| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
docs: September changelog entries and tighter dividers (#7591) ## What Changelog entries for everything user-facing that shipped since the Sept 3 "Audit trail" entry, plus a spacing fix on the changelog page. **New entries** (`docs/updates/changelog.mdx`) - BYOC self-hosting (Sept 21) - Smaller improvements (Sept 17): generic MCP OAuth scopes, `--sourcemap false`, `nango.getVariant()`, Zoom/Gong/Granola/Outlook webhooks - nango.yaml sunset (Sept 16) - Agent sessions updates (Sept 16): `nango_proxy`, session termination, logs filter, clearer tool errors - 1,000+ supported APIs (Sept 14) - Webhook verification (Sept 14): Gmail, Drive/Calendar, GitHub App, and the Slack/PagerDuty/Checkr signature enforcement - Billing page improvements (Sept 9), with a screenshot - Environment read APIs (Sept 9) New integrations are left for the September roundup on Oct 1. Gated work (scheduled/webhook functions, the OAuth server for Management MCP) is not announced. **Divider spacing** (`docs/custom.css`) Each `<Update>` has 32px padding top and bottom, and the `---` between entries renders as a prose `hr` with 48px margins above and below, so consecutive entries sat 160px apart. Two rules scoped to the changelog page trim the entry padding to 24px and zero the `hr` margins, so the divider now sits 24px from the content on both sides. `scroll-margin-top` is adjusted to match so anchor links still land on the label. **Favicon** (`docs/favicon-black.svg`, `docs/favicon-white.svg`) Both files now hold the teal brand mark (#29ABE2) instead of the black and white variants, per design. `docs.json` already points at these filenames. ## Review notes - **Webhook verification**: reworded after review and broadened to cover #7430 and #7462. Gmail token verification pre-dates this window; what changed is that unsigned pushes are rejected by default (#7424, with a per-account exception) and Drive/Calendar gained a channel-token check that applies once a webhook secret is saved (#7373). The entry now says exactly that. - **nango.yaml migration guide** (`docs/guides/platform/migrations/migrate-to-zero-yaml.mdx`): the sunset entry links to it, and it still said nango.yaml was supported until the end of 2025 and could be used to roll back. Intro, EOL, and rollback answers updated for the September 15, 2026 sunset. - `mintlify broken-links` passes; no links changed in the follow-up commits. --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> | 6 天前 | |
docs: make BYOC the main self-hosting path (#7453) Reframes self-hosting around Bring Your Own Cloud, splitting one page into two. | Page | URL | In nav | Covers | | - | - | - | - | | **BYOC** | `/guides/platform/self-hosting` (unchanged) | Yes | How BYOC works · Cloud vs BYOC · the access grant · shared responsibility · operations | | **Free self-hosting** | `/guides/platform/free-self-hosting` (new) | No | Install · configure · data stores · hardening · updates | BYOC keeps the existing slug so inbound links and search results land on the page prospects should read. Free self-hosting moves to a new page that is hidden from the nav and linked only from the README and the BYOC page, so old links don't default to it. Cross-references in `security.mdx`, `environments.mdx`, `changelog.mdx`, and the README are repointed, the LLM indexes are regenerated, and `mintlify broken-links` passes. **Note:** two changelog entries pointed at MFA and Management MCP setup instructions that no longer exist on either page. Neither feature is available on free self-hosted, so the links are removed rather than redirected — but that leaves MFA, the audit trail, feature flags, and Management MCP setup without a documented home for paid self-hosted deployments. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Ross McEwan <ross@nango.dev> | 7 天前 | |
docs: audit trail (NAN-6487) (#7164) - **New `guides/platform/audit-trail` page**, linked in the nav under Platform. Documents the resource/action vocabulary, the fields carried on an entry, the actor types, and the fact that entries are produced wherever the operation happens — dashboard, public API, CLI, and the management MCP server, with `context.interface` distinguishing them. Availability is stated as enterprise-by-default with a year of retention, and other paid plans can ask for it. - **An explicit non-coverage section**, which is the part NAN-4530 asks for: a warning that reading a connection's credentials produces no entry (including the SDK helpers built on it), the data-plane exclusions, that reads generally leave no trace, and that self-hosted is not covered yet. - **Corrected the security page's audit claims.** It said "all credential access and modifications are logged", listing credential reads, refresh operations, and API requests using credentials. None of the three hold as written: reading a connection produces no record at all, `connection.refreshed` is recorded only for the explicit refresh endpoint and not for automatic refreshes, and proxy traffic is data plane. The paragraph was describing activity logs while calling them an audit log. ### Why the security page mattered That section is the one a customer reads during a security review, so it is the worst place for an overstatement — it invites reliance on coverage that does not exist. It now points at the audit trail for control-plane changes, repeats the credential-read warning, and keeps activity logs and their OpenTelemetry export as the separate, operational thing they are. Draft until [#7146](https://github.com/NangoHQ/nango/pull/7146) merges. The Actors table documents `connect_session` and `unknown`, which that PR introduces, and the claim that connections are recorded however they are created — Connect UI, OAuth, per-auth-mode endpoints, import — only becomes true with it. The 1-year retention statement lands with #7162. ## Test plan - [x] Event list checked resource by resource against `AuditEventTable`, the compile-time source of truth - [x] Every claim removed from the security page checked against the code: no logging in `getConnection`, and `connection.refreshed` declared only on `PostConnectionRefresh` - [x] `npm run docs:generate:llms` re-run after the edits - [ ] `mintlify broken-links` — **could not run locally**, it refuses to start on Node 25. The two new links from the security page were checked by hand (nav entry in `docs.json`, and the `what-is-not-recorded` anchor exists on the page), but the scan still needs a run on an LTS Node - [ ] Docs preview renders and the nav entry appears in the right place under Platform - [ ] Re-read the Actors table once #7146 is on master, to confirm the vocabulary matches what ships --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Robin Guldener <r.guldener@gmail.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> | 25 天前 | |
docs: replace mentions of secret key with API key (#7107) <!-- Describe the problem and your solution --> Follow-up to the Account API keys docs work (NAN-6569): replace leftover legacy “secret key” terminology across docs with Environment API key / API key language. - Prose and first-request examples now say **Environment API key** - Placeholders use `<NANGO-API-KEY>`; Node examples prefer `apiKey` - Dashboard “secret key” links now point to `/reference/backend/http-api/api-keys` - Preserved CLI `NANGO_SECRET_KEY_<ENV>`, provider Secret Key fields, changelog history, and the deprecated SDK `secretKey` alias - Follow-up commit fixed false positives (Huntress provider wording, placeholder hyphenation, leftover dashboard links) <!-- Issue ticket number and link (if applicable) --> https://linear.app/nango/issue/NAN-6569 <!-- Testing instructions (skip if just adding/editing providers) --> - [x] `mintlify broken-links` from `docs/` - [ ] Spot-check a provider first-request example (cURL + Node) - [ ] Spot-check security, functions CLI, sample app, and webhooks guides - [ ] Confirm CLI `.env` examples still use `NANGO_SECRET_KEY_DEV` / `NANGO_SECRET_KEY_PROD` - [ ] Confirm provider connect docs still say provider Secret Key / API Secret where appropriate Made with [Cursor](https://cursor.com) <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7107?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> | 1 个月前 | |
docs: make BYOC the main self-hosting path (#7453) Reframes self-hosting around Bring Your Own Cloud, splitting one page into two. | Page | URL | In nav | Covers | | - | - | - | - | | **BYOC** | `/guides/platform/self-hosting` (unchanged) | Yes | How BYOC works · Cloud vs BYOC · the access grant · shared responsibility · operations | | **Free self-hosting** | `/guides/platform/free-self-hosting` (new) | No | Install · configure · data stores · hardening · updates | BYOC keeps the existing slug so inbound links and search results land on the page prospects should read. Free self-hosting moves to a new page that is hidden from the nav and linked only from the README and the BYOC page, so old links don't default to it. Cross-references in `security.mdx`, `environments.mdx`, `changelog.mdx`, and the README are repointed, the LLM indexes are regenerated, and `mintlify broken-links` passes. **Note:** two changelog entries pointed at MFA and Management MCP setup instructions that no longer exist on either page. Neither feature is available on free self-hosted, so the links are removed rather than redirected — but that leaves MFA, the audit trail, feature flags, and Management MCP setup without a documented home for paid self-hosted deployments. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Ross McEwan <ross@nango.dev> | 7 天前 | |
docs: make BYOC the main self-hosting path (#7453) Reframes self-hosting around Bring Your Own Cloud, splitting one page into two. | Page | URL | In nav | Covers | | - | - | - | - | | **BYOC** | `/guides/platform/self-hosting` (unchanged) | Yes | How BYOC works · Cloud vs BYOC · the access grant · shared responsibility · operations | | **Free self-hosting** | `/guides/platform/free-self-hosting` (new) | No | Install · configure · data stores · hardening · updates | BYOC keeps the existing slug so inbound links and search results land on the page prospects should read. Free self-hosting moves to a new page that is hidden from the nav and linked only from the README and the BYOC page, so old links don't default to it. Cross-references in `security.mdx`, `environments.mdx`, `changelog.mdx`, and the README are repointed, the LLM indexes are regenerated, and `mintlify broken-links` passes. **Note:** two changelog entries pointed at MFA and Management MCP setup instructions that no longer exist on either page. Neither feature is available on free self-hosted, so the links are removed rather than redirected — but that leaves MFA, the audit trail, feature flags, and Management MCP setup without a documented home for paid self-hosted deployments. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Ross McEwan <ross@nango.dev> | 7 天前 | |
chore(docs): add log retention to docs (#7435) Add logs retention period to the docs. <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7435?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> | 19 天前 | |
docs: recommend OAuth for Management MCP (#7603) <!-- Describe the problem and your solution --> OAuth is now the recommended Management MCP sign-in method, with environment selection and setup examples for Claude Code, Codex, and VS Code. API key authentication is documented as a secondary option for clients without CIMD support, with client-specific examples, while active Beta labels are removed and the generated LLM indexes are refreshed. <!-- Issue ticket number and link (if applicable) --> <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7603?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 6 天前 | |
docs: update docs structure and verify links (#6013) ## Summary - Flatten and reorganize the Reference section into the requested structure: Frontend, Backend, and Functions. - Move Reference files to match the nav: `reference/frontend/frontend-sdk`, `reference/backend/http-api`, `reference/backend/backend-sdk`, and `reference/functions/{functions-cli,functions-sdk}`. - Move API configuration out of `reference/` into `integrations/api-configuration`, where it is linked from the APIs & Integrations tab. - Rename guide files so slugs match page titles, move sync docs under `guides/functions/syncs`, and unnest the platform proxy page. - Update affected Nango docs links across docs, app/CLI doc URLs, provider metadata, agent docs, and generator/source files. - Update snippet generation logic, but intentionally exclude generated docs output from this PR so the diff stays reviewable. - Add docs agent guidance that link-maintenance PRs must only edit links and must run targeted Prettier checks when code URLs change. ## Redirect note - Generated integration/API pages and generated snippets are intentionally unchanged in this PR. - Because those generated files still contain legacy docs paths, `docs.json` keeps redirect coverage for now; pruning redirects before the separate generation PR would break current generated docs links. - Redirect destinations were normalized to current canonical pages and do not include `#` anchors or query params, since Mintlify redirects do not support those. ## Link audit - Checked Nango docs links across the codebase, not just `docs/`. - Current result: 0 invalid docs paths and 0 invalid redirect destinations. - Some legacy generated-output links are still redirect-covered by design and should disappear in the separate generation PR. ## Validation - Custom docs route/redirect audit: passes - Exact-content check for moved Reference files: passes, only expected URL rewrites - Generated output directories/pages have no net diff against the previous PR commit - `npx prettier --check` on changed code files - `git diff --check` Created by Codex. | 4 个月前 | |
docs: make BYOC the main self-hosting path (#7453) Reframes self-hosting around Bring Your Own Cloud, splitting one page into two. | Page | URL | In nav | Covers | | - | - | - | - | | **BYOC** | `/guides/platform/self-hosting` (unchanged) | Yes | How BYOC works · Cloud vs BYOC · the access grant · shared responsibility · operations | | **Free self-hosting** | `/guides/platform/free-self-hosting` (new) | No | Install · configure · data stores · hardening · updates | BYOC keeps the existing slug so inbound links and search results land on the page prospects should read. Free self-hosting moves to a new page that is hidden from the nav and linked only from the README and the BYOC page, so old links don't default to it. Cross-references in `security.mdx`, `environments.mdx`, `changelog.mdx`, and the README are repointed, the LLM indexes are regenerated, and `mintlify broken-links` passes. **Note:** two changelog entries pointed at MFA and Management MCP setup instructions that no longer exist on either page. Neither feature is available on free self-hosted, so the links are removed rather than redirected — but that leaves MFA, the audit trail, feature flags, and Management MCP setup without a documented home for paid self-hosted deployments. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Ross McEwan <ross@nango.dev> | 7 天前 | |
feat(webhooks): verify salesforce webhooks with a Nango webhook secret (NAN-7214) (#7630) NAN-7214 Stacked on #7629. Salesforce webhooks now require the Nango webhook secret in `X-Nango-Webhook-Secret`, taken from the connection metadata `webhookSecret` or the integration secret. Unsigned deliveries stay allowed for accounts with `allow-unauthorized-salesforce-webhook` enabled. <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7630?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 3 天前 | |
feat(server): Connection deleted webhook (#7235) <!-- Describe the problem and your solution --> Adds connection webhook deletion so customers can take appropriate cleanup actions on a connection deletion event <!-- Issue ticket number and link (if applicable) --> [NAN-5591: feat(server): Connection deleted webhook](https://linear.app/nango/issue/NAN-5591/featserver-connection-deleted-webhook) <!-- Testing instructions (skip if just adding/editing providers) --> 1. Configure your webhooks locally to point somewhere like [webhook.site](https://webhook.site/) or a local server for testing 2. Create a new connection if required 3. Delete connection 4. Receive webhook: { "operation": "deletion", "success": true, "type": "auth", ... } 5. Check log for associated entry <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7235?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> | 27 天前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 6 天前 | ||
| 7 天前 | ||
| 25 天前 | ||
| 1 个月前 | ||
| 7 天前 | ||
| 7 天前 | ||
| 19 天前 | ||
| 6 天前 | ||
| 4 个月前 | ||
| 7 天前 | ||
| 3 天前 | ||
| 27 天前 |