Releases: xinbetween/flowlight
Release list
Flowlight 0.9.7
What's new in 0.9.7
- Relaunch works when something else starts your agents. A program reads its proxy settings once, at launch, so inspection only sees an agent started with them set. Relaunching assumed a person types in a terminal — but agents are increasingly started by something that outlives any window: a session manager, a supervising daemon, an editor's extension host. Opening a new terminal then changed nothing, because that shell will never be any agent's parent. The feature appeared to work and did nothing.
- It now finds what actually starts them. Flowlight walks up from a running agent, steps over the shells, and looks at what is above. A terminal means the relaunch opens in that terminal rather than Terminal.app. Anything else means the offer becomes to restart that process with the proxy environment set, so the agents it spawns afterwards inherit it — restarted with the command it was actually running, since a daemon invoked with a subcommand is not the same program as its bare name.
- And it says what that costs. Restarting a supervisor ends every session it is running. That is stated before you agree, not discovered after. What it cannot do is reach agents already running: their proxy settings were read at launch, and nothing changes them now.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.9.7.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
567f9c99e7047b08f576974f0c7338f84f38c3d97a0312216a981b185861cd01 Flowlight.dmg
d0166820bab4f78574b8eef3637ed037e10055dae9680d0c9e419885fbfdf6aa Flowlight-0.9.7.pkg
Flowlight 0.9.6
What's new in 0.9.6
- Every domain an MCP server reaches. An MCP server touches the network four different ways, and Flowlight already learned each of them somewhere different: a URL in a config file, an endpoint the proxy watched this Mac speak JSON-RPC to, a connector declared to the model provider in the request body, and ordinary calls a local server process made itself. All four were being collected; none was offered as something you could act on. They are one list now, under MCP servers in an agent's detail, each domain labelled with which of the four it is known from — and a domain carrying several labels is a stronger fact than one carrying a single label, since configured and contacted says more than either alone.
- Two ways to refuse each one. For that agent and the tools it starts, or for every app on the Mac — different decisions, and the difference is invisible once a rule exists, so both are offered where the choice is made rather than one being discovered later in the rule editor. Both write ordinary rules, so the violations feed reports them and the simulation from 0.9.4 will say what one would have refused before it refuses anything.
- The extension stops asking you to wait for something that cannot happen. Reported three times as "the filter stops working after an update", and each time the version check was examined and found correct. It was. After several updates macOS holds the superseded copies until you restart — activated enabled for the build that matches the app, terminated waiting to uninstall on reboot for the rest — and because it runs one content filter at a time, the matching build is installed without being the one running. Nothing is stale, so nothing is repaired, and the app redialled an extension that could not answer until a restart, six times, then fell back to the sampler without naming the one thing that fixes it. It now recognises that state and says to restart.
- Except where a rule could not reach. A connector the provider reaches on its own never touches this Mac, so that row explains why instead of offering a refusal that would quietly do nothing. The moment the same host is also configured locally or contacted from this Mac, the buttons appear. A local server that only ever speaks over a pipe contributes no domain at all, for the same reason it appears nowhere else: that is not network traffic.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.9.6.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
46130d671f3a06b7203c633a0fb46cb79e0e1cfc840341a47f96983cedc3d412 Flowlight.dmg
9a471a9f31135e0ac273a1d25e581aa3726532e1b60b2e37331650b454fcaa5e Flowlight-0.9.6.pkg
Flowlight 0.9.5
What's new in 0.9.5
- What leaves the Mac, before it leaves. Flowlight asks every app on your Mac to say what it sends and where. The export is the one place Flowlight itself sends anything substantial, and it used to start the moment a switch was flipped. Turning it on now opens a page first: the collector's address, whether the connection is encrypted or whether everything crosses the network readable by anything on the path, exactly the fields your settings will send with a sentence explaining each, and the names of any headers on the request. Header values are never shown — they live in the Keychain, and a screen that printed a token to prove it was being sent would be the thing it warns about.
- Approving one thing does not approve another. The approval is tied to what was disclosed, not to having once agreed: change the collector, switch the host name on, add a header, start sending alerts as well as rollups, and Flowlight stops and asks again, because what leaves is no longer what you agreed to. Rotating a token does not ask again — the value was never part of the disclosure. Switching the export off withdraws the approval, so turning it back on is a fresh decision against whatever the settings say by then.
- The check is where the bytes would leave, not only in the settings screen, so a future screen that forgets to ask cannot send anyway.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.9.5.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
2de8549ebbf1b9d736b51376de6ec309e969a59b536d7aca50fb7b4a4148a01d Flowlight.dmg
e08ca53919c1eed3edd83d789d733977922d35247b3eca8501d896574bc06051 Flowlight-0.9.5.pkg
Flowlight 0.9.4
What's new in 0.9.4
- Show me what this rule would have done. A rule that refuses connections is easy to write and frightening to switch on, because the first thing you normally learn about one is what it broke — and you learn it later, from something failing somewhere else. The rule editor now answers that first: it replays recorded traffic against the rule you are writing and lists what would have changed, before anything is refused. The data has been on disk the whole time; it had only ever been used to explain the past.
- It reports a change, not a match. If a rule you already have refuses that traffic, adding another that also refuses it changes nothing — so saying "would refuse 4,000 connections" would be untrue. Every recorded connection is decided twice, once with your rules as they stand and once with the new one added, and only the ones that come out differently are listed. An allow rule written to carve an exception reports the mirror image: what it would let through.
- Two details that decide whether the number can be trusted. Schedules are judged at the time the traffic happened, so a rule for weeknights reports what it would have refused on weeknights rather than what it would refuse if that traffic happened now. And an empty result distinguishes "would have changed nothing, out of 1,240 connections" from "no recorded traffic in this period to test against" — the same empty list, opposite meanings, and only one of them says the rule is safe. The screen names the oldest traffic it could see, because a rule tested against two hours of history has been tested against two hours of history.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.9.4.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
550a198392fc6ed41b01692d766bbe640bb386774387b58a6001336165a81d26 Flowlight.dmg
9005d8df590d9f4cdf608369ece157df1690b39b36f86484d2fc83b591bf2903 Flowlight-0.9.4.pkg
Flowlight 0.9.3
What's new in 0.9.3
- A budget for HTTPS inspection. Recorded bodies are the most sensitive thing Flowlight holds, and what protected them was a guess at which headers carry credentials. A guess is the wrong shape for this: it can only know the headers somebody thought of, and when it is wrong it writes a secret to disk under a promise that it wouldn't. Headers are now kept because they are on a list, not discarded because they looked dangerous. The old behaviour is still offered — reading an unfamiliar API means seeing headers nobody has allowed yet — and a third option keeps no header values at all. Whatever you choose, header names and value lengths survive. Hiding the header altogether would be the quieter lie: it would show a shorter request than the one that actually happened, and nothing on screen would say so.
- Limits you set, rather than limits you hope for. Words of your own mark a header as a credential whatever a vendor calls it. A daily per-app ceiling caps recorded bodies, and past it the exchange is still recorded — time, host, path, status, headers — with only the bodies dropped and a note saying why. Retention is a setting. And inspection now ends by itself after eight hours, because "until somebody remembers" left the most sensitive mode in the app running long after the reason for it had passed.
- Two sentences that were not true. The Advanced panel said recorded requests were kept for three days and credential headers were never stored. The period had become a setting, and what happens to a credential is that its length is stored instead. That line is now generated from the settings, so it cannot drift from them again.
- An agent is no longer renamed by its own updates. Claude Code was appearing as 2.1.260, 2.1.267, 2.1.283 — a new identity on every release, each with its own allowlist, baselines and history. The executable's path names it correctly, but that path cannot be read once a process has exited, and the fallback was the filename — which, for an installer that keeps one file per release, is the version. A version is never accepted as an identity now, the real name is remembered from the times the path was readable, and a one-time repair merges the identities already recorded, adding their traffic together rather than letting one overwrite another.
- Inspecting one app shows that app. "Inspect …'s Traffic" put the name in the search field, and that search reads response bodies too — so asking for one agent's traffic returned every page whose HTML happened to mention it. It scopes now, with a chip you can remove.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.9.3.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
eb1f8dbcaf1084c1b13cfdb9eb58154349c485cb8c96bb380e01c20fb584a4af Flowlight.dmg
9874ebce3ba2bd85d73aeede2eb42db9f6a2ee280337ef32918e488071be080f Flowlight-0.9.3.pkg
Flowlight 0.9.1
What's new in 0.9.1
- Inspect it from the row you found it on. Right-click an app or a destination in Live, Reports or AI Agents and Inspect opens already looking at it, instead of changing screen and retyping the name. The subject lands in the search field rather than a hidden filter, so you can widen it, narrow it or clear it without going back.
- Updates work again. 0.8.2 made the updater refuse a download it couldn't verify — correct, except that no release had ever published the checksum file it looks for. The checksums were being written into the release notes, where nothing can read them. They are published as an asset now, the file is attached to 0.9.0 as well so 0.8.2 can update, and a release that doesn't carry it fails to publish rather than shipping something nobody can install.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.9.1.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
6e577d64302422f3b8247710cce6b4082f5a530588c8800269cc5dac4a4d5473 Flowlight.dmg
fe19998c2494c4210b56cb306539ebf5c933d87597ba4ea7a06fdc4f5db1f9ca Flowlight-0.9.1.pkg
Flowlight 0.9.0
What's new in 0.9.0
- A new screen: Coverage. Every other screen says what happened. This one says what you would not have been told — per app, and separately for each of the three ways it can go wrong. Was the connection seen at all: the filter sees flows as they open, while the sampler reads counters once a second and misses whole connections between readings. Was the destination named, measured in bytes rather than connections, because one unnamed connection carrying a gigabyte is a bigger hole than a hundred carrying a kilobyte. And was it readable — with being on the Never decrypted list counted as the choice it is, not as a failure.
- What no engine sees is on the screen, not in a footnote: traffic from before capture started, system services content filters are never shown, apps that pin their certificates, QUIC, and an agent's local MCP server talking over a pipe. A coverage figure that counted only what it could see would be a reassurance rather than a fact.
- A crash that was waiting for a tenth screen. The sidebar derived ⌘1 to ⌘9 from each item's position, so adding a tenth produced an impossible keyboard shortcut and trapped on launch. It runs ⌘1–⌘9 then ⌘0 now, the way browsers number tabs.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.9.0.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
bbee277a5f24720e76047de2a6365f981bedccabf338505891486394c3903864 Flowlight.dmg
eb97b2d8b7619db61015e5aa5398517b26983fe24470c3ad15f436b88e01a7de Flowlight-0.9.0.pkg
Flowlight 0.8.2
What's new in 0.8.2
- An update is verified before it is installed. The checksum comparison treated "no checksum published", "no line for this disk image" and "the file didn't parse" as a match — every way of not knowing was read as knowing it was right. It now requires a published checksum and refuses the download without one.
- And it has to be signed by us. The installer checked the downloaded app's version and bundle identifier — strings inside the disk image that nothing signs — and then removed the quarantine flag, which is what would have made macOS check the signature on first launch. Updates are now validated against Apple's anchor and the Team ID of the running copy: an update has to come from whoever signed the Flowlight asking for it.
- A model endpoint can't take your key over plain HTTP. A compatible hosted endpoint sent an API key and a question about your own traffic to whatever address was typed. https:// is now required, except for loopback and private addresses, where the model is running on your own machine or network.
- Credential headers are recognised by their words, not by a list. Redaction knew the common names, so X-Access-Key or a vendor's own spelling was written to disk under a promise that says API keys are never stored. Anything whose name carries key, token, secret, auth, credential, session or signature is redacted now.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.8.2.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
9a6e39e41c99cdf793e061d85b2d994dcfa380da563f63b841d794f63d2c88e5 Flowlight.dmg
a4a35cde5a406c155cd372dc619c42f9261207308668af0f646738beaaf9acb6 Flowlight-0.8.2.pkg
Flowlight 0.8.1
What's new in 0.8.1
- Flowlight stops working when you are not looking at it. It was rebuilding the live chart and the per-app list every second whenever a window existed — including when that window was minimised, completely covered by another app, or parked on a Space you had left. The work was gated on SwiftUI's onAppear, which only says a window exists, not that anyone can see it. It now follows the window's occlusion state, so a hidden Flowlight builds nothing and the menu bar rates keep updating as before.
- A blocking system call no longer ran once a second, forever. Settings read "launch at login" in a property's default value, and that expression re-runs every time the settings pane is constructed — which happened on every traffic update, whether or not Settings was open. Reading it means a synchronous round trip to the system service manager on the main thread. It is now read once, when the pane actually appears.
- Together these are the difference between an idle Flowlight costing a measurable share of a CPU core and costing almost nothing. If macOS had been listing Flowlight under "Using Significant Energy" while it sat in the background, this is why.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.8.1.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
2c0600837a1e636d337e5f93d09e357f3f06a346b8874c1f3de946e054f8e0e6 Flowlight.dmg
e574754477b6231b93300ec9d214f4f2e86b2d9448cb733068536dc2f4cc0db5 Flowlight-0.8.1.pkg
Flowlight 0.8.0
What's new in 0.8.0
- Send an agent through the proxy in one click. HTTPS inspection can only read what goes through Flowlight, and a program reads its proxy settings once — when it starts. So an agent already running when you switched inspection on sends its model traffic straight past it, and its tool calls can't be read. Relaunch Through the Proxy quits the agent and starts it again with its HTTPS pointed at Flowlight: an app is relaunched by macOS with the settings applied, a command-line agent gets a Terminal window already running it. Electron agents are given Chromium's own proxy flag as well, because Chromium reads none of the usual variables.
- Capture, Devices and Rules fill the window like every other screen. They used to stop at a fixed width, which read as a different app; now the cards and rows stretch and only the paragraphs keep a readable measure.
- Ten languages, current. Every new string is translated, and two English phrases that were quietly wrong are fixed: a warning that read as "you will lose unsaved work" when the opposite is true, and a docs page that still called refusing connections a roadmap item three releases after it shipped.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.8.0.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
a4e23bd5fe17f7ee49219fe642e2207598891c245c1b55963ec365bb4d9996e5 Flowlight.dmg
b6cb11a8593c198c83c63456b64dc6f9dc9a5b46ed72469b4f1373ed08e280a9 Flowlight-0.8.0.pkg