Files
composiohq__composio/ts
Alberto Schiabel 1d31c80eff fix(sdk): keep credentials private in storage and logs (#4318)
## Summary

- write CLI user data, pending login sessions, and agent identities
through one atomic `0600` helper
- repair `0644` credential files created by older CLI versions before
reading them
- redact credential-shaped structured values from CLI user-context
diagnostics
- redact secret-shaped text at both TypeScript and Python SDK log-output
boundaries, including Pusher `auth` responses and exception tracebacks
- preserve Python logger compatibility: errors remain untruncated,
disabled levels remain lazy, and malformed placeholders cannot expose
arguments

## Local reproduction

Under the normal `022` umask, `next` created a plaintext credential file
with mode `0644`. The pre-fix CLI user-context and TypeScript SDK debug
paths also emitted sentinel credentials. The private atomic writer
changes an existing `0644` target to `0600`, and the upgrade tests now
prove all three legacy credential files are tightened without changing
their contents.

## Verification

- CLI permission upgrade tests: 31 passed across user data, pending
login, and agent identity paths
- CLI source and test typechecks passed
- TypeScript core logging, redaction, and Pusher tests: 17 passed
- TypeScript core source and type-test typechecks passed
- Python logging regression tests: 5 passed
- focused Ruff, Prettier, Oxlint, and `git diff --check` passed

The focused CLI runner needed a temporary local alias for the
pre-existing missing `#ssrf_guard` mapping in the CLI Vitest config. The
alias was removed after verification and is not part of this PR.

## Contributor context

Credit to **Syed Anas Mohiuddin**, independent security researcher, for
reporting the legacy CLI credential-file permission issue.

Supersedes [#4300](https://github.com/ComposioHQ/composio/pull/4300) ·
[Glen review](https://app.tryglen.com/ComposioHQ/composio/pull/4300).
The implementation also covers agent credentials, retains atomic writes,
and applies redaction at the shared SDK logging boundary.
2026-09-03 01:45:11 +02:00
..

Composio TypeScript workspace

This directory contains the TypeScript half of the Composio SDK monorepo: the core SDK, provider adapters, the CLI, examples, and end-to-end tests. For an overview of Composio itself, start at the root README and docs.composio.dev.

If you just want to use the SDK:

npm install @composio/core
import { Composio } from '@composio/core';

const composio = new Composio({ apiKey: process.env.COMPOSIO_API_KEY });

const session = await composio.create('user_123');
const tools = await session.tools();

See the @composio/core README and the quickstart for the full flow, including provider setup for your agent framework.

Packages

Published packages:

Package Description
@composio/core The Composio SDK. Ships its TypeScript source and SDK docs so installed copies are inspectable by coding agents.
@composio/slim Same API as @composio/core without the packaged source and docs; smaller install.
composio CLI Standalone CLI binary: search, execute, and script tools from your shell.
@composio/* providers Adapters that format Composio tools for agent frameworks (OpenAI, Anthropic, Vercel AI SDK, LangChain, and more). See the provider table.
@composio/experimental Experimental integrations, currently the Pi provider.
@composio/json-schema-to-zod JSON Schema to Zod conversion.

Internal (unpublished) packages: cli-keyring and cli-local-tools support the CLI; ts-builders generates TypeScript source.

Layout

ts/
  packages/        Published and internal packages (see above)
  examples/        Runnable examples per feature and framework
  e2e-tests/       Runtime E2E tests (Node, Deno, Cloudflare Workers, CLI)
  docs/            Workspace SDK docs: API notes and internal guides
  scripts/         Build, validation, and scaffolding scripts
  vendor/          Read-only reference submodules; do not edit

Development

Commands run from the repository root. Install the pinned toolchain first:

mise install
pnpm install

Build and verify:

pnpm build:packages   # build all TS packages
pnpm typecheck        # typecheck all TS packages
pnpm lint:packages    # oxlint over ts/packages
pnpm test             # package unit tests plus example validation

Runtime E2E suites (require credentials):

pnpm test:e2e:node
pnpm test:e2e:deno
pnpm test:e2e:cloudflare
pnpm test:e2e:cli

Scaffolding:

pnpm create:provider <name> [--agentic]   # new provider package
pnpm create:example <name>                # new example under ts/examples

Changesets are required for changes to published packages; see the contribution guidelines.

Support