Releases: nottelabs/reverse-api-engineer
Release list
v0.13.0 - client_executed json-stream event
Added
-
client_executedjson-stream event (#114): a non-interactive--json/--json-streamrun is a single SDK turn end-to-end, soresultonly fires once the whole turn is over — a caller watching the stream had no earlier way to know a working, live-verified client already existed, even when the agent spent a long tail of that turn on unrelated busywork.--json-streamnow emits{"event": "client_executed", "script_path": "..."}as soon as the agent successfully runs the generated client with its own language-specific run command, giving wrapper scripts a signal they can bound cost and time against.Emitted for both
engineerandagent; Claude SDK only (OpenCode/Copilot/Cursor have separate streaming handlers). See the scripted usage docs.
Changed
- Slimmer source distribution: the sdist no longer ships the repo's binary banner/demo assets, the
examples/anddesign/trees, oruv.lock— none are needed to build, install, or test the package (README images are served from GitHub, not the tarball). The published.tar.gzdrops from ~1.0 MB to ~229 KB. The wheel is unchanged.
pip install --upgrade reverse-api-engineerFull Changelog: v0.12.0...v0.13.0
v0.12.0 - Lightweight base install (Playwright now optional)
Changed
-
Playwright is now an optional
[manual]extra. Agent mode (the default) captures throughnpx-launched browser tooling — browser MCP servers (Playwright or Chrome DevTools) or the Vercelagent-browserCLI — and never imports the Python Playwright package.playwrightandplaywright-stealthmoved out of the base dependencies into a[manual]optional-dependency group, so the base install (and any runtime that bundles the package) stays lightweight.Manual capture users: install with
pip install "reverse-api-engineer[manual]"(oruv tool install "reverse-api-engineer[manual]") followed byplaywright install chromium. Agent mode needs neither. Entering manual mode without the extra fails fast with an actionable hint and records no run.
Fixed
- Manual capture no longer wedges the REPL after a failed start: a mistyped or scheme-less URL previously left Playwright's event loop running, so every later prompt spun on
asyncio.run() cannot be called from a running event loop. The browser is now torn down on a failed start. - Scheme-less capture URLs are accepted — a bare host like
jobs.example.com/xis treated ashttps://jobs.example.com/x. - CLI error text with brackets renders in full (e.g.
reverse-api-engineer[manual]is no longer swallowed as Rich markup).
Full changelog: https://github.com/kalil0321/reverse-api-engineer/blob/main/CHANGELOG.md
v0.11.0
Changed
- OpenCode setup: RAE now reuses an existing server or downloads/starts
opencode-ai@latestthroughnpxwithout requiring a global OpenCode install, with configurable auto-start, package, and base URL settings plus password inheritance. Fresh configurations default to freeopencode/big-pickle. Provider/model pairs are validated before session creation, invalid configurations include current free-model suggestions, and older compatible servers show an upgrade warning./settingsshows a loading spinner, uses a live searchable provider/model picker, saves the pair atomically, and remains open across related changes until Back is selected. - Ollama setup: OpenCode mode can discover tool-capable Ollama models, start an installed daemon, and inject provider configuration without modifying the user's
opencode.json.
Fixed
- "Prompt is too long" session deadlock (#93): Claude SDK sessions now run with proactive auto-compaction configured per the Claude Code docs —
CLAUDE_CODE_AUTO_COMPACT_WINDOW(capped by the CLI to the model's real context window) plusCLAUDE_AUTOCOMPACT_PCT_OVERRIDE=85— leaving enough headroom that a max-size HAR read landing near the threshold no longer jumps straight past the hard context limit. Both variables are respected if the user sets them explicitly. When the window is exhausted anyway, the error is now explained (progress is saved on disk; start a new run for the same target to continue) and the follow-up prompt is no longer offered on the dead session, where every further message would fail with the same error. - OpenCode permissions: Permission V2 events now reply through OpenCode's current, non-deprecated permission endpoint while retaining compatibility with older servers.
- OpenCode errors: Known authentication, model configuration, and temporary provider-availability failures now produce one actionable message without the unexpected-error issue prompt.
- OpenCode TUI prompt echo: Streamed text is now restricted to assistant message IDs, preventing RAE's internal browser and reverse-engineering instructions from appearing as model output.
run/listnow work for every output language:discover_scripts()previously only found.pyfiles, soreverse-api-engineer run <run_id>failed with "No Python scripts found" for JS/TS/Go/Java/C#/PHP/Ruby/C clients. Discovery now covers all supported extensions (excluding build dirs and the vendored cJSON sources), and the run command dispatches to the right toolchain per language (compile+execute for C), with a clear error when the required tool isn't on PATH.- Windows-safe run-command quoting: the Java/C#/PHP/Ruby/C run commands quoted paths with POSIX-only
shlex.quote, which cmd.exe/PowerShell parse incorrectly for paths containing spaces. Paths are now quoted per-platform (subprocess.list2cmdlineon Windows).
Added
- Go output language:
output_language: "go"is now supported alongside python/javascript/typescript, generating a standard-library-first (net/http,encoding/json) Go program, with the same auth-hardcoding/refresh and bot-detection-fallback guidance as the other languages. - Java output language:
output_language: "java"is now supported alongside python/javascript/typescript, generating a small Maven project usingjava.net.http.HttpClient(JDK 11+, no HTTP library dependency) and Gson for JSON, with the same auth-hardcoding/refresh guidance as the other languages. - C# output language:
output_language: "csharp"is now supported alongside python/javascript/typescript, generating a minimal .NET project usingSystem.Net.Http.HttpClientandSystem.Text.Json(both part of the .NET 5+ base class library — no NuGet dependency needed), with the same auth-hardcoding/refresh guidance as the other languages. - PHP output language:
output_language: "php"is now supported alongside python/javascript/typescript, generating a script using thecurlandjson_encode/json_decodecore extensions (ext-curl,ext-json— no Composer dependency needed), with the same auth-hardcoding/refresh guidance as the other languages. - Ruby output language:
output_language: "ruby"is now supported alongside python/javascript/typescript, generating a script usingnet/httpandjson(both part of Ruby's standard library — no gem/Bundler dependency needed), with the same auth-hardcoding/refresh guidance as the other languages. - C output language:
output_language: "c"is now supported alongside python/javascript/typescript, generating a program usinglibcurlfor HTTP and a vendoredcJSONfor JSON (C has neither in its standard library), compiled and run as a single{run_command}step, with the same auth-hardcoding/refresh guidance as the other languages.
v0.10.0
Changed
- Packaging metadata: Refreshed the package
description,keywords, andclassifiers, bumpedDevelopment Statusto4 - Beta, and updated the project URLs (Homepagenow points to https://reverseapi.dev, addedDocumentationandChangelog) - Source distribution excludes
website/: The marketing site underwebsite/(Astro/Cloudflare Pages source) is now excluded from the sdist build so it no longer ships inside the PyPI package; the wheel already only packagedsrc/reverse_api
Added
agent_provider: "agent-browser": Shell-driven Vercel agent-browser CLI—RAE prefers anagent-browserbinary onPATH, otherwise runsnpm install -g <pin>(with a console notice), validates--help, and only then falls back tonpx -y <pin>if npm cannot install. Prompts embed the resolved shell prefix plusskills get …/skills list, HAR flows, and optionalagent_browser_notes. No bundled browser MCP shim; pin viaagent_browser_npx_package/RAE_AGENT_BROWSER_PACKAGE.
Added
- Cursor SDK support: Added
sdk=cursor/--sdk cursorengineering support through a bundled Node bridge around the Cursor TypeScript SDK. Cursor runs use the configured Cursor model (defaultcomposer-2), accept MCP server configuration, resume Cursor agents across follow-up turns, and normalize streamed tool output plus token usage into the existing TUI/message-store flow - Cursor bridge packaging: Bundled the
src/reverse_api/cursor_bridge/Node package so@cursor/sdkdependencies can be installed on demand when Cursor mode is first used
Fixed
- Manual REPL model resolution: Follow-up engineering now resolves model settings from the selected SDK, including Cursor, OpenCode, and Copilot
- Cursor streaming: Buffered Cursor model text before rendering so streamed deltas are shown as coherent blocks and no longer produce stray
..lines or bridge hangs - Sync test compatibility: Restored the temporary-file helper used by the existing sync test surface
Removed
- Chrome extension and native messaging host: The
chrome-extension/workspace and the Pythonnative_hostmodule are removed. Theinstall-host,uninstall-host, andrun-hostCLI subcommands no longer exist. The extension was an experimental/WIP capture surface that never reached parity withmanualandagentmodes; deleting it also eliminates a JS dev-tooling supply chain (vite, postcss, picomatch, rollup, prismjs) and the corresponding dependabot churn
Security
- Drop
[pricing]extra (litellm): LiteLLM 1.83.7 patched 3 advisories (1 critical SQLi + 2 high RCE/SSTI) but hard-pinsclick==8.1.8, which would force a click downgrade for all users. The vulnerable code paths are all in the LiteLLM proxy server, which we do not run — we only used litellm as a library for cost lookups. Removed the optional dependency entirely;pricing.pykeeps a graceful import-detect path so users who installlitellmindependently still get the extended model coverage - cryptography
>=46.0.7(was>=46.0.6) — patches a buffer overflow on non-contiguous buffer inputs (medium) - pytest
>=9.0.3(was>=8.0.0) — patches vulnerabletmpdirhandling (medium, dev only) - python-multipart
>=0.0.27(was 0.0.22 transitively viamcp) — patches DoS via large multipart preamble/epilogue (medium)
v0.9.0
Added
- Cursor SDK support via
sdk=cursor/--sdk cursor, backed by a bundled Node bridge around the Cursor TypeScript SDK. - Cursor bridge package files are shipped without
node_modules; dependencies install on first Cursor use.
Fixed
- Manual REPL model resolution for Cursor, OpenCode, and Copilot SDK selections.
- Cursor streaming buffers model deltas into coherent blocks and avoids stray
..output / bridge hangs. - Restored the sync temporary-file helper used by the existing sync test surface.
Removed / Security
- Removed the experimental Chrome extension/native host workspace and related CLI subcommands.
- Dropped the
[pricing]LiteLLM extra and included dependency security bumps listed in the changelog.
v0.8.0 - Agent-friendly CLI
Highlights
This release makes reverse-api-engineer invocable from other agents and scripts via a structured non-interactive surface, and retires two providers and the legacy tag system.
Added
- Agent-friendly CLI:
--json,--no-interactive,--dry-run,--headless,--json-schema-version v2 - Stable JSON contract: normalized usage shapes and
error_kindenum for machine-readable error handling engineer --prompt/--fresh: replace@id <run_id> [--fresh] <prompt>REPL syntax with first-class flags- Expanded
--helpepilogs with examples on every subcommand
Changed
- Prompts extracted to markdown templates under
src/reverse_api/prompts/for easier review - New painted-ruins JPG banner
Removed (Breaking)
browser-useandstagehandagent providers: upstream churn made them unreliable. Useauto(Playwright MCP) orchrome-mcp(Chrome DevTools MCP). The[agent]extra is gone; configs auto-migrate toauto- Tag system (
@record-only,@codegen,@id,@docs,@help): replaced by CLI flags.@codegenand@docsremoved entirely (the latter returns later as adocssubcommand) agent --reverse-engineer/--no-engineer: was parsed but never wired through. Usemanual --no-engineerfor HAR-only recordings
Fixed
engineer --jsonemits JSON even whenRUN_IDis missing- Follow-up prompt suppressed in
--json/--no-interactivemode
📦 PyPI: https://pypi.org/project/reverse-api-engineer/0.8.0/
📜 Full changelog: https://github.com/kalil0321/reverse-api-engineer/blob/v0.8.0/CHANGELOG.md
v0.7.1
v0.7.0
What's New
run command
Execute generated scripts directly from the CLI:
reverse-api-engineer run ashby # fuzzy match by name
reverse-api-engineer run a450e520ca30 # by run ID
reverse-api-engineer run ashby --ls # list scripts
reverse-api-engineer run ashby --file api_client.py
reverse-api-engineer run ashby -- --org acme # pass args to script- Shared venv at
~/.reverse-api/runs/.venvwithrequestspre-installed - Auto-install missing imports — offers to
pip installand retry onModuleNotFoundError - Real-time output — stdout streams live, stderr captured for error detection
Security
- litellm >=1.83.0 (critical + high)
- requests >=2.33.0 (medium)
- aiohttp >=3.13.4 (4 medium + 6 low)
- pygments >=2.20.0 (low)
- cryptography >=46.0.6 (low)
Install / Upgrade
pip install -U reverse-api-engineer
# or
uv tool upgrade reverse-api-engineerv0.6.0
See CHANGELOG.md.
PyPI: reverse-api-engineer 0.6.0
Highlights
- Chrome DevTools MCP (
chrome-mcp) as an agent provider next to Playwright MCP (auto) - Smaller sdist on PyPI (excludes local demo video, packed extension zip, store screenshots)
- Streaming fix: tool results fall back to
result/outputwhencontentis empty
Install: uv tool install reverse-api-engineer==0.6.0 or pip install reverse-api-engineer==0.6.0
v0.5.0 - Follow-up chat, abort, AskUserQuestion free mode
What's New
Follow-up Chat
After a run completes, type follow-up messages to iterate in the same session — no new run IDs or folders. The agent retains full conversation context. Press Enter to finish and return to the REPL.
Abort Run (Ctrl+C)
Gracefully cancel a running agent/engineer session with Ctrl+C. Returns to the REPL instead of exiting the app.
AskUserQuestion Free Mode
All select/checkbox prompts now include "Other (type your answer)" so you can always provide free-text input. The agent prompt now documents free-form, multi-select, and multi-question capabilities.
Random Task Suggestions (Ctrl+R)
Press Ctrl+R in agent mode to fill the prompt with a random curated task idea. Press again to cycle through 20 examples.
Fixes
- Usage tracking: Token counts now accumulate across all follow-up turns instead of being overwritten
- Agent mode follow-up: Auto engineer now reuses the shared conversation loop
Install / Upgrade
uv tool install reverse-api-engineer --upgrade
# or
pip install reverse-api-engineer==0.5.0Full Changelog: v0.4.5...v0.5.0