github teng-lin/notebooklm-py v0.8.4

2 hours ago

Added

  • Android multi-profile REST and MCP serving (#1901). Serve several Android
    accounts with --profiles, route each request by profile, and isolate profile
    startup failures and recovery.

  • Web multi-profile REST and MCP serving (#1901). notebooklm-server --profiles work,personal and notebooklm-mcp --profiles work,personal now serve several
    profiles on the default Web backend, with the same X-NotebookLM-Profile /
    per-tool profile routing, per-profile isolation, 503 profile_unavailable
    degradation, and recovery cooldown as Android multi-profile mode. Each profile
    opens its own storage_state.json by explicit path; a profile with only a
    master_token.json mints its own session first. A profile that shares either
    session cookie (__Secure-1PSID or SID) with another configured profile, such
    as a copied storage_state.json, is refused while siblings keep serving;
    diagnostics report session_conflict. Web profile opens
    take turns, and waiting for a turn does not count against the startup timeout. Web
    multi-profile mode refuses NOTEBOOKLM_AUTH_JSON and a non-blank
    NOTEBOOKLM_HEADLESS_REAUTH_CDP_URL. Copies made after both profiles are serving
    are detected only when one reopens. Single-profile and Android behavior are
    unchanged.

  • MCP inspection and retry metadata (#1925). Studio summary and single-item
    responses include decoded media duration, slide count, and source count;
    unavailable metadata stays null. MCP errors preserve known retry delays as
    retry_after_seconds in both structured results and tool-error messages.

  • Opt-in URL recovery (#2110). CLI source add --fallback-fetch and
    MCP/REST fallback_fetch can import eligible failed web pages as static text,
    using a bounded, public-address-only browser-impersonating fetch. Results and
    content preserve provenance. Optional cleanup_on_failure removes only an
    attributable ERROR stub after replacement readiness; ambiguous rows remain.
    Requires the impersonate and markdown extras. Android URL commit failures
    with code 9 retain their original ClientError/RPCError type and carry the
    correlated tentative source_id as operation metadata for recovery.

  • Bulk note deletion (#1999). notes.delete(notebook_id, note_ids) accepts a
    list and sends one delete request on Web and Android. MCP studio_delete(items=...)
    previews an explicit subset, batches text notes, routes artifacts and mind maps
    by kind, and reports deleted / not_found results. Confirmed batches require
    the canonical IDs from the preview.

  • Bulk MCP sharing (#2000). share_set_user(grants=[...]) accepts 1–100 mixed
    editor/viewer grants through the existing sharing.set_users() batch API.
    Confirmation previews include every grantee; notification and welcome-message
    settings apply to the whole batch. Together with the existing
    sources.add_urls_batch() / source_add(urls=...) support (#1998), these expose
    the verified batch-capable operations without adding MCP tools.

Fixed

  • Authentication across rebranded hosts (#2443, #2444). Recognize
    notebook.google landing redirects and enterprise hosts, and report access
    gates without misclassifying them as expired sessions.

  • Mutation rejection handling (#2446). Note deletion and sharing reject
    explicit backend failures instead of reporting success.

  • Android RPC health baseline. Add the missing reviewed schema baseline,
    using matching fingerprints from three consecutive protected-main runs, so
    the canary can enforce drift checks after its bootstrap grace period.

Changed

  • Allow FileLock 4.x (#2450). Keep FastMCP pinned to the validated 3.4.2 release;
    the 4.0.9 upgrade (#2451) is deferred because it breaks MCP imports and types.

Security

  • Update locked urllib3 to 2.8.0 and virtualenv to 21.7.13, resolving the
    advisories reported by the release dependency audit.

Documentation

  • Master-token re-mint guidance (#1901). The auth cookie lifecycle guide no
    longer calls Web re-minting "single-consumer per account", and ADR-0023 gains
    an amendment recording why. Live testing found that sessions minted from copies
    of one master token stay independent. The guidance now warns against two
    consumers actively using the same cookie session at once instead.

Don't miss a new notebooklm-py release

NewReleases is sending notifications on new releases.