Repository navigation
Releases: thrashr888/cider
Release list
v0.10.0 — Safari network capture
Capture Safari's real network requests and original API response bodies from Cider.
New commands
cider safari network <url> --bodiesopens a temporary Safari tab and captures requests and original response text through Safari 27's native MCP server.cider safari monitor --window 1 --tab 2 --filter /i/api/graphql/ --bodies --seconds 30observes future fetch/XHR requests in an existing signed-in tab. Use the page during capture to generate requests.- The README includes a Twitter/X feed example that captures the UI's actual HomeTimeline endpoint and extracts its response without reserializing the JSON.
Both commands include dry runs, bounded request/body capture, explicit unavailable/oversized-body states, machine-readable schema metadata, and library APIs. Errors provide setup and recovery instructions. Request credentials and payloads are not exported.
Safari setup and limits
network requires Safari 27 native MCP support and Allow remote automation and external agents. Its automation session may not inherit a regular tab's login.
monitor uses an existing tab and requires Automation permission plus Allow JavaScript from Apple Events. It observes future fetch/XHR calls in that document, restores its temporary wrappers afterward, and leaves the tab open. Reloading the document ends the monitor. Parsed JSON XHR bodies are marked unavailable rather than reconstructed.
Validation
Rust and browser-script tests, macOS/Linux CI, read-only live smoke tests, native capture of a real public JSON API, and byte-for-byte response capture with a Safari HttpOnly session cookie. Live signed-in X verification remains a tracked follow-up.
Install or update
brew update && brew upgrade cider
# or
cargo install cider-cli --version 0.10.0 --lockedv0.9.0 — Safari pages and sessions
Safari pages and existing sessions
- Search Safari history by URL or title with
safari history --search,--limit, and--offset. - Read an existing Safari tab's text or HTML with
safari content. - Open a URL in a new tab and return its page content with
safari fetch. - Make bounded, same-origin GET requests using a selected Safari tab's existing session with
safari request, including HttpOnly cookies. - Get concrete recovery instructions for missing permissions, invalid tabs, origin mismatches, timeouts, and common HTTP failures. The README includes setup and troubleshooting.
cider safari tabs --pretty
cider safari content --window 1 --tab 2
cider safari fetch https://example.com --window 1
cider safari request https://example.com/api/me --window 1 --tab 2
cider safari history --search github.com --limit 20Tab commands require macOS Automation permission. fetch and request also require Safari Settings > Developer > Allow JavaScript from Apple Events. Native content does not require that JavaScript setting. History reads may require Full Disk Access for the launching app.
Network commands support --dry-run, output limits, and deadlines. Fetch leaves its new tab open. Requests reject redirects and cross-origin URLs, preserve HTTP error status/body, and do not export cookies or infer application-specific bearer/CSRF headers. These commands are available through the CLI and Rust library; the MCP allowlist is unchanged.
v0.8.0
What's new
- Apple Notes keep their structure:
notes listandnotes getgain amarkdownfield carrying the note's real shape — paragraphs,-bullets,1.numbering,- [x]checklists, headings and links — converted from the HTML the Notes app stores. Apple'splaintextflattens all of that into bare lines, so a bulleted list used to reach a consumer indistinguishable from prose, and anything rendering it as Markdown collapsed it into one paragraph. notes getreports its folder:name of container of noteerrors with -1728 on a note reference, so the folder always came back empty. It is now read from a bound container.
Try it
brew update && brew upgrade cider
cider notes get --id "$(cider notes list --brief | jq -r '.[0].id')" | jq -r '.markdown'Compatibility
body is unchanged — still Apple's flattened plaintext — so callers reading it keep what they had. markdown is additive, and falls back to the plaintext for a note with no rich text. notes list now reads two properties per note instead of one; notes list --brief is unaffected and remains the fast catalog call.
Validated with 237 library tests, including conversion fixtures for flat and nested lists, checklists, headings, links and entities, plus live reads of real notes on macOS.
v0.7.0 — MCP and local activity history
What's new
- Local MCP server:
cider mcpexposes 12 read-only tools for Knowledge, notifications, downloads, interactions, Biome, Calendar, Reminders, and diagnostics. Select sources per client with--sources; tools call the same library APIs as the CLI. - Knowledge activity history: discover streams and query recorded app usage and other local events from
knowledgeC.db, with date filters and pagination. - Four more local history sources: retained Notification Center records, quarantine/download origins, Core Duet interaction metadata, and local Biome streams. Biome supports SEGB v1/v2 records, checksum checks, common field decoding, and optional raw payloads.
- Practical examples: README recipes for notification patterns, download provenance, participants, app switches, and recorded usage intervals, plus MCP client setup.
- Release checks: stabilize Bridge tests across dates and CI scheduling, and prevent disconnected test sockets from terminating the test runner.
Try it
brew update && brew upgrade cider
cider mcp --sources knowledge,notifications,downloads,interactions,biomeAn MCP client launches that command and communicates over stdio. See the README for client configuration, available tools, and permissions.
Compatibility and validation
MCP is included in default builds and requires Rust 1.88 or newer when building from source. Library consumers can continue using default-features = false to omit both MCP and Clap.
History readers are read-only and report retained data, which can be incomplete. macOS permissions apply to the app launching Cider; Calendar and reminder-list discovery may request Automation access.
Validated with 260 Rust tests, 93 Bridge tests, 64 live read checks, and real MCP client calls covering source discovery, history reads, source restrictions, and error recovery. Release binaries are provided for Apple Silicon and Intel Macs.
v0.6.2
Library code no longer writes to stdout or stderr. Every module under src/sources/ used eprintln! for its diagnostics, which is fine for the cider binary and dangerous for anything that links the crate: in a host app with a closed stderr, eprintln! panics, and that has aborted Alchemy in the field. Those diagnostics now go through the log facade, which stays inert until a consumer installs a logger, so an embedding host decides where the words land — or that they land nowhere.
- The
ciderbinary installs a small stderr logger that prints the bare message, socider watchand every other command read exactly as they did in 0.6.1. No output changed. - A unit test scans
src/lib.rsandsrc/sources/for print macros, so library code cannot quietly start printing again.
v0.6.1
Patch release on top of v0.6.0 (see its notes for the Cider Bridge, permissions, and command changes).
- The crate now builds on Linux, so
cargo publishverification succeeds andcider-cli0.6.x reaches crates.io. v0.6.0 never published because the release workflow hid the failure; it now checks crates.io for the version and otherwise fails loudly. - CI builds the crate on Linux and dry-runs the publish before any tag.
- Bridge wire dates always carry a numeric offset (
+00:00at UTC, neverZ), so consumers see one shape regardless of the machine's zone.
v0.6.0
Cider Bridge
A signed Swift helper that gives cider the Apple frameworks it could not reach from Rust:
- HomeKit (personal build):
cider home --live,home state,home run,home set, andhome triggers create-timer— live accessory values, scenes, and timer automations that fire on the home hub. Apple only allows the HomeKit entitlement in App Store and development builds, so this part iscider bridge build --installon your own Mac (Xcode + Apple Developer team). - WeatherKit:
cider weatheris back, sourced from Apple Weather with attribution, defaulting to your primary home's coordinates. - EventKit and Contacts through the
cider-bridgeCLI: Reminders and Calendar writes route through it when installed, calendar events gainmodified_at, andcider watchstreams store changes.
brew install cider now ships the notarized bridge app and CLI (everything except HomeKit). cider bridge status and cider doctor show what is installed, running, and authorized.
Permissions
cider permissions reports every macOS permission cider can need, its status, who has to grant it, and the Info.plist keys a host app must declare. Also available as a library call for apps that embed cider. See README › Permissions.
New and changed commands
cider homereads the Home app's cache: homes, rooms, accessories, scenes with stable ids, plus cache age.cider shortcuts export|gen|install: decode installed shortcuts, generate signed ones from a JSON spec (scenes, delay, speak, URL, SSH), install them.cider icloud: account, quota, Drive status and log, listing with download state,downloadandevict.cider watch: foreground change stream over Reminders, Calendar, Notes, Contacts, Home, and Shortcuts (FSEvents or the bridge CLI).--sinceonreminders,calendar,notes,messages(RFC 3339 orYYYY-MM-DD).cider wifireports the interface's address and router.cider doctorchecks the Home cache, Shortcuts database, iCloud Drive, bridge app, socket, CLI, signing-profile expiry, and per-store authorization.
Removed
find-my, journal, weather (old cache reader), maps, news, stickies: none could return data on current macOS. Weather returns via the bridge.
Fixes
Empty Music library is an empty list, not an error; byte-level head no longer prints an error envelope; a stale bridge reports a version mismatch instead of "unknown command".
Testing
A read-only live smoke suite (cargo test --test live -- --ignored) runs every read command on a real Mac and fails on hangs, non-JSON, untyped errors, or an empty result from a store that is present. CI now builds and tests the Swift bridge too.
v0.5.0
Highlights
- Added stable identifier contracts across Calendar, Mail, Contacts, and Reminders, with exact-id targeting for mutations and safe failure on ambiguous legacy Calendar matches.
- Replaced the shallow hand-maintained schema with complete metadata generated from the real command parser, covering all 41 top-level commands, actions, arguments, defaults, dry-run support, and identifier contracts.
- Added single-session batch operations for Calendar creation and Mail/Reminders mutations, with per-item results and explicit partial-failure status.
- Deepened the core PIM APIs: richer Calendar event access and updates, searchable/filterable Mail with stable Message-ID targeting, full labeled multi-value Contacts data, and Reminders reopen/batch operations.
- Added prompt-free
cider doctorandcider auth-statusdiagnostics for tools, data stores, and macOS access state. - Preserved the fast local SQLite read paths, Calendar fallback behavior, compact JSON, envelopes, dry runs, pretty output, and the no-Clap library build.
Compatibility
- Existing Calendar title/date deletion and Mail index targeting remain available for compatibility, but stable ids are preferred.
- Output changes are additive. The CLI and Rust library remain a single binary/crate with no selectable backend or sidecar runtime.
Validation
- 102 automated tests pass.
cargo fmt -- --check, both Clippy configurations,cargo test, andcargo build --releasepass locally and on GitHub's macOS CI.- Live prompt-free
schema,doctor, andauth-statuschecks pass on macOS.
v0.4.1
Highlights
cider --version(also-Vand-v) prints the installed version, so scripts and agents can feature-probe instead of guessing which cider they're talking to.
v0.4.0
Highlights
Content comes through whole. Every source that reads user-authored text — Reminders, Notes, Calendar, Messages, Mail, Books, Stickies — now returns it in full. Multiline notes keep their newlines, long bodies keep their length, and tabs no longer cut a record short. The old tab-separated readers flattened or silently dropped anything that didn't fit on one line; reads now come back as JSON end to end.
Reminders learned get and update. Fetch one reminder in full by id or title, and edit name, notes, priority, or due date in place — preserving the item's id and creation date. --append-notes adds to existing notes, and --notes - reads from stdin for content that shell arguments handle badly. Same for create.
Fixes
- Multiline text in AppleScript writes no longer breaks the script — newlines, tabs, and returns are escaped properly, so notes of any shape write cleanly.
- Apple Notes
getreturns the raw note id, so it round-trips; it used to come back lowercased and cut at 60 characters. - Apple Notes
listno longer caps bodies at 2000 characters, and titles are never truncated in returned data. - Calendar event notes — meeting agendas, dial-ins — are no longer cut at the first newline or capped at 500 characters.
- Slow scans over big lists (Reminders, Mail) no longer die on the default AppleEvent timeout; mutations get a proper timeout wall.
- Message text is returned in full instead of being capped at 120 characters.