Commit graph

1551 commits

Author SHA1 Message Date
Soham Daga
3803cd703f docs(api): v5 list limit caps at 100 2026-10-05 16:45:24 -07:00
Soham Daga
46ec7277ea docs(api): note related memory ids in v5 search 2026-10-05 16:45:24 -07:00
Soham Daga
c5e4073810 docs(api): document v5 list pagination defaults 2026-10-05 16:12:03 -07:00
Soham Daga
a0b059a886 docs(api): document 202 for v5 async ingest 2026-10-05 16:12:03 -07:00
Soham Daga
8f8af5edff docs(api): document v5 delete count and search isInference 2026-10-05 16:11:55 -07:00
Soham Daga
ecb2db59b5 docs(api): rename v5 attach to include 2026-10-05 13:49:06 -07:00
Dhravya Shah
b114063d39 Merge branch 'api-v5-docs/versioned-reference' into api-v5-docs/migration-guide
# Conflicts:
#	apps/docs/docs.json
2026-09-29 18:27:07 -07:00
Dhravya Shah
a11da2e5b1 Merge remote-tracking branch 'origin/main' into api-v5-docs/versioned-reference
# Conflicts:
#	apps/docs/docs.json
2026-09-29 18:26:49 -07:00
Dhravya Shah
60fd86132d docs(api): SDK, tools and CLI status in the v5 migration guide
- New "SDKs, tools and the CLI" section: TypeScript SDK is v5 from
  5.0.0-rc.5 (earlier RCs still v3/v4), Python SDK and @supermemory/tools
  still on v3/v4, CLI and `supermemory local` unaffected; v4 -> v5 SDK
  call map and dropped methods, linking the SDK's MIGRATION.md
- Link /v5/reference and /reference to api.supermemory.ai
- List conversation ingestion and container-tag merges as having no v5
  replacement

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 18:24:56 -07:00
Dhravya Shah
ce4facf662
docs: branded OG thumbnails with photo background (#1729)
Some checks failed
Publish OpenAI SDK Python / publish (push) Has been cancelled
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 18:01:29 -07:00
Dhravya Shah
1b958f48c8
docs: explain advanced PDF extraction availability (#1728) 2026-09-29 17:40:50 -07:00
Dhravya Shah
0a9b796f85 Merge branch 'main' of https://github.com/supermemoryai/supermemory into api-v5-docs/migration-guide
# Conflicts:
#	apps/docs/docs.json
2026-09-29 17:36:12 -07:00
Parthiv
640eeaa8e8
docs: refresh the documentation design (#1715)
Co-authored-by: Dhravya Shah <dhravya@supermemory.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 17:26:13 -07:00
Dhravya Shah
0c74b55693
fix(docs): remove vulnerable ZIP extractor and patch tar via Mintlify (#1727) 2026-09-29 16:59:39 -07:00
Dhravya Shah
e7d7b78d90
fix(mcp): override vulnerable image and HTTP dependencies (#1722) 2026-09-29 15:28:02 -07:00
Dhravya Shah
cf4436bf4b
fix(raycast): patch high severity lockfile vulnerabilities (#1721) 2026-09-29 15:27:27 -07:00
MaheshtheDev
10e464aac7 feat(mcp): group PostHog MCP tool calls by conversation id (#1718)
The server is stateless HTTP, so every tool call landed in its own PostHog session. Enable conversation ids and let $mcp_conversation_id and $session_id through the metadata filter so echoed handles group calls.
2026-09-29 20:32:36 +00:00
MaheshtheDev
b392bc7d1b Instrument MCP server with metadata-only PostHog analytics (#1712)
## Summary
- Instrument the MCP v2 server with the pinned PostHog MCP Analytics SDK and replace the custom `mcp_tool_executed` wrapper with standard `$mcp_*` events.
- Send only allowlisted metadata, disable schema injection and exception autocapture, and use personless user IDs with person-profile processing disabled.
- Deliver events through immediate capture guarded by Cloudflare `waitUntil`.

## Verification
- The initial implementation passed the MCP typecheck, existing unit suite, Biome, and Wrangler dry-run bundle.
- A local `who_am_i` MCP call returned successfully and emitted a metadata-only `$mcp_tool_call` on the initial implementation.
- All five checks passed on the final `54a2384` head, including the Cloudflare MCP build.

Actual PostHog ingestion is not verified yet; this workspace still needs a PostHog project token and authenticated Supermemory MCP credential.
2026-09-29 06:08:45 +00:00
Mahesh Sanikommu
4d6fc3a9a2 docs(api): deprecation banner, agent prompt first, legacy callout, v5 overview icons 2026-09-28 19:29:58 -07:00
Mahesh Sanikommu
e8561ff714 docs(api): lowercase v3/v4/v5 across migration and reference pages 2026-09-28 19:29:48 -07:00
sohamd22
cfa6c7cb17 fix(memory-graph): distinguish document links from derives relations (#1701)
Document-to-memory links and actual `derives` relations were both emitted as `derives`, so they shared the same color and legend entry.

This separates structural document links into a `document` edge type, adds a dedicated theme color with `--graph-edge-document` support, and updates force-layout and level-of-detail handling to preserve existing structural behavior. The package and MCP widget legends/themes now distinguish document links from derived-memory relations.

Adds regression coverage for edge classification and validates the package plus its MCP consumer.

<!-- capy-badge:start -->
<a href="https://capy.ai/thread/jam_01M36F4MPFXZCA8J14T53YY029"><picture><source media="(prefers-color-scheme: dark)" srcset="https://capy.ai/badge/accent-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://capy.ai/badge/accent-light.svg"><img alt="Open in Capy" src="https://capy.ai/badge/accent-light.svg"></picture></a>
<!-- capy-badge:end -->
2026-09-25 22:00:12 +00:00
Dhravya
0e12f0b3a6 fix(mcp): treat full-scope read grants as read-only 2026-09-22 18:22:26 -07:00
Soham Daga
ec8e3aedb4
chore(docs): run Mintlify development with Node 22 (#1692) 2026-09-19 22:42:08 -07:00
Soham Daga
e47336737e docs(api): add V3/V4 to V5 migration guide
## Stack context

This is the second PR in the V5 documentation stack, on top of the versioned API reference.

## What and why

Add an agent-oriented V3/V4 to V5 migration guide covering document ingestion and updates, content management, search, profiles, forgetting, namespaces, organization settings, typed filters, and rollout verification. Shared snippets keep the comprehensive guide and focused topic pages consistent.

```mermaid
flowchart LR
  Legacy[Legacy integration inventory] --> Mapping[Domain migration guidance]
  Mapping --> V5[V5 requests and response readers]
  V5 --> Verify[Side-by-side verification and rollout]
```

## Validation

- Verified all 11 migration navigation entries resolve to authored pages.
- Verified all imports across 23 migration and snippet files resolve.
- `git diff --check` passed.
- Mintlify build validation passed against the local generated V5 OpenAPI snapshot.

## Impact

Documentation only. The guide explicitly covers changed defaults, removed operations, partial failures, namespace isolation, and rollback-oriented side-by-side testing.
2026-09-19 21:49:47 -07:00
Soham Daga
f55fe00e32 docs(api): add versioned V5 API reference
## Stack context

This is the first PR in the V5 documentation stack. The migration guide and local-development wrapper build on it.

## What and why

Add Legacy and Latest versions to the API Reference navigation, organize all V5 operations by user workflow, and introduce concise overview pages for each domain. The Latest reference consumes the authoritative `/v5/openapi` document published by the Mono API stack.

```mermaid
flowchart LR
  Legacy[Legacy V3/V4 OpenAPI] --> Selector[Reference version selector]
  V5[V5 OpenAPI] --> Selector
  Selector --> Pages[Version-specific endpoint pages]
```

The `GET /ns` compatibility alias remains in the OpenAPI document but is intentionally omitted from navigation in favor of `GET /namespaces`.

## Validation

- Parsed `docs.json` successfully with `jq`.
- Compared navigation against the generated V5 schema: 22 displayed operations, 23 schema operations, with only `GET /ns` intentionally omitted.
- Mintlify build validation passed against the local generated V5 OpenAPI snapshot.

## Deployment dependency

The committed source is `https://api.supermemory.ai/v5/openapi`, which returns 404 until Mono PR #3306 and its API stack are deployed. Merge this PR after that endpoint is live.
2026-09-19 21:49:42 -07:00
shardulmane10
57b430b5b6 Align billing and Gmail docs with current plan entitlements (#1685)
Some checks failed
Publish Memory Graph / publish (push) Has been cancelled
## Summary

The billing guide omits Max and contradicts the pricing page about Gmail access. Add Max ($100/month with $130 in monthly credits), correct the plan feature matrix, list all six current coding plugins as available on Free with credit-consuming usage, and update both remaining Scale-only requirements on the Gmail connector page to Max or above.

Clarify that paid-plan automatic top-up limits cap automatic credit purchases, not the total invoice, and correct the documented auto-topup update endpoint from PATCH to POST.

Companion website changes: https://github.com/supermemoryai/landing-2/pull/32

## Validation

- Compared prices, credit inclusions, connector gates, and top-up behavior with the console and API source on main. Verified that all six coding plugins are on FREE_TIER_PLUGIN_IDS and the authentication route bypasses the generic Pro gate for them. Usage still consumes plan credits.
- Checked Markdown table column counts and required Max entries; `git diff --check` passed.
- Confirmed the Gmail introduction, prerequisite, and troubleshooting requirement consistently say Max or above.
- Documentation-only change. A full Mintlify build was not run.

Crawler-access verification, AI-search benchmarking, and analytics/measurement work are excluded from this PR.
2026-09-18 22:01:05 +00:00
Dhravya Shah
69327ca1c6
Add Muse Code plugin docs (#1674) 2026-09-17 09:36:04 -07:00
Dhravya Shah
c927c98f2c
feat(mcp): add get_profile and use snake_case for public tools (#1665) 2026-09-16 23:37:34 -07:00
Dhravya Shah
814f92731a
docs.json: 35 redirects for stale docs IA slugs (GSC Pages report) (#1673) 2026-09-16 20:46:20 -07:00
Prasanna
8652a0e5ea
add eve docs and refresh integrations (#1671) 2026-09-16 15:24:08 -07:00
Dhravya Shah
958ae8b619
fix(deps): bump next to 16.3.3 in chatapp, sdk-playground, and memory-graph-playground (#1655)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-09-09 23:01:32 -07:00
MaheshtheDev
5258cb74c8 chore(web): reduce the app to a redirect shell, drop the browser extension (#1651)
chore(web): reduce the app to a redirect shell, drop the browser extension

app.supermemory.ai now forwards everything to the console: plugin, OAuth and invite paths get an immediate 308 with the query intact, everything else shows a short notice first. Removes the browser extension workspace.

chore(web): give the moved notice a proper design

Hostnames become the headline, one primary action, a draining line for the countdown, DM Sans and the dot-grid backdrop from the brand.

chore(docs): point docs and README at the console, drop stale sections

Docs and both READMEs now link to console.supermemory.ai for API keys. Removed the company-brain docs tab with a redirect, and trimmed the README app section.

chore(web): give the redirect five seconds
2026-09-07 19:56:46 +00:00
MaheshtheDev
4d8a4ebfdd fix(mcp): let getDocument read any accessible document (#1641)
Some checks failed
Publish Pipecat SDK Python / publish (push) Has been cancelled
Publish Agent Framework Python / publish (push) Has been cancelled
Publish AI SDK / publish (push) Has been cancelled
Publish Cartesia SDK Python / publish (push) Has been cancelled
Publish OpenAI SDK Python / publish (push) Has been cancelled
Publish Tools / publish (push) Has been cancelled
getDocument filtered on the caller's active space, so an ID from listDocuments in any other space returned "Document not found". With activeSpace unset the fallback is sm_project_default, which broke most cross-space reads.

The API already scopes document reads to the caller's org, so the extra filter added no protection. Verified locally against the mono API: own-space and cross-space IDs now resolve, foreign-org IDs still 404.
2026-09-02 21:49:57 +00:00
Luv
9a0c5a5ad6
docs: fixed typo in graph-memory.mdx (#1640) 2026-09-02 10:07:03 -07:00
MaheshtheDev
17eab43cd4 docs: add Cursor and Grok Bot plugin pages (#1635)
Ship dedicated integration docs and point the plugin catalog at them. Grok Bot stays to install, auth, and skills — no Cursor-only config or repo tags.
2026-09-01 20:51:54 +00:00
Dhravya
4ad5f0beb1
feat(sdk-playground): reflect SDK-owned memory block in debug view (#1533)
## Stack Context

Part 3 (top) of a 3-PR stack moving memory deduplication into the SDKs. See `sdk-dedup/tools-ts` for full context.

## What?

Update the SDK playground so its debug view reflects the SDK-owned memory block.

- Displays the current deduplicated `<supermemory>` replacement block produced by the SDK middleware, instead of the old browser-side "seen facts" delta.
- Adds a `memory-dedupe` helper and ignores local `*.tsbuildinfo`.

## Why?

The previous debug cards were misleading — they showed an incremental browser-filtered delta while the middleware actually re-injected the full profile. Now the visualization matches what the SDK really sends.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Playground-only visualization and chat gating changes; no production SDK or API behavior.
>
> **Overview**
> The playground **debug trace** now shows the **deduplicated memory block** the SDK middleware would inject (static → dynamic → search, mode-aware), instead of a misleading browser-side “new facts” delta. A new **`memory-dedupe`** helper mirrors `@supermemory/tools` middleware behavior and is applied when fetching container context and building middleware memory debug entries; the context preview card is relabeled to reflect that each turn **replaces** the prior `<supermemory>` block.
>
> **Chat UX:** messaging is enabled when API keys are configured on the **server** (`hasSupermemoryKey` / `hasOpenAiKey` from `/api/chat`), not only when keys are typed in the panel. The message input stays editable while waiting for text; Send still requires non-empty input.
>
> Also ignores `*.tsbuildinfo` in `.gitignore`.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit ed15364eb3. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
2026-09-01 06:10:37 +00:00
Dhravya
03773c4f2e
feat(python-sdks): SDK-level cross-source memory deduplication (#1532)
## Stack Context

Part 2 of a 3-PR stack moving memory deduplication into the SDKs. See `sdk-dedup/tools-ts` (parent) for the full context and the TypeScript implementation this mirrors.

## What?

Port the normalized, priority-ordered (`static > dynamic > search`) profile deduplication into the Python SDKs.

- Each request injects one **owned memory block that replaces** the prior block rather than accumulating.
- Dedup is **request-local** (no shared state), so it stays correct under concurrency.

Covers OpenAI, Agent Framework (middleware + context provider), Cartesia, and Pipecat.

## Why?

Keeps the Python SDKs at behavioral parity with the TypeScript SDK so all integrations deduplicate memory the same way.

## Testing

- OpenAI: 31 passed, 11 skipped (live)
- Agent Framework: 59 passed
- Cartesia: 8 passed
- Pipecat: 8 passed

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes memory formatting and system-prompt injection across multiple SDK integrations; incorrect dedup or replacement could alter LLM context, but there is no auth or data-store risk.
>
> **Overview**
> Ports **normalized cross-source memory deduplication** and **replace-not-append injection** into the Python OpenAI, Agent Framework, Cartesia, and Pipecat packages so they match the TypeScript SDK behavior.
>
> **Deduplication** uses request-local keys: strip optional `[YYYY-MM-DD]` prefixes, normalize whitespace, and compare with `casefold`, with priority **static → dynamic → search**. In **`query` mode**, profile static/dynamic are excluded from dedup input so facts that only appear in search (or overlap profile) are not dropped before formatting.
>
> **Injection** no longer appends memory text every turn. OpenAI and Agent Framework middleware **strip prior owned `<supermemory context="user-memories" readonly>` blocks** and **replace** them once per request while keeping the caller’s system instructions; extra system messages lose stale blocks only. New helpers (`strip`/`replace`/`wrap`) live in each package’s utils.
>
> Tests cover normalized fact variants, query-mode search retention, and stale block replacement.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 42f308b224. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
2026-09-01 06:10:36 +00:00
Dhravya
b01d2b69a3
feat(sdk-playground): interactive SDK chat playground (#1437)
## Summary
- Add `apps/sdk-playground` — chat UI to test TS/Python SDK integrations
- Context panel with document memories, API keys in dashboard, tools reference tab
- Python FastAPI server on port 8792; portless entry in `portless.json`

Stacked on #1436

## Test plan
- [ ] `cd apps/sdk-playground && bun run check-types`
- [ ] `bun run dev` with Supermemory + OpenAI keys in UI
- [ ] Switch SDKs and verify chat + context panel

Made with [Cursor](https://cursor.com)
2026-09-01 06:10:36 +00:00
Dhravya Shah
879ddd5c95
docs: clarify customer content is never used to train models on any plan (#1613)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-08-31 23:09:30 -07:00
Dhravya
de3bbb3ce9
feat(tools): 7-tool parity and description refresh (#1432)
## Summary
- Refresh canonical tool descriptions in `tools-shared.ts`
- Align OpenAI and AI SDK tool bindings with 7-tool surface
- Export `TOOL_DESCRIPTIONS` / `PARAMETER_DESCRIPTIONS` from package index

Stacked on #1431

## Test plan
- [ ] `bun run test:unit` in `packages/tools`

Made with [Cursor](https://cursor.com)
2026-09-01 05:59:57 +00:00
Dhravya Shah
5fee2f2872
docs(mcp): fix grammar in ChatGPT web plugin description (#1630)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-08-31 21:46:32 -07:00
MaheshtheDev
143024fa34 chore(web): forward legacy auth paths (#1631)
Forwards /auth/connect and /auth/agent-connect with the query string intact, and drops the pages they replaced.
2026-09-01 00:55:16 +00:00
MaheshtheDev
9ccd1b64c3 chore(web): clean up onboarding and dashboard surfaces (#1614)
Removes stale promo cards, banners, and the setup modal. Simplifies the onboarding entry so all new workspaces go through one flow.
2026-08-29 04:57:09 +00:00
Aditya kumar singh
d436792e77
docs: document self-hosted v0.0.5 model mixing bug and v0.0.7 resolution (#1450) (#1606) 2026-08-27 16:38:11 -07:00
MaheshtheDev
29c43984fe feat(web): pause Google Drive connect with a notify-me fallback (#1602)
![image.png](https://app.graphite.com/user-attachments/assets/6d7dd2cf-575b-450c-b7bb-c24b8ec834b9.png)

Google is not approving new authorizations while it re-reviews our app, so
every path that starts a new Google connection now shows a PAUSED badge and a
"Notify me" button instead of Connect.

- Existing connections are untouched: sync, file picking and history still work.
- Notify me fires a connector_paused_clicked PostHog event and remembers the
choice in localStorage, so we can pull who to email when the review clears.
- One list in lib/connector-availability.ts drives every surface; removing the
two entries turns Google back on.
2026-08-27 20:20:13 +00:00
MaheshtheDev
f11d8c4620 feat(web): drop the Web research row from Company Brain models (#1600)
The `research` / `researchEffort` model role no longer exists on the API,
so remove its card, its preset entries, and its types.
2026-08-26 19:07:56 +00:00
MaheshtheDev
9652478093 feat(web): offer a setup call alongside Slack install (#1599)
- First-landing modal on the Company Brain home: book a 30-min setup call, or install Slack yourself. Dismissal stored in localStorage.
- Setup call also reachable from a header icon, the user menu, and the onboarding research rail.
- Drops the desktop Invite button from the header; invite stays in the stats row and mobile menu.
2026-08-26 07:43:48 +00:00
MaheshtheDev
3f7b9667c6 chore: remove two dead onboarding routes and a note-content console.log (#1596)
Cherry-picks two cleanup PRs and finishes the job. Net 262 deletions.

- #1473 (@abhay-codes07): drops a `console.log` in the fullscreen note editor that printed the whole note body on every keystroke, which PostHog session replay can capture.
- #1563 (@ishaanxgupta): removes `/api/onboarding/research` and `/api/onboarding/extract-content`. Neither has a caller anywhere in the repo, and both spent metered Exa and xAI quota. This reverts the guards added for them in #1589, which only existed to make unreachable code safe.
- On top: `EXA_API_KEY`, `XAI_API_KEY` and the `@ai-sdk/xai` dependency are removed, since deleting those routes left them with no consumer.

Co-Authored-By: abhay-codes07 <182421137+abhay-codes07@users.noreply.github.com>
Co-Authored-By: ishaanxgupta <124028055+ishaanxgupta@users.noreply.github.com>
2026-08-25 10:19:47 +00:00
MaheshtheDev
f051af098e fix(mcp): bound tool inputs and scope get_document to the active space (#1593)
Cherry-picks #1582, #1583, #1584 and #1585 from @Sravanjangam (security audit #1578) onto one branch.

- MCP: `get_document` scopes to the active space like its sibling read tools, `fetch-graph-data` bounds page/limit, `guided-save` caps prefill at 200k, and `whoAmI` no longer returns the transport session id.
- ai-sdk: search limit clamped to 1-50 with a 30s client timeout.
- validation: caps on `DocumentsWithMemoriesQuerySchema.limit` and `BulkDeleteMemoriesSchema.containerTags`.
- Raycast: `metadata.url` is parsed and only http(s) is offered to the OS opener.

Dropped his `add_memory` permission gate: it checked the target against the list of existing spaces, so writes to a new space failed and the no-active-space path surfaced `No write access to space "undefined"`. Write permission stays enforced in the API via `containerTagGate`.

Hardening and consistency rather than a security fix, since the API already enforces every permission boundary here.

Co-Authored-By: Sravanjangam <163002695+Sravanjangam@users.noreply.github.com>
2026-08-24 21:36:04 +00:00
MaheshtheDev
6cae175852 fix(mcp): return 503 on auth-backend outages instead of invalid_token (#1591)
Cherry-picks #1587 from @Sravanjangam, plus the OAuth half on top.

When the auth backend is slow or returns a 5xx, the MCP server currently answers `invalid_token`. That is the protocol's signal to discard the credential and re-authenticate, so a brief upstream blip logs every connected client out, and `sm_` API key users have no automatic way back. These requests now return 503 with `Retry-After: 5` so clients retry instead.

His change covered the API key path only. This shares one `transientAuthErrorFor` helper between `validateApiKey` and `validateOAuthToken`, so a JWKS timeout or a 5xx also returns 503 on the OAuth path that Claude, Cursor and browser clients use.

Genuinely bad tokens are unaffected: bad signature, expired, and no-matching-key still resolve to 401. Verified across all seven cases.

Co-Authored-By: Sravanjangam <163002695+Sravanjangam@users.noreply.github.com>
2026-08-24 15:53:06 +00:00