Download Latest Version 0.4.0 source code.zip (1.9 MB) Google Add to Preferred Sources
Home / 0.4.0
Name Modified Size InfoDownloads / Week
Parent folder
Caddyfile 2026-09-30 830 Bytes
docker-compose-0.4.0.yml 2026-09-30 14.4 kB
docker-compose-lite-0.4.0.yml 2026-09-30 4.5 kB
docker-compose.lite.exec.yml 2026-09-30 709 Bytes
sinas-0.4.0.tgz 2026-09-30 17.4 kB
0.4.0 source code.tar.gz 2026-09-30 1.5 MB
0.4.0 source code.zip 2026-09-30 1.9 MB
README.md 2026-09-30 16.1 kB
Totals: 8 Items   3.4 MB 0

Sinas 0.4.0 adds pipelines, a single-container deployment profile, role-scoped API keys and OIDC-compatible tokens, and brings the Anthropic integration up to date with the current Claude models. It also closes two permission gaps in API keys, so read the upgrade notes before upgrading from 0.3.

Documentation: docs.sinas.co

Highlights

  • Pipelines. Unified triggers and linear, typed steps, with a steps editor in the console. Agents can call pipelines as tools.
  • All-in-one lite profile. API, workers, scheduler, change data capture and the console in one container, idling at about 256 MiB including Postgres and Redis.
  • Role-scoped API keys. Keys can be linked to roles, and a key's permissions are always capped by what its owner holds right now.
  • Current Claude models. Per-agent effort control, native structured outputs, and fixes for parallel tool calls.
  • Console at /ui. The console now lives under /ui, so the ingress routes by path with no allowlist to maintain.

New

Pipelines and automation

  • Pipelines with unified triggers and linear typed steps, schedulable, with persisted run output.
  • A pipeline steps editor in the console, and pipeline tools on agents.
  • Webhooks can target agents natively, with an optional raw response mode.
  • Runtime discovery endpoints GET /pipelines and GET /queries, completing the discovery surface.

Authentication and access

  • OIDC-compatible tokens. Optional RS256 signing, a /.well-known/jwks.json endpoint and /userinfo, so other services can verify Sinas tokens with standard JWT libraries.
  • API keys linked to roles. A key can carry zero or more roles. Its effective permissions are its own grants plus its roles' permissions, capped by the owner's live permissions.
  • PATCH /api-keys/{id} changes a key's scope in place, and roles can be created with their permissions inline.
  • Packages can ship roles. They define roles but never assign them.
  • Superadmin setup link. An install with no superadmin password and no SMTP no longer fails to install. On boot, the backend logs a one-time setup link for the superadmin.

Models and providers

  • Per-agent effort for Anthropic models. Current Claude models think by default, and effort is the only control over how much. Set it per agent in the console or with providerOverrides.effort.
  • Native structured outputs for Anthropic. Output-schema agents now use Claude's native structured outputs, which work on every current Claude model.
  • Per-agent provider overrides, starting with prompt caching.
  • A Gemini provider type with batch support.
  • Provider-native batching for tool-less agent batches, at batch pricing.
  • Cached-token reporting for OpenAI-compatible providers.
  • Configurable OAuth token-response paths for connectors whose providers deviate from the standard, such as Slack.

Deployment

  • The all-in-one lite profile, with a values-lite.yaml preset and docker-compose.lite.yml.
  • External PostgreSQL, for managed databases such as Cloud SQL.
  • nodeSelector, tolerations and affinity for every workload. Global defaults deliberately never reach the stateful datastores.
  • Toggles to disable code execution and the built-in database.
  • Image tags now default to the chart's version, so a versioned install pulls matching images.

Console

  • Light mode, with a theme toggle.
  • The new Sinas logo and favicon.

Fixes

  • Parallel tool calls on OpenAI, Azure and Gemini collapsed onto one id when streaming. The chat then failed on that turn and on every turn after it.
  • Authentication under load. Every request wrote the same API key row and the same user row, so a single shared service key serialised all traffic. Usage timestamps are now written at most once a minute.
  • Package uninstall failed once a package had been used, because of function versions and chats that still referenced it. Chats are now kept, and only their link to the removed agent is cleared.
  • Keys created in the console could not execute namespaced resources such as functions. The editor now grants the path-form permission as well.
  • Resumed turns that failed after tool approval or delegation now leave an error in the chat, instead of stopping silently.
  • Admin password reset returned a 500 on every install that had never issued one.
  • The built-in database connection can no longer be renamed or re-pointed into a broken state.
  • Queue saturation is handled with bounded deferral and retry, and crash-safe slot claims in the shared worker pool.
  • Numerous chart fixes, including helm upgrade --reuse-values from older releases and datastore resource requests.
  • The chart now passes the configured domain to the backend. OAuth connector callbacks and public file links previously pointed at localhost on chart deployments.

Upgrading from 0.3

Change What to do
The console moved to /ui Update bookmarks and links to https://<your-domain>/ui/. Old console paths redirect.
API keys are capped by their owner's live permissions A key keeps only the permissions its owner currently holds. Keys whose grants exceed their owner's roles lose the excess on upgrade. Review service keys before upgrading.
Creating a role no longer adds the creator as a member Assign members explicitly. A non-admin who creates a role cannot see it unless they are added to it.
Output schemas on Anthropic agents Schemas are now enforced natively. An object that allows arbitrary extra keys, such as a free-form map, is rejected with the path named. Give it explicit properties, or model it as an array of key and value objects.
temperature has no effect on Anthropic models The current Anthropic SDK no longer accepts sampling parameters. Use effort to trade depth for cost instead.
Superadmin password If SUPERADMIN_PASSWORD is set, it is applied on every restart, and changes made in the console are reverted. Leave it unset to manage the password in Sinas.
Helm --reuse-values Prefer -f values.yaml. --reuse-values does not pick up new chart defaults.
extraEnv workarounds Remove any AUTH_MODE or SUPERADMIN_PASSWORD entries you added to extraEnv before upgrading. The chart now sets these itself, and duplicate keys are rejected.
Objects patched by hand with kubectl Helm will report field-manager conflicts on upgrade. Delete the patched object and let Helm recreate it.

Known limitations

  • Effort is rejected by Claude Haiku 4.5 and Sonnet 4.5. Leave it unset for agents on those models.
  • Streaming chat does not yet enforce output schemas on Anthropic models, and relies on the instruction in the prompt.

What's Changed

Full Changelog: https://github.com/sinas-platform/sinas/compare/0.3.0...0.4.0

Source: README.md, updated 2026-09-30