v1.3.0
Minor release. Big themes: recipes and pantry items from CookTrace, an opt-in way to mark diary days complete, new ways to reach your data from your own tools (a REST API, outgoing webhooks and more MCP tools), Cronometer imports working again, a round of iPhone fixes, better Open Food Facts search, and several security fixes worth updating for.
Upgrade note. The database picks up its new columns automatically on first start; nothing to do. To import CookTrace pantry items you need a CookTrace version with the
read:pantrypermission and a token created with it ticked. Existing CookTrace tokens keep working for recipes.
Added
- CookTrace recipes and pantry items. If you also run CookTrace, a CookTrace chip on the Foods screen searches it: pick a recipe to open it in the Meal Editor with its ingredients, servings, photo and nutrition, or a pantry item to open it in the Food Editor. Settings, Connected Services, CookTrace can also import every recipe or every pantry item in one go. Imported items stay linked to CookTrace, so importing again updates what you already have instead of making a copy, and when a recipe changes in CookTrace, NutriTrace offers to pull the update rather than overwriting anything. Opt-in, with a token you create in CookTrace.
- Mark diary days complete (#207). Off by default (Settings, Diary, Show Day Completion). Close a day from the date bar, or tick meals one at a time and the day closes when they're all done. Completed days get a check on the week strip and date picker, Statistics counts them, the weekly summary includes them, and on Android the bedtime notification has a Close today button. Marks sync between your devices. Thanks @tellis82 for the suggestion.
- A REST API for your own scripts and automations.
/api/v1/diary,/api/v1/goals,/api/v1/meals,/api/v1/stepsand/api/v1/profile. Off by default (PUBLIC_API_ENABLED=1;PUBLIC_API_WRITE_ENABLED=1also allows logging food, water, meals and body stats). Uses the same tokens as MCP. Seedocs/public-api.md. - Outgoing webhooks. Set a URL in Settings, Webhooks and NutriTrace sends a signed HTTP POST when you log a food, water or a body stat, or reach a daily nutrition goal. Off by default (
WEBHOOKS_ENABLED=1). Failed deliveries are retried, a send button next to each webhook fires a test event, and addresses on your local network are refused unlessALLOW_PRIVATE_WEBHOOK_URLS=1. Seedocs/webhooks.md. - More MCP tools (#215, #219). Diary entries and daily totals over a date range, optional dates on recent foods and recent meals, daily steps from connected wearables, and your gender and date of birth. Any
mcp:readtoken can read your date of birth, so an AI client connected over MCP can see it. Thanks @kgenerozov for contributing both. - Average Heart Rate card in Wellness (#205). Health Connect already recorded it; now it shows, next to Resting Heart Rate. Thanks @kgenerozov for the report.
- Health Connect weight can fill in Body Stats (#200). Optional (Settings, Wellness, Mirror wellness weight to Body Stats). Your scale reading fills that day's Body Stats weight, so the Diary widget and the Weight goal use it too. A weight you entered yourself is never overwritten. Thanks @tmzhuang for the suggestion.
- Custom nutrients in the Food Editor (#201). Nutrients you add in Settings, Nutrients can now be filled in on a food and count toward your diary totals. Thanks @caioqv-dev for the report.
- Share new items automatically (#183). Settings, Sharing, Auto Share: set it to Everyone and every food, meal and recipe you create from then on is shared with your group. Existing items are left as they are. Thanks @nomad64 for the suggestion.
- Select All and Select None when managing foods (#175). Both follow your current filters and search. Thanks @nomad64 for the suggestion.
- Forward proxy support (#177).
HTTP_PROXY,HTTPS_PROXYandNO_PROXYsend all of the server's outgoing requests through your proxy. Thanks @yoyo-san for the suggestion. - Screen layout details in diagnostic logs. With Diagnostic Mode on (Settings, Diagnostics), the log also records screen sizes and positions, which helps sort out display problems on phones I can't test on. Nothing you type is recorded.
Changed
- Open Food Facts search keeps the best match on top (#213, #192). Results with a photo and more complete data used to be moved up across the whole page, which could bury the product you searched for when it had no photo. Now OFF's own order wins whenever one result is clearly a better match, and photos and completeness only sort results that match about equally well. With a local OFF mirror, results are sorted by completeness instead of photos, since mirror entries rarely have them. Thanks @NoBackups and @systems-monitor for the reports.
- Typing over a filled-in number replaces it (#170). Sheets that open with a value already in the box select it, so you type the new number instead of adding to the old one. The remaining sheets, including the Goals editors, also focus their first box and save on Enter.
- Claude Fable 5.1 in Trace's model list. It is now the most capable Claude option; Fable 5 stays available, marked as previous.
Fixed
- iPhone and iPad no longer zoom in when you tap a text field (#212). Other devices are unchanged. Thanks @Sanket-Pati-007 for the report.
- Diary's summary bar sits at the bottom of the iPhone screen (#208). It could float with a see-through gap underneath. Opening NutriTrace from the Home Screen could also leave a black strip along the bottom until you scrolled; there's now a workaround for that too. Thanks @zen-pavel for the report.
- Copy buttons work over plain http. On an http address, such as a LAN IP, every Copy button failed. They now work there too.
- Foods panels no longer cover the header when you scroll (#217). On a wide window, loading more search results could move the Sources and food details panels over the search bar. Coming back from the food editor also returns you to where you were in the list instead of the top. Thanks @fatman00 for the report.
- Cronometer imports work again. Cronometer stopped including nutrition in its per-food export on at least some accounts, so importing it failed. NutriTrace now also imports the Daily Nutrition export, as one entry per meal (tick "Include diary group rows") or one per day. Evening entries are no longer saved as morning, supplements and spices are no longer skipped, dates in your account's own format are read correctly, and the daily Total row isn't counted twice.
- "As percent" macro goals show and convert correctly (#209, #210). Applying a macro preset could turn a gram target into a huge percentage, and the Goals page showed percent goals as grams. If you hit this, applying your preset again fixes it. Thanks @drunkenpeleg for the report and the fix.
- Health Connect body composition no longer saves as 0 (#206). Bone mass, lean mass, body fat, temperature, breathing rate, VO2 max and BMR were stored as 0, and BMR was in the wrong unit. Existing zeros are cleared on the next launch and your next sync fills in the real values. Thanks @kgenerozov for the report.
- Health Connect asks for every permission it needs (#204). If you only granted some before, you'll see one prompt for the rest the next time you turn it on. Thanks @kgenerozov for the report.
- Per-weekday calorie and macro targets are used correctly (#203). Diary's Remaining used the week's highest target instead of that day's, and Statistics now compares against your weekly average. Thanks @kgenerozov for the report.
- Slow loading when a food had a photo saved in it (#199). A photo stored inside a food was copied into every diary entry that used it, which could make the diary a 50 MB download. Existing photos are moved to normal files on the next restart. Thanks @tellis82 for the report.
- Diary week strip (#180, #168). Each day's bar now uses that day's own goal, so logging activity no longer shifts the others, and editing a serving size updates the day's ring straight away. Thanks @drekkym for the report.
- Foods no longer looks empty while it's loading (#178). Thanks @tmzhuang for the report.
- A stuck connection can't block syncing for minutes. A stalled sync now gives up after 30 seconds instead of holding up every later sync for 10 to 19 minutes.
- USDA foods split monounsaturated and polyunsaturated fat correctly (#179). Foods you already imported keep the old split until imported again. Thanks @herver1971 for the fix.
- Wide-screen Diary shows the multi-select buttons (#198), and the Foods manage-mode buttons stay at the right edge on very wide windows. Thanks @tellis82 for the report.
- Local OFF mirror search (#185 to #191). Products with an apostrophe in the name are found, popular products come before obscure copies, the quality filter no longer hides everything, typed barcodes are found, results load past the first page, words match in any order, and a duplicate barcode can no longer freeze the app. Thanks @systems-monitor for the reports.
- Mealie recipe images load when Mealie is on your home network.
- Reordering items within a meal is kept after syncing.
- Password reset and invite links use https behind a reverse proxy.
- Turning on user management keeps everything from single-user mode. Activity, fasting, Trace chat history, wearable data and wearable connections were left behind when the first account was created; they now move to it. Instances that already switched get them back on the next start.
- Deleting an account removes its wearable data and connections, and single-user mode shows all of its wearable data again.
- MCP tools refuse dates that don't exist. A date such as 2026-02-31 read back as an empty day, and logging to it created a diary entry for it. It's now an error.
Translations
- German, fully translated on Weblate by KAiSER. Choose it in Settings, Regional & Units, Language. A few labels are still in English in every language because they haven't been made translatable yet.
Security
- Backups can no longer be downloaded from the uploads folder. When scheduled backups were on, a backup file could be fetched by anyone who knew or guessed its name, without signing in. If your instance is on the internet and had backups turned on, check your access log for requests to
/uploads/backups/. - Uploaded files can no longer run as web pages. Files are stored under an extension that matches what they actually are, and everything under
/uploadsis served in a way that can't run scripts. - Dependency updates: nodemailer 9.1.1 (GHSA-8m3c-c648-2xjj, high), multer 2.4.0 (GHSA-wc9g-mqfw-jrwm, GHSA-qfvm-cv95-jqjf, GHSA-535w-7cp7-47q4, high), fast-uri 3.1.8 (GHSA-5jgf-p345-68v8 and three related, high), hono 4.13.8, qs 6.16.0, adm-zip 0.6.1 (GHSA-vwc7-r8mq-g2x9) and devalue 5.9.4 (GHSA-9rgm-9g3h-6x36), all moderate, plus updated build tools.
npm auditreports 0 vulnerabilities.
NutriTrace is free and always will be. The iOS fund is raising $1,300 toward a Mac and an iPhone, so the Trace apps can run properly on iPhone.