Skip to content
CAI
Software that uses CAICheck a score

decolua/9router

32.5

Weak · 1 October 2026

137.6k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a local AI routing gateway and management dashboard that aggregates over 40 upstream providers into a single OpenAI-compatible endpoint. It normalizes diverse API formats for text, image, video, and audio services while handling user authentication, usage tracking, and secure proxy tunneling. The platform provides a unified interface for configuring provider connections, managing quotas, and integrating with CLI-based coding tools.

Features

API endpoint for managing Codex CLI model profiles

A new API route at /api/cli-tools/codex-profiles has been added, enabling users to create, list, and delete custom Codex CLI model profiles stored in the local \~/.codex directory. This allows the application to manage multiple model configurations (e.g., switching between different AI models) via the CLI tool, with profiles persisted as TOML files.

src/app/api/cli-tools/codex-profiles · high confidence

API endpoint to redeem free Claude usage limit resets

A new API route at /api/usage/\[connectionId\]/claude-reset has been added, allowing users with Claude OAuth connections to redeem free usage limit grants. This endpoint validates the connection type, refreshes authentication credentials, and calls the underlying service to consume a specific grant ID, returning the result or an appropriate error if the reset cannot be applied.

src/app/api/usage/\[connectionId\]/claude-reset · high confidence

Add API endpoint to manage DeepSeek TUI configuration

A new server-side route at /api/cli-tools/deepseek-tui-settings allows users to read, update, and reset the local DeepSeek TUI configuration file (config.toml). The endpoint detects whether the DeepSeek CLI is installed, parses the existing TOML settings, and supports writing new configurations for the 9Router provider (using an OpenAI-compatible mode) or resetting to default DeepSeek settings. This enables the dashboard to programmatically manage the CLI tool's provider settings, including API keys and base URLs.

src/app/api/cli-tools/deepseek-tui-settings · high confidence

Add API endpoints to enable and disable Tailscale tunneling

New API routes have been added to allow users to enable and disable the Tailscale tunnel. The \tailscale-enable\ endpoint calls the underlying enable function and subsequently configures tunnel monitoring based on current settings, while the \tailscale-disable\ endpoint performs the reverse operation, disabling the tunnel and updating the monitoring configuration. These endpoints provide the necessary backend support for toggling the tunnel state.

src/app/api/tunnel/tailscale-enable · high confidence

Add API route for Factory Droid CLI settings management

A new API endpoint at src/app/api/cli-tools/droid-settings/route.js has been added to manage the Factory Droid CLI configuration. This route allows users to check if the CLI is installed, read current settings (tolerating JSONC formats with trailing commas), and update or delete 9Router custom model configurations via GET, POST, and DELETE methods. The implementation supports multi-model setups, normalizes base URLs, and handles legacy single-model inputs for backward compatibility.

src/app/api/cli-tools/droid-settings · high confidence

Add Codex reset credits API endpoints

A new API route at /api/usage/\[connectionId\]/codex-reset-credits has been added to manage Codex rate-limit reset credits. The GET endpoint retrieves current credit status and expiry details for a specified connection, while the POST endpoint consumes a reset credit. Both endpoints support OAuth and access-token authentication, automatically refreshing credentials when necessary, and return structured responses including reset status, expiry windows, and specific error codes such as 'no\_credit'.

src/app/api/usage/\[connectionId\]/codex-reset-credits · high confidence

Add Cursor IDE OAuth token import endpoint

Users can now import and validate access tokens from the Cursor IDE's local SQLite database via the new /api/oauth/cursor/import endpoint. The API accepts an access token and machine ID, validates them against Cursor's services, and creates a persistent provider connection in the database, while also providing instructions on where to locate these credentials in the local state file.

src/app/api/oauth/cursor/import · high confidence

Add Devin CLI installation status check endpoint

A new API route at /api/cli-tools/devin-settings has been added to allow the dashboard to verify the presence and version of the Devin CLI. The endpoint performs a GET request that checks for the binary via PATH and known installation directories on Windows and macOS/Linux, returning the installation status, source path, and version string if found, or an error message and installation link if the CLI is missing.

src/app/api/cli-tools/devin-settings · high confidence

Add Grok Build configuration API endpoint

A new API route at src/app/api/cli-tools/grok-build-settings/route.js has been added to manage Grok Build settings. This endpoint allows users to read, update, and reset the local Grok configuration file (config.toml), including support for configuring subagent models and context windows. It also includes logic to detect if the Grok CLI is installed and handles API key resolution.

src/app/api/cli-tools/grok-build-settings · high confidence

Add OIDC and SAML 2.0 SSO authentication support

The authentication API now supports OpenID Connect (OIDC) and SAML 2.0 Single Sign-On (SSO) in addition to the existing password-based login. New endpoints have been added to handle the OIDC and SAML authorization flows, including starting the login process, handling provider callbacks, and exchanging tokens. A new status endpoint exposes the current authentication mode and provider configuration, while dedicated test endpoints allow administrators to validate their OIDC and SAML settings before enabling them. The login route has been updated to enforce SSO when these modes are active and to block password-based access if an SSO provider is configured.

src/app/api/auth · high confidence

Add OpenAI-compatible /v1/embeddings endpoint

A new API route at /v1/embeddings has been added to support OpenAI-compatible embedding requests. The endpoint handles POST requests by delegating to the existing embeddings handler and includes CORS configuration to allow cross-origin requests.

src/app/api/v1/embeddings · high confidence

Add OpenAI-compatible audio API endpoints for speech, transcription, and voice listing

New API routes have been added to the v1 audio namespace to support text-to-speech, speech-to-text, and voice management. The /v1/audio/speech endpoint enables TTS by delegating to the internal handler, while /v1/audio/transcriptions provides Whisper-compatible STT with support for larger file uploads. Additionally, /v1/audio/voices allows users to list available voices from multiple providers (ElevenLabs, Deepgram, Inworld, Edge TTS, and local device), returning them in an OpenAI-compatible format with provider-specific aliases for use in speech requests.

src/app/api/v1/audio · high confidence

Add OpenRouter and Vertex AI (Veo) video generation providers

Users can now generate videos using OpenRouter and Google's Vertex AI (Veo) in addition to existing providers. The new OpenRouter adapter supports video generation jobs with standard async polling, while the Vertex AI adapter translates requests to Google's predictLongRunning API, handling authentication via Service Account JSON or OAuth tokens. The Vertex implementation includes strict validation to reject job IDs and model IDs that could escape URL paths, ensuring safe request construction.

open-sse/handlers/videoProviders · high confidence

Add Responses API transformer and stream-to-JSON converter

The transformer module now includes a new \responsesTransformer.js\ that converts OpenAI Chat Completions SSE into the Codex Responses API SSE format, including support for reasoning summaries and structured logging. Additionally, a \streamToJsonConverter.js\ has been added to aggregate Responses API SSE streams into a single JSON response, enabling non-streaming client support for providers that only offer streaming.

open-sse/transformer · high confidence

Add System One (Jev) decision endpoint

A new POST endpoint at /v1/systemone is now available to handle System One (Jev) decisions. The route includes CORS support for cross-origin requests and delegates processing to the existing SSE handler.

src/app/api/v1/systemone · high confidence

Add Tailscale installation API with SSE progress updates

A new API endpoint at /api/tunnel/tailscale-install has been added to handle Tailscale installation. The endpoint accepts a POST request with an optional sudo password and returns a Server-Sent Events (SSE) stream to report installation progress, completion, or errors. It detects the operating system (Windows, macOS with Homebrew, or other) to determine if a sudo password is required, and uses the 'windowsHide' option for child process execution to ensure compatibility on Windows environments.

src/app/api/tunnel/tailscale-install · high confidence

Add console log retrieval and real-time streaming endpoints

New API routes have been added to the translator console-logs area to allow users to retrieve buffered logs via a standard JSON endpoint and subscribe to live log updates via a Server-Sent Events (SSE) stream. The GET route returns previously captured logs, while the stream route initializes log capture at server boot, sends any existing buffered logs upon connection, pushes new log lines in real-time, and includes a keepalive mechanism to maintain the connection. The stream implementation also includes robust cleanup logic to prevent listener leaks when clients disconnect.

src/app/api/translator/console-logs · high confidence

Add headless API key authentication for Kiro

Users can now authenticate with the Kiro provider using a long-lived API key via a new headless import endpoint at /api/oauth/kiro/api-key. This feature allows users to bypass standard OAuth flows by submitting an API key and region, which is validated against the Amazon Q model catalog and stored with a one-year expiration. The implementation includes SSRF hardening by suppressing upstream error details in the response.

src/app/api/oauth/kiro/api-key · high confidence

Add media provider detail page with custom embedding support

Users can now view detailed information for individual media providers via a new page at /dashboard/media-providers/\[kind\]/\[id\]. This page displays provider metadata, API key links, and kind-specific configuration (such as search, fetch, TTS, STT, embedding, or systemone configs). It includes dedicated cards for connections and models (hidden for TTS/webSearch/webFetch), and renders kind-specific example cards for embedding and TTS. A key addition is support for custom embedding nodes: users can edit and delete custom embeddings directly from this view, with the UI reflecting the custom prefix and providing specific actions for these nodes.

src/app/(dashboard)/dashboard/media-providers/\[kind\]/\[id\] · high confidence

Add tunnel shared utilities for DNS, connectivity, state, and watchdog configuration

New shared modules have been added to the tunnel library to support connection stability and state management. A DNS resolver (dnsResolver.js) now forces public DNS servers (Cloudflare, Google) to bypass OS negative caching, with a fallback to the system resolver. An internet connectivity checker (internetCheck.js) verifies reachability via a TCP connection to Cloudflare. Tunnel state is now persisted to a local JSON file (state.js) with helpers for loading, saving, clearing, and generating short IDs. Finally, watchdog configuration (watchdogConfig.js) defines timing intervals for restarts and network checks, and includes a regex to skip virtual network interfaces (like utun, awdl) to prevent false network-change triggers.

src/lib/tunnel/shared · high confidence

Add xAI Grok Imagine video generation and editing endpoints

New API routes have been added under /v1/videos to support xAI Grok Imagine capabilities. Users can now create async video generations via POST /v1/videos/generations, create video edits via POST /v1/videos/edits, and create video extensions via POST /v1/videos/extensions. Additionally, a GET /v1/videos/{id} endpoint is available to poll the status of these async jobs.

src/app/api/v1/videos · high confidence

Added API endpoints to enable and disable the tunnel service

New API routes have been introduced to allow users to programmatically start and stop the tunnel. The enable endpoint triggers the tunnel startup and includes an 8-second delay to allow DNS propagation at the Cloudflare edge before returning success, while the disable endpoint stops the tunnel and updates the monitoring configuration. Both endpoints handle errors by returning appropriate JSON responses with status codes.

src/app/api/tunnel/enable · high confidence

Added API endpoints to load and save translator log files

New API routes have been added to allow reading and writing specific translator log files. The load endpoint retrieves content from predefined JSON and text files in the logs/translator directory, while the save endpoint writes content to these same restricted filenames. Both endpoints enforce a strict allowlist of file names to prevent unauthorized file access or creation.

src/app/api/translator/load, src/app/api/translator/save · high confidence

Added Kiro OAuth import and social login endpoints

New API routes have been added to support importing Kiro IDE tokens and authenticating via social providers (Google, GitHub). The \/api/oauth/kiro/import\ endpoint now accepts refresh tokens and, for IDC (organization) tokens, requires clientId, clientSecret, and region to refresh via the regional AWS OIDC endpoint. The \/api/oauth/kiro/social-authorize\ and \/api/oauth/kiro/social-exchange\ endpoints handle the PKCE-based social login flow, generating authorization URLs and exchanging codes for access tokens to create provider connections.

src/app/api/oauth/kiro/import · high confidence

Added internal model health-check endpoint

A new internal API route at /api/models/test has been introduced, allowing the application to probe the availability and responsiveness of configured model providers. The endpoint accepts a model identifier and a kind (llm, embedding, image, stt, or systemone) and returns latency and success status, enabling users to verify that their model integrations are correctly configured and reachable before use.

src/app/api/models/test · high confidence

Added service worker for push notifications

A new service worker (sw.js) has been added to the public directory to enable push notification support. It handles incoming push events by displaying notifications with customizable bodies, icons, and vibration patterns, and manages notification clicks by closing the notification and opening the application window.

public · high confidence

Added usage statistics streaming endpoint

A new API route at /api/usage/stream has been introduced to provide real-time usage statistics via Server-Sent Events (SSE). This endpoint allows clients to subscribe to live updates regarding active requests, recent activity, and error providers, ensuring the UI reflects changes immediately without requiring manual refreshes.

src/app/api/usage/stream · high confidence

App shell overhaul: PWA manifest, runtime i18n, and theme flash fix

The application now supports Progressive Web App (PWA) installation via a new web manifest and adds runtime internationalization with English, Vietnamese, and Simplified Chinese support. To improve the user experience on reload, the root layout now applies the persisted theme before the first paint, eliminating the light-theme flash, and defers the visibility of Material Symbols icons until the font is fully loaded. Additionally, the home page now redirects users directly to the dashboard.

src/app · high confidence

Background sync of model capabilities from models.dev

The model catalog now automatically refreshes model capabilities (such as context windows and token limits) from the models.dev API in the background every 24 hours. This ensures that the application uses up-to-date information about supported models and their constraints, reducing reliance on static, hand-written configuration tables. The sync process runs asynchronously to avoid blocking server startup and handles errors gracefully to prevent service disruption if the external source is unavailable.

src/lib/modelCatalog · high confidence

Bulk import Grok CLI accounts via API

A new API endpoint at /api/oauth/grok-cli/bulk-import allows users to import multiple Grok CLI OAuth accounts in a single request. The endpoint accepts an array, a single object, or a wrapped object containing account data, supporting both snake\_case and camelCase field names for tokens and email. It processes each account to create provider connections, returning a summary of successes and failures for each item.

src/app/api/oauth/grok-cli · high confidence

Centralized configuration for CLI tools, TTS providers, and app settings

This change consolidates and expands shared constants to support new product capabilities. It introduces a new \cliTools.js\ file defining MITM tools (Antigravity, Kiro) and CLI tools (Claude, OpenClaw, Codex, Copilot, OpenCode, Cowork, Hermes, Droid) with specific model aliases and configuration types. A new \ttsProviders.js\ file centralizes UI behavior and configuration for a wide range of Text-to-Speech providers (Google, OpenAI, ElevenLabs, Edge, Nvidia, Minimax, Gemini, Xiaomi MiMo, etc.). The \config.js\ file is updated to rename the app to '9Router Proxy', integrate the version from \package.json\, and add configuration for GitHub links, auto-updater settings, console logging, and a quota auto-ping feature for Claude and Codex. Additionally, \providers.js\ is refactored to derive provider lists (Free, OAuth, API Key, Web Cookie) from a central registry, introduces support for 'cookie' authentication, and adds helper functions for OpenAI/Anthropic compatible providers and media kinds. New files include \coworkPlugins.js\ for default remote and local stdio plugins, \locales.js\ for locale display flags, \mitmToolHosts.js\ for per-tool DNS mapping, \providersDisplay.js\ for UI display config with risk notices, \skills.js\ for agent skills metadata, and \colors.js\ which updates sidebar and border colors to use semi-transparent RGBA values.

src/shared/constants · high confidence

Claude settings API now supports Exa MCP and auto-compact window configuration

The Claude settings API route now handles two new configuration options: enabling the Exa MCP server and setting the auto-compact window threshold. When users update settings, the API writes the Exa MCP configuration to \~/.claude.json (which the Claude Code CLI reads) and sets the CLAUDE\_CODE\_AUTO\_COMPACT\_WINDOW environment variable. The API also tolerates JSONC syntax (trailing commas) in the settings file to prevent errors, normalizes the ANTHROPIC\_BASE\_URL to include the /v1 suffix, and preserves existing authentication tokens during updates. The GET endpoint now reports whether the Exa MCP is enabled, and the DELETE endpoint cleans up the Exa MCP configuration.

src/app/api/cli-tools/claude-settings · high confidence

Database backup import and export with re-authentication

A new API endpoint at /api/settings/database now allows users to export and import the application database. To ensure security, the export (GET) operation requires re-authentication via a dashboard password (unless a trusted CLI token is present), and the import (POST) operation also requires password verification. Additionally, upon a successful database import, the system automatically re-applies any configured outbound HTTP proxy settings to ensure they take effect immediately.

src/app/api/settings/database · high confidence

Database migration to SQLite and introduction of advanced routing and update infrastructure

The application has migrated its local data storage from lowdb (JSON files) to a new SQLite-based database layer, significantly improving reliability and performance for storing provider connections, usage statistics, and request details. This change introduces new capabilities for managing AI provider routing, including the ability to create and manage 'combos' (multi-model groups) with round-robin strategies, configure per-provider connection presets for tools like Cursor and Claude, and define custom models. Additionally, a robust, cross-platform self-update mechanism has been added, allowing the application to safely update itself by managing process lifecycles and file locks, while a new console log capture system provides better visibility into application behavior for debugging.

src/lib · high confidence

Dynamic configuration support for Pi, OMP, Crush, ForgeCode, Smelt, and CodeWhale

The CLI tools section now provides dedicated API endpoints to manage 9Router integration for six additional CLI-based AI tools. New server routes allow users to read, apply, and remove 9Router settings for Pi (updating \models.json\), Oh My Pi (updating \models.yml\ and \agent.db\), Crush (updating \crush.json\), ForgeCode (updating \config.toml\), Smelt (updating \config.json\), and CodeWhale (updating \config.toml\). Each endpoint handles provider-specific configuration formats, normalizes base URLs, resolves API keys, and detects existing 9Router configurations.

(repo-wide) · high confidence

Dynamic model catalog integration for /v1/models

The /v1/models API endpoint now supports live model resolution for multiple providers (Kiro, Qoder, Kimchi, GitHub Copilot, Cline, ClinePass, Grok CLI, Cursor, and Zed) by fetching real-time catalogs based on user credentials, rather than relying solely on static lists. This change introduces a provider-specific resolver system that dynamically populates the model list, including handling of aliases, capability metadata (such as tool support), and filtering of disabled models. It also ensures that compatible provider models and custom models are correctly included in the listing, with proper handling of model kinds (LLM, image, TTS, etc.) and token limits.

src/app/api/v1/models · high confidence

Endpoint dashboard gains tunnel health monitoring and security controls

The Endpoint dashboard now includes a dedicated section for managing Cloudflare Tunnel and Tailscale access, featuring real-time client-side health probes to verify reachability and prevent UI flicker during network hiccups. A new security gate blocks remote exposure if the dashboard login is disabled or the default password is in use, ensuring safe remote access. The UI has been refactored with reusable components for endpoint rows, status alerts, and security warnings, and introduces settings to toggle API key requirements and visibility.

src/app/(dashboard)/dashboard/endpoint · high confidence

Expand provider registry with new gateways and split Alibaba services

The provider registry now includes several new OpenAI-compatible aggregators (Agnes AI, Atria Dawn, B.AI, API.airforce) and regional Alibaba services (Alibaba Coding, Alibaba Studio, Alibaba Token Plan) alongside existing providers like CodeBuddy CN/Intl and Cloudflare AI. This update also adds support for new model families and capabilities, including Gemini 3.8 Flash, GPT-6.1 Sol, and image generation via Black Forest Labs and Codex, while refining authentication and transport configurations for existing providers like Cline and Anthropic.

open-sse/providers/registry · high confidence

Expanded OAuth provider support and proxy management

The OAuth API now supports additional providers including GitLab Duo (via Personal Access Token), xAI, Xiaomi MiMo, Zed, Trae, and Windsurf. This update introduces dynamic local proxy servers for handling OAuth callbacks for desktop and IDE-integrated providers, enabling device-code flows and secure token exchange. Users can now authenticate with these new services, with the system automatically managing proxy lifecycles and session states to facilitate seamless login experiences across different platforms.

src/app/api/oauth/\[provider\] · high confidence

Expanded OAuth provider support with new authentication flows

The OAuth provider registry in src/lib/oauth/providers now includes handlers for a wide range of new services, enabling users to authenticate with platforms such as Z.ai (GLM), Meta Muse, Qoder CN, CodeBuddy (CN and International), Cline, ClinePass, GitLab Duo, KiloCode, Kimi, Kimchi, Trae, Windsurf, and Zed. The implementation introduces diverse authentication mechanisms to match each provider's requirements, including standard authorization code flows with PKCE (e.g., Claude, Codex, GitLab), device code polling flows for CLI-based logins (e.g., GitHub, Grok CLI, KiloCode, Z.ai), and specialized token import or browser-token validation flows (e.g., Cursor, Kimchi). A shared utility module (\_shared.js) was added to support common parsing tasks across providers like Trae and Windsurf, and the central index.js orchestrates these new providers while maintaining backward compatibility for legacy aliases like kimi-coding.

src/lib/oauth/providers · high confidence

Expanded profile settings with SSO, proxy, and database management

The Profile page now supports comprehensive configuration for Single Sign-On (SAML and OIDC), outbound HTTP proxy settings, and database import/export operations. Users can configure SAML endpoints and certificates, manage OIDC issuer URLs and client secrets, and test these connections directly from the UI. Additionally, the page includes controls to enable and test outbound proxy connections, as well as a secure workflow for exporting and importing the application database with re-authentication and SSRF protection. The layout also integrates a language switcher and password change functionality.

src/app/(dashboard)/dashboard/profile · high confidence

Expanded text-to-speech provider support with unified registry

The TTS handler system has been significantly expanded to support a wider variety of text-to-speech providers. New built-in adapters include Google Translate TTS, Microsoft Edge TTS, ElevenLabs, Gemini TTS, Xiaomi MiMo, MiniMax, and OpenRouter, alongside existing support for OpenAI and local device synthesis. A new generic format dispatcher allows configuration-driven integration with providers like Deepgram, Nvidia NIM, HuggingFace, Cartesia, PlayHT, Inworld, Coqui, and Tortoise. The system now features a centralized registry for provider selection, model/voice parsing, and voice fetching, enabling users to choose from a much broader range of voice options and synthesis engines.

open-sse/handlers/ttsProviders · high confidence

Expanded usage tracking for new and existing AI providers

The usage service now supports quota and balance tracking for a wider range of providers. New handlers have been added for CodeBuddy CN (distinguishing between recurring refill packs and one-time bonus credits), DeepSeek (displaying multi-currency balances), and GLM Coding (supporting both TOKENS\_LIMIT and CREDIT\_LIMIT with dynamic intervals). Existing providers have also been enhanced: Antigravity now tracks weekly quotas for Gemini and Claude/GPT families with caching to reduce API load, while Claude usage now supports limit reset grants and handles OAuth rate limits more gracefully. Codex usage now displays reset credit expiry details and tracks GPT-5.3-Codex-Spark windows, and Grok CLI usage now fetches the SuperGrok weekly pool via gRPC-web and displays public subscription tiers.

open-sse/services/usage · high confidence

Expose Kilo free models via new API endpoint

A new API route at /api/providers/kilo/free-models has been added to fetch and expose the list of free models available from the Kilo provider. The endpoint retrieves data from the Kilo API, filters for models marked as free, and implements an in-memory cache with a one-hour TTL to reduce external API calls. Users can now access this curated list of free models through the application's API, with fallback behavior that returns cached data or an error response if the external service is unavailable.

src/app/api/providers/kilo · high confidence

Expose local stdio MCP plugins over SSE

The API at src/app/api/mcp now bridges local stdio-based Model Context Protocol (MCP) plugins to HTTP clients via Server-Sent Events (SSE). New endpoints at /api/mcp/\[plugin\]/sse and /api/mcp/\[plugin\]/message allow external tools to connect to a plugin's SSE stream and send messages, enabling local MCP plugins to be accessed remotely over standard HTTP.

src/app/api/mcp · high confidence

Headroom proxy lifecycle and extras management

The application now manages the Headroom compression proxy as a background process, allowing users to start, stop, and restart it with specific compression extras (code-aware AST compression and ML-based Kompress). A new detection module identifies the installed Headroom CLI and compatible Python interpreter (\>=3.10), probes the proxy's health status, and verifies which extras are active. Users can install or upgrade these compression extras via the UI, with the system handling the underlying pip installation and proxy restarts automatically.

src/lib/headroom · high confidence

Headroom proxy lifecycle management and extras installation API

This change introduces a new set of API endpoints under /api/headroom to manage the Headroom proxy service and its optional compression extras. Users can now start, stop, and restart the proxy via dedicated routes (start, stop, restart), with the system enforcing that loopback proxies are managed internally while external proxies must be handled outside the application. A new status endpoint provides current proxy state and process ID, while a proxy route transparently forwards requests to the Headroom dashboard, rewriting internal fetch calls to ensure the UI functions correctly through the app. Additionally, a new extras route allows users to detect, install, and uninstall compression extras, with support for polling installation logs for progress feedback.

src/app/api/headroom · high confidence

Initial release of 9Router with Docker support and documentation

This change introduces the initial codebase for 9Router, a local AI routing gateway and Next.js dashboard that exposes an OpenAI-compatible endpoint to route traffic across 40+ upstream providers. The release includes a production-ready Dockerfile and docker-compose.yml (bundling the Headroom sidecar by default), a custom HTTP server wrapper for secure client IP derivation, and comprehensive documentation (CLAUDE.md, DOCKER.md, .env.example). It also establishes the project's licensing (MIT) and version control configuration.

(repo-wide) · high confidence

Introduce OpenCode CLI settings management with multi-model and subagent support

This change adds a new API route at src/app/api/cli-tools/opencode-settings to manage the local OpenCode CLI configuration file (opencode.json). The endpoint detects whether the CLI is installed, reads the existing config (tolerating JSONC formats like trailing commas), and allows users to configure the '9router' provider. Key capabilities include multi-model support (storing an array of models with input/output modalities), setting an active model, configuring a base URL and API key, and defining a dedicated 'explorer' subagent model. The implementation ensures that provider options are merged correctly and handles cases where the config file is missing or corrupted gracefully.

src/app/api/cli-tools/opencode-settings · high confidence

Introduce Zustand-based global stores with caching and notification support

The application state management has been updated to use Zustand, introducing new global stores for header search, notifications, and settings. Users now benefit from a centralized toast notification system that provides success, error, warning, and info feedback with auto-dismissal capabilities. Additionally, the provider and settings stores now implement client-side caching with a configurable TTL, reducing unnecessary network requests and improving performance by skipping fetches when data is fresh.

src/store · high confidence

Introduce centralized schema enums for translator formats

Added a new \open-sse/translator/schema\ module that centralizes pure-data enums and constants for the message translator. This includes discriminators for content blocks (OpenAI, Claude, and OpenAI Responses API), finish/stop reasons (OpenAI, Claude, Gemini), message roles (standard and Gemini-specific), and default fallback values for model IDs and image MIME types. These constants are exported via a barrel file to support consistent type handling across the translator logic.

open-sse/translator/schema · high confidence

Introduce proxy pool management with multi-provider relay support

The dashboard now includes a dedicated page for managing proxy pools, allowing users to create, edit, and delete pools with options for strict proxy binding. This update adds native integration for deploying relays via Vercel, Cloudflare Workers, and Deno Deploy, each with its own configuration modal. The interface also features batch import capabilities, health checking with progress tracking, and replaces native browser confirmation dialogs with a custom modal component for safer deletion workflows.

src/app/(dashboard)/dashboard/proxy-pools · high confidence

Native image generation support across multiple providers

The application now supports native image generation through a new modular adapter system located in \open-sse/handlers/imageProviders\. This change introduces dedicated handlers for a wide range of providers, including OpenAI, Codex (ChatGPT Plus/Pro), Google Gemini, Anthropic (Antigravity), Stability AI, Black Forest Labs (FLUX), HuggingFace, Fal.ai, Runway ML, Cloudflare Workers AI, NanoBanana, ComfyUI, and SD WebUI. The implementation includes a shared base module for common utilities (such as size-to-aspect-ratio mapping and polling logic) and a central registry (\index.js\) that wires these adapters into the system, enabling users to generate images via text prompts and image editing across these diverse backends.

open-sse/handlers/imageProviders · high confidence

New /v1/models/info endpoint for model metadata

A new API endpoint at /v1/models/info has been added to retrieve detailed metadata for specific models. Users can query this endpoint with an id parameter (formatted as alias/modelId) and an optional kind parameter to disambiguate models with the same ID across different types (e.g., LLM vs STT). The response includes the model's name, kind, owner, endpoint path, and optional details like parameters, capabilities, context window, and dimensions. For TTS models from supported providers, it also includes a voicesUrl. For web search and fetch capabilities, it exposes specific configuration details like search types and max results.

src/app/api/v1/models/info · high confidence

New API endpoint for fetching and filtering suggested models from various providers

A new API route at /api/providers/suggested-models has been introduced to aggregate and filter model suggestions from multiple upstream sources. The endpoint accepts a provider URL and a filter type (openrouter-free, opencode-free, opencode-go, mimo-free, or airforce-free) to return a curated list of models. It applies specific logic for each provider, such as filtering OpenRouter models by zero cost and context length, handling OpenCode's free models (including known non-suffixed IDs and excluding dead ones), selecting all models from the OpenCode Go catalog, filtering for MiMo models, and selecting free, chat-capable models from Airforce.

src/app/api/providers/suggested-models · high confidence

New API endpoint for managing MITM tool aliases

A new API route has been added at /api/cli-tools/antigravity-mitm/alias to allow users to retrieve and update model alias mappings for specific CLI tools. The GET endpoint fetches current aliases, while the PUT endpoint allows saving new mappings, provided that DNS interception is already enabled for the target tool. This change introduces a new capability for configuring how the Antigravity MITM tool resolves models.

src/app/api/cli-tools/antigravity-mitm/alias · high confidence

New API endpoint for managing custom models

A new API route at /api/models/custom has been added, enabling users to list, add, and delete custom models via GET, POST, and DELETE requests. The endpoint supports sanitizing capability flags and STT transport markers to ensure data integrity when registering new models.

src/app/api/models/custom · high confidence

New API endpoint for retrieving recent usage logs

A new GET endpoint at /api/usage/logs has been added, allowing users to fetch the 200 most recent usage logs via the application's API. This provides programmatic access to recent activity data, with error handling that returns a 500 status code if the retrieval fails.

src/app/api/usage/logs · high confidence

New API endpoint for retrieving usage history

A new GET endpoint at /api/usage/history has been added, allowing users to retrieve their AI request usage statistics. The endpoint calls the underlying usage database to fetch stats and returns them as JSON, handling errors by returning a 500 status with an error message.

src/app/api/usage/history · high confidence

New API endpoint to detect Tailscale installation and daemon status

A new API route at /api/tunnel/tailscale-check has been added to provide detailed diagnostics about the local Tailscale environment. The endpoint performs parallel probes to determine if Tailscale is installed, whether the system daemon or a custom daemon (via socket probe) is running, if the user is logged in, and if a password is cached. It also checks for Homebrew availability on macOS. This allows the application to accurately assess connectivity prerequisites and handle authentication states based on the actual system configuration.

src/app/api/tunnel/tailscale-check · high confidence

New API endpoint to import Microsoft SSO credentials via CLIProxyAPI

Users can now import Microsoft external identity provider accounts by sending a POST request to /api/oauth/kiro/import-cli-proxy. The endpoint accepts authentication JSON (from cliProxyAuth, auth, or json fields), normalizes the token data, and creates a new Kiro OAuth connection with the provided access and refresh tokens, returning the new connection ID and email on success.

src/app/api/oauth/kiro/import-cli-proxy · high confidence

New API endpoint to list unique AI providers

A new GET /api/usage/providers endpoint has been added to return a list of distinct AI providers used in request details. This endpoint queries the database for distinct provider IDs and enriches them with human-readable names by mapping against local node configurations and shared provider constants, specifically designed to avoid Out-Of-Memory errors that occurred when parsing full JSON blobs.

src/app/api/usage/providers · high confidence

New API endpoint to test provider model connectivity

A new POST endpoint at /api/providers/\[id\]/test-models has been added, allowing users to verify connectivity for all models associated with a specific provider connection. The endpoint resolves the provider's model list (fetching live models for OpenAI/Anthropic-compatible providers if none are pre-configured) and sequentially pings the first model to handle token refresh, then tests the remaining models in parallel, returning a detailed status report for each.

src/app/api/providers/\[id\]/test-models · high confidence

New API endpoint to validate provider node connectivity and credentials

A new POST endpoint at /api/provider-nodes/validate has been introduced to allow users to verify that their API keys and base URLs are correct for various provider types. The endpoint supports validation for OpenAI-compatible, Anthropic-compatible, and custom embedding providers, automatically falling back to chat completion tests if the models endpoint is unavailable. It includes an SSRF guard to prevent requests to internal or private network addresses, enforces a 10-second timeout on all network calls, and returns user-friendly error messages for common issues like connection refused, DNS failures, or unauthorized access.

src/app/api/provider-nodes/validate · high confidence

New API endpoints for jcode configuration and batch status retrieval

The dashboard now supports configuring the jcode CLI tool and retrieving the status of all connected CLI tools in a single request. A new batch endpoint at /api/cli-tools/all-statuses aggregates the installation and configuration status of tools such as Claude, Codex, Devin, and jcode, allowing the UI to display a comprehensive overview without multiple round-trips. Additionally, a dedicated endpoint for jcode allows users to install, configure (including setting up the 9router provider with API keys), and remove settings directly from the dashboard.

src/app/api/cli-tools/all-statuses · high confidence

New API endpoints for managing pricing configurations

A new pricing API route has been added at /api/pricing, enabling users to retrieve, update, and reset pricing configurations via GET, PATCH, and DELETE methods. The endpoint validates input data to ensure pricing fields (input, output, cached, reasoning, cache\_creation) are non-negative numbers, and supports resetting specific models, entire providers, or all pricing data. A separate endpoint at /api/pricing/defaults allows fetching the default pricing configuration provided by the open-sse library.

src/app/api/pricing · high confidence

New API endpoints for managing provider nodes

Added REST API endpoints to create, list, update, and delete provider nodes, supporting OpenAI-compatible, Anthropic-compatible, and custom embedding types. The new endpoints handle provider node creation with type-specific validation and base URL sanitization, allow updates to node details and associated connections, and enable deletion of nodes along with their linked connections.

src/app/api/provider-nodes · high confidence

New API endpoints for web search and URL fetching

Added new API routes at /v1/search and /v1/web/fetch to expose web search and URL fetching capabilities. These endpoints handle CORS preflight requests and delegate POST processing to their respective server-sent event handlers, enabling external clients to trigger search and fetch operations via standard HTTP POST requests.

src/app/api/v1/search, src/app/api/v1/web · high confidence

New API route for MITM server management

A new Next.js API route at src/app/api/cli-tools/antigravity-mitm/route.js has been added to expose MITM (Man-in-the-Middle) server controls. This endpoint allows users to start, stop, and query the status of the MITM server, as well as enable or disable DNS interception for specific tools. It includes logic to handle sudo/administrator privileges, cache passwords securely, and manage a configurable MITM router base URL.

src/app/api/cli-tools/antigravity-mitm · high confidence

New Basic Chat interface for testing models

A new Basic Chat page has been added to the dashboard, allowing users to test AI models directly. This feature includes a client-side interface that manages chat sessions (with local storage persistence), supports multiple providers (including Anthropic and OpenAI-compatible endpoints), and handles multimodal inputs like image attachments. It provides a simplified, standalone chat experience distinct from the main application flow.

src/app/(dashboard)/dashboard/basic-chat · high confidence

New CLI API client with file-based authentication

The CLI now includes a new API client module (cli/src/cli/api/client.js) that handles communication with the backend service. This client implements a file-based authentication mechanism, generating tokens by combining a machine ID and a randomly generated secret stored in the user's data directory, ensuring secure and persistent sessions. It provides functions to configure connection details (host, port, protocol) and make HTTP requests to various API endpoints, including provider management operations.

cli/src/cli/api · high confidence

New CLI build and packaging scripts

Added build scripts for the CLI package, MITM proxy, and macOS ARM64 tray binary. The CLI build script handles Next.js standalone output (including Next.js 16 nested paths), copies required API artifacts, and manages version syncing. The MITM build script bundles the proxy server using esbuild to ensure a self-contained runtime. The tray build script compiles a native Apple Silicon menubar binary from the systray-portable source, verifies its architecture and signature, and checks the SHA256 against the pinned value in trayRuntime.js.

cli/scripts · high confidence

New CLI commands for remote server connection and video generation

The 9Router CLI now includes two new subcommands: \connect\ and \xai video\. The \connect\ command allows users to configure local AI coding tools (such as Claude Code, Codex, and OpenCode) to point at a remote 9Router server without running a local instance, handling authentication and API key management automatically. The \xai video\ command enables the generation of Grok Imagine videos via the local gateway, supporting features like image-to-video and custom output paths. These additions are accompanied by updated documentation and packaging files to support the new functionality.

cli · high confidence

New CLI menus for API keys, CLI tools, combos, providers, and settings

The CLI now includes a new interactive menu system under \cli/src/cli/menus\ that lets users manage API keys (create, view, copy, delete), configure CLI tools like Claude Code and Codex CLI (quick setup, model selection, reset), manage model combos (create, edit, delete, view details), configure and connect to AI providers (OAuth and API key auth for providers like Claude, OpenAI, Gemini, Z.ai GLM, Kimi, etc.), and adjust settings (tunnel on/off, RTK/Headroom toggles, password reset, auth mode reset). This provides a structured, menu-driven interface for these previously command-line or manual tasks.

cli/src/cli/menus · high confidence

New CLI tool for managing Hermes agent configuration

A new API route has been added to manage the local Hermes agent's YAML configuration and environment variables. Users can now view and update the default model, delegation model, and auxiliary role settings via a structured API, with support for detecting 9router proxy configurations.

src/app/api/cli-tools/hermes-settings · high confidence

New Console Log viewer in the dashboard

A new Console Log page has been added to the dashboard, allowing users to view real-time application logs. The feature uses Server-Sent Events to stream log lines from the server, displaying them with color-coded severity levels (LOG, INFO, WARN, ERROR, DEBUG) and automatically scrolling to the latest entries. Users can also clear the log history via a dedicated button.

src/app/(dashboard)/dashboard/console-log · high confidence

New Cowork MCP registry and settings APIs

Added two new API routes under src/app/api/cli-tools: a cowork-mcp-registry endpoint that fetches and caches a filtered list of commercial MCP servers from the Anthropic registry, and a cowork-settings endpoint that manages local configuration for the Cowork tool, including reading/writing the Claude desktop config, injecting CLI tokens for local SSE bridges, and cleaning up legacy stdio entries.

src/app/api/cli-tools/cowork-settings · high confidence

New Cursor auto-import API endpoint

Added a new API route at /api/oauth/cursor/auto-import that automatically detects and extracts Cursor access tokens and machine IDs from the local SQLite database. The implementation uses better-sqlite3 as the primary method for reading the database, with a fallback to the sqlite3 CLI if necessary, and supports Windows, macOS, and Linux platforms.

src/app/api/oauth/cursor/auto-import · high confidence

New GitBook documentation site with multi-language support

A new Next.js-based documentation site has been added to the \gitbook\ directory, providing a structured, multi-language knowledge base for the 9Router product. The site supports English, Vietnamese, Simplified Chinese, Spanish, and Japanese, with a language switcher component and localized navigation. It features a responsive layout with a sidebar for navigation, a table of contents for in-page context, and styled markdown rendering for content such as installation guides, provider details, combo strategies, and deployment instructions (localhost and cloud). The site is statically generated for performance and includes a root redirect to the default language.

gitbook · high confidence

New Kiro external identity provider support and OAuth helper refactoring

Users can now import Microsoft SSO credentials via the CLIProxyAPI external identity provider (Kiro), with the system automatically resolving the AWS profile ARN and validating the Microsoft token endpoint. This change also introduces new OAuth helper utilities for JWT decoding, email extraction, and endpoint validation, while consolidating the provider configuration logic in \src/lib/oauth/providers.js\ to support these new flows.

src/lib/oauth · high confidence

New MITM handlers for Antigravity, Copilot, and Kiro IDEs

The MITM proxy now includes dedicated interceptors for Antigravity, Copilot, and Kiro. The Antigravity handler forwards requests to the router's /v1/chat/completions endpoint, while the Copilot handler maps various IDE endpoints (such as /chat/completions and /v1/messages) to corresponding router paths. The Kiro handler implements a full AWS EventStream translator, handling binary frame construction, SSE-to-EventStream conversion, and specific fixes for inline images and tool calls. A base module supports these handlers with configurable router URLs and SSE piping utilities.

src/mitm/handlers · high confidence

New MITM management page in the dashboard

A new MITM (Man-in-the-Middle) section has been added to the dashboard, providing a dedicated interface for managing local proxy services that intercept HTTPS traffic for IDE tools like Antigravity, GitHub Copilot, and Kiro. The page displays a security warning regarding Terms of Service violations and account bans, and includes components to monitor the MITM server status, manage API keys, and configure tool-specific DNS settings. It aggregates data from active providers and model aliases to help users control how requests are redirected to their local providers.

src/app/(dashboard)/dashboard/mitm · high confidence

New OAuth providers (Cursor, Kiro, Qoder, xAI, Kimchi) and removal of Qwen

Users can now authenticate with five new providers: Cursor (importing tokens from the local IDE database), Kiro (AWS Builder ID/IDC and social login), Qoder (device code flow with PKCE), xAI/Grok (PKCE OAuth), and Kimchi (browser-based login). The Qwen provider has been removed. Additionally, the Antigravity and Gemini services now use a shared metadata helper to align their API headers, and the Codex service now records the last token refresh time.

src/lib/oauth/services · high confidence

New OpenAI-compatible image generation endpoint

A new POST endpoint at /v1/images/generations has been added to the API, allowing users to generate images via an OpenAI-compatible interface. The route includes CORS support and delegates the generation logic to the existing image generation handler.

src/app/api/v1/images · high confidence

New OpenClaw CLI settings API route with robust config handling

Added a new API route at src/app/api/cli-tools/openclaw-settings/route.js to manage OpenClaw CLI configuration. The route detects the CLI installation using platform-specific commands (which/where) and gracefully handles JSONC syntax in settings files by stripping trailing commas. It also normalizes agent model definitions that may be stored as objects with primary/fallback fields, ensuring consistent string-based model IDs for downstream operations.

src/app/api/cli-tools/openclaw-settings · high confidence

New Provider Limits dashboard with quota tracking and management

The Usage dashboard now features a dedicated Provider Limits section that displays quota usage for connected AI providers. Users can view per-provider quota cards with progress bars, usage counts, and reset countdowns, or switch to a sortable, paginated table view. The interface supports filtering by provider and account status, allows manual quota refresh, and includes auto-refresh and auto-ping settings for providers like Claude and Codex to manage quota windows. It also handles specific provider details such as Kiro authentication methods and Codex credit expiry.

src/app/(dashboard)/dashboard/usage/components/ProviderLimits · high confidence

New Skills page for AI integration

A new Skills page has been added to the dashboard, providing users with a curated list of AI skills. The page displays each skill's name, description, and endpoint, along with a 'START HERE' badge for entry-level skills. Users can view the raw skill content via direct links and use a copy button to easily copy the skill URL for pasting into their AI tools. The page also includes a section linking to the skills repository on GitHub for further exploration.

src/app/(dashboard)/dashboard/skills · high confidence

New Token Saver dashboard page for managing prompt compression and proxy settings

A new Token Saver page has been added to the dashboard, providing a client-side interface to manage token-saving features. Users can now enable or disable RTK, Caveman, Ponytail, and PXPIPE multimodal prompt compression, as well as configure the Headroom proxy (including URL, timeout, and extras installation). The page exposes controls for enabling/disabling these features, adjusting levels, and viewing status, with settings persisted via the /api/settings endpoint.

src/app/(dashboard)/dashboard/token-saver · high confidence

New Translator Page for Debugging API Requests and Responses

A new interactive page has been added to the dashboard to help users debug and understand the translation process between client requests and provider responses. The page visualizes a 7-step pipeline (from raw client request to final client response) using a dynamic Monaco editor. Users can load specific log files, trigger translations to OpenAI intermediate formats, build target requests with provider/model metadata, and send requests to external providers to view streaming responses. It includes features like auto-detection of provider/model from the first step, clipboard copying, and error handling with loading states.

src/app/(dashboard)/dashboard/translator · high confidence

New UI components and modal integrations

Added several new UI components to the shared library: AddCustomEmbeddingModal for managing custom embedding providers, CapacityBadges for displaying model capability icons, ChangelogModal for viewing release notes, and HeaderMenu with a MenuItem component for structured navigation. Also added Drawer for slide-out panels, HeaderLanguage for locale switching, and IFlowCookieModal for iFlow authentication. Updated CursorAuthModal to handle manual instructions for Windows users and ComboFormModal to support model deselection and inline editing.

src/shared/components · high confidence

New Usage Chart API with configurable time periods

A new API endpoint at /api/usage/chart has been added to support fetching usage data for charts. Users can now specify a time period via the 'period' query parameter, with support for 'today', '24h', '7d', '30d', '60d', and 'all' options (defaulting to '7d'). This enables more flexible usage analytics visualization by allowing clients to request data for specific historical ranges.

src/app/api/usage/chart · high confidence

New Usage and Quota dashboard pages with tabbed navigation and period filtering

Users can now view usage statistics and quota limits via two new dashboard pages: /dashboard/usage and /dashboard/quota. The Usage page features a segmented control to switch between Overview, Logs, and Details tabs, with the Overview tab allowing users to filter data by time periods (Today, 24h, 7D, 30D, 60D, All). Tab selection is persisted in the URL query parameters, and both pages use Suspense boundaries with skeleton loaders for improved perceived performance during data fetching.

src/app/(dashboard)/dashboard/usage · high confidence

New batch connection testing API endpoint

A new POST endpoint at /api/providers/test-batch has been added, allowing users to test multiple provider connections simultaneously. The endpoint supports filtering by specific provider, authentication type (OAuth, free, API key, or compatible), or testing all active connections at once, returning a summary of passed and failed tests along with detailed diagnostics for each connection.

src/app/api/providers/test-batch · high confidence

New combo detail page for managing media provider combinations

A new detail page has been added for individual media provider combos, allowing users to view and edit configuration such as the combo name, associated models, and round-robin fallback settings. The page provides a UI to add, remove, or reorder models within a combo, test the configuration against provider APIs, and view usage logs. It also supports deleting the combo and navigating back to the appropriate provider listing based on the combo's kind.

src/app/(dashboard)/dashboard/media-providers/combo · high confidence

New compact conversation endpoint and cleanup of initialization logging

A new POST endpoint at /v1/responses/compact has been added to allow clients to send a compact conversation context; it reuses the existing chat handling pipeline by injecting a \_compact flag into the request body. Additionally, the standard /v1/responses endpoint has been updated to remove a console.log statement from its translator initialization routine, resulting in cleaner server logs.

src/app/api/v1/responses · high confidence

New dedicated handlers for embeddings, speech, images, video, and responses

The \open-sse/handlers\ directory now includes dedicated orchestrator modules for previously unified or missing capabilities: \embeddingsCore.js\ routes embedding requests to provider-specific adapters; \imageGenerationCore.js\ handles image generation with executor delegation and binary output support; \videoCore.js\ proxies async video jobs (e.g., xAI Grok Imagine) with idempotency and secret sanitization; \ttsCore.js\ and \sttCore.js\ manage text-to-speech and speech-to-text via adapters and transport markers (including Gemini Live WebSocket STT); \responsesHandler.js\ converts OpenAI Responses API requests to Chat Completions and back; and \systemoneCore.js\ passes native decision payloads for System One providers. These handlers centralize provider routing, credential refresh, error formatting, and usage tracking for their respective modalities.

open-sse/handlers · high confidence

New dynamic CLI tool detail pages with provider-aware model selection

Users can now access dedicated detail pages for CLI tools (such as Claude, Codex, Jcode, Grok Build, and generic tools like Pi or OMP) that dynamically surface available AI models based on active provider connections. The interface intelligently handles OpenAI/Anthropic-compatible providers by falling back to their custom model configurations, ensuring the 'Apply' button remains enabled even when static model catalogs are empty. It also includes safeguards for disabled or unknown tools to prevent crashes, and supports configuration via cloud, tunnel, or Tailscale URLs.

src/app/(dashboard)/dashboard/cli-tools/\[toolId\] · high confidence

New embedding provider adapters with self-hosted safety and Gemini support

This change introduces a new registry of embedding provider adapters in the \open-sse/handlers/embeddingProviders\ module. It adds native support for Google Gemini embeddings, including the forwarding of the \outputDimensionality\ parameter for both single and batch requests. It also introduces a dedicated \selfhostedEmbedding\ adapter that strictly requires a \baseUrl\ configuration, preventing the silent fallback to OpenAI's public API that occurred with the previous generic OpenAI-compatible node logic. The module consolidates handling for various OpenAI-compatible providers (such as Mistral, Voyage, Jina, and Vercel AI Gateway) and custom node providers into a unified adapter structure.

open-sse/handlers/embeddingProviders · high confidence

New endpoints for bulk and single-token Codex account import

Added two new API routes under /api/oauth/codex to streamline account provisioning. The bulk-import endpoint allows users to submit multiple account JSON objects in a single request (accepting arrays, single objects, or wrapped formats), automatically backfilling missing identity fields from JWT claims and processing connections serially to prevent race conditions. The import-token endpoint enables importing a single ChatGPT access token directly, bypassing the standard OAuth refresh flow by decoding the JWT to extract email, account ID, and plan type, then saving the connection with an 'access\_token' auth type.

src/app/api/oauth/codex · high confidence

New format detection and translation registry in the translator module

The translator module now includes a dedicated \formats.js\ file that defines supported format identifiers (such as OpenAI, Claude, Gemini, Kiro, and Antigravity) and a \detectFormatByEndpoint\ function to identify the source format based on the request URL pathname and body structure. The main \index.js\ file implements a lazy-initialized registry system for request and response translators, allowing for direct, lossless translation routes between specific source and target formats (e.g., Claude to Kiro) instead of always pivoting through an intermediate OpenAI format. This change also introduces logic to handle specific provider quirks, such as stripping content types, normalizing thinking configurations, ensuring tool call IDs, and managing Claude-specific requirements like trailing user turns and OAuth-based tool cloaking.

open-sse/translator · high confidence

New handlers for embeddings, web fetch, search, image/video generation, TTS, STT, and System One

The server now exposes dedicated handlers for embeddings, web fetch, web search, image generation, video generation, text-to-speech (TTS), speech-to-text (STT), and the System One decision endpoint. Each handler implements a consistent authentication flow (respecting the requireApiKey setting), credential rotation with account fallback, and combo expansion (round-robin or fusion strategies) where applicable. Web fetch and search include SSRF guards and scoped failure locks to prevent cross-capability outages, while video generation handles async job creation and polling with idempotency and connection pinning.

src/sse/handlers · high confidence

New health check API endpoint added

A new health check endpoint is now available at /api/health. This endpoint supports GET requests to return a simple { ok: true } status response and OPTIONS requests to handle CORS preflight checks, allowing external services or monitoring tools to verify the application's availability.

src/app/api/health · high confidence

A new API route at /api/oauth/iflow/cookie has been added to support authenticating with the iFlow provider using a browser cookie. Users can now submit their iFlow session cookie to the backend, which validates it against the iFlow platform, retrieves the associated API key, and stores the connection details (including the extracted BXAuth token and expiration time) in the database for subsequent use.

src/app/api/oauth/iflow · high confidence

New interactive example cards for media providers

The media provider detail page now includes interactive example cards for Embeddings, Speech-to-Text (STT), Text-to-Speech (TTS), and generic media kinds (Image, Video, Music, Web Search, Web Fetch, Image-to-Text, and System One). These components allow users to select a model, configure parameters (such as dimensions, language, or voice), and run live API requests directly from the dashboard to test functionality. The cards support tunneling for local development, display formatted cURL snippets for easy integration, and handle specific provider requirements like binary image outputs and streaming responses.

src/app/(dashboard)/dashboard/media-providers/\[kind\]/\[id\]/components · high confidence

New login page with SSO and password-change support

The login interface at src/app/login/page.js has been introduced to replace the previous implementation. It now supports multiple authentication modes including password, OIDC, and SAML 2.0 SSO, dynamically adjusting the UI based on server configuration. A key behavioral change is the addition of a mandatory password-change step for users logging in remotely with default credentials, enforced via a new form before granting dashboard access. The page also handles rate-limiting countdowns and prevents infinite loading states during authentication checks.

src/app/login · high confidence

New media provider management pages for kind-specific and web search providers

Added new dashboard pages at /dashboard/media-providers/\[kind\] and /dashboard/media-providers/web to manage AI provider connections. The \[kind\] page lists providers for a specific category (e.g., image, embedding), displays connection status (connected, error, disabled), and allows toggling providers on or off. It also supports custom embedding nodes and combo configurations. The web page consolidates web search and fetch providers, displaying their status and allowing users to create new provider combos. Both pages fetch live connection data from the API and provide a unified interface for managing media provider integrations.

src/app/(dashboard)/dashboard/media-providers/\[kind\] · high confidence

New modular translator concerns for robust API translation

The translator now uses a set of dedicated concern modules to handle specific translation tasks, improving reliability and security. Key additions include a hardened image fetcher that prevents SSRF by pinning DNS resolutions and verifying image magic bytes, and a modality stripper that removes unsupported media (vision, audio, PDF) from requests before translation, replacing them with text placeholders. The system also introduces a config-driven parameter stripping mechanism to remove unsupported fields (like temperature or reasoning fields) for specific providers and models, and a unified thinking normalizer that maps client effort levels to provider-native thinking configurations. Additional helpers cover safe JSON parsing, OpenAI chunk and usage building, tool call ID sanitization, and reasoning text extraction.

open-sse/translator/concerns · high confidence

New multi-step translation API endpoint

A new API route at /api/translator/translate has been added to support a three-step translation pipeline. Step 1 detects the source format and target provider settings. Step 2 translates the request from the source format to an OpenAI-compatible intermediate format. Step 3 translates from the intermediate format to the target provider's specific format, constructs the final request URL and headers using the provider's executor, and returns the complete payload ready for execution.

src/app/api/translator/translate · high confidence

New outbound proxy configuration and connection proxy pool support

The network layer now supports configuring outbound HTTP proxies via environment variables (HTTP\_PROXY, HTTPS\_PROXY, etc.) through a new initialization module that validates schemes and manages state. Additionally, connection-level proxying has been enhanced with support for proxy pools, allowing users to select proxies via round-robin or random strategies. The system resolves proxy configurations by prioritizing proxy pools (including Vercel, Cloudflare, and Deno relay types) over legacy proxy settings, and includes a dedicated utility to test proxy connectivity with configurable timeouts.

src/lib/network · high confidence

New pricing settings page for cost tracking configuration

A new Pricing Settings page has been added to the dashboard, allowing users to view and configure pricing rates for cost tracking. The page displays an overview of total models and providers, explains the cost calculation logic (based on input, output, cached, and reasoning tokens), and provides a modal interface to edit pricing details. This enables users to manage how usage costs are calculated across different AI providers.

src/app/dashboard · high confidence

New provider connection and model management UI

The dashboard now includes dedicated components for managing AI provider connections and models. Users can add OpenAI and Anthropic compatible providers via a new modal that supports API type selection and connection validation. The provider list view displays connection status, proxy configurations, and cooldown timers, while a new model status badge provides real-time health checks for all models, allowing users to clear cooldowns directly. Additionally, a models card enables users to view, test, copy, and manage custom model aliases for each provider.

src/app/(dashboard)/dashboard/providers/\[id\], src/app/(dashboard)/dashboard/providers/components · high confidence

New provider executors and base infrastructure for Antigravity, Azure, and CodeBuddy

The executors module now includes dedicated executors for new and existing providers: Antigravity (with native image generation support and request sanitization), Azure OpenAI (routing to deployment-specific endpoints), CodeBuddy CN and Intl (forcing streaming and handling Tencent-specific content filters and rate limits), CommandCode (NDJSON-to-SSE translation with retry logic), and Cursor (protobuf-based AgentService communication). These are built on a refactored BaseExecutor that centralizes retry, fallback, and credential-refresh logic, and a DefaultExecutor for standard OpenAI-compatible providers.

open-sse/executors · high confidence

New provider registry skeleton and model capability system

The \open-sse/providers\ area now includes a structured registry skeleton (\REGISTRY\_TEMPLATE.js\, \schema.js\) and a comprehensive model capability system (\capabilities.js\, \catalogOverride.js\, \pricing.js\, \thinkingLevels.js\). This introduces a standardized way to define providers with transport, OAuth, and media configurations, while automatically resolving model capabilities (vision, reasoning, context windows) and pricing from a synced catalog and local overrides. Users benefit from more accurate model metadata, better support for new models like Claude Opus 5 and Sonnet 5.5, and improved handling of reasoning effort levels across different providers.

open-sse/providers · high confidence

New proxy pool management and multi-platform relay deployment APIs

This change introduces a complete set of API routes for managing proxy pools and deploying relay workers to Cloudflare Workers, Vercel Edge Functions, and Deno Deploy. Users can now create, list, update, and delete proxy pools via standard REST endpoints, with support for filtering by active status and viewing bound connection counts. The system also provides dedicated deployment endpoints that automatically provision and configure relay workers on the selected platform (Cloudflare, Vercel, or Deno), creating the corresponding proxy pool entry upon successful deployment. Additionally, a test endpoint allows users to verify the connectivity and status of a specific proxy pool, updating its active state based on the result.

src/app/api/proxy-pools · high confidence

New request translators for Antigravity, Kiro, CommandCode, and Cursor

Added dedicated request translators to convert incoming requests from Antigravity, Claude, Gemini, OpenAI, and OpenAI Responses into the specific formats required by Kiro, CommandCode, and Cursor. The Antigravity-to-OpenAI translator normalizes schema types and strips unsupported fields like enumDescriptions. The Claude-to-Kiro translator implements a direct route that canonicalizes conversation history, merges consecutive user turns, and handles image and tool result payloads. The Claude-to-OpenAI translator strips Anthropic billing headers from system prompts and fixes missing tool responses. The Gemini-to-OpenAI translator derives deterministic tool call IDs to ensure proper pairing with function responses. The OpenAI-to-CommandCode translator maps content blocks to the /alpha/generate schema, including native image and reasoning blocks. The OpenAI-to-Cursor translator converts tool outputs into structured text blocks to prevent backend errors and strips irrelevant fields. The OpenAI-to-Gemini translator sanitizes function names to meet API requirements and handles thinking signatures.

open-sse/translator/request · high confidence

New response translators for Claude, CommandCode, Cursor, Gemini, Kiro, Ollama, and OpenAI Responses

This change introduces a suite of new response translators in the \open-sse/translator/response\ directory, enabling the system to convert streaming responses from various upstream providers (Claude, CommandCode, Cursor, Gemini, Kiro, Ollama, and OpenAI Responses) into standardized OpenAI-compatible formats or other target formats like Claude. These translators handle specific streaming events, usage tracking, tool calls, and reasoning content from each provider, ensuring consistent behavior across different AI backends.

open-sse/translator/response · high confidence

New shared authentication and utility modules for Cline, Zed, and Xiaomi MiMo

The open-sse/shared area now includes dedicated helper modules that standardize how the platform authenticates and communicates with specific providers. For Cline, clineAuth.js ensures ClinePass API keys are sent verbatim without the 'workos:' prefix that previously caused 401 errors, while clineEnvelope.js safely unwraps the provider's response structure for opted-in providers. For Zed, zedAuth.js implements a native app OAuth flow using ephemeral RSA keypairs to handle token generation, decryption, and catalog fetching. For Xiaomi MiMo, mimoAccount.js enables server-assisted desktop login by reading account cookies from the local MiMo Desktop installation and acquiring service tokens across five regional clusters. Additionally, machineId.js provides a consistent, salted machine identifier for client telemetry.

open-sse/shared · high confidence

New stdio-to-SSE bridge for local MCP plugins

A new bridge component in src/lib/mcp allows local Command Line Interface (CLI) plugins to be exposed over Server-Sent Events (SSE). This enables the application to spawn and manage child processes for specific, pre-defined plugins, translating their JSON-RPC output into SSE streams for client consumption. The implementation includes safeguards such as restricting execution to a whitelist of local plugins to prevent remote code execution, and automatically terminating child processes when no longer needed to prevent resource leaks.

src/lib/mcp · high confidence

New terminal UI with native input handling and model selection

The CLI now includes a new terminal-based user interface (Terminal UI) located in cli/src/cli/utils, replacing the previous input mechanism. This change introduces a native readline-based input system (cli/src/cli/utils/input.js) to eliminate input lag, adds a model selector (cli/src/cli/utils/modelSelector.js) that groups models by provider and filters them based on active connections, and provides a full menu structure (cli/src/cli/terminalUI.js) for managing providers, API keys, and settings. Utility modules for display, formatting, clipboard, and endpoint handling support this new interactive experience.

cli/src/cli/utils · high confidence

New translator API endpoint with automatic credential refresh

A new API route at /api/translator/send has been added to handle translation requests. This endpoint accepts a provider, model, and request body, retrieves the active connection credentials, and executes the request via the OpenSSE executor. A key behavioral addition is automatic token refresh: if the provider returns a 401 or 403 error, the endpoint automatically refreshes the access token (including provider-specific data like copilot tokens), persists the updated credentials to the local database, and retries the request before returning the response.

src/app/api/translator/send · high confidence

New usage dashboard with detailed cost and token tracking

The usage dashboard now features a comprehensive set of components for monitoring AI consumption. Users can view summary statistics including total requests, input/output/cached tokens, and estimated costs via OverviewCards. The UsageChart allows toggling between tokens, requests, and cost views over time. Breakdowns are available by provider (ProviderBarChart) and by model (TopModelsChart), each switchable between token and request counts. A new UsageTable provides sortable, grouped views of usage data in either token or cost modes, and the RequestDetailsTab offers a filterable, paginated list of individual requests with expandable details.

src/app/(dashboard)/dashboard/usage/components · high confidence

New utility modules for client detection, proxy bypass, and provider-specific tool handling

The open-sse/utils directory now includes several new modules that enhance client identification and provider compatibility. clientDetector.js identifies CLI tools (Claude Code, Gemini CLI, Codex, Antigravity, DeepSeek TUI) via headers and body fields to enable lossless passthrough for native pairs. bypassHandler.js intercepts specific Claude CLI patterns (title extraction, warmup, count, skip patterns, and topic naming) to return fake responses without calling the provider. claudeCloaking.js renames client tools with an '\_ide' suffix and injects decoy tools to prevent bans, with corresponding decloak logic for both streaming and non-streaming responses. codexToolSchema.js strips Unicode property escapes from tool schemas to fix 400 errors on the Codex provider. cursorChecksum.js and cursorProtobuf.js implement the Jyh cipher and ConnectRPC protobuf encoding required for Cursor IDE authentication and communication. kiroSessionReplay.js preserves the first user message in Kiro sessions to maintain cacheability. modelMarkers.js strips the '\[1m\]' context marker from Claude Code model names to prevent routing failures. ollamaTransform.js converts OpenAI SSE streams to Ollama's JSON-lines format. opencodeFingerprint.js canonicalizes tool names for the OpenCode Zen free-tier client. claudeSignature.js validates Claude thinking signatures, and claudeToolTypeSelfCheck.mjs provides tests for tool type defaults. error.js centralizes error formatting with low-level cause details, and debugLog.js adds tagged debug logging.

open-sse/utils · high confidence

New version check and update API endpoints

Added three new API routes under src/app/api/version to support in-app version management. The /version endpoint checks for updates by comparing the current package version against the latest version on npm, using a one-hour in-memory cache to reduce registry lookups. The /version/update endpoint triggers an automatic update process in production builds by killing sibling processes to release file locks and spawning a detached updater. The /version/shutdown endpoint allows the application to shut down gracefully to facilitate manual updates.

src/app/api/version · high confidence

New web fetch handler supporting multiple providers

A new web fetch handler has been added to the SSE API, enabling users to retrieve and normalize content from web pages using a unified interface. The implementation supports six distinct providers: Firecrawl, Jina Reader, Tavily, Exa, Ollama, and TinyFish. Users can specify the desired provider and output format (such as markdown or HTML) via the handler's parameters, with the system handling provider-specific authentication, timeouts, and response parsing to return a consistent data structure.

open-sse/handlers/fetch · high confidence

Open-sse module initialization and proxy support

The open-sse package is now initialized with a public API entry point (index.js) that exports core configuration, translator, service, handler, and executor modules. This release integrates proxy support by patching the global fetch function, ensuring all upstream provider requests route through the configured proxy. Documentation (AGENTS.md) and build artifacts (.npmignore) are added to support development and packaging.

open-sse · high confidence

PXPIPE Token Saver dashboard and management API

Users can now monitor and manage the PXPIPE multimodal prompt compression feature directly from the dashboard. A new PxpipeClient page displays real-time status, uptime, and token-saving statistics (original vs. compressed tokens, reduction percentage) with time-window filters (Today, Yesterday, 7 days, 30 days, All time). The dashboard is backed by a new set of API routes under /api/pxpipe that allow users to check health, view logs, retrieve stats, and control the in-process module lifecycle (start, stop, restart, install/repair) without requiring a server restart. This provides visibility into compression effectiveness and control over the feature's availability.

src/app/(dashboard)/dashboard/pxpipe, src/app/api/pxpipe, src/lib/pxpipe · high confidence

Per-provider custom header overrides via API

A new API endpoint at /api/providers/\[id\]/overrides allows users to view and modify custom HTTP headers for specific providers. The GET method returns both the user's custom overrides and the provider's built-in headers from the registry, while the PUT method enables setting or clearing these overrides with strict validation (e.g., blocking sensitive headers like Authorization, limiting header count to 20, and enforcing RFC 7230 token rules for names). This change introduces the backend logic for storing and retrieving these per-provider customizations, grounded in the local database settings.

src/app/api/providers/\[id\]/overrides · high confidence

RTK port introduces JS-native text compression and style-injection capabilities

The \open-sse/rtk\ module has been ported to JavaScript, introducing a comprehensive set of text filters (git-diff, git-log, git-status, build-output, grep, find, ls, tree, dedup-log, smart-truncate, read-numbered, search-list) that automatically detect and compress verbose tool outputs to reduce token usage. It also adds a 'Caveman' system prompt injector with multiple intensity levels (including Wenyan classical Chinese) to enforce terse responses, a 'Ponytail' injector for minimal-code generation, and a 'PXPIPE' multimodal prompt compression feature that renders bulky context as dense PNGs. The module includes a headroom compression system for Kiro conversation state and OpenAI Responses, along with safe error handling for filter execution.

open-sse/rtk · high confidence

Runtime-based internationalization with 36 supported languages

The application now supports runtime internationalization (i18n) for the user interface, allowing users to switch languages dynamically without a full page reload. This change introduces a new \RuntimeI18nProvider\ and associated configuration that supports 36 languages, including English, Vietnamese, Simplified Chinese, Traditional Chinese, Japanese, Korean, Spanish, French, German, Italian, Portuguese, Russian, Arabic, Hebrew, Farsi, Khmer, Thai, Hindi, Bengali, Urdu, and others. The system loads translation files from \/i18n/literals/{locale}.json\ and uses a MutationObserver to translate text nodes in the DOM as they change, ensuring that UI text updates correctly when the user changes their locale preference stored in a cookie.

src/i18n · high confidence

Support for Zed, Trae, and Windsurf IDEs with hardened OAuth security

Users can now authenticate with the Zed, Trae, and Windsurf IDEs. The system automatically detects installed IDEs and, for Zed, imports existing session credentials from the OS keychain to streamline login. To prevent login-CSRF attacks, the local OAuth callback proxy now rejects requests with non-loopback Origin headers. Additionally, the PKCE code verifier generation is now configurable, allowing providers like xAI to use larger byte sizes for enhanced security.

src/lib/oauth/utils · high confidence

Support for single model lookup via catch-all API route

A new catch-all route at src/app/api/v1/models/\[...model\]/route.js has been added to support OpenAI-compatible single model lookups. This endpoint allows clients to retrieve details for a specific model by ID (e.g., GET /v1/models/{provider}/{model}) in addition to filtering the models list by capability kind (e.g., image, tts, stt). It implements CORS headers and returns a 404 error if the requested model is not found or inaccessible.

src/app/api/v1/models/\[...model\] · high confidence

Unified endpoint and API key management for CLI tool cards

The CLI tools dashboard now uses shared \BaseUrlSelect\ and \ApiKeySelect\ components across tool cards (such as Cline, Copilot, Cowork, Droid, and Antigravity), allowing users to select from local, tunnel, Tailscale, and cloud endpoints, as well as saved API key presets. This change introduces browser-local persistence for endpoint and key presets via \localStorage\, enabling users to save, load, and delete configurations that persist across sessions, while also supporting custom URL inputs and automatic \/v1\ path normalization.

src/app/(dashboard)/dashboard/cli-tools/components · high confidence

Xiaomi MiMo integration now supports dual authentication via API keys and server-assisted desktop login

The Xiaomi MiMo OAuth provider now supports two distinct authentication methods: manual API key import and server-assisted desktop login. Users can now import an existing API key (starting with 'sk-') which is validated against the models endpoint, or initiate a server-side login flow that handles the initial authentication hops and manages session cookies for desktop-style access. The auto-import feature detects credentials from local configuration files (auth.json) to streamline setup. This change enables multi-account support with independent session rotation and region-specific proxy handling for non-CN clusters.

src/app/api/oauth/xiaomi-mimo · high confidence

Removals

Removal of Cloud Sync API endpoints

The cloud synchronization feature has been removed from the application. The API routes for initializing cloud sync (\/api/sync/initialize\) and performing cloud data synchronization (\/api/sync/cloud\) have been deleted, meaning users can no longer enable, sync, or disable cloud-based data synchronization through the application.

src/app/api/sync · high confidence

Removal of legacy cloud API endpoints

The legacy cloud synchronization feature has been removed, resulting in the deletion of four API route handlers: \src/app/api/cloud/auth/route.js\ (provider credential retrieval), \src/app/api/cloud/credentials/update/route.js\ (token refresh), \src/app/api/cloud/model/resolve/route.js\ (alias resolution), and \src/app/api/cloud/models/alias/route.js\ (alias management and sync triggering). Users can no longer interact with these specific cloud-based model alias and credential management endpoints.

src/app/api/cloud · high confidence

Removed legacy usage fetcher module

The \src/lib/usage/fetcher.js\ file has been deleted. This module previously handled fetching usage data and quotas for various AI providers (GitHub, Gemini, Claude, etc.) via their respective APIs. Its removal indicates that this specific implementation of usage data retrieval is no longer part of the application.

src/lib/usage · high confidence

Security

Redaction of sensitive conversation data in usage request details API

The /api/usage/request-details endpoint now redacts sensitive conversation payloads (request bodies, provider requests, and responses) before returning them to the client. While metadata such as model, tokens, latency, and status remains available for filtering and display, the actual message content is replaced with a redaction marker to prevent unauthorized exposure of user conversation history.

src/app/api/usage/request-details · high confidence

SSRF protection added to MCP tool probe endpoint

The cowork-mcp-tools API route now validates incoming URLs against SSRF attacks before probing the MCP server. For remote requests, the endpoint enforces a public URL policy using the assertPublicUrl utility, rejecting internal or private addresses. Local requests are exempted to allow self-hosted MCP servers to function. This change mitigates the risk of server-side request forgery when users provide custom MCP server URLs.

src/app/api/cli-tools/cowork-mcp-tools · high confidence

Server shutdown endpoint now requires authentication and is disabled in production

The server shutdown API route now enforces security controls: it returns a 403 error in production environments and requires a valid Bearer token matching the SHUTDOWN\_SECRET environment variable for authorization in other environments. Previously, the endpoint was accessible without any authentication checks.

src/app/api/shutdown · high confidence

Architecture

New chatCore handlers for streaming, non-streaming, and SSE-to-JSON conversion

The chatCore handler logic has been reorganized into four new modules: streamingHandler.js, nonStreamingHandler.js, sseToJsonHandler.js, and requestDetail.js. This refactoring introduces dedicated handling for streaming responses (including abort terminal bytes and non-SSE upstream error sanitization), non-streaming responses (with explicit conversion of OpenAI Chat Completions bodies to the OpenAI Responses API shape for tool\_calls and reasoning), and forced SSE-to-JSON parsing (reconstructing a single JSON response from streaming chunks). Additionally, requestDetail.js centralizes usage extraction (supporting cached tokens, reasoning tokens, and provider-specific metadata), request configuration extraction, and usage logging, ensuring consistent token accounting and request tracking across all chat paths.

open-sse/handlers/chatCore · high confidence

Tunnel module restructured with unified exports

The tunnel management logic has been reorganized into a centralized entry point that aggregates and re-exports functionality from distinct service modules. Users and other parts of the application now access Cloudflare tunnel operations (such as enabling/disabling, status checks, and cloudflared management) and Tailscale operations (including installation, daemon management, login, and health probing) through a single, consistent interface. This change also exposes shared utilities for state management, internet connectivity checks, and watchdog configuration constants, simplifying how tunnel features are integrated and maintained.

src/lib/tunnel · high confidence

Behavioural changes

API keys can now be retrieved and updated, and cloud sync is removed

Users can now fetch individual API keys and toggle their active status via new GET and PUT endpoints at /api/keys/\[id\]. The previous behavior of automatically syncing keys to the cloud upon creation or deletion has been removed, as the cloud sync logic and related imports have been deleted from the key management routes.

src/app/api/keys · high confidence

CLI tool settings routes now tolerate JSONC configuration files

The API routes for Cline and Kilo Code settings now gracefully handle configuration files that contain JSONC syntax (such as trailing commas). Previously, malformed JSON would cause a server error that the UI might misinterpret as the tool being uninstalled; the new implementation strips invalid characters before parsing, ensuring that users with non-standard config files can still view and update their settings without interruption.

src/app/api/cli-tools/cline-settings, src/app/api/cli-tools/kilo-settings · high confidence

Cached tunnel status API endpoint

The tunnel status API endpoint now caches the results of tunnel and Tailscale probes for 3 seconds to reduce redundant checks during rapid polling, while keeping download status live for smooth UI updates.

src/app/api/tunnel/status · high confidence

Centralized configuration and security hardening for provider integrations

The \open-sse/config\ directory has been restructured to serve as a single source of truth for provider constants, model metadata, and runtime settings. This change introduces a unified error classification system (\errorConfig.js\) that standardizes HTTP status codes and implements exponential backoff for rate limits, alongside configurable timeouts for streaming and media fetching. Security is strengthened via \mediaConfig.js\, which enforces strict limits on remote image sizes and blocks SSRF-prone hosts. Provider-specific logic is now isolated into dedicated modules, including \appConstants.js\ for Antigravity and Gemini CLI identity spoofing, \grokCli.js\ for version alignment, and \kiroConstants.js\ for Kiro-specific thinking and chunking rules. The update also adds comprehensive support for Text-to-Speech (\ttsModels.js\, \googleTtsLanguages.js\) and consolidates model registry lookups in \providerModels.js\.

open-sse/config · high confidence

Centralized model schema and routing logic for OpenSSE providers

The model provider layer now uses a centralized schema and helper utilities to normalize model entries, derive display names from IDs, and determine routing formats. New files in \open-sse/providers/models\ introduce \schema.js\ for normalizing model IDs (handling version separator differences), defining default properties (kind, quota family, target format), and exposing supported formats per model. \helpers.js\ adds logic to auto-generate Codex review variants, identify Muse Spark and DeepSeek models for specific API routing (Responses vs Messages), and apply OpenCode family-based format fallbacks. \namePatterns.js\ provides regex-based fallback naming for models that omit explicit names. These changes standardize how model metadata is processed and how requests are routed based on model identity and capabilities.

open-sse/providers/models · high confidence

Combo presets, cloud sync removal, and name validation update

Users can now create default presets for Cursor and Claude via the new /api/combos/presets endpoint, which fetches live models and creates missing combos. The automatic cloud synchronization feature has been removed from combo creation, updates, and deletion, meaning combos are no longer synced to the cloud. Additionally, combo names now support the dot (.) character, and updating or deleting a combo now resets its rotation state to ensure consistency.

src/app/api/combos · high confidence

Database backend migrated from lowdb to SQLite with a new migration system

The application's data layer has been replaced with SQLite, introducing a formal migration system (starting with version 1) and a key-value store helper for managing scoped settings. This change shifts the underlying storage engine, which may affect performance characteristics and data persistence behavior compared to the previous lowdb implementation.

src/lib/db/helpers, src/lib/db/migrations · high confidence

Database layer migrated to SQLite with runtime-specific adapters

The database adapter layer in src/lib/db/adapters has been replaced with a set of SQLite-based implementations to improve performance and reduce dependencies. The system now automatically selects the optimal driver based on the runtime: it uses the native bun:sqlite adapter when running under Bun, the experimental node:sqlite adapter for Node.js 22.5.0+, the better-sqlite3 npm package for standard Node.js environments, and falls back to the pure-JavaScript sql.js library for older Node versions. All adapters share a unified interface for running queries, handling transactions, and managing WAL checkpointing to keep database files small.

src/lib/db/adapters · high confidence

Database migration to SQLite with new repository layer

The application has migrated its data storage from lowdb to SQLite, introducing a new repository pattern in src/lib/db/repos to manage data access. This change brings a new set of repository modules (such as aliasRepo, apiKeysRepo, combosRepo, connectionsRepo, disabledModelsRepo, nodesRepo, pricingRepo, proxyPoolsRepo, requestDetailsRepo, settingsRepo, and usageRepo) that handle CRUD operations for various entities. The migration includes specific features like atomic upserts for custom models, deduplication logic for provider connections, observability request logging with sanitization, and usage tracking with cached token support. The settings repository now supports a comprehensive default configuration including SSO, proxy, and headroom settings.

src/lib/db/repos · high confidence

Database storage migrated from JSON files to SQLite

The application's local data storage has switched from multiple JSON files (db.json, usage.json, etc.) to a single SQLite database (data.sqlite). This change introduces a new driver layer that automatically selects the best available SQLite runtime for your environment, preferring Bun's built-in sqlite, then better-sqlite3, then Node's native node:sqlite, with sql.js as a fallback. To ensure a smooth transition, the system now includes an automatic one-time migration that imports your existing JSON data into the new SQLite schema, along with a safety backup mechanism that creates lightweight snapshots of your data before applying any schema changes.

src/lib/db · high confidence

Dynamic model discovery and enhanced provider integration

The provider models API route now supports dynamic model fetching for a wider range of providers, including Codex, Qoder, Kimchi, and Zed, replacing or augmenting static configurations. This change introduces custom resolvers that handle OAuth token refresh on 401/403 errors, parse provider-specific model formats (such as Gemini CLI and Codex review models), and integrate with external model resolution services. Users will see more accurate and up-to-date model lists for these providers, with automatic fallback to static catalogs if dynamic fetching fails.

src/app/api/providers/\[id\]/models · high confidence

Enhanced combo management with drag-and-drop, bulk actions, and capacity adapters

The Combos page now supports drag-and-drop reordering of models within combos and allows users to select multiple combos for bulk operations. A new capacity adapter system lets users configure fallback models for specific input modalities (vision, audio) to handle missing capabilities gracefully. Users can also generate preset combos based on Cursor or Claude default configurations, and the page now explicitly filters to show only LLM-type combos while hiding web-search variants.

src/app/(dashboard)/dashboard/combos · high confidence

Enhanced provider connection management with proxy support and compatible provider normalization

The provider API route now supports configuring connection-level proxies (URL, no-proxy list, and enable/disable flag) and binding connections to specific proxy pools via a new proxyPoolId field. For OpenAI-compatible, Anthropic-compatible, and custom embedding providers, the API validates that the corresponding provider node exists and automatically enriches the connection with node-specific metadata (prefix, baseUrl, apiType, nodeName). The GET endpoint now returns enriched names for compatible providers by resolving them against the provider node registry. Input validation has been broadened to accept web-cookie providers, free-tier providers, and providers supporting API-key auth modes, while normalizing provider IDs and specific data structures.

src/app/api/providers · high confidence

Enhanced provider dashboard with status filtering, search, and compatible provider support

The Providers dashboard now supports filtering providers by connection status (All, Active, Inactive, No connection) and includes a global search feature to quickly locate specific providers. The view has been expanded to display 'OpenAI-compatible' and 'Anthropic-compatible' provider nodes alongside standard API key and OAuth providers, allowing users to manage a broader range of AI integrations. Connection status badges have been refined to provide more granular error categorization (e.g., AUTH, RUNTIME, 429, 5XX), and the layout now prioritizes providers based on usage and connection state for easier access.

src/app/(dashboard)/dashboard/providers · high confidence

Enhanced settings API with password management and dynamic proxy application

The settings API now supports updating configuration via a new PATCH endpoint, enabling users to change their password (with current password verification and hashing) and modify outbound proxy or combo routing strategies without restarting the application. The GET endpoint has been updated to securely exclude sensitive fields like passwords and OIDC secrets from responses, instead exposing a boolean flag to indicate if a password is set, and adds environment-driven toggles for request logging and translation features.

src/app/api/settings · high confidence

Expanded API key validation for new provider types and media services

The provider validation endpoint now supports validating API keys for OpenAI-compatible, Anthropic-compatible, and custom embedding providers by probing their respective API endpoints (such as /models and /embeddings). It also adds specific validation logic for Cloudflare AI (requiring an Account ID) and introduces generic probing for web search/fetch and media providers (TTS, embedding, STT, image, video) based on their configuration schemas. Additionally, the validation flow now normalizes provider IDs and correctly handles providers that do not require an API key, such as ollama-local.

src/app/api/providers/validate · high confidence

Gemini API compatibility and native TTS support in /v1beta/models

The /v1beta/models endpoint now distinguishes between streaming and non-streaming requests based on the URL action suffix (:streamGenerateContent vs :generateContent) rather than body fields, transforming OpenAI SSE responses into Gemini SSE format for streaming and converting JSON responses for non-streaming calls. It adds support for native Gemini Text-to-Speech by forwarding specific TTS requests directly to the Google Generative Language API. The models listing route now exposes Gemini models under both provider-prefixed and native paths, and includes input/output token limits.

src/app/api/v1beta · high confidence

Improved credential refresh and expanded provider support for usage API

The usage API now supports usage tracking for whitelisted API-key providers (such as Kiro, GLM, and MiniMax) in addition to OAuth connections. For OAuth connections, the API implements a more robust credential refresh lifecycle that reads the latest tokens from the database before refreshing to prevent token reuse issues, and automatically detects and retries on auth-expired responses from providers. Proxy configuration is also resolved and passed through to ensure reliable connectivity during usage and refresh operations.

src/app/api/usage/\[connectionId\] · high confidence

Improved token counting for structured Anthropic message blocks

The /v1/messages/count\_tokens endpoint now uses a more comprehensive estimation logic that accounts for structured Anthropic content blocks, including tool\_use, tool\_result, and thinking types, as well as system and tool definitions. Previously, the endpoint only counted plain text content; the new implementation recursively processes complex message structures to provide a more accurate token count for users relying on this mock endpoint for cost estimation or quota management. Additionally, a debug log message regarding SSE translator initialization has been removed from the main messages route.

src/app/api/v1/messages · high confidence

Introduce per-tool DNS management with atomic Windows host file updates

The MITM server now manages DNS entries on a per-tool basis using the new TOOL\_HOSTS mapping, allowing users to enable or disable interception for specific tools independently. On Windows, host file modifications are performed atomically to prevent corruption, while macOS and Linux users benefit from explicit DNS cache flushing after changes. The system also intelligently handles privilege escalation, detecting whether sudo is available and whether a password is required, ensuring compatibility with minimal Docker environments where sudo may be absent.

src/mitm/dns · high confidence

Landing page UI updates and clipboard fallback

The landing page now uses a shared ProviderIcon component for tool logos instead of Next.js Image, and the copy-to-clipboard action in the GetStarted section relies on a custom hook that provides a fallback when navigator.clipboard is unavailable. The data location paths displayed to users have been updated to point to SQLite files (data.sqlite) instead of the previous JSON database, and the navigation logo is now a semantic button with an aria-label for better accessibility.

src/app/landing · high confidence

MITM server restructured with new configuration, routing, and IDE version override logic

The MITM (Man-in-the-Middle) interception layer has been restructured to support multiple IDE tools (Antigravity, Copilot, Kiro, Cursor) with improved routing and configuration. A new \config.js\ centralizes target hosts, URL patterns, and model synonym/pattern mappings, enabling flexible model aliasing and passthrough rules. The \antigravityIdeVersion.js\ module now rewrites IDE version markers on generation requests to ensure compatibility with upstream backends, while preserving client identity on other requests. The \manager.js\ handles server lifecycle, including root CA generation, DNS entry management, and cross-platform process control (with Windows UAC elevation support via \winElevated.js\). Logging and debugging are enhanced via \logger.js\, which dumps requests/responses to disk with gzip/brotli decoding and blacklist filtering. The \server.js\ implements TLS/SNI handling, ALPN negotiation, and HTTP/1.1/2 passthrough, integrating all components into a cohesive interception pipeline.

src/mitm · high confidence

Model listing now filters disabled models and exposes capability metadata

The /api/models endpoint now respects user-configured disabled models, excluding them from the returned list based on provider alias and model ID. Additionally, every model entry now includes a 'caps' object detailing specific capabilities (vision, search, reasoning, context window, and max output), sourced from the provider's capability definitions. Custom LLM models are also included in this list, with their stored capabilities overriding default heuristics, allowing users to see and manage custom model availability and features alongside standard models.

src/app/api/models · high confidence

New Cloudflare quick tunnel implementation with improved process management

The Cloudflare tunnel module has been rewritten to introduce a robust quick-tunnel mechanism. This includes automatic downloading and platform-specific validation of the cloudflared binary, ensuring a valid executable is always available. The new manager handles tunnel lifecycle (enable/disable) with better state persistence, including short ID and URL tracking. A key behavioral improvement is the preservation of the cloudflared process ID via a dedicated PID file, allowing the system to correctly identify and manage the running tunnel process across restarts or unexpected exits, rather than relying solely on port checks.

src/lib/tunnel/cloudflare · high confidence

New dashboard authentication, OIDC/SAML SSO, and hardened security controls

This update introduces a new JWT-based session system for the dashboard (with a 24-hour cookie max-age and secure cookie handling), adds native SAML 2.0 and OIDC SSO integrations for external identity providers, and hardens security by enforcing real client IP rate-limiting on login attempts, requiring password re-authentication for sensitive actions, and validating the x-9r-real-ip header via a trusted peer token to prevent SSRF and IP spoofing.

src/lib/auth · high confidence

New live model catalog fetchers and capacity adapter for improved reliability

The service layer now includes dedicated live model catalog fetchers for Cursor, GitHub Copilot, Cline, ClinePass, Grok CLI, Kimchi, and Kiro, replacing static registries with account-specific, up-to-date model lists. A new capacity adapter automatically injects fallback models (defaulting to mimo-v2.6-flash-free) when a request requires capabilities like vision or PDF that the primary models lack, and intelligently strips conversation history to fit context windows when switching to these adapters. Additionally, robust account fallback logic with exponential backoff and model-specific locking ensures that transient errors or rate limits on one account do not block requests, while combo handling has been enhanced with capability-based reordering and tool-history flattening for better compatibility.

open-sse/services · high confidence

New model capability hook, clipboard fallback, and system theme sync

This update introduces three distinct improvements to the shared hooks. First, it adds a new \useModelCaps\ hook that fetches and caches model capabilities (such as vision, search, and reasoning) from the \/api/models\ endpoint, automatically refreshing when custom models change. Second, it fixes a potential crash in \useCopyToClipboard\ by adding a fallback mechanism using a temporary textarea and \document.execCommand\ when the \navigator.clipboard\ API is unavailable. Third, it refactors \useTheme\ to use \useSyncExternalStore\ for subscribing to system theme changes, ensuring the UI correctly reflects the OS preference when the theme is set to 'system' and improving server-side rendering safety.

src/shared/hooks · high confidence

New model catalog sync API and hardened dashboard access controls

Users can now monitor and trigger background model catalog synchronization via new API endpoints (/api/models/catalog-sync) and test outbound proxy configurations via /api/settings/proxy-test. Access to the dashboard and sensitive settings is now governed by a centralized guard (dashboardGuard.js) that enforces strict local-only access for tunnel and CLI tool operations, validates CLI tokens for API access, and respects the requireLogin setting, while the legacy cloud sync initialization has been removed in favor of the new background sync mechanism.

src · high confidence

OAuth configuration centralized and new providers added

OAuth settings for existing providers (Claude, Codex, Gemini, Qwen, iFlow, Antigravity, OpenAI, GitHub, Kiro, Cursor, Kimi) are now sourced from a central provider registry rather than being hardcoded in this file, improving maintainability. The file also introduces configuration constants for new OAuth providers including xAI (Grok), Qoder, and Qoder CN. Additionally, a security fix validates AWS region inputs to prevent Server-Side Request Forgery (SSRF) attacks.

src/lib/oauth/constants · high confidence

Proactive token refresh and quota-aware account routing

The system now proactively refreshes OAuth tokens in the background before they expire, reducing the likelihood of authentication errors during active use. For Antigravity accounts, a new quota cache tracks real-time usage limits and implements a circuit breaker to block accounts that are returning 429 errors despite showing available quota, preventing retry storms. Account selection logic has been enhanced to respect these quota limits and model-specific rate locks, ensuring that exhausted or blocked accounts are skipped in favor of available ones.

src/sse/services · high confidence

Provider connection listing now supports filtering, pagination, and data sanitization

The client provider API endpoint has been significantly enhanced to support paginated, filtered, and sorted retrieval of provider connections. Users can now filter results by provider and account status, sort by priority or provider name, and control pagination via query parameters. The response includes metadata such as total counts, available provider options, and pagination details. Additionally, sensitive data is now sanitized before being returned to the client, with specific fields masked or excluded to improve security.

src/app/api/providers/client · high confidence

Provider connections now support per-connection proxy pools and detailed status tracking

The provider connection API now allows users to assign specific proxy pools to individual connections and configure per-connection proxy settings (URL, enabled status, no-proxy list) via the provider-specific data. Additionally, the update endpoint now accepts and persists test status, last error, and last error timestamp fields, enabling better visibility into connection health. The previous automatic synchronization to cloud storage on update or delete has been removed, decoupling local provider management from cloud sync operations.

src/app/api/providers/\[id\] · high confidence

Qoder integration overhaul: image handling, context tiers, and regional support

The Qoder provider integration has been significantly expanded and stabilized. It now supports the Qoder CN region (qoder.com.cn) alongside the international site, and adds Personal Access Token (PAT) authentication with automatic job-token exchange. Image and file attachments are no longer inlined as large base64 strings; instead, they are uploaded to Qoder's file API and replaced with URLs, preventing payload size limits and upstream 413 errors. The system also introduces automatic context-window tier escalation, allowing long sessions to automatically switch to larger context limits (e.g., 1M tokens) when needed. Additionally, the SSE stream coalescer now correctly reports token usage to all clients, and the model catalog has been refreshed with updated capability mappings.

open-sse/shared/qoder · high confidence

Qoder module restructured to re-export from open-sse/shared

The qoder module in src/lib/qoder has been refactored to act as a re-export layer, delegating its constants, COSY signing helpers, and encoding logic to the open-sse/shared/qoder directory. This change consolidates the qoder implementation within the open-sse package, ensuring that the lib/qoder location remains self-contained and serves primarily as an import point for these shared utilities.

src/lib/qoder · high confidence

Refactor Codex settings persistence to use confbox and update API key handling

The CLI tools settings endpoint now uses the confbox library for robust TOML parsing and stringification, replacing the previous custom parser. This change introduces support for a subagent model configuration and modifies how the API key is stored: instead of writing it to the auth.json file, the key is now passed directly via an HTTP Authorization header in the model provider configuration. Additionally, the base URL is automatically normalized to ensure it ends with /v1, and the route is explicitly marked as dynamic.

src/app/api/cli-tools/codex-settings · high confidence

Removal of cloud synchronization for model aliases

The alias management API no longer synchronizes changes to the cloud. The route handler has been refactored to remove the \syncToCloudIfEnabled\ helper and its associated imports, meaning that creating, updating, or deleting model aliases is now a local-only operation without automatic cloud replication.

src/app/api/models/alias · high confidence

Removal of legacy cloud sync and debug logging in chat API

The chat API endpoints no longer rely on the legacy cloud synchronization mechanism, as the import and usage of \callCloudWithMachineId\ have been removed from the completions route. Additionally, verbose debug logging regarding translator initialization has been stripped from both the main chat route and the completions route to reduce console noise.

src/app/api/v1/chat · high confidence

Runtime dependencies are now installed locally to avoid build tools and AV issues

The CLI now installs native dependencies (better-sqlite3 and systray2) into a user-writable runtime directory instead of the global package folder. This prevents Windows file-locking errors during global updates, removes the need for build tools (like Python or Xcode CLT) on Node 22+ by using prebuilt binaries, and resolves macOS Apple Silicon tray issues by downloading a native arm64 binary. It also cleans up the legacy systray package to avoid antivirus false positives and loading failures on modern macOS versions.

cli/hooks · high confidence

Security hardening, provider icon optimization, and bulk API key collision fix

This update introduces several improvements to the shared utilities layer. Security is strengthened by adding a robust SSRF guard (ssrfGuard.js) that blocks internal, private, and metadata IP ranges (including IPv6-mapped IPv4 addresses) and enforces DNS resolution checks to prevent bypasses via wildcard DNS. Provider icons are now lazy-loaded with a session-level cache to prevent 404 spam, and aliases (e.g., GitLab Duo, Ollama Search) are resolved to existing assets. The bulk API key addition flow (bulkAdd.js) now plans collision-free names against existing connections, preventing accidental overwrites. Additionally, legacy cloud sync functionality has been removed, and machine ID generation is now persisted to disk for consistency across CLI and server environments.

src/shared/utils · high confidence

Simplified CLI Tools dashboard with unified status monitoring

The CLI Tools page has been refactored to remove cloud integration features and complex model mapping logic, replacing them with a streamlined view that displays tool statuses via a single API call. Users will no longer see cloud settings, API key management, or provider-specific model selection within this page; instead, the interface now focuses on a grid of tool status cards, including new support for MITM tool links and a summary card, providing a cleaner and more focused management experience.

src/app/(dashboard)/dashboard/cli-tools · high confidence

Standalone build asset handling and registry schema migration

The standalone build process now correctly includes static assets, public files, and the custom server wrapper in the output directory, ensuring the application serves requests properly outside the development environment. Additionally, the provider registry has been migrated to a unified 'Model-A' schema where all model types (chat, media, etc.) are consolidated into a single \models\ array with a \kind\ field, and media-specific configuration fields are promoted to the top level. A new script automates the injection of display names, categories, and UI aliases into registry files based on source constants, and a translation tool for README documentation has been added.

scripts · high confidence

Standardized voice listing API for TTS providers

The system now provides a unified voice selection experience by introducing dedicated API endpoints for Deepgram, ElevenLabs, Inworld, and MiniMax, alongside a consolidated central route. These new endpoints fetch and normalize available voices from each provider into a consistent format, allowing users to browse and filter voices by language across all supported text-to-speech services.

src/app/api/media-providers · high confidence

Startup performance improved and legacy cloud sync removed

Application startup is now faster because heavy initialization tasks (such as database cleanup, tunnel restoration, and background service scheduling) are deferred by 3 seconds, preventing them from blocking the first HTTP request. The legacy cloud synchronization feature has been removed, with the \CloudSyncScheduler\ and its initialization logic deleted from the codebase. Additionally, a new \bootstrap.js\ entry point ensures the application initializes only once per server process and skips initialization during Next.js build phases.

src/shared/services · high confidence

Support for Kiro IDC (organization) token auto-import

The auto-import API now supports AWS IAM Identity Center (IDC) organization tokens. In addition to extracting the refresh token from the AWS SSO cache, the endpoint resolves the linked clientId and clientSecret from the client registration file and normalizes the profile ARN region to us-east-1 for the runtime gateway, ensuring token refresh works correctly for organization-based Kiro IDE logins.

src/app/api/oauth/kiro/auto-import · high confidence

Token refresh service deduplication and provider-specific handling

The token refresh service now prevents redundant refresh requests by deduplicating concurrent calls for the same provider and token, caching results for 10 seconds to reduce load and race conditions. It also introduces specialized refresh logic for specific providers: Cline tokens are now refreshed using a JSON body with a 'clientType: extension' contract, and XAI tokens are handled via a dedicated service singleton. Generic OAuth2 refreshes support configurable body formats (JSON vs form-encoded) and extra headers, allowing providers like Claude and iFlow to use custom authentication styles.

open-sse/services/tokenRefresh · high confidence

Unified request lifecycle logging with session-colored tags and configurable log levels

The logging utility in src/sse/utils/logger.js has been refactored to unify request lifecycle logging. Log levels are now configurable via the LOG\_LEVEL environment variable (defaulting to INFO instead of DEBUG). To help correlate log lines within the same session, the logger now assigns stable, session-specific colored tags (e.g., 🟢, 🔵) derived from a session seed, ensuring consistent coloring for related requests. New exported functions (line, errorLine, tagForSession, nextTag, fmtThink) support this correlated output, and warning messages are now explicitly printed to the console.

src/sse/utils · high confidence

Unified search handler with SSRF protection and multi-provider support

The search handler in open-sse/handlers/search has been consolidated into a single dispatcher that routes requests to either dedicated search APIs (Serper, Brave, Perplexity, Exa, Tavily, TinyFish, Google PSE, Linkup, SearchApi, YouCom) or chat-based LLM wrappers (Gemini, Antigravity, OpenAI, XAI, Kimi, MiniMax). This new architecture introduces a unified response format for all providers and adds strict SSRF guards that validate client-supplied base URLs against internal or private addresses. Users benefit from a consistent search experience across diverse providers, with built-in credential fallbacks and retry logic for retriable errors.

open-sse/handlers/search · high confidence

Usage stats API now supports dynamic period selection

The usage statistics endpoint now accepts a 'period' query parameter, allowing clients to request data for specific timeframes such as 'today', '24h', '7d', '30d', '60d', or 'all'. If no period is specified, the API defaults to the '7d' view. This change enables more flexible consumption of usage data by frontend components that previously relied on a fixed period.

src/app/api/usage/stats · high confidence

Fixes

Dynamic MITM certificate generation and cross-platform trust store installation

The MITM module now replaces the previous static wildcard certificate with a dynamic system: a 10-year Root CA is generated on first use (and auto-regenerated if expired), and unique leaf certificates are issued per domain at runtime. To ensure these dynamic certificates are trusted, the system now automatically installs the Root CA into the OS trust stores on Windows (Root store), macOS (System keychain), and Linux (via distribution-specific paths and NSS database injection), handling stale certificate cleanup and elevation requirements on each platform.

src/mitm/cert · high confidence

Fix 9Router API key resolution and add JSONC tolerance for VS Code Copilot settings

The CLI tools API now correctly resolves the API key for the 9Router VS Code Copilot configuration by falling back to the first active dashboard key instead of writing the invalid placeholder 'sk\_9router', which previously caused 401 errors in deployments requiring an API key. Additionally, the route that reads the VS Code \chatLanguageModels.json\ config now tolerates JSONC syntax (trailing commas), preventing parse errors from being misinterpreted as the tool being uninstalled.

src/app/api/cli-tools/copilot-settings · high confidence

Fix Zed OAuth paste-token crash and add IDE auto-import

This change fixes a crash that occurred when pasting a Zed OAuth token and introduces a new IDE auto-import capability. A new GET endpoint at /api/oauth/zed/auto-import reads the signed-in Zed IDE session directly from the OS keyring (macOS Keychain, Linux secret-tool, or Windows Credential Manager) to retrieve credentials. A corresponding POST endpoint at /api/oauth/zed/import validates the provided access token, fetches user information, and creates a provider connection, allowing users to seamlessly import their Zed session without manual token entry.

src/app/api/oauth/zed · high confidence

Fixes for prompt formatting, tool schema translation, and API compatibility

This update introduces several fixes to the translator's format handlers to improve compatibility with Claude, Gemini, and OpenAI APIs. For Claude, the translator now correctly handles prompt caching by anchoring cache markers on the last cacheable tool (avoiding conflicts with deferred tools) and capping markers at the API's four-per-request limit; it also fixes tool-use ordering by removing text blocks that follow tool calls and merges consecutive same-role messages. Gemini tool schemas are now sanitized to strip unsupported JSON Schema keywords (such as minLength, deprecated, and vendor extensions) that cause request rejections. OpenAI format filtering now preserves cache\_control when required (e.g., for DashScope) and normalizes tool definitions from Claude and Gemini formats. Additionally, the Responses API handler now robustly normalizes input, clamps call IDs to prevent validation errors, and coerces arguments and outputs to valid string types.

open-sse/translator/formats · high confidence

Improved Tailscale tunnel reliability and responsiveness

The Tailscale tunnel implementation now detects system-installed Tailscale binaries via a dual-socket probe (checking both custom and system sockets) to ensure connectivity even when Tailscale is installed outside the app's bundled directory. Probes for login and running status are now non-blocking, using background refresh and caching to prevent UI freezes during status checks. Additionally, the health check wait time for the enable flow is capped at 20 seconds, allowing the tunnel to proceed even if DNS propagation or certificate provisioning is slow, with a watchdog retrying verification afterwards.

src/lib/tunnel/tailscale · high confidence

Reliable autostart and native system tray support across macOS, Windows, and Linux

The tray module now includes a robust autostart mechanism that correctly registers the application with the OS (using launchctl on macOS, startup scripts on Windows, and .desktop files on Linux) and resolves the CLI path reliably across various Node.js managers like nvm. The system tray UI has been updated to use the systray2 fork for native macOS and Linux support, ensuring native arm64 execution on Apple Silicon without Rosetta, while Windows now uses a PowerShell-based NotifyIcon implementation that is DPI-aware for high-resolution displays.

cli/src/cli/tray · high confidence

Restore model availability API endpoint

The API endpoint for retrieving and managing model availability status has been restored. This endpoint now exposes the current availability of AI models by checking provider connections and active cooldown locks, allowing users to see which models are in a 'cooldown' or 'unavailable' state. It also supports clearing cooldowns for specific models via a POST request, which resets the connection status and error states, effectively restoring access to the affected models.

src/app/api/models/availability · high confidence

Secure OAuth callback relay and support for token-based flows

The OAuth callback page now restricts postMessage targets to specific trusted origins (the current origin and localhost:1455) instead of allowing any origin, mitigating man-in-the-middle risks. It also extracts and relays an optional 'token' parameter alongside the code, enabling token-based authentication flows, and simplifies the post-login status logic to always proceed to success if a code or token is present.

src/app/callback · high confidence

Test coverage

Added golden snapshot tests for the translator; Expanded real-provider integration tests for translation accuracy and edge cases; Expanded test coverage for the translation layer; Expanded unit test coverage for provider integrations and core services; Refactored provider connection testing to use centralized test utilities; Updated provider alias and test baseline snapshots.

Dependencies

Major dependency upgrade and CLI package introduction

The main application has upgraded to Next.js 16.1.6 and React 19.2.4, introducing new dependencies for drag-and-drop interactions (@dnd-kit), SSO authentication (@node-saml/node-saml), and data visualization (recharts). The database storage backend has shifted from lowdb to sql.js (with better-sqlite3 as an optional native fallback), and several other libraries like jose, marked, and express have been updated. A new 'cli' package has been added to manage the command-line interface, bundling tools like enquirer and node-forge, while a 'gitbook' package was introduced for documentation hosting using Next.js 16.1.1. Test infrastructure was also updated with a new 'tests' package using Vitest.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 29 → 32 (+3.1)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 33 → 34 (+0.2)
  • Architecture 63 → 62 (-1.2)
  • Maturity 77 → 77 (-0.3)
  • Readiness 18 → 16 (-1.1)
  • Security 31 → 52 (+21.5)
  • Performance 60 (new)

Resolved (117)

  • Boundary-crossing change coupling: providers.js ↔ AddApiKeyModal.js (open-sse/config/providers.js)
  • Boundary-crossing change coupling: usage.js ↔ utils.js (open-sse/services/usage.js)
  • Change coupling: MitmServerCard.js ↔ route.js (src/app/(dashboard)/dashboard/cli-tools/components/MitmServerCard.js)
  • Change coupling: providerModels.js ↔ pricing.js (open-sse/config/providerModels.js)
  • Change coupling: route.js ↔ server.js (src/app/api/cli-tools/antigravity-mitm/route.js)
  • CodexExecutor.transformRequest (cognitive 25) (open-sse/executors/codex.js)
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: cli/src/cli/menus/providers.js (cli/src/cli/menus/providers.js)
  • Hotspot: open-sse/config/kiroConstants.js (open-sse/config/kiroConstants.js)
  • Hotspot: open-sse/executors/codebuddy-cn.js (open-sse/executors/codebuddy-cn.js)
  • Hotspot: open-sse/executors/devin-cli.js (open-sse/executors/devin-cli.js)
  • Hotspot: open-sse/executors/grok-cli.js (open-sse/executors/grok-cli.js)
  • Hotspot: open-sse/executors/grok-web.js (open-sse/executors/grok-web.js)
  • Hotspot: open-sse/executors/perplexity-web.js (open-sse/executors/perplexity-web.js)
  • …and 97 more

New (179)

  • (anonymous) (cognitive 19) (src/app/(dashboard)/dashboard/providers/[id]/page.js)
  • (anonymous) (cyclomatic 19) (src/app/(dashboard)/dashboard/providers/[id]/page.js)
  • Boundary-crossing change coupling: MitmToolCard.js ↔ manager.js (src/app/(dashboard)/dashboard/cli-tools/components/MitmToolCard.js)
  • Change coupling: MitmServerCard.js ↔ MitmToolCard.js (src/app/(dashboard)/dashboard/cli-tools/components/MitmServerCard.js)
  • Change coupling: opencode-go.js ↔ opencode-go.js (open-sse/executors/opencode-go.js)
  • Change-coupling hub: route.js → MitmServerCard.js, MitmToolCard.js, server.js (src/app/api/cli-tools/antigravity-mitm/route.js)
  • ClassTooLong: CodexToolCard (src/app/(dashboard)/dashboard/cli-tools/components/CodexToolCard.js)
  • ClassTooLong: GenericCliToolCard (src/app/(dashboard)/dashboard/cli-tools/components/GenericCliToolCard.js)
  • CodeBuddyExecutor.parseError (cognitive 30) (open-sse/executors/codebuddy-cn.js)
  • CodeBuddyIntlExecutor.parseError (cognitive 30) (open-sse/executors/codebuddy-intl.js)
  • CombosPage (cyclomatic 78) (src/app/(dashboard)/dashboard/combos/page.js)
  • CustomConfigCard.CustomConfigCard (cognitive 25) (src/app/(dashboard)/dashboard/providers/[id]/CustomConfigCard.js)
  • CustomConfigCard.CustomConfigCard (cyclomatic 27) (src/app/(dashboard)/dashboard/providers/[id]/CustomConfigCard.js)
  • FileTooLong: components/CodexToolCard.js (src/app/(dashboard)/dashboard/cli-tools/components/CodexToolCard.js)
  • FileTooLong: components/GenericCliToolCard.js (src/app/(dashboard)/dashboard/cli-tools/components/GenericCliToolCard.js)
  • FunctionTooLong: CustomConfigCard.CustomConfigCard (src/app/(dashboard)/dashboard/providers/[id]/CustomConfigCard.js)
  • FunctionTooLong: GenericCliToolCard.GenericCliToolCard (src/app/(dashboard)/dashboard/cli-tools/components/GenericCliToolCard.js)
  • FunctionTooLong: ZedAuthModal.ZedAuthModal (src/shared/components/ZedAuthModal.js)
  • FunctionTooLong: geminiLiveStt.transcribeGeminiLive (open-sse/handlers/geminiLiveStt.js)
  • FunctionTooLong: page.CapacityAdapterCap (src/app/(dashboard)/dashboard/combos/page.js)
  • …and 159 more

Changes since last survey

  • 150 commits — 65 feature/other, 85 fixes

By area

  • open-sse/providers — 36 commits
  • src/app — 24 commits
  • open-sse/translator — 18 commits
  • (root) — 12 commits
  • open-sse/executors — 11 commits
  • src/shared — 9 commits
  • tests/unit — 9 commits
  • open-sse/utils — 6 commits
  • open-sse/services — 5 commits
  • open-sse/config — 4 commits
  • src/lib — 4 commits
  • open-sse/handlers — 3 commits
  • tests/translator — 3 commits
  • .github/issue-assets — 1 commit
  • .github/workflows — 1 commit
  • cli/README.md — 1 commit
  • cli/src — 1 commit
  • public/i18n — 1 commit
  • public/providers — 1 commit

Notable commits

  • fix: fix(antigravity): drop requestType "agent" to avoid false 429 RESOURCE_EXHAUSTED
  • fix: fix(antigravity): rewrite all Hermes identity variants, not just the legacy sentence
  • fix: fix(antigravity): sanitize Hermes system identity
  • fix: fix(antigravity): scope cached thought signatures to the model family
  • fix: fix(antigravity): separate weekly and short-window quotas and clean up redundant rows
  • fix: fix(antigravity): strip Claude Code billing header from system prompts
  • fix: fix(auth): don't cool down an account for a request-scoped 4xx
  • fix: fix(capabilities): add deepseek-v4-1-flash vision alias; fix(modal): add zed to live catalog providers
  • fix: fix(capabilities): publish real GPT-6/GPT-5.4+ context windows and combo token limits
  • fix: fix(capabilities): stop caching the catalog source per module copy (#4351)
  • fix: fix(claude): cache a tool loop's final tool results with the 4th breakpoint
  • fix: fix(claude): decloak tool names when toolNameMap misses (#4342)
  • fix: fix(claude): inject unsigned thinking placeholders for opencode-go DeepSeek /messages (#4436)
  • fix: fix(claude): keep a trailing user turn so cleanup never yields assistant prefill
  • fix: fix(claude): preserve intentional prefill from non-messages[] source formats
  • fix: fix(claude): resolve Sonnet 5.x to adaptive thinking so no forged thinking placeholders are sent
  • fix: fix(claude): update spoofed cli version to 2.1.280 to support Opus 5.5
  • fix: fix(cli): filter model selector by active connections and noAuth providers
  • fix: fix(cli-tools): keep existing ANTHROPIC_AUTH_TOKEN when applying Claude settings
  • fix: fix(cli-tools): refresh Codex settings after apply (#4347)
  • …and 130 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

decolua/9router was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a99cf57239ff778b61e434c2786009d5ed1c412c — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.