Skip to content

Releases: dfinity/imcp2

v0.5.1

Choose a tag to compare

@aterga aterga released this 24 Sep 13:16
8ccbd25

What's Changed

  • Probe production health every 8 hours instead of every 15 minutes by @aterga in #201
  • build(deps): Bump rmcp from 1.7.0 to 2.1.0 by @dependabot[bot] in #193
  • Make the CIMD switch a McpConfig field, on by default; OAUTH_CIMD_ENABLED becomes a kill switch by @aterga in #203
  • Ship a Claude Desktop bundle with every local-MCP release, and explain the install scripts by @aterga in #202
  • Bump the crates to 0.5.1 by @aterga in #205

Full Changelog: v0.5.0...v0.5.1

release-2026-09-24-0.5.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 10:48
ddcdc56

Rolled out to production.

Commit ddcdc56d624f1b0751bf4ddbc2df6bf22a31d5fd
Target linux/arm64 (Amazon Linux 2023, Graviton)
Run 35988964617

The attached binary is the one that was shipped: the deploy asserts
GET /version on the host reports this commit before the run is allowed
to pass. Verify with sha256sum -c imcp2-linux-arm64.sha256.

imcp2-local-v0.5.1

Choose a tag to compare

@github-actions github-actions released this 24 Sep 14:51
8ccbd25

What the install scripts below do: each downloads the imcp2-local binary for your platform from this release, installs it plus an auto-updater into ~/.cargo/bin, and adds that directory to your PATH — the shell script by appending a line to every shell profile it can find, the PowerShell script by editing your Path registry key. The shell script also compares a checksum baked into itself, but where sha256sum is missing (older macOS releases, for one) it prints a one-line "skipping" notice and installs anyway; the PowerShell script does not check one at all. Where that shell checksum does run it ships inside the very script being piped to a shell, so on either platform it is the archive's attestation that establishes provenance, checked against this release's own tag as the README's verified install does. IMCP2_LOCAL_NO_MODIFY_PATH=1 and IMCP2_LOCAL_DISABLE_UPDATE=1 opt out of the PATH edits and the updater.

Then connect it to your AI tool: imcp2-local setup registers the server with the clients on this machine — Claude Desktop, Claude Code, Codex, Cursor, Antigravity — and prints Perplexity's UI steps; imcp2-local setup --print shows each client's steps without writing anything, and imcp2-local setup --remove undoes them. Restart the client afterwards. On Claude Desktop you can skip both steps: double-click imcp2-local.mcpb from this release (it is not yet code-signed, so expect an unverified-developer warning). The README lists the per-client registration each one receives.

Install imcp2-local 0.5.1

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/dfinity/imcp2/releases/download/imcp2-local-v0.5.1/imcp2-local-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/dfinity/imcp2/releases/download/imcp2-local-v0.5.1/imcp2-local-installer.ps1 | iex"

Download imcp2-local 0.5.1

File Platform Checksum
imcp2-local-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
imcp2-local-x86_64-apple-darwin.tar.xz Intel macOS checksum
imcp2-local-x86_64-pc-windows-msvc.zip x64 Windows checksum
imcp2-local-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
imcp2-local-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo dfinity/imcp2

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

v0.5.0

Choose a tag to compare

@aterga aterga released this 24 Sep 06:50
6c12aec

What's Changed

  • Stop grading /version on the status dashboard by @aterga in #188
  • Accept ChatGPT's issuer-identification OAuth redirect by @aterga in #189
  • Check in rustfmt.toml and enforce formatting in CI by @aterga in #190
  • fix(local): drop the callback allow-list II can't fetch from loopback by @sea-snake in #172
  • Publish the status dashboard on staging only; point public status at status.internetcomputer.org by @aterga in #194
  • Cross-build from a bullseye snapshot: the live -security pool is gone by @aterga in #195
  • Submission docs: domain verification via the parent origin; drop stale redirect caveats by @aterga in #196
  • ci(health): pin the Internet Identity the production probe checks by @aterga in #197
  • Support Client ID Metadata Documents (CIMD) as a registration mode by @aterga in #191
  • Assert the /metrics 404 against Caddy on the host, not through the public name by @aterga in #198
  • Bump the crates to 0.5.0 by @aterga in #199

Full Changelog: v0.4.0...v0.5.0

release-2026-08-18-0.5.0-RC

Choose a tag to compare

@aterga aterga released this 23 Sep 15:51
d1983a2

What's Changed

  • Stop grading /version on the status dashboard by @aterga in #188
  • Accept ChatGPT's issuer-identification OAuth redirect by @aterga in #189
  • Check in rustfmt.toml and enforce formatting in CI by @aterga in #190
  • fix(local): drop the callback allow-list II can't fetch from loopback by @sea-snake in #172
  • Publish the status dashboard on staging only; point public status at status.internetcomputer.org by @aterga in #194
  • Cross-build from a bullseye snapshot: the live -security pool is gone by @aterga in #195
  • Submission docs: domain verification via the parent origin; drop stale redirect caveats by @aterga in #196
  • ci(health): pin the Internet Identity the production probe checks by @aterga in #197
  • Support Client ID Metadata Documents (CIMD) as a registration mode by @aterga in #191

Full Changelog: v0.4.0...release-2026-08-18-0.5.0

imcp2-local-v0.5.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 07:14
6c12aec

Install imcp2-local 0.5.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/dfinity/imcp2/releases/download/imcp2-local-v0.5.0/imcp2-local-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/dfinity/imcp2/releases/download/imcp2-local-v0.5.0/imcp2-local-installer.ps1 | iex"

Download imcp2-local 0.5.0

File Platform Checksum
imcp2-local-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
imcp2-local-x86_64-apple-darwin.tar.xz Intel macOS checksum
imcp2-local-x86_64-pc-windows-msvc.zip x64 Windows checksum
imcp2-local-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
imcp2-local-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo dfinity/imcp2

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

v0.4.0

Choose a tag to compare

@aterga aterga released this 02 Sep 22:24
eb5c31f

What's Changed

  • Point the operator-facing terms references at the App Operator Terms by @aterga in #182
  • Tolerate redirects in the status dashboard's landing-page check by @aterga in #181
  • Gate every canister-reaching tool on the discoverability manifest by @aterga in #184
  • Show staging and production side by side on the status dashboard by @aterga in #183
  • Bound the OQL schema reply and parse it once by @aterga in #187
  • Test the canister tools end to end, over MCP against a real replica by @aterga in #186
  • Bump to 0.4.0 by @sea-snake in #185

Full Changelog: v0.3.0...v0.4.0

v0.3.0

Choose a tag to compare

@aterga aterga released this 01 Sep 16:41
fa387f6

What's Changed

  • Give the site a favicon by @MRmarioruci in #146
  • Design docs: IMCP2 local deployment (minimal stdio binary, no OAuth) by @aterga in #148
  • Stage 1: extract imcp2-core (transport/OAuth-agnostic components) by @aterga in #77
  • Push the status dashboard's verdict to a Statuspage component by @aterga in #151
  • Make icp_top_up_canister instructions-only: never execute funding by @aterga in #153
  • Stage 2: imcp2-local — the stdio binary with built-in II browser login by @aterga in #150
  • Refuse ledger transfer/approval methods in canister_update_call by @aterga in #154
  • Stage 3: end-user setup, PocketIC login e2e, and the dist release pipeline by @aterga in #152
  • Remove financial framing; state the server is not for financial operations by @aterga in #155
  • Split IcTools into IcCanisterTools and IcProtocolTools by @aterga in #157
  • Regression-test deep-nesting reply decode (depth-safe, no abort) by @aterga in #147
  • Serve only the app/canister tools by @aterga in #158
  • Refresh submission docs against verified production state by @aterga in #161
  • Drop the README roadmap section by @aterga in #162
  • Serve skill:// resources from a reviewed static bundle by @aterga in #164
  • Serve the II app-metadata document at the origin root by @sea-snake in #169
  • Stop shipping the static/ directory the deploy no longer has by @sea-snake in #170
  • Drop the landing site in favour of internetcomputer.org/icp-mcp; the old page paths redirect permanently by @aterga in #165
  • Refuse update calls to known finance-related canisters by @aterga in #163
  • Describe the surface in model-readable metadata, don't direct the model by @aterga in #167
  • Restrict update calls to canisters an app declares (service discoverability) by @aterga in #166
  • Describe the surface once, not in every field by @sea-snake in #173
  • Reconcile privacy and submission evidence with the deployed state by @aterga in #177
  • Pin setup-node, upload-artifact and download-artifact to commit SHAs by @aterga in #178
  • Publish the workspace in one cargo invocation, not crate by crate by @aterga in #180
  • Bump to 0.3.0 by @aterga in #179

Full Changelog: v0.2.0...v0.3.0

v0.2.0

Choose a tag to compare

@aterga aterga released this 19 Aug 15:53
c4979b8

What's Changed

Full Changelog: v0.1.1...v0.2.0

release-2026-08-18-0.1.1: Delete two dead items and bump to 0.1.1 (#142)

Choose a tag to compare

@aterga aterga released this 18 Aug 15:19
bbf0844
* Delete the two dead items the compiler was warning about

`cargo build` has been emitting two dead-code warnings. Both are real
dead code, not false positives:

`IcTools::tool_router` is written by `new()` and never read. rmcp 1.7's
`#[tool_handler]` defaults its router expression to `Self::tool_router()`
— the associated function the `#[tool_router]` macro generates, not the
field — so the stored copy was only ever constructed and cloned. Dropping
it also stops `new()` building a router nobody consults.

`ok()` has no callers left; the tools return through `ok_with_value()`.

Removing the field frees the `ToolRouter` import too. No behavior change:
the handler resolves its router exactly as before.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DzHqmVVfkNyXpPi79Fh1eM

* Bump to 0.1.1

First release cut through .github/workflows/publish-crate.yml rather than
by hand — 0.1.0 had to be published manually because crates.io only lets
a trusted publisher be configured on a crate that already exists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DzHqmVVfkNyXpPi79Fh1eM

---------

Co-authored-by: Claude <noreply@anthropic.com>