Commit graph

1929 commits

Author SHA1 Message Date
Prasanna A P
d0f3ab81e1 fix docs icons and strip comments 2026-09-30 14:44:32 -07:00
Dhravya Shah
ce4facf662
docs: branded OG thumbnails with photo background (#1729)
Some checks failed
Publish OpenAI SDK Python / publish (push) Has been cancelled
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 18:01:29 -07:00
Dhravya Shah
1b958f48c8
docs: explain advanced PDF extraction availability (#1728) 2026-09-29 17:40:50 -07:00
Parthiv
640eeaa8e8
docs: refresh the documentation design (#1715)
Co-authored-by: Dhravya Shah <dhravya@supermemory.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 17:26:13 -07:00
Dhravya Shah
0c74b55693
fix(docs): remove vulnerable ZIP extractor and patch tar via Mintlify (#1727) 2026-09-29 16:59:39 -07:00
Dhravya Shah
83f315fc17
fix(chatapp): patch high severity transitive dependencies (#1723) 2026-09-29 15:28:16 -07:00
Dhravya Shah
e7d7b78d90
fix(mcp): override vulnerable image and HTTP dependencies (#1722) 2026-09-29 15:28:02 -07:00
Dhravya Shah
cf4436bf4b
fix(raycast): patch high severity lockfile vulnerabilities (#1721) 2026-09-29 15:27:27 -07:00
Dhravya Shah
c4382f5ffc
fix(python-sdk): patch vulnerable async and tooling dependencies (#1720) 2026-09-29 15:26:59 -07:00
MaheshtheDev
10e464aac7 feat(mcp): group PostHog MCP tool calls by conversation id (#1718)
The server is stateless HTTP, so every tool call landed in its own PostHog session. Enable conversation ids and let $mcp_conversation_id and $session_id through the metadata filter so echoed handles group calls.
2026-09-29 20:32:36 +00:00
MaheshtheDev
b392bc7d1b Instrument MCP server with metadata-only PostHog analytics (#1712)
## Summary
- Instrument the MCP v2 server with the pinned PostHog MCP Analytics SDK and replace the custom `mcp_tool_executed` wrapper with standard `$mcp_*` events.
- Send only allowlisted metadata, disable schema injection and exception autocapture, and use personless user IDs with person-profile processing disabled.
- Deliver events through immediate capture guarded by Cloudflare `waitUntil`.

## Verification
- The initial implementation passed the MCP typecheck, existing unit suite, Biome, and Wrangler dry-run bundle.
- A local `who_am_i` MCP call returned successfully and emitted a metadata-only `$mcp_tool_call` on the initial implementation.
- All five checks passed on the final `54a2384` head, including the Cloudflare MCP build.

Actual PostHog ingestion is not verified yet; this workspace still needs a PostHog project token and authenticated Supermemory MCP credential.
2026-09-29 06:08:45 +00:00
sohamd22
cfa6c7cb17 fix(memory-graph): distinguish document links from derives relations (#1701)
Document-to-memory links and actual `derives` relations were both emitted as `derives`, so they shared the same color and legend entry.

This separates structural document links into a `document` edge type, adds a dedicated theme color with `--graph-edge-document` support, and updates force-layout and level-of-detail handling to preserve existing structural behavior. The package and MCP widget legends/themes now distinguish document links from derived-memory relations.

Adds regression coverage for edge classification and validates the package plus its MCP consumer.

<!-- capy-badge:start -->
<a href="https://capy.ai/thread/jam_01M36F4MPFXZCA8J14T53YY029"><picture><source media="(prefers-color-scheme: dark)" srcset="https://capy.ai/badge/accent-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://capy.ai/badge/accent-light.svg"><img alt="Open in Capy" src="https://capy.ai/badge/accent-light.svg"></picture></a>
<!-- capy-badge:end -->
2026-09-25 22:00:12 +00:00
Dhravya
0e12f0b3a6 fix(mcp): treat full-scope read grants as read-only 2026-09-22 18:22:26 -07:00
shardulmane10
57b430b5b6 Align billing and Gmail docs with current plan entitlements (#1685)
Some checks failed
Publish Memory Graph / publish (push) Has been cancelled
## Summary

The billing guide omits Max and contradicts the pricing page about Gmail access. Add Max ($100/month with $130 in monthly credits), correct the plan feature matrix, list all six current coding plugins as available on Free with credit-consuming usage, and update both remaining Scale-only requirements on the Gmail connector page to Max or above.

Clarify that paid-plan automatic top-up limits cap automatic credit purchases, not the total invoice, and correct the documented auto-topup update endpoint from PATCH to POST.

Companion website changes: https://github.com/supermemoryai/landing-2/pull/32

## Validation

- Compared prices, credit inclusions, connector gates, and top-up behavior with the console and API source on main. Verified that all six coding plugins are on FREE_TIER_PLUGIN_IDS and the authentication route bypasses the generic Pro gate for them. Usage still consumes plan credits.
- Checked Markdown table column counts and required Max entries; `git diff --check` passed.
- Confirmed the Gmail introduction, prerequisite, and troubleshooting requirement consistently say Max or above.
- Documentation-only change. A full Mintlify build was not run.

Crawler-access verification, AI-search benchmarking, and analytics/measurement work are excluded from this PR.
2026-09-18 22:01:05 +00:00
Prasanna721
8a4d9d76ae release memory graph 0.2.4 (#1686)
Before: npm serves 0.2.3 without the merged fixes.

After: merging publishes 0.2.4 with the theme, initial fit, and node settling fixes.

Validation: package typecheck and build passed.
2026-09-18 21:44:52 +00:00
Prasanna721
2a6dcda7f6 fix graph styling and initial layout (#1684)
**Before:** Console lost its theme and dots. Incoming nodes needed a drag to reorganize, fit missed later pages, and clicks or drag release could leave the layout moving.

**After:** Restore themed rendering with configurable dots. Automatically settle and fit incoming nodes, keep clicks from reheating forces, and cool the layout after drag release.

**Checked:** Package types/build and Console build linked to this package.

Console companion: [mono#3295](https://github.com/supermemoryai/mono/pull/3295).
2026-09-18 21:18:33 +00:00
polylane
b26e917a83 fix(ci): restore bun.lock so frozen dependency install passes (#1680)
**Fixes:** [supermemoryai/supermemory publishes SDKs to npm and PyPI on merge to main with no approval or CI gate](https://console.polylane.com/supermemory/threads/thrd_0b2312a59001ty7ozbknhwen?ref=github.autofix-pr)

The dependency lockfile on this branch had been regenerated by a different Bun version than the one CI pins, so the frozen-install step aborted and took down the quality gate and both Worker builds. Restoring the lockfile to the revision already on main lets those checks install dependencies and run again.

## What caused this

**Affected:** `int_ecd270c87001rlz8v4a308n0`

## Why this fix

Quality Checks (`CI - Type Check, Format & Lint`, run 35297979197) failed on commit f9aeae8 in 16 seconds: steps ran through checkout and bun setup, then step 4 `Install dependencies` failed at 02:05:55Z. Both Cloudflare builds, `Workers Builds: supermemory-app` and `Workers Builds: supermemory-mcp`, failed at the same second, before producing a build, so all three checks died on the same step rather than on any source change.

That commit also carried a regenerated `bun.lock` (401 insertions, 21 deletions) with no accompanying manifest edit, written by the sandbox's Bun 1.2.14 while CI pins `bun@1.3.6`. The regenerated file added `apps/raycast-extension` as a workspace even though the root manifest excludes it, and dropped the `configVersion` marker the pinned release expects. With the lockfile in that state, `bun install --frozen-lockfile` refuses to proceed.

I reproduced both directions with the CI-pinned release: Bun 1.3.6 against the commit's lockfile exits 1 with `lockfile had changes, but lockfile is frozen`, while Bun 1.3.6 against the restored lockfile succeeds (`15 packages installed`). The failing step is the install, and this change removes the mismatch it reads, so the install proceeds and the downstream checks can run.

The workflow edit itself is untouched and still pins the three third-party actions to the same commit SHAs the sibling Python publish workflows use. Reverting the lockfile removes an unrelated dependency-graph rewrite, so the published-artifact behaviour this pull request targets is unchanged.

<details>
<summary>1 file changed (+6/-4)</summary>

- `.github/workflows/publish-openai-sdk-python.yml`: modified, +6/-4

</details>

Repository lint: `bun run lint` (declared in CLAUDE.md) could not run in the sandbox because its tool is not installed there; run it before merging.

<a href="https://console.polylane.com/pages/page_0b2431438001t1tqtbrria8659s7c1o9lb9icrt4?token=eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJ0aHJkXzBiMjMxMmE1OTAwMXR5N296YmtuaHdlbiIsIndvcmtzcGFjZV9pZCI6IndzX2VjZDI2NGZlNjAwMTc0MG1mYXF3MHB2eTFiOXV3MnBpIiwicmVwb3NpdG9yeV9pZCI6InJlcG9fZWNkMjc0YTZjMDAxejJrNDJlbXBudGhpIiwib3duZXIiOiJzdXBlcm1lbW9yeWFpIiwicmVwbyI6InN1cGVybWVtb3J5IiwicHJfbnVtYmVyIjoxNjgwLCJpYXQiOjE3ODk2OTcyNzEsImF1ZCI6InBvbHlsYW5lOnByLXRocmVhZC1ndWVzdCIsImV4cCI6MTc5MjI4OTI3MSwiaXNzIjoiaHR0cHM6Ly9hcGkucG9seWxhbmUuY29tIn0.MVY_F-H8-bt2BXF7w4iN9d0HgfB6c_L0zeShWelJq1U&amp;ref=github.autofix-pr"><picture><source media="(prefers-color-scheme: dark)" srcset="https://badges.polylane.com/view-autofix/dark.svg?v=6&amp;face=1"><source media="(prefers-color-scheme: light)" srcset="https://badges.polylane.com/view-autofix/light.svg?v=6&amp;face=1"><img alt="View autofix" src="https://badges.polylane.com/view-autofix/light.svg?v=6&amp;face=1"></picture></a> <a href="https://console.polylane.com/supermemory/threads/thrd_0b2312a59001ty7ozbknhwen?ref=github.autofix-pr"><picture><source media="(prefers-color-scheme: dark)" srcset="https://badges.polylane.com/view-investigation/dark.svg?v=6"><source media="(prefers-color-scheme: light)" srcset="https://badges.polylane.com/view-investigation/light.svg?v=6"><img alt="View thread" src="https://badges.polylane.com/view-investigation/light.svg?v=6"></picture></a>

---

Generated by [Polylane](https://polylane.com/?ref=github.autofix-pr). You can ask follow-ups by mentioning @polylane in a comment.
2026-09-18 20:14:12 +00:00
Dhravya
bf2db3dc79
fix(ci): gate auto-fix to same-repo human runs (#1663)
## Summary

The `workflow_run` auto-fix job has write permissions and checks out the triggering PR branch. It now runs only when all three conditions hold:

- the tracked CI workflow failed on a pull request;
- the pull request branch belongs to this repository, not a fork;
- the triggering actor is not a bot account.

The same-repository check closes the privileged fork boundary. The generic `[bot]` suffix check covers Polylane, Graphite, Dependabot, and other GitHub App bot users without maintaining a name list.

## Validation

- `go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.12 .github/workflows/claude-auto-fix-ci.yml`
- YAML parse with the repository's installed parser
- Final diff audit: one workflow, +3/-1, no added comments

Human-triggered same-repository pull requests keep the existing auto-fix behavior.
2026-09-18 05:46:34 +00:00
Dhravya Shah
69327ca1c6
Add Muse Code plugin docs (#1674) 2026-09-17 09:36:04 -07:00
Dhravya Shah
c927c98f2c
feat(mcp): add get_profile and use snake_case for public tools (#1665) 2026-09-16 23:37:34 -07:00
Dhravya Shah
a92c21b2dc
chore(ci): disable Claude Code Review on pull requests (#1666) 2026-09-16 23:36:00 -07:00
Dhravya Shah
814f92731a
docs.json: 35 redirects for stale docs IA slugs (GSC Pages report) (#1673) 2026-09-16 20:46:20 -07:00
Prasanna
8652a0e5ea
add eve docs and refresh integrations (#1671) 2026-09-16 15:24:08 -07:00
karthik rajan
2415a5c796
fix(memory-graph): add aria-labels to zoom controls (#1662)
Signed-off-by: Karthik Rajan <karthikrajanmr@gmail.com>
2026-09-11 11:23:37 -07:00
Dhravya Shah
958ae8b619
fix(deps): bump next to 16.3.3 in chatapp, sdk-playground, and memory-graph-playground (#1655)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-09-09 23:01:32 -07:00
MaheshtheDev
5258cb74c8 chore(web): reduce the app to a redirect shell, drop the browser extension (#1651)
chore(web): reduce the app to a redirect shell, drop the browser extension

app.supermemory.ai now forwards everything to the console: plugin, OAuth and invite paths get an immediate 308 with the query intact, everything else shows a short notice first. Removes the browser extension workspace.

chore(web): give the moved notice a proper design

Hostnames become the headline, one primary action, a draining line for the countdown, DM Sans and the dot-grid backdrop from the brand.

chore(docs): point docs and README at the console, drop stale sections

Docs and both READMEs now link to console.supermemory.ai for API keys. Removed the company-brain docs tab with a redirect, and trimmed the README app section.

chore(web): give the redirect five seconds
2026-09-07 19:56:46 +00:00
MaheshtheDev
4d8a4ebfdd fix(mcp): let getDocument read any accessible document (#1641)
Some checks failed
Publish Pipecat SDK Python / publish (push) Has been cancelled
Publish Agent Framework Python / publish (push) Has been cancelled
Publish AI SDK / publish (push) Has been cancelled
Publish Cartesia SDK Python / publish (push) Has been cancelled
Publish OpenAI SDK Python / publish (push) Has been cancelled
Publish Tools / publish (push) Has been cancelled
getDocument filtered on the caller's active space, so an ID from listDocuments in any other space returned "Document not found". With activeSpace unset the fallback is sm_project_default, which broke most cross-space reads.

The API already scopes document reads to the caller's org, so the extra filter added no protection. Verified locally against the mono API: own-space and cross-space IDs now resolve, foreign-org IDs still 404.
2026-09-02 21:49:57 +00:00
Luv
9a0c5a5ad6
docs: fixed typo in graph-memory.mdx (#1640) 2026-09-02 10:07:03 -07:00
MaheshtheDev
17eab43cd4 docs: add Cursor and Grok Bot plugin pages (#1635)
Ship dedicated integration docs and point the plugin catalog at them. Grok Bot stays to install, auth, and skills — no Cursor-only config or repo tags.
2026-09-01 20:51:54 +00:00
Dhravya
4ad5f0beb1
feat(sdk-playground): reflect SDK-owned memory block in debug view (#1533)
## Stack Context

Part 3 (top) of a 3-PR stack moving memory deduplication into the SDKs. See `sdk-dedup/tools-ts` for full context.

## What?

Update the SDK playground so its debug view reflects the SDK-owned memory block.

- Displays the current deduplicated `<supermemory>` replacement block produced by the SDK middleware, instead of the old browser-side "seen facts" delta.
- Adds a `memory-dedupe` helper and ignores local `*.tsbuildinfo`.

## Why?

The previous debug cards were misleading — they showed an incremental browser-filtered delta while the middleware actually re-injected the full profile. Now the visualization matches what the SDK really sends.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Playground-only visualization and chat gating changes; no production SDK or API behavior.
>
> **Overview**
> The playground **debug trace** now shows the **deduplicated memory block** the SDK middleware would inject (static → dynamic → search, mode-aware), instead of a misleading browser-side “new facts” delta. A new **`memory-dedupe`** helper mirrors `@supermemory/tools` middleware behavior and is applied when fetching container context and building middleware memory debug entries; the context preview card is relabeled to reflect that each turn **replaces** the prior `<supermemory>` block.
>
> **Chat UX:** messaging is enabled when API keys are configured on the **server** (`hasSupermemoryKey` / `hasOpenAiKey` from `/api/chat`), not only when keys are typed in the panel. The message input stays editable while waiting for text; Send still requires non-empty input.
>
> Also ignores `*.tsbuildinfo` in `.gitignore`.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit ed15364eb3. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
2026-09-01 06:10:37 +00:00
Dhravya
03773c4f2e
feat(python-sdks): SDK-level cross-source memory deduplication (#1532)
## Stack Context

Part 2 of a 3-PR stack moving memory deduplication into the SDKs. See `sdk-dedup/tools-ts` (parent) for the full context and the TypeScript implementation this mirrors.

## What?

Port the normalized, priority-ordered (`static > dynamic > search`) profile deduplication into the Python SDKs.

- Each request injects one **owned memory block that replaces** the prior block rather than accumulating.
- Dedup is **request-local** (no shared state), so it stays correct under concurrency.

Covers OpenAI, Agent Framework (middleware + context provider), Cartesia, and Pipecat.

## Why?

Keeps the Python SDKs at behavioral parity with the TypeScript SDK so all integrations deduplicate memory the same way.

## Testing

- OpenAI: 31 passed, 11 skipped (live)
- Agent Framework: 59 passed
- Cartesia: 8 passed
- Pipecat: 8 passed

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes memory formatting and system-prompt injection across multiple SDK integrations; incorrect dedup or replacement could alter LLM context, but there is no auth or data-store risk.
>
> **Overview**
> Ports **normalized cross-source memory deduplication** and **replace-not-append injection** into the Python OpenAI, Agent Framework, Cartesia, and Pipecat packages so they match the TypeScript SDK behavior.
>
> **Deduplication** uses request-local keys: strip optional `[YYYY-MM-DD]` prefixes, normalize whitespace, and compare with `casefold`, with priority **static → dynamic → search**. In **`query` mode**, profile static/dynamic are excluded from dedup input so facts that only appear in search (or overlap profile) are not dropped before formatting.
>
> **Injection** no longer appends memory text every turn. OpenAI and Agent Framework middleware **strip prior owned `<supermemory context="user-memories" readonly>` blocks** and **replace** them once per request while keeping the caller’s system instructions; extra system messages lose stale blocks only. New helpers (`strip`/`replace`/`wrap`) live in each package’s utils.
>
> Tests cover normalized fact variants, query-mode search retention, and stale block replacement.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 42f308b224. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
2026-09-01 06:10:36 +00:00
Dhravya
d0f53b0d64
feat(tools): SDK-level cross-source memory deduplication (#1531)
## Stack Context

This stack moves memory deduplication **out of the playground UI and into the SDKs themselves**, so every integration injects a single, deduplicated, self-replacing memory block. Three PRs:

1. **`sdk-dedup/tools-ts`** (this PR) — TypeScript SDK core + integrations
2. `sdk-dedup/python` — Python SDKs
3. `sdk-dedup/playground` — playground debug view reflects the SDK-owned block

## What?

Move profile deduplication into the SDK middleware for the TypeScript tools package.

- Facts are normalized (strip leading `[YYYY-MM-DD]`, trim, collapse whitespace, casefold) and deduplicated in **`static > dynamic > search`** priority within a single request.
- The result is injected as one **owned `<supermemory>` block** that *replaces* the previous block instead of accumulating a new one each turn.
- Dedup is **mode-aware**: in query mode, search results are not dropped against a profile that isn't being injected.
- Deduplication is **request-local** — no global/browser `Set`. Safe for multiple users, concurrent requests, and Cloudflare Worker isolates.

Covers AI SDK, OpenAI (Chat + Responses), Mastra, and VoltAgent. New `shared/memory-context.ts` owns the block-replacement logic.

## Why?

The earlier "conversation-scoped deduplication" was only a playground browser `Set` — a UI debug affordance that did not change what the SDK sent to the model, and would have been unsafe as server-side global state. Real cross-source dedup belongs in the SDK, applied fresh per stateless model request.

## Testing

- `bun run test` in `packages/tools`: 145 passed (the one failing suite, `claude-memory.test.ts`, is a pre-existing broken import unrelated to this change).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes how system prompts and instructions are built across all TypeScript integrations; behavior is well-covered by unit tests but incorrect strip/replace logic could drop or duplicate context in production prompts.
>
> **Overview**
> Moves **cross-source memory deduplication** and **owned prompt injection** into `@supermemory/tools` so every integration sends one deduplicated memory block per request instead of growing context each turn.
>
> **Deduplication:** Facts are normalized via `normalizeMemoryFact` (strip `[YYYY-MM-DD]`, trim, collapse whitespace, lowercase) and deduplicated with **static → dynamic → search** priority. `deduplicateMemoriesForMode` keeps search hits in **query** mode when the profile is not injected.
>
> **Owned `<supermemory>` block:** New `shared/memory-context.ts` wraps memories in `<supermemory context="user-memories" readonly>`, strips stale blocks, and **replaces** prior SDK context while preserving caller system instructions. Applied in AI SDK (`injectMemoriesIntoParams`), OpenAI Chat/Responses middleware, Mastra input processor (`wrapMemoryContext`), and VoltAgent hooks.
>
> **Tests:** Unit coverage for block replacement (with-supermemory, OpenAI, VoltAgent), Mastra wrapper tag assertion, normalized dedup variants, and concurrent `containerTag` isolation.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 2fa2e0d85c. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
2026-09-01 06:10:36 +00:00
Dhravya
b01d2b69a3
feat(sdk-playground): interactive SDK chat playground (#1437)
## Summary
- Add `apps/sdk-playground` — chat UI to test TS/Python SDK integrations
- Context panel with document memories, API keys in dashboard, tools reference tab
- Python FastAPI server on port 8792; portless entry in `portless.json`

Stacked on #1436

## Test plan
- [ ] `cd apps/sdk-playground && bun run check-types`
- [ ] `bun run dev` with Supermemory + OpenAI keys in UI
- [ ] Switch SDKs and verify chat + context panel

Made with [Cursor](https://cursor.com)
2026-09-01 06:10:36 +00:00
Dhravya
7974498062
chore(ci): wire JS tools unit tests into CI (#1436)
## Summary
- Add tools/ai-sdk unit test jobs to `ci.yml`
- Update `turbo.json` and root `package.json` scripts
- Refresh `bun.lock`

Stacked on #1435

## Test plan
- [ ] CI passes on this branch

Made with [Cursor](https://cursor.com)
2026-09-01 06:10:36 +00:00
Dhravya
4173edb9e6
docs(skills): refresh Supermemory skill for 7-tool parity (#1435)
## Summary
- Update `SKILL.md` with proactive search and full 7-tool surface
- Refresh `sdk-guide.md` with v4 API examples and tool descriptions

Stacked on #1434

## Test plan
- [ ] Review skill content for accuracy

Made with [Cursor](https://cursor.com)
2026-09-01 06:10:36 +00:00
Dhravya
c262cc9953
fix(python-sdks): v4 API migration for integration packages (#1434)
## Summary
- **agent-framework**: proactive search tool descriptions
- **cartesia / pipecat**: v4 `client.add` + hybrid search, dedupe fixes, tests

Stacked on #1433

## Test plan
- [ ] pytest in agent-framework, cartesia, pipecat packages

Made with [Cursor](https://cursor.com)
2026-09-01 06:10:36 +00:00
Dhravya Shah
879ddd5c95
docs: clarify customer content is never used to train models on any plan (#1613)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-08-31 23:09:30 -07:00
Dhravya
46d1b53230
feat(ai-sdk): re-export 7-tool surface (#1433)
## Summary
- Re-export full tool set from `@supermemory/tools/ai-sdk`
- Add unit tests for tool re-exports

Stacked on #1432

## Test plan
- [ ] `bun run test:unit` in `packages/ai-sdk`

Made with [Cursor](https://cursor.com)
2026-09-01 05:59:58 +00:00
Dhravya
de3bbb3ce9
feat(tools): 7-tool parity and description refresh (#1432)
## Summary
- Refresh canonical tool descriptions in `tools-shared.ts`
- Align OpenAI and AI SDK tool bindings with 7-tool surface
- Export `TOOL_DESCRIPTIONS` / `PARAMETER_DESCRIPTIONS` from package index

Stacked on #1431

## Test plan
- [ ] `bun run test:unit` in `packages/tools`

Made with [Cursor](https://cursor.com)
2026-09-01 05:59:57 +00:00
Dhravya Shah
5fee2f2872
docs(mcp): fix grammar in ChatGPT web plugin description (#1630)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-08-31 21:46:32 -07:00
Dhravya Shah
ece20ff53e
chore(ci): Python SDK pytest workflow (#1431)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-31 21:39:36 -07:00
Dhravya
348483d5e8
feat(openai-sdk-python): 7-tool parity (#1430)
## Summary
- Expand `SupermemoryTools` from 2 tools to 7 (matches `@supermemory/tools`)
- Add `memory_forget` via shared HTTP helper
- Add document list/add/delete and get_profile tool surfaces
- Expand tests for new tools and execution paths

Stacked on #1429

## Test plan
- [x] `uv run pytest tests/test_tools.py::TestMemoryOperationsUnit`

Made with [Cursor](https://cursor.com)
2026-09-01 04:34:18 +00:00
Dhravya
c5b7e7d4fc
fix(openai-sdk-python): migrate to v4 Supermemory APIs (#1429)
## Summary
- Replace deprecated `search.execute` with `search.memories` (hybrid mode) in `search_memories`
- Replace `memories.add` with `client.add` in tools and middleware
- Fix middleware `container_tag` param (was incorrectly `container_tags`)
- Fix profile memory deduplication for string and Pydantic API items
- Bump `supermemory>=3.50` and `requires-python>=3.9`

## Test plan
- [x] `uv run pytest tests/test_tools.py::TestMemoryOperationsUnit`

Made with [Cursor](https://cursor.com)
2026-09-01 04:34:18 +00:00
MaheshtheDev
143024fa34 chore(web): forward legacy auth paths (#1631)
Forwards /auth/connect and /auth/agent-connect with the query string intact, and drops the pages they replaced.
2026-09-01 00:55:16 +00:00
MaheshtheDev
9ccd1b64c3 chore(web): clean up onboarding and dashboard surfaces (#1614)
Removes stale promo cards, banners, and the setup modal. Simplifies the onboarding entry so all new workspaces go through one flow.
2026-08-29 04:57:09 +00:00
Aditya kumar singh
d436792e77
docs: document self-hosted v0.0.5 model mixing bug and v0.0.7 resolution (#1450) (#1606) 2026-08-27 16:38:11 -07:00
MaheshtheDev
29c43984fe feat(web): pause Google Drive connect with a notify-me fallback (#1602)
![image.png](https://app.graphite.com/user-attachments/assets/6d7dd2cf-575b-450c-b7bb-c24b8ec834b9.png)

Google is not approving new authorizations while it re-reviews our app, so
every path that starts a new Google connection now shows a PAUSED badge and a
"Notify me" button instead of Connect.

- Existing connections are untouched: sync, file picking and history still work.
- Notify me fires a connector_paused_clicked PostHog event and remembers the
choice in localStorage, so we can pull who to email when the review clears.
- One list in lib/connector-availability.ts drives every surface; removing the
two entries turns Google back on.
2026-08-27 20:20:13 +00:00
MaheshtheDev
f11d8c4620 feat(web): drop the Web research row from Company Brain models (#1600)
The `research` / `researchEffort` model role no longer exists on the API,
so remove its card, its preset entries, and its types.
2026-08-26 19:07:56 +00:00
MaheshtheDev
9652478093 feat(web): offer a setup call alongside Slack install (#1599)
- First-landing modal on the Company Brain home: book a 30-min setup call, or install Slack yourself. Dismissal stored in localStorage.
- Setup call also reachable from a header icon, the user menu, and the onboarding research rail.
- Drops the desktop Invite button from the header; invite stays in the stats row and mobile menu.
2026-08-26 07:43:48 +00:00
MaheshtheDev
3f7b9667c6 chore: remove two dead onboarding routes and a note-content console.log (#1596)
Cherry-picks two cleanup PRs and finishes the job. Net 262 deletions.

- #1473 (@abhay-codes07): drops a `console.log` in the fullscreen note editor that printed the whole note body on every keystroke, which PostHog session replay can capture.
- #1563 (@ishaanxgupta): removes `/api/onboarding/research` and `/api/onboarding/extract-content`. Neither has a caller anywhere in the repo, and both spent metered Exa and xAI quota. This reverts the guards added for them in #1589, which only existed to make unreachable code safe.
- On top: `EXA_API_KEY`, `XAI_API_KEY` and the `@ai-sdk/xai` dependency are removed, since deleting those routes left them with no consumer.

Co-Authored-By: abhay-codes07 <182421137+abhay-codes07@users.noreply.github.com>
Co-Authored-By: ishaanxgupta <124028055+ishaanxgupta@users.noreply.github.com>
2026-08-25 10:19:47 +00:00