Skip to content

v1.6.0 — the operator release

Choose a tag to compare

@slabbdev slabbdev released this 07 Oct 13:32
· 59 commits to main since this release

Deploy navette on machines that are not yours.

  • --token SECRET: Bearer auth on every HTTP route (except /health) — Authorization: Bearer or X-Navette-Token. An MCP host attaches to a protected serve with the NAVETTE_TOKEN env var. Loopback-only was never enough for shared machines and lab LANs.
  • --proxy URL: HTTP CONNECT or SOCKS5, applied at webview creation on the wry backends (soup / WebView2 options / Network framework). Proxy credentials in the URL are refused loudly — the engine layer doesn't carry them; use IP allowlisting. macOS follows the system proxy.
  • --user-agent UA: per-serve override at webview creation, WKWebView included.
  • linux-arm64 joins the release assets (aarch64 Linux is where agents actually run).

All three flags validated live: 401 without/with wrong token, 200 with Bearer and X-Navette-Token; navigator.userAgent override confirmed; a bogus --proxy blocks navigation while the API stays reachable.

Binaries: macOS arm64, Windows x64, Linux x64 + arm64.