Fixes https://github.com/twentyhq/core-team-issues/issues/1956 **Problem** Within an app, the `.yarn/releases/` folder contains executable Yarn binaries that run when executing any yarn command (`.yarnrc` file indicates yarn path to be `.yarn/releases/yarn-4.9.2.cjs `.) This is a supply chain attack vector: a malicious actor could submit a PR with a compromised `yarn-4.9.2.cjs binary`, which would execute arbitrary code on developers' machines or CI systems. **Fix** Actually, thanks to Corepack, we don't need to store and execute this binary. Corepack can be seen as the manager of a package manager: in `package.json` we indicate a packageManager version like `"packageManager": "yarn@4.9.2"`, and when executing `yarn` Corepack will securely fetch the verified version from npm, avoiding the risk of executing a compromised binary committed to the repository. This was already in our app's package.json template but we were not using it! We can now - remove the folder containing the binary from our app template base-application (that is scaffolded when creating an app through cli), `.yarn/releases/`, and remove `yarnPath: .yarn/releases/yarn-4.9.2.cjs` from its .yarnrc - remove them from the community apps that were already published in the repo - add .yarn to gitignore **Tested** This has been tested and works for app created in the repo, outside the repo, and existing apps in the repo
🧠 AI-Powered Meeting Transcript to CRM Data Integration
Overview
This feature automatically transforms meeting transcripts into structured CRM data using AI. When unstructured meeting notes are received via a webhook, the system processes them and creates organized notes, tasks, and assignments directly in Twenty CRM.
Key Features
-
🤖 AI-Powered Analysis: Extracts summaries, action items, assignees, and due dates from natural language transcripts.
-
🗂 Smart Task Consolidation: Merges related sub-tasks into unified deliverables (e.g.,
"draft"+"review"+"present"→ one consolidated task). -
🧑🤝🧑 Intelligent Assignment: Uses GraphQL member lookup to match extracted assignee names to workspace member IDs with flexible string matching.
-
🔗 Automatic Linking: Links generated notes and tasks to relevant contacts using
noteTargetsandtaskTargets. -
📅 Date Parsing: Converts relative date expressions (e.g., “next Monday”, “end of week”) into ISO-formatted dates for accurate scheduling.
Requirements
- Twenty CLI - Install globally:
npm install -g twenty-cli - Twenty CRM instance with API access
- API key from Settings > API & Webhooks
- OpenAI API key or compatible service (Groq, etc.)
Installation
-
Authenticate with Twenty CLI:
twenty auth login -
Configure environment variables:
Copy
.env.exampleto.envand fill in your credentials:cp .env.example .envRequired environment variables:
AI_PROVIDER_API_KEY: Your OpenAI or Groq API keyTWENTY_API_KEY: Generated from your Twenty CRM instanceTWENTY_API_URL: Your Twenty CRM instance URL (e.g., https://your-instance.twenty.com)WEBHOOK_SECRET_TOKEN: Secret token for webhook authenticationAI_PROVIDER_API_BASE_URL: Base URL for OpenAI-compatible API (defaults to https://api.openai.com/v1)
-
Install dependencies:
yarn install -
Deploy to your Twenty workspace:
twenty app sync
Configuration
Using Groq Instead of OpenAI
To use Groq's API (which is compatible with OpenAI's SDK), set:
AI_PROVIDER_API_BASE_URL=https://api.groq.com/openai/v1
AI_PROVIDER_API_KEY=your-groq-api-key
Using OpenAI
To use OpenAI's official API:
AI_PROVIDER_API_BASE_URL=https://api.openai.com/v1
AI_PROVIDER_API_KEY=your-openai-api-key
🔗 Webhook Setup (inside Twenty)
Navigate to: Twenty → Workspace Settings → APIs & Webhook → + New Webhook
| Field | Value |
|---|---|
| Method | POST |
| URL | your deployed endpoint URL |
| Secret | Generate one & store same in .env |
Usage
Send a POST request to your webhook endpoint with the following payload:
{
"transcript": "During the Project Phoenix Kick-off on November 1st, 2025...",
"meetingTitle": "Project Phoenix Kick-off",
"meetingDate": "2025-11-01",
"participants": [
"Brian Chesky",
"Dario Amodei",
"Iqra Khan"
],
"token": "your-webhook-secret-token",
"relatedPersonId": "person-uuid-from-crm"
}
Response
{
"success": true,
"noteId": "note-uuid",
"taskIds": ["task-uuid-1", "task-uuid-2"],
"summary": {
"noteCreated": true,
"tasksCreated": 2,
"actionItemsProcessed": 2,
"commitmentsProcessed": 0
},
"executionLogs": [
"✅ Validation passed",
"🤖 Starting transcript analysis...",
"✅ Analysis complete"
]
}
Technical Stack
| Component | Description |
|---|---|
| AI Provider | Groq (via OpenAI SDK) using the GPT-OSS-20B model |
| APIs | Twenty CRM REST API + GraphQL (for member resolution) |
| Runtime | Webhook-triggered serverless function written in TypeScript |
Development
Build
yarn build
Type Check
yarn type-check
Environment Variables
| Variable | Required | Secret | Description |
|---|---|---|---|
AI_PROVIDER_API_KEY |
Yes | Yes | API key for OpenAI-compatible service |
TWENTY_API_KEY |
Yes | Yes | Twenty CRM API authentication token |
TWENTY_API_URL |
Yes | No | Base URL for Twenty CRM instance |
WEBHOOK_SECRET_TOKEN |
Yes | Yes | Secret for webhook request validation |
AI_PROVIDER_API_BASE_URL |
No | No | Base URL for AI service (defaults to OpenAI) |
Demo Preview
The demo below shows the full workflow where a raw meeting transcript is processed and automatically converted into structured Notes + Tasks inside Twenty CRM.