Skip to content

v0.3.0

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 06 Aug 07:58
· 113 commits to develop since this release

0.3.0 (2026-08-06)

Features

  • add anthropic streaming support; fix oauth model id forwarding (a076266)
  • add modules:read and modules:manage permissions across the chain (df169be)
  • api-reverse-proxy: add api_reverse_proxy di token and module wrapper (cc4f6cf)
  • api: add api_routes di token exposing the route-contribution hook (590815a)
  • api: connections + instances crud and descriptors list (1ff3d5e)
  • api: model crud operates on instances and connections (10d7f26)
  • api: require model:read permission for get /api/models (8114934)
  • api: wire route-contribution registry into the api plugin (bb4b1c2)
  • audit: add audit di token and module wrapper (14fa3f0)
  • auth: 2fa totp enrollment and login verification (#84) (64f7650)
  • auth: add auth di token and module wrapper (f37c0a3)
  • auth: add connections:read/connections:manage permission chain (a3ab4ee)
  • auth: add optimizers:read/manage permissions (2a4fa18)
  • auth: merge feat/issue-84-2fa-totp into release/0.3.0 (#84) (b51cc57)
  • auth: persist requiremfa setting and add 2fa blocking redirect (#84) (351fcbd)
  • budget: hierarchical spend limits org/team/key cascade (#82) (3c0e066)
  • cache: semantic response caching for non-streaming llm requests (#75) (3146694)
  • catalog: add catalog di token and module wrapper (7688656)
  • catalog: dynamic provider catalog from configurable git repositories (25cb42c), closes #114
  • catalog: merge feature/114-dynamic-provider-catalog into release/0.3.0 (42711db)
  • catalog: repeatable per-provider instance import script (5fabd25)
  • ci: make promote-stable a reusable workflow with explicit source-image check (9f8b43d)
  • ci: publish versioned tag from develop promotion (3bd2616)
  • ci: publish versioned tag from develop promotion (ff08c07)
  • ci: run full test suite on release branches (b447227)
  • ci: run full test suite on release branches (ea06466)
  • claude code integration via routerly transparent proxy (ed026e1)
  • claude: add a docs-writer agent to the chain (9d69e80)
  • cli: add report savings subcommand (42d340d)
  • cli: add cli coverage for all 0.3.0 features (a3fa0f0)
  • cli: add routerly modules list/enable/disable command (2f603a5)
  • cli: add routerly profiles list/show/clone/set (11e090d)
  • cli: add the experiments command group (627fbc2)
  • cli: bind models to preconfigured connections (741ea23)
  • cli: claude code client integration (fba5d5f)
  • cli: client-integration contract + token acquisition (0231a5f)
  • cli: codex client integration (a2d90ce)
  • cli: continue client integration + cline documented entry (1ba1d13)
  • cli: cover the whole client registry, manual steps included (88d1627)
  • cli: describe optimizer thresholds, list captured prompts, replay them in preview (6ae1ccd)
  • cli: drive mcp from personal tokens (aa36281)
  • clients: extend the client registry with connect modes and mcp snippets (80be733)
  • cli: match the readable inbox on the command line (33565f5)
  • cli: notification inbox and channel commands (2b32ee5)
  • cli: opencode client integration (d95dc06)
  • cli: optimizers list/config/preview commands (571d5ab)
  • cli: profiles command for routing, optimizer and security kinds (14ff9da)
  • cli: routerly clients list|inspect|configure|doctor|undo|launch (b8f4f4a)
  • cli: routerly connections list|add|remove + models connection column (7aa2f7f)
  • cli: routerly mcp tools|test|serve (05d04a9)
  • cli: safe file-transaction helper (backup+checksum+atomic+rollback) (aa3e735)
  • config: add updateAnnouncement to the config store (2fcf30d)
  • config: config module exposes loader behind config store (61ba575)
  • config: one-shot idempotent models.json to connections+instances migration (9eb94e4)
  • config: persist provider connections and model instances sections (78f44d6)
  • connections: provider defaults and custom upstream provider (a23bfc0)
  • connections: provider-aware credential parity across service, cli, dashboard (1e96ef6)
  • connections: unique generated names and a one-click provider picker (7956fd4)
  • connect: official brand marks and a guided client grid (77ece69)
  • core: add alterableregistry generic hook-ordered contribution registry (b2360f2)
  • core: add alterableregistry get(id) lookup (2a42dab)
  • core: add routecontribution and createrouteregistry for future route-hook modules (11bed93)
  • core: add servicecontainer.override for service decoration (572175b)
  • core: build kernel bootstrap seam (69cdad8)
  • core: dependency graph topological sort (bece08d)
  • core: expose alterableregistry and route-contribution hooks via core barrels (ae784ac)
  • core: frozen di service tokens (db83e2d)
  • core: inert contrib module registration seam (06a12d6)
  • core: let modules own their config migrations (33bb936)
  • core: module kernel lifecycle runner (85831d6)
  • core: module manifest and definemodule (d9bd318)
  • core: phase-scoped processor dag (74ae56b)
  • core: public barrel export for modular kernel (f398d1b)
  • core: public module sdk authoring barrel (b42b09c)
  • core: result and kernel error primitives (c12c67f)
  • core: surface/metamodule contract stub (types-only) (48797cb)
  • core: typed service container (3e9180d)
  • dashboard: add end-users tab to project detail page (#96) (697bb1d)
  • dashboard: add end-users tab to project detail page (#96) (c97ae4d)
  • dashboard: add label for system.update_available event (4ea5515)
  • dashboard: add settings > modules tab with enable/disable toggles (764c59b)
  • dashboard: add the project dashboard tab (0c95bca)
  • dashboard: clickable project rows + multi-endpoint connection info (dbb6ae3)
  • dashboard: clients discovery page (fd98d02)
  • dashboard: connect section with a page per client (cd21174)
  • dashboard: connect shortcut card on the overview page (7cb1033)
  • dashboard: connections + model instances pages (161643a)
  • dashboard: convert remaining native selects to searchable select (c32336d)
  • dashboard: curate the server info block and flatten the sidebar order (5e751a8)
  • dashboard: dedicated connection create/edit pages (c7c7c72)
  • dashboard: download and pick the llmlingua-2 checkpoint from its own row (0a2e2a1)
  • dashboard: experiments section with metrics and manual close (722945c)
  • dashboard: fold the model leaderboard into the usage table (32ef3cb)
  • dashboard: full prompt playground with compare mode and presets (#99) (552ca53)
  • dashboard: generic connect instructions, official client marks, one form per profile kind (3bdc6fa)
  • dashboard: guardrail/blocked usage observability + judge dropdown filter (c2/c5) (5d1c351)
  • dashboard: health tab sortable, filterable, paginated (515cd53)
  • dashboard: kind-aware profiles list with dedicated create/edit pages (fb5c2d8)
  • dashboard: manage connection models from filtered list, drop instances page (93814b3)
  • dashboard: mcp tool-browser page + nav + mcp permissions (80966ea)
  • dashboard: merge model discovery (#81) into release/0.3.0 (6c85e51)
  • dashboard: merge model discovery page with catalog and provider filter (#81) (ec29c9d)
  • dashboard: merge provider health as tab inside models page (bfba4e3)
  • dashboard: merge provider health into the models table (7cab419)
  • dashboard: model discovery page with catalog and provider filter (#81) (bc2303c)
  • dashboard: model form binds to preconfigured or custom connection (99cac7f)
  • dashboard: model leaderboard page and /api/leaderboard endpoint (#80) (5604d90)
  • dashboard: move the mcp surface into the profile (f445661)
  • dashboard: name the nav items after what they hold (2b5af35)
  • dashboard: notification channels pages and in-app inbox (060cbf9)
  • dashboard: notification ux + ia restructure (leaderboard/health tabs) (8a71a10)
  • dashboard: notifications sub-tabs + cooldown validation + playground second token (#90 #99) (9db6c10)
  • dashboard: one chart system for the overview charts (5d7063c)
  • dashboard: one tab per profile kind, drop selector and fallback knobs (ea4a7aa)
  • dashboard: open the primary action by clicking a table row (7d5dd0a)
  • dashboard: per-project optimizer tab (0bd5556)
  • dashboard: profile/custom switch on project routing, optimizer and security tabs (83b92a2)
  • dashboard: profiles page, project assignment, simulate preview (07bc33e)
  • dashboard: rebuild the connection snippets on the project page (accf505)
  • dashboard: redesign overview page (#105) (a25d4ae), closes #66 #71 #70
  • dashboard: redirect back to origin page after login (902de8d)
  • dashboard: render scannable 2fa qr image from otpauth uri (#84) (574dc65)
  • dashboard: rework the experiments section layout (68025e8)
  • dashboard: savings on usage, positive-only savings, data-driven type filters (20ce8b2)
  • dashboard: show connections before models in nav (0f5ea9d)
  • dashboard: sortable usage + models tables, usage rank column (ecfadb4)
  • dashboard: tune optimizers against real prompts (4316ea4)
  • dashboard: use searchable select for provider, model, and connection dropdowns (d723ccd)
  • dashboard: wire provider health page and fix cli status type (#101) (95f2891)
  • embeddings: add embeddings di token and module wrapper (170579a)
  • experiments: drop the start/stop lifecycle and the declared winner (4cae99b)
  • experiments: measure each variant and score it with a judge (b2884d8)
  • experiments: richer metrics with a shared date range picker (1aef4f3)
  • gateway: enforce ttft timeout per model attempt + usage live by default (44bc376)
  • guardrails: add per-rule action override (#77 part 2) (13acab0)
  • guardrails: content guardrails + pii scrubbing, provider-faithful block wire format (e6bd0d5), closes #77 #76 76/#77
  • guardrails: full-context judging, judge token accounting, blocked-turn display (a17f598)
  • guardrails: inject scope, judge scoring, pii policy cleanup, full coverage (74c6c83)
  • guardrails: remove 'flag' action, clean up cli option (#77 part 1) (2caddad)
  • health: provider health status dashboard and api (#101) (54aebd7)
  • integrations: add metrics export integrations (#85) (7f86715)
  • mcp: add mcp sdk (mit) + shared mcp types, mcp permissions and token scopes (7dd0aff)
  • mcp: add mcp tools registry token and mcp module skeleton (2c56ac7)
  • mcp: create_project_token + toggle_model write tools behind mcp:write (no raw secret) (078c29b)
  • mcp: dedicated token page, per-client wiring guide, cursor/cline/zed (12c04fc)
  • mcp: gate tool contribution on di-token presence so a disabled module removes its tool (044daff)
  • mcp: get /api/mcp/tools management routes + mcp:read/mcp:manage permissions (8c158f5)
  • mcp: list_models read tool (secret-stripped) (c685e37)
  • mcp: make the mcp surface user-owned, permission-gated (e4965a3)
  • mcp: shared mcp server builder with scope-filtered tools/list and enforced tools/call (c328830)
  • mcp: six project-scoped read tools (model, route_preview, usage, budget, metrics, projects) (1e9176b)
  • mcp: stdio json-rpc transport gated by routerly_mcp_stdio (7011d2e)
  • mcp: streamable http transport at /mcp authenticated by project token + mcp scope (29c94c0)
  • metrics: prometheus /metrics endpoint (#93) (5380b48)
  • models: add catalog endpoint, dashboard discovery page and cli discover command (#81) (bf3128e)
  • models: add test button to models table and model edit page (37b1027)
  • modules: budget module wraps isallowed for upstream.prepare (ccd9d4c)
  • modules: cache module no-op predisposition (no response cache exists) (da8b3d8)
  • modules: guardrails module owns request+response guardrail processors (0502a09)
  • modules: logging module owns ingress+finalize trace processors (e5eae2c)
  • modules: pii module owns input+output pii processors (ef41945)
  • modules: routing module wraps routerequest + routing memory (bd86ee2)
  • modules: usage module wraps tracked usage in finalize (a957fe1)
  • modules: wire core modules into kernel (dark pipeline, routes still inline) (bc7c99b)
  • notification routing rules, cooldowns, per-project channels, model discovery (#81 #90 #91) (d97341e)
  • notifications: add a readable catalog for the event slugs (df1e614)
  • notifications: add notifications di token and module wrapper (33621d6)
  • notifications: add system.update_available event (ff72dad)
  • notifications: clicking bell popup item opens notification detail (2df72ef)
  • notifications: dashboard channel, per-channel events/targets, per-user inbox (612d6d3), closes #93
  • notifications: event taxonomy, routing rules, cooldown, inbox (#89, #90, #91) (b12b019)
  • notifications: fold events of the same trace into one incident (a09354e)
  • notifications: make the inbox readable and navigable (8cb8458)
  • notifications: native slack, teams, pagerduty, discord adapters (#88) (627ffef)
  • notifications: per-channel events routing, per-channel cooldown, budget events (#90) (441331b)
  • notifications: per-channel projects scope, 3-tab edit, remove project tab (2e83f66)
  • notifications: routing rules, cooldowns, per-project channels (#90 #91) (967ae61)
  • notifications: show a user only the inbox items they can reach (617e482)
  • observability: add observability di token and module wrapper (b00dd76)
  • observability: surface guardrail + pii evaluation in the trace (8381f21)
  • optimizers: add json-table (b9f87bb)
  • optimizers: attribute measured savings per optimizer (db4d136)
  • optimizers: back llmlingua-2 with a real tokenizer and an installable checkpoint (2c9b636)
  • optimizers: caveman lexical-compression optimizer (lossy, clean-room) (3fefcbd)
  • optimizers: ccr context-reduction optimizer (recoverable) (d3b4740)
  • optimizers: classify message content and keep caveman on prose (e356e8c)
  • optimizers: gate caveman to english so it stays inert elsewhere (10e16f6)
  • optimizers: headroom context-fit optimizer (lossless) (a82fbf0)
  • optimizers: llmlingua-2 optimizer (lossy, onnx, optional, off by default) (9841b7f)
  • optimizers: lossy safety/quality gate (9266a4a)
  • optimizers: message read/write helpers (0362509)
  • optimizers: optimizer-core module + request.preprocess processor (232401e)
  • optimizers: per-step preview text and recent traffic samples (5fb3a04)
  • optimizers: pick an llmlingua-2 checkpoint, and fixtures that actually trigger (329833b)
  • optimizers: project config crud + list + preview endpoints (ee69d7e)
  • optimizers: registry + di token (0ec0b32)
  • optimizers: relevance optimizer (lossy, gated, opt-in) (7922a6d)
  • optimizers: rtk token-compaction optimizer (recoverable) (f976443), closes modules/optimizers/README.md#rtk
  • optimizers: say why a step was skipped (628692c)
  • optimizers: session-dedup optimizer (lossless) (5c0ed88)
  • optimizers: show why a step did nothing in preview, dashboard and cli (56a5d77)
  • overview: savings over time and cross-links from the stat cards (a0b9d44)
  • overview: show what routing saved against the models in play (39cbe10)
  • pii: add multiple named pii policies per project (#76) (b4bf1b9)
  • playground: per-panel params and debug traces in compare mode (2f76e92)
  • playground: separate in/out tokens per compare panel (#99) (f867dc5)
  • playground: the turn is the card, newest first (60c3cf8)
  • process: measure where the agent time and tokens actually go (9658c87)
  • profiles: create a profile from scratch, not only by cloning (ae9189c)
  • profiles: generalize profiles to routing, optimizer and security kinds (fcd2f5f)
  • projects: ttft timeout defaults to 2s and accepts 0 to disable (141eca4)
  • provider: add list effective models as single model-list source (ab03273)
  • provider: add provider descriptor registry beside closed provider union (158431e)
  • provider: encrypted oauth credential storage + refresh (b5c4234)
  • provider: gate oauth/web connections behind module records (e3bd86c)
  • provider: opt-in encrypted web-cookie adapters, off by default (48479ae)
  • provider: register provider module in kernel bootstrap (15ed95c)
  • provider: resolve modelinstance and connection into effectivemodel (0230e59)
  • providers: activate openai-web and anthropic-web adapters (#85) (2117d6e)
  • providers: aws bedrock, azure openai, google vertex ai adapters (#87) (d948eb9)
  • providers: merge feat/issue-87-enterprise-providers into release/0.3.0 (#87) (0607e08)
  • providers: provider-native prompt caching for anthropic (#97) (dbe0121)
  • proxy: wire-faithful /v1/responses and tool calling on anthropic models (ad29b9c)
  • RA-05: publish prerelease docker image on green release branch ci (7a6073d)
  • RA-05: publish prerelease docker image on green release branch ci (9763d80)
  • RA-11: add docs deploy workflow to firebase hosting (ad35fde)
  • RA-11: add docs deploy workflow to firebase hosting (1721f29)
  • RA-12: automate promotion pipeline gated on a promoted output (79b6284)
  • RA-13: add release-abort script and workflow (6b204cd)
  • RA-13: add release-abort script to clean up abandoned rc tags (f28a47c)
  • RA-15: notify instances when a newer release is available (d0f17bc)
  • RA-16: add advisory pre-push screenshot proposal hook (bb83abb)
  • RA-16: add screenshot impact selector and mapping (f4c25c8)
  • RA-16: advise which screenshots need review on push (b33f04a)
  • RA-17: enforce measured coverage floors in ci (3e274ae)
  • ra-17: set coverage floors from measured baseline (3547288)
  • ra-17: stop neutralising coverage thresholds in ci (277e608)
  • RC-1: merge dry-runnable semantic-release engine into 0.4.0 (1930eb7)
  • RC-2: merge release-channels ci pipeline into 0.4.0 (76f8045)
  • RC-2: wire release-channels pipeline into ci (59ed2be)
  • RC-3: rename update channels to current/next with deprecated aliases (5a3d103)
  • release-pipeline: restore release-automation pipeline dropped by branch reset (959c4e4)
  • release/0.3.0: merge feat/issue-85-web-session-providers (c140688)
  • release/0.3.0: merge feat/issue-97-provider-prompt-caching (9bf7262)
  • release/0.3.0: merge usage enrichment (#94, #95, #96) (f06369e)
  • release: cut a documentation version with one command (b31cd82)
  • release: gate promotion jobs on a promoted output (9c2d76b)
  • release: generate release notes from the git history (d272936)
  • release: make the product version the single source for module manifests (1eeb309)
  • release: make the product version the single source for module manifests (8c594dc)
  • release: open a version pr on every release branch push (0258479)
  • release: render release notes from git-cliff (5dbac32)
  • release: wire release notes into the release workflow (f57e9be)
  • resilience: add cli resilience status|reset (84ddebd)
  • resilience: add dashboard resilience page (03f6079)
  • resilience: add get /api/resilience + post /api/resilience/reset (ac74b21)
  • resilience: add in-memory 3-level resilience store (4bd458a)
  • resilience: add modelconfig resilience key adapter (e5c29b3)
  • resilience: add resilience:read/manage permission chain (53d9521)
  • resilience: add upstream error classifier (eb812ed)
  • resilience: make resilience a hard routing pre-filter (fe4ec80)
  • resilience: record faults, classify ttft timeout, retire resiliencepage (25c8afb)
  • resilience: register resilience module + resilience_store token (f298400)
  • resilience: route executor failures through classifier+store, preserve events (b2b977c)
  • reverse-proxy: add proxy context types and block-aware phase runner (9e2ab57)
  • reverse-proxy: add wire-faithful helpers for plan 5 concern processors (779ad8e)
  • reverse-proxy: anthropic transport lane (upstream + attempt + egress) (6e1b4f6)
  • reverse-proxy: atomic flip routes to runproxy; delete inline handlers (pipeline live) (f413dc8)
  • reverse-proxy: openai transport lane (upstream + attempt + egress) (67e26be)
  • reverse-proxy: register transport pipeline in the module kernel (dark) (afb558c)
  • reverse-proxy: resolve effectivemodel before adapter dispatch, legacy fallback (30dd3a0)
  • routing: add fallback strategy registry (next-best/retry-after-cooldown/abort) (9da46cd)
  • routing: add immutable built-in profile presets (a140c94)
  • routing: add model-preference policy (0efd397)
  • routing: add round-robin cursor primitive to memory store (a4184b2)
  • routing: add selector registry (argmax/weighted-random/round-robin/cheapest/lowest-latency) (b1a3b54)
  • routing: per-agent routing policies via x-routerly-policy header (#78) (0b2ae69)
  • routing: profile resolution + resolve-time default-profile migration (744bc0a)
  • routing: resolve profile and apply selector; replace ad-hoc random (7219389)
  • security: content guardrails and pii scrubbing middleware (#77, #76) (b947918)
  • security: per-rule block/log guardrails + policies-only pii (99c1c5a)
  • security: remove flag action and detect injection from guardrails ui (#77) (947a2df)
  • service,dashboard,shared: oauth subscription support for anthropic-oauth and openai-oauth (5daeea5)
  • service: add get/enable/disable module management endpoints (074d6f9)
  • service: add module enable/disable registry with dependency guards (ea083be)
  • service: add the experiments management api (5f62155)
  • service: boot modular kernel and config module in server bootstrap (a55205c)
  • service: gate kernel module list on persisted module records (d22c37a)
  • service: gated get /api/clients metadata endpoint + client-configurator module (7e5631b)
  • service: guardrail observability (evaluated trace, blocked usage, budget gate) (6b0577a)
  • service: implement real bedrock converse-stream binary parser (#87) (219c3dc)
  • service: notification channels and in-app inbox endpoints (2bfa9b2)
  • service: per-model usage filters and performance metrics (989dd7f)
  • service: persist module records in modules.json (614687e)
  • service: persist user routing profiles in profiles.json (655e5a8)
  • service: prometheus metrics auth token and docker-compose integration (#93) (c0c1a89)
  • service: provider module exposes adapter behind provider registry (10f50e5)
  • service: route experiment tokens to variant projects (10c5b76)
  • service: routing-profile crud, assign, and simulate endpoints (0cfcbc9)
  • service: transparent pass-through proxy for unhandled provider endpoints (#100) (48477df)
  • service: transparent pass-through proxy for unhandled provider endpoints (#100) (#106) (eb21e43)
  • service: wire 8 missing notification events (#89) (0f25b23)
  • settings: rebuild general tab, add security tab, drop modules page (83e4737)
  • shared: add client-integration registry metadata (151b10b)
  • shared: add experiment types and the experiments permissions (fc7c611)
  • shared: add modulerecord type (7fa8f1d)
  • shared: add routing profile types + profiles permissions (c159340)
  • shared: notification channel targets + inbox per-user dismiss types (1bd943b)
  • shared: optimizer contract + per-project config types (5945439)
  • tokens: add scopes field to project token create/update (cli + dashboard + api) (2bb64a4)
  • tokens: session tracking and key-value tags on project tokens (#94, #95) (8edfdec)
  • trace: make the trace an event-driven module, with a live channel and exports (15c3e6f)
  • trace: trace every stage of the request, on two levels (8fcb195)
  • transparent anthropic pass-through for claude code compatibility (5ecded8)
  • update-checker: emit system.update_available on new release, deduplicated (ef230c5)
  • usage: add the savings and counterfactual layer (95271ac)
  • usage: name the token a call came in on, and retire end users (f0121bc)
  • usage: per-end-user tracking, session tracking, tag-based attribution (#96, #94, #95) (5a65338)
  • usage: readable call log, caller filter on the cli, usage docs (0eef761)
  • usage: record and filter the request type of every call (e867853)
  • users: add reset 2fa button in admin users list (#84) (c66eb04)

Bug Fixes

  • agents: correct tester subagent model id (oppus typo -> opus) (c40aeb9)
  • api: correct model-connection credential handling and rebinding (f55e522)
  • api: redact all connection credentials from model responses (1623801)
  • catalog: carry model overrides through instances and write sync results back (8fe94d8)
  • catalog: last repo in list overrides earlier ones on key conflict (ee39f97)
  • catalog: track content-change timestamp separately from last-check (f6b16d8)
  • catalog: use upstream timestamp from index.json as content-change date (1c96b75)
  • catalog: validate explicit provider against connection on import (754dea3)
  • ci: keep the newest docker tag from moving on old-version rebuilds (9aa96a5)
  • ci: make the docs-version suite pass on a checkout that never installed website/ (846fa3e)
  • ci: push develop tag by refspec to avoid ambiguity with branch name (0e655ec)
  • claude: repair agent-cost.mjs and require live third-party checks (95b1c11)
  • cli: add email provider channel creation for dashboard parity (2f4b186)
  • cli: correct mode preservation, error handling, and integrity in safe-file (f5ea888)
  • cli: default new config files to 0600, not 0644 (2c5ce1e)
  • cli: drop unused fs import in safe-file helper (120fd44)
  • clients: remove em dashes and harden anthropic snippet regression test (c2cd26f)
  • cli: guardrail/blocked breakdown in report usage, free/local model label (6d5846a)
  • cli: honest cline config-kind and correct stale continue.md docs (169d3ee)
  • cli: opencode em dashes and routing sentinel model id (803d4e5)
  • cli: strip credentials from connections --json, document connections command (d80afa0)
  • cli: surface /mcp http error message and propagate serve exit code (e69abd3)
  • connections: drop '(migrated)' suffix from connection labels (50ccd5a)
  • core: honor intra-phase shortcircuit in processor registry (0d7e6d6)
  • core: remove em dash from sdk.ts doc comment (0887987)
  • correct the playwright-mcp gitignore entry (dd2ac05)
  • dashboard,cli: guard null cost in usage page, fix leaderboard field names (e30fc8d)
  • dashboard: align optimizer threshold controls, define --surface-active (153a746)
  • dashboard: allow timeframe selection in live mode (4de2092)
  • dashboard: buffer playground sse across chunk boundaries (df76df5)
  • dashboard: clients page cline text, em dashes, feature-detect error handling (56a0cc8)
  • dashboard: correct swapped rtk/headroom klass labels in optimizer tab (40fbe56)
  • dashboard: gate write affordances behind their permission (c13103a)
  • dashboard: honor discovered model in add form (#81) (65fe2fa)
  • dashboard: move usage refresh controls out of subtitle paragraph (7f66244)
  • dashboard: notification dropdown z-index and 2fa ux improvements (838eb1c)
  • dashboard: prefill model form from discovery provider and model id params (#81) (805eceb)
  • dashboard: prevent login redirect loop and double-encoded to param (a56910f)
  • dashboard: redirect legacy /dashboard/instances to the models list (0206087)
  • dashboard: remember the period picked on the overview (13cc7f8)
  • dashboard: resolve usage provider column from configured models (6588c5f)
  • dashboard: restore accessible naming and keyboard operation for searchable selects (31203e1)
  • dashboard: restore dropped credential-preservation and non-error rejection tests (0cee04b)
  • dashboard: scale cost axis ticks to the values plotted (d1fffe4)
  • dashboard: show only the table on experiment metrics (5653b7a)
  • dashboard: translate date range picker to english (88a6792)
  • dashboard: translate time inputs and follow page theme (5df8955)
  • dashboard: typescript strict errors in test files (6c1a394)
  • deps: clear every high advisory that has an upstream fix (fe9d4ad)
  • deps: resolve npm audit high-severity vulnerabilities (d36b098)
  • docker: stop docker-rebuild from moving :latest onto an old release (f649718)
  • docs+cli+dashboard: remove em dashes in client-configurator code comments (6da2cf6)
  • docs: copy docs/assets into versioned snapshots (1d16aab)
  • docs: correct clients configure permission claim (c0e1848)
  • docs: correct docs-versioning to match the release channel model (765af03)
  • docs: escape mdx angle brackets in models.md filter descriptions (bab33b0)
  • docs: remove em dashes from client configurator docs (1f35ad3)
  • gemini: strip provider prefix from model id before upstream call (#115) (bc1cf93)
  • guardrails: trace header on block, budget-exceeded 429, streaming block wire parity (a4b47d6)
  • health: compute p95 latency over 1h window instead of 5m (6687bca)
  • mcp: drop fabricated enabled field, remove vitest from shipped helper (4eb6d67)
  • mcp: remove em dash and stale enabled-field mention in read.ts comment (4d73568)
  • mcp: remove em dash in expectnosecrets ponytail comment (592ce2b)
  • mcp: thread scopes through cli token auto-mint; remove em dash in mcp page (f9e1545)
  • models: use flaskconical icon for test button, consistent with rest of ui (c646ad5)
  • oauth: resolve static bearer for legacy migrated oauth connections (3c832a0)
  • optimizers: ccr keeps anthropic tool pairs atomic, no consecutive user msgs (f1f79ca)
  • optimizers: ccr window 3 by default, relevance falls back to 0.1 (310efee)
  • optimizers: correct caveman threshold docs, remove em dashes (5327932)
  • optimizers: correct fixture counts and preview's unnamed model (8af75d8)
  • optimizers: derive the api optimizer id enum from the catalog (12caeea)
  • optimizers: make headroom fire (f3838ec)
  • optimizers: one token estimator for every step (783d86d)
  • optimizers: per-optimizer threshold range instead of uniform 0-1 (585091f)
  • optimizers: score llmlingua-2 in encoder windows, not one throwing pass (e091538)
  • optimizers: stop caveman eating file paths and dotted identifiers (338a0e9)
  • optimizers: structure-aware session-dedup key (no multimodal/tool-call loss) (c4bf502)
  • provider: encrypt oauth/web credentials on connection create/update (b46acfd)
  • provider: gate oauth resolve on provider-oauth module (bbeb3c4)
  • provider: guard oauth refresh against unknown expiry + malformed credentials (55ec324)
  • providers/custom: replace openai sdk with raw fetch for wire-format transparency (21df1af), closes #109
  • RA-13: use Bearer auth scheme for Docker Hub API calls (239d891)
  • RA-16: stop double-printing git's stderr on an invalid range (a8313f4)
  • RC-1: repair notes parity and add make_latest on promotion (91ed70d)
  • RC-1: repair notes parity and add make_latest on promotion (8c6509e)
  • RC-3: rename update channels to current/next with deprecated aliases (6aa9598)
  • RC-4: merge deprecated-channel deprecation hint into 0.4.0 (0cb74ee)
  • RC-4: source deprecation hint from raw stored channel, not the normalised one (04582ff)
  • release: anchor the commit parsers to real conventional-commit syntax (e98d5d4)
  • release: keep release-notes.sh to its one-line error contract (d2671ab)
  • release: make screenshot capture deterministic (c234e96)
  • remove remaining em dashes flagged by final branch review (38453ab)
  • resilience: add cli docs, drop dead cast (8461dc9)
  • resilience: add record-success signal, remove incorrect half-open recovery heuristic (4c2cd26)
  • resilience: clarify elapsed-time call-site comment (5735ac1)
  • resilience: declare routing's dependency on resilience module to fix registration order (00d20cf)
  • resilience: key the connection breaker on the real connectionid (ea041a8)
  • resilience: reject partial level/id reset body, address review nits (457b4c3)
  • resolve pre-existing test failures and oauth body-parse crash (daf69e0)
  • reverse-proxy: anthropic egress: no trace header on block results that never carried it (c72fdbe)
  • reverse-proxy: block results must still reach the egress phase (7ecea8e)
  • reverse-proxy: make guardrail injection merge idempotent across fallback (0c4b034)
  • reverse-proxy: merge guardrail steering injection into upstream request (c98638c)
  • reverse-proxy: openai egress must not add trace header on block results that never carried it (3fad71f)
  • reverse-proxy: satisfy exactoptionalpropertytypes for attemptresponse assignment (2ecc220)
  • reverse-proxy: use reply.status() consistently in anthropic egress (727c12c)
  • routing/semantic-intent: look up embedding credentials from model registry (dcd9e3c), closes #112
  • routing/semantic-intent: use resolvedcfg.embedding_endpoint in trackusage (d441afc), closes #109 #112
  • routing: fix fairness policy bugs and add oauth usage tracking (183d32d)
  • screenshots: make the capture deterministic and every output distinct (5bd0a9e)
  • screenshots: settle on the page's own loading state, not the request count (6b27edd)
  • scripts: stop capacity.sh crashing when no story is in flight (c5ae7b6)
  • service: enforce notification:write, scope test inbox item, bound ids, harden ssrf (a437c32)
  • service: exclude blocked records from leaderboard and routing health (280720d)
  • service: honor x-forwarded-proto/host for /api/clients base url (b27592e)
  • service: honour x-routerly-no-trace header to suppress sse trace events (#110) (103fb82)
  • service: honour x-routerly-no-trace header to suppress sse trace events (#110) (70f5f18)
  • service: isolate simulate cursor state, validate profile assignment, fix ranked order (bf1062a)
  • service: make config writes atomic and stop reads from persisting an empty default (5108d71)
  • service: restore leaderboard api and cli command (#80) (5433105), closes #82
  • service: widen config write lock retry budget (4a918d4)
  • settings: accept extra fields in notifications config (758cd1a)
  • shared: mark codex client as auto-configurable (e9a5482)
  • telemetry: async ping with retry logic, dedup install, skip tracking in tests (1ca58a4)
  • trace: store the whole trace on the usage record (5f14cbe)
  • update-checker: extract semver from release name for rolling channels (develop/stable) (430f1bd)

Documentation

  • 0.3.0: guardrail observability, blocked usage, cli breakdown, 2fa qr, model prefill (e85f070)
  • 0.3.0: notification rework, dashboard ia, guardrail wire, x-api-key auth (c81dfe1)
  • 0.4.0 modular-kernel refactory plan set (effe797)
  • add light-mode screenshots to all dashboard pages and key getting-started docs (91abd97)
  • add step 0 modular restructure overview and detailed execution plan (d6522d9)
  • add step 10 modular restructure plan (cdfbfa0)
  • add step 11 modular restructure plan (ddac5d1)
  • add step 12 modular restructure plan (597624f)
  • add step 13 modular restructure plan (a572e21)
  • add step 14 modular restructure plan (7684b2b)
  • add step 15 modular restructure plan (a975909)
  • add step 16 bootstrap extraction plan (b9a85cb)
  • add step 2 lib extraction execution plan (5d79fa9)
  • add step 3 config module extraction execution plan (dc42359)
  • add step 5 catalog extraction plan (59b03da)
  • add step 6 embeddings extraction plan (f456b58)
  • add step 7 budget/usage extraction plan (533d139)
  • add step 8 and step 9 modular restructure plans (f0c93d4)
  • bump version label to 0.3.0, add 0.2.0 to version picker (8906d0f)
  • changelog: correct 0.4.0 phase-list accuracy (91e170b)
  • claude: extract feature-lifecycle mechanics into a lazy-loaded skill (8edd4e0)
  • client configurator (cli + dashboard + per-client manual guides) (e352a2d)
  • config: set 0.2.0 as default docusaurus version (#70) (64bb088)
  • connect: document the connect section and every registry client (9fce5bf)
  • connections + model instances api and dashboard reference (5be12dc)
  • connections cutover and model-connection binding (c0198f4)
  • correct modules dependson type, enable 409s, dashboard rbac (bc816ba)
  • correct project, budget and proxy pages against the current surfaces (33c963a)
  • cut the real 0.3.0 documentation snapshot from develop (aa688d3)
  • dashboard: add discovery and 2fa screenshots, refresh #81 behavior (fc469d2)
  • dashboard: add end-users tab documentation (#96) (4220f2f)
  • dashboard: renumber sidebar_position to make room for connections page (9ab7fac)
  • document routerly report savings (f840c9a)
  • document experiments across concepts, dashboard, cli and api (b28b64b)
  • document merged models-health and usage-leaderboard tables (2327185)
  • document modules feature (api, cli, dashboard) (6bcc544)
  • experiments: state that judge score ignores the metrics window (f52c1d5)
  • fix em dash and false model:read auth claim in connections docs (223b5c0)
  • guides: add web session provider guides and cli cf-clearance flag (#85) (c1b085a)
  • mcp: document mcp server transports, scopes, tools, and surfaces (2038b99)
  • mcp: document the personal mcp surface and client wiring (66f4776)
  • notifications: correct dismiss endpoint, drop false admin global-delete claim (b705419)
  • notifications: document channels, in-app inbox, unread, per-user delete (8c0657f)
  • notifications: document the readable inbox across surfaces (10717f6)
  • notifications: routing rules, cooldowns, per-project channels, model discovery (#81 #90 #91) (265f6f4)
  • observability: document guardrail:evaluated + pii:evaluated trace entries (0d67da1)
  • optimizers: document llmlingua-2 windowing and the grow-back rollback (fc37cc6)
  • optimizers: document the overhauled optimizer surface (52b0640)
  • optimizers: document threshold semantics, traffic samples and per-step diffs (0c98d1d)
  • optimizers: usage, api reference, provenance and licensing (6f2d8e6)
  • overview: document the savings series across dashboard, cli and api (e1e659c)
  • process: three edits the cost measurement forced (d484ada)
  • profiles: document the three profile kinds across dashboard, cli and api (5e9afe3)
  • RA-10: backfill 0.4.0 as a versioned docs snapshot (b2a8421)
  • RA-10: cut documentation version 0.4.0 (3a60fd3)
  • RA-16: add screenshot-review skill for judgement layer (c979525)
  • RA-16: document the screenshot impact layer (2fbbd53)
  • RA-18: document the release pipeline in-repo (75a2e03)
  • RA-18: document the release pipeline in-repo (c550955)
  • RC-6: deletion sweep, anchor repair and page verification (fe0de9e)
  • RC-6: merge release process documentation into 0.4.0 (663aa3a)
  • RC-6: rewrite branches/channels and promotion model (08d3b80)
  • RC-6: rewrite contributor protocol around conventional commits (6e879df)
  • RC-6: rewrite credentials and failure-path sections (c5da4f5)
  • readme: update for shipped notifications, fix broken links, add playground screenshot (36a017b)
  • release: add release notes and update progress for 0.3.0 (36890c3)
  • release: document module version sync and --check (52e7d0d)
  • release: document the docker rebuild workflow (fe33ff2)
  • release: document the Docker Rebuild workflow (dd5c17c)
  • release: explain changesets and the version pr (c710b14)
  • release: fold the maintainer procedure into one page (41bf2cd)
  • releasing: document generated release notes (6ab0426)
  • remove completed superpowers refactory plans (abfbd98)
  • repair three cross-reference anchors (9cfad4c)
  • routing: document routing profiles across api, dashboard, and concepts (1b49cf3)
  • screenshots: explain the full reproducibility mechanism, not just the fixed port (1c2b5de)
  • step 4 provider extraction execution plan (575df31)
  • trace: correct the phase list and what pii:evaluated counts (efa1452)
  • update usage page screenshot and document telemetry env vars (449cfce)
  • update-checker: document the system.update_available alert (cb9cac6)
  • workflow: correct the user-check gate to feature level, not per story (247d2fa)
  • workflow: gate qa/docs/merge behind a user-check, not auto-run (8d53abf)

Refactor

  • api-reverse-proxy: move routes/openai,anthropic,passthrough into modules/ (d8188e2)
  • api-reverse-proxy: repoint external consumers to modules/api-reverse-proxy/ (105a129)
  • api: move routes/api.ts into modules/api/ (da61d70)
  • api: repoint external consumers to modules/api/ (97022cb)
  • audit: move audit/logger into modules/audit/ (f354d7e)
  • audit: repoint external consumers to modules/audit/ (0439b4e)
  • auth: move auth/ and plugins/jwt+auth into modules/auth/ (11944c2)
  • auth: repoint external consumers to modules/auth/ (53f3b33)
  • budget,usage: move budget/tracker/usagestore into modules/ (e6aa71d)
  • budget,usage: move module wrappers to index.ts, fix token paths (0cd6f3e)
  • budget,usage: repoint external consumers to modules/ (3a82ee0)
  • catalog: move fetcher/sync into modules/catalog/ (e3ca5af)
  • catalog: repoint external consumers to modules/catalog/ (41001e1)
  • config: move loader and migrate into modules/config (1f873f6)
  • config: repoint all consumers to modules/config (3966f00)
  • core: rebase processorregistry onto alterableregistry, add per-processor override (c016582)
  • core: reorganize core/ into container, modules, events, pipeline, lifecycle subfolders (9af3584)
  • cost: route executor cost through calculatecost (dedup, cache-creation aware) (d228a33)
  • cost: unify usage.json scans onto readusagerecords (dedup) (b9765e8)
  • dashboard: extract reusable connectionform component (1153ce2)
  • dashboard: remove health columns from models tab, health tab only (b741bd9)
  • embeddings: move dispatcher/openai/ollama into modules/embeddings/ (17395dc)
  • embeddings: repoint external consumers to modules/embeddings/ (8c599ed)
  • guardrails,pii: absorb flat module wrappers into module dirs (1361dfd)
  • guardrails: move middleware/guardrails.ts into modules/guardrails/ (60c4258)
  • lib: extract calculatecost into lib/cost.ts (bf12ec8)
  • lib: extract config_paths into lib/paths.ts (14681b4)
  • logging: absorb flat module wrapper into modules/logging/ (277256e)
  • logging: move routing tracestore into modules/logging/ (e33ff97)
  • logging: repoint external consumers to modules/logging/tracestore (1f8a633)
  • notifications: move notifications/ into modules/notifications/ (c1be654)
  • notifications: repoint external consumers to modules/notifications/ (9095f0f)
  • observability: move integrations/ into modules/observability/ (bb5a1d0)
  • observability: repoint external consumers to modules/observability/ (1c179e3)
  • pii: move middleware piiscrubber into modules/pii/ (71456ee)
  • profiles: remove the built-in security presets (489e610)
  • provider: add registry.ts hook-based dispatcher (7ad35e5)
  • provider: hook-based dispatch via alterableregistry (11a956b)
  • provider: move adapter files into modules/provider/ (a823d0b)
  • provider: repoint consumers at modules/provider/registry.js (53010c8)
  • reverse-proxy: loadeffectivemodel resolves only via instances (12b2b00)
  • reverse-proxy: move llm/executor.ts and reverse-proxy/ into modules/reverse-proxy/ (90cc1ad)
  • reverse-proxy: repoint external consumers to modules/reverse-proxy/ (6b0f083)
  • routing: fix module wrapper and consumer import paths (f8c5e0c)
  • routing: move module wrapper to index.ts, fix token/consumer paths (6e54a92)
  • routing: move router, policies, intent into modules/routing/ (2a1d86e)
  • routing: remove dead selectmodel path (grep-gated, zero callers) (a726bd1)
  • service: dissolve routes/ into modules/observability and modules/reverse-proxy/lanes (c24b867)
  • service: extract bootstrap/ module-array assembly from server.ts (642e972)
  • service: move telemetry and update-checker into modules/ (25f9b51)
  • service: reuse p95 helper, cover unknown usage filters (4cefcd0)
  • service: route all model-list reads through listeffectivemodels (b079940)
  • settings: expose listening addresses, drop the global timeout (11d4cd8)