github kortix-ai/suna v0.13.47
v0.13.47 — Microsoft Teams for every project, secrets you can share with an agent, failed-trigger alerts, and immediate sign-out

latest releases: dev-latest, desktop-dev-latest
2 hours ago

Microsoft Teams for every project, secrets you can share with an agent, failed-trigger alerts, and immediate sign-out

New

  • Microsoft Teams is on for every project. There is no feature flag to turn on: connect Teams from the project's Connectors → Channels page. A tenant admin consents once, or the project brings its own bot. A project that connected Teams while it was a flag keeps its install. @kortix/sdk keeps teams as a deprecated flag key that always reports enabled. (#8601, #8603)

  • What Kortix says to one person in Teams stays with that person. In a channel or group chat, only that person sees:

    • the prompt to connect an account or request access, with the connect button right in the thread;
    • command replies;
    • why a message did not run;
    • approval requests and decisions.

    Teams marks these "Only you can see this message", as Slack does. The shared "Working on it…" card appears only when the message can run. (#8609)

  • Kortix shows when your Teams app is out of date. When your organization's Teams catalog has an older Kortix app, the Channels page and kortix channels status say so and name the two steps: a Teams admin publishes the update, then a team owner updates the app in each team where Teams offers it. A Teams thread that the agent may not read now comes back with who fixes it, instead of Microsoft's error alone. The Teams app moves to version 1.6.1. (#8624)

  • A failing trigger is no longer silent. When a trigger's run fails, the Schedule page shows the trigger as failed with the reason, and the account owner gets one push when a failure streak starts, not one per fire. The next run that finishes clears it. A reused session that grew too large to compact is retired, so the next fire starts a fresh one. (#8586, #8588)

  • Human Messaging reaches every agent surface (projects with the Human Messaging feature on). Agents in sessions, Slack, Teams and the hosted MCP server know how to ask a person and answer back, and the mobile app groups what people asked you under "Asked you". An ask from a session runs the asking session's own agent. (#8622, #8623)

  • Share a secret or a connector account with an agent. "Who can use it" now offers agents next to people and groups. A value shared with an agent reaches every session of that agent, triggers and schedules included; running the agent stays gated by its own access. A secret link can keep the value to the person who asked. kortix secrets share --agent <name> does the same from the CLI. (#8635, #8638)

  • Approve or deny a connector call from the Review Center header, next to Back, as for a change request. Deny takes an optional note that reaches the agent. Long parameter values collapse behind Show more. (#8641)

  • An agent's ask names the agent, not the session title, in "Asked you" (Human Messaging projects). With the Human Messaging feature off, it no longer appears anywhere. (#8626, #8637)

Security

  • Sharing a session cannot leak a personal value. Making a session project-visible or creating a public share is refused (409 PERSONAL_SECRET_REQUIRES_PRIVATE_SESSION) while the session holds a value shared only with its owner. (#8635)
  • Permissions follow the capability. A rule on bash also covers the terminal tools, websearch covers web and image search, and webfetch covers page scraping. Unknown tools fail closed. (#8553)

Fixed

  • Slack and Teams sign-in links open again. Since 2026-09-24 the link to connect a chat account answered "page not found". (#8611)
  • Accounts that require MFA work after the code is verified. Linking Slack or Teams, and some API routes such as connectors, asked for the second factor again even after it passed. Connecting a chat account now continues by itself after the code. (#8611) Members' sessions in such an account now reach shared provider keys, including a ChatGPT login shared with the project, and changing a shared key still needs the second factor. (#8618, #8620)
  • A Slack or Teams conversation runs the model it shows. A message without a /model change could run on the model of an earlier message instead of the conversation's model. (#8618)
  • Signup asks you to open the emailed link. The confirmation screen no longer asks for a six-digit code that the email does not contain. (#8608)
  • Signing out takes effect on every route at once. A logged-out, banned or revoked access token is rejected everywhere. Before, it stayed valid until it expired, up to an hour, on routes outside the account session check. (#8594)
  • Migrated sessions start again. A session moved from the previous platform could hold a sign-in token that the move had revoked, and never finished starting. Opening it now restores that one token, only for the session's own box. (#8636)
  • Audit ingestion wastes fewer retries. After a database timeout, a retry sends half the rows instead of the same statement again, and a small batch gives up after one try. (#8599)
  • Email connections survive a failed inbox listing. When the inbox listing failed, Kortix treated it as an empty list and removed the project's email connections. It now keeps them and reports the error. (#8607)
  • The bring-your-own Teams webhook answers 404, not 503, for a project that has no bot of its own. (#8603)
  • The Kortix icon is the same everywhere again. The favicon, app icons and home-screen icon all show the light tile with the dark mark, in light and dark mode. (#8647)
  • Translated pages are translated again. Blog titles and descriptions, SEO descriptions, the site description and the open-source headline show in all eight non-English languages. The brand kit had left them in English. (#8587)

Behind the scenes

  • Sandbox boot is split into session setup, prompt delivery and turn relays, with no change in behavior (#8600); its boot-order guards follow the moved code (#8627). The SDK's server entrypoint no longer imports itself in a cycle (#8591).
  • Test repairs for mobile, the CLI and self-hosted Supabase, and the Stop flow (#8575, #8578, #8584, #8590). A flaky kortixd test resets its shared cooldown (#8598). A synthetic test token no longer trips the secret scanner (#8614, #8616). Learnings entries on translating changed copy and on Teams app updates (#8593, #8624).
  • The runtime protocol is Kortix-owned: transcripts are versioned as kortix.transcript.v1, both agent harnesses serve Kortix turn routes, and @kortix/sdk no longer depends on @opencode-ai/sdk. (#8553)
  • SDK and host refactors with no change in behavior (#8246, #8398, #8449, #8581, #8632), billing provider handlers split out (#8628), an engineers IAM group for MFA-gated day-to-day AWS access (#8633), and release-gate fixes (#8643, #8645, #8646, #8648, #8650, #8652). Message ids now use the platform's secure random source. (#8646, #8648)
  • One migration: a nullable run_failing_since column on trigger runtime state (#8588).

Release source: staging 40de384e4f517dacea723221cb430ef45ffe8b00 (promotion #8642; supersedes the earlier candidate 4defc4c).

What's Changed

  • fix(mobile): repair main after 5ac201f (KRTX-899) by @agent-kortix in #8578
  • fix(cli,tests): repair main after f605a96 (KRTX-910) by @Ino-Bagaric in #8584
  • feat(triggers): a failed trigger run shows on the trigger and pushes the account owner by @Ino-Bagaric in #8586
  • fix(triggers): a failed run stays failed across later fires and pushes once per streak by @Ino-Bagaric in #8588
  • fix(web): repair main after 7e5e373 — localize the brand-kit copy, fix the tone assertion by @Ino-Bagaric in #8587
  • test(flows): accept the /stop "stopping" answer and wait for the stop to land by @markokraemer in #8590
  • docs(learnings): changed English copy needs a new hashed key in every catalog by @Ino-Bagaric in #8593
  • fix(auth): reject logged-out ES256 access tokens on every route by @markokraemer in #8594
  • chore(release): staging VERSION → 0.13.47 [skip ci] by @github-actions[bot] in #8596
  • chore(release): VERSION → 0.13.47 [skip ci] by @github-actions[bot] in #8597
  • fix(kortixd): reset the reconcile cooldown before the refresh convergence rows by @Ino-Bagaric in #8598
  • fix(audit): never re-send an identical audit ingest statement after a timeout by @markokraemer in #8599
  • Promote main 13a995e to staging by @Ino-Bagaric in #8595
  • feat(teams): Microsoft Teams is on for every project — graduate the teams flag by @Ino-Bagaric in #8601
  • fix(teams): the bring-your-own webhook answers 404 for a project with no bot of its own by @Ino-Bagaric in #8603
  • fix(mobile): repair main after f256929 (KRTX-398) by @agent-kortix in #8575
  • Promote main c259040 to staging by @Ino-Bagaric in #8604
  • fix(teams): what the bot says to one person in a channel or group chat only that person sees by @Ino-Bagaric in #8609
  • fix(channels): chat sign-in links open and complete by @Ino-Bagaric in #8611
  • test(web): a synthetic sign-in token that gitleaks does not flag by @Ino-Bagaric in #8614
  • chore(security): ignore the reviewed synthetic sign-in token in 127d878 by @Ino-Bagaric in #8616
  • fix(auth): align signup prompt with email link (KRTX-937) by @agent-kortix in #8608
  • fix(channels): a channel turn runs the model Kortix shows; MFA accounts reach shared keys by @Ino-Bagaric in #8618
  • refactor(sandbox): separate session and relay from boot (KRTX-930) by @agent-kortix in #8600
  • fix(secrets): a caller's own key changes keep their MFA level by @Ino-Bagaric in #8620
  • feat(messaging): teach every agent surface to message people; mobile Asked you by @markokraemer in #8622
  • fix(sessions): an ask from a session runs the asking session's agent by @markokraemer in #8623
  • refactor(sdk): remove server entrypoint back edges (KRTX-927) by @agent-kortix in #8591
  • fix(teams): show a tenant's outdated Teams app and say who updates it by @Ino-Bagaric in #8624
  • fix(api): preserve email connections when install listing fails (KRTX-935) by @agent-kortix in #8607
  • test(kortixd): repair main after 986ffa6 (KRTX-930) by @Ino-Bagaric in #8627
  • docs(learnings): moving a function breaks the source guards that read its old file by @Ino-Bagaric in #8630
  • feat(messaging): human_messaging off = invisible everywhere; pi honours noReply; asks name their asker by @markokraemer in #8626
  • Promote main 022eb6f to staging by @Ino-Bagaric in #8629
  • refactor(sdk): dedupe the audit querystring builder across audit and host-boundary (KRTX-413) by @agent-kortix in #8398
  • refactor(sdk): share workspace search core and prepare injected client (KRTX-392) by @agent-kortix in #8449
  • refactor(sdk): split event dispatch and stream hydration (KRTX-921) by @agent-kortix in #8581
  • feat(iam): engineers group for MFA-gated PowerUser access by @markokraemer in #8633
  • refactor(sdk): move gateway query hooks behind web shim (KRTX-716) by @agent-kortix in #8246
  • feat(secrets): agents as principals, session-share guard, secret-link audience by @markokraemer in #8635
  • fix(sessions): a box's own superseded session token heals on start instead of locking the session out by @markokraemer in #8636
  • refactor(billing): separate provider handlers and wallet orchestration (KRTX-944) by @agent-kortix in #8628
  • feat(messaging): an agent's ask names the agent, not the session title by @markokraemer in #8637
  • fix(secrets): agent object grants never activate an agent; agent values at first boot; link values are fresh by @markokraemer in #8638
  • docs(learnings): an object grant never activates an agent service account by @markokraemer in #8639
  • refactor(search): use shared workspace search client in hosts (KRTX-393) by @agent-kortix in #8632
  • feat(review-center): approval decides from the header; long parameter values collapse by @sutharjay1 in #8641
  • fix: green main — heal module import, billing-gate mock, agent-identities query key by @markokraemer in #8643
  • feat: OpenCode decoupling W5 — Kortix-owned contract (kortix.transcript.v1 emitted by pi, Kortix turn verbs, @kortix/sdk without @opencode-ai/sdk) by @DimitrijeGlibic in #8553
  • fix: clear the staging gate — CodeQL ReDoS + fs race, journey 23 label by @markokraemer in #8645
  • fix(sdk): clear CodeQL high alerts — crypto id suffix, no backtracking slash trim by @markokraemer in #8646
  • fix(web): every app icon and favicon renders the favicon.svg art by @sutharjay1 in #8647
  • fix(sdk): wire message id tail defaults to crypto random by @markokraemer in #8648
  • test(kortixd): wait for the note file, not just a running tool (W5 E4 race) by @markokraemer in #8650
  • test(web): give flag-gated session surfaces a query client (human_messaging, #8626) by @markokraemer in #8652
  • fix(audit): the project agent-identities route gets its own audit action by @markokraemer in #8654
  • fix(sdk): unbiased crypto tail for wire message ids by @markokraemer in #8655
  • fix(email): never relay mail to reserved test domains by @markokraemer in #8656
  • test(agent-tunnel): keep the runner's AGENT_TUNNEL_HOME out of the CLI tests by @markokraemer in #8657
  • refactor(slack): separate thread routing and session launch (KRTX-939) by @agent-kortix in #8613
  • test(api): notification emails go to a relayable recipient domain by @markokraemer in #8658
  • Promote main 1bf48b5 to staging by @markokraemer in #8642
  • Release v0.13.47 — Microsoft Teams for every project, secrets you can share with an agent, failed-trigger alerts, and immediate sign-out by @github-actions[bot] in #8605

Full Changelog: v0.13.46...v0.13.47

Don't miss a new suna release

NewReleases is sending notifications on new releases.