---
collection: productivity-apps
collection_name: Productivity & Collaboration
week_start: 2026-09-28
title: Block Kit expands as Notion locks down browser tokens
release_count: 11
generated: 2026-10-05
canonical: https://releases.sh/collections/productivity-apps/digest/2026-09-28
---

# Block Kit expands as Notion locks down browser tokens

Notion's JavaScript SDK now refuses to run browser-side with a token unless you explicitly opt out, while Slack's SDKs grew first-class support for Code agents and new Block Kit containers across Python and Node.

### Notion closes a token-leak door

The week's most consequential change for anyone embedding Notion is a security default that flips. [Constructing a client with `auth` inside a browser page, web worker, or service worker now throws `BrowserTokenNotAllowedError`](https://github.com/makenotion/notion-sdk-js/releases/tag/v5.27.0) — the same error fires for per-request `auth` and OAuth client credentials before a request ever leaves the machine. It's a blunt fix for a real problem: any script that can load the page can read the token and act as the integration. Server-side code is untouched, and browser code that genuinely needs the old behavior can pass `dangerouslyAllowBrowser: true`, but the naming is the point — the SDK wants you to mean it.

The same SDK also picked up `client.plugins` and `client.skills` methods returning signed archive URLs, typed databases via a `database_type` field, and refreshed agent response types, including the `notion_ai` personal agent ID. The desktop and mobile apps churned quietly alongside with [bug fixes and performance improvements](https://apps.apple.com/us/app/notion-notes-tasks-ai/id1232780281?v=1.7.344) and a [second round of the same](https://apps.apple.com/us/app/notion-notes-tasks-ai/id1232780281?v=1.7.343) — worth a mention only because the SDK work is what actually changes how you build.

### Slack builds out agent and block primitives

Slack's SDKs spent the week laying groundwork for agents that live inside conversations. The [Python SDK added the `agents.conversations.*` methods](https://github.com/slackapi/python-slack-sdk/releases/tag/v3.45.0) alongside new model types, and [Node's Web API client followed with the same surface](https://github.com/slackapi/node-slack-sdk/releases/tag/%40slack/web-api%408.2.0) — create, archive, setProperties, and more — giving both languages parity for Code agents.

Block Kit got the other half of the attention. Node's type package landed a [ContainerBlock interface](https://github.com/slackapi/node-slack-sdk/releases/tag/%40slack/types%403.2.0) plus a `data_table` block type, `raw_number` cells in table rows, and optional `action_id` fields; Python's models mirrored the container and raw-number work. Anyone building layout-heavy messages should check which of these are typed before reaching for a workaround. Separately, the socket-mode client [added support for `undici@8` and pinned WebSocket connections to HTTP/1.1 by default](https://github.com/slackapi/node-slack-sdk/releases/tag/%40slack/socket-mode%403.1.0), and stopped a spurious ping/pong warning that had been firing off other undici WebSockets. The Slack app itself fixed duplicate bookmarked workflows by [quietly collapsing them into one](https://apps.apple.com/us/app/slack/id618783545?v=26.09.50).

### Figma makes motion shareable

Figma pushed two features that both answer the same question — how does work leave the file? [Community riffs let you post animations, prototypes, and experiments](https://www.figma.com/release-notes/?title=post-riffs-to-figma-community) to the Figma Community and your profile, turning one-off experiments into a portfolio piece. And [Figma Motion gained custom styles, audio, text animations, and Lottie export](https://www.figma.com/release-notes/?title=motion-adds-styles-audio-animations-lottie), which matters most for handoff: Lottie output means an animation built here can ship in production without being rebuilt. The [mobile app picked up smaller collaboration and navigation improvements](https://www.figma.com/release-notes/?title=smoother-design-collaboration) in the same batch.

## Releases covered

### Figma

- [Figma adds Community riffs for sharing animations and prototypes](https://www.figma.com/release-notes/?title=post-riffs-to-figma-community)
- [Figma Motion adds custom styles, audio, text animations and Lottie export](https://www.figma.com/release-notes/?title=motion-adds-styles-audio-animations-lottie)
- [Figma mobile app improves design collaboration and navigation](https://www.figma.com/release-notes/?title=smoother-design-collaboration)

### Notion

- [Notion JS SDK v5.27.0 blocks tokens in browsers by default](https://github.com/makenotion/notion-sdk-js/releases/tag/v5.27.0)
- [Notion 1.7.344 bug fix and performance update](https://apps.apple.com/us/app/notion-notes-tasks-ai/id1232780281?v=1.7.344)
- [Notion 1.7.343 bug fixes and performance improvements](https://apps.apple.com/us/app/notion-notes-tasks-ai/id1232780281?v=1.7.343)

### Slack

- [v3.45.0](https://github.com/slackapi/python-slack-sdk/releases/tag/v3.45.0)
- [@slack/web-api@8.2.0](https://github.com/slackapi/node-slack-sdk/releases/tag/%40slack/web-api%408.2.0)
- [@slack/types@3.2.0](https://github.com/slackapi/node-slack-sdk/releases/tag/%40slack/types%403.2.0)
- [@slack/socket-mode@3.1.0](https://github.com/slackapi/node-slack-sdk/releases/tag/%40slack/socket-mode%403.1.0)
- [Slack 26.09.50](https://apps.apple.com/us/app/slack/id618783545?v=26.09.50)
