Skip to content

Releases: beyondhumane/tunnel-agent

Tunnel Agent 1.1.12

Choose a tag to compare

@github-actions github-actions released this 03 Oct 18:03

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Security

  • Perplexity account backups kept forever and readable by other users (AccountService, CredentialBackups): removing a Perplexity account (or resetting all of them) copied its session token into .backup/ inside the accounts folder with default permissions and never deleted it. These backups now go to the same credential-backups/{timestamp}/perplexity/ folder as the CLIProxyAPI ones, with owner-only permissions (0700 folder, 0600 file), and are deleted after 7 days; old backups left in .backup/ are locked to the owner (0700) and deleted after 7 days too. Account files are now created as 0600 inside a 0700 folder.

What's Changed

  • feat(site): add landing page and documentation site by @Villoh in #74
  • feat(site): add motion across the landing and docs by @Villoh in #75
  • fix(perplexity): store account backups in credential-backups with owner-only permissions and 7-day retention by @Villoh in #76
  • chore: release 1.1.12 by @Villoh in #77

Full Changelog: v1.1.11...v1.1.12

Tunnel Agent 1.1.11

Choose a tag to compare

@github-actions github-actions released this 03 Oct 09:39

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Fixed

  • Quota "authentication token is unavailable" with newer CLIProxyAPI auth files (OAuthTokenDetector, QuotaFetchService): CLIProxyAPI now names token files {provider}-{id}-{email}[-{plan}].json (e.g. claude-f9c692a7-me@example.com.json), so the Claude and Codex quota readers, which looked for {provider}-{email}*.json, no longer found the token of a signed-in account. Token files are now matched by their JSON email field (falling back to the exact legacy filename), the plan badge is read from both filename formats, an account whose email is a prefix of another's (a@x.com / a@x.com.au) no longer also matches the other one's file when disabling or removing it, and a file without an access token no longer stops the search.
  • OAuth login failures reported as "browser opened" (OAuthService, MainWindowViewModel): CLIProxyAPI exits 0 when a login fails (cancelled in the browser, callback timeout, failed code exchange), and its output was only read during the first second. The app now waits for the login process to exit and, if its output reports authentication failed or no token file was written or rewritten, shows the binary's last output lines as an error (a failed login running alongside another provider's login is shown once that login's toast closes). The sign-in toast now closes when that login finishes instead of on any write to the provider's token files (e.g. a token refresh), a sign-in URL printed after the first second is still shown, stderr is captured, starting a login only cancels a running login of the same provider, and the Codex login no longer gets an automatic empty line on stdin after 12 s.
  • Accounts sharing an email collapsed into one (OAuthTokenDetector, ProviderCatalogService, QuotaFetchService): CLIProxyAPI writes one token file per Claude organization or Codex workspace, but accounts were keyed by email, so they showed as a single row, disabling or removing one also hit the others, and quota used whichever file was found first. Accounts are now keyed by token file (Claude, Codex, Devin, Antigravity, xAI); rows sharing an email show the organization name (or file id), and disable, remove and quota act on that file only. When a row's file is replaced by another one with the same email, its old quota, plan and resets are cleared and re-fetched.

Security

  • Removed OAuth credentials kept forever in backups (ProviderCatalogService): credential files copied to credential-backups before removing an account, disconnecting or resetting are now deleted after 7 days (checked at startup and on each removal), a second backup of the same file no longer overwrites the first, and on macOS/Linux the backups are only readable by the user.

What's Changed

  • fix(quota): find token files with CLIProxyAPI's hashed filenames by @Villoh in #71
  • fix(oauth): report failed logins, key accounts by token file, expire credential backups by @Villoh in #72
  • chore: release 1.1.11 by @Villoh in #73

Full Changelog: v1.1.10...v1.1.11

Tunnel Agent 1.1.10

Choose a tag to compare

@github-actions github-actions released this 02 Oct 16:14

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Fixed

  • Claude quota stuck on HTTP 429 (QuotaFetchService, ProviderViewModel, QuotaView, TrayUsagePopup): Claude usage is fetched at most once every 5 minutes per account (manual refreshes reuse the last result inside that window, and overlapping refreshes share one request), and after a 429 the app waits for Retry-After (or 5 minutes) before calling the API again instead of retrying on every refresh and extending the limit. While rate limited, the last good bars stay visible with a "showing the last values, retrying in ~N min" notice instead of being cleared; the cache is dropped after using a saved reset or when the account's token changes. Claude OAuth requests now identify as Claude Code (claude-cli/… (external, cli)), which Anthropic also uses to decide whether saved limit resets are returned.

What's Changed

  • fix(quota): throttle Claude usage calls and keep last values on 429 by @Villoh in #69
  • chore: release 1.1.10 by @Villoh in #70

Full Changelog: v1.1.9...v1.1.10

Tunnel Agent 1.1.9

Choose a tag to compare

@github-actions github-actions released this 02 Oct 14:39

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Added

  • Claude saved limit resets ("Reset for free") (QuotaFetchService, ProviderViewModel, QuotaView, MainWindowViewModel): Claude accounts with a saved reset now show the same collapsible "Usage limit resets" section as Codex, listing each grant (title + expiry) with a "Use reset" button. Grants that can only be spent once a limit is hit are listed with the button disabled. Uses the same Anthropic endpoints as Claude Code's /limit-reset; consuming one re-fetches usage so the bars update immediately. The Codex reset view model and strings are now shared between both providers.

What's Changed

  • feat(quota): add Claude saved limit resets to Quota window by @Villoh in #67
  • chore: release 1.1.9 by @Villoh in #68

Full Changelog: v1.1.8...v1.1.9

Tunnel Agent 1.1.8

Choose a tag to compare

@github-actions github-actions released this 30 Sep 18:37

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Fixed

  • Linux environment variables stored outside the app settings folder (UnixUserEnvironmentService): variables are now persisted in ~/.config/TunnelAgent/environment, next to the rest of the app settings, instead of the lowercase ~/.config/tunnelagent/. The old file is moved on startup with permissions set to 600, and the ~/.profile hook is updated where it already sits so the order of your own exports doesn't change. If the move fails, the app keeps using the old file instead of failing to start.
  • Empty CLIProxyAPI API-key list when the settings folder isn't writable (MainWindowViewModel): the key from TUNNEL_AGENT_CLIPROXY_API_KEY is shown even when it can't be copied into proxy-config.yaml.

What's Changed

New Contributors

Full Changelog: v1.1.7...v1.1.8

Tunnel Agent 1.1.7

Choose a tag to compare

@github-actions github-actions released this 29 Sep 08:18

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Added

  • Devin OAuth provider (OAuthService, OAuthTokenDetector, ProviderCatalogService, ProviderIconRegistry, ProviderViewModel, ModelFetchService): connect Devin (Cognition) through CLIProxyAPI's -devin-login flow. Detects devin-*.json auth files, shows the Devin brand icon from @lobehub/icons, and labels cognition-owned models as Devin/OAuth.
  • Devin quota (QuotaFetchService, QuotaView, MainWindowViewModel): new Devin tab after Codex showing daily/weekly quota, plan badge, and extra-usage balance via Devin's GetUserStatus Connect-RPC endpoint, using the CLIProxyAPI session token.
  • Meta (Muse Spark) CLIProxyAPI provider (OAuthService, OAuthTokenDetector, ProviderCatalogService, ProviderIconRegistry, ProviderViewModel, ModelFetchService): connect Meta accounts via CLIProxyAPI's -meta-login device-code flow; meta-*.json credentials are detected, toggled and removed like other OAuth providers. Account lookups also match by the JSON email field because Meta sanitizes the email in the filename. Brand icon from @lobehub/icons.

What's Changed

  • chore: Bump the nuget-packages group with 3 updates by @dependabot[bot] in #55
  • chore: Bump the avalonia group with 5 updates by @dependabot[bot] in #56
  • chore: Bump the nuget-packages group with 6 updates by @dependabot[bot] in #58
  • feat: add Devin provider and quota by @Villoh in #62
  • chore: Bump Velopack from 1.2.0 to 1.2.158 by @dependabot[bot] in #61
  • chore: Bump the nuget-packages group with 2 updates by @dependabot[bot] in #60
  • feat: add Meta (Muse Spark) CLIProxyAPI provider by @Villoh in #64

Full Changelog: v1.1.6...v1.1.7

Tunnel Agent 1.1.6

Choose a tag to compare

@github-actions github-actions released this 26 Aug 10:08
814b595

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Added

  • Management key visibility toggle (ConfigurationView, MainWindowViewModel): the management key field is masked by default, matching every other credential input in the app, with an eye/eye-off button to reveal it.
  • Codex saved rate-limit resets ("banked resets") (QuotaFetchService, ProviderViewModel, QuotaView, MainWindowViewModel): Codex accounts on an eligible plan can bank an early reset of the current usage window. Quota now shows a collapsible "Usage limit resets" section per account listing every redeemable reset (title + expiry) with a "Use reset" button; consuming one re-fetches usage so the bars update immediately. Calls ChatGPT's own backend directly, independent of CLIProxyAPI.

Fixed

  • Management key row broke on narrow panels (ConfigurationView): the control group (field, eye, copy, regenerate, apply) wrapped onto a new line instead of squeezing the label down to one character per line on narrow windows.
  • Credential backups showed up as accounts in CLIProxyAPI's own management UI (ProviderCatalogService): resetting, disconnecting, or removing an OAuth account backed up the deleted token file to .tunnelagent-backup\ inside auth-dir — the exact folder CLIProxyAPI scans for its management.html credential list, so old backups appeared there as extra accounts. Backups now go to LocalDataDirectory\credential-backups\ instead, outside auth-dir.

Full Changelog: v1.1.5...v1.1.6

Tunnel Agent 1.1.5

Choose a tag to compare

@github-actions github-actions released this 26 Aug 08:00
1bde596

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Added

  • Editable management key (ConfigurationView, MainWindowViewModel): the management API / control panel password (ManagementKey) can now be copied, typed in directly, or regenerated to a new random value from Configuration → CLIProxyAPI → Security. Any change rewrites proxy-config.yaml and restarts CLIProxyAPI if it's running.

Full Changelog: v1.1.4...v1.1.5

Tunnel Agent 1.1.4

Choose a tag to compare

@github-actions github-actions released this 26 Aug 07:23
e63602a

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Added

  • CLIProxyAPI web control panel toggle (ConfigurationView, MainWindowViewModel, ConfigService): a new setting under Configuration → CLIProxyAPI → Security lets you serve the management page (management.html) on the proxy port instead of always disabling it. Toggling restarts CLIProxyAPI if it's running.

Full Changelog: v1.1.3...v1.1.4

Tunnel Agent 1.1.3

Choose a tag to compare

@github-actions github-actions released this 17 Aug 09:22
b0972a7

Installation

Platform Installer Portable
Windows x64 Setup.exe .zip
Windows arm64 Setup.exe .zip
Linux x64 .AppImage · .deb · .rpm —
Linux arm64 .AppImage · .deb · .rpm —
macOS x64 (Intel) .pkg .zip
macOS arm64 (Apple Silicon) .pkg .zip

Existing installations update automatically via Velopack.


Changed

  • Sidebar submenu chevrons (MainWindow.axaml, Controls.axaml, FallbackView.axaml): Quota and Fallback arrows now use the primary foreground color and rotate 90° with the same 0.18s CubicEaseOut transition as virtual-model expanders, instead of swapping muted right/down icons.

Fixed

  • Icon buttons flashed a gray fill on click (Controls.axaml): Fluent's pressed state still painted a background on icon / icon-btn controls. Press now stays transparent like the theme toggle, while scale feedback and the current pagination highlight are unchanged.
  • Sidebar selection pill shifted after collapsing Quota or Fallback (MainWindow.axaml.cs): collapsing a submenu after moving to another section left the accent pill on a stale Y and sometimes indented by the child margin, so hover/selection looked offset (e.g. on Configuration). The pill now stays full-rail width, X is pinned to 0, and it is remeasured after the submenu layout settles.

What's Changed

  • fix: keep sidebar pill aligned after collapsing submenus by @Villoh in #52
  • fix: keep icon buttons transparent on press by @Villoh in #53
  • Make sidebar chevrons white with rotate transition by @Villoh in #54

Full Changelog: v1.1.2...v1.1.3