v0.3.0
Pre-release
Pre-release
·
113 commits
to develop
since this release
0.3.0 (2026-08-06)
Features
- add anthropic streaming support; fix oauth model id forwarding (a076266)
- add modules:read and modules:manage permissions across the chain (df169be)
- api-reverse-proxy: add api_reverse_proxy di token and module wrapper (cc4f6cf)
- api: add api_routes di token exposing the route-contribution hook (590815a)
- api: connections + instances crud and descriptors list (1ff3d5e)
- api: model crud operates on instances and connections (10d7f26)
- api: require model:read permission for get /api/models (8114934)
- api: wire route-contribution registry into the api plugin (bb4b1c2)
- audit: add audit di token and module wrapper (14fa3f0)
- auth: 2fa totp enrollment and login verification (#84) (64f7650)
- auth: add auth di token and module wrapper (f37c0a3)
- auth: add connections:read/connections:manage permission chain (a3ab4ee)
- auth: add optimizers:read/manage permissions (2a4fa18)
- auth: merge feat/issue-84-2fa-totp into release/0.3.0 (#84) (b51cc57)
- auth: persist requiremfa setting and add 2fa blocking redirect (#84) (351fcbd)
- budget: hierarchical spend limits org/team/key cascade (#82) (3c0e066)
- cache: semantic response caching for non-streaming llm requests (#75) (3146694)
- catalog: add catalog di token and module wrapper (7688656)
- catalog: dynamic provider catalog from configurable git repositories (25cb42c), closes #114
- catalog: merge feature/114-dynamic-provider-catalog into release/0.3.0 (42711db)
- catalog: repeatable per-provider instance import script (5fabd25)
- ci: make promote-stable a reusable workflow with explicit source-image check (9f8b43d)
- ci: publish versioned tag from develop promotion (3bd2616)
- ci: publish versioned tag from develop promotion (ff08c07)
- ci: run full test suite on release branches (b447227)
- ci: run full test suite on release branches (ea06466)
- claude code integration via routerly transparent proxy (ed026e1)
- claude: add a docs-writer agent to the chain (9d69e80)
- cli: add
report savingssubcommand (42d340d) - cli: add cli coverage for all 0.3.0 features (a3fa0f0)
- cli: add routerly modules list/enable/disable command (2f603a5)
- cli: add routerly profiles list/show/clone/set (11e090d)
- cli: add the experiments command group (627fbc2)
- cli: bind models to preconfigured connections (741ea23)
- cli: claude code client integration (fba5d5f)
- cli: client-integration contract + token acquisition (0231a5f)
- cli: codex client integration (a2d90ce)
- cli: continue client integration + cline documented entry (1ba1d13)
- cli: cover the whole client registry, manual steps included (88d1627)
- cli: describe optimizer thresholds, list captured prompts, replay them in preview (6ae1ccd)
- cli: drive mcp from personal tokens (aa36281)
- clients: extend the client registry with connect modes and mcp snippets (80be733)
- cli: match the readable inbox on the command line (33565f5)
- cli: notification inbox and channel commands (2b32ee5)
- cli: opencode client integration (d95dc06)
- cli: optimizers list/config/preview commands (571d5ab)
- cli: profiles command for routing, optimizer and security kinds (14ff9da)
- cli: routerly clients list|inspect|configure|doctor|undo|launch (b8f4f4a)
- cli: routerly connections list|add|remove + models connection column (7aa2f7f)
- cli: routerly mcp tools|test|serve (05d04a9)
- cli: safe file-transaction helper (backup+checksum+atomic+rollback) (aa3e735)
- config: add updateAnnouncement to the config store (2fcf30d)
- config: config module exposes loader behind config store (61ba575)
- config: one-shot idempotent models.json to connections+instances migration (9eb94e4)
- config: persist provider connections and model instances sections (78f44d6)
- connections: provider defaults and custom upstream provider (a23bfc0)
- connections: provider-aware credential parity across service, cli, dashboard (1e96ef6)
- connections: unique generated names and a one-click provider picker (7956fd4)
- connect: official brand marks and a guided client grid (77ece69)
- core: add alterableregistry generic hook-ordered contribution registry (b2360f2)
- core: add alterableregistry get(id) lookup (2a42dab)
- core: add routecontribution and createrouteregistry for future route-hook modules (11bed93)
- core: add servicecontainer.override for service decoration (572175b)
- core: build kernel bootstrap seam (69cdad8)
- core: dependency graph topological sort (bece08d)
- core: expose alterableregistry and route-contribution hooks via core barrels (ae784ac)
- core: frozen di service tokens (db83e2d)
- core: inert contrib module registration seam (06a12d6)
- core: let modules own their config migrations (33bb936)
- core: module kernel lifecycle runner (85831d6)
- core: module manifest and definemodule (d9bd318)
- core: phase-scoped processor dag (74ae56b)
- core: public barrel export for modular kernel (f398d1b)
- core: public module sdk authoring barrel (b42b09c)
- core: result and kernel error primitives (c12c67f)
- core: surface/metamodule contract stub (types-only) (48797cb)
- core: typed service container (3e9180d)
- dashboard: add end-users tab to project detail page (#96) (697bb1d)
- dashboard: add end-users tab to project detail page (#96) (c97ae4d)
- dashboard: add label for system.update_available event (4ea5515)
- dashboard: add settings > modules tab with enable/disable toggles (764c59b)
- dashboard: add the project dashboard tab (0c95bca)
- dashboard: clickable project rows + multi-endpoint connection info (dbb6ae3)
- dashboard: clients discovery page (fd98d02)
- dashboard: connect section with a page per client (cd21174)
- dashboard: connect shortcut card on the overview page (7cb1033)
- dashboard: connections + model instances pages (161643a)
- dashboard: convert remaining native selects to searchable select (c32336d)
- dashboard: curate the server info block and flatten the sidebar order (5e751a8)
- dashboard: dedicated connection create/edit pages (c7c7c72)
- dashboard: download and pick the llmlingua-2 checkpoint from its own row (0a2e2a1)
- dashboard: experiments section with metrics and manual close (722945c)
- dashboard: fold the model leaderboard into the usage table (32ef3cb)
- dashboard: full prompt playground with compare mode and presets (#99) (552ca53)
- dashboard: generic connect instructions, official client marks, one form per profile kind (3bdc6fa)
- dashboard: guardrail/blocked usage observability + judge dropdown filter (c2/c5) (5d1c351)
- dashboard: health tab sortable, filterable, paginated (515cd53)
- dashboard: kind-aware profiles list with dedicated create/edit pages (fb5c2d8)
- dashboard: manage connection models from filtered list, drop instances page (93814b3)
- dashboard: mcp tool-browser page + nav + mcp permissions (80966ea)
- dashboard: merge model discovery (#81) into release/0.3.0 (6c85e51)
- dashboard: merge model discovery page with catalog and provider filter (#81) (ec29c9d)
- dashboard: merge provider health as tab inside models page (bfba4e3)
- dashboard: merge provider health into the models table (7cab419)
- dashboard: model discovery page with catalog and provider filter (#81) (bc2303c)
- dashboard: model form binds to preconfigured or custom connection (99cac7f)
- dashboard: model leaderboard page and /api/leaderboard endpoint (#80) (5604d90)
- dashboard: move the mcp surface into the profile (f445661)
- dashboard: name the nav items after what they hold (2b5af35)
- dashboard: notification channels pages and in-app inbox (060cbf9)
- dashboard: notification ux + ia restructure (leaderboard/health tabs) (8a71a10)
- dashboard: notifications sub-tabs + cooldown validation + playground second token (#90 #99) (9db6c10)
- dashboard: one chart system for the overview charts (5d7063c)
- dashboard: one tab per profile kind, drop selector and fallback knobs (ea4a7aa)
- dashboard: open the primary action by clicking a table row (7d5dd0a)
- dashboard: per-project optimizer tab (0bd5556)
- dashboard: profile/custom switch on project routing, optimizer and security tabs (83b92a2)
- dashboard: profiles page, project assignment, simulate preview (07bc33e)
- dashboard: rebuild the connection snippets on the project page (accf505)
- dashboard: redesign overview page (#105) (a25d4ae), closes #66 #71 #70
- dashboard: redirect back to origin page after login (902de8d)
- dashboard: render scannable 2fa qr image from otpauth uri (#84) (574dc65)
- dashboard: rework the experiments section layout (68025e8)
- dashboard: savings on usage, positive-only savings, data-driven type filters (20ce8b2)
- dashboard: show connections before models in nav (0f5ea9d)
- dashboard: sortable usage + models tables, usage rank column (ecfadb4)
- dashboard: tune optimizers against real prompts (4316ea4)
- dashboard: use searchable select for provider, model, and connection dropdowns (d723ccd)
- dashboard: wire provider health page and fix cli status type (#101) (95f2891)
- embeddings: add embeddings di token and module wrapper (170579a)
- experiments: drop the start/stop lifecycle and the declared winner (4cae99b)
- experiments: measure each variant and score it with a judge (b2884d8)
- experiments: richer metrics with a shared date range picker (1aef4f3)
- gateway: enforce ttft timeout per model attempt + usage live by default (44bc376)
- guardrails: add per-rule action override (#77 part 2) (13acab0)
- guardrails: content guardrails + pii scrubbing, provider-faithful block wire format (e6bd0d5), closes #77 #76 76/#77
- guardrails: full-context judging, judge token accounting, blocked-turn display (a17f598)
- guardrails: inject scope, judge scoring, pii policy cleanup, full coverage (74c6c83)
- guardrails: remove 'flag' action, clean up cli option (#77 part 1) (2caddad)
- health: provider health status dashboard and api (#101) (54aebd7)
- integrations: add metrics export integrations (#85) (7f86715)
- mcp: add mcp sdk (mit) + shared mcp types, mcp permissions and token scopes (7dd0aff)
- mcp: add mcp tools registry token and mcp module skeleton (2c56ac7)
- mcp: create_project_token + toggle_model write tools behind mcp:write (no raw secret) (078c29b)
- mcp: dedicated token page, per-client wiring guide, cursor/cline/zed (12c04fc)
- mcp: gate tool contribution on di-token presence so a disabled module removes its tool (044daff)
- mcp: get /api/mcp/tools management routes + mcp:read/mcp:manage permissions (8c158f5)
- mcp: list_models read tool (secret-stripped) (c685e37)
- mcp: make the mcp surface user-owned, permission-gated (e4965a3)
- mcp: shared mcp server builder with scope-filtered tools/list and enforced tools/call (c328830)
- mcp: six project-scoped read tools (model, route_preview, usage, budget, metrics, projects) (1e9176b)
- mcp: stdio json-rpc transport gated by routerly_mcp_stdio (7011d2e)
- mcp: streamable http transport at /mcp authenticated by project token + mcp scope (29c94c0)
- metrics: prometheus /metrics endpoint (#93) (5380b48)
- models: add catalog endpoint, dashboard discovery page and cli discover command (#81) (bf3128e)
- models: add test button to models table and model edit page (37b1027)
- modules: budget module wraps isallowed for upstream.prepare (ccd9d4c)
- modules: cache module no-op predisposition (no response cache exists) (da8b3d8)
- modules: guardrails module owns request+response guardrail processors (0502a09)
- modules: logging module owns ingress+finalize trace processors (e5eae2c)
- modules: pii module owns input+output pii processors (ef41945)
- modules: routing module wraps routerequest + routing memory (bd86ee2)
- modules: usage module wraps tracked usage in finalize (a957fe1)
- modules: wire core modules into kernel (dark pipeline, routes still inline) (bc7c99b)
- notification routing rules, cooldowns, per-project channels, model discovery (#81 #90 #91) (d97341e)
- notifications: add a readable catalog for the event slugs (df1e614)
- notifications: add notifications di token and module wrapper (33621d6)
- notifications: add system.update_available event (ff72dad)
- notifications: clicking bell popup item opens notification detail (2df72ef)
- notifications: dashboard channel, per-channel events/targets, per-user inbox (612d6d3), closes #93
- notifications: event taxonomy, routing rules, cooldown, inbox (#89, #90, #91) (b12b019)
- notifications: fold events of the same trace into one incident (a09354e)
- notifications: make the inbox readable and navigable (8cb8458)
- notifications: native slack, teams, pagerduty, discord adapters (#88) (627ffef)
- notifications: per-channel events routing, per-channel cooldown, budget events (#90) (441331b)
- notifications: per-channel projects scope, 3-tab edit, remove project tab (2e83f66)
- notifications: routing rules, cooldowns, per-project channels (#90 #91) (967ae61)
- notifications: show a user only the inbox items they can reach (617e482)
- observability: add observability di token and module wrapper (b00dd76)
- observability: surface guardrail + pii evaluation in the trace (8381f21)
- optimizers: add json-table (b9f87bb)
- optimizers: attribute measured savings per optimizer (db4d136)
- optimizers: back llmlingua-2 with a real tokenizer and an installable checkpoint (2c9b636)
- optimizers: caveman lexical-compression optimizer (lossy, clean-room) (3fefcbd)
- optimizers: ccr context-reduction optimizer (recoverable) (d3b4740)
- optimizers: classify message content and keep caveman on prose (e356e8c)
- optimizers: gate caveman to english so it stays inert elsewhere (10e16f6)
- optimizers: headroom context-fit optimizer (lossless) (a82fbf0)
- optimizers: llmlingua-2 optimizer (lossy, onnx, optional, off by default) (9841b7f)
- optimizers: lossy safety/quality gate (9266a4a)
- optimizers: message read/write helpers (0362509)
- optimizers: optimizer-core module + request.preprocess processor (232401e)
- optimizers: per-step preview text and recent traffic samples (5fb3a04)
- optimizers: pick an llmlingua-2 checkpoint, and fixtures that actually trigger (329833b)
- optimizers: project config crud + list + preview endpoints (ee69d7e)
- optimizers: registry + di token (0ec0b32)
- optimizers: relevance optimizer (lossy, gated, opt-in) (7922a6d)
- optimizers: rtk token-compaction optimizer (recoverable) (f976443), closes modules/optimizers/README.md#rtk
- optimizers: say why a step was skipped (628692c)
- optimizers: session-dedup optimizer (lossless) (5c0ed88)
- optimizers: show why a step did nothing in preview, dashboard and cli (56a5d77)
- overview: savings over time and cross-links from the stat cards (a0b9d44)
- overview: show what routing saved against the models in play (39cbe10)
- pii: add multiple named pii policies per project (#76) (b4bf1b9)
- playground: per-panel params and debug traces in compare mode (2f76e92)
- playground: separate in/out tokens per compare panel (#99) (f867dc5)
- playground: the turn is the card, newest first (60c3cf8)
- process: measure where the agent time and tokens actually go (9658c87)
- profiles: create a profile from scratch, not only by cloning (ae9189c)
- profiles: generalize profiles to routing, optimizer and security kinds (fcd2f5f)
- projects: ttft timeout defaults to 2s and accepts 0 to disable (141eca4)
- provider: add list effective models as single model-list source (ab03273)
- provider: add provider descriptor registry beside closed provider union (158431e)
- provider: encrypted oauth credential storage + refresh (b5c4234)
- provider: gate oauth/web connections behind module records (e3bd86c)
- provider: opt-in encrypted web-cookie adapters, off by default (48479ae)
- provider: register provider module in kernel bootstrap (15ed95c)
- provider: resolve modelinstance and connection into effectivemodel (0230e59)
- providers: activate openai-web and anthropic-web adapters (#85) (2117d6e)
- providers: aws bedrock, azure openai, google vertex ai adapters (#87) (d948eb9)
- providers: merge feat/issue-87-enterprise-providers into release/0.3.0 (#87) (0607e08)
- providers: provider-native prompt caching for anthropic (#97) (dbe0121)
- proxy: wire-faithful /v1/responses and tool calling on anthropic models (ad29b9c)
- RA-05: publish prerelease docker image on green release branch ci (7a6073d)
- RA-05: publish prerelease docker image on green release branch ci (9763d80)
- RA-11: add docs deploy workflow to firebase hosting (ad35fde)
- RA-11: add docs deploy workflow to firebase hosting (1721f29)
- RA-12: automate promotion pipeline gated on a promoted output (79b6284)
- RA-13: add release-abort script and workflow (6b204cd)
- RA-13: add release-abort script to clean up abandoned rc tags (f28a47c)
- RA-15: notify instances when a newer release is available (d0f17bc)
- RA-16: add advisory pre-push screenshot proposal hook (bb83abb)
- RA-16: add screenshot impact selector and mapping (f4c25c8)
- RA-16: advise which screenshots need review on push (b33f04a)
- RA-17: enforce measured coverage floors in ci (3e274ae)
- ra-17: set coverage floors from measured baseline (3547288)
- ra-17: stop neutralising coverage thresholds in ci (277e608)
- RC-1: merge dry-runnable semantic-release engine into 0.4.0 (1930eb7)
- RC-2: merge release-channels ci pipeline into 0.4.0 (76f8045)
- RC-2: wire release-channels pipeline into ci (59ed2be)
- RC-3: rename update channels to current/next with deprecated aliases (5a3d103)
- release-pipeline: restore release-automation pipeline dropped by branch reset (959c4e4)
- release/0.3.0: merge feat/issue-85-web-session-providers (c140688)
- release/0.3.0: merge feat/issue-97-provider-prompt-caching (9bf7262)
- release/0.3.0: merge usage enrichment (#94, #95, #96) (f06369e)
- release: cut a documentation version with one command (b31cd82)
- release: gate promotion jobs on a promoted output (9c2d76b)
- release: generate release notes from the git history (d272936)
- release: make the product version the single source for module manifests (1eeb309)
- release: make the product version the single source for module manifests (8c594dc)
- release: open a version pr on every release branch push (0258479)
- release: render release notes from git-cliff (5dbac32)
- release: wire release notes into the release workflow (f57e9be)
- resilience: add cli resilience status|reset (84ddebd)
- resilience: add dashboard resilience page (03f6079)
- resilience: add get /api/resilience + post /api/resilience/reset (ac74b21)
- resilience: add in-memory 3-level resilience store (4bd458a)
- resilience: add modelconfig resilience key adapter (e5c29b3)
- resilience: add resilience:read/manage permission chain (53d9521)
- resilience: add upstream error classifier (eb812ed)
- resilience: make resilience a hard routing pre-filter (fe4ec80)
- resilience: record faults, classify ttft timeout, retire resiliencepage (25c8afb)
- resilience: register resilience module + resilience_store token (f298400)
- resilience: route executor failures through classifier+store, preserve events (b2b977c)
- reverse-proxy: add proxy context types and block-aware phase runner (9e2ab57)
- reverse-proxy: add wire-faithful helpers for plan 5 concern processors (779ad8e)
- reverse-proxy: anthropic transport lane (upstream + attempt + egress) (6e1b4f6)
- reverse-proxy: atomic flip routes to runproxy; delete inline handlers (pipeline live) (f413dc8)
- reverse-proxy: openai transport lane (upstream + attempt + egress) (67e26be)
- reverse-proxy: register transport pipeline in the module kernel (dark) (afb558c)
- reverse-proxy: resolve effectivemodel before adapter dispatch, legacy fallback (30dd3a0)
- routing: add fallback strategy registry (next-best/retry-after-cooldown/abort) (9da46cd)
- routing: add immutable built-in profile presets (a140c94)
- routing: add model-preference policy (0efd397)
- routing: add round-robin cursor primitive to memory store (a4184b2)
- routing: add selector registry (argmax/weighted-random/round-robin/cheapest/lowest-latency) (b1a3b54)
- routing: per-agent routing policies via x-routerly-policy header (#78) (0b2ae69)
- routing: profile resolution + resolve-time default-profile migration (744bc0a)
- routing: resolve profile and apply selector; replace ad-hoc random (7219389)
- security: content guardrails and pii scrubbing middleware (#77, #76) (b947918)
- security: per-rule block/log guardrails + policies-only pii (99c1c5a)
- security: remove flag action and detect injection from guardrails ui (#77) (947a2df)
- service,dashboard,shared: oauth subscription support for anthropic-oauth and openai-oauth (5daeea5)
- service: add get/enable/disable module management endpoints (074d6f9)
- service: add module enable/disable registry with dependency guards (ea083be)
- service: add the experiments management api (5f62155)
- service: boot modular kernel and config module in server bootstrap (a55205c)
- service: gate kernel module list on persisted module records (d22c37a)
- service: gated get /api/clients metadata endpoint + client-configurator module (7e5631b)
- service: guardrail observability (evaluated trace, blocked usage, budget gate) (6b0577a)
- service: implement real bedrock converse-stream binary parser (#87) (219c3dc)
- service: notification channels and in-app inbox endpoints (2bfa9b2)
- service: per-model usage filters and performance metrics (989dd7f)
- service: persist module records in modules.json (614687e)
- service: persist user routing profiles in profiles.json (655e5a8)
- service: prometheus metrics auth token and docker-compose integration (#93) (c0c1a89)
- service: provider module exposes adapter behind provider registry (10f50e5)
- service: route experiment tokens to variant projects (10c5b76)
- service: routing-profile crud, assign, and simulate endpoints (0cfcbc9)
- service: transparent pass-through proxy for unhandled provider endpoints (#100) (48477df)
- service: transparent pass-through proxy for unhandled provider endpoints (#100) (#106) (eb21e43)
- service: wire 8 missing notification events (#89) (0f25b23)
- settings: rebuild general tab, add security tab, drop modules page (83e4737)
- shared: add client-integration registry metadata (151b10b)
- shared: add experiment types and the experiments permissions (fc7c611)
- shared: add modulerecord type (7fa8f1d)
- shared: add routing profile types + profiles permissions (c159340)
- shared: notification channel targets + inbox per-user dismiss types (1bd943b)
- shared: optimizer contract + per-project config types (5945439)
- tokens: add scopes field to project token create/update (cli + dashboard + api) (2bb64a4)
- tokens: session tracking and key-value tags on project tokens (#94, #95) (8edfdec)
- trace: make the trace an event-driven module, with a live channel and exports (15c3e6f)
- trace: trace every stage of the request, on two levels (8fcb195)
- transparent anthropic pass-through for claude code compatibility (5ecded8)
- update-checker: emit system.update_available on new release, deduplicated (ef230c5)
- usage: add the savings and counterfactual layer (95271ac)
- usage: name the token a call came in on, and retire end users (f0121bc)
- usage: per-end-user tracking, session tracking, tag-based attribution (#96, #94, #95) (5a65338)
- usage: readable call log, caller filter on the cli, usage docs (0eef761)
- usage: record and filter the request type of every call (e867853)
- users: add reset 2fa button in admin users list (#84) (c66eb04)
Bug Fixes
- agents: correct tester subagent model id (oppus typo -> opus) (c40aeb9)
- api: correct model-connection credential handling and rebinding (f55e522)
- api: redact all connection credentials from model responses (1623801)
- catalog: carry model overrides through instances and write sync results back (8fe94d8)
- catalog: last repo in list overrides earlier ones on key conflict (ee39f97)
- catalog: track content-change timestamp separately from last-check (f6b16d8)
- catalog: use upstream timestamp from index.json as content-change date (1c96b75)
- catalog: validate explicit provider against connection on import (754dea3)
- ci: keep the newest docker tag from moving on old-version rebuilds (9aa96a5)
- ci: make the docs-version suite pass on a checkout that never installed website/ (846fa3e)
- ci: push develop tag by refspec to avoid ambiguity with branch name (0e655ec)
- claude: repair agent-cost.mjs and require live third-party checks (95b1c11)
- cli: add email provider channel creation for dashboard parity (2f4b186)
- cli: correct mode preservation, error handling, and integrity in safe-file (f5ea888)
- cli: default new config files to 0600, not 0644 (2c5ce1e)
- cli: drop unused fs import in safe-file helper (120fd44)
- clients: remove em dashes and harden anthropic snippet regression test (c2cd26f)
- cli: guardrail/blocked breakdown in report usage, free/local model label (6d5846a)
- cli: honest cline config-kind and correct stale continue.md docs (169d3ee)
- cli: opencode em dashes and routing sentinel model id (803d4e5)
- cli: strip credentials from connections --json, document connections command (d80afa0)
- cli: surface /mcp http error message and propagate serve exit code (e69abd3)
- connections: drop '(migrated)' suffix from connection labels (50ccd5a)
- core: honor intra-phase shortcircuit in processor registry (0d7e6d6)
- core: remove em dash from sdk.ts doc comment (0887987)
- correct the playwright-mcp gitignore entry (dd2ac05)
- dashboard,cli: guard null cost in usage page, fix leaderboard field names (e30fc8d)
- dashboard: align optimizer threshold controls, define --surface-active (153a746)
- dashboard: allow timeframe selection in live mode (4de2092)
- dashboard: buffer playground sse across chunk boundaries (df76df5)
- dashboard: clients page cline text, em dashes, feature-detect error handling (56a0cc8)
- dashboard: correct swapped rtk/headroom klass labels in optimizer tab (40fbe56)
- dashboard: gate write affordances behind their permission (c13103a)
- dashboard: honor discovered model in add form (#81) (65fe2fa)
- dashboard: move usage refresh controls out of subtitle paragraph (7f66244)
- dashboard: notification dropdown z-index and 2fa ux improvements (838eb1c)
- dashboard: prefill model form from discovery provider and model id params (#81) (805eceb)
- dashboard: prevent login redirect loop and double-encoded to param (a56910f)
- dashboard: redirect legacy /dashboard/instances to the models list (0206087)
- dashboard: remember the period picked on the overview (13cc7f8)
- dashboard: resolve usage provider column from configured models (6588c5f)
- dashboard: restore accessible naming and keyboard operation for searchable selects (31203e1)
- dashboard: restore dropped credential-preservation and non-error rejection tests (0cee04b)
- dashboard: scale cost axis ticks to the values plotted (d1fffe4)
- dashboard: show only the table on experiment metrics (5653b7a)
- dashboard: translate date range picker to english (88a6792)
- dashboard: translate time inputs and follow page theme (5df8955)
- dashboard: typescript strict errors in test files (6c1a394)
- deps: clear every high advisory that has an upstream fix (fe9d4ad)
- deps: resolve npm audit high-severity vulnerabilities (d36b098)
- docker: stop docker-rebuild from moving :latest onto an old release (f649718)
- docs+cli+dashboard: remove em dashes in client-configurator code comments (6da2cf6)
- docs: copy docs/assets into versioned snapshots (1d16aab)
- docs: correct clients configure permission claim (c0e1848)
- docs: correct docs-versioning to match the release channel model (765af03)
- docs: escape mdx angle brackets in models.md filter descriptions (bab33b0)
- docs: remove em dashes from client configurator docs (1f35ad3)
- gemini: strip provider prefix from model id before upstream call (#115) (bc1cf93)
- guardrails: trace header on block, budget-exceeded 429, streaming block wire parity (a4b47d6)
- health: compute p95 latency over 1h window instead of 5m (6687bca)
- mcp: drop fabricated enabled field, remove vitest from shipped helper (4eb6d67)
- mcp: remove em dash and stale enabled-field mention in read.ts comment (4d73568)
- mcp: remove em dash in expectnosecrets ponytail comment (592ce2b)
- mcp: thread scopes through cli token auto-mint; remove em dash in mcp page (f9e1545)
- models: use flaskconical icon for test button, consistent with rest of ui (c646ad5)
- oauth: resolve static bearer for legacy migrated oauth connections (3c832a0)
- optimizers: ccr keeps anthropic tool pairs atomic, no consecutive user msgs (f1f79ca)
- optimizers: ccr window 3 by default, relevance falls back to 0.1 (310efee)
- optimizers: correct caveman threshold docs, remove em dashes (5327932)
- optimizers: correct fixture counts and preview's unnamed model (8af75d8)
- optimizers: derive the api optimizer id enum from the catalog (12caeea)
- optimizers: make headroom fire (f3838ec)
- optimizers: one token estimator for every step (783d86d)
- optimizers: per-optimizer threshold range instead of uniform 0-1 (585091f)
- optimizers: score llmlingua-2 in encoder windows, not one throwing pass (e091538)
- optimizers: stop caveman eating file paths and dotted identifiers (338a0e9)
- optimizers: structure-aware session-dedup key (no multimodal/tool-call loss) (c4bf502)
- provider: encrypt oauth/web credentials on connection create/update (b46acfd)
- provider: gate oauth resolve on provider-oauth module (bbeb3c4)
- provider: guard oauth refresh against unknown expiry + malformed credentials (55ec324)
- providers/custom: replace openai sdk with raw fetch for wire-format transparency (21df1af), closes #109
- RA-13: use Bearer auth scheme for Docker Hub API calls (239d891)
- RA-16: stop double-printing git's stderr on an invalid range (a8313f4)
- RC-1: repair notes parity and add make_latest on promotion (91ed70d)
- RC-1: repair notes parity and add make_latest on promotion (8c6509e)
- RC-3: rename update channels to current/next with deprecated aliases (6aa9598)
- RC-4: merge deprecated-channel deprecation hint into 0.4.0 (0cb74ee)
- RC-4: source deprecation hint from raw stored channel, not the normalised one (04582ff)
- release: anchor the commit parsers to real conventional-commit syntax (e98d5d4)
- release: keep release-notes.sh to its one-line error contract (d2671ab)
- release: make screenshot capture deterministic (c234e96)
- remove remaining em dashes flagged by final branch review (38453ab)
- resilience: add cli docs, drop dead cast (8461dc9)
- resilience: add record-success signal, remove incorrect half-open recovery heuristic (4c2cd26)
- resilience: clarify elapsed-time call-site comment (5735ac1)
- resilience: declare routing's dependency on resilience module to fix registration order (00d20cf)
- resilience: key the connection breaker on the real connectionid (ea041a8)
- resilience: reject partial level/id reset body, address review nits (457b4c3)
- resolve pre-existing test failures and oauth body-parse crash (daf69e0)
- reverse-proxy: anthropic egress: no trace header on block results that never carried it (c72fdbe)
- reverse-proxy: block results must still reach the egress phase (7ecea8e)
- reverse-proxy: make guardrail injection merge idempotent across fallback (0c4b034)
- reverse-proxy: merge guardrail steering injection into upstream request (c98638c)
- reverse-proxy: openai egress must not add trace header on block results that never carried it (3fad71f)
- reverse-proxy: satisfy exactoptionalpropertytypes for attemptresponse assignment (2ecc220)
- reverse-proxy: use reply.status() consistently in anthropic egress (727c12c)
- routing/semantic-intent: look up embedding credentials from model registry (dcd9e3c), closes #112
- routing/semantic-intent: use resolvedcfg.embedding_endpoint in trackusage (d441afc), closes #109 #112
- routing: fix fairness policy bugs and add oauth usage tracking (183d32d)
- screenshots: make the capture deterministic and every output distinct (5bd0a9e)
- screenshots: settle on the page's own loading state, not the request count (6b27edd)
- scripts: stop capacity.sh crashing when no story is in flight (c5ae7b6)
- service: enforce notification:write, scope test inbox item, bound ids, harden ssrf (a437c32)
- service: exclude blocked records from leaderboard and routing health (280720d)
- service: honor x-forwarded-proto/host for /api/clients base url (b27592e)
- service: honour x-routerly-no-trace header to suppress sse trace events (#110) (103fb82)
- service: honour x-routerly-no-trace header to suppress sse trace events (#110) (70f5f18)
- service: isolate simulate cursor state, validate profile assignment, fix ranked order (bf1062a)
- service: make config writes atomic and stop reads from persisting an empty default (5108d71)
- service: restore leaderboard api and cli command (#80) (5433105), closes #82
- service: widen config write lock retry budget (4a918d4)
- settings: accept extra fields in notifications config (758cd1a)
- shared: mark codex client as auto-configurable (e9a5482)
- telemetry: async ping with retry logic, dedup install, skip tracking in tests (1ca58a4)
- trace: store the whole trace on the usage record (5f14cbe)
- update-checker: extract semver from release name for rolling channels (develop/stable) (430f1bd)
Documentation
- 0.3.0: guardrail observability, blocked usage, cli breakdown, 2fa qr, model prefill (e85f070)
- 0.3.0: notification rework, dashboard ia, guardrail wire, x-api-key auth (c81dfe1)
- 0.4.0 modular-kernel refactory plan set (effe797)
- add light-mode screenshots to all dashboard pages and key getting-started docs (91abd97)
- add step 0 modular restructure overview and detailed execution plan (d6522d9)
- add step 10 modular restructure plan (cdfbfa0)
- add step 11 modular restructure plan (ddac5d1)
- add step 12 modular restructure plan (597624f)
- add step 13 modular restructure plan (a572e21)
- add step 14 modular restructure plan (7684b2b)
- add step 15 modular restructure plan (a975909)
- add step 16 bootstrap extraction plan (b9a85cb)
- add step 2 lib extraction execution plan (5d79fa9)
- add step 3 config module extraction execution plan (dc42359)
- add step 5 catalog extraction plan (59b03da)
- add step 6 embeddings extraction plan (f456b58)
- add step 7 budget/usage extraction plan (533d139)
- add step 8 and step 9 modular restructure plans (f0c93d4)
- bump version label to 0.3.0, add 0.2.0 to version picker (8906d0f)
- changelog: correct 0.4.0 phase-list accuracy (91e170b)
- claude: extract feature-lifecycle mechanics into a lazy-loaded skill (8edd4e0)
- client configurator (cli + dashboard + per-client manual guides) (e352a2d)
- config: set 0.2.0 as default docusaurus version (#70) (64bb088)
- connect: document the connect section and every registry client (9fce5bf)
- connections + model instances api and dashboard reference (5be12dc)
- connections cutover and model-connection binding (c0198f4)
- correct modules dependson type, enable 409s, dashboard rbac (bc816ba)
- correct project, budget and proxy pages against the current surfaces (33c963a)
- cut the real 0.3.0 documentation snapshot from develop (aa688d3)
- dashboard: add discovery and 2fa screenshots, refresh #81 behavior (fc469d2)
- dashboard: add end-users tab documentation (#96) (4220f2f)
- dashboard: renumber sidebar_position to make room for connections page (9ab7fac)
- document
routerly report savings(f840c9a) - document experiments across concepts, dashboard, cli and api (b28b64b)
- document merged models-health and usage-leaderboard tables (2327185)
- document modules feature (api, cli, dashboard) (6bcc544)
- experiments: state that judge score ignores the metrics window (f52c1d5)
- fix em dash and false model:read auth claim in connections docs (223b5c0)
- guides: add web session provider guides and cli cf-clearance flag (#85) (c1b085a)
- mcp: document mcp server transports, scopes, tools, and surfaces (2038b99)
- mcp: document the personal mcp surface and client wiring (66f4776)
- notifications: correct dismiss endpoint, drop false admin global-delete claim (b705419)
- notifications: document channels, in-app inbox, unread, per-user delete (8c0657f)
- notifications: document the readable inbox across surfaces (10717f6)
- notifications: routing rules, cooldowns, per-project channels, model discovery (#81 #90 #91) (265f6f4)
- observability: document guardrail:evaluated + pii:evaluated trace entries (0d67da1)
- optimizers: document llmlingua-2 windowing and the grow-back rollback (fc37cc6)
- optimizers: document the overhauled optimizer surface (52b0640)
- optimizers: document threshold semantics, traffic samples and per-step diffs (0c98d1d)
- optimizers: usage, api reference, provenance and licensing (6f2d8e6)
- overview: document the savings series across dashboard, cli and api (e1e659c)
- process: three edits the cost measurement forced (d484ada)
- profiles: document the three profile kinds across dashboard, cli and api (5e9afe3)
- RA-10: backfill 0.4.0 as a versioned docs snapshot (b2a8421)
- RA-10: cut documentation version 0.4.0 (3a60fd3)
- RA-16: add screenshot-review skill for judgement layer (c979525)
- RA-16: document the screenshot impact layer (2fbbd53)
- RA-18: document the release pipeline in-repo (75a2e03)
- RA-18: document the release pipeline in-repo (c550955)
- RC-6: deletion sweep, anchor repair and page verification (fe0de9e)
- RC-6: merge release process documentation into 0.4.0 (663aa3a)
- RC-6: rewrite branches/channels and promotion model (08d3b80)
- RC-6: rewrite contributor protocol around conventional commits (6e879df)
- RC-6: rewrite credentials and failure-path sections (c5da4f5)
- readme: update for shipped notifications, fix broken links, add playground screenshot (36a017b)
- release: add release notes and update progress for 0.3.0 (36890c3)
- release: document module version sync and --check (52e7d0d)
- release: document the docker rebuild workflow (fe33ff2)
- release: document the Docker Rebuild workflow (dd5c17c)
- release: explain changesets and the version pr (c710b14)
- release: fold the maintainer procedure into one page (41bf2cd)
- releasing: document generated release notes (6ab0426)
- remove completed superpowers refactory plans (abfbd98)
- repair three cross-reference anchors (9cfad4c)
- routing: document routing profiles across api, dashboard, and concepts (1b49cf3)
- screenshots: explain the full reproducibility mechanism, not just the fixed port (1c2b5de)
- step 4 provider extraction execution plan (575df31)
- trace: correct the phase list and what pii:evaluated counts (efa1452)
- update usage page screenshot and document telemetry env vars (449cfce)
- update-checker: document the system.update_available alert (cb9cac6)
- workflow: correct the user-check gate to feature level, not per story (247d2fa)
- workflow: gate qa/docs/merge behind a user-check, not auto-run (8d53abf)
Refactor
- api-reverse-proxy: move routes/openai,anthropic,passthrough into modules/ (d8188e2)
- api-reverse-proxy: repoint external consumers to modules/api-reverse-proxy/ (105a129)
- api: move routes/api.ts into modules/api/ (da61d70)
- api: repoint external consumers to modules/api/ (97022cb)
- audit: move audit/logger into modules/audit/ (f354d7e)
- audit: repoint external consumers to modules/audit/ (0439b4e)
- auth: move auth/ and plugins/jwt+auth into modules/auth/ (11944c2)
- auth: repoint external consumers to modules/auth/ (53f3b33)
- budget,usage: move budget/tracker/usagestore into modules/ (e6aa71d)
- budget,usage: move module wrappers to index.ts, fix token paths (0cd6f3e)
- budget,usage: repoint external consumers to modules/ (3a82ee0)
- catalog: move fetcher/sync into modules/catalog/ (e3ca5af)
- catalog: repoint external consumers to modules/catalog/ (41001e1)
- config: move loader and migrate into modules/config (1f873f6)
- config: repoint all consumers to modules/config (3966f00)
- core: rebase processorregistry onto alterableregistry, add per-processor override (c016582)
- core: reorganize core/ into container, modules, events, pipeline, lifecycle subfolders (9af3584)
- cost: route executor cost through calculatecost (dedup, cache-creation aware) (d228a33)
- cost: unify usage.json scans onto readusagerecords (dedup) (b9765e8)
- dashboard: extract reusable connectionform component (1153ce2)
- dashboard: remove health columns from models tab, health tab only (b741bd9)
- embeddings: move dispatcher/openai/ollama into modules/embeddings/ (17395dc)
- embeddings: repoint external consumers to modules/embeddings/ (8c599ed)
- guardrails,pii: absorb flat module wrappers into module dirs (1361dfd)
- guardrails: move middleware/guardrails.ts into modules/guardrails/ (60c4258)
- lib: extract calculatecost into lib/cost.ts (bf12ec8)
- lib: extract config_paths into lib/paths.ts (14681b4)
- logging: absorb flat module wrapper into modules/logging/ (277256e)
- logging: move routing tracestore into modules/logging/ (e33ff97)
- logging: repoint external consumers to modules/logging/tracestore (1f8a633)
- notifications: move notifications/ into modules/notifications/ (c1be654)
- notifications: repoint external consumers to modules/notifications/ (9095f0f)
- observability: move integrations/ into modules/observability/ (bb5a1d0)
- observability: repoint external consumers to modules/observability/ (1c179e3)
- pii: move middleware piiscrubber into modules/pii/ (71456ee)
- profiles: remove the built-in security presets (489e610)
- provider: add registry.ts hook-based dispatcher (7ad35e5)
- provider: hook-based dispatch via alterableregistry (11a956b)
- provider: move adapter files into modules/provider/ (a823d0b)
- provider: repoint consumers at modules/provider/registry.js (53010c8)
- reverse-proxy: loadeffectivemodel resolves only via instances (12b2b00)
- reverse-proxy: move llm/executor.ts and reverse-proxy/ into modules/reverse-proxy/ (90cc1ad)
- reverse-proxy: repoint external consumers to modules/reverse-proxy/ (6b0f083)
- routing: fix module wrapper and consumer import paths (f8c5e0c)
- routing: move module wrapper to index.ts, fix token/consumer paths (6e54a92)
- routing: move router, policies, intent into modules/routing/ (2a1d86e)
- routing: remove dead selectmodel path (grep-gated, zero callers) (a726bd1)
- service: dissolve routes/ into modules/observability and modules/reverse-proxy/lanes (c24b867)
- service: extract bootstrap/ module-array assembly from server.ts (642e972)
- service: move telemetry and update-checker into modules/ (25f9b51)
- service: reuse p95 helper, cover unknown usage filters (4cefcd0)
- service: route all model-list reads through listeffectivemodels (b079940)
- settings: expose listening addresses, drop the global timeout (11d4cd8)