Migrate docs from Mintlify to fumadocs#457
Conversation
- content unchanged: 140 mdx pages keep their paths and URLs; Mintlify components (Info, CodeGroup, Steps, Card, ...) aliased to fumadocs equivalents in components/mdx.tsx - docs.json stays the navigation source of truth; lib/tree.ts converts it to the fumadocs page tree at build time - API Reference generated from the same Stainless OpenAPI spec via fumadocs-openapi (virtual pages, playground off by default) - llms.txt, llms-full.txt, per-page raw markdown (.md suffix on any page URL), and AI page actions built in - Ask AI assistant wired to Anthropic via AI SDK (needs ANTHROPIC_API_KEY at deploy time) - redirects, GA4, Inter font, and brand colors ported from docs.json Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
| const [actualOpen, setActualOpen] = useState(open); | ||
| useHotKey(); | ||
|
|
||
| if (open && !actualOpen) setActualOpen(open); |
There was a problem hiding this comment.
setState during render in panel
Medium Severity
AISearchPanel calls setActualOpen(open) directly in the render path when open && !actualOpen. Updating state while rendering violates React’s rules and can cause extra renders or warnings, especially under Strict Mode.
Reviewed by Cursor Bugbot for commit 6ed79ee. Configure here.
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This changes the production delivery stack for the entire documentation site rather than only moving content: 195 files are affected, with new Next.js routing, OpenAPI rendering, search, raw-markdown endpoints, and deployment/build configuration. That gives the migration a broad user-facing blast radius.
The new
POST /api/chatroute also invokes a billable Anthropic model from client-supplied message history without authentication, rate limiting, or request-size/history validation. Although its tool access is limited to public docs, this creates material cost-abuse, prompt-integrity, and operational-load risk. The existing broken-link workflow still runs the Mintlify checker and is currently failing against the migrated tree, so migration validation isn't green.I did not approve this PR because these cross-file runtime and operational changes meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
The Vercel project was imported while the default branch was still Mintlify-only (no package.json), so framework auto-detection picked "Other" and served public/ statically. Pinning it here overrides the project setting on every deploy. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This PR replaces the production delivery stack for the entire documentation site: 196 files are affected, with new Next.js routing, navigation generation, OpenAPI rendering, search, raw-markdown/OG endpoints, and build/deployment configuration. Although most documentation files are mechanical moves, the runtime and infrastructure changes have a broad user-facing blast radius.
The public
POST /api/chatroute also sends client-provided message histories to a billable Anthropic model without authentication, rate limiting, or request-size/history validation, which creates material cost-abuse and operational-load risk. The latest update addsvercel.jsonto select the Next.js framework; it doesn't reduce those existing risks and further confirms that this PR changes deployment behavior.I didn't approve because the cross-file production migration and unauthenticated model-backed endpoint meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This PR still replaces the production delivery stack for the entire documentation site: 196 files are affected, including new Next.js page/API routes, navigation generation, OpenAPI rendering, search, markdown/OG endpoints, and Vercel/build configuration. Most content changes are mechanical moves, but the runtime and deployment changes have a broad user-facing blast radius.
The new public
POST /api/chatroute also accepts client-provided message histories and invokes a billable Anthropic model without authentication, rate limiting, or request-size/history validation. The latest update changes only the default model from Sonnet to Haiku; that may reduce per-request cost but doesn't remove the cost-abuse, prompt-integrity, or operational-load exposure.I didn't approve because the cross-file production migration and unauthenticated model-backed endpoint remain Medium risk.
Sent by Cursor Automation: Assign PR reviewers
- port Kernel brand CSS from style.css (global lowercase, zero border radius, sidebar eyebrow headings, table styling, tinker-box, pricing button vars) - Card forwards img prop, CardGroup/Columns forward className - pages with url: frontmatter redirect externally instead of rendering an empty body - guard the .md/.mdx rewrites against /llms.mdx/* paths (they were double-rewriting direct raw-markdown URLs to 404s) and special-case /index.md for the home page - /api/chat requires a same-origin Origin header and caps output tokens - search index tolerates single-page failures instead of failing whole - set metadataBase so OG image URLs are absolute - ignore .env, simplify proxy.ts to Accept-header negotiation only Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Top navbar with horizontal tab bar (guides / api reference / cli / mcp) like the Mintlify site, and the Kernel logo SVGs from docs.json instead of a text title. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This PR replaces the production delivery stack for the entire documentation site: 196 files change, including new Next.js page and API routes, sitewide rendering/layout code, navigation generation, OpenAPI rendering, search, raw-markdown/OG endpoints, and Vercel/build configuration. Most MDX changes are mechanical moves, but the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The updated
POST /api/chatnow checksOriginand caps output at 2,048 tokens, which reduces cross-site browser abuse and per-request cost. It remains an unauthenticated, billable Anthropic proxy with no rate limiting or input/history size validation; direct clients can forge the matchingOriginheader and send high-volume or token-heavy requests. The latest layout and branding changes don't reduce the migration's sitewide deployment risk.I didn't approve because the full-stack docs migration and remaining cost/operational exposure meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This PR replaces the production delivery stack for the entire documentation site: 196 files change, including new Next.js page and API routes, sitewide rendering/layout code, navigation generation, OpenAPI rendering, search, raw-markdown/OG endpoints, and Vercel/build configuration. Most MDX changes are mechanical moves, but the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The public
POST /api/chatroute remains an unauthenticated proxy to a billable Anthropic model. Its origin check and output cap reduce browser-based abuse and per-request cost, but there is still no rate limiting or input/history size validation, and non-browser clients can supply a matchingOriginheader. The latest commit adds only sidebar hover/active styling, so it doesn't reduce the migration or endpoint risks.I didn't approve because the sitewide production migration and remaining cost/operational exposure meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
Override the MDX img component with fumadocs' ImageZoom so screenshots, diagrams, and demo gifs are click-to-zoom. Uses the built-in component + its stylesheet — no custom image handling. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 3,999 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public, billable Anthropic-backed chat endpoint with BotID, dashboard-managed firewall rate limiting, request/output bounds, and Braintrust telemetry that can send user message content, client IP, model output, and usage data to a third party. The latest update only enables click-to-zoom rendering for content images; it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the external model and telemetry integrations meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
| if (doc) search.add(doc); | ||
| } | ||
|
|
||
| return search; |
There was a problem hiding this comment.
Chat rebuilds search every cold start
Medium Severity
Each serverless instance starts createSearchServer() at module load and awaits getText("processed") for every docs page before flexsearch is usable. First Ask AI requests on a cold worker can block on hundreds of page extractions with no shared or build-time index.
Reviewed by Cursor Bugbot for commit 240ffc7. Configure here.
| const response = ctx.schema.resolve(responses[status]); | ||
| const contentTypes = response.content ? Object.entries(response.content) : []; | ||
| const [mediaType, media] = contentTypes[0] ?? []; | ||
| const schema = media ? ctx.schema.resolve(media).schema : undefined; |
There was a problem hiding this comment.
API response drops extra media
Medium Severity
The custom API response UI always takes the first entry from response.content and never lets readers switch media types. Operations with multiple response body types (for example JSON and an error schema) show only the first type’s schema.
Reviewed by Cursor Bugbot for commit 240ffc7. Configure here.
The 50k-char guard was returning 413 after a handful of turns (stateless chat re-sends full history + verbose answers). Raise to 400k chars (~100k tokens, ~half of Haiku's context) — a coarse abuse ceiling that real multi-turn conversations stay under, with rate limit + spend cap as the real cost bounds. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 4,001 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public, billable Anthropic-backed chat endpoint with BotID, dashboard-managed firewall rate limiting, and Braintrust telemetry that can transmit user message content, client IP, model output, and usage data to a third party. The latest update raises the accepted message-history size from 50,000 to 400,000 characters, increasing the possible per-request model cost and JSON parsing load while the rate-limit policy remains external to this diff.
I didn't approve because the sitewide runtime/infrastructure migration and the external model, cost-control, and telemetry surfaces meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
The filled saturated badges (white text on bright green/blue/red/orange) read as off-brand and loud. Switch to muted tint backgrounds + coloured text, matching the subtle prod badges — keeps the get/post/del semantic without the in-your-face fills. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 4,002 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public, billable Anthropic-backed chat endpoint with BotID, dashboard-managed firewall rate limiting, a 400,000-character request-history allowance, and Braintrust telemetry that can transmit user message content, client IP, model output, and usage data to a third party. The latest update only changes API method-badge colors; it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the external model, cost-control, and telemetry surfaces meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
- chat: return 403 (not 500) on a malformed Origin header, and reject an oversized body by Content-Length before parsing it - llms-full.txt: use allSettled so one failing page can't drop the whole corpus - markdown: bound the streaming render cache (FIFO) so a long streamed answer can't grow it without limit - Ask AI input: guard the localStorage read for the server render pass - pricing calculator: clamp number inputs so an empty field can't emit NaN totals, and hydrate from shared-link query params on mount - api-reference: exclude from the .md/.mdx rewrites and markdown negotiation so those pages serve HTML instead of rewriting to a 404 (generated from the OpenAPI spec, they have no markdown source) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 4,064 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public Anthropic-backed chat endpoint, a new system prompt, BotID and dashboard-managed firewall controls, and Braintrust telemetry that logs user message content and client IP while auto-instrumenting model output and usage. The latest update adds malformed-Origin and request-size guards and fixes several rendering/route issues, but it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the new external model and telemetry integrations meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
Brings in the latest content edits from main — the FAQ 'Unsupported Websites' → bot-detection reframing (#459) and the per-browser-type Stripe pricing updates. Rename detection carried them onto the migrated content/docs paths; no code overlap, build + lint green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 4,064 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public Anthropic-backed chat endpoint, a new system prompt, BotID and dashboard-managed firewall controls, and Braintrust telemetry that logs user message content and client IP while auto-instrumenting model output and usage. The latest update changes browser-automation guidance and Stripe Projects pricing documentation only; it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the external model and telemetry integrations meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
- size cap: read the raw body and check its length before JSON.parse instead of trusting Content-Length (absent on chunked requests), so an oversized body is rejected without being parsed and the cap can't be skipped by omitting the header - Ask AI index: skip external-link stub pages (frontmatter `url`, no real body) so search no longer returns empty internal URLs Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Carries main's latest content onto the migrated content/docs paths: - pricing feature matrix 'Browser telemetry' row (#460) - new audit-logs pages, info/ + reference/cli/ (#416), relocated into content/docs via directory-rename detection; docs.json nav merged Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
There are 7 total unresolved issues (including 6 from previous reviews).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 1a81b29. Configure here.
| if (rawBody.length > MAX_INPUT_CHARS) { | ||
| return new Response("Payload Too Large", { status: 413 }); | ||
| } | ||
| const reqJson = JSON.parse(rawBody); |
There was a problem hiding this comment.
Malformed chat JSON crashes
Medium Severity
The chat handler's POST function performs JSON.parse on the request body without error handling. This means any invalid JSON payload will cause an uncaught exception and a 500 response.
Reviewed by Cursor Bugbot for commit 1a81b29. Configure here.
There was a problem hiding this comment.
Risk assessment: Medium
The actual diff changes 203 files and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, markdown/OG endpoints, a new dependency/build stack, and Vercel configuration. Most MDX changes are mechanical moves, but the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public Anthropic-backed chat endpoint with a new system prompt, a server-side API key, BotID, dashboard-managed firewall controls, a 400,000-character request allowance, and Braintrust telemetry that logs user message content and client IP while instrumenting model output and usage. The latest update improves raw-body size enforcement and adds audit-log documentation, but it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the external model and telemetry integrations meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers




Summary
Replaces Mintlify hosting with a self-hosted fumadocs (Next.js) app, deployable on Vercel.
What's preserved
/browsers/standby). Content edits were limited to removing 3 dead snippet-import lines and adding frontmatter to one untracked testing doc.docs.jsonstays the navigation source of truth —lib/tree.tsconverts its tabs/groups into the sidebar at build time, so the editing workflow doesn't change. Redirects ported tonext.config.mjs.Info,Note,Tip,Warning,Card,CardGroup,Steps,Tabs,Accordion,Frame,Update,CodeGroup(incl. tab labels from fence titles, via a small remark plugin) are aliased to fumadocs equivalents incomponents/mdx.tsx.fumadocs-openapi(virtual pages, no generated files). Interactive playground is off (one flag incomponents/api-page.tsxto enable).New (things Mintlify gated behind paid tiers)
/llms.txt+/llms-full.txt(~970KB markdown dump).md/.mdxto any page URLANTHROPIC_API_KEYset in Vercel; degrades gracefully without itKnown gaps / review notes
/api-reference/getProjectsinstead of Mintlify's generated paths) — worth eyeballing hardest in the previewbun run buildcompiles all 561 pages green,bun run lintgreen, key routes smoke-tested (content pages, API reference, llms routes, .md rewrites, redirects). No visual QA beyond that yet.Deploy
Vercel: import repo, framework Next.js,
bun install && bun run build, setANTHROPIC_API_KEY, pointdocs.kernel.shat it.🤖 Generated with Claude Code
Note
High Risk
Large platform swap plus a new
/api/chatendpoint that uses an Anthropic API key and abuse controls; API reference URL slugs and search coverage may differ from production Mintlify.Overview
Replaces Mintlify with a self-hosted fumadocs (Next.js) docs app (
bun dev/bun run build, Biome lint). MDX stays undercontent/docs/;docs.jsonstill drives the sidebar vialib/tree.ts, with Mintlify MDX tags mapped incomponents/mdx.tsxand a remark pass forCodeGroup/ fence titles.New site capabilities: Orama-backed
/api/search, Ask AI (/api/chat— Anthropic, flexsearch tool, same-origin + BotID + Vercel rate limits, Braintrust tracing),llms.txt/ per-page markdown routes, OG images, and OpenAPI reference pages from the same Stainless spec (custom response UI; playground off by default). Brand/layout moves intoapp/global.css(Kernel colors, lowercase prose, square corners).Content touch-ups: drop old snippet import paths on a few pages; snippets become real React components (
CopyPromptButton,PricingCalculator,YouTubeVideo).Reviewed by Cursor Bugbot for commit 1a81b29. Bugbot is set up for automated code reviews on this repo. Configure here.