Migrate docs from Mintlify to fumadocs#457
Conversation
- content unchanged: 140 mdx pages keep their paths and URLs; Mintlify components (Info, CodeGroup, Steps, Card, ...) aliased to fumadocs equivalents in components/mdx.tsx - docs.json stays the navigation source of truth; lib/tree.ts converts it to the fumadocs page tree at build time - API Reference generated from the same Stainless OpenAPI spec via fumadocs-openapi (virtual pages, playground off by default) - llms.txt, llms-full.txt, per-page raw markdown (.md suffix on any page URL), and AI page actions built in - Ask AI assistant wired to Anthropic via AI SDK (needs ANTHROPIC_API_KEY at deploy time) - redirects, GA4, Inter font, and brand colors ported from docs.json Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
| const [actualOpen, setActualOpen] = useState(open); | ||
| useHotKey(); | ||
|
|
||
| if (open && !actualOpen) setActualOpen(open); |
There was a problem hiding this comment.
setState during render in panel
Medium Severity
AISearchPanel calls setActualOpen(open) directly in the render path when open && !actualOpen. Updating state while rendering violates React’s rules and can cause extra renders or warnings, especially under Strict Mode.
Reviewed by Cursor Bugbot for commit 6ed79ee. Configure here.
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This changes the production delivery stack for the entire documentation site rather than only moving content: 195 files are affected, with new Next.js routing, OpenAPI rendering, search, raw-markdown endpoints, and deployment/build configuration. That gives the migration a broad user-facing blast radius.
The new
POST /api/chatroute also invokes a billable Anthropic model from client-supplied message history without authentication, rate limiting, or request-size/history validation. Although its tool access is limited to public docs, this creates material cost-abuse, prompt-integrity, and operational-load risk. The existing broken-link workflow still runs the Mintlify checker and is currently failing against the migrated tree, so migration validation isn't green.I did not approve this PR because these cross-file runtime and operational changes meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
The Vercel project was imported while the default branch was still Mintlify-only (no package.json), so framework auto-detection picked "Other" and served public/ statically. Pinning it here overrides the project setting on every deploy. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This PR replaces the production delivery stack for the entire documentation site: 196 files are affected, with new Next.js routing, navigation generation, OpenAPI rendering, search, raw-markdown/OG endpoints, and build/deployment configuration. Although most documentation files are mechanical moves, the runtime and infrastructure changes have a broad user-facing blast radius.
The public
POST /api/chatroute also sends client-provided message histories to a billable Anthropic model without authentication, rate limiting, or request-size/history validation, which creates material cost-abuse and operational-load risk. The latest update addsvercel.jsonto select the Next.js framework; it doesn't reduce those existing risks and further confirms that this PR changes deployment behavior.I didn't approve because the cross-file production migration and unauthenticated model-backed endpoint meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This PR still replaces the production delivery stack for the entire documentation site: 196 files are affected, including new Next.js page/API routes, navigation generation, OpenAPI rendering, search, markdown/OG endpoints, and Vercel/build configuration. Most content changes are mechanical moves, but the runtime and deployment changes have a broad user-facing blast radius.
The new public
POST /api/chatroute also accepts client-provided message histories and invokes a billable Anthropic model without authentication, rate limiting, or request-size/history validation. The latest update changes only the default model from Sonnet to Haiku; that may reduce per-request cost but doesn't remove the cost-abuse, prompt-integrity, or operational-load exposure.I didn't approve because the cross-file production migration and unauthenticated model-backed endpoint remain Medium risk.
Sent by Cursor Automation: Assign PR reviewers
- port Kernel brand CSS from style.css (global lowercase, zero border radius, sidebar eyebrow headings, table styling, tinker-box, pricing button vars) - Card forwards img prop, CardGroup/Columns forward className - pages with url: frontmatter redirect externally instead of rendering an empty body - guard the .md/.mdx rewrites against /llms.mdx/* paths (they were double-rewriting direct raw-markdown URLs to 404s) and special-case /index.md for the home page - /api/chat requires a same-origin Origin header and caps output tokens - search index tolerates single-page failures instead of failing whole - set metadataBase so OG image URLs are absolute - ignore .env, simplify proxy.ts to Accept-header negotiation only Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Top navbar with horizontal tab bar (guides / api reference / cli / mcp) like the Mintlify site, and the Kernel logo SVGs from docs.json instead of a text title. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This PR replaces the production delivery stack for the entire documentation site: 196 files change, including new Next.js page and API routes, sitewide rendering/layout code, navigation generation, OpenAPI rendering, search, raw-markdown/OG endpoints, and Vercel/build configuration. Most MDX changes are mechanical moves, but the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The updated
POST /api/chatnow checksOriginand caps output at 2,048 tokens, which reduces cross-site browser abuse and per-request cost. It remains an unauthenticated, billable Anthropic proxy with no rate limiting or input/history size validation; direct clients can forge the matchingOriginheader and send high-volume or token-heavy requests. The latest layout and branding changes don't reduce the migration's sitewide deployment risk.I didn't approve because the full-stack docs migration and remaining cost/operational exposure meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This PR replaces the production delivery stack for the entire documentation site: 196 files change, including new Next.js page and API routes, sitewide rendering/layout code, navigation generation, OpenAPI rendering, search, raw-markdown/OG endpoints, and Vercel/build configuration. Most MDX changes are mechanical moves, but the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The public
POST /api/chatroute remains an unauthenticated proxy to a billable Anthropic model. Its origin check and output cap reduce browser-based abuse and per-request cost, but there is still no rate limiting or input/history size validation, and non-browser clients can supply a matchingOriginheader. The latest commit adds only sidebar hover/active styling, so it doesn't reduce the migration or endpoint risks.I didn't approve because the sitewide production migration and remaining cost/operational exposure meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
This remains a sitewide production-platform migration rather than a documentation-only change. The actual diff changes 201 files with 3,981 additions and replaces Mintlify delivery with a Next.js/Fumadocs application, including shared routing and layout code, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX files are mechanical moves, the runtime and deployment cutover affects every docs page.
The PR also adds a public, billable Anthropic-backed chat endpoint with BotID, dashboard-managed firewall rate limiting, request/output bounds, and Braintrust telemetry. The latest update derives a stable trace context from a client-supplied conversation message ID so multiple turns share one external telemetry trace; it doesn't reduce the existing privacy, cost, and operational surface of the endpoint. Several user-facing correctness concerns also remain open in review threads.
I didn't approve because the full-site runtime/infrastructure cutover and third-party model and telemetry integrations meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
The AI SDK re-POSTs on retry (trigger: regenerate-message), so a regeneration logs as a fresh turn span. Tag it: trigger metadata + the regenerated message id, and name the span 'docs-chat (retry)' so retried answers are obvious and filterable in the thread (a regenerate is a signal the first answer fell short) while staying in the conversation. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 3,991 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public, billable Anthropic-backed chat endpoint with BotID, dashboard-managed firewall rate limiting, request/output bounds, and Braintrust telemetry that can send user message content, client IP, model output, and usage data to a third party. The latest update only tags retry requests and regenerated-message IDs in that telemetry; it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the new external model and telemetry integrations meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
Override the MDX img component with fumadocs' ImageZoom so screenshots, diagrams, and demo gifs are click-to-zoom. Uses the built-in component + its stylesheet — no custom image handling. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 3,999 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public, billable Anthropic-backed chat endpoint with BotID, dashboard-managed firewall rate limiting, request/output bounds, and Braintrust telemetry that can send user message content, client IP, model output, and usage data to a third party. The latest update only enables click-to-zoom rendering for content images; it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the external model and telemetry integrations meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
| if (doc) search.add(doc); | ||
| } | ||
|
|
||
| return search; |
There was a problem hiding this comment.
Chat rebuilds search every cold start
Medium Severity
Each serverless instance starts createSearchServer() at module load and awaits getText("processed") for every docs page before flexsearch is usable. First Ask AI requests on a cold worker can block on hundreds of page extractions with no shared or build-time index.
Reviewed by Cursor Bugbot for commit 240ffc7. Configure here.
| const response = ctx.schema.resolve(responses[status]); | ||
| const contentTypes = response.content ? Object.entries(response.content) : []; | ||
| const [mediaType, media] = contentTypes[0] ?? []; | ||
| const schema = media ? ctx.schema.resolve(media).schema : undefined; |
There was a problem hiding this comment.
API response drops extra media
Medium Severity
The custom API response UI always takes the first entry from response.content and never lets readers switch media types. Operations with multiple response body types (for example JSON and an error schema) show only the first type’s schema.
Reviewed by Cursor Bugbot for commit 240ffc7. Configure here.
The 50k-char guard was returning 413 after a handful of turns (stateless chat re-sends full history + verbose answers). Raise to 400k chars (~100k tokens, ~half of Haiku's context) — a coarse abuse ceiling that real multi-turn conversations stay under, with rate limit + spend cap as the real cost bounds. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 4,001 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public, billable Anthropic-backed chat endpoint with BotID, dashboard-managed firewall rate limiting, and Braintrust telemetry that can transmit user message content, client IP, model output, and usage data to a third party. The latest update raises the accepted message-history size from 50,000 to 400,000 characters, increasing the possible per-request model cost and JSON parsing load while the rate-limit policy remains external to this diff.
I didn't approve because the sitewide runtime/infrastructure migration and the external model, cost-control, and telemetry surfaces meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
The filled saturated badges (white text on bright green/blue/red/orange) read as off-brand and loud. Switch to muted tint backgrounds + coloured text, matching the subtle prod badges — keeps the get/post/del semantic without the in-your-face fills. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 4,002 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public, billable Anthropic-backed chat endpoint with BotID, dashboard-managed firewall rate limiting, a 400,000-character request-history allowance, and Braintrust telemetry that can transmit user message content, client IP, model output, and usage data to a third party. The latest update only changes API method-badge colors; it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the external model, cost-control, and telemetry surfaces meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
- chat: return 403 (not 500) on a malformed Origin header, and reject an oversized body by Content-Length before parsing it - llms-full.txt: use allSettled so one failing page can't drop the whole corpus - markdown: bound the streaming render cache (FIFO) so a long streamed answer can't grow it without limit - Ask AI input: guard the localStorage read for the server render pass - pricing calculator: clamp number inputs so an empty field can't emit NaN totals, and hydrate from shared-link query params on mount - api-reference: exclude from the .md/.mdx rewrites and markdown negotiation so those pages serve HTML instead of rewriting to a 404 (generated from the OpenAPI spec, they have no markdown source) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Medium
The actual diff changes 201 files with 4,064 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public Anthropic-backed chat endpoint, a new system prompt, BotID and dashboard-managed firewall controls, and Braintrust telemetry that logs user message content and client IP while auto-instrumenting model output and usage. The latest update adds malformed-Origin and request-size guards and fixes several rendering/route issues, but it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the new external model and telemetry integrations meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
Brings in the latest content edits from main — the FAQ 'Unsupported Websites' → bot-detection reframing (#459) and the per-browser-type Stripe pricing updates. Rename detection carried them onto the migrated content/docs paths; no code overlap, build + lint green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
Risk assessment: Medium
The actual diff changes 201 files with 4,064 additions and replaces the production delivery stack for the entire documentation site with a Next.js/Fumadocs application. It adds sitewide routing and rendering, generated OpenAPI pages, search, raw-markdown and OG endpoints, a new dependency/build stack, and Vercel configuration. Although most MDX changes are mechanical moves, the runtime and deployment cutover affects every docs page and has a broad user-facing blast radius.
The PR also adds a public Anthropic-backed chat endpoint, a new system prompt, BotID and dashboard-managed firewall controls, and Braintrust telemetry that logs user message content and client IP while auto-instrumenting model output and usage. The latest update changes browser-automation guidance and Stripe Projects pricing documentation only; it doesn't reduce the migration, privacy, cost, or operational surface.
I didn't approve because the sitewide runtime/infrastructure migration and the external model and telemetry integrations meet the Medium-risk threshold.
Sent by Cursor Automation: Assign PR reviewers
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.
There are 8 total unresolved issues (including 6 from previous reviews).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 3fe509e. Configure here.
| return new Response("Payload Too Large", { status: 413 }); | ||
| } | ||
|
|
||
| const reqJson = await req.json(); |
There was a problem hiding this comment.
Missing Content-Length skips size cap
Medium Severity
The chat route rejects oversized bodies using Number(req.headers.get("content-length")) before req.json(). When Content-Length is absent, that value is 0, so the check never runs and a large chunked body can be fully parsed before the later JSON size guard.
Reviewed by Cursor Bugbot for commit 3fe509e. Configure here.
| description: page.data.description, | ||
| url: page.url, | ||
| content: await page.data.getText("processed"), | ||
| } as CustomDocument; |
There was a problem hiding this comment.
Ask AI indexes external stubs
Low Severity
The Ask AI flexsearch index includes every page with getText, including frontmatter-only external link stubs. Search can return those internal URLs with empty content instead of useful docs or the real external target.
Reviewed by Cursor Bugbot for commit 3fe509e. Configure here.




Summary
Replaces Mintlify hosting with a self-hosted fumadocs (Next.js) app, deployable on Vercel.
What's preserved
/browsers/standby). Content edits were limited to removing 3 dead snippet-import lines and adding frontmatter to one untracked testing doc.docs.jsonstays the navigation source of truth —lib/tree.tsconverts its tabs/groups into the sidebar at build time, so the editing workflow doesn't change. Redirects ported tonext.config.mjs.Info,Note,Tip,Warning,Card,CardGroup,Steps,Tabs,Accordion,Frame,Update,CodeGroup(incl. tab labels from fence titles, via a small remark plugin) are aliased to fumadocs equivalents incomponents/mdx.tsx.fumadocs-openapi(virtual pages, no generated files). Interactive playground is off (one flag incomponents/api-page.tsxto enable).New (things Mintlify gated behind paid tiers)
/llms.txt+/llms-full.txt(~970KB markdown dump).md/.mdxto any page URLANTHROPIC_API_KEYset in Vercel; degrades gracefully without itKnown gaps / review notes
/api-reference/getProjectsinstead of Mintlify's generated paths) — worth eyeballing hardest in the previewbun run buildcompiles all 561 pages green,bun run lintgreen, key routes smoke-tested (content pages, API reference, llms routes, .md rewrites, redirects). No visual QA beyond that yet.Deploy
Vercel: import repo, framework Next.js,
bun install && bun run build, setANTHROPIC_API_KEY, pointdocs.kernel.shat it.🤖 Generated with Claude Code
Note
High Risk
Full docs platform swap affects every URL, build, and deploy path; the new
/api/chatroute uses a paid LLM API key and needs correct abuse controls in production.Overview
Replaces Mintlify with a fumadocs + Next.js app (
bun dev/bun run build, Biome lint). MDX stays undercontent/docs/;docs.jsonstill drives the sidebar vialib/tree.ts, with redirects moved to Next config.Routing & content: Catch-all doc pages, a separate API reference tree from the same Stainless OpenAPI URL (
fumadocs-openapi), OG images, and.md/.mdxrewrites to raw markdown for agents. Mintlify fences/CodeGroupbehavior is handled byremarkMintlifyCode; callouts, cards, tabs, etc. are aliased incomponents/mdx.tsx. Snippet components (CopyPromptButton,PricingCalculator,YouTubeVideo) are proper client modules registered in MDX.New product surface: Site search (
/api/search),/llms.txt//llms-full.txt, Ask AI (floating panel +/api/chatwith Anthropic, Flexsearch tool, origin check, BotID, Vercel Firewall rate limit, Braintrust tracing). Page actions: copy markdown, open in ChatGPT/Claude. Kernel brand CSS (lowercase UI, square corners, table styling) ports Mintlify theming.API docs UX: Custom sidebar method badges, response status dropdown instead of accordions, playground disabled by default.
Content tweaks only: Remove old
/snippets/*imports from a few pages; add frontmatter to one testing markdown file.Reviewed by Cursor Bugbot for commit 3fe509e. Bugbot is set up for automated code reviews on this repo. Configure here.