# Changelog - Sep 22, 2026

**Documentation:** https://docs.composio.dev/docs/changelog/2026/09/22

## Python SDK 0.23.0 and TypeScript SDK 0.20.0 add a faster API client

Both SDKs now use a faster handrolled client, expose more v3.1 APIs, and tighten authentication and session updates.

Python SDK `0.23.0` and TypeScript SDK `0.20.0` replace the old autogenerated client with a new handrolled one. Its lightweight HTTP transport is substantially faster while preserving the SDK APIs you already use. The client also covers more of Composio's v3.1 API.

### Release versions [#release-versions]

| SDK                         | Version  |
| --------------------------- | -------- |
| Python `composio`           | `0.23.0` |
| TypeScript `@composio/core` | `0.20.0` |
| TypeScript `@composio/slim` | `0.20.0` |

### Faster API requests [#faster-api-requests]

The new client reduces request overhead without changing existing imports, types, retries, timeouts, error classes, raw responses, streaming responses, or `AbortSignal` support. TypeScript users also get configurable SDK logging through `logger` and `logLevel`; Python routes client deprecations through `ComposioDeprecationWarning`.

### More of the Composio API [#more-of-the-composio-api]

* Project webhooks (`webhooks.subscriptions` and `webhooks.endpoints`), tool execution logs, customer-managed keyring transfer keys, experimental usage metering, and experimental project-owned custom toolkits.
* Connected account revocation and deferred OAuth completion.
* Toolkit bulk retrieval, changelogs, OAuth scope recommendations, and grant contexts. Toolkit auth details now include each field's end-user visibility and the scopes an auth method always requests.
* Tool Router session configuration history through `session.listConfigHistory()` in TypeScript and `session.list_config_history()` in Python.
* `userApiKey` and `orgApiKey` in TypeScript, and `user_api_key` and `org_api_key` in Python, for user- and organization-scoped operations.

### Safer authentication and session updates [#safer-authentication-and-session-updates]

You can now authenticate without a project key by setting `apiKey: null` in TypeScript or `disable_api_key=True` in Python, then supplying a user or organization API key. Consumer requests can be scoped with `orgId` and `projectId` in TypeScript or `org_id` and `project_id` in Python.

Session MCP configuration exports only the credential and project scope used for the session request, and only when the MCP URL has the same origin as the configured Composio API. `session.update()` now uses the session's last observed config version by default. Concurrent writes raise a typed conflict instead of silently overwriting a newer configuration, and nullable policy fields can remove stored overrides.

> **Migration note**

In TypeScript, `apiKey: null` now explicitly disables project-key fallbacks. If you want the SDK
to fall back to `COMPOSIO_API_KEY` or the CLI config when an environment variable is missing, pass
`undefined` or omit `apiKey` instead:

```typescript
import { Composio } from '@composio/core';

const composio = new Composio({
  apiKey: process.env.COMPOSIO_API_KEY,
});
```

Session updates now reject stale writes with `ComposioSessionConfigConflictError` in TypeScript
or `SessionConfigConflictError` in Python. Re-fetch the session and retry, or pass
`expectedConfigVersion: false` (`expected_config_version=False` in Python) when you explicitly
need last-writer-wins behavior.

> `connectedAccounts.refresh()` is deprecated because the API deprecated its endpoint. The API also
removed credential validation from refresh, so TypeScript now ignores `validateCredentials` and
logs a warning when you set it.

---