Conversation
Adds src/generated/types.ts and operations.ts, emitted by the private lettermint/sdk-generator (TypeScript emitter, next naming profile) from the lettermint#2582 spec pinned at 80d8ab2a2d. scripts/generate.mjs regenerates them, or with --check verifies them; without the generator it only checks the generated headers.
… tokens
One client, `new Lettermint({ sendingToken, teamToken })` (or a token
string whose prefix selects the surface), replaces Lettermint.email() and
Lettermint.api(). Nothing about a message is stored on the client:
emails.send(message, { idempotencyKey }), emails.sendBatch() and an
immutable emails.compose() builder whose setters return new builders.
Concurrent sends on one client can no longer mix recipients, content or
Idempotency-Keys, and a failed build cannot leak into the next send.
- Team API sub-clients are thin wrappers over the generated operation
table, with typed nested query objects and async iterate() helpers
that follow next_cursor.
- Transport: fetch with redirect: 'manual' (3xx raises RedirectError),
a timeout that covers headers and body, optional AbortSignal, no
retries, and typed errors for every outcome (ApiError subclasses by
status, TimeoutError, ConnectionError, UnexpectedResponseError for
empty or non-JSON bodies).
- Tokens live in private fields; util.inspect and JSON.stringify of the
client, sub-clients, builders and the webhook verifier redact them.
- Webhook verification uses Web Crypto, requires both the signature and
the delivery header, accepts Headers or Node header records and
reports a reason code.
- Runs on Node 20+, Bun, Deno and edge runtimes: no Buffer, no node:
imports, no process. Built unminified as ESM and CJS with a default
and named exports.
BREAKING CHANGE: Lettermint.email(), Lettermint.api(), ApiClient,
EmailEndpoint, Endpoint, LettermintClient, the .email property,
positional attach(), HttpRequestError, ClientError and QueryParams are
removed; error classes, type names and Webhook.verify() changed, and
Node 18 is no longer supported. See UPGRADE.md.
Drops Node 18 and 23 from the matrix, checks the generated-file headers (the generator is private) and adds scripts/smoke.mjs, which packs the package, installs the tarball into a temporary project and checks the file list, ESM import, CJS require, token redaction and the type declarations under moduleResolution nodenext.
The README covers tokens, the immutable builder, batch sending, idempotency, scheduling, Sandbox, tags, attachments, the Team API with pagination, errors, webhooks (Express and Fetch runtimes) and runtime support. UPGRADE.md gives before/after code for every changed call, the error and type rename tables and the removed exports, and keeps the 1.x to 2.0 guide below it.
…in docs - Drop source maps from dist, which cuts the unpacked package from 1.0 MB to 582 kB. - Name the sending token environment variable LETTERMINT_PROJECT_TOKEN, matching the documentation and the other SDKs. - State that 2.x no longer receives updates.
The spec at lettermint/lettermint@0b4ecbdd23 (main, the #2582 merge) is identical to the previous pin; only the generated file headers change.
This was referenced Oct 3, 2026
Bjornftw
approved these changes
Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Lettermint Node SDK 3.0, a new major version. The main reason is safety: in 2.x,
Lettermint.email(token)returned one mutable builder per client. Two emails built at the same time on one client could mix recipients, content andIdempotency-Key, and an email abandoned halfway leaked into the next send. 3.0 stores nothing about a message on the client.What changes
new Lettermint({ sendingToken, teamToken })replacesLettermint.email()andLettermint.api(). One token is enough.emails.*uses the sending token, the Team API uses the team token.ping(),messages.reschedule()andmessages.cancel()accept either.lm_team_plus letters and digits is a team token,lm_plus letters and digits is a sending token. Anything else (such aslm_sso_…) throws.emails.send(),emails.sendBatch(), and an immutableemails.compose()builder where every setter returns a new builder. The idempotency key is a per-call option. Attachments are objects.ApiError(withstatusand APIcode) and its subclasses for 401, 403, 404, 409, 422, 429 and 5xx. AlsoTimeoutError,ConnectionError,UnexpectedResponseError(empty or HTML bodies) andRedirectError. Class names survive the build.console.log,util.inspectorJSON.stringify.Buffer, nonode:imports.CursorPage<T>, anditerate()helpers. A few methods moved, e.g.projects.routes(id)→routes.list(projectId).verify()is async (Web Crypto). It requires bothX-Lettermint-SignatureandX-Lettermint-Delivery, accepts any matchingv1, and accepts strings or bytes.ListDomainsResponse,ProjectMutationResponse,ApiError. Enums are open, so new API values don't break typing.UPGRADE.mdhas a ready-to-copy instruction for Claude Code, Codex and similar tools. It ships in the package, so agents can read the guide fromnode_modules.UPGRADE.mdcovers every changed call and the full type rename table. All 81 removed or renamed 2.x exports are listed (checked by script).Release notes for the maintainer
3.0.0by publishing a GitHub releasev3.0.0.release.yamlsets the version from the tag.package.jsonsays3.0.0-devon the branch.3.0.0is on npm.Verification
npm run test:smokepacks the tarball and checks:nodenext;lettermint/sdk-generator): 42 of 42 scenarios pass with--strict. They cover concurrent and half-built emails, unknown enum values, empty and HTML bodies, redirects, timeouts, token redaction, token detection and 25 webhook vectors. For comparison, 2.8.0 fails 7.