* docs: move superpowers/research artifacts to isolated _tasks repo + docs tree cleanup
- Move docs/superpowers/{plans,specs} and docs/research/* into the gitignored,
separately-versioned _tasks/ repo; untrack the two tracked research design docs.
- Add CLAUDE.md "Planning & Research Artifacts" section overriding the superpowers
default save paths (docs/... -> _tasks/...); align REPOSITORY_MAP and
DOCUMENTATION_OVERHAUL_PLAN with the new convention.
- Drop 4 now-obsolete /api/discovery/* entries from check-docs-symbols allowlist
(stale-enforcement) and refresh code/spec path comments to _tasks/...
- Sweeps in concurrent docs-tree restructuring (root-level provider/guide docs,
compression spec cleanup, .mcp.json.example removal).
* docs: reorganize docs/ tree + fix stale facts across ~26 docs
Phase A — reorganization:
- Move 7 orphan root docs into subfolders (providers/ created; TIERS+USAGE_QUOTA→guides/;
plugins+PLUGIN_SDK→frameworks/); delete 8 obsolete/redundant docs (SUBMIT_PR superseded
by CONTRIBUTING; DOCUMENTATION_OVERHAUL_PLAN; INCIDENT_RESPONSE/PERF_BUDGETS/THREAT_MODEL;
3 ops snapshots). Rebuild README index (was missing ~40 files) + per-folder meta.json nav.
- Clean 14 dangling doc-path references in bin/ ops scripts, scripts/, workflow, tests;
fix the dockerignore-docs-coverage required-docs path (PROVIDERS→providers/CLAUDE_WEB).
Phase B — content accuracy (verified against code, not the audit summary):
- Functional: ENVIRONMENT flag defaults (INPUT_SANITIZER/MCP_ENFORCE_SCOPES=true,
COMPRESS_DESCRIPTIONS=false, dynamic heap); MCP-SERVER notion tool names (omniroute_*→
notion_*) + counts 87→94; coverage gate 75/70→60/60/60/60 (RELEASE_CHECKLIST, COVERAGE_PLAN,
ERROR_SANITIZATION, CONTRIBUTING); pre-push hook description; regenerate PROVIDER_REFERENCE (237).
- Count drift: providers 237, executors 70, migrations 106, db modules 94, oauth 19,
strategies 17, MCP 94, flags 38, TS 6.0, open-sse ~900/services 294 across architecture/
frameworks/ops docs; AUTO-COMBO 9→12 factors w/ correct DEFAULT_WEIGHTS; REASONING +2
patterns; STEALTH UA defaults; AGENT_PROTOCOLS +cursor-cloud/list-capabilities;
LANGUAGE_PACKS +id pack.
- Kept Node 20 (runtime guard accepts 20.20.2+; only engines is stricter) and MCP scopes=13
(mcpScopes.ts) — both were correct in the docs; corrected only the attribution.
* docs: finish content refresh — compression engines, CLI_TOKEN merge, metadata sweep
- Compression: document the additional built-in engines (CCR, headroom, ionizer,
session-dedup) in COMPRESSION_ENGINES; clarify LLMLingua-2 is the ultra-mode SLM
backend + cross-ref the extra engines in EXTENDING_COMPRESSION; add the id
(Indonesian) language pack to LANGUAGE_PACKS.
- AUTO-COMBO: replace the orphan 'How tiers fit' weight table (stale weights) with a
pointer to the canonical 12-factor DEFAULT_WEIGHTS table.
- Security: merge CLI_TOKEN_AUTH.md (legacy 32-char SHA-256 format) into CLI_TOKEN.md
as a 'Legacy format — still accepted' section (server accepts both HMAC + legacy),
delete CLI_TOKEN_AUTH.md, drop it from the index + security nav.
- Metadata: bump stale frontmatter (version/lastUpdated) to 3.8.40/2026-06-28 across the
doc set audited this pass, and normalize the in-body 'Last updated' header lines to match.
* fix(runtime): drop Node 20 from supported range + align all docs/diagrams/counts
- Node minimum is now 22 (aligned with package.json engines). SUPPORTED_NODE_RANGE in
src/shared/utils/nodeRuntimeSupport.ts (and the bin/ mirror) drops the 20.x line →
'>=22.22.2 <23 || >=24.0.0 <27'; getNodeRuntimeSupport now rejects Node 20 as
unsupported-major. Test updated (TDD): node-runtime-support.test.ts asserts Node 20
rejected. Docs aligned (TROUBLESHOOTING ×2, TERMUX, RELEASE_CHECKLIST, CODEBASE,
CLI-TOOLS, README, llm.txt + 42 i18n llm.txt mirrors, skills/cli-serve).
- Diagrams regenerated: mcp-tools-87 -> mcp-tools-94 (34 base + pool 6 = 94) and
auto-combo-9factor -> auto-combo-12factor (correct DEFAULT_WEIGHTS); SVGs re-rendered
via mermaid-cli; doc refs + diagrams/README updated; fixed a pre-existing broken
resilience-3layers image path.
- CLAUDE.md + AGENTS.md aligned to real counts (237 providers, 94 MCP tools / 34 base,
106 migrations, 94 db modules, 12-factor auto-combo, 17 strategies); README provider
count 231 -> 237; executor count corrected to 68 (provider executors, excl base/index)
and OAuth to 18 across architecture docs. check:docs-all now passes (0 strict drift,
0 broken links); removed dead .mcp.json.example doc link.
* fix(services): update installer Node hint to >=22.22.2 (aligned with dropped Node 20)
* docs: realign counts to current release tip after rebase
The release tip advanced while this work was in flight (Gemini CLI provider/executor
removed by #5246, plus other PRs). Re-counted against the current code and updated:
providers 237->236, executors 68->67, OAuth modules 18->17, open-sse services 294->298;
regenerated PROVIDER_REFERENCE.md (236). check:docs-all passes (0 strict drift).
* docs(changelog) + i18n: record Node 20 drop + fix nodeIncompatibleHint
- CHANGELOG: add [3.8.40] entries for the Node 20.x removal (runtime) and the docs
reorganization/accuracy audit.
- i18n: nodeIncompatibleHint across all 42 locales no longer lists Node 20.x as
supported (ASCII + CJK full-width variants), aligned with the dropped Node 20.
* fix(docs): repair CI breakages from the doc moves
- test: cli-plugin-system asserted docs/dev/plugins.md exists; the file moved to
docs/frameworks/PLUGINS.md — point the test at the new path (Unit fast-path 2/2 fix).
- frontmatter: PLUGINS.md and PLUGIN_SDK.md moved into the fumadocs-indexed
docs/frameworks/ which requires a 'title' frontmatter; the missing frontmatter
failed the Next.js MDX build (dast-smoke 'invalid frontmatter'). Added frontmatter
to both, plus the providers/ docs (consistency; that folder is not indexed).
6.6 KiB
title, version, lastUpdated
| title | version | lastUpdated |
|---|---|---|
| Notion Context Source | 3.8.40 | 2026-06-28 |
Notion Context Source
Source of truth:
src/lib/notion/api.ts(REST client),src/lib/db/notion.ts(token persistence),open-sse/mcp-server/tools/notionTools.ts(6 MCP tools),src/app/api/settings/notion/route.ts(settings API). Tool registration and scope wiring lives inopen-sse/mcp-server/server.ts.
What it is
OmniRoute can connect to a Notion workspace as a context source — a read/write knowledge base that agents reach through the built-in MCP server. Once a Notion integration token is configured, the MCP tools let an LLM search pages and databases, read page content and block trees, query databases with filters/sorts, and append new blocks — all proxied through OmniRoute (with retry, timeout, and error classification) so the model never touches the Notion API directly.
The integration is a thin, hardened wrapper over the official Notion REST API
(https://api.notion.com/v1, Notion-Version: 2026-03-11). The client
(src/lib/notion/api.ts) adds:
- Retry with exponential backoff (up to 3 attempts) for
429and5xx. - 55-second request timeout via
AbortController. - Typed error classification —
NotionAuthError(401/403),NotionNotFoundError(404),NotionRateLimitError(429, honorsretry afterhints),NotionValidationError(400/409),NotionServerError(5xx),NotionTimeoutError. - Message sanitization that strips stack-trace-like fragments before surfacing.
Setup
There is no environment variable for the Notion token — it is stored in the
SQLite key_value table (namespace notion, key integration_token) via
src/lib/db/notion.ts. Configure it from the Context Sources tab of the Endpoint
dashboard (ObsidianSourceCard's sibling NotionSourceCard), or via the settings REST API.
Note
The token is a Notion internal integration token. Create an integration at https://www.notion.com/my-integrations, then share the pages/databases you want OmniRoute to access with that integration (Notion's permission model is share-based, not workspace-wide).
Configure via REST
# Save + validate the integration token (POST validates by issuing a test search)
curl -X POST http://localhost:20128/api/settings/notion \
-H "Content-Type: application/json" \
-d '{"token":"ntn_xxx"}'
# Check connection status
curl http://localhost:20128/api/settings/notion
# Disconnect (clears the stored token)
curl -X DELETE http://localhost:20128/api/settings/notion
All three methods require dashboard authentication (isAuthenticated). On POST,
OmniRoute saves the token and immediately runs a 1-result test search; if Notion
returns an error object the token is cleared and the call fails with 400.
MCP tools (6)
Defined in open-sse/mcp-server/tools/notionTools.ts. The token is resolved at call
time via getNotionToken(); if none is configured the tool throws
"Notion integration token not configured. Set it in Settings > Context Sources."
| Tool | Scope | Description |
|---|---|---|
notion_search |
read:notion |
Search pages and databases by text query (returns titles, IDs, URLs). Paginated. |
notion_get_page |
read:notion |
Get content and metadata of a page by its ID. |
notion_list_block_children |
read:notion |
List all block children of a block or page (the block tree). Paginated. |
notion_query_database |
read:notion |
Query a database with optional filter + sorts (Notion API format). Paginated. |
notion_get_database |
read:notion |
Get the schema/metadata of a database by ID. |
notion_append_blocks |
write:notion |
Append block children to an existing block or page (max 100 blocks per request). |
Input parameters
notion_search—query(1–500 chars),pageSize(1–100, default 20),startCursor(optional).notion_get_page—pageId(32-char hex or UUID).notion_list_block_children—blockId,pageSize(1–100, default 50),startCursor(optional).notion_query_database—databaseId,filter(optional, Notion filter format),sorts(optional array),pageSize(1–100, default 50),startCursor(optional).notion_get_database—databaseId.notion_append_blocks—blockId,children(array of block objects),after(optional position).
Scopes
The read tools require read:notion and the write tool requires write:notion.
Scopes are enforced by withScopeEnforcement() in
open-sse/mcp-server/server.ts only when OMNIROUTE_MCP_ENFORCE_SCOPES=true; the
caller's allowed scopes come from OMNIROUTE_MCP_SCOPES (comma-separated) or the
authenticated API key's scope context. See MCP-SERVER.md for the
full scope model.
Endpoints
| Method | Path | Purpose |
|---|---|---|
GET |
/api/settings/notion |
Return { connected, hasToken }. |
POST |
/api/settings/notion |
Save + validate the integration token. |
DELETE |
/api/settings/notion |
Disconnect (clear the stored token). |
These are dashboard settings routes. There is no public
/v1Notion proxy endpoint — Notion is reached exclusively through the MCP tools above.
Use cases
- Knowledge-grounded answers — let an agent
notion_searchthe workspace andnotion_get_pagethe top hit before answering, so responses cite real internal docs. - Database-backed workflows —
notion_query_databasea tasks/CRM database with filters + sorts, then summarize or triage the rows. - Write-back / logging —
notion_append_blocksto append meeting notes, run summaries, or agent output into an existing page (append-only; no destructive edits). - Structure exploration —
notion_list_block_childrento walk a page's block tree, ornotion_get_databaseto discover a database's property schema before querying it.
Related
- MCP Server — transports, scope enforcement, full tool inventory.
- Obsidian Context Source — the other built-in context source.
- Memory System — persistent conversational memory (complementary context layer, injected automatically rather than tool-fetched).