1.1.0
Major release: MCP server for AI clients, subcommand-first CLI, JSON
output, multi-profile configuration, product-level fan-outs, and a
consistent error taxonomy across both interfaces.
Added
- MCP server (
thinr mcp) exposing ~26 typed tools over stdio for AI
clients (Claude Code, Claude Desktop, and any other MCP host). Covers
discovery, shellexec, filesystem (read/write/ls/mkdir/delete/
move), typedresourcecalls, properties, scripts (device- and
product-level), products, monitoring and agent updates, plus a profiles
lookup. MCP errors carry the same{ code }taxonomy as the CLI JSON
mode (exposed on_meta) so clients can pattern-match without parsing
human strings. - Subcommand-first CLI UX:
thinr device <action> <deviceId>/
thinr product <action> <productId>replaces the previous top-level
flag shape. Matcheskubectl/gitidioms. thinr device list [pattern]with case-insensitive regex filtering on
the server side (replaces the oldthinr devices).thinr device exec <deviceId> <command...>with streaming stdout/stderr,
SIGINT cancellation,--jsonenvelope, and--legacyone-shot fallback
for older agents.thinr device update check|applyfor managing agent upgrades.thinr device resourcewith per-resource input/output schema
introspection, andthinr product resource/thinr product property
for fleet fan-outs.- Multi-profile configuration store (
~/.config/thinr-cli/config.json):
one profile per server, selected via--profile, theTHINR_PROFILE
env var, or a per-call MCP parameter. Legacy single-file configs are
detected and migrated in-memory on read. thinr profile list|current|use|deletefor managing configured
environments.--json/-joutput envelope on every data-producing command with a
stable{ code }taxonomy:not_configured,not_found,
unauthorized,server_error,network_error,input_error,
timeout,cancelled,error.-u, --useradmin impersonation flag plumbed through every
device-scoped operation (CLI + MCP).THINR_INSECURE=1env var to accept self-signed TLS certificates
against non-localhost hosts (localhost / 127.0.0.1 are always
accepted).- Device property setter via PUT (
setDevicePropertyin the CLI,
thinr_property_setin MCP). thinr_device_infoMCP tool surfaces server-side product, asset group
and description alongside the agent's ownsystem_info.- Refresh-token flow on 401s: the CLI transparently swaps expired access
tokens for a fresh one when arefresh_tokenis on record, and fails
cleanly (with an actionableunauthorizederror) when it isn't.
Changed
- MCP server internals: tool schema and handler now paired in a
registry, so they cannot drift apart. Tools grouped by area under
lib/mcp/tools-*.js, withserver.jsreduced to a thin bootstrap. - CLI
devicecommand split into one file per subcommand under
commands/device/(previously a single 17 KB module). lib/device.jsrenamed tolib/devices.js(plural: operations on the
fleet), paired with the low-levellib/device-api.js.- Interactive handlers (auth / console / proxy) no longer call
process.exitfromlib/*; the CLI entry owns the exit code. - Centralised API error classification in
lib/errors.js— one
{ message, code, status }contract consumed by both CLI JSON mode
and MCP_meta. - Re-thrown auth errors chain the original
causefor better
debugging. - Bad
-i key=valuevalues surface as a clean Commander
InvalidArgumentErrorinstead of a stack trace. - Node.js engine requirement bumped to
>=18;.nvmrcpinned to 20. - The MCP server's
initializeresponse now reports the CLI's
package.jsonversion inserverInfo.version(was hardcoded). - Runtime dependencies refreshed, including majors:
@inquirer/prompts
7 → 8,conf14 → 15,open10 → 11,ora8 → 9. All npm audit
advisories cleared (0 vulnerabilities on install).
Removed
thinr devices(usethinr device listinstead).thinr device mcp <deviceId>(usethinr mcpwith per-calldevice
parameter).thinr device envlauncher.
Tooling
- ESLint 10 (flat config) + Prettier 3 with
eslint-config-prettier
bridge. Scripts:npm run lint/lint:fix/format/
format:check. - TypeScript
checkJsvia per-file// @ts-checkopt-in; 21 files
underlib/mcp/andcommands/device/pass type-check today. Script:
npm run typecheck. - Unit tests with
node --test(zero deps): MCP registry invariants +
error helpers. Script:npm test. - Publish pipeline migrated from a long-lived
NPM_TOKENsecret to npm
Trusted Publishing (OIDC), with--provenanceattestations on every
publish. GitHub Actions bumped tocheckout@v5/setup-node@v5.