NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2299 most downloaded on PyPI
Official Box Python SDK
Last release 8 days ago
09 Sep 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
121 releases · first in 2015
Fix bug when thumbnail representations are not found
Bug Fixes:
Add metadata query functionality
One column per quarter.
Deprecate and add method for getting a thumbnail
New Features and Enhancements:
__New Features and Enhancements:__
Fix exception handling for OAuth
Added support for token exchange using shared links
Fixed bug in _get_retry_request_callable introduced in release 2.7.0 which caused chunked uploads to fail
_get_retry_request_callable introduced in release 2.7.0 which caused chunked uploads to failFixed bug in get_admin_events function which caused errors when the optional event_types parameter was omitted.
Added api_ call decorator for copy method.
Adding a new get admin events function with created_before, created_after, and event_type parameters. Thank you @capk1rk!
Adding a new get admin events function with created_before, created_after, and event_type parameters. Thank you @capk1rk!
Allowed passing None to clear configurable_permission field in the add_member() method.
Allowed passing None to clear configurable_permission field in the add_member() method.
Added ability for users to use set metadata on files and folders
Added ability to set metadata on a file or a folder
Fixing an issue in v2.3.1 where package could not be installed.
Fixing an issue in v2.3.0 where package could not be installed.
Added the ability to set file description upon upload
Updated requests-toolbelt dependency restriction
Fixing an issue in v2.2.0 where package could not be installed.
Added abilty for user to retrieve an avatar for a user.
Added ability for user to chunk upload files and resume uploads for interrupted uploads.
.response_object() method on an API object could throw.All custom format strings will now have to use the same keyword format placeholders. Though this is a breaking change, the good news is that using key…
Breaking Changes
Python 2.6 is no longer supported.
Python 3.3 is no longer supported.
client.search() now returns a Search object that exposes a query() method to call the Search API.
Use client.search().query(**search_params) instead of client.search(**search_params).
client.get_memberships(...) has a change in signature. The limit and offset parameters have swapped positions to keep
consistency with the rest of the SDK.
client.groups(...) has been changed to client.get_groups. The limit and offset parameters have swapped positions.
The unshared_at parameter for item.create_shared_link(...) and file.get_shared_link_download_url(...)
now takes an RFC3339-formatted <https://tools.ietf.org/html/rfc3339#section-5.8> unicode string instead of a
datetime.date. Users migrating from v1.x can pass the value of date.isoformat() instead of the date
object itself.
Events.get_events(...) now returns a list of Event instances rather than a list of dict
representing events. Event inherits from Mapping but will not have all the same capabilities as
dict.
Your code is affected if you use Events.get_events(...) and expect a list of dict rather than a list of
Mapping. For example, if you use __setitem__ (event['key'] = value), update(), copy(), or
if your code depends on the str or repr of the Event. Use of __getitem__ (event['key']),
get(), and other Mapping methods is unaffected. See
https://docs.python.org/2.7/library/collections.html#collections-abstract-base-classes for methods supported on
Mapping instances.
Migration: If you still need to treat an Event as a dict, you can get a deepcopy of the original dict
using the new property on BaseAPIJSONObject, response_object.
LoggingNetwork has been removed. Logging calls are now made from the DefaultNetwork class. In addition,
the logging format strings in this class have changed in a way that
will break logging for any applications that have overridden any of these
strings. They now use keyword format placeholders instead of positional
placeholders. All custom format strings will now have to use the same keyword
format placeholders. Though this is a breaking change, the good news is that
using keyword format placeholders means that any future changes will be
automatically backwards-compatibile (as long as there aren't any changes to
change/remove any of the keywords).
File.update_contents() and File.update_contents_with_stream() now
correctly return a File object with the correct internal JSON structure.
Previously it would return a File object where the file JSON is hidden
inside file['entries'][0]. This is a bugfix, but will be a breaking
change for any clients that have already written code to handle the bug.
Comparing two objects (e.g. a File and a Folder) that have the same Box ID but different types with ==
will now correctly return False.
The following methods now return iterators over the entire collection of returned objects, rather than a single page:
client.users()client.groups()client.search().query()folder.get_items()Since folder.get_items() now returns an iterator, folder.get_items_limit_offset() and
folder.get_items_marker() have been removed. To use marker based paging with folder.get_items(),
pass the use_marker=True parameter and optionally specify a marker parameter to begin paging from that
point in the collection.
Additionally, group.membership() has been renamed to group.get_memberships(), and returns an iterator of
membership objects. This method no longer provides the option to return tuples with paging information.
The Translator class has been reworked; translator.get(...) still returns the constructor for the object class
corresponding to the passed in type, but translator.translate(...) now takes a Session and response object
directly and produces the translated object. This method will also translate any nested objects found.
GroupMembership to have a custom constructor; it now uses the default
BaseObject constructor.Features
All publicly documented API endpoints and parameters should now be supported by the SDK
Added more flexibility to the object translation system:
Translator instances, which can extend or
not-extend the global default Translator.BoxSession with a custom Translator.Translator which is associated
with a BoxSession or a Client.Translator that is
referenced by the BoxSession, instead of directly using the global
default Translator.translator.translate()When the auto_session_renewal is True when calling any of the request
methods on BoxSession, if there is no access token, BoxSession will
renew the token before making the request. This saves an API call.
Auth objects can now be closed, which prevents them from being used to
request new tokens. This will also revoke any existing tokens (though that
feature can be disabled by passing revoke=False). Also introduces a
closing() context manager method, which will auto-close the auth object
on exit.
Various enhancements to the JWTAuth baseclass:
authenticate_app_user() method is renamed to
authenticate_user(), to reflect that it may now be used to authenticate
managed users as well. See the method docstring for details.
authenticate_app_user() is now an alias of authenticate_user(), in
order to not introduce an unnecessary backwards-incompatibility.user argument to authenticate_user() may now be either a user
ID string or a User instance. Before it had to be a User instance.user keyword argument, which
may be a user ID string or a User instance. When this is passed,
authenticate_user() and can be called without passing a value for the
user argument. More importantly, this means that refresh() can be
called immediately after construction, with no need for a manual call to
authenticate_user(). Combined with the aforementioned improvement to
the auto_session_renewal functionality of BoxSession, this means
that authentication for JWTAuth objects can be done completely
automatically, at the time of first API call.rsa_private_key_file_sys_path
parameter is now optional, but it is required to pass exactly one of
rsa_private_key_file_sys_path or rsa_private_key_data.enterprise_id argument to JWTAuth is allowed to
be None.authenticate_instance() now accepts an enterprise argument, which
can be used to set and authenticate as the enterprise service account user,
if None was passed for enterprise_id at construction time.Added an Event class.
Moved metadata() method to Item so it's now available for Folder
as well as File.
The BaseAPIJSONObject baseclass (which is a superclass of all API
response objects) now supports __contains__ and __iter__. They behave
the same as for Mapping. That is, __contains__ checks for JSON keys
in the object, and __iter__ yields all of the object's keys.
Added a RecentItem class.
Added client.get_recent_items() to retrieve a user's recently accessed items on Box.
Added support for the can_view_path parameter when creating new collaborations.
Added BoxObjectCollection and subclasses LimitOffsetBasedObjectCollection and
MarkerBasedObjectCollection to more easily manage paging of objects from an endpoint.
These classes manage the logic of constructing requests to an endpoint and storing the results,
then provide __next__ to easily iterate over the results. The option to return results one
by one or as a Page of results is also provided.
Added a downscope_token() method to the Client class. This generates a token that
has its permissions reduced to the provided scopes and for the optionally provided
File or Folder.
Added methods for configuring JWTAuth from config file: JWTAuth.from_settings_file and
JWTAuth.from_settings_dictionary.
Added network_response property to BoxOAuthException.
API Configuration can now be done per BoxSession instance.
Other
BoxAPIException.collaboration() method to Client.BaseEndpoint was the parent of BaseObject which was the parent
of all smart objects. Now BaseObject is a child of both BaseEndpoint and BaseAPIJSONObject.
BaseObject is the parent of all objects that are a part of the REST API. Another subclass of
BaseAPIJSONObject, APIJSONObject, was created to represent pseudo-smart objects such as Event that are not
directly accessible through an API endpoint.network_response_constructor as an optional property on the
Network interface. Implementations are encouraged to override this
property, and use it to construct NetworkResponse instances. That way,
subclass implementations can easily extend the functionality of the
NetworkResponse, by re-overriding this property. This property is defined
and used in the DefaultNetwork implementation.LoggingNetworkResponse class (which is
made possible by the aforementioned network_response_constructor
property). Now the SDK decides whether to log the response body, based on
whether the caller reads or streams the content.LoggingNetwork.LoggingNetwork.JWTAuth.refresh() correctly matches
that of the auth interface (by returning a tuple of
((access token), (refresh token or None)), instead of just the access token).
In particular, this fixes an exception in BoxSession that always occurred
when it tried to refresh any JWTAuth object.ExtendableEnumMeta.__dir__().Nothing published for this version
Nothing published for this version
(Breaking change) Removed the downscope_token() method from the OAuth2 class.
downscope_token() method from the OAuth2 class.can_view_path parameter when creating new collaborations.downscope_token() method to the Client class. This generates a token that has its permissions reduced to the provided scopes and for the optionally provided File or Folder.JWTAuth from config file: JWTAuth.from_settings_file and JWTAuth.from_settings_dictionary.network_response property to BoxOAuthException.Increased required minimum version of six to 1.9.0.
**kwargs to JWTAuth constructor. Fixes #231.downscope_token() to return a TokenResponse object. (Breaking interface change from v2.0.0a8.)Nothing published for this version
Auth objects can now be closed, which prevents them from being used to request new tokens. This will also revoke any existing tokens (though that feat
revoke=False). Also introduces a
closing() context manager method, which will auto-close the auth object
on exit.This is a bugfix, but will be a breaking change for any clients that have already written code to handle the bug.
Breaking Changes
File.update_contents() and File.update_contents_with_stream() now
correctly return a File object with the correct internal JSON structure.
Previously it would return a File object where the file JSON is hidden
inside file['entries'][0]. This is a bugfix, but will be a breaking
change for any clients that have already written code to handle the bug.Features
JWTAuth constructor now supports passing the RSA private key in two different
ways: by file system path (existing functionality), or by passing the key
data directly (new functionality). The rsa_private_key_file_sys_path
parameter is now optional, but it is required to pass exactly one of
rsa_private_key_file_sys_path or rsa_private_key_data.Other
JWTAuth.refresh() correctly matches
that of the auth interface (by returning a tuple of
((access token), (refresh token or None)), instead of just the access token).
In particular, this fixes an exception in BoxSession that always occurred
when it tried to refresh any JWTAuth object.Nothing published for this version
All custom format strings will now have to use the same keyword format placeholders. Though this is a breaking change, the good news is that using key…
Breaking Changes
Events.get_events(...) now returns a list of Event instances rather than a list of dict
representing events. Event inherits from Mapping but will not have all the same capabilities as
dict.
Events.get_events(...) and expect a list of dict rather than a list of
Mapping. For example, if you use __setitem__ (event['key'] = value), update(), copy(), or
if your code depends on the str or repr of the Event. Use of __getitem__ (event['key']),
get(), and other Mapping methods is unaffected. See
https://docs.python.org/2.7/library/collections.html#collections-abstract-base-classes for methods supported on
Mapping instances.Event as a dict, you can get a deepcopy of the original dict
using the new property on BaseAPIJSONObject, response_object.LoggingNetwork have changed in a way that
will break logging for any applications that have overridden any of these
strings. They now use keyword format placeholders instead of positional
placeholders. All custom format strings will now have to use the same keyword
format placeholders. Though this is a breaking change, the good news is that
using keyword format placeholders means that any future changes will be
automatically backwards-compatibile (as long as there aren't any changes to
change/remove any of the keywords).Features
Translator instances, which can extend or
not-extend the global default Translator.BoxSession with a custom Translator.Translator which is associated
with a BoxSession or a Client.Translator that is
referenced by the BoxSession, instead of directly using the global
default Translator.auto_session_renewal is True when calling any of the request
methods on BoxSession, if there is no access token, BoxSession will
renew the token before making the request. This saves an API call.JWTAuth baseclass:
authenticate_app_user() method is renamed to
authenticate_user(), to reflect that it may now be used to authenticate
managed users as well. See the method docstring for details.
authenticate_app_user() is now an alias of authenticate_user(), in
order to not introduce an unnecessary backwards-incompatibility.user argument to authenticate_user() may now be either a user
ID string or a User instance. Before it had to be a User instance.user keyword argument, which
may be a user ID string or a User instance. When this is passed,
authenticate_user() and can be called without passing a value for the
user argument. More importantly, this means that refresh() can be
called immediately after construction, with no need for a manual call to
authenticate_user(). Combined with the aforementioned improvement to
the auto_session_renewal functionality of BoxSession, this means
that authentication for JWTAuth objects can be done completely
automatically, at the time of first API call.enterprise_id argument to JWTAuth is allowed to
be None.authenticate_instance() now accepts an enterprise argument, which
can be used to set and authenticate as the enterprise service account user,
if None was passed for enterprise_id at construction time.Event class.metadata() method to Item so it's now available for Folder
as well as File.BaseAPIJSONObject baseclass (which is a superclass of all API
response objects) now supports __contains__ and __iter__. They behave
the same as for Mapping. That is, __contains__ checks for JSON keys
in the object, and __iter__ yields all of the object's keys.Other
BoxAPIException.collaboration() method to Client.BaseEndpoint was the parent of BaseObject which was the parent
of all smart objects. Now BaseObject is a child of both BaseEndpoint and BaseAPIJSONObject.
BaseObject is the parent of all objects that are a part of the REST API. Another subclass of
BaseAPIJSONObject, APIJSONObject, was created to represent pseudo-smart objects such as Event that are not
directly accessible through an API endpoint.network_response_constructor as an optional property on the
Network interface. Implementations are encouraged to override this
property, and use it to construct NetworkResponse instances. That way,
subclass implementations can easily extend the functionality of the
NetworkResponse, by re-overriding this property. This property is defined
and used in the DefaultNetwork implementation.LoggingNetworkResponse class (which is
made possible by the aforementioned network_response_constructor
property). Now the SDK decides whether to log the response body, based on
whether the caller reads or streams the content.LoggingNetwork.LoggingNetwork.ExtendableEnumMeta.__dir__().All custom format strings will now have to use the same keyword format placeholders. Though this is a breaking change, the good news is that using key…
Breaking Changes
Events.get_events(...) now returns a list of Event instances rather than a list of dict
representing events. Event inherits from Mapping but will not have all the same capabilities as
dict.
Events.get_events(...) and expect a list of dict rather than a list of
Mapping. For example, if you use __setitem__ (event['key'] = value), update(), copy(), or
if your code depends on the str or repr of the Event. Use of __getitem__ (event['key']),
get(), and other Mapping methods is unaffected. See
https://docs.python.org/2.7/library/collections.html#collections-abstract-base-classes for methods supported on
Mapping instances.Event as a dict, you can get a deepcopy of the original dict
using the new property on BaseAPIJSONObject, response_object.LoggingNetwork have changed in a way that
will break logging for any applications that have overridden any of these
strings. They now use keyword format placeholders instead of positional
placeholders. All custom format strings will now have to use the same keyword
format placeholders. Though this is a breaking change, the good news is that
using keyword format placeholders means that any future changes will be
automatically backwards-compatibile (as long as there aren't any changes to
change/remove any of the keywords).Features
Translator instances, which can extend or
not-extend the global default Translator.BoxSession with a custom Translator.Translator which is associated
with a BoxSession or a Client.Translator that is
referenced by the BoxSession, instead of directly using the global
default Translator.auto_session_renewal is True when calling any of the request
methods on BoxSession, if there is no access token, BoxSession will
renew the token before making the request. This saves an API call.JWTAuth baseclass:
authenticate_app_user() method is renamed to
authenticate_user(), to reflect that it may now be used to authenticate
managed users as well. See the method docstring for details.
authenticate_app_user() is now an alias of authenticate_user(), in
order to not introduce an unnecessary backwards-incompatibility.user argument to authenticate_user() may now be either a user
ID string or a User instance. Before it had to be a User instance.user keyword argument, which
may be a user ID string or a User instance. When this is passed,
authenticate_user() and can be called without passing a value for the
user argument. More importantly, this means that refresh() can be
called immediately after construction, with no need for a manual call to
authenticate_user(). Combined with the aforementioned improvement to
the auto_session_renewal functionality of BoxSession, this means
that authentication for JWTAuth objects can be done completely
automatically, at the time of first API call.enterprise_id argument to JWTAuth is allowed to
be None.authenticate_instance() now accepts an enterprise argument, which
can be used to set and authenticate as the enterprise service account user,
if None was passed for enterprise_id at construction time.Event class.metadata() method to Item so it's now available for Folder
as well as File.Other
BoxAPIException.collaboration() method to Client.BaseEndpoint was the parent of BaseObject which was the parent
of all smart objects. Now BaseObject is a child of both BaseEndpoint and BaseAPIJSONObject.
BaseObject is the parent of all objects that are a part of the REST API. Another subclass of
BaseAPIJSONObject, APIJSONObject, was created to represent pseudo-smart objects such as Event that are not
directly accessible through an API endpoint.network_response_constructor as an optional property on the
Network interface. Implementations are encouraged to override this
property, and use it to construct NetworkResponse instances. That way,
subclass implementations can easily extend the functionality of the
NetworkResponse, by re-overriding this property. This property is defined
and used in the DefaultNetwork implementation.LoggingNetworkResponse class (which is
made possible by the aforementioned network_response_constructor
property). Now the SDK decides whether to log the response body, based on
whether the caller reads or streams the content.LoggingNetwork.LoggingNetwork.ExtendableEnumMeta.__dir__().Events.get_events(...) now returns a list of Event instances rather than a list of dict representing events. Event inherits from Mapping but will not
Breaking Changes
Events.get_events(...) now returns a list of Event instances rather than a list of dict
representing events. Event inherits from Mapping but will not have all the same capabilities as
dict.
Events.get_events(...) and expect a list of dict rather than a list of
Mapping. For example, if you use __setitem__ (event['key'] = value), update(), copy(), or
if your code depends on the str or repr of the Event. Use of __getitem__ (event['key']),
get(), and other Mapping methods is unaffected. See
https://docs.python.org/2.7/library/collections.html#collections-abstract-base-classes for methods supported on
Mapping instances.Event as a dict, you can get a deepcopy of the original dict
using the new property on BaseAPIJSONObject, response_object.Features
Translator instances, which can extend or
not-extend the global default Translator.BoxSession with a custom Translator.Translator which is associated
with a BoxSession or a Client.Translator that is
referenced by the BoxSession, instead of directly using the global
default Translator.Event class.Other
BoxAPIException.collaboration() method to Client.BaseEndpoint was the parent of BaseObject which was the parent
of all smart objects. Now BaseObject is a child of both BaseEndpoint and BaseAPIJSONObject.
BaseObject is the parent of all objects that are a part of the REST API. Another subclass of
BaseAPIJSONObject, APIJSONObject, was created to represent pseudo-smart objects such as Event that are not
directly accessible through an API endpoint.ExtendableEnumMeta.__dir__().Events.get_events(...) now returns a list of Event instances rather than a list of dict representing events. Event inherits from Mapping but will not
Breaking Changes
Events.get_events(...) now returns a list of Event instances rather than a list of dict
representing events. Event inherits from Mapping but will not have all the same capabilities as
dict.
Events.get_events(...) and expect a list of dict rather than a list of
Mapping. For example, if you use __setitem__ (event['key'] = value), update(), copy(), or
if your code depends on the str or repr of the Event. Use of __getitem__ (event['key']),
get(), and other Mapping methods is unaffected. See
https://docs.python.org/2.7/library/collections.html#collections-abstract-base-classes for methods supported on
Mapping instances.Event as a dict, you can get a deepcopy of the original dict
using the new property on BaseAPIJSONObject, response_object.Features
_item_type defined.Event class.Other
BoxAPIException.collaboration() method to Client.BaseEndpoint was the parent of BaseObject which was the parent
of all smart objects. Now BaseObject is a child of both BaseEndpoint and BaseAPIJSONObject.
BaseObject is the parent of all objects that are a part of the REST API. Another subclass of
BaseAPIJSONObject, APIJSONObject, was created to represent pseudo-smart objects such as Event that are not
directly accessible through an API endpoint.Add kwargs to JWTAuth constructor. Fixes #231.
**kwargs to JWTAuth constructor. Fixes #231.Bugfix so that the return value of JWTAuth.refresh() correctly matches that of the auth interface (by returning a tuple of ((access token), (refresh t
JWTAuth.refresh() correctly matches
that of the auth interface (by returning a tuple of
((access token), (refresh token or None)), instead of just the access token).
In particular, this fixes an exception in BoxSession that always occurred
when it tried to refresh any JWTAuth object.ExtendableEnumMeta.__dir__().Bugfix so that JWTAuth opens the PEM private key file in 'rb' mode.
JWTAuth opens the PEM private key file in 'rb' mode.Bugfix so that OAuth2 always has the correct tokens after a call to refresh().
OAuth2 always has the correct tokens after a call to refresh().Added a revoke() method to the OAuth2 class. Calling it will revoke the current access/refresh token pair.
revoke() method to the OAuth2 class. Calling it will revoke the current access/refresh token pair.Added a new class, LoggingClient. It\'s a Client that uses the LoggingNetwork class so that requests to the Box API and its responses are logged.
LoggingClient. It's a Client that uses the
LoggingNetwork class so that requests to the Box API and its
responses are logged.DevelopmentClient that combines LoggingClient
with the existing DeveloperTokenClient. This client is ideal for
exploring the Box API or for use when developing your application.oauth parameter to Client optional. The constructor now
accepts new parameters that it will use to construct the OAuth2
instance it needs to auth with the Box API.__repr__, making them easier to
identify during debugging sessions.__dir__, making them easier to explore.
When created with a Box API response, these objects will now include
the API response fields as attributes.Make sure that __all__ is only defined once, as a list of str. Some programs (e.g. PyInstaller) naively parse __init__.py files, and if __all__ is def
Make sure that __all__ is only defined once, as a list of str. Some
programs (e.g. PyInstaller) naively parse init.py files, and if
__all__ is defined twice, the second one will be ignored. This can cause
__all__ to appear as a list of unicode on Python 2.
Create wheel with correct conditional dependencies and license file.
Change the license meta-data from the full license text, to just a short
string, as specified in [1][2].
[1] https://docs.python.org/3.5/distutils/setupscript.html#additional-meta-data
[2] https://www.python.org/dev/peps/pep-0459/#license
Include entire test/ directory in source distribution. test/init.py was previously missing.
Update documentation.
Files now support getting a direct download url.
Added key id parameter to JWT Auth.
Nothing published for this version
Fixed import error for installations that don\'t have redis installed.
raw_input in the developer token auth for py3
compatibility.Fix boxsdk.util.log.setup_logging() on Python 3 (#90).
boxsdk.util.log.setup_logging() on Python 3 (#90).Add requests-toolbelt to setup.py (it was accidentally missing from 1.3.0).
Support for cryptography\>=1.0 on PyPy 2.6.
The SDK now supports setting a password when creating a shared link.
Fixed an ImportError for installs that didn\'t install the \[jwt\] extras.
Supports Box Developer Edition, supports making API requests as another user, and improves shared link handling.
Supports Box Developer Edition, supports making API requests as another user, and improves shared link handling.
create_user
functionality.client.get_shared_item method will remember the shared link (and
the optionally provided shared link password) so methods called on
the returned items will be properly authorized.Add context_info from failed requests to BoxAPIException instances.
Item.remove_shared_link() was trying to return an incorrect
(according to its own documentation) value, and was also attempting
to calculate that value in a way that made an incorrect assumption
about the API response. The latter problem caused invocations of the
method to raise TypeError. The method now handles the response
correctly, and correctly returns type bool.Added support for the Box accelerator API for premium accounts.
Added support for preflight check during file uploads and updates.
Added support to the search endpoint for metadata filters.
Added support for the /shared_items endpoint. client.get_shared_item can be used to get information about a shared link. See
client.get_shared_item can be used to get information about a
shared link. See https://developers.box.com/docs/#shared-itemsCertain endpoints (e.g. search, get folder items) no longer raise an exception when the response contains items that are neither files nor folders.
A minor change to namespacing. The OAuth2 class can now be imported directly from boxsdk. Demo code has been updated to reflect the change.
OAuth2 class can now be
imported directly from boxsdk. Demo code has been updated to
reflect the change.Box Metadata, improved example code, and bugfixes.
Box Metadata, improved example code, and bugfixes.
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →