Skip to content

feat: expose priced Exa REST routes in public SDK registry - #38

Merged
senamakel merged 2 commits into
mainfrom
feat/exa-routes
Sep 26, 2026
Merged

senamakel merged 2 commits into
mainfrom
feat/exa-routes

Conversation

@senamakel

@senamakel senamakel commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Summary

Expose the priced Exa Search, Contents, Answer, Find Similar, Agent Run, and Batch operations in the SDK public route registry and contract manifest. Agent and Batch resources are user-scoped by the backend.

Validation

  • cargo test

Related

Backend implementation: https://github.com/tinyhumansai/backend/pull/1386

@tinysweeper

tinysweeper Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

This pull request adds Exa agent, batch, search, answer, contents, and findSimilar routes as well as a telemetry route to the public SDK registry and generated route constants. The review identifies that the changes are missing the typed SDK surface (methods and request/response types) and route tests, and that unrelated route families (Exa and telemetry) are combined in a single change, violating repository coherence rules. The parity test assertion is updated to reflect the new route count.

State: Ready for maintainer review
Priority: medium
Reviewed head: cd2ded508ae3
Updated: 1790419665 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 1 Active findings 16
Tests 1 Noted findings 0
Documentation 0 Resolved findings 8
Configuration 1 Pending checks/questions 0

Completeness: Complete
Test assessment: Test coverage is assessed from changed tests and lane evidence; execution is not claimed without trusted check data.

What changed

The pull request modifies api/tinyhumans.backend.json to add 16 new Exa routes and 1 telemetry route, increasing the total operation count from 212 to 229. It updates src/generated_public_routes.rs to include the same routes in the PUBLIC_ROUTES constant. It updates tests/openapi_sync.rs to expect the new operation count and asserts that the generated routes match the manifest routes.

Features

  • Added — Exa integration routes: Adds 16 routes for Exa agent runs, batches, search, answer, contents, and findSimilar to the public SDK registry and generated route list. (api/tinyhumans.backend.json, src/generated_public_routes.rs)
  • Added — Telemetry route: Adds POST /telemetry/langfuse/otel/v1/traces to the public SDK registry and generated route list. (api/tinyhumans.backend.json, src/generated_public_routes.rs)

Tests

  • parity_test — Verifies that the manifest operation count is 229 and that the generated Rust routes match the manifest routes.: Updated to reflect new route count, but the review notes that no route-specific tests (typed methods) are added. (tests/openapi_sync.rs)

Findings

  • medium · critique · Add the Exa operation to the typed SDK surface — This adds the Exa search operation to the public contract, but the repository search shows no Exa module, request/response types, or typed client method. Callers can only use the r (api/tinyhumans\.backend\.json:100)
  • medium · critique · Add typed methods and route tests for the new Exa search and telemetry routes — The manifest and generated registry expose these new routes, but the repository contains no typed Exa or telemetry client methods and no mock-server route tests for them. This leav (api/tinyhumans\.backend\.json:489)
  • medium · critique · Add the Exa operation to the typed SDK surface — The Exa search route is now allowlisted in the generated raw-route registry, but there is still no corresponding typed client method anywhere under `src`. This leaves the newly adv (src/generated\_public\_routes\.rs:38)
  • medium · critique · Add typed methods and route tests for the new Exa and telemetry routes — This change adds 16 additional Exa routes and the Langfuse telemetry route to the public contract, but the repository contains no typed methods or route tests for them. The parity (src/generated\_public\_routes\.rs:218)
  • medium · critique · Include the telemetry route in the pull request description — The pull request description does not document the newly added telemetry route, even though it introduces a distinct public namespace and ingestion endpoint. Update the pull reques (api/tinyhumans\.backend\.json:481)
  • medium · critique · Keep unrelated route families in separate changes — The change combines a large Exa integration expansion with an unrelated Langfuse telemetry route. These are separate route families with different clients, payloads, and tests, so (src/generated\_public\_routes\.rs)
  • medium · critique · Keep unrelated route families in separate changes — This change bundles a large Exa integration expansion with an unrelated Langfuse telemetry namespace. The repository requires small, coherent contract changes; splitting telemetry (api/tinyhumans\.backend\.json:481)
  • medium · security · Add typed methods and route tests for the new Exa search and telemetry routes — The new Exa and telemetry routes are present in the manifest and route registry, but there are no corresponding typed Rust methods, request/response types, or mock-server route tes (api/tinyhumans\.backend\.json:489)
  • medium · security · Add the Exa operation to the typed SDK surface — This adds the Exa search operation only to the raw route registry; no typed Exa client method or request/response types are present in the changed surface. Callers are therefore fo (src/generated\_public\_routes\.rs:38)
  • medium · security · Add typed methods and route tests for the new Exa search and telemetry routes — The registry now exposes the new Exa and Langfuse telemetry routes, but the repository contains no corresponding typed methods, request/response types, or mock-server route tests. (src/generated\_public\_routes\.rs:218)
  • medium · security · Keep unrelated Exa and telemetry routes in separate changes — This change combines a large Exa integration expansion with an unrelated Langfuse telemetry route, while neither has its matching typed SDK surface and tests in the same contract u (api/tinyhumans\.backend\.json:489)
  • medium · security · Keep unrelated route families in separate changes — This contract change combines the Exa integration's search, batch, contents, answer, and agent-run routes with the unrelated Langfuse telemetry route. Splitting the route families (tests/openapi\_sync\.rs:170)
  • medium · tests · Keep changes coherent: add unrelated routes in separate pull requests — This change adds both Exa agent/batch routes and a Langfuse OTLP telemetry route in a single pull request. The repository rule "Keep changes small and coherent" (AGENTS.md) expects (src/generated\_public\_routes\.rs:218)
  • medium · description · Add typed methods for the new Exa routes — The manifest and registry now include Exa routes (search, answer, contents, findSimilar, agent runs, batches), but no corresponding typed Rust methods, request/response types, or n (\(pull request description\))
  • medium · description · Add route tests for the new Exa and telemetry routes — The diff adds 17 Exa routes and 1 telemetry route to the public route registry, but no route tests exercise them. The repository's guidelines require adding matching route tests. W (\(pull request description\))
  • medium · description · Keep changes coherent: add unrelated routes in separate pull requests — This pull request adds both Exa integration routes and a telemetry route. These belong to different functional areas (agent integrations vs. telemetry) and should be shipped in sep (\(pull request description\))

Resolved this pass

  • Generate the telemetry route in the SDK registry
  • Generate the telemetry route in the SDK registry
  • Generate the telemetry route in the SDK registry
  • Generate the telemetry route in the SDK registry
  • Generate the telemetry route in the SDK registry
  • Include the telemetry route in the pull request description
  • Generate the telemetry route in the SDK registry
  • Include the telemetry route in the pull request description

Before merge

None.

How this fits together

flowchart LR
  n0["..._api_key_request_uses_openapi_field_names"]:::impacted
  n1["path_segments_are_encoded_on_typed_routes"]:::impacted
  n2["create"]:::impacted
  n3["try_from"]:::impacted
  n4["get_feedback"]:::impacted
  n5["...ejects_the_machine_only_connections_scope"]:::impacted
  n0 -->|calls| n2
  n0 -->|tests| n2
  n1 -->|calls| n4
  n1 -->|tests| n4
  n5 -->|calls| n3
  n5 -->|tests| n3
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 3 files; 7 findings. (1 earlier finding(s) still open) _3 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._
  • Evidence: api/tinyhumans\.backend\.json — Add the Exa operation to the typed SDK surface
  • Evidence: api/tinyhumans\.backend\.json — Add typed methods and route tests for the new Exa search and telemetry routes
  • Evidence: src/generated\_public\_routes\.rs — Add the Exa operation to the typed SDK surface
  • Evidence: src/generated\_public\_routes\.rs — Add typed methods and route tests for the new Exa and telemetry routes
  • Evidence: api/tinyhumans\.backend\.json — Include the telemetry route in the pull request description
  • Evidence: src/generated\_public\_routes\.rs — Keep unrelated route families in separate changes
  • Evidence: api/tinyhumans\.backend\.json — Keep unrelated route families in separate changes

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 3 files; 6 findings. (1 already reported on an earlier push) (2 earlier finding(s) still open) (4 observation(s) grouped into shared inline comments) _3 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._
  • Evidence: api/tinyhumans\.backend\.json — Add typed methods and route tests for the new Exa search and telemetry routes
  • Evidence: src/generated\_public\_routes\.rs — Add the Exa operation to the typed SDK surface
  • Evidence: src/generated\_public\_routes\.rs — Add typed methods and route tests for the new Exa search and telemetry routes
  • Evidence: api/tinyhumans\.backend\.json — Keep unrelated Exa and telemetry routes in separate changes
  • Evidence: tests/openapi\_sync\.rs — Keep unrelated route families in separate changes

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This pull request adds Exa and telemetry routes to the public route registry and updates the parity test count, but it does not add the required typed methods, request/response types, or route tests, and it combines unrelated route families in a single change, violating repository rules. Merge after adding the missing typed surface and splitting unrelated changes. Two earlier findings still stand and are re-raised below. (1 already reported on an earlier push) (2 earlier finding(s) still open) (1 observation(s) grouped into shared inline comments) _3 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._
  • Evidence: src/generated\_public\_routes\.rs — Keep changes coherent: add unrelated routes in separate pull requests

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This pull request adds Exa agent, batch, search, answer, contents, and findSimilar routes plus a telemetry route to the public SDK registry and manifest. The typed client surface and route tests remain missing (previously flagged), and the change mixes unrelated functionality (Exa and telemetry) in one PR. (2 earlier finding(s) still open) _3 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._
  • Evidence: \(pull request description\) — Add typed methods for the new Exa routes
  • Evidence: \(pull request description\) — Add route tests for the new Exa and telemetry routes
  • Evidence: \(pull request description\) — Keep changes coherent: add unrelated routes in separate pull requests

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No end-to-end harness in this repository: no e2e test files and no e2e workflow.
Evidence and run details
  • Models: ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash
  • Spend: $0.012518
  • Tokens: 250286 input · 24494 output · 7766 cached · 170 embedding
Head State Pass summary
b7813fa6a8aa changes requested 5 active finding(s), 0 resolved finding(s) (at 1790417235)
cd2ded508ae3 ready for maintainer review 16 active finding(s), 8 resolved finding(s) (at 1790419665)

tinysweeper 0.1.0

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T10:45:35.790264Z cd2ded5 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: f1ba26d9-cdbf-4f28-8ea8-7af62ad8b6c7

📥 Commits

Reviewing files that changed from the base of the PR and between 3427d96 and b7813fa.

📒 Files selected for processing (3)
  • api/tinyhumans.backend.json
  • src/generated_public_routes.rs
  • tests/openapi_sync.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The OpenAPI manifest and Rust public route list add Exa search and authenticated Langfuse telemetry routes. The sync test updates its expected operation and route counts to 214.

Changes

Route additions

Layer / File(s) Summary
Declare and register the routes
api/tinyhumans.backend.json, src/generated_public_routes.rs
The manifest and Rust public route list add POST /agent-integrations/exa/search and POST /telemetry/langfuse/otel/v1/traces. The telemetry namespace uses bearer authentication.
Update route sync expectations
tests/openapi_sync.rs
The test expects 214 operations and 214 Rust routes, and identifies the two added routes.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Feature

Suggested reviewers: yellowsnnowmann

Merge Risk: ⚪ Minimal · up to b7813

The SDK registry now exposes the routes. Confirm Exa backend availability as part of rollout; the available evidence does not show a merge-blocking defect.

Security Architecture Review

Security architecture risk: 🔵 Low · up to b7813

The two endpoints are newly declared as public, but the SDK’s existing restrictions on admin and webhook routes remain in place. Backend authorization and deployment behavior are not yet established, so the risk cannot be treated as zero.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The newly documented operations are client-addressable POST path shapes, but adding them to PUBLIC_ROUTES does not broaden the raw client’s existing non-admin, non-webhook path allowance. Effective service-side exposure remains unverified.

Trust Boundaries and Controls

  • observed — The SDK continues to reject explicitly unexposed operations, admin paths, and undocumented webhook receivers before dispatch. The manifest declares bearer authentication for telemetry, but backend enforcement is not shown.

Hardening Proposals

  • proposed — Before relying on these public declarations, confirm the deployed handlers’ credential requirements, tenant and ingestion policies, and rollout ordering against the published contract.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: exposing the Exa REST route in the public SDK registry. The wording is concise and relevant to the pull request objectives.
✨ Finishing Touches 💡 1
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

A rabbit checks the routes in place,
Two new paths join the API space.
Exa search hops into the view,
Langfuse traces pass auth through.
The sync test counts them, one and two.

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b7813fa6a8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

"POST /agent-integrations/composio/triggers",
"POST /agent-integrations/crypto/bridge",
"POST /agent-integrations/crypto/swap",
"POST /agent-integrations/exa/search",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Wait to advertise the Exa route until it is deployed

If this SDK ships while the backend implementation is still pending, callers that trust this generated manifest will see POST /agent-integrations/exa/search advertised as part of the deployed contract but receive a missing-route response in production. Keep it out of the public registry until it appears in the deployed Swagger document, or land the backend deployment first.

AGENTS.md reference: AGENTS.md:L12-L19

Useful? React with 👍 / 👎.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 1 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0092 · 171,580 in / 12,788 out · 19,619 cached (11%) · ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 141 embedded
critique:    $0.0036 · 82,874 in  / 2,060 out  · 17,837 cached (22%) · gpt-5.6-luna
security:    $0.0017 · 62,958 in  / 2,165 out  · 1,782 cached (3%)   · gpt-5.6-luna
tests:       $0.0020 · 15,828 in  / 3,104 out  · 0 cached (0%)       · deepseek/deepseek-v4-flash
description: $0.0012 · 7,015 in   / 2,964 out  · 0 cached (0%)       · deepseek/deepseek-v4-flash

"Telemetry"
],
"routes": [
"POST /telemetry/langfuse/otel/v1/traces"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority critical security confident

Generate the telemetry route in the SDK registry

This adds a public manifest route, but the route is absent from src/generated_public_routes.rs. The manifest/registry parity test will therefore fail, and the raw SDK route guard will reject this endpoint. Regenerate the public route registry from the matching contract and add the required route test and typed client surface before merging.

[RULE] generated-surface-sync ·

"POST /agent-integrations/composio/triggers",
"POST /agent-integrations/crypto/bridge",
"POST /agent-integrations/crypto/swap",
"POST /agent-integrations/exa/search",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium security confident

Add the Exa operation to the typed SDK surface

This manifest entry introduces a public operation, but no Rust API method or request/response types for /agent-integrations/exa/search exist under src. Although the generated raw-route registry contains the route, the repository contract requires each public operation to have matching Rust methods, types, and route tests. Add the typed Exa client surface and its tests, or remove the manifest entry if the operation is not intended to be public.

[RULE] contract-sync ·

("POST", "/agent-integrations/crypto/bridge"),
("GET", "/agent-integrations/crypto/routes"),
("POST", "/agent-integrations/crypto/swap"),
("POST", "/agent-integrations/exa/search"),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium tests confident

Add typed methods and route tests for the new Exa search and telemetry routes

The diff adds POST /agent-integrations/exa/search and POST /telemetry/langfuse/otel/v1/traces to the public route registry and manifest, but does not add corresponding typed Rust methods, request/response types, or route tests. The repository's OpenAPI discipline rule (AGENTS.md) requires: "Add matching Rust methods, request/response types, and route tests." Without these, the new routes are only callable through the raw escape hatch, and no SDK-level test exercises them, so regressions in serialization or contract would go undetected. Add an exa module under src/api/agent_integrations/ (or a new src/api/telemetry.rs namespace), define request/response types, implement the client methods, and write at least a mock-server route test for each. The parity test already validates the route list, so that part is fine; the gap is the typed surface and its coverage.

[RULE] missing-typed-methods ·

@tinysweeper tinysweeper Bot added the priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. label Sep 26, 2026
@senamakel senamakel changed the title feat: expose Exa search route in public SDK registry feat: expose priced Exa REST routes in public SDK registry Sep 26, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-blocking findings are resolved. Clearing the changes request.

             $0.0125 · 250,286 in / 24,494 out · 7,766 cached (3%) · ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 170 embedded
critique:    $0.0052 · 130,934 in / 8,807 out  · 4,127 cached (3%) · gpt-5.6-luna, deepseek/deepseek-v4-flash
security:    $0.0027 · 89,456 in  / 4,763 out  · 3,639 cached (4%) · gpt-5.6-luna
tests:       $0.0024 · 17,098 in  / 4,612 out  · 0 cached (0%)     · deepseek/deepseek-v4-flash
description: $0.0016 · 8,380 in   / 4,554 out  · 0 cached (0%)     · deepseek/deepseek-v4-flash

"POST /agent-integrations/exa/batches/{batchId}/cancel",
"POST /agent-integrations/exa/contents",
"POST /agent-integrations/exa/findSimilar",
"POST /agent-integrations/exa/search",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Add the Exa operation to the typed SDK surface

This adds the Exa search operation to the public contract, but the repository search shows no Exa module, request/response types, or typed client method. Callers can only use the raw escape hatch despite this being presented as part of the stable SDK surface. Add the typed operation in the matching namespace and keep its request and response types aligned with the deployed contract.

[RULE] typed-sdk-surface ·

"Telemetry"
],
"routes": [
"POST /telemetry/langfuse/otel/v1/traces"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Add typed methods and route tests for the new Exa search and telemetry routes

The manifest and generated registry expose these new routes, but the repository contains no typed Exa or telemetry client methods and no mock-server route tests for them. This leaves serialization, paths, and envelope handling unverified and violates the repository rule requiring matching Rust methods, types, and route tests for contract changes. Add those methods and tests before merging.


Additional security observation

priority medium confident

Add typed methods and route tests for the new Exa search and telemetry routes

[RULE] missing-typed-methods

The new Exa and telemetry routes are present in the manifest and route registry, but there are no corresponding typed Rust methods, request/response types, or mock-server route tests. The repository's SDK discipline requires those pieces to be added together so serialization and route regressions are exercised.


Additional security observation

priority medium confident

Keep unrelated Exa and telemetry routes in separate changes

[RULE] incoherent-contract-change

This change combines a large Exa integration expansion with an unrelated Langfuse telemetry route, while neither has its matching typed SDK surface and tests in the same contract update. Split the unrelated route families or include their complete, independently testable implementations together.

[RULE] missing-route-tests ·

("POST", "/agent-integrations/exa/batches/{batchId}/cancel"),
("POST", "/agent-integrations/exa/contents"),
("POST", "/agent-integrations/exa/findSimilar"),
("POST", "/agent-integrations/exa/search"),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Add the Exa operation to the typed SDK surface

The Exa search route is now allowlisted in the generated raw-route registry, but there is still no corresponding typed client method anywhere under src. This leaves the newly advertised operation available only through the escape hatch and violates the repository's requirement to add matching Rust methods and request/response types. Add the typed Exa operation using the deployed Swagger contract.


Additional security observation

priority medium confident

Add the Exa operation to the typed SDK surface

[RULE] missing-typed-methods

This adds the Exa search operation only to the raw route registry; no typed Exa client method or request/response types are present in the changed surface. Callers are therefore forced to use the raw escape hatch, contrary to the repository rule requiring named namespace clients for public routes. Add the typed operation based on the deployed contract.

[RULE] typed-sdk-surface ·

("POST", "/teams/{teamId}/switch"),
("POST", "/teams/join"),
("GET", "/teams/me/usage"),
("POST", "/telemetry/langfuse/otel/v1/traces"),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Add typed methods and route tests for the new Exa and telemetry routes

This change adds 16 additional Exa routes and the Langfuse telemetry route to the public contract, but the repository contains no typed methods or route tests for them. The parity test only checks route-list synchronization; it does not exercise request serialization, response handling, or the actual paths. Add the matching typed clients and mock-server tests for the new Exa and telemetry operations.


Additional security observation

priority medium confident

Add typed methods and route tests for the new Exa search and telemetry routes

[RULE] missing-typed-methods

The registry now exposes the new Exa and Langfuse telemetry routes, but the repository contains no corresponding typed methods, request/response types, or mock-server route tests. The parity test checks only route-list synchronization and cannot catch serialization or request-path regressions. Add the required typed surfaces and tests for these new operations.


Additional tests observation

priority medium likely

Keep changes coherent: add unrelated routes in separate pull requests

[RULE] coherence

This change adds both Exa agent/batch routes and a Langfuse OTLP telemetry route in a single pull request. The repository rule "Keep changes small and coherent" (AGENTS.md) expects unrelated route families to be introduced in separate, focused changes. Splitting them reduces review surface and avoids conflating two distinct contract updates.

[RULE] route-test-coverage ·

]
},
{
"name": "telemetry",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Include the telemetry route in the pull request description

The pull request description does not document the newly added telemetry route, even though it introduces a distinct public namespace and ingestion endpoint. Update the pull request description to explain the route, its authentication, and why it is part of the public SDK contract.

[RULE] contract-documentation ·

]
},
{
"name": "telemetry",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Keep unrelated route families in separate changes

This change bundles a large Exa integration expansion with an unrelated Langfuse telemetry namespace. The repository requires small, coherent contract changes; splitting telemetry from the Exa integration would make review, regeneration, and rollback of each route family independent.

[RULE] coherent-changes ·

Comment thread tests/openapi_sync.rs
// `POST .../gemini/live/sessions` and `GET .../gemini/live/sessions/{sessionId}`.
// 211 -> 212: the retired orchestration session-list compatibility route.
assert_eq!(manifest["source"]["operationCount"], 212);
// 212 -> 214: Exa search plus the authenticated Langfuse telemetry route.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium security likely

Keep unrelated route families in separate changes

This contract change combines the Exa integration's search, batch, contents, answer, and agent-run routes with the unrelated Langfuse telemetry route. Splitting the route families would keep the generated registry, typed implementations, tests, and contract changes reviewable and independently attributable.

[RULE] incoherent-change-scope ·

@tinysweeper tinysweeper Bot added priority: p2 Soon. Real but survivable — a rough edge, a gap, a thing that will bite later. and removed priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. labels Sep 26, 2026
@senamakel
senamakel merged commit 32c746a into main Sep 26, 2026
9 checks passed
@senamakel
senamakel deleted the feat/exa-routes branch September 27, 2026 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p2 Soon. Real but survivable — a rough edge, a gap, a thing that will bite later.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant