
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@attrove/sdk
Advanced tools
Official TypeScript SDK for the Attrove API - AI-powered context retrieval for your apps
Official TypeScript SDK for the Attrove API. Access AI-powered context from your users' Gmail, Slack, Google Calendar, and more.
npm install @attrove/sdk
# or
yarn add @attrove/sdk
# or
pnpm add @attrove/sdk
import { Attrove } from '@attrove/sdk';
// Create a client
const attrove = new Attrove({
apiKey: 'sk_...', // API key from your dashboard
userId: 'user-uuid' // User ID from provisioning
});
// Query user's context
const response = await attrove.query('What meetings do I have tomorrow?');
console.log(response.answer);
// Search for specific information
const results = await attrove.search('quarterly report');
query(prompt, options?)Ask questions about the user's unified context with AI-generated answers.
// Simple query
const response = await attrove.query('What did Sarah say about the Q4 budget?');
console.log(response.answer);
console.log(response.used_message_ids); // msg_xxx IDs
console.log(response.used_meeting_ids); // mtg_xxx IDs
console.log(response.used_event_ids); // evt_xxx IDs
// Multi-turn conversation - pass history from previous response
let history = response.history;
const followUp = await attrove.query('What about Q3?', { history });
// Update history for subsequent queries
history = followUp.history;
// With filters
const filtered = await attrove.query('Latest updates', {
integrationIds: ['int_xxx'], // Only search specific integration
includeSources: true // Include source snippets
});
// Custom instructions + reference context
const custom = await attrove.query('Compare Alice and Bob on budget adherence.', {
// instructions: control output format and behavior (overrides default style)
instructions: 'Return a markdown table with columns: Person, On-Track, Key Evidence.',
// context: ground-truth data the AI treats as authoritative (influences query rewriting, not vector search)
context: 'FY26 budget: Engineering $2M, Marketing $800K. Alice owns Engineering, Bob owns Marketing.',
});
search(query, options?)Semantic search that returns raw matches across messages, meetings, and events without AI summarization.
const results = await attrove.search('product launch', {
afterDate: '2024-01-01',
senderDomains: ['acme.com'],
includeBodyText: true
});
for (const [convId, conv] of Object.entries(results.conversations)) {
console.log(`Conversation: ${conv.conversation_name}`);
}
// Get user profile and integrations
const { user, integrations } = await attrove.users.get();
// Update user profile
await attrove.users.update({
timezone: 'America/New_York'
});
// Get sync statistics
const stats = await attrove.users.syncStats();
console.log(`Messages: ${stats.totals.messages.count}`);
// List messages
const { data, pagination } = await attrove.messages.list({
limit: 20,
expand: ['body_text']
});
// Get specific messages (e.g., after a query)
const { data: messages } = await attrove.messages.list({
ids: response.used_message_ids,
expand: ['body_text']
});
// Get a single message by ID
const message = await attrove.messages.get('message-uuid');
// List conversations
const { data: conversations } = await attrove.conversations.list({
syncedOnly: true
});
// Update sync settings
await attrove.conversations.updateSync([
{ id: 'conversation-uuid-1', importMessages: true },
{ id: 'conversation-uuid-2', importMessages: false }
]);
// List integrations
const integrations = await attrove.integrations.list();
// Get a single integration
const integration = await attrove.integrations.get('integration-id');
console.log(`${integration.provider}: last synced ${integration.last_synced_at}`);
// Disconnect an integration
await attrove.integrations.disconnect('integration-uuid');
// Discover relevant threads via semantic search
const { threads } = await attrove.threads.discover('Q4 budget discussion', {
integrationTypes: ['slack'],
afterDate: '2024-01-01',
limit: 5,
});
for (const thread of threads) {
console.log(`${thread.title} (score: ${thread.relevance_score})`);
}
// Analyze a thread for structured insights
const analysis = await attrove.threads.analyze('conversation-uuid');
console.log(analysis.summary);
console.log(`Sentiment: ${analysis.sentiment}`);
console.log(`Action items: ${analysis.action_items.length}`);
console.log(`Decisions: ${analysis.decisions.length}`);
// List meetings
const { data: meetings } = await attrove.meetings.list({
expand: ['summary', 'action_items', 'attendees'],
});
// Get a single meeting
const meeting = await attrove.meetings.get('meeting-id');
// Update a meeting's summary or action items
const updated = await attrove.meetings.update('meeting-id', {
summary: 'Revised meeting summary.',
shortSummary: 'Brief revision.',
actionItems: [
{ description: 'Follow up with client', assignee: 'Alice' },
],
});
// Regenerate the AI summary from the transcript
const result = await attrove.meetings.regenerateSummary('meeting-id');
console.log(result.summary);
console.log(`Action items: ${result.action_items.length}`);
Use the admin client for operations that require partner authentication:
import { Attrove } from '@attrove/sdk';
// Create admin client
const admin = Attrove.admin({
clientId: 'your-client-id',
clientSecret: 'your-client-secret'
});
// Create a user
const { id, apiKey } = await admin.users.create({
email: 'user@example.com',
firstName: 'John',
lastName: 'Doe'
});
// Generate integration token for OAuth flow
const { token: connectToken, expires_at } = await admin.users.createConnectToken(id);
// Use the apiKey for subsequent API calls
const attrove = new Attrove({ apiKey, userId: id });
// Redirect user to OAuth flow
// The URL format depends on your deployment - check your dashboard for the exact URL
// Example: const oauthUrl = `${YOUR_BASE_URL}/connect/gmail?token=${connectToken}`;
The SDK provides typed errors for better error handling:
import {
Attrove,
AttroveError,
AuthenticationError,
NotFoundError,
RateLimitError
} from '@attrove/sdk';
try {
const response = await attrove.query('...');
} catch (error) {
if (error instanceof AuthenticationError) {
console.log('Invalid API key');
} else if (error instanceof RateLimitError) {
console.log(`Rate limited. Retry after ${error.retryAfter}s`);
} else if (error instanceof NotFoundError) {
console.log('Resource not found');
} else if (error instanceof AttroveError) {
console.log(`Error: ${error.code} - ${error.message}`);
}
}
For real-time streaming of query responses:
const result = await attrove.stream('What happened in the meeting?', {
onChunk: (chunk) => process.stdout.write(chunk),
onState: (state) => console.log('State:', state),
onEnd: (reason) => console.log('Stream ended:', reason)
});
console.log('Full answer:', result.answer);
Note: Streaming uses WebSocket connections and requires the same API key authentication as other SDK methods. It is primarily intended for end-user facing applications where progressive display of responses improves the user experience.
const attrove = new Attrove({
apiKey: 'sk_...', // Required: API key
userId: 'user-uuid', // Required: User ID
baseUrl: 'https://api.attrove.com', // Optional: API base URL
timeout: 30000, // Optional: Request timeout (ms)
maxRetries: 3 // Optional: Retry attempts
});
The SDK is fully typed. Import types as needed:
import {
QueryOptions,
QueryResponse,
SearchOptions,
SearchResponse,
User,
Message,
Integration,
ConversationMessage
} from '@attrove/sdk';
MIT
FAQs
Official TypeScript SDK for Attrove — create watched outcomes (Goals) that catch conversations going quiet, and query users' email, Slack, meetings, and calendar with cited evidence.
The npm package @attrove/sdk receives a total of 129 weekly downloads. As such, @attrove/sdk popularity was classified as not popular.
We found that @attrove/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.