Skip to content

feat(api): update API spec from langfuse/langfuse 24f89b2 - #1000

Closed
langfuse-bot wants to merge 1 commit into
mainfrom
api-spec-bot-24f89b2-37661365756-1
Closed

langfuse-bot wants to merge 1 commit into
mainfrom
api-spec-bot-24f89b2-37661365756-1

Conversation

@langfuse-bot

@langfuse-bot langfuse-bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

RetriggerConfidence Score: 4/5

Fix the single-score return type before merging; it breaks TypeScript checking in the existing compatibility alias.

Summary

Updates the generated API client with batch score creation, an unstable skills API, prompt filters, and API-key names and expiration fields. It also refreshes ingestion sunset and real-time API documentation.

  • Preserve the single-score return type before merging; the existing compatibility alias no longer type-checks.
  • Correct the skill hash documentation so callers do not encode values twice.

Reviews (1) · Last reviewed commit: "feat(api): update API spec from langfuse..." · Reviewed by Greptile

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
langfuse-js Error Error Oct 7, 2026 5:46pm UTC

Request Review

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

@claude review

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

No review was started: this request came from a bot account. Manual reviews can only be requested by someone with write access to this repository. Ask a maintainer to comment @claude review, or have your automation post the comment from a user account with write access.

Tip: disable this comment in your organization's Code Review settings.

Comment on lines 93 to +96
public create(
request: LangfuseAPI.CreateScoreRequest,
request: LangfuseAPI.CreateScoresRequest,
requestOptions?: Scores.RequestOptions,
): core.HttpResponsePromise<LangfuseAPI.CreateScoreResponse> {
): core.HttpResponsePromise<LangfuseAPI.CreateScoresResponse> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Single-score calls stop compiling

Scores.create() now returns CreateScoresResponse even for a single score. The existing ScoreV1.create() alias returns that result but promises CreateScoreResponse, which requires id. The batch response types have no id, so the alias no longer type-checks. Existing single-score callers also lose typed access to id.

Add separate overloads for single-score and batch requests to preserve the single-score return type.

Prompt To Fix With AI
This is a comment left during a code review.
Path: packages/core/src/api/api/resources/scores/client/Client.ts
Line: 93-96

Comment:
**Single-score calls stop compiling**

`Scores.create()` now returns `CreateScoresResponse` even for a single score. The existing `ScoreV1.create()` alias returns that result but promises `CreateScoreResponse`, which requires `id`. The batch response types have no `id`, so the alias no longer type-checks. Existing single-score callers also lose typed access to `id`.

Add separate overloads for single-score and batch requests to preserve the single-score return type.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

* }
*/
export interface GetSkillFileContentsRequest {
/** Comma-separated list of one to 50 canonical base64-encoded SHA-256 hashes from skill file manifests. URL-encode the value, including +, /, and = characters. */

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Hashes get encoded twice

The sha256Hashes documentation tells callers to URL-encode the value, but the client already does that. Following this instruction turns %2B, %2F, and %3D into %252B, %252F, and %253D. The request then carries percent escapes instead of the original base64 hashes, preventing callers from reading the requested files.

Tell callers to pass the raw comma-separated hashes; the SDK encodes them.

Suggested change
/** Comma-separated list of one to 50 canonical base64-encoded SHA-256 hashes from skill file manifests. URL-encode the value, including +, /, and = characters. */
/** Comma-separated list of one to 50 canonical base64-encoded SHA-256 hashes from skill file manifests. Pass the raw hashes; the SDK URL-encodes the value. */
Prompt To Fix With AI
This is a comment left during a code review.
Path: packages/core/src/api/api/resources/unstable/resources/skills/client/requests/GetSkillFileContentsRequest.ts
Line: 12

Comment:
**Hashes get encoded twice**

The `sha256Hashes` documentation tells callers to URL-encode the value, but the client already does that. Following this instruction turns `%2B`, `%2F`, and `%3D` into `%252B`, `%252F`, and `%253D`. The request then carries percent escapes instead of the original base64 hashes, preventing callers from reading the requested files.

Tell callers to pass the raw comma-separated hashes; the SDK encodes them.

```suggestion
  /** Comma-separated list of one to 50 canonical base64-encoded SHA-256 hashes from skill file manifests. Pass the raw hashes; the SDK URL-encodes the value. */
```

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

@niklassemmler

Copy link
Copy Markdown
Contributor

FYI I have removed the code changes I am responsible from this PR. The following are remaining

Owner Upstream PR(s) JS files Size
@tobi12345 langfuse/langfuse#17803, langfuse/langfuse#18062 (skills) core/src/api/.../unstable/resources/skills/*, unstable/client/Client.ts, unstable/resources/index.ts +1241
@tobi12345 langfuse/langfuse#17779 (prompt name prefix filter) prompts/client/{Client,requests/ListPromptsMetaRequest}.ts (new filter param) +41 / −2
@marliessophie langfuse/langfuse#18408 (batch POST /scores) scores/* +72 / −12
@maxdeichmann langfuse/langfuse#17261, langfuse/langfuse#17453 (ingestion _deprecation, sunset docs) ingestion/* +44 / −20
@maxdeichmann langfuse/langfuse#17468 (real-time path docs) {metrics,observations,opentelemetry}/client/Client.ts +6
@marksalpeter langfuse/langfuse#17952 (RBAC API keys) projects/*, organizations/types/OrganizationApiKey.ts +38 / −1

This includes breaking changes:

  • @marliessophie: this breaks the build and is breaking for TS callers. scores.create() now takes CreateScoresRequest (single score or array) and returns the union CreateScoresResponse = CreateScoreResponse | CreateScoreBatchResponse | CreateScoreBatchResults.
    • Widening the request is fine.
    • The return type is the problem. The legacy alias ScoreV1.create() (written by scripts/patch-generated-score-create-alias.mjs, from fix(api): preserve score create compatibility #888) still declares CreateScoreResponse, which gives TS2322 in legacy/resources/scoreV1/client/Client.ts:74.
    • In user code, (await langfuse.api.scores.create({...})).id no longer type-checks without narrowing.
    • Greptile suggests overloads: single score returns CreateScoreResponse, array returns the batch types. If the patch script can add them, we avoid a major. Otherwise this waits for the next major.
  • @maxdeichmann: breaking type exports. SdkLogEvent, SdkLogBody and IngestionEvent.SdkLog are removed (docs(api): warn on sunset ingestion event types langfuse#17453). Any import type { SdkLogEvent } from "@langfuse/core" breaks, even though the server still accepts sdk-log events. Nothing in the SDK packages uses them, so only types are affected, not runtime.
  • @tobi12345:
    • Please check that the skills client endpoints match upstream.
    • Greptile also flagged the sha256Hashes doc in GetSkillFileContentsRequest.ts. It tells callers to URL-encode the hashes, but the client already does, so they'd get double-encoded (%252B). That fix belongs upstream in the Fern definition.
  • @marksalpeter: no break. name and expiresAt are added, and note is kept but marked @deprecated.

🤖 Summaries Generated with Claude

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Beyond the inline finding on Scores.create's widened return type breaking the legacy scoreV1 compatibility shim, I also checked the new expiresAt null-ability doc comment on ApiKeySummary/OrganizationApiKey — the field's type (string | undefined) is unchanged by this diff (only a comment was added), so that doc/type mismatch is pre-existing and not a regression introduced here.

Extended reasoning...

The diff is entirely Fern-generated API client code (types and Client.ts files), the largest piece being a new "skills" resource plus smaller additions to scores, ingestion, and API-key types; none of it is hand-written business logic and there is no injection/auth-surface change. I independently confirmed the already-flagged bug: scores/client/Client.ts now returns the union CreateScoresResponse from create(), while legacy/resources/scoreV1/client/Client.ts (lines 70-75, untouched by this diff) still declares HttpResponsePromise<CreateScoreResponse> and delegates to it — I traced this to scripts/patch-generated-score-create-alias.mjs, the repo's custom post-codegen patch that keeps the two create() methods in sync but did not account for the canonical method's return type widening. That is a real, non-trivial type-safety regression tied to this repo's custom generation pipeline, so a human should confirm the regen/patch script is updated before merging.

Comment on lines 93 to +96
public create(
request: LangfuseAPI.CreateScoreRequest,
request: LangfuseAPI.CreateScoresRequest,
requestOptions?: Scores.RequestOptions,
): core.HttpResponsePromise<LangfuseAPI.CreateScoreResponse> {
): core.HttpResponsePromise<LangfuseAPI.CreateScoresResponse> {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Widening Scores.create's return type to LangfuseAPI.CreateScoresResponse (a union of CreateScoreResponse | CreateScoreBatchResponse | CreateScoreBatchResults) breaks the unregenerated compatibility shim in legacy/resources/scoreV1/client/Client.ts:70-75, which still declares core.HttpResponsePromise<LangfuseAPI.CreateScoreResponse> while delegating to new Scores(this._options).create(...). Since HttpResponsePromise exposes withRawResponse(): Promise<WithRawResponse<T>> (data: T is covariant), returning the now-wider union where the narrower single type is declared is a type error, so tsc -b --noEmit (root typecheck/check:type scripts) and pnpm build's tsup dts: true declaration emit fail for @ langfuse/core. … [also at: packages/core/src/api/api/resources/legacy/resources/scoreV1/client/Client.ts:75 - Maintainers get a package that fails to type-check: Scores.create() widened its return type, but the legacy ScoreV1.create() alias (which just forwards to it) still declares the old narrow return type. scores/client/Client.ts:93-96 now returns…]

Why this was flagged

…Fix: regenerate/patch legacy/scoreV1/client/Client.ts's create() signature (via scripts/patch-generated-score-create-alias.mjs) whenever Scores.create's request/response types change, keeping both aliases' declared types consistent with the canonical implementation.

legacy/resources/scoreV1/client/Client.ts:70-75 (untouched by this diff; confirmed via git diff) declares public create(request: LangfuseAPI.CreateScoreRequest): core.HttpResponsePromise<LangfuseAPI.CreateScoreResponse> and returns new Scores(this._options).create(request, requestOptions). After this diff, Scores.create (scores/client/Client.ts:93-96) returns core.HttpResponsePromise<LangfuseAPI.CreateScoresResponse>, a union including CreateScoreBatchResponse/CreateScoreBatchResults.

Verification: normal. The diff widens Scores.create's return type at scores/client/Client.ts:93-96 to core.HttpResponsePromise<LangfuseAPI.CreateScoresResponse>, where CreateScoresResponse.ts:7-10 defines CreateScoreResponse | CreateScoreBatchResponse | CreateScoreBatchResults.

This branch had an error being deployed

1 failed deployment
Preview — 55f6e7b0 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants