Skip to content

v1.1.0

Choose a tag to compare

@WebTigers WebTigers released this 11 Sep 05:49
· 8 commits to main since this release

The agent handshake. A browser-aware AI client can now drive the installer and be handed a working, scoped credential at the end — without weakening a single default.

Machine-readable state on every screen

Every page carries a JSON block so a client can tell where it is and whether the last action worked, without scraping prose:

<script type="application/json" id="tiger-install-state">{ "step": "...", "status": "..." }</script>

status alone answers "did that work?" — blocked (an unmet requirement), error (retryable, with a stable slug), ok (only on finish). The requirements step reports each check with ok / required / fix.

The connect handshake

A fresh Tiger is deliberately unreachable by an agent: /mcp is off and tokens are normally minted by an authenticated admin. The installer's finish step is the one moment a human is present, authenticated, and making a deliberate choice — so that is where the credential is handed out.

Tick "Let the assistant that installed Tiger manage it" on the admin step. It can be pre-ticked with ?agent=1, but it is always visible before you submit and can be turned off. On success the finish screen shows a scoped key once, and the state block carries it alongside the /mcp endpoint and the /mcp/admin URL where it can be revoked.

Scope is the curated starter set, org-scoped. tiger.api.discovery is untouched. There is no callback URL — the key appears on the installer's own screen and nowhere else.

If the box is not ticked you get exactly today's defaults, and the screen tells you how to enable it later.

Also

  • CI: lints on PHP 8.1–8.5, the range a cPanel host is likely to offer, plus 61 assertions guarding the installer's invariants — one file, no dependencies, no shell calls, and no callback field of any kind.
  • Release artifacts are now built by CI rather than assembled by hand.