Skip to content

Helix 1.6.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 01:51
· 7 commits to main since this release

Helix 1.6.0 is a numbered private-LAN release. Keep it on a network you control. Public-internet exposure is not supported.

The dashboard Update Helix control uses these SHA-256-pinned source assets. It does not use git pull. Game containers are not replaced.

  • 2026-09-28

Added

  • Server API tokens can be viewed again. View token asks for your dashboard
    password, then shows the value. Helix keeps an encrypted copy (XChaCha20-Poly1305
    via the existing secret store) whose key lives in secrets/ under the data
    directory, outside state/, so a copied state database or state backup does
    not reveal tokens. Viewing is audited. Tokens made before this release have no
    copy; rotate one once to make it viewable.
  • Full access token permission (all): every server permission on the
    selected servers, including ones added later, in one click. Host controls stay
    out of reach. Permissions also get Select all and plain names.
  • Tokens can now install marketplace plugins and mods (files.write), search the
    marketplace (view), empty backup trash (backups.write), open a server to
    the internet (network), and move a server to Removed servers (remove).
    Creating a token with network or Full access needs the firewall permission.

Fixed

  • Dashboard preferences were never saved to the server ("Preference service
    unavailable · using the browser copy") because the server did not know the
    Machines page and rejected every save. Older dashboards that send the previous
    page list are repaired instead of rejected.