Repository navigation
Releases: cyberpapiii/plug
Release list
plug v0.11.0
Added
- A client can be given only the servers you pick. Switch off "Adopt Newly
Added Servers" under Settings on a client's page and a server you add later stays off for that client
until you turn it on; what the client gets today does not change. The
same from the command line withplug clients only <client> --server <name>or--tool <name>, and--offto end it. - Clients lists a client that connects, makes its calls, and leaves again,
such as a script on a timer. It shows where it runs, with "Last used" and
the time, and can be named, given an icon, and kept from servers and tools
like any other client. It stays listed while its last call is in Activity. - Plug's menu bar icon is there whenever Plug is serving. It comes back on
its own when something else closes the app (a quit-all, a crash, a force
quit) and appears after login. Settings has a "Keep in Menu Bar" switch
for it, on by default. - Settings has a Permissions section: whether macOS lets Plug run in the
background, open at login, and send notifications, with the way to System
Settings beside anything that was turned off there. - A server whose tools Plug splits into groups says so on its page: a
Clients See row lists the groups, such as Gmail, GoogleDrive, GoogleSheets. - A Google Workspace server gets its Gmail, GoogleDrive and other groups
under any name you give it, not onlyworkspace: Plug goes by what the
server says it is. - Two servers that would give a tool the same name no longer leave only one
of them. Each gets its own name added to the prefix, so two Google servers
show asGmailWorkspace__…andGmailGoogleWork__…. - A client kept from a tool is no longer sent that tool's results through
an event watch. Listing, subscribing and delivery all check the tool, and
an event already queued is dropped when the tool is blocked. - A tool switched off, or kept from a client, stays that way when a second
account changes its name (Gmail__…toGmailWorkspace__…) and when that
account is removed again. - Two servers whose names differ only in punctuation (
google-work,
google_work) each get their own tool names; one is numbered. If two
servers still claim one name, the second is left out and the log says so,
instead of one silently replacing the other. - Codex CLI can be signed in again from its page in Plug: a Sign In button
runs its sign-in and opens the approval in your browser. Other clients
still sign in from inside themselves, and their page says how. - A client can be given a place: the computer it runs on, such as "Work
laptop". Its page has a Runs On menu for it, and clients with a place are
listed under it. The rest stay under On This Mac and Over the Network.
Activity andplug clientsshow the place beside the client's name, and
plug clients place <client> <place>sets it from the command line. - Each server's page has a Settings row that says where the server's own
settings are and takes you there: the app it runs from, a file its
arguments name, the page it gave for itself, or Plug's own form. Plug
only uses what it already holds and never searches the disk. - Clients has an Add Client button. Pick any client (one on this Mac, one on
the web such as ChatGPT, one Plug cannot find, or one it has never heard
of) and how it connects, on this Mac or over the network. Plug sets up a
client it finds with one button; for any other it shows the command or
address to paste, alone or as a whole settings entry. A client Plug has never
heard of can be given a name and an icon there, which it shows under from
its first connection. - A client whose sign-in to Plug ended says "Needs sign-in" in Clients, with
how to sign it in again, and Plug sends a notification when it happens.
plug auth clients listsays so too.
Changed
- Clients distinguish missing local configuration from hosted access. Network
authorization details show the local HTTP clients represented by that row,
including Codex CLI, without implying an active connection. - A client you name after one Plug knows takes that client's icon: a second
Cursor sign-in renamed "GrokBot" shows Grok Bot's icon, not Cursor's. - Activity shows each call under the name you gave the client that made
it. Two sign-ins that both report "Cursor" are told apart from then on;
calls recorded before this stay as they were. - Quitting Plug asks first. "Quit" closes the app and leaves Plug serving,
with the icon away until Plug is opened again; "Turn Plug Off and Quit"
stops it. Before, quitting left Plug serving without saying so.
Fixed
- Two scripts started the same way from different folders, such as
python3 main.py, are two clients. They were one, sharing a name and
what they were kept from. - A script that connects on this Mac is called by its own name, or by its
folder when the file is amain.py. It showed aspython3ornode,
the same as every other script. - A task's large result is kept with the tool the task ran, so a client is
kept from it only when it is kept from that tool. A client with a block on
anything used to be refused every such result. - A network client's open session ends when its sign-in runs out, not only
when the sign-in is revoked. - The menu bar panel and Activity show a client's icon wherever the
Clients list does: a network client that says nothing about itself is
pictured by its sign-in's name in the panel too, and ChatGPT is found by
the app OpenAI ships now, whatever the owner named it. - A tool switched off for one client is stored by its server and that
server's own name for the tool, so renaming the tool or its server's
prefix cannot switch it back on. Blocks written the old way, by listed
name, are brought over the first time Plug sees the tool, and a rule
with*in it now also holds for a tool that was renamed out from under
it. A large result kept on disk follows the same block whatever the tool
was called when it was kept. - A client kept from a server no longer hears about that server's sign-in,
and a local client kept from a server gets no log lines, as a remote one
already did. - A remote session ends when the sign-in it was opened under is revoked,
not only when the client is removed, and nothing more is sent to it. - A secret command's helper left holding only the error output is stopped.
- An environment entry named like another entry's stored key (
env.token
besidetoken) gets its own stored key. - A watch check that was waiting its turn no longer runs after the watch is
removed or while Plug is shutting down. - Servers whose names read alike are numbered around names already in use,
so a numbered name can no longer land on another server and hide its tool. - A remote client's open session ends when its sign-in does, however that
happened, including a removal whose save failed. A client newly kept from
a server stops getting log lines on a stream it already had open. - A watched tool that is slow to answer no longer delays the next check of
the other watches, and is not called again while still answering. - A secret command that runs past its time is stopped together with
anything it started, and one that prints without end is cut off. - Updated
rustlsto 0.23.45 or later for RUSTSEC-2026-0285. - A server's bearer token and an environment entry named
tokenno longer
share one stored key, and a refused change puts each key back exactly as
it was. A whole server change, keys included, now happens one at a time,
so two changes at once cannot undo each other's keys. - A watch calls a tool on a timer only when the server itself marks the tool
read-only. A tool the server says nothing about needsallow_writes, as a
writing tool does; before, a harmless-looking name was enough. - A large result Plug set aside stays out of reach of a client kept from its
server or tool even after the tool is renamed or the server is removed. - Saving the config writes servers in name order, so the file no longer
reshuffles on every save. - Setting up a client whose config file is YAML that cannot be read leaves
the file alone and says so, where before Plug wrote a fresh file over it. - One watched tool that is slow to answer no longer holds up the other
watches that are due with it. - A secret store command that leaves a program running behind it no longer
hangs the read; it stops at the store's time limit. - A client kept from a tool can no longer read a large result of that tool
that Plug set aside as a file. - An API server's key is not sent on when the API redirects to another port
or from HTTPS to plain HTTP on the same host. Plug also stops reading an
API response, or an API description, once it passes the size limit, where
before it read the whole thing first. - Removing a client's access ends the sessions it has open, where before an
open stream stayed up until it timed out. A session answers only to the
client that opened it. - A client kept from a server no longer receives the log lines servers send.
- A server change that is refused, such as adding a server under a name
already taken, no longer replaces the key the existing server works with. - Removing a server keeps a stored key that another account of it still
uses; the key goes when the last one does. - Two servers whose names differ only in punctuation, or a server with a
very long name, no longer share one stored key. Keys already stored keep
their names. - Watching a tool for change follows what the server says about it: a tool
the server marks as writing is not called on a timer because its name
reads as harmless. - A client that runs as several processes keeps its sign-in. Each holds
the copy of the stored token it started with, so one renews and another
presents the used copy later; before, that one was taken for a thief and
the whole sign-in was revoked, which kept...
plug v0.10.0
Changed
- The menu bar icon is a plug, where it was a lightning bolt. It is solid
when everything runs and an outline when Plug is off, and carries a small
badge when Plug is starting, needs attention, or cannot run. The same plug
stands for Plug in the window. - The menu bar panel shows connected clients with the names and icons the
Clients list gives them. A client known only by its link, or one that
signed in over the network, showed there as a blank tile. - The window is laid out like a Mac app. A sidebar on the left lists Servers,
Clients, Events, and Activity. Every section is a list with the selected
item's details beside it, where before each section had its own layout:
cards, popovers, and rows that opened in place. - The window has three columns: the sidebar, the list, and the selected
item. macOS draws the bars and the dividers between them, so the top bar
and the lines between the columns no longer look broken. - Servers and clients show icons. A server named for an app on this Mac
shows that app's icon, and so does a client connected over the network.
Anything else gets a tile with its first letter. A server's state shows as
a dot on its icon, and in the list only when it needs attention. - The buttons at the bottom of the menu bar panel have icons again.
- An icon that arrives with an empty margin of its own is no longer shown small on a white tile.
- A server that runs as a local command, and a client with no app, find an icon too: from its maker's web site when its name carries a known one (Oura, Python, Stripe, and about eighty more), and for a server started with
npxoruvx, from the site or the owner its package names. Goose and Qwen Code ship a logo. - Servers and clients find their own icons. A server shows the icon it offers for itself, the app it runs inside, or the icon of its own web site, asked for only over HTTPS at the server's own address. Eight command line clients with no app, among them Gemini CLI, Copilot CLI, OpenCode, and Pi, show a logo that ships with Plug. Right-click any server or client and pick Choose Icon to use a picture of your own.
- Each call in Activity shows two icons, the client and the server it
called, and a failed call is marked beside its time. - Settings is its own window, on Command-comma and from the menu bar panel.
It is no longer a tab in the main window. - Lists and detail panes use the system's own list and form styles, so
spacing, selection, and text sizes match the rest of macOS in light and
dark. - The app uses the same words and the same buttons everywhere. A button
whose name ends in three dots asks before it does anything; the others act
at once. Titles, empty lists, and error messages follow one style. - Each client is one row, however many connections it has open. A green dot
marks the ones connected now, and the two groups are On This Mac and Over
the Network. - Empty lists and problems are clearer. An empty section says what belongs
there and offers the next step. A problem says what went wrong and what to
do, and a call the client stopped is no longer shown as a failure. - The menu bar panel is simpler: the headline, your servers with a fix beside
any that need one, who is connected, recent activity, and three plain
buttons for Open Plug, Settings, and Quit Plug. - Settings is shorter. Open at Login, Notifications, and automatic updates
are together at the top, and the checkup sits with the Plug switch. - Rename a client by typing in its Name field. Leave the field empty to go
back to the client's own name. - Editing a server moves a key that was still written in the settings file
to the place keys are kept, where before it stayed in the file until
plug secret move.
Added
- Muse, Meta's agent, is named and pictured when it connects as a remote
client. It is a different client from Muse Code, the command line tool. - Plug links four more clients: Amp, OpenClaw, LM Studio, and Muse Code.
plug link,plug import, repair, andplug doctorknow where each
keeps its servers. The paths come from each maker's documentation; none
was installed to try. - Menus and shortcuts. File has Add Server (Command-N), Import Servers
(Shift-Command-I), and Watch a Tool (Shift-Command-N). View has the four
sections on Command-1 to Command-4, Refresh on Command-R, and the sidebar
toggle. Help has How Plug Works, Run Checkup, and Show Logs in Finder. Check for
Updates is in the Plug menu. - A client can be kept from single tools in the app. In a client's details,
open a server to see its tools, each with its own switch. A tool that a
rule written withplug clients blockturns off says so and is changed
there. - Choose where a server's keys are kept. The form for adding or editing a
server has Keep Keys In, with the Keychain and Plug's.envfile. A key
from 1Password is used by typing where it is, such as
op://vault/item/field, in place of the key. - Delete removes the selected server, after asking. Remove Server is also in
a server's right-click menu.
Fixed
plug clientsnames a remote client it does not recognise after the name
it signed in under, as the app does. It showed as Unknown.- Linking or unlinking a client whose settings file is not plain JSON, such
as one with comments, no longer replaces the file with only Plug's entry.
Plug leaves the file alone and says so.
plug v0.9.0
Added
-
Activity rows open. Click a call to see the tool, the server, the client,
when it ran, how long it took, and whether it worked. A failed call says
why, in the error's own words, and what to do next. The reason is kept for
calls made after this update, cut to 240 characters. -
Add Server starts from a list. Pick Notion, Linear, Atlassian, Asana,
Sentry, Stripe, Vercel, Cloudflare, Canva, Intercom, or Context7 and Plug
fills in the rest and asks you to sign in; a server Plug already has is not
offered again. Pasting a setup block, a command, or an address still works,
one step below the list. -
A server's key can live in the Keychain instead of in
config.toml.
plug secret set <name>asks for the value without showing it, or takes it
from a pipe, and stores it; the server then sayskeychain:<name>where the
key used to be, as its bearer token or as the value of one of itsenv
entries. Only the service reads the value, when it starts that server. A
server whose secret is missing says so inplug statusand the others start
as usual.plug secret rm <name>removes one. -
A server's key can also come from 1Password, from Plug's
.envfile, or
from any other password manager.op://vault/item/fieldasks the 1Password
command-line tool;file:<name>reads the.envfile, and
plug secret set --store file <name>writes it. Any other tool is three
lines under[secrets.stores.<id>]: acommandwith{name}where the
secret's name goes, and<id>:<name>runs it. A store that locks after a
server started does not stop that server: Plug keeps the value it read, in
memory only, and uses it until the store answers again. -
Skills served over MCP keep their server's name. A
skill://resource
from a server reaches every client asskill://<server>/…, in the
resource list, in reads, in update notices, and in tool results, so two
servers with a skill of the same name no longer collide and a client can
tell where a skill came from. A skill file that is not listed is read
through its server's name, and a URI written without the name still works
when one server serves it. -
A key typed into Plug goes to the Keychain on its own. Adding or editing a
server in the app or withplug server addstores its token, and anyenv
entry whose name says it is a credential, in the Keychain and writes
keychain:<server>.<field>toconfig.toml. Removing the server, or the
token, removes the stored value. A machine with no credential store keeps
the key in the file as before. -
plug doctorand the app's checkup name the keys still written in
config.toml, andplug secret movemoves them all to the Keychain. -
Plug can watch a tool and tell a client when its result changes. Add an
[[events.watch]]entry naming a server, a tool, and how often to check, and
the event<server>.<name>appears to remote clients that support MCP
Events. Plug only watches tools their server marks read-only unless the
watch saysallow_writes = true, sends nothing for the first result, and
keeps a client away from the events of a server it is kept from. See
docs/events.md. -
plug eventslists every watch with when it was last checked, when it last
changed, and how many clients listen.plug events watch <server> <tool>
adds one and says at once when the tool does not exist or is not read-only;
plug events unwatch <event>removes it. -
The app has an Events tab. It lists every event with how it is doing in one
sentence and how many clients listen. Watch a Tool asks for a server, a
tool, and how often to check; it offers only the tools the server marks
read-only unless you ask for the rest, and Stop Watching removes a watch. -
The app has a first-run guide. On a Mac with no servers it opens by itself
once; after that the question mark in the toolbar opens it. It shows Plug's
two sides in one picture and walks three steps, add a server, connect a
client, use a tool, each with the button that does it and a tick when it is
done. Copy Setup Prompt puts instructions on the clipboard that an agent can
follow to set Plug up; the same text isdocs/guides/agent-setup.md. -
A server can have a second account.
plug server add-account <server> <account>and Add Another Account in a server's menu add the same server
again as<server>-<account>, with the same settings. An OAuth server's
copy starts signed out and signs in with the other account; any other copy
keeps the same credentials until you edit it. Tool groups carry the account
in their name, soGmailandGmailPersonalsit side by side. -
The Clients tab chooses which servers each client can use. Every client that
uses Plug has a button that opens its servers with a switch each, and a
client kept from something says so in its row. The popover says plainly that
for a client on this Mac this keeps the list short and is not a lock, while a
remote client is held to it. -
A client kept from a server stops hearing that server's resource updates,
even for a subscription it made before the block. Lifting the block brings
them back. -
A client kept from a server is kept from all of it. Its resources, resource
templates, and prompts leave that client's lists, and reading one, getting
one, completing against one, or subscribing to one answers as if it did not
exist. Before, a block covered the server's tools only. -
Pi, Warp, and Kiro are clients.
plug link pi,plug link warp, and
plug link kirowrite each one's own MCP file, the Clients tab lists them,
andplug importreads servers from them. -
GitHub Copilot CLI is a client.
plug link copilot-cliand the Clients tab
write~/.copilot/mcp-config.jsonwith thetypeandtoolsfields Copilot
CLI requires, andplug import copilot-clireads servers from it. -
Every request knows which client sent it.
plug connect --client <target>
says which link started the connector, so a client is placed by how it was
linked rather than by the name it reports; a remote request is placed by its
grant, and requests on the shared token share one key. Nothing acts on the
key yet: it is the ground per-client access stands on. -
plug linkand the Clients tab writeconnect --client <target>into a
local link, so a client whose own name Plug does not recognise (Pi, Warp,
Kiro, Kilo Code) shows under its real name and icon. Links written before
this keep working unchanged; link the client again to pick it up. -
A client can be kept from a server or from single tools. Under
[clients."<key>"]in the config,blocked_servers = ["slack"]and
blocked_tools = ["github__delete_*"]take those tools out of that client's
list and make a call to one answer as an unknown tool, by any route: a
direct call, a task, tool search, or the invoke wrapper. The key is the one
plug clients -vshows. A change applies on config reload, and connected
clients are told their tool list changed. For a local client this keeps a
tidy tool list, it is not a security boundary: any program running as you
can link itself under another name. For a remote client the key is its
verified grant. -
plug clients block <client> --server <name>and--tool <name>keep a
client from a server or a tool, andplug clients unblocklets it back in.
The client is picked as inplug clients rename: by the name it shows
under, or by its key. It applies at once, without a reload, and
plug clientslists who is kept from what. -
An unknown local client started by an interpreter is told apart by the script
it runs. Two tools that both run underpython3ornodeare now two
clients, each with its own name. A name given to such a client before this
change no longer applies; rename it once more. -
A remote session knows the grant it came in on. Clients names a remote
client Plug does not recognise after that grant, shows the matching app's
icon when the Mac has one, and lets it be renamed from its own row; the name
is stored under the grant, so it follows the client across sessions.
plug clients -vlists the session's key asoauth:<client id>. -
A client can be renamed. Clients has a pencil on every remote client and on
every local client Plug can tell apart, andplug clients rename <client> "<name>"does the same; an empty name goes back to the one Plug works out.
The name is kept in[clients."<key>"]in the config, under the client's
target, the program that started it, or its grant, never under the name it
reports.plug clients -vlists each key. -
A local client Plug does not recognise is named after the program that
started it.plug connectreads its parent from the process table, looking
past shells and launchers, and reports it when it registers; Clients shows
that app's name and icon in place of "Unidentified local client", and
plug clientslists it under that name. A client cannot choose this name,
unlike the one it sends ininitialize. -
Opt-in Slack event delivery. With
[http.slack_events]configured, Plug
receives Slack's Events API at/events/slack, keeps coworker mentions of one
Slack user and replies in those threads across public channels, and delivers
each asslack.ditto_messageto one chosen downstream OAuth client through
modern MCP Events (events/list,events/subscribe,events/unsubscribe,
scopeevents:subscribe). Callbacks are verified and signed, subscriptions
and the retry queue survive restarts, and the Slack signing secret is entered
at a hidden prompt (plug auth slack-events set) and kept in the Keychain.
Off unless configured; Slack only. Seedocs/slack-mcp-events.md. -
owner_proof_untillets the owner prove Slack event delivery alone for up to
one hour by sending one exact test marker. Every other owner message stays
excluded. -
Grok Build is a client.
plug link grok-buildwrit...
plug v0.8.13
Changed
-
The menu bar panel has a Plug on/off switch, separate from Quit. Turning
off confirms that connected apps lose access, stops the app-owned background
service, and stays off across launches. Turning on restores the service.
Quit only closes the menu bar app and leaves a running service alone.
Recent-call durations keep their full width beside long tool names. -
Apps uses the current session list for connected state and counts. A stale
app scan no longer invents a connected app or keeps an old session count. -
The window has three sections: Servers, Apps, and Activity. Tools moved
into the server they belong to: Servers shows the list on the left and the
selected server in full on the right, with its tools and their switches.
Searching in Servers finds tools as well as servers, and clicking a tool
shows its details beside it. A server's header carries Restart, Edit, and
an on/off switch. Connections is now called Apps. -
Apps groups by what matters first: Connected now, On this Mac, and Remote
clients. A connected app opens to show each of its sessions with its id,
how long it has been open, and how many tools it can reach. A remote
client shows the site it signs in from, or a short id, in place of its
registration method. -
The menu bar panel lists the three most recent tool calls, with the server,
the outcome, and how long each took. Clicking them opens Activity.
plug v0.8.11
Added
scripts/dev-install.shbuilds Plug.app from the working tree, signs it with
the Developer ID already in the login keychain, and installs it in place.
About two minutes cold and seconds warm, with no network, notarization,
version bump, or commit. It stamps the current time as the build number so
the app replaces its own daemon and Sparkle never offers a downgrade. This is
the loop for trying a change on this Mac; releases stay onrelease.sh.
Changed
- The development gate is lighter. Five CI jobs that gated nothing for a
single-developer tool (MSRV check, cargo deny, a macOS duplicate of the
Linux tests, a cross-compile check, and a binary-size ceiling) are gone,
along with the disk-space guard that ran on every commit, checkout, merge,
and push. The app test lane builds once instead of twice. Ten scripts that
nothing ran, seven of them tests of other scripts, are deleted, and the
oldplug-devpath (dev-reinstall.sh,setup-codesigning.sh) retires in
favor ofdev-install.sh.plug doctorpoints at the new loop. - Releases ship the macOS app only. The four Linux tarballs, the cargo-dist
shell installer, the source tarball, and theplugHomebrew Formula are no
longer built; Linux users build from source withcargo install, and the
tap's formula stays at 0.8.10. GitHub release notes are now the matching
CHANGELOG.mdsection instead of agit-cliffrendering of commit
subjects. The release build restores its Rust cache from a job that runs
on every push tomain, where before it compiled cold on every tag. scripts/ship.shreturns tomainafter arming auto-merge and steps off a
ship branch whose pull request already merged, so a follow-up change can no
longer be pushed onto a dead branch.scripts/release.shthen waits until
that prepare pull request actually lands before tagging, instead of treating
the return tomainas proof the version bump is already there.- The repository's agent and contributor instructions collapse into one short
CLAUDE.md;AGENTS.mdpoints at it. The project-state snapshot, plan,
truth rules, workflow model, per-change doc-update checklists, finished
todos, plans, brainstorms, research, solution write-ups, audits, and
per-version release-notes files move underdocs/archive/. Open work now
lives indocs/STATUS.md;CHANGELOG.mdis the only change record. - Each app section now opens with one page header that carries its title, a
live summary, and the section's controls, so the window toolbar holds only
search. Loading and unavailable states share one look, and every section has
a retry. - The menu bar panel closes itself before opening a window, sheet, or
inspector, so it no longer floats above what it just opened. Its attention
list and footer sit in glass containers on macOS 26, animations respect
Reduce Motion, and troubled servers no longer count twice. - Accessibility labels, header traits, and named actions cover the tool list,
server list, connections, settings, and the menu bar panel. plug clientslists Devin under its current name while keeping the Windsurf
config target it still reads, and no longer lists RooCode.
plug v0.8.10
plug v0.8.9
plug v0.8.8
[0.8.8] - 2026-08-31
Bug Fixes
- connect: Exit on a daemon upgrade so the host respawns the client (#166)
plug v0.8.7
[0.8.7] - 2026-08-31
Bug Fixes
- downstream-oauth: Let the issuer state lock outlast a departing writer (#164)