Commit graph

381 commits

Author SHA1 Message Date
rajashidattapy
b5db9a725b refactor(tools): narrow memory tool input with a type guard
Replace the bare `block.input as MemoryCommand` assertions in the
Anthropic example with an isMemoryCommand type guard, so unexpected
tool input is skipped instead of silently mistyped.
2026-10-02 18:35:07 -07:00
rajashidattapy
81f1f5ccf1 fix(tools): clear every type error under packages/tools/test
`claude-memory.ts` moved to src/ and five files in test/ kept importing
`./claude-memory`; the Mastra and AI-SDK fixtures drifted behind their
installed types. Together these left `bunx tsc --noEmit` unusable for the
package.

- repoint the five `./claude-memory` imports at `../src/claude-memory`
- add the `state` property Mastra now requires on ProcessInputArgs and
  ProcessOutputResultArgs (35 fixtures)
- add `totalTokens` to the two LanguageModelV2Usage fixtures and drop the
  `rawCall` property the type no longer has
- iterate with `.entries()` instead of indexing, which was tripping
  noUncheckedIndexedAccess once the files started resolving
- pass containerTag/customId through options in test-supermemory.ts, matching
  the current `withSupermemory` signature
- exclude test/chatapp: a standalone Next.js demo with its own package.json,
  lockfile and tsconfig that has no business in this package's program

Repointing the import also made test/claude-memory.test.ts loadable again, and
it turned out to be a live-API suite: gate it behind SUPERMEMORY_API_KEY the
same way the other integration suites are, so `vitest run` no longer collects
a dozen 401s.
2026-10-02 18:35:07 -07:00
Aditya kumar singh
f7e5bf2f77 fix(tools): handle trailing slashes and whitespace in normalizeBaseUrl and addConversation 2026-10-02 18:35:07 -07:00
Agnik47
b89ed824a6 fix(tools): accept zero-argument OpenAI tool calls and reject non-object args
`getProfile`, `documentList` and `memoryForget` all declare `required: []`,
so a model may legitimately call them with no arguments at all. The OpenAI
API serialises that as `arguments: ""`, and `parseToolArguments` handed the
empty string straight to `JSON.parse`, so every no-argument call came back as

    {"success":false,"error":"Invalid JSON arguments for getProfile"}

Those three tools were unreachable in their documented no-argument form.

The same gate also lets non-object JSON through. `"null"` parses cleanly and
then rejects in the destructuring parameter of every tool function --
`TypeError: Cannot destructure property 'containerTag' of 'object null'` --
which escapes `executeToolCall`, since it has no catch, and fails the whole
request. That is precisely the throw #1488 added this gate to contain. `"5"`
and `"\"text\""` are quieter but worse: they destructure to `undefined` and
call the API with no container tag at all.

Treat blank arguments as `{}`, and require the parsed value to be a non-null,
non-array object. Malformed JSON still returns the tool error #1488 added.

Adds eight regression tests. Six of them fail against the current
implementation -- two on the blank-argument path and four on the non-object
path, one carrying the raw TypeError. The two guard tests, malformed JSON and
an ordinary well-formed call, pass both before and after, so the behaviour
2026-10-02 18:35:07 -07:00
abhinav7x94
44869502b1 test(tools): remove redundant result assertions 2026-10-02 18:35:07 -07:00
shamAnimates
8a1cf31af8 test(tools): type scoped operation results 2026-10-02 18:35:07 -07:00
shamAnimates
977b2fcd0a fix(tools): enforce configured container scope 2026-10-02 18:35:07 -07:00
Aditya kumar singh
17ced72233 fix(tools): escape delimiters in makeTurnKey to prevent cache collision 2026-10-02 18:35:07 -07:00
therahul-yo
274e6b6e6a fix(tools): bound and harden the shared /v4/profile request
`supermemoryProfileSearch` in `shared/memory-client.ts` is the only
Supermemory HTTP call in this package with neither a request timeout nor
redirect handling. The identical `/v4/profile` call in
`openai/middleware.ts` sets both, and `/v4/conversations`
(`conversations-client.ts`) and `/v4/memories` (`shared/forget-memory.ts`)
each set a 30s budget.

Two consequences:

- **Unbounded request.** A timeout only applied when the caller supplied a
  signal. `withSupermemory` passes one (5s), but `buildMemoriesText` is
  called with no signal by the Mastra processor and the VoltAgent
  middleware, and by the exported `buildMemoriesText` / `addSystemPrompt`
  helpers. `fetch` has no default deadline, so a stalled connection blocks
  the agent turn indefinitely — the failure both integrations' surrounding
  try/catch is written to absorb, but which never surfaces as an error.
- **Redirects followed.** The request carries `Authorization: Bearer
  <apiKey>`; a 3xx from a misconfigured or attacker-influenced `baseUrl`
  was followed silently rather than refused.

Apply a 30s `PROFILE_REQUEST_TIMEOUT_MS` unconditionally and set
`redirect: "error"`. A caller signal is composed with the timeout via
`AbortSignal.any` rather than replacing it, so a caller-side budget can
only shorten the request, never leave it unbounded — the wrapper is kept
separate so the composition is stated once rather than re-derived at the
call site.

`src/shared/memory-client.test.ts` existed but was absent from the
`test:unit` file list CI runs, so its assertions never ran on a pull
request; add it alongside the new coverage.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L7GkmUn6skD6dCzKtcHDbe
2026-10-02 18:35:07 -07:00
Agnik47
444b4f1698 fix(tools): keep the forget-memory timeout when a caller passes a signal
`forgetMemoryRequest` combined the caller's signal and the 30s abort with
`??`, making them mutually exclusive. Passing a cancellation signal removed
the timeout, so a hung `DELETE /v4/memories` could wedge the tool call again
— the exact condition #1451 set out to remove. There was also no way for a
caller to ask for both cancellation and a timeout.

Compose the two with `AbortSignal.any` instead of choosing between them.
`AbortSignal.any` is available in Node 20.3+, Bun and workerd.

No production call site passes `options` today (`ai-sdk.ts` and
`openai/tools.ts` both omit it), so this was latent rather than live.

The existing test asserted the buggy behaviour (`init.signal` being the
caller's own signal), so it is replaced by two tests that pin the composed
semantics: aborting the caller aborts the request, and the timeout leg still
aborts the request on its own. Both fail against the previous implementation.

Fixes #1549
2026-10-02 18:35:07 -07:00
Rikinshah787
0d90a15100 fix(tools): handle the memory tool commands Claude actually sends
Three places where ClaudeMemoryTool diverges from the documented
memory_20250818 wire format:

- rename sends old_path/new_path, not path. handleCommand validated
  command.path, so every rename coming from a real model died with
  "Cannot read properties of undefined (reading 'startsWith')".
  path is still accepted as the source for existing callers.
- insert_line means "insert after this line" (0 = top of file), but we
  spliced at insertLine - 1 and rejected 0, so every insert landed one
  line above where Claude asked and inserting at the top was impossible.
- str_replace with new_str omitted is a deletion per the spec; we
  rejected it.

The new tests mock the supermemory client so they run without an API
key. Also fixed the rename example in the docs, which showed the same
path shape the code expected.
2026-10-02 18:35:07 -07:00
Aditya kumar singh
4929603cb4 fix(tools): clean up legacy customId documents during mutations to prevent path ambiguity 2026-10-02 18:35:07 -07:00
Aditya kumar singh
d110df8ad2 fix(tools): handle legacy customIds during document verification 2026-10-02 18:35:07 -07:00
Aditya kumar singh
db64d1369c fix(tools): prevent customId collisions in claude memory tool (#1547) 2026-10-02 18:35:07 -07:00
Aniruddha Adak
b8b95112af fix(tools): reject parent-directory segments in Claude memory paths 2026-10-02 18:35:07 -07:00
Rohit
76470610ff fix(tools): align claude-memory insert with memory_20250818 line semantics
Anthropic's memory_20250818 spec defines insert as: insert_text is inserted
AFTER line insert_line, 0 inserts at the beginning of the file, and the valid
range is [0, n_lines]. The implementation treated insert_line as a 1-based
insert-BEFORE index with range [1, n_lines + 1].

Since the caller of this tool is Claude itself, which is trained on the spec
semantics, every model-driven insert landed one line earlier than intended,
insert_line: 0 (insert at top of file) was rejected as invalid, and
insert_line: n_lines (append) inserted before the last line instead of after
it.

Fix the validation range to [0, n_lines], splice at insert_line directly
(0-based insert-after), and update the error and success messages to match.
One existing tool-operations test encoded the old insert-before behavior; its
insert_line is adjusted so its expected output is unchanged under spec
semantics. Adds four regression tests covering top-of-file, middle,
append, and both out-of-range directions.
2026-10-02 18:35:07 -07:00
abhinav7x94
0d77c8f759 fix(tools): isolate OpenAI middleware clients 2026-10-02 18:35:07 -07:00
Dhravya Shah
62cc57eda6
fix(auth): upgrade Better Auth to patched 1.7.6 (#1719)
Some checks failed
Publish AI SDK / publish (push) Has been cancelled
Publish Memory Graph / publish (push) Has been cancelled
Publish Tools / publish (push) Has been cancelled
Co-authored-by: Mahesh Sanikommu <maheshthedev@gmail.com>
2026-10-02 17:05:13 -07:00
dependabot[bot]
bce2d0dc16
chore(deps): bump better-auth from 1.3.3 to 1.6.22 in /packages/lib (#1741)
Some checks failed
Publish LiveKit SDK Python / publish (push) Has been cancelled
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Dhravya <dhravya@supermemory.com>
2026-10-01 17:06:40 -07:00
Dhravya Shah
b36b225375
feat(livekit): add persistent memory for LiveKit Agents (#1702)
Co-authored-by: Ishaan Gupta <ishaankone@gmail.com>
2026-10-01 15:26:35 -07:00
Dhravya Shah
83f315fc17
fix(chatapp): patch high severity transitive dependencies (#1723) 2026-09-29 15:28:16 -07:00
Dhravya Shah
c4382f5ffc
fix(python-sdk): patch vulnerable async and tooling dependencies (#1720) 2026-09-29 15:26:59 -07:00
sohamd22
cfa6c7cb17 fix(memory-graph): distinguish document links from derives relations (#1701)
Document-to-memory links and actual `derives` relations were both emitted as `derives`, so they shared the same color and legend entry.

This separates structural document links into a `document` edge type, adds a dedicated theme color with `--graph-edge-document` support, and updates force-layout and level-of-detail handling to preserve existing structural behavior. The package and MCP widget legends/themes now distinguish document links from derived-memory relations.

Adds regression coverage for edge classification and validates the package plus its MCP consumer.

<!-- capy-badge:start -->
<a href="https://capy.ai/thread/jam_01M36F4MPFXZCA8J14T53YY029"><picture><source media="(prefers-color-scheme: dark)" srcset="https://capy.ai/badge/accent-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://capy.ai/badge/accent-light.svg"><img alt="Open in Capy" src="https://capy.ai/badge/accent-light.svg"></picture></a>
<!-- capy-badge:end -->
2026-09-25 22:00:12 +00:00
Prasanna721
8a4d9d76ae release memory graph 0.2.4 (#1686)
Before: npm serves 0.2.3 without the merged fixes.

After: merging publishes 0.2.4 with the theme, initial fit, and node settling fixes.

Validation: package typecheck and build passed.
2026-09-18 21:44:52 +00:00
Prasanna721
2a6dcda7f6 fix graph styling and initial layout (#1684)
**Before:** Console lost its theme and dots. Incoming nodes needed a drag to reorganize, fit missed later pages, and clicks or drag release could leave the layout moving.

**After:** Restore themed rendering with configurable dots. Automatically settle and fit incoming nodes, keep clicks from reheating forces, and cool the layout after drag release.

**Checked:** Package types/build and Console build linked to this package.

Console companion: [mono#3295](https://github.com/supermemoryai/mono/pull/3295).
2026-09-18 21:18:33 +00:00
karthik rajan
2415a5c796
fix(memory-graph): add aria-labels to zoom controls (#1662)
Signed-off-by: Karthik Rajan <karthikrajanmr@gmail.com>
2026-09-11 11:23:37 -07:00
Dhravya Shah
958ae8b619
fix(deps): bump next to 16.3.3 in chatapp, sdk-playground, and memory-graph-playground (#1655)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-09-09 23:01:32 -07:00
Dhravya
03773c4f2e
feat(python-sdks): SDK-level cross-source memory deduplication (#1532)
## Stack Context

Part 2 of a 3-PR stack moving memory deduplication into the SDKs. See `sdk-dedup/tools-ts` (parent) for the full context and the TypeScript implementation this mirrors.

## What?

Port the normalized, priority-ordered (`static > dynamic > search`) profile deduplication into the Python SDKs.

- Each request injects one **owned memory block that replaces** the prior block rather than accumulating.
- Dedup is **request-local** (no shared state), so it stays correct under concurrency.

Covers OpenAI, Agent Framework (middleware + context provider), Cartesia, and Pipecat.

## Why?

Keeps the Python SDKs at behavioral parity with the TypeScript SDK so all integrations deduplicate memory the same way.

## Testing

- OpenAI: 31 passed, 11 skipped (live)
- Agent Framework: 59 passed
- Cartesia: 8 passed
- Pipecat: 8 passed

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes memory formatting and system-prompt injection across multiple SDK integrations; incorrect dedup or replacement could alter LLM context, but there is no auth or data-store risk.
>
> **Overview**
> Ports **normalized cross-source memory deduplication** and **replace-not-append injection** into the Python OpenAI, Agent Framework, Cartesia, and Pipecat packages so they match the TypeScript SDK behavior.
>
> **Deduplication** uses request-local keys: strip optional `[YYYY-MM-DD]` prefixes, normalize whitespace, and compare with `casefold`, with priority **static → dynamic → search**. In **`query` mode**, profile static/dynamic are excluded from dedup input so facts that only appear in search (or overlap profile) are not dropped before formatting.
>
> **Injection** no longer appends memory text every turn. OpenAI and Agent Framework middleware **strip prior owned `<supermemory context="user-memories" readonly>` blocks** and **replace** them once per request while keeping the caller’s system instructions; extra system messages lose stale blocks only. New helpers (`strip`/`replace`/`wrap`) live in each package’s utils.
>
> Tests cover normalized fact variants, query-mode search retention, and stale block replacement.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 42f308b224. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
2026-09-01 06:10:36 +00:00
Dhravya
d0f53b0d64
feat(tools): SDK-level cross-source memory deduplication (#1531)
## Stack Context

This stack moves memory deduplication **out of the playground UI and into the SDKs themselves**, so every integration injects a single, deduplicated, self-replacing memory block. Three PRs:

1. **`sdk-dedup/tools-ts`** (this PR) — TypeScript SDK core + integrations
2. `sdk-dedup/python` — Python SDKs
3. `sdk-dedup/playground` — playground debug view reflects the SDK-owned block

## What?

Move profile deduplication into the SDK middleware for the TypeScript tools package.

- Facts are normalized (strip leading `[YYYY-MM-DD]`, trim, collapse whitespace, casefold) and deduplicated in **`static > dynamic > search`** priority within a single request.
- The result is injected as one **owned `<supermemory>` block** that *replaces* the previous block instead of accumulating a new one each turn.
- Dedup is **mode-aware**: in query mode, search results are not dropped against a profile that isn't being injected.
- Deduplication is **request-local** — no global/browser `Set`. Safe for multiple users, concurrent requests, and Cloudflare Worker isolates.

Covers AI SDK, OpenAI (Chat + Responses), Mastra, and VoltAgent. New `shared/memory-context.ts` owns the block-replacement logic.

## Why?

The earlier "conversation-scoped deduplication" was only a playground browser `Set` — a UI debug affordance that did not change what the SDK sent to the model, and would have been unsafe as server-side global state. Real cross-source dedup belongs in the SDK, applied fresh per stateless model request.

## Testing

- `bun run test` in `packages/tools`: 145 passed (the one failing suite, `claude-memory.test.ts`, is a pre-existing broken import unrelated to this change).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes how system prompts and instructions are built across all TypeScript integrations; behavior is well-covered by unit tests but incorrect strip/replace logic could drop or duplicate context in production prompts.
>
> **Overview**
> Moves **cross-source memory deduplication** and **owned prompt injection** into `@supermemory/tools` so every integration sends one deduplicated memory block per request instead of growing context each turn.
>
> **Deduplication:** Facts are normalized via `normalizeMemoryFact` (strip `[YYYY-MM-DD]`, trim, collapse whitespace, lowercase) and deduplicated with **static → dynamic → search** priority. `deduplicateMemoriesForMode` keeps search hits in **query** mode when the profile is not injected.
>
> **Owned `<supermemory>` block:** New `shared/memory-context.ts` wraps memories in `<supermemory context="user-memories" readonly>`, strips stale blocks, and **replaces** prior SDK context while preserving caller system instructions. Applied in AI SDK (`injectMemoriesIntoParams`), OpenAI Chat/Responses middleware, Mastra input processor (`wrapMemoryContext`), and VoltAgent hooks.
>
> **Tests:** Unit coverage for block replacement (with-supermemory, OpenAI, VoltAgent), Mastra wrapper tag assertion, normalized dedup variants, and concurrent `containerTag` isolation.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 2fa2e0d85c. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
2026-09-01 06:10:36 +00:00
Dhravya
c262cc9953
fix(python-sdks): v4 API migration for integration packages (#1434)
## Summary
- **agent-framework**: proactive search tool descriptions
- **cartesia / pipecat**: v4 `client.add` + hybrid search, dedupe fixes, tests

Stacked on #1433

## Test plan
- [ ] pytest in agent-framework, cartesia, pipecat packages

Made with [Cursor](https://cursor.com)
2026-09-01 06:10:36 +00:00
Dhravya
46d1b53230
feat(ai-sdk): re-export 7-tool surface (#1433)
## Summary
- Re-export full tool set from `@supermemory/tools/ai-sdk`
- Add unit tests for tool re-exports

Stacked on #1432

## Test plan
- [ ] `bun run test:unit` in `packages/ai-sdk`

Made with [Cursor](https://cursor.com)
2026-09-01 05:59:58 +00:00
Dhravya
de3bbb3ce9
feat(tools): 7-tool parity and description refresh (#1432)
## Summary
- Refresh canonical tool descriptions in `tools-shared.ts`
- Align OpenAI and AI SDK tool bindings with 7-tool surface
- Export `TOOL_DESCRIPTIONS` / `PARAMETER_DESCRIPTIONS` from package index

Stacked on #1431

## Test plan
- [ ] `bun run test:unit` in `packages/tools`

Made with [Cursor](https://cursor.com)
2026-09-01 05:59:57 +00:00
Dhravya
348483d5e8
feat(openai-sdk-python): 7-tool parity (#1430)
## Summary
- Expand `SupermemoryTools` from 2 tools to 7 (matches `@supermemory/tools`)
- Add `memory_forget` via shared HTTP helper
- Add document list/add/delete and get_profile tool surfaces
- Expand tests for new tools and execution paths

Stacked on #1429

## Test plan
- [x] `uv run pytest tests/test_tools.py::TestMemoryOperationsUnit`

Made with [Cursor](https://cursor.com)
2026-09-01 04:34:18 +00:00
Dhravya
c5b7e7d4fc
fix(openai-sdk-python): migrate to v4 Supermemory APIs (#1429)
## Summary
- Replace deprecated `search.execute` with `search.memories` (hybrid mode) in `search_memories`
- Replace `memories.add` with `client.add` in tools and middleware
- Fix middleware `container_tag` param (was incorrectly `container_tags`)
- Fix profile memory deduplication for string and Pydantic API items
- Bump `supermemory>=3.50` and `requires-python>=3.9`

## Test plan
- [x] `uv run pytest tests/test_tools.py::TestMemoryOperationsUnit`

Made with [Cursor](https://cursor.com)
2026-09-01 04:34:18 +00:00
MaheshtheDev
e4afc770be feat(tools): apiKey option, type re-exports, and two reliability fixes (#1594)
Some checks failed
Publish Tools / publish (push) Has been cancelled
Cherry-picks four contributor PRs for `@supermemory/tools` onto one branch, and bumps the package to 2.2.0.

- #1244 (@rajarshidattapy): `withSupermemory` accepts `options.apiKey` instead of only reading `SUPERMEMORY_API_KEY`, matching the Vercel, Mastra and Voltagent integrations. Unblocks secrets managers, edge runtimes and per-request keys.
- #1574 (@Agnik47): re-exports `PromptTemplate`, `MemoryPromptData` and `WithSupermemoryOptions` from `ai-sdk`. `./vercel` is not a published subpath, so the documented custom-template example did not compile.
- #1488 (@abhinav7x94): malformed tool-call JSON returns an error result instead of throwing out of the request.
- #1507 (@abhinav7x94): VoltAgent `onEnd` awaits the conversation save, which was fire-and-forget and could be dropped when a serverless runtime tore down.

Dropped the `middleware.test.ts` added by #1244. Note that editing `packages/tools/package.json` triggers the npm publish workflow on merge.

Co-Authored-By: rajarshidattapy <138959719+rajarshidattapy@users.noreply.github.com>
Co-Authored-By: Agnik47 <140933190+Agnik47@users.noreply.github.com>
Co-Authored-By: abhinav7x94 <204053250+abhinav7x94@users.noreply.github.com>
2026-08-24 22:39:55 +00:00
MaheshtheDev
f051af098e fix(mcp): bound tool inputs and scope get_document to the active space (#1593)
Cherry-picks #1582, #1583, #1584 and #1585 from @Sravanjangam (security audit #1578) onto one branch.

- MCP: `get_document` scopes to the active space like its sibling read tools, `fetch-graph-data` bounds page/limit, `guided-save` caps prefill at 200k, and `whoAmI` no longer returns the transport session id.
- ai-sdk: search limit clamped to 1-50 with a 30s client timeout.
- validation: caps on `DocumentsWithMemoriesQuerySchema.limit` and `BulkDeleteMemoriesSchema.containerTags`.
- Raycast: `metadata.url` is parsed and only http(s) is offered to the OS opener.

Dropped his `add_memory` permission gate: it checked the target against the list of existing spaces, so writes to a new space failed and the no-active-space path surfaced `No write access to space "undefined"`. Write permission stays enforced in the API via `containerTagGate`.

Hardening and consistency rather than a security fix, since the API already enforces every permission boundary here.

Co-Authored-By: Sravanjangam <163002695+Sravanjangam@users.noreply.github.com>
2026-08-24 21:36:04 +00:00
Rajarshi Datta
20410a6862
fix(ui): remove the unused, broken AnonymousAuth component (#1555) 2026-08-19 19:22:17 +05:30
Dhravya
5d2b5855fe
feat(auth): AgentID sign-in button on the web login page (#1467)
## What?

Adds a "Continue with AgentID" button to the web app's login page, matching the existing Google/GitHub buttons (same `ExternalAuthButton` pattern, PostHog `login_attempt` capture, last-used badge).

- `packages/lib/auth.ts`: adds the `genericOAuthClient` plugin — generic OAuth providers sign in via `signIn.oauth2({ providerId })`, not `signIn.social`.
- `apps/web/app/(auth)/login/page.tsx`: the button, gated the same way as the other social buttons — always shown on cloud (`NEXT_PUBLIC_HOST_ID === "supermemory"`), opt-in elsewhere via `NEXT_PUBLIC_AGENTID_AUTH_ENABLED` (added to `.env.example`).

## Why?

Companion to supermemoryai/mono#2908, which registers an `agentid` generic OAuth provider (OIDC against auth.agentid.com) on the API so agents can authenticate with their AgentID identity. The consumer app talks to the same better-auth server, so it gets the same sign-in option. mono#2916 additionally auto-invites the agent's verified human owner to the agent's workspace.

Requires mono#2908 to be deployed for the button to work; until then the API rejects the unknown provider and the page shows its normal error state.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Touches authentication entry points and OAuth client configuration; risk is moderate because it extends login surface area but follows existing social sign-in patterns and is feature-flagged.
>
> **Overview**
> Adds **Continue with AgentID** on the web login page, using the same `ExternalAuthButton` flow as Google/GitHub (PostHog `login_attempt`, last-used badge, loading/error handling).
>
> The button calls **`signIn.oauth2({ providerId: "agentid" })`** instead of `signIn.social`, enabled by registering **`genericOAuthClient`** on the shared better-auth client in `packages/lib/auth.ts`.
>
> Visibility matches other social providers: shown on cloud when `NEXT_PUBLIC_HOST_ID === "supermemory"`, or elsewhere when **`NEXT_PUBLIC_AGENTID_AUTH_ENABLED`** is set (documented in `.env.example`). Depends on the API registering the `agentid` generic OAuth provider.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 90a32786a3. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
2026-08-16 23:20:38 +00:00
Abhinav Kumar Singh
82dae50ef4
fix(tools): bound memory forget requests (#1451) 2026-08-13 19:11:00 +05:30
Abhinav Kumar Singh
9d64e0f950
fix: add type checks for TypeScript workspaces (#1447) 2026-08-13 17:55:50 +05:30
pawan
47152afc1d
fix(openai-sdk): cap supermemory to <3.5 so a fresh install imports (#1236) 2026-08-12 20:56:54 +05:30
Abhay Singh
14bcc92c31
fix(memory-graph): center arrow-key navigation in the visible graph area (#1337) 2026-08-12 20:56:23 +05:30
Abhay Singh
74b2201eeb
fix(memory-graph): stop painting expired memories as expiring (#1335)
Co-authored-by: Vedant Mahajan <vedant.04.mahajan@gmail.com>
2026-08-12 20:55:53 +05:30
Abhay Singh
a7efd817ec
fix(validation): reject non-positive page/limit in pagination query schemas (#1271) 2026-08-12 19:35:45 +05:30
vorflux[bot]
2731de5c06
fix(web): add Gmail connector logo (#1428)
Co-authored-by: Vorflux AI <249966464+vorflux[bot]@users.noreply.github.com>
2026-08-07 17:35:26 -07:00
Dhravya Shah
45585b4c0f
feat(web): add API Keys management in settings (#1426)
Co-authored-by: Mahesh Sanikommu <maheshthedev@gmail.com>
2026-08-07 12:44:40 -07:00
vorflux
8071a7b085 Add Nova workspace prompt settings (#1323)
Adds a dedicated Workspace Prompt editor for Company Brain organizations while preserving the existing Organization Context ingestion-filter controls for every organization manager.

## Changes

- Keeps Organization Context byte-for-byte unchanged and available independently to all organization managers.
- Adds Workspace Prompt as a separate Company-Brain-only section below it, using the established settings styling and contextual divider.
- Describes Workspace Prompt as persistent guidance that can shape operating preferences, priorities, source/tool choices, workflows, terminology, formatting, and communication style.
- Adds nullable, 1,500-character `workspacePrompt` support to shared request, GET response, and PATCH response contracts.
- Aligns PATCH validation with the real `{ orgId, orgSlug, updated }` API response.
- Merges canonical `updated` settings into the submitting organization’s cache, then exactly refetches that organization.
- Preserves drafts during background refetches, isolates organization switches, retains actionable errors, accessibility, empty `filterPrompt` compatibility, and `X-App-Source: nova`.

## Testing

- Passed focused Biome checks on all changed files.
- Passed `packages/lib` and `packages/validation` TypeScript checks.
- Verified GET/PATCH settings response contracts, partial/null/limit validation, canonical cache merge, and exact organization-bound invalidation.
- Verified Organization Context remains unchanged and Workspace Prompt is separately Company-Brain/manager-gated.
- Confirmed no remaining Workspace Persona identifiers.
- Public preview returns HTTP 200; authenticated settings interactions remain unavailable without a saved OAuth session.
- Full web type-check remains blocked by unrelated baseline diagnostics; none reference changed files.
- No dedicated tests were added, per requester instruction.

---
**Session Details**
- Session: [View Session](https://supermemory.us1.vorflux.com/agent-sessions/7544b72b-aeca-48e2-81c3-514df21cd081)
- Requested by: Soham Daga (soham@supermemory.com)
- Address comments on this PR. Add `(aside)` to your comment to have me ignore it.
2026-07-29 21:13:59 +00:00
Vedant Mahajan
cfc2b49192
Add shared Agents memory workspace (#1290) 2026-07-23 12:18:44 -07:00
Abhay Singh
d5f95827ed
fix(memory-graph): allow selecting nodes on touch devices (#1262) 2026-07-22 17:57:50 +05:30
Dhravya Shah
f882f1104d
docs: restructure documentation site and update integration UI (#1331)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-07-21 20:19:30 -07:00