This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to next, this PR will be updated. # Releases ## @composio/claude-agent-sdk@0.12.0 ### Minor Changes -9447932: Dereference internal $ref/$defs in tool input schemas before provider translation, so properties reachable only through a reference keep their types and validation instead of degrading to untyped (z.any) or being emitted as a dangling reference. This changes the JSON Schema these providers emit for $ref-using tools. Downstream snapshot tests on tool definitions will see diffs. Schemas the Composio API ships with a $ref but no $defs block (e.g. GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than throwing. The strict-structured-outputs path of @composio/openai-agents is unchanged — OpenAI supports $defs/$ref natively, including recursion. ## @composio/google@0.11.0 ### Minor Changes -9447932: Dereference internal $ref/$defs in tool input schemas before provider translation, so properties reachable only through a reference keep their types and validation instead of degrading to untyped (z.any) or being emitted as a dangling reference. This changes the JSON Schema these providers emit for $ref-using tools. Downstream snapshot tests on tool definitions will see diffs. Schemas the Composio API ships with a $ref but no $defs block (e.g. GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than throwing. The strict-structured-outputs path of @composio/openai-agents is unchanged — OpenAI supports $defs/$ref natively, including recursion. ## @composio/langchain@0.11.0 ### Minor Changes -9447932: Dereference internal $ref/$defs in tool input schemas before provider translation, so properties reachable only through a reference keep their types and validation instead of degrading to untyped (z.any) or being emitted as a dangling reference. This changes the JSON Schema these providers emit for $ref-using tools. Downstream snapshot tests on tool definitions will see diffs. Schemas the Composio API ships with a $ref but no $defs block (e.g. GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than throwing. The strict-structured-outputs path of @composio/openai-agents is unchanged — OpenAI supports $defs/$ref natively, including recursion. ## @composio/llamaindex@0.11.0 ### Minor Changes -9447932: Dereference internal $ref/$defs in tool input schemas before provider translation, so properties reachable only through a reference keep their types and validation instead of degrading to untyped (z.any) or being emitted as a dangling reference. This changes the JSON Schema these providers emit for $ref-using tools. Downstream snapshot tests on tool definitions will see diffs. Schemas the Composio API ships with a $ref but no $defs block (e.g. GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than throwing. The strict-structured-outputs path of @composio/openai-agents is unchanged — OpenAI supports $defs/$ref natively, including recursion. ## @composio/openai-agents@0.11.0 ### Minor Changes -9447932: Dereference internal $ref/$defs in tool input schemas before provider translation, so properties reachable only through a reference keep their types and validation instead of degrading to untyped (z.any) or being emitted as a dangling reference. This changes the JSON Schema these providers emit for $ref-using tools. Downstream snapshot tests on tool definitions will see diffs. Schemas the Composio API ships with a $ref but no $defs block (e.g. GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than throwing. The strict-structured-outputs path of @composio/openai-agents is unchanged — OpenAI supports $defs/$ref natively, including recursion. ## @composio/vercel@0.12.0 ### Minor Changes -9447932: Dereference internal $ref/$defs in tool input schemas before provider translation, so properties reachable only through a reference keep their types and validation instead of degrading to untyped (z.any) or being emitted as a dangling reference. This changes the JSON Schema these providers emit for $ref-using tools. Downstream snapshot tests on tool definitions will see diffs. Schemas the Composio API ships with a $ref but no $defs block (e.g. GMAIL_FETCH_EMAILS) degrade to a permissive object schema rather than throwing. The strict-structured-outputs path of @composio/openai-agents is unchanged — OpenAI supports $defs/$ref natively, including recursion. ## @composio/core@0.18.1 ### Patch Changes -8a56383: Fix: automatic S3 file downloads are now capped at 100 MiB (configurable per call) to prevent memory exhaustion from oversized or streaming responses. -7420927: Fix custom toolkit child slug mapping: reject response tools that have local handles but no exact toolkit match instead of silently dropping them or binding another toolkit's handler, derive bare-slug ambiguity from local definitions, and only reuse a same-toolkit bare alias in customToolkits(). -1d31c80: Redact credential-shaped values at the SDK log boundary. -95f9d32: Expose the runtime-conditional SSRF-safe fetch helper for protected URL upload consumers. -0d28bef: Map file-download transport failures to the SDK error contract and bound streamed response bodies. -52efb5b: Fix trigger subscriptions ignoring the `authConfigId` filter. - Updated dependencies [ab289d6] - @composio/json-schema-to-zod@0.3.2 ## @composio/experimental@0.2.4 ### Patch Changes -4e633d1: Update TypeBox to 1.3.18. ## @composio/json-schema-to-zod@0.3.2 ### Patch Changes -ab289d6: Preserve Draft 7 acceptance across primitive, composed, referenced, conditional, and typeless schemas. Enforce sibling and object/array assertions, retain positional tuple and `additionalItems` behavior, and prevent native Zod materialization from rejecting values already accepted by the source schema. ## @composio/openai@0.12.2 ### Patch Changes -620075a: Fix: stop printing MCP server URLs (credential-bearing) to stdout via console.log in the OpenAI Responses provider; log server names via logger.debug instead. ## @composio/slim@0.18.1 ### Patch Changes - Updated dependencies [ab289d6] - @composio/json-schema-to-zod@0.3.2 ## @e2e-tests/cf-workers-basic@0.0.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## @e2e-tests/cf-workers-files@0.0.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## @e2e-tests/cf-workers-tool-router-ai@0.0.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/vercel@0.12.0 ## @e2e-tests/node-claude-agent-sdk@0.0.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/claude-agent-sdk@0.12.0 ## @e2e-tests/node-custom-tools@0.0.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## @e2e-tests/node-json-schema-to-zod-v3@0.0.2 ### Patch Changes - Updated dependencies [ab289d6] - @composio/json-schema-to-zod@0.3.2 ## @e2e-tests/node-json-schema-to-zod-v4@0.0.2 ### Patch Changes - Updated dependencies [ab289d6] - @composio/json-schema-to-zod@0.3.2 ## @e2e-tests/node-mastra-tool-router-zod-v3@0.0.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/mastra@0.10.4 ## @e2e-tests/node-mastra-tool-router-zod-v4@0.0.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/mastra@0.10.4 ## @e2e-tests/node-tool-router-files@0.0.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## @e2e-tests/node-tool-router-pagination@0.0.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## anthropic-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/claude-agent-sdk@0.12.0 - @composio/anthropic@0.11.1 ## connected-accounts-example@0.1.11 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## error-handling-example@0.1.11 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## file-handling-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## google-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/google@0.11.0 ## json-schema-to-zod-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/vercel@0.12.0 ## langchain-example@0.1.11 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/langchain@0.11.0 ## llamaindex-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/llamaindex@0.11.0 ## mastra-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/mastra@0.10.4 ## mcp-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/vercel@0.12.0 ## modifiers-example@0.1.11 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/vercel@0.12.0 ## openai-example@0.1.11 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [620075a] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/openai-agents@0.11.0 - @composio/openai@0.12.2 ## session-management-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## tool-router-example@1.0.12 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/claude-agent-sdk@0.12.0 - @composio/vercel@0.12.0 - @composio/openai-agents@0.11.0 ## toolkits-example@0.1.11 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/vercel@0.12.0 ## tools-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/vercel@0.12.0 ## triggers-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## vercel-example@0.1.11 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [9447932] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 - @composio/vercel@0.12.0 ## versioning-example@0.1.2 ### Patch Changes - Updated dependencies [8a56383] - Updated dependencies [7420927] - Updated dependencies [1d31c80] - Updated dependencies [95f9d32] - Updated dependencies [0d28bef] - Updated dependencies [52efb5b] - @composio/core@0.18.1 ## @composio/json-schema-to-effect-schema@0.1.1 ### Patch Changes -ab289d6: Translate draft-4 boolean `exclusiveMinimum`/`exclusiveMaximum` flags (as emitted by OpenAPI 3.0 exporters) into their Draft 7 numeric spelling so exclusive bounds are enforced instead of silently ignored. Co-authored-by: sdkrelease[bot] <294075132+sdkrelease[bot]@users.noreply.github.com>
Composio TypeScript examples
Each directory here is its own private workspace package (<name>-example) showing one integration or feature: openai/, anthropic/, langchain/, connected-accounts/, tools/, triggers/, mcp/, tool-router/, and more.
Run one example
cd ts
pnpm install
out=$(node ../scripts/examples-provision.mjs) && eval "$out"
pnpm --filter openai-example start
pnpm --filter <package-name> start runs the example with bun (see the scripts.start entry in that package's package.json). Some packages expose extra entrypoints alongside start, for example openai-example also has start:chat-completion, start:assistant, and start:mcp — check the package's package.json for the full list.
Configuration
Examples read configuration from environment variables and fail loudly, naming the missing variable, if one isn't set:
COMPOSIO_API_KEY— always required.COMPOSIO_EXAMPLES_USER_ID— the user id examples act as.COMPOSIO_EXAMPLES_{GMAIL,GITHUB,SLACK}_AUTH_CONFIG_IDandCOMPOSIO_EXAMPLES_{GMAIL,GITHUB,SLACK}_CONNECTED_ACCOUNT_ID— per-toolkit auth config and standing connected account.COMPOSIO_EXAMPLES_APIKEY_AUTH_CONFIG_IDandCOMPOSIO_EXAMPLES_APIKEY_PLACEHOLDER— the serpapi API-key auth config and its placeholder key value.OPENAI_API_KEY/ANTHROPIC_API_KEY— only needed by examples that call that LLM provider.
node ../scripts/examples-provision.mjs (run from ts/, or node scripts/examples-provision.mjs from the repo root) checks a Composio project for this state, prints a report to stderr, and prints export COMPOSIO_EXAMPLES_*=... lines to stdout. Load them with out=$(node ../scripts/examples-provision.mjs) && eval "$out". Capture first, then eval. eval "$(...)" reports the status of the text it evaluates, so it would hide a failed provisioning run. It's idempotent — it verifies what already exists and only creates what's missing — and it never prints credential values.
Add --initiate-missing to also start an OAuth connection request for any toolkit (gmail, googledrive, github, slack) that has no active connected account yet; it prints an authorization URL to visit once in a browser. The serpapi API-key auth config is created automatically, no browser step needed.
Run node ../scripts/examples-provision.mjs --gc to delete what example runs leave behind: connected accounts that never reached ACTIVE, surplus serpapi demo accounts, and MCP configs from earlier runs. It skips anything created in the last 24h and only touches resources the examples created. It deletes for real, so preview it with --gc --dry-run first and point it only at the disposable examples project.
A note on connection examples
Examples that demonstrate creating a connection (for example connected-accounts/) only initiate the OAuth flow and print a line like Please visit the following URL to authorize the user: ... — running them does not require you to complete that authorization. Examples that use a connection (calling a tool through Gmail, GitHub, or Slack) rely on the standing connected accounts that the provisioning script already verified are active.