v2.0.0
Restish v2.0.0 is a major redesign of the REST-ish HTTP CLI, with a new Go codebase, stronger OpenAPI command generation, typed JSONC config, safer auth/config handling, improved output/filtering/pagination behavior, and first-party plugin support.
Highlights:
- New v2 module path:
github.com/rest-sh/restish/v2 - Improved generic HTTP and generated OpenAPI workflows
- Automatic v1 config migration for standard config locations
- New out-of-process plugin system, including CSV, MCP, bulk, and PKCS#11 plugins
- Refreshed docs, install guide, v1 upgrade guide, and interactive tour
This is a breaking major release. Users upgrading from v1 should read the upgrade guide before switching production workflows.
See more at https://rest.sh/docs/getting-started/tour/
Changelog
- 2d92b74 Merge pull request #331 from rest-sh/v2
- 3b30aba build(output): add OCI image packaging
- 1ce964a build: bump shorthand/v2 to 2.3.0
- 3cea485 build: move module path to github.com/rest-sh/restish/v2
- 5cd809e build: preserve v1 release archive names
- 0af3be4 build: update docker ignore patterns
- bfd79df chore(auth): cache OAuth tokens in memory
- 5b3e77a chore(auth): design OpenAPI credential auth model
- 3fb6f63 chore(auth): enforce profile selection and auth hooks
- a94b74e chore(auth): list supported auth types in errors
- f1ad6c4 chore(auth): rename generated auth override flag
- 63a483b chore(auth): strip query credentials on cross-host follows
- 525a074 chore(auth): update credential storage hardening and permission warnings
- 9024a75 chore(cache): encode response cache path components
- b0babbb chore(cli): quiet non-request command help
- 3d7a9c9 chore(cli): reframe v2 command surface decision
- 6827a96 chore(cli): startup fast-path skips flags and recognizes built-in verbs
- 8f3bf76 chore(cli): update aPI-name vs built-in command collision guard
- 2a92bdc chore(cli): update centralized global-flag parsing
- c225f5b chore(cli): update flag-completion registrations
- c51692b chore(cli): update setup command correctness and UX improvements
- 8d4e762 chore(config): lock config patch writes
- 0cb641a chore(config): update config write safety and error quality
- 8a59f6f chore(config): update unified directory and path helpers with XDG + Windows support
- d8ae425 chore(config): use XDG-style config defaults on Unix
- 58fe081 chore(config): write config files atomically
- d8ef1c4 chore(deps): update shorthand to v2.4.0
- 89ef7c4 chore(openapi): let spec loaders persist transformed ContentType and Raw
- f590e28 chore(openapi): refresh cached specs when sources change
- e5e527a chore(openapi): resolve refs before merging spec files
- 26c3f47 chore(openapi): respect GLAMOUR_STYLE for Markdown rendering
- 4f15624 chore(openapi): skip generated API loading for built-ins
- e4ddf99 chore(openapi): spec-discovery error aggregation and deterministic reporting
- e039605 chore(openapi): tidy generated command help-all output
- 09a6377 chore(openapi): warn on broken generated specs and extra args
- e19a317 chore(output): clarify raw and line output semantics
- cff14fc chore(output): group help output for commands and global flags
- 7ccab1f chore(output): highlight HTTP dates and paginated framed output
- 774bd95 chore(output): stabilize verbose header output
- 246518b chore(output): update phase 10 filter/content/output polish
- 861f088 chore(output): update setupMarkdownHelp race safety
- 12b3c18 chore(output): use readable formatting for streamed JSON output
- bd59c60 chore(plugin): cache generated operations and parallelize bulk
- 7145337 chore(plugin): cache plugin manifests between runs
- 7fa4f14 chore(plugin): clarify safe plugin decoder usage
- 619621d chore(plugin): close command plugin pipes on start failure
- da0eb2e chore(plugin): require declared plugin hooks for extensions
- 29c0f5f chore(plugin): unify formatter plugin streaming output
- fba0d26 chore(plugin): update install and plugin paths to rest-sh module
- 3ff1c55 chore(plugin): update phase 9 plugin subsystem cleanup
- a7d7997 chore(retry): clarify retry help default
- 739005f chore(stream): return status errors from links command
- dd92a85 chore: Replace interface{} with any
- 7871e5c chore: add basic AGENTS.md
- 8e1e1f9 chore: address restish v2 review findings
- 2953850 chore: clone only paginated wrapper paths
- a7a5921 chore: colorize diagnostic labels
- 13bc26a chore: ignore local test notes
- e904fcf chore: log every verbose request through the shared transport
- 9c8e352 chore: manage TLS signer subprocess lifecycle
- b710873 chore: parse hints and multi-expression shorthand
- 192bd26 chore: refine rsh-review skill
- ccaa463 chore: remove unused link dependency
- 7b4438e chore: remove v1 implementation for v2 import
- a57c9a7 chore: reuse shared editor lookup for api edit
- 788c7bd chore: scope OIDC endpoints to issuer path
- 3a91cc6 chore: update confirmEdit safe-on-EOF; Enter-as-yes only on TTY
- 06d764c chore: update examples using live endpoints
- 3792251 chore: update runAPIEdit wires editor subprocess to c.Stdin/Stdout/Stderr
- 2ccde52 chore: update shorthand.md full-depth rewrite
- 7c95d1a chore: update signal handling, root context, ExitCodeError cause
- f8e1481 chore: update unified Prompter interface
- 5708a87 chore: update verbose -vv TLS details
- db1ffe6 chore: use equal jitter for retries
- 001f984 chore: use errors.Is for EOF checks
- 865070a chore: use errors.Is for missing-file checks
- 291ab6f ci: add dormant docs site deploy workflow
- 6a9850a ci: add v2 validation workflow
- 4ce47a9 ci: keep release workspace clean
- 42b8ada ci: use releaser app for v2 publishing
- e17ef31 docs(embed): document cache namespace safety
- 3530554 docs(guide): add mise alternative method installation
- 23fb21a docs(site): improve Restish command highlighting
- 98828e6 feat(auth): add API key auth handler
- 0254975 feat(auth): add api auth commands
- a4ea588 feat(auth): add credential bindings to config
- fa3d6c2 feat(auth): add curl-friendly auth get command
- 760bb4d feat(auth): add operation credential metadata
- 71cc480 feat(auth): add shared auth profiles and token helpers
- 66a2a2d feat(auth): configure fallback operation credentials
- fcb8723 feat(auth): create token cache temp files securely
- 2e96184 feat(auth): extend x-cli-config credentials
- 9262bc5 feat(auth): overhaul oauth flows and handler context
- 7265523 feat(auth): select operation credentials for generated requests
- 30d0185 feat(auth): show values in auth inspect
- 944b695 feat(auth): support credentials in auth inspect
- e0a0e7d feat(cli): add cert command and TLS options
- f685809 feat(cli): add edit command
- a7984a6 feat(cli): add shell completion and setup command
- eb1efb2 feat(cli): add shell completion installers
- 358dd88 feat(cli): expose help-all in focused help
- a569e2f feat(cli): finish phase 4 command polish
- 01650b5 feat(cli): finish phase 6 polish
- 41ab96f feat(cli): improve v1 migration ergonomics
- c0f977e feat(cli): infer POST for bare URL bodies
- 0e1bdee feat(cli): let embedders disable signal handling
- 3b3075f feat(cli): overhaul response output
- 64ac36c feat(cli): polish v2 command diagnostics
- 83a3234 feat(config): add API management subcommands (configure/show/edit/set/sync/content-types)
- 7575295 feat(config): add auto-pagination with streaming, collect mode, and per-API config
- 1de9d1e feat(config): add configurable output themes and GitHub shorthand names
- 72e847d feat(config): add explicit config file selection
- a92ab4a feat(config): expand config show summary
- 5b2fbcc feat(config): make retry wait caps configurable
- aedc3cd feat(config): migrate v1 config on first v2 load
- b3eb1d3 feat(config): support shorthand config patches
- ce63a41 feat(config): wire CacheConfig.MaxSize into HTTP cache budget
- 5ae21f4 feat(docs): generate reference drift checks
- 4e1f2cd feat(doctor): expand support bundle output
- 4329a16 feat(openapi): add generated security override
- d525858 feat(openapi): implement focused generated help and tag layout
- 95d1037 feat(openapi): load generated commands for targeted API only
- 3a1e545 feat(openapi): render schemas in generated command help
- e38c6da feat(openapi): support OpenAPI multipart encodings
- e86cbb5 feat(openapi): support OpenAPI parameter serialization
- 2f31273 feat(openapi): support external OpenAPI refs and server escapes
- eda9e1f feat(output): add table, gron, cbor formatters; --rsh-silent; AddFormatter on CLI
- bdbed89 feat(output): render markdown responses with Glamour
- 256903f feat(plugin): add CBOR wire format and plugin helpers
- 9b27296 feat(plugin): add CSV formatter plugin example
- 64659f8 feat(plugin): add CommandClient for command plugin authors (P14)
- a13cb49 feat(plugin): add HandleStartupFlags and Run entry-point helpers (P16)
- 6aa6f8d feat(plugin): add MCP call timeout diagnostics
- 0fe3387 feat(plugin): add MCP command plugin
- da00eee feat(plugin): add PKCS#11 TLS signer plugin
- 5f9f324 feat(plugin): add TLS signer plugin params
- 4edb1c4 feat(plugin): add TLS signer plugin support
- f0e27fc feat(plugin): add TerminalContext helper (P15)
- 3b1568a feat(plugin): add WriteManifest and WriteCommands helpers (P13)
- cf7b305 feat(plugin): add command plugin client helpers
- f4a4843 feat(plugin): add command plugin stdio passthrough
- 10af33a feat(plugin): add command plugin support
- 5527ba4 feat(plugin): add config-read message type (P5)
- 12f280e feat(plugin): add debug hint to plugin load warnings
- 717e441 feat(plugin): add filter field to http-request message (P7)
- edd9f1c feat(plugin): add hook plugins for auth, request-middleware, response-middleware
- 9e2878b feat(plugin): add hook plugins for loader and formatter
- eca3e66 feat(plugin): add list-apis and list-profiles message types (P4)
- 284fb31 feat(plugin): add no_cache and cache_ttl to http-request message (P1)
- 9d9ffde feat(plugin): add no_paginate field to http-request message (P3)
- fd360a7 feat(plugin): add plugin discovery and manifest loading (plugin list/install/remove)
- 375c456 feat(plugin): add plugins config namespace in restish.json (P21)
- 3362475 feat(plugin): add prompt and confirm message types (P6)
- 029bd75 feat(plugin): add restish-bulk command plugin
- 1f69d9f feat(plugin): add timeout to http-request message (P2)
- bcb6f27 feat(plugin): export typed message structs and type constants (P12)
- 7dd5df2 feat(plugin): index plugins by hook
- 4c64bf9 feat(plugin): introduce Decoder for safe sequential stream reads
- ff5d9e2 feat(plugin): load plugins only from config plugin dir
- 832c17d feat(plugin): scope auth hooks to specific APIs via auth_api_names (P9)
- 4750b82 feat(plugin): serve resolved operations to MCP plugin
- dad6be4 feat(stream): add SSE and NDJSON streaming support
- 3fe69bc feat(theme): add bundled themes and local installs
- 0ad7413 feat(theme): add reset and refresh docs palette
- e7a2757 feat: API registration in config with profile support
- 8c17f38 feat: HTTP Basic auth with password prompting (Step 9)
- a1d607c feat: JSONC config system with RSH_CONFIG_DIR support
- 3f55f3a feat: OAuth2 client credentials and authorization code flows (Step 10)
- d86232a feat: add 'api list' and 'api delete' commands (DX-3, DX-5)
- 3797759 feat: add -v logs request/response headers to stderr
- e43c37a feat: add Amazon Ion content type support
- f87008f feat: add CLI.Config() accessor for embedders (DX-19)
- 7a6fd6a feat: add CLI.FetchResponse for programmatic single HTTP requests (DX-18)
- 5fb6dd1 feat: add Restish product skill
- fcc0dff feat: add YAML output formatter and dynamic format name lists
- 20920ad feat: add bootstrap-safe diagnostics
- eecc21f feat: add bundled output themes
- 89e0115 feat: add doctor JSON diagnostics
- 044cf6a feat: add external-tool auth handler
- 933c8f9 feat: add form and multipart request body support
- a060526 feat: add hypermedia link parsing (Link header, HAL, TSJ, JSON:API, Siren)
- ea5d7d3 feat: add more bundled themes
- 7647c1c feat: add pagination.items_path and pagination.next_path to 'api set' (DX-12)
- 715ae6f feat: add public embeddable API
- 5f41349 feat: add retry with exponential backoff and RSH_TIMEOUT env var (step 12)
- fe0dbe0 feat: add shorthand input support for api add and set
- f1bd3e4 feat: add simplify skill
- 27e94e6 feat: add spec_files, local spec loading, and operation_base
- 0f24a4b feat: add terminal image rendering for image/* responses
- 7ce9c56 feat: addAuthHandler lets embedders register custom auth schemes (DX-16)
- d11afee feat: apply v2 design decisions
- f0586f8 feat: complete generated operation URLs
- 0c163ee feat: content type registry, encodings, and raw pass-through output
- 18d40e9 feat: enhance x-cli-config with security scheme resolution and template expansion
- 082680a feat: extend 'api set' with auth and tls_signer fields (DX-4)
- 981c46c feat: finalize v2 theme and content aliases
- 7675490 feat: gate cross-origin operation servers
- 16c31ad feat: generate Cobra commands from OpenAPI operations (step 14)
- 692f45c feat: generate deep object query child flags
- ea327e5 feat: generic HTTP verb commands with URL normalization and global flags
- 6a3136a feat: hint about body. prefix when -f filter returns no results (DX-9)
- c5ac788 feat: hint shell setup on first run to prevent noglob foot-gun (DX-10)
- 3b92962 feat: implement API spec discovery and caching (step 13)
- 89a21f7 feat: implement RFC 7234 HTTP response cache (step 11)
- 6790228 feat: implement final pre-release decisions
- d098a34 feat: implement x-cli-* OpenAPI extensions (step 15)
- 4318cc8 feat: link --rsh-columns and --rsh-sort-by from output-format help (DX-6)
- 66f72e4 feat: module setup and CLI struct skeleton
- 238efd1 feat: preview bundled themes
- 16520da feat: rename --tls-min-version to --rsh-tls-min-version (DX-2)
- 21aaeaf feat: render command Long descriptions as Markdown in TTY help output
- 9fceb49 feat: report spec discovery result after api configure (DX-1)
- b90bb39 feat: response filtering with shorthand and jq, --rsh-raw output
- 83af830 feat: response formatting with chroma syntax highlighting
- 7f74b5a feat: shorthand request body input and -c content-type flag
- 36e3c34 feat: suggest 'api edit' when JSONC comment preservation note is shown (DX-8)
- 09871ae feat: update AGENTS and add some skills
- 3c702bf feat: warn about broken plugins at startup (DX-11)
- 07a9976 feat: warn on unhandled plugin message type (P22)
- 27e1779 feat: warn when response-middleware follow.body/headers/query is ignored (P8)
- 4584259 fix(api): preserve embedder defaults during connect
- 0e5d330 fix(auth): clarify inspection guidance
- d6a5e78 fix(auth): serialize OAuth token refreshes
- df403e7 fix(auth): use portable shell execution and tighten oauth validation
- 87c6d15 fix(bulk): harden url handling and atomic metadata writes
- 8da5be5 fix(bulk): preserve hidden checkout resources
- 0136293 fix(bulk): restore themed v1 bulk output
- 6633ace fix(cache): fix API cache clearing and retry delay compatibility
- 73a9d71 fix(cache): fix HTTP cache size accounting
- 348e1de fix(cache): make writes safer and retry semantics explicit
- be1f563 fix(cli): fail on invalid pagination paths
- 20ac1ea fix(cli): finalize v2 command surface
- 94ac30f fix(cli): fix reviewed CLI edge cases
- 68de0f1 fix(cli): honor help-all without side effects
- 154492a fix(cli): improve generated API help
- 69fdde4 fix(cli): polish help and usage errors
- 12e9200 fix(cli): propagate command context through CLI requests
- f550a9c fix(cli): restore edit interactive flag
- a945615 fix(cli): standardize local command polish
- 1365e06 fix(cli): tighten config and diagnostics handling
- 50481b4 fix(cli): unify streaming item limits
- cca12eb fix(config): fix api configure invalid config handling
- ec989e3 fix(config): guard invalid JSONC inline-object bounds
- 1cfb9c0 fix(config): honor XDG path overrides in config paths
- 51de9e8 fix(config): preserve JSONC comments in config edits
- 6d4974a fix(config): preserve JSONC edit directory modes
- 1c1b068 fix(config): preserve config dirs and clarify migration recovery
- a4dcffe fix(config): preserve profiles during API configure
- b563799 fix(config): protect credential diagnostics
- 49a55d9 fix(csv): handle row schema drift in streaming output
- c459ee0 fix(docs): restore preview command selection
- 2cfd3a4 fix(filter): improve jq fallback errors and cache eviction
- 984ceeb fix(filter): prefer jq for leading dot fields
- 2626c91 fix(mcp): validate json-rpc frames and encode array parameters
- f65302a fix(openapi): bound OpenAPI server variable resolution
- 48ebc8b fix(openapi): correct operation_base path semantics
- 5b6aafc fix(openapi): fix generated command regression handling
- d609770 fix(openapi): honor OpenAPI server base paths and scopes
- 5c40f2b fix(openapi): invalidate spec cache after config changes
- 6d9ceec fix(openapi): preserve generated array defaults
- 5371efc fix(openapi): preserve generated schema string body fields
- fa5dc24 fix(openapi): preserve reserved query bytes and same-origin checks
- 4218ab1 fix(openapi): restore generated API help descriptions
- 7f89876 fix(openapi): restore generated OpenAPI command semantics
- 8d3191c fix(output): always close formatter plugin streams
- e27ac57 fix(output): fix filter hint for top-level roots
- 4aa28e2 fix(output): fix output formatter regressions
- f9280a0 fix(output): fix v1 request and output regressions
- d299a55 fix(output): honor pagination cancellation during output
- fcf455f fix(output): redact sensitive response headers
- a003c65 fix(output): restore headers for TTY image output
- 77286d4 fix(output): tighten output filter default behavior
- 82f86aa fix(plugin): fail stream errors early and time out MCP calls
- 361a82d fix(plugin): fix auth and plugin hardening issues
- bf5a421 fix(plugin): fix bulk plugin race-test fixture
- 9218d6a fix(plugin): fix bulk pull local version tracking
- 806c6bb fix(plugin): fix command plugin and MCP shutdown handling
- 9070a1b fix(plugin): fix command plugin stdio integration fixture
- 54d6642 fix(plugin): fix plugin quickstart CBOR terminology
- 976713c fix(plugin): fix reviewed plugin and retry edge cases
- c7d32e5 fix(plugin): fix reviewed plugin, config, and shell issues
- f38ef1d fix(plugin): honor spec file freshness for command plugins
- 5133a7f fix(plugin): polish bundled command help
- 6a2cced fix(plugin): reject bulk push on version conflicts
- 904d620 fix(plugin): reject malformed command plugin messages
- 63b7b03 fix(plugin): surface debug decode errors and make discovery cache robust
- e843ad4 fix(plugin): treat host plugin flags as an internal prefix
- f414ae3 fix(plugin): validate installed plugin binaries
- c40f057 fix(plugin): validate plugin capabilities
- 6ed82e2 fix(plugin): validate plugin remove names
- 04f6506 fix(plugins): preserve MCP stdin ordering
- 9c7a8f3 fix(retry): fix header timeouts and retry handling
- e54dc04 fix(site): align preview command baseline
- 9696039 fix(stream): bound sse memory and clarify event parsing
- 0a5a009 fix(stream): fix edit, pagination, cert, and prompt edge cases
- ae774d2 fix(stream): honor status codes for streaming and pagination
- 1e50413 fix(stream): polish streaming and pagination behavior
- 0b4e75a fix: a couple of examples in docs
- 9681d87 fix: add wildcard accept fallback
- 71b73a3 fix: address code review issues across plugin, config, and CLI layers
- fafbd08 fix: address phase 1 correctness issues
- 7b94f8d fix: address phase 2 and 3 correctness issues
- 9fec8eb fix: advertise all supported operation response types
- fec5228 fix: align enum fallback schema help
- 152523a fix: align pagination streaming and filter metadata
- f4f1055 fix: align plugin install GitHub shorthand
- 891ef37 fix: allow anonymous optional auth fallback
- ababaa1 fix: allow null body pagination next links
- f7e1ed1 fix: apply OpenAPI route auth to generic URLs
- 09995ea fix: apply header and cookie parameters in generated API commands
- 9c7abba fix: apply operation auth to allowed cross-origin servers
- 818362f fix: avoid URL completion placeholders
- d503bb7 fix: avoid caching stale or varying responses
- 696eae7 fix: avoid oauth scope prompts in noninteractive setup
- 8ef7052 fix: bound generated api root help descriptions
- 9e2e2fc fix: clarify per-record filters and silent requests
- f029944 fix: close pipes on error in startTLSSigner, fix retry bugs, fix formatters map race
- 9169a8e fix: color ndjson output in terminals
- 26bf83d fix: colorize generated API help groups
- d664749 fix: correct ExternalTool auth bugs and browser/editor process handling
- 9915cd1 fix: correct commonPrefix trailing slash and hoist regex (B11, SI-17)
- aba7f94 fix: decode all CBOR messages in plugin debug, not just first (P23/DX-14)
- 44b19d4 fix: disambiguate auto filter detection
- f3c4d25 fix: embed official themes
- 1136a4f fix: encode json-content query child flags as parent value
- d6d6675 fix: expose headers to shorthand projections
- 5af52f6 fix: fix URL-aware API profile matching
- cab4b03 fix: fix regressions from hardening pass
- 1ec3adb fix: fix remaining correctness edge cases
- fc835bb fix: fix review cleanup items
- e1e9e27 fix: fix review findings before restish v2 release
- b76ea7d fix: fix review remediation items
- eb99156 fix: flush streaming output and verbose requests
- 6069f3c fix: guide v1 api configure users to v2
- a5be648 fix: handle JSON sequence ndjson output
- 3e2b2e0 fix: handle runtime edge cases and diagnostics
- 761fd92 fix: handle structured suffix content types
- b9d9ff8 fix: harden plugin and mcp generated operations
- ce9c10d fix: harden plugin archive extraction
- bd292c5 fix: highlight JSON command output on TTY
- 95c5786 fix: honor anonymous-only operation security
- ee3fbd2 fix: honor content type for generated body examples
- 95b0cfd fix: honor explicit Host headers
- 40b007b fix: ignore conflicting generated examples
- 0e6f142 fix: ignore edit formatting-only changes
- aba9004 fix: ignore unrelated server variables for operation servers
- 5cbe295 fix: improve CLI error recovery diagnostics
- 773b076 fix: improve CLI onboarding feedback
- 7b2f9d6 fix: improve generated API spec discovery
- fde6da8 fix: improve generated auth precedence and fallback
- c910a6e fix: inspect all configured auth credentials
- dcee338 fix: keep YAML formatter body-only
- b0c3d43 fix: keep docs navbar section links active
- 9a436b3 fix: keep generated body shorthand schema-agnostic
- 2d0041c fix: keep header values plain in HTTP highlighting
- 672fc45 fix: keep paginated filters item-scoped across outputs
- 78babcd fix: keep stale generated API commands available
- b083cd8 fix: let auth set user-agent credentials
- 9b6863c fix: let docs code blocks use full width
- b71ea57 fix: make cancellation interrupt auth and plugin waits
- 56e56ab fix: make sure Accept header has text/event-stream
- ad09a16 fix: mark review fixes complete
- b7e2ea0 fix: merge duplicate header parameters
- 1a8f13d fix: merge explicit headers with defaults
- 3ee5e74 fix: normalize explicit config cache identity
- 6956b6f fix: normalize filtered headers and protect cache
- 8e594fa fix: normalize generated scalar examples
- 9162633 fix: normalize headers_all for shorthand filters
- 6b3b72c fix: parallelize OpenAPI external ref loading
- 07fcda7 fix: polish built-in output and redirects
- 8642e26 fix: prefer JSON in default Accept negotiation
- f1e81f9 fix: prefer anonymous over profile auth for optional operations
- 4cdb6a9 fix: preserve MCP parameter content schemas
- be111da fix: preserve concurrent connect caches
- ab642b5 fix: preserve generated command cache on clear
- 3658bb5 fix: preserve generated commands with operator flags
- ec7ffe5 fix: preserve generated optional defaults as documentation
- 4ec6c14 fix: preserve nullable generated body nulls
- 26d82c5 fix: preserve plugin short flags
- cdd2115 fix: preserve raw XML and NDJSON bodies
- 2c23f30 fix: preserve redirected response body bytes
- c89c4a9 fix: preserve scalar type for const variants
- fe05eb6 fix: preserve spec cache for operation metadata changes
- 2461b91 fix: redact credentials in network errors
- 347588a fix: redact suffixed password fields
- e13672a fix: redact token-like verbose credentials
- 09a4ec2 fix: reduce generated startup noise and cold-cache surprises
- 750647d fix: refine reviewer skill guidance
- 5128f7e fix: reject config path output transforms
- 11040b2 fix: reject invalid explicit specs
- 6f7678b fix: reject missing multipart file references
- 11b8d41 fix: reject negative numeric global flags
- 0e9c2fa fix: reject negative request timeouts
- 78a6d4e fix: reject non-HTTP server overrides
- 9aec84b fix: reject root-relative URLs without context
- 4c0ae9e fix: reject unknown command help typos
- 51e71fa fix: reject unsupported built-in output flags
- 0aa3494 fix: reject unsupported structured output formats
- 44d53ba fix: reject unused auth setup answers
- f2e116b fix: render conditional schema help
- a1db5c8 fix: render large text responses as text
- ed76d70 fix: report auth readiness consistently
- 6685e54 fix: report invalid bulk list JSON path
- 0d1c0c4 fix: report local spec doctor operations
- f9d16c3 fix: report noninteractive auth setup requirements
- d7ffdfe fix: require usable auth-code oauth before requests
- 302977a fix: reserve generated flag names
- ee69bef fix: resolve follow-up CLI findings
- e0cf392 fix: resolve real-world test findings
- 91da42e fix: restore HTTP status family exit codes
- 008bbc6 fix: satisfy duplicated query api keys from auth
- 656b4fd fix: satisfy mutual TLS with transport config
- 7c1eb59 fix: send raw binary generated bodies
- de411a4 fix: serialize buffered stdout writes
- e63b9f7 fix: serialize json content array flags as arrays
- 530c6da fix: serialize non-exploded label params with commas
- 5e7f088 fix: show resolved filter language in verbose output
- 312a113 fix: skip unsupported fallback auth schemes
- 7cf3a03 fix: sort numeric table columns numerically
- b1f9994 fix: suggest rsh-prefixed flags
- 136d187 fix: suggest valid array body filters
- 0e40a15 fix: support escaped commas in env request options
- 832c7ae fix: surface undeclared operation security schemes
- c721fa2 fix: terminal window colorful gradient tweaks
- 0fad4eb fix: tighten generated command request construction
- 89b4d5a fix: tolerate mismatched enum parameter types
- 99446b7 fix: trace request pipeline in verbose output
- d222bc5 fix: type-check bulk matches against files
- cd21e97 fix: use auth readiness for connect coverage
- b1606e9 fix: use maintained HTTP cache transport
- bcb2925 fix: validate explicit filter language
- f4898e7 fix: validate output flags before requests
- fef4e1f fix: validate persistent request options
- 9421383 fix: warn on server variable enum mismatch
- d0fe154 perf(cache): cache computed Accept headers
- 8e6f953 perf(config): avoid double-build of V3 model in FallbackXCLIConfig
- 3c360c3 perf(config): optimize JSONC path patch parsing
- 66e6c8d perf(openapi): benchmark large OpenAPI startup paths
- 12eebcc perf(output): cache compiled jq filters
- 34588f9 perf(output): preallocate jq filter result slices
- 97d2f44 perf(output): reduce formatter allocation churn
- 7f46033 perf(output): reduce gron path allocations
- 7b4e018 perf(stream): avoid SSE event join allocations
- 5970a30 perf(stream): preallocate collected pagination buffers
- 9ea2e41 perf: avoid rune-slice allocation in toKebabCase (PERF-8)
- ccb977f perf: memoize BuildV3Model() result on APISpec (PERF-4)
- 2b4d0fe perf: reuse HTTP transport across paginated requests (B10, PERF-6)
- 6a60164 perf: run LRU cache eviction asynchronously (PERF-5)
- abae410 perf: skip PATH scan when allowed_plugins is set (PERF-9)
- a31e1df perf: skip yaml re-marshal for single-file specs (PERF-7)
- 39af614 refactor(auth): centralize credential detection
- aec9b6e refactor(auth): complete API auth management TODOs
- a48630a refactor(auth): improve API auth configuration UX
- d79fd43 refactor(auth): simplify auth and config helpers
- b051a02 refactor(auth): tighten OAuth token compatibility
- e57ce3c refactor(cli): consolidate small helper files
- 1522da2 refactor(cli): delete unused compatibility helpers
- 5880a08 refactor(cli): improve CLI body and edit ergonomics
- 9c46c7d refactor(cli): improve schema help highlighting
- 76f7401 refactor(cli): polish command surface compatibility
- 5cebe4a refactor(cli): refactor shared CLI request execution
- fecd647 refactor(cli): refine v2 command surface
- 33d3394 refactor(cli): replace API setup with connect command
- dd27fb6 refactor(cli): simplify shared API and helper logic
- 1a9b020 refactor(cli): trim minor helper duplication
- e6901cd refactor(config): improve API configure setup flow
- f6be7fa refactor(config): replace JSONC patcher with CST-preserving parser (hujson)
- 685cdb8 refactor(config): simplify JSONC patch benchmarks
- f33a81d refactor(openapi): decouple command generation from libopenapi
- 5cb0af3 refactor(openapi): improve generated command body ergonomics
- b8abba0 refactor(openapi): improve spec discovery fidelity
- 7f590b9 refactor(openapi): tighten OpenAPI discovery trust boundaries
- bf59a74 refactor(openapi): tighten spec discovery and configure errors
- 250e233 refactor(output): improve output and parsing hot paths
- 8e461a8 refactor(output): polish links and verbose output
- e4bc2a3 refactor(output): refactor CLI output formatting pipeline
- 38e2938 refactor(output): refine pagination and streaming output semantics
- fe79ec2 refactor(output): remove raw output format
- 978cede refactor(output): share CLI filter and raw output logic
- 3401e04 refactor(output): trim gron formatter path allocations
- 27a78f7 refactor(plugin): finish plugin protocol hardening TODOs
- d826b9c refactor(plugin): improve public plugin and auth APIs
- 9506f5c refactor(plugin): remove misleading plugin verbose hint
- 0a189e5 refactor(plugin): replace stringly-typed plugin protocol with typed message structs
- 11156a9 refactor(plugin): use cbor.Decoder for stream reading
- 92ef222 refactor: centralize config mutations
- 69937de refactor: collapse body parsing entrypoint
- 8119aaa refactor: complete v2 TODO follow-ups
- b913fef refactor: consolidate atomic file writes
- 1cf8770 refactor: consolidate startup arg scanning
- cb53750 refactor: eliminate readableIndentDepth global using LexerState.MutatorContext (SI-26)
- 7986bf4 refactor: eliminate redundant bodyReader variable in runHTTPInternal (SI-14)
- 0cd89b5 refactor: export plugin.DecMode to deduplicate cbor.DecMode definition (SI-7)
- 7d47c21 refactor: extract buildQualityHeader helper in content/registry.go (SI-10)
- 30f9139 refactor: extract callHookRaw to deduplicate subprocess launch in hook.go (SI-11)
- 74021dd refactor: extract configDir() helper to deduplicate env lookup (SI-25)
- 8a5adba refactor: extract effectiveTransport helper in discover.go (SI-12)
- 638d5c2 refactor: extract mergeTLSSignerParams to deduplicate merge logic (SI-2)
- 3d8ded1 refactor: extract plugin helper functions to public plugin package (P10/P11/SI-4/SI-5/SI-6)
- 9c912b3 refactor: extract profileFromCmd() to deduplicate profile resolution (SI-1)
- 53f057c refactor: extract writeRaw helper to deduplicate raw output logic (SI-9)
- b54809f refactor: finish remaining Phase 7 items
- 6dffe63 refactor: inline verbose response transport hook
- 3730644 refactor: isolate plugin install pipeline
- 4083c8f refactor: make spec loaders options-aware
- d30c043 refactor: merge prompt helpers
- 7680ae5 refactor: promote OpExtBool/OpExtString/PathItemMethods to internal/spec (SI-3, SI-8)
- 4da5ccf refactor: remove archived v1 and wasm prototype
- 7c90b9f refactor: remove dead lowercase-key lookup in supportsMergePatch (SI-16)
- b2714d4 refactor: remove duplicate DiscoverOIDC call in resolveTokenURL (SI-21)
- c3dfe04 refactor: remove local notes and committed binary
- 6116408 refactor: remove unexported wrapper functions in oauth_authcode (SI-20)
- 85cef44 refactor: rename done channel to stopCh to avoid shadowing (SI-22)
- 913bfce refactor: rename ttyErr to stderrIsTTY in pagination (B13/SI-23)
- 28f8147 refactor: replace custom unifiedDiff with gotextdiff/myers in edit.go (SI-18)
- 633fcce refactor: replace fmt.Sscanf with strconv.Atoi in cacheTTL (SI-24)
- 74b4f12 refactor: share Link header parsing and clean stale comments
- 892d6cf refactor: share OpenAPI parameter serialization
- 24ebe90 refactor: share secret prompt handling
- bb22662 refactor: simplify internal API surfaces
- a845877 refactor: simplify request transport cleanup
- 850c7a5 refactor: split bulk command and file helpers
- ac62810 refactor: split command plugin runtime and handlers
- 4334517 refactor: split mcp server responsibilities
- b58154e refactor: tighten HTTP pipeline handling
- 7d824ae refactor: trim request closers after each request
- 5457980 refactor: unify CLI prompt handling
- ba9fb55 refactor: use configFilePath() in CLI.Run instead of inline logic (SI-13)
- 11b0ef3 security(auth): harden OAuth and external auth handling
- 451cae2 security(auth): harden OAuth browser and device flows
- 325f1be security(auth): harden OAuth callback handling
- 803a1b6 security(auth): harden OAuth token cache writes
- 2ea1d83 security(auth): harden direct OAuth endpoints
- d973376 security(auth): harden redirects and authenticated caching
- 24220b0 security(auth): secure OAuth token storage and external tools
- 01a83df security(cli): harden shell setup file permissions
- 68aa3aa security(config): harden config editing and migration
- 6481caf security(config): restrict config directory permissions
- b016dff security(openapi): fail closed on spec discovery DNS checks
- ac229b9 security(openapi): harden spec cache names and OIDC host checks
- eb23173 security(openapi): harden spec discovery against SSRF
- 29166e7 security(plugin): bound plugin protocol inputs
- 50cd9e6 security(plugin): cap plugin debug capture memory
- 0af9ef5 security(plugin): cap plugin install downloads and extraction
- 01c2e51 security(plugin): gate MCP write tools behind flag
- 05d4e31 security(plugin): harden bulk push preconditions
- bfb790e security(plugin): harden command plugin process handling
- a9cfed4 security(plugin): harden plugin manifest compatibility
- 25189cf security(plugin): reject bulk paths outside checkout base
- b323aa5 security(plugin): require explicit plugin install trust
- 50f585e security(stream): block HTTPS to HTTP scheme downgrade on next links
- 80c40ea security(tls): default to TLS 1.2 minimum
- ba556f8 security: add allowed_plugins allowlist for plugin auto-discovery (S-H2)
- 45e40b5 security: cap response body and spec fetch at 100/50 MiB (S-M3)
- e196b3c security: disallow external-tool auth in x-cli-config (S-H3)
- 75e08fc security: fix Windows 'cmd /c start ' special char handling (S-L4)
- 799e72b security: percent-encode cookie parameter values to prevent header injection (S-L5)
- 300acc3 security: redact URL userinfo in diagnostics
- 3f13140 security: redact auth headers in verbose mode, add insecure-TLS warning, cap MCP payload, fix SSE buffer, fix UTF-8 truncation
- 73a001a security: redact generated api-key auth targets
- d4aadfc security: redact secret auth params from plugin dispatch (S-L7)
- bada961 security: redact secret auth params in 'api show' output (S-L2)
- 17d282e security: redact secret headers in hook payloads
- 6cbb42c security: restrict config and cache file permissions to owner-only (0600/0700)
- 7320034 security: strip credentials on cross-host response-middleware follows (S-M6)
- 53f8035 security: validate OIDC endpoint URLs against issuer hostname (S-M2)
- 9a11b85 style(theme): refresh default CLI palette
- d312c43 style: tune bundled theme palettes
- aa524f7 test(auth): convert auth and pagination tests to injected transports
- 15bd8a7 test(cli): close v2 release guardrails
- c490822 test(cli): consolidate CLI test helpers
- e569457 test(cli): convert CLI tests to injected transports
- ab2a1da test(cli): cover edit warning without validators
- 9060ece test(cli): fix CLI test hangs with TTY
- cc147ae test(cli): gate slow CLI tests behind integration tag
- a41fe7a test(cli): guard non-tty color behavior
- 7094b12 test(cli): mark CLI override fields as test-only
- 0bb054e test(config): cover API-rooted shorthand swaps
- 8aa6d28 test(openapi): add OpenAPI robustness regression coverage
- b72702e test(openapi): add public OpenAPI shape regression tests
- 79bf23d test(openapi): expand OpenAPI edge case coverage
- b9a3cbe test(openapi): expand spec-loading and command-generation test coverage
- 249a944 test(openapi): harden OpenAPI generated command coverage
- 4d1f68f test(openapi): test OpenAPI server and required parameter behavior
- e57087f test(output): highlight paginated readable output and add regression tests
- 468dfce test(plugin): add pluginFormatter.FormatValue round-trip test
- 9ae818c test(plugin): cover MCP resolved server variables
- 0f3eb31 test(plugin): fix data race in PluginSigner and pass go test -race ./...
- feeaa50 test(plugin): speed up CLI plugin test helper builds
- 3153c2f test(stream): add NDJSON streaming support and regression tests