Evidence-backed facts
- A Notion connection can read only content covered by its capabilities and pages or databases that users have shared with the connection. informative
- Create or update capability and endpoint requirements are distinct; some capabilities allow updating existing pages without allowing creation of new pages. informative
- REST calls use an installation access token, and public connections require a user authorization flow while internal sharing is explicitly configured. informative
- The installation token is secret and belongs in a secret manager or environment, and missing page sharing must produce an authorization error rather than broader discovery. informative