Helix 1.6.0
Helix 1.6.0 is a numbered private-LAN release. Keep it on a network you control. Public-internet exposure is not supported.
The dashboard Update Helix control uses these SHA-256-pinned source assets. It does not use git pull. Game containers are not replaced.
- 2026-09-28
Added
- Server API tokens can be viewed again. View token asks for your dashboard
password, then shows the value. Helix keeps an encrypted copy (XChaCha20-Poly1305
via the existing secret store) whose key lives insecrets/under the data
directory, outsidestate/, so a copied state database or state backup does
not reveal tokens. Viewing is audited. Tokens made before this release have no
copy; rotate one once to make it viewable. - Full access token permission (
all): every server permission on the
selected servers, including ones added later, in one click. Host controls stay
out of reach. Permissions also get Select all and plain names. - Tokens can now install marketplace plugins and mods (
files.write), search the
marketplace (view), empty backup trash (backups.write), open a server to
the internet (network), and move a server to Removed servers (remove).
Creating a token withnetworkor Full access needs the firewall permission.
Fixed
- Dashboard preferences were never saved to the server ("Preference service
unavailable · using the browser copy") because the server did not know the
Machines page and rejected every save. Older dashboards that send the previous
page list are repaired instead of rejected.