What’s changed
Behavior changes
- Tokens are blocked in browsers by default (#791)
- In a browser page, web worker, or service worker, constructing a client with
auththrowsBrowserTokenNotAllowedError. Per-requestauthand OAuth client credentials reject with the same error before anything is sent. Anyone who can load the page can read the token and act as the connection. - Pass
dangerouslyAllowBrowser: trueto opt out, for example in jsdom tests. A client without a token still works in a browser, such as one whosebaseUrlpoints at your own server. See the README's "Browser usage" section.
- In a browser page, web worker, or service worker, constructing a client with
New capabilities
- Agent Skills API (#804)
- Adds
client.plugins.list(),client.plugins.retrieve(), andclient.skills.retrieve(). The retrieve methods return a signed archive URL. They don't download or extract files.
- Adds
- Typed databases (#790)
client.databases.create()acceptsdatabase_typeoftasks,projects, orskills. Database and data source responses include a read-onlydatabase_type.
API response types
These changes match what the Agents API (public beta) returns today. Code that matched the old literals needs a small update.
- Personal agent ID is
notion_ai(#806, from #774)- Agent response IDs can be
notion_ai. The personal agent inQueryAgentsResponsehasid: "notion_ai"instead of33333333-3333-3333-3333-333333333333. Requests still accept the old UUID.
- Agent response IDs can be
- Personal agent insights (#806, from #780)
client.agents.retrieveInsights()responses allownotion_aiforidandagent_type.
- Personal agent
nameis astring(#806, from #803)- Owners can rename their personal agent, so it's no longer always
"Notion Agent".
- Owners can rename their personal agent, so it's no longer always
stream.endhas nolast_sequence(#806, from #773)- The API stopped sending it. Resume with event IDs.
- Session stream events are generated (#786). Event shapes are unchanged.
Docs and internals
- Doc comments for bounded session query pages (#788), session filter properties (#802), and several path and file upload parameters (#792, #793, #796).
- Standard
Clientmethods are generated from endpoint definitions, with no public API change (#781). CI now checks each PR's public types against its base (#783).
Links
- Full Changelog: v5.26.0...v5.27.0
- NPM Package: https://www.npmjs.com/package/@notionhq/client/v/5.27.0