npm @notionhq/client 5.27.0
v5.27.0

3 hours ago

What’s changed

Behavior changes

  • Tokens are blocked in browsers by default (#791)
    • In a browser page, web worker, or service worker, constructing a client with auth throws BrowserTokenNotAllowedError. Per-request auth and OAuth client credentials reject with the same error before anything is sent. Anyone who can load the page can read the token and act as the connection.
    • Pass dangerouslyAllowBrowser: true to opt out, for example in jsdom tests. A client without a token still works in a browser, such as one whose baseUrl points at your own server. See the README's "Browser usage" section.

New capabilities

  • Agent Skills API (#804)
    • Adds client.plugins.list(), client.plugins.retrieve(), and client.skills.retrieve(). The retrieve methods return a signed archive URL. They don't download or extract files.
  • Typed databases (#790)
    • client.databases.create() accepts database_type of tasks, projects, or skills. Database and data source responses include a read-only database_type.

API response types

These changes match what the Agents API (public beta) returns today. Code that matched the old literals needs a small update.

  • Personal agent ID is notion_ai (#806, from #774)
    • Agent response IDs can be notion_ai. The personal agent in QueryAgentsResponse has id: "notion_ai" instead of 33333333-3333-3333-3333-333333333333. Requests still accept the old UUID.
  • Personal agent insights (#806, from #780)
    • client.agents.retrieveInsights() responses allow notion_ai for id and agent_type.
  • Personal agent name is a string (#806, from #803)
    • Owners can rename their personal agent, so it's no longer always "Notion Agent".
  • stream.end has no last_sequence (#806, from #773)
    • The API stopped sending it. Resume with event IDs.
  • Session stream events are generated (#786). Event shapes are unchanged.

Docs and internals

  • Doc comments for bounded session query pages (#788), session filter properties (#802), and several path and file upload parameters (#792, #793, #796).
  • Standard Client methods are generated from endpoint definitions, with no public API change (#781). CI now checks each PR's public types against its base (#783).

Links

Don't miss a new client release

NewReleases is sending notifications on new releases.