so the build, release
packaging, install verification, `upgrade` and the self-repair download
pick them up unchanged. The three hand-maintained uninstall lists and the
upgrade E2E fixture gain the two file names.

Two smaller startup costs go with it:

- `src/constants.ts` imported `constants` from `@composio/core`'s root
  entry for two strings and two URLs, which evaluated the whole SDK at
  startup (~25ms of module-scope work, mostly zod schemas). The four
  values are spelled out and pinned to core's by a test.
- `tool-file-uploads.ts` imported three core helpers at module scope that
  only a file upload reaches; they are imported on that path now.

The binary build gains a guard: after bundling the companions it bundles
`src/bin.ts` once more unminified and fails if the executable's graph
reaches `typescript`, `js-tiktoken`, core's root entry, `src/generation/*`
or a companion entry. Without it a stray static import would put the
compiler back into the executable with nothing to notice.

Building also surfaced that `assertBundledRuntimeFiles` blanked string
literals to same-length runs of spaces, which made the import patterns'
`^\s*` backtrack quadratically across the compiler's multi-megabyte
embedded lib strings and stalled the build for over ten minutes. String
bodies are dropped now. (The check itself has never matched a specifier,
since the specifiers it looks for are the string literals it removes;
that is left as it was.)

Measured on the pinned toolchain, Bun 1.4.1+4661e494f, linux-x64, best
of 15, telemetry disabled, both binaries built in the same session:

  composio --version       288ms -> 199ms
  tools execute --help     287ms -> 202ms
  peak RSS                 97.8MB -> 77.3MB
  executable               85.9MB -> 79.7MB
  executable JavaScript    8.3MB -> 2.1MB (minified)

The `execute` tail after `execute.tool_call.end` is unchanged for
responses under 10KB (~10ms) and ~20ms slower above it (351 -> 374ms),
which is the on-demand parse of the 2.2MB encoder companion.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Wx9gEjuiHux2weiHjdNcDs
2026-09-14 15:52:49 +02:00
Brendan O'Leary 11706780b3 docs: preserve source tracking on contact links 2026-09-11 17:58:12 +00:00
Brendan O'Leary 4b295a5813 docs: update contact links with CTA placement 2026-09-11 17:53:35 +00:00
Brendan O'Leary 4c0c89b090 Remove fastmode as it isn't in the SDK yet 2026-09-11 09:52:33 -07:00
Brendan O'Leary 1a26ea0869 docs: document unattended agent authentication (#4434)
## Summary

Autonomous coding agents assumed Composio signup required a human,
leaving integrations without credentials or live verification. Add a
prominent guide for the supported `composio login --agent` flow when no
human is available.

Addresses Gauge action `cmtvu1rwe00040ip8mxhszmj1`. Reviewed the
metadata, insights, logs, and diffs for [evidence run
1](https://agents.withgauge.com/composio-aclx/runs/cmtvrts3n001201ea7jwbhu4q)
and [evidence run
2](https://agents.withgauge.com/composio-aclx/runs/cmtvrts3n001401eak0rwndar).
Both assumed signup required human interaction; the second attempted
disposable-email signup before switching to mocks.

## Changes

- Document unattended login, readiness checks, project API-key
extraction, credential handling, constraints, and the human login
fallback.
- Include a live Hacker News tool call and require separate verification
of the requested integration, including provider authorization and
confirmation of write results.
- Link the guide from the agent setup sidebar, quickstart, CLI docs, API
authentication reference, and `llms.txt`.

## Type of change

- [x] Documentation

## How Has This Been Tested?

From `docs/`:

- `bun run test`: 557 passed, 0 failed. Run with loopback access for the
analytics test's local server.
- `bun run lint:links`: 0 errors.
- `bun run lint`: passed with existing warnings.
- `bun run postinstall`: regenerated MDX collections successfully.

All five shell snippets pass `bash -n`. The key-extraction snippet
accepts a valid local fixture and rejects missing, blank, and non-string
keys without printing credentials. `git diff --check` passes. No live
account was provisioned or tool executed for this documentation change.

## Checklist

- [x] I ran linters/tests locally and they passed
- [x] I updated documentation as needed
- [x] I added tests or explain why not applicable: existing docs checks
and focused snippet validation cover this documentation-only change.
- [x] I added a changeset if this change affects published packages: not
applicable; no published package changes.
2026-09-11 08:25:59 -07:00
Brendan O'Leary 03f92ee026 docs: shorten unattended auth sidebar label 2026-09-11 15:20:02 +00:00
Brendan O'Leary 9968ea60ce Update docs/content/docs/security/token-custody.mdx
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-09-11 07:59:45 -07:00
Brendan O'Leary 0536957a38 docs: explain token custody architecture and deployment options 2026-09-11 14:44:44 +00:00
sdkrelease[bot] e265ff838a docs(kb): refresh public support knowledge (#4437)
Automated knowledge-base refresh for `ComposioHQ/support-knowledge`.

- Source commit: `5eac683455ff252a7a3b62f33ab6566445009b52` (unchanged;
rebuilt a stale semantic artifact)
- Regenerated public KB pages and search records
- Reused unchanged vectors and rebuilt the checked semantic artifact
- Ran KB freshness and semantic-artifact verification

Co-authored-by: sohambasu963 <80603154+sohambasu963@users.noreply.github.com>
2026-09-11 16:24:51 +02:00
Brendan O'Leary eb1d1e1d35 Merge branch 'next' into codex/docs-unattended-agent-auth 2026-09-10 16:33:20 -07:00
Brendan O'Leary abb272572b Merge branch 'next' into codex/docs-unattended-agent-auth 2026-09-10 16:22:29 -07:00
Brendan O'Leary ba84d94b02 Merge branch 'next' into docs/changelog-update-e2270d1 2026-09-10 16:22:21 -07:00
Brendan O'Leary 2ad6c8742f fix(docs): make semantic artifact freshness advisory in PR checks 2026-09-10 23:12:09 +00:00
Brendan O'Leary 1f44efb709 Merge branch 'next' into docs/changelog-update-e2270d1 2026-09-10 15:26:56 -07:00
Brendan O'Leary faaf37761c docs: update Python SDK reference from source (#4409)
## Summary
Auto-generated Python SDK reference docs from `python/composio/`.

Regenerates pages at `docs/content/reference/sdk-reference/python/` to
reflect changes in the Python package's public API (new methods, updated
signatures, changed types).
2026-09-10 15:23:13 -07:00
Brendan O'Leary 19c9fb2dc8 docs: document unattended agent authentication 2026-09-10 22:23:07 +00:00
Brendan O'Leary 64a48ba326 chore(docs): refresh semantic index after merging next 2026-09-10 13:06:32 -07:00
Brendan O'Leary ba69d58219 Merge remote-tracking branch 'origin/next' into codex/devrel-35-markdown-install 2026-09-10 13:05:41 -07:00
Brendan O'Leary 21ba266c1a chore(docs): regenerate semantic index for Markdown changes 2026-09-10 12:33:46 -07:00
Brendan O'Leary b972a93b22 fix(docs): improve homepage social preview 2026-09-10 12:05:26 -07:00
Brendan O'Leary f0399b4f9a docs: curate the agent routing map and separate the full index (#4426)
Replace the exhaustive `/llms.txt` dump with a short routing map for
product selection, installation, authentication, sessions, execution,
and troubleshooting. Keep the full catalog at `/llms-index.txt`, using
named links and descriptions, and put that catalog and other long-tail
resources under Optional. Current REST v3.1 and legacy v3.0 remain
explicitly separated.

Fixes [DEVREL-34](https://linear.app/composio/issue/DEVREL-34). The
format follows the descriptive-link and Optional conventions in the
[llms.txt proposal](https://llmstxt.org/).

Validation: 551 static tests passed, including bounded routing-map
coverage and route resolution. Typecheck, lint, and link validation
passed. Existing exhaustive-catalog coverage now tests
`/llms-index.txt`; the HTTP version-grouping test follows the new
catalog route. Existing lint warnings remain.
2026-09-10 12:03:26 -07:00
Brendan O'Leary b7cd83709e docs: add setup and skill guidance to llms.txt 2026-09-10 11:54:17 -07:00
Brendan O'Leary ae7956354e docs: expose release notes from agent-readable pages (#4427)
Agents reading individual pages or `/llms-full.txt` could miss the
Markdown changelog. Its dated `.md` links also matched a broad legacy
redirect and landed on HTML instead of release-note Markdown.

Link page Markdown and the full corpus to `/docs/changelog.md`, and
route dated `.md` and `.mdx` requests to the existing Markdown renderer
before the legacy HTML redirects. Add an HTTP regression that follows
quickstart → changelog → dated release and checks both extensions.

Fixes [DEVREL-31](https://linear.app/composio/issue/DEVREL-31).

Validation: typecheck, link validation, and all 551 static tests passed
for discovery. The new HTTP test reproduced the redirect defect locally
and in CI. The corrected combined production build passed. Its full HTTP
suite passed 92 tests with one existing API-key-dependent skip,
including dated .md and .mdx release-note checks. No new feed format or
dependency is added.
2026-09-10 11:52:23 -07:00
Brendan O'Leary 5f7e2af52c fix(docs): serve social preview images from the docs host (#4425)
The live docs advertise `https://og.composio.dev/api/og?title=Welcome`,
which returns HTTP 404 and breaks link previews. Serve 1200×630 PNG
previews from `/api/og` on the docs host and point the shared page
metadata and root metadata at that route. Titles are bounded to keep the
image readable and rendering work limited.

Fixes [DEVREL-41](https://linear.app/composio/issue/DEVREL-41).

Validation: reproduced the live 404, rendered and visually inspected the
replacement image, tested PNG signatures and dimensions for default,
normal, special-character, and long titles, and passed typecheck, lint,
and all 551 static tests. Existing lint warnings remain. No remote image
service or new dependency is required.
2026-09-10 11:49:09 -07:00
Brendan O'Leary 609918aee2 fix(docs): preserve dated Markdown changelog links through redirects 2026-09-10 11:27:46 -07:00
Brendan O'Leary 17ff9cce85 docs: expose release notes from agent-readable pages 2026-09-10 11:21:46 -07:00
Brendan O'Leary b7891d78fe docs: curate the agent routing map and separate the full index 2026-09-10 11:21:42 -07:00
Brendan O'Leary 37a647d1c4 fix(docs): serve social preview images from the docs host 2026-09-10 11:21:17 -07:00
Brendan O'Leary a18698787f fix(docs): preserve install commands and agent setup in Markdown 2026-09-10 11:19:55 -07:00
Brendan O'Leary d9e4b78653 docs: document the contribution and review workflow 2026-09-10 11:19:06 -07:00
Brendan O'Leary ce33bfb281 fix(docs): hide deprecated fields only in API playground (#4413)
Deprecated API fields clutter the interactive playground at the top of
reference pages. Hide those inputs while retaining their descriptions,
deprecation badges, defaults, and response examples in the reference
below.

Filter a cloned schema only inside the playground renderer. Keep the
shared OpenAPI loader unchanged and preserve synchronization between
playground edits, example selection, server selection, and generated
request code. Published OpenAPI files remain unchanged.

Validation: all 547 docs static tests pass, `bun run types:check`
passes, and `bun run lint` passes with existing warnings. Browser checks
on Create auth config confirm both auth variants omit deprecated inputs,
the JSON editor omits deprecated values, reference descriptions and
badges remain, and edits update the cURL example.

Fixes DEVREL-51.
2026-09-10 10:55:39 -07:00
Brendan O'Leary 947bfb4590 fix(docs): filter deprecated fields only in playground 2026-09-10 09:50:54 -07:00
Brendan O'Leary 60313e9e3d fix(docs): prevent copy page overlap on mobile 2026-09-10 09:37:40 -07:00
Brendan O'Leary 3cb6cf2217 Merge next into bdo/add-agent-setup-guide and rebuild semantic index 2026-09-10 08:48:33 -07:00
jkomyno 71aac53e9b docs: auto-generate Python SDK reference 2026-09-10 15:15:25 +00:00
sdkrelease[bot] 123905a81a docs: update toolkits, API spec, and meta tools data (#4414)
## Summary
Automated sync of backend data into the docs site.

- Trigger: `schedule`
- Dispatch action: `n/a`
- Source commit: `n/a`

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
2026-09-10 15:57:38 +02:00
Brendan O'Leary e4a05d2f45 docs: group launch guides under Production readiness 2026-09-09 16:36:52 -07:00
Brendan O'Leary e53db1823f fix(docs): hide deprecated fields from API reference 2026-09-09 16:13:32 -07:00
Brendan O'Leary 97c5ed9751 docs: add SIEM log collection guide for POC to prod 2026-09-09 16:11:56 -07:00
Tridhatri Vallamkondu a65db05b82 docs(sessions): simplify experimental fast mode wording 2026-09-09 14:01:52 -07:00
Tridhatri Vallamkondu bec7e4871d docs: refresh semantic index for fast mode guide 2026-09-09 13:58:06 -07:00
Tridhatri Vallamkondu ba49066bce docs(sessions): explain experimental fast mode 2026-09-09 13:53:46 -07:00
sdkrelease[bot] 2956831941 docs: update toolkits, API spec, and meta tools data (#4402)
## Summary
Automated sync of backend data into the docs site.

- Trigger: `schedule`
- Dispatch action: `n/a`
- Source commit: `n/a`

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
Co-authored-by: Sushmitha Mallesh <sushdec6@gmail.com>
2026-09-09 21:30:15 +02:00
sdkrelease[bot] dfdb1e286c docs: update Python SDK reference from source (#4380)
## Summary
Auto-generated Python SDK reference docs from `python/composio/`.

Regenerates pages at `docs/content/reference/sdk-reference/python/` to
reflect changes in the Python package's public API (new methods, updated
signatures, changed types).

Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-09-09 16:04:07 +02:00
sdkrelease[bot] 08402f81bb docs: update toolkits, API spec, and meta tools data (#4390)
## Summary
Automated sync of backend data into the docs site.

- Trigger: `schedule`
- Dispatch action: `n/a`
- Source commit: `n/a`

## What changed
- **Toolkit catalog** (`docs/public/data/toolkits.json`,
`toolkits-list.json`) — refreshed list of available toolkits, auth
schemes, and tools from the backend API
- **OpenAPI specs** (`docs/public/openapi.json`,
`docs/public/openapi-v3.json`, `docs/public/openapi-webhooks.json`) —
latest v3.1 and v3.0 API specifications plus the webhook-events spec,
fetched from production
- **API reference pages** (`docs/content/reference/api-reference/`,
`docs/content/reference/v3/api-reference/`) — regenerated index pages
for both API versions
- **Meta tools reference** (`docs/public/data/meta-tools.json`,
`docs/content/toolkits/meta-tools/*.mdx`) — updated meta tool schemas
and reference docs

Co-authored-by: Sushmithamallesh <19796925+Sushmithamallesh@users.noreply.github.com>
2026-09-09 15:58:04 +02:00