Download Latest Version v0.22.0 source code.zip (12.1 MB) Google Add to Preferred Sources
Home / v0.20.0
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-09-24 3.1 kB
v0.20.0 source code.tar.gz 2026-09-24 10.8 MB
v0.20.0 source code.zip 2026-09-24 11.9 MB
Totals: 3 Items   22.7 MB 8

The audit release: every account can now see which agents and keys are connected to it and what each one called, and an admin can see that for everyone.

Audit log

  • A new Audit log page in the profile menu lists the agents (browser sign-ins) and connection keys connected to your account, with when each connected, when it was last used and how much it has called. Admins see every account.
  • A row opens in place to the calls that agent or key made: a platform capability, a tool from a connected server or .tool manual, or a skill it read, with the outcome and the time, newest first. Skills and tools link to their pages.
  • Only what was called is recorded. Nothing an agent sent or received is stored.
  • Any row can be revoked. Revoking an agent cuts off every token it holds, including a local server's exchanged grant, and it reconnects only by signing in again.
  • One row per agent per person. A client that registers itself afresh on every sign-in, as Claude does, no longer appears once per registration; existing duplicates are merged on upgrade.
  • A new deployment setting, Keep events for, prunes events older than that many days. Left blank, zero or negative keeps them forever.
  • The page replaces the admin Connection keys page. Keys are still created and deleted on External agent access. A deleted key leaves the owner's listings while its history stays visible to admins.

Local MCP server

  • A browser sign-in from the local server now belongs to the agent that runs it. The server learns which one from the MCP handshake and registers as, for example, "Claude Code ยท local server on your-machine". That is the name on the Audit log page, and what a revoke there ends.
  • Each agent on a machine signs in once, as itself, and keeps its own credential. Key mode is unchanged.
  • A client that hangs up during the sign-in, or a sign-in that fails, ends the process instead of leaving it waiting.

Fixes

  • A path naming the repository's internal git folder, or a symbolic link into it, is refused with the one sanitized 403 however the path is spelled. Nothing under the folder was reachable before; the refusal named the wrong reason.
  • The agent filesystems judge a path against the git folder in one pass instead of two, so each read resolves the root once.
  • A build clears its output folder first, so a published package holds only the modules its source declares. Earlier packages could carry compiled files of modules since deleted.

Upgrading

  • Two migrations run at boot, as every core migration does: one adds the audit tables, the other merges duplicate agent rows per person and adds soft deletion for keys. Boot waits for them.
  • On the first start after upgrading, a keyless local server signs in once more, because the sign-in is now the agent's. Its previous per-machine sign-in is revoked at the workspace and removed from disk.
  • /connection-keys redirects to /audit-log. Bookmarks keep working.
  • Events are kept forever unless you set AUDIT_RETENTION_DAYS, or the Keep events for setting, to a number of days.
Source: README.md, updated 2026-09-24