Kong/insomnia
49.7
Weak · 28 September 2026
162.8k
lines of production code
TypeScript
primary language
3
measurements over time
What this system is
This system is a modernized, cross-platform API client and development environment that supports HTTP, gRPC, WebSocket, and GraphQL protocols. It features a robust data layer with local and Git-based version control, secure plugin sandboxing, and a unified scripting environment for request automation. The application provides comprehensive tools for API design, testing, and synchronization with cloud services, all built on a secure, isolated architecture.
How it got here
2016–2022 — Monorepo migration and modernization
91 changes.
The project underwent a comprehensive architectural overhaul, migrating from a legacy Redux and Webpack setup to a modern monorepo structure using esbuild, Vitest, and React Aria. This period focused on rebuilding core infrastructure, including a new database layer, a sandboxed plugin system, and a unified CLI, while simultaneously replacing the UI with accessible, component-based designs and LiquidJS templating.
2023–2026 — Architecture overhaul and security hardening
91 changes.
This period focused on a comprehensive architectural restructuring of the Insomnia codebase, extracting the data layer into the insomnia-data package and implementing a new service layer for centralized database access. Significant security improvements were introduced, including a QuickJS sandbox for plugin execution, a secure Windows installer wrapper, and a new VCS package for encrypted sync. The work also involved migrating the templating engine to LiquidJS, overhauling the UI with Tailwind v4, and expanding support for MCP, Konnect, and external vault integrations.
Features
Add Electron API shim for request sending in non-electron environments
A new shim file has been added to the send-request package to provide minimal implementations of Electron-specific APIs (app.getPath, ipcMain, BrowserWindow). This allows the request-sending logic to function correctly in environments where the full Electron runtime is not available, by mocking these dependencies with standard Node.js alternatives like os.tmpdir().
packages/insomnia/send-request · high confidence
Add build and test configuration for the scripting-environment package
The \insomnia-scripting-environment\ package now includes dedicated configuration files to support its build and testing workflows. An \esbuild-runner.config.js\ file is introduced to mark \@getinsomnia/node-libcurl\ and \electron\ as external dependencies, ensuring they are not bundled. A \tsconfig.json\ file establishes the TypeScript compilation settings, targeting ES2022, enabling strict type checking, and configuring path aliases to resolve \\~/\*\ to the \insomnia\ source directory. Additionally, a \vitest.config.ts\ file is added to configure the test runner, including an alias for the \\~\ path and settings to hide skipped tests.
packages/insomnia-scripting-environment · high confidence
Add themed Button and AsyncButton components
The Insomnia UI now includes a new set of reusable button components in the \themed-button\ package. The \Button\ component supports configurable sizes (default, small, medium, xs), variants (outlined, contained, text), and themes (default, surprise, info, success, notice, warning, danger), allowing for consistent styling across the application. Additionally, an \AsyncButton\ component is provided to handle asynchronous actions, automatically managing a loading state and disabling the button while an operation is in progress.
packages/insomnia/src/ui/components/themed-button · high confidence
Added code snippet type definitions and autocomplete generation script
The application now includes TypeScript interfaces for HTTP snippet clients and targets (code-snippet.ts) to support code generation features, alongside a new build script (generate-autocomplete.ts) that statically derives autocomplete snippets from the scripting API for use in the renderer without requiring Node.js integration.
packages/insomnia-scripting-environment/scripts, packages/insomnia/src/types · high confidence
Added sync delta diff and patch utilities
New \diff\ and \patch\ modules have been added to the sync delta package to support content synchronization. The \diff\ function generates a sequence of COPY and INSERT operations by comparing source and target strings using SHA-1 hashed blocks, while the \patch\ function applies these operations to reconstruct the target content. This logic is foundational for the sync feature's ability to calculate and apply changes between document versions.
packages/insomnia/src/sync/delta · high confidence
Define sync model schemas for Insomnia data models
The sync module now includes explicit schema definitions for core Insomnia data models (Workspace, Request, GrpcRequest, RequestGroup, and Environment) via a new \model-schemas.ts\ file. These schemas, built using \fluent-builder\ and derived from \insomnia-data\ model initializers, standardize the structure of data objects used during synchronization, ensuring consistent field presence and types for sync operations.
packages/insomnia/src/sync/\\schemas\\_ · high confidence_
Experimental QuickJS sandbox for pre-request and after-response scripts
Insomnia introduces an opt-in QuickJS-based sandbox for running pre-request and after-response scripts, designed to run off the main thread via a dedicated Web Worker to prevent UI blocking. This experimental feature is disabled by default (controlled by \QUICKJS\_SANDBOX\_ENABLED\ and the \settings.useQuickJsScriptSandbox\ flag) and provides a restricted scripting environment that blocks dangerous Node.js built-ins (such as \fs\, \child\_process\, and \crypto\), prevents prototype pollution, and limits access to global objects like \process\ and \globalThis\. The sandbox exposes a minimal \insomnia\ API for reading/writing environment and transient variables, accessing the request object, and sending HTTP requests via \insomnia.sendRequest()\, while supporting a curated set of external libraries including \lodash\, \moment\, \chai\, and \cheerio\. Comprehensive test coverage has been added for the security policy, module interception, and the QuickJS engine's behavior.
packages/insomnia/src/scripting · high confidence
Initial release of the Insomnia Component Documentation site
A new Docusaurus-based documentation site has been added for Insomnia's shared UI component library. This site provides detailed API references, usage examples, and styling guidelines for base components including Button, Input, Checkbox, Select, Switch, Tabs, Banner, and InputNumber. It features live-editable code examples powered by React Aria and Tailwind CSS, with a dark/light theme system and an autogenerated sidebar for easy navigation.
packages/insomnia-component-docs · high confidence
Inso CLI adds telemetry, collection run reporting, and test output formatting
The Inso CLI now collects anonymous usage analytics via Segment, respecting the new INSO\_TELEMETRY\_DISABLED environment variable and the user's enableAnalytics setting in local settings. Collection runs can now save a detailed result report (RunCollectionResultReport) that includes execution stats, timing, and redacted or plaintext data. Additionally, the CLI introduces multiple test output reporters (dot, list, min, progress, spec, tap) to format test results in the console, and supports reading iteration data from CSV files with proper handling of quoted fields.
packages/insomnia-inso/src · high confidence
Introduce MCP client UI with elicitation, sampling, and server primitive management
Insomnia now includes a dedicated UI for interacting with Model Context Protocol (MCP) servers. This update adds a new \mcp\ component area featuring \McpPane\ for browsing and filtering server primitives (tools, resources, prompts), and \McpRequestPane\ for configuring request parameters, authentication, and file roots. It introduces \ElicitationForm\ and \SamplingForm\ to handle interactive server requests, allowing users to submit data, approve/reject sampling, or use an AI-assisted response generator. The \McpNotificationTab\ and \EventView\ provide a searchable log of server events with raw and formatted viewing options, while \McpUrlActionBar\ manages connection states and transport types (HTTP/STDIO).
packages/insomnia/src/ui/components/mcp · high confidence
Introduce insomnia-api package for shared API functionality
The new \insomnia-api\ package centralizes API client logic and types for use across both the Insomnia application and inso-cli. It provides a unified, proxy-aware fetch mechanism to ensure requests respect system proxies and OS certificates, and exposes modules for user profiles, vault operations, organizations, spaces, collaborators, enterprise features, trials, and VCS integration.
packages/insomnia-api · high confidence
Introduce new GraphQL Explorer UI components
The GraphQL Explorer now features a comprehensive set of new React components to enhance schema exploration. Users can now see default values for arguments, view deprecation warnings with tooltips, and navigate between types and fields via clickable links. The explorer includes a dedicated search interface with fuzzy matching for types and fields, lazy-loaded results to maintain performance, and detailed views for enums, object types, interfaces, and unions, including their descriptions, implementations, and field arguments.
packages/insomnia/src/ui/components/graph-ql-explorer · high confidence
Introduce new MCP client implementation with OAuth and transport support
The MCP client logic in the main process has been rewritten to use the Model Context Protocol SDK, introducing dedicated transports for both STDIO and Streamable HTTP connections. This change adds full OAuth 2.0 support for MCP servers, including a new 'mcp\_auth\_flow' grant type that allows users to authorize via a browser window with options to disable automatic browser launching and disable SSL validation. The new implementation also supports resource subscriptions, server-side elicitation and sampling requests, and integrates with the insomnia-data package for persisting responses and environments.
packages/insomnia/src/main/mcp · high confidence
Introduces shared basic component library
Insomnia now provides a new shared component library at \\~/basic-components\, consolidating UI primitives like Button, Modal, Tabs, Banner, Card, and SelectPopover into a single, consistent API built on React Aria and Tailwind CSS. This library standardizes styling conventions (using CSS variables and Tailwind utilities) and accessibility patterns across the application, serving as the foundation for future UI migrations and theme customization.
packages/insomnia/src/basic-components · high confidence
Konnect sync now supports Kong Expressions router and proxy configuration
The Konnect integration has been expanded to handle Kong's new Expressions router DSL. When syncing routes that use expressions, Insomnia now parses the expression to extract standard HTTP fields (methods, paths, hosts, headers) so they can be represented as requests; routes relying on unsupported features like TLS SNI matching are skipped. Additionally, the sync process now automatically configures proxy settings by deriving environment variables (proxy\_host, grpc\_proxy\_host, grpcs\_proxy\_host) from the Control Plane's proxy URLs, and it sanitizes incoming data by stripping Liquid template syntax to prevent injection issues.
packages/insomnia/src/konnect · high confidence
New AI assistant skills for component documentation and scripting troubleshooting
The AI assistant now includes dedicated skills to streamline two key workflows: maintaining Docusaurus component documentation and debugging the scripting environment. The new component-docs skill provides a structured procedure for authoring and updating MDX docs for shared UI components, including instructions for registering live code examples in the ReactLiveScope. Additionally, the fix-scripting-feature skill offers detailed architectural context and reference documentation for the pre-request, after-response, and test scripting APIs (pm/insomnia), helping to resolve common issues like sandbox violations, module import errors, and unexpected behavior in the Postman-compatible API surface.
.claude · high confidence
New FancyReporter for inso CLI output
The inso CLI now includes a new FancyReporter that formats log output with colored icons, badges, and Unicode support. This reporter handles various log types (info, error, warn, etc.) with distinct visual indicators, formats error stacks and chained causes, and adapts layout based on terminal width. It also supports character formatting for backticks and underscores in log messages.
packages/insomnia-inso/src/reporters · high confidence
New Git Repository Settings modal for project configuration
A new Git Repository Settings modal has been introduced to allow users to view and manage the configuration of a connected Git repository. This interface displays the associated Git provider and connection details, the selected author email for commits, and the local folder path where the repository is stored, including a 'Reveal' button to open the directory in the file system. Users can also disconnect the Git repository directly from this modal.
packages/insomnia/src/ui/components/modals/git-repository-settings-modal · high confidence
New Import Modal with Bulk Project and cURL Support
The Import modal has been replaced with a new implementation that supports importing entire projects by selecting a root folder containing multiple sub-projects, in addition to the existing single-file import. It now explicitly supports cURL scripts (alongside Insomnia, Postman, Swagger, OpenAPI, HAR, and WSDL) and provides a drag-and-drop interface for files and directories. The modal also includes a security disclaimer warning users to only import files from trusted sources due to potential automatic code execution.
packages/insomnia/src/ui/components/modals/import-modal · high confidence
New LLM provider settings components with model selection and parameter controls
The AI Settings UI now includes dedicated configuration panels for OpenAI, Anthropic (Claude), Google Gemini, local GGUF models, and custom URL-based endpoints. Users can enter API tokens to dynamically load available models from the provider's API (or local directory for GGUF), select a specific model, and activate it. The OpenAI, Claude, and Gemini panels allow toggling the active provider and deactivating it, while the GGUF and URL panels expose advanced generation parameters (such as temperature, top\_p, and max\_tokens) with validation schemas to fine-tune model behavior.
packages/insomnia/src/ui/components/settings/llms · high confidence
New UI components and editor modes for Insomnia
The application introduces a suite of new UI components and editor modes to enhance the user experience. A new AppLoadingIndicator provides visual feedback during startup. The Command Palette has been implemented to allow quick searching and navigation between requests and workspaces. The Environment Picker has been redesigned to simplify selecting and managing project and global environments. New components include Avatar and AvatarGroup for user representation, a CollectionTab for switching between API specs and tests, a DiffViewEditor for comparing document changes, an EditableInput for inline text editing, and an EncodingPicker for file encoding selection. Additionally, new CodeMirror syntax highlighting modes have been added for Clojure, cURL, Nunjucks (used for templating), and OpenAPI specifications, improving code readability in the editor.
packages/insomnia/src/ui/components · high confidence
New UI forms for AWS, Azure, GCP, and HashiCorp external vaults
The templating tag editor now includes dedicated configuration forms for external secret managers. Users can configure AWS Secrets Manager (with plaintext or key-value secret types), Azure Key Vault (with URL validation for secret identifiers), GCP Secret Manager, and HashiCorp Vault (supporting both on-premises KV v1/v2 engines and HCP Vault Dedicated, including namespace header options). These new forms replace the previous generic JSON input, providing structured fields, help tooltips, and credential editing capabilities directly in the UI.
packages/insomnia/src/ui/components/templating/external-vault · high confidence
New UI hooks for navigation, state, and integrations
This change introduces a suite of new React hooks in the \packages/insomnia/src/ui/hooks\ directory to support the application's new navigation model and feature set. \useInsomniaNavigation\ and \useInsomniaTab\ manage the new URL-based routing and tab state for requests, workspaces, and MCP resources. \useAccountServerData\ centralizes account, user, and plan data fetching with TanStack Query. \useCio\ initializes the Customer.io SDK and ensures events are only tracked for identified users to prevent anonymous profiles. \useKonnectSync\ handles the Konnect synchronization process with progress tracking and analytics. Additional hooks include \useImageCache\ for avatar caching, \useThemes\ for theme management, \useCloseConnection\ for managing WebSocket/SSE/GRPC connections, \useCommandSearch\ for the command palette, and \useGitFileIssues\ for Git sync conflict detection.
packages/insomnia/src/ui/hooks · high confidence
New UI icon assets added to the Insomnia package
The \packages/insomnia/src/ui/components/assets\ directory now includes a comprehensive set of new SVG icon files (such as \icn-arrow-right.svg\, \icn-bitbucket-logo.svg\, \icn-sparkles.svg\, and \icn-gitlab-logo.svg\) and their corresponding React component wrappers (e.g., \IcnArrowRight.tsx\). These assets provide the visual icons required for the application's user interface components.
packages/insomnia/src/ui/components/assets · high confidence
New UI utility functions and tests for sync, formatting, and mock routing
This change introduces a suite of new utility functions and their corresponding tests in the UI layer. It adds \dedupeCollectionItems\ to remove duplicate items from collections while preserving order, and \first-request-treatment\/\first-request-latch\ to manage an A/B experiment for the first-request onboarding experience, including account-aware request counting and server-side threshold latching. It also adds \insomnia-sync\ to handle sync merge conflict modals, \git-folder-trust\ and \git-repo-path\ to manage Git folder trust prompts and path resolution, \method-colors\ to map HTTP methods to theme-aware UI colors, \mock-route\ to enforce unique method+path constraints for mock routes, \grpc\ to provide user-friendly error messages for gRPC connection issues, and \prettify\ (JSON and EDN) to format request bodies. All new functionality is accompanied by comprehensive test coverage.
packages/insomnia/src/ui/utils · high confidence
New WebSocket, Socket.IO, and MCP real-time debugging interface
Insomnia now includes a dedicated real-time debugging experience for WebSocket, Socket.IO, and Model Context Protocol (MCP) connections. This update introduces a new action bar for managing connection states (connect, disconnect, disconnect all), a unified event log view that tracks and displays incoming and outgoing messages for all three protocols, and a detailed event viewer with support for JSON previewing, raw text export, and binary data handling. The interface also features a request pane for configuring connection parameters and a response pane that visualizes real-time streams, including stream summaries for SSE-like patterns and specific handling for MCP notifications and unsupported methods.
packages/insomnia/src/ui/components/websockets · high confidence
New and updated theme definitions for Insomnia
The application now includes a refreshed set of built-in themes, adding new options such as Colorblind Dark, Gruvbox Dark, High Contrast Light, Hyper, and a Designer Light/Dark pair, while also introducing a Legacy theme to preserve previous visual styles. These theme definition files in the plugins/themes directory provide the specific color palettes, background/foreground settings, and UI style overrides (for components like the sidebar, pane headers, and dialogs) that users can select to customize the application's appearance.
packages/insomnia/src/plugins/themes · high confidence
New app-data service for efficient workspace and organization data retrieval
A new \app-data\ service has been introduced in the \insomnia-data\ package to provide optimized, batched retrieval of workspace and organization data. This service includes functions to fetch comprehensive organization data (including projects, linked Git repositories, workspaces, and metadata) and to efficiently walk nested collection structures, aggregating all requests, request groups, and their associated metadata (for REST, gRPC, WebSocket, and SocketIO) in a single pass. This change supports the sidebar cache logic by providing a structured way to load hierarchical workspace children and their states, improving performance for UI components that need to display complex workspace trees.
packages/insomnia-data/node-src/services/app-data · high confidence
New application-level React contexts for state management and data caching
The application now introduces several new React contexts in the \packages/insomnia/src/ui/context/app\ directory to centralize and improve state handling. The \InsomniaTabContext\ manages multi-tab navigation, including adding, closing, and reordering tabs with history support. The \InsomniaEventStreamContext\ handles real-time collaboration presence and server-side event streams (such as file changes and storage rule updates) via Server-Sent Events. The \AppDataCacheProvider\ and \ServerDataCacheProvider\ establish dedicated TanStack Query clients for local database queries and remote server data respectively, ensuring appropriate caching and refetch strategies. Additionally, the \RunnerContext\ manages state for the request runner, and the \SidebarContext\ controls sidebar collapse state.
packages/insomnia/src/ui/context/app · high confidence
New base UI component library
Insomnia introduces a new set of base UI components in the \packages/insomnia/src/ui/components/base\ directory, providing a consistent foundation for the application's interface. This release adds a Badge for status labeling, a Checkbox and CheckboxGroup for selections, a CopyButton for clipboard operations, a DatePicker for date input, a FileInputButton for file selection, an IndeterminateCheckbox for tree-like states, an InputNumber for numeric entry, a versatile Input with password visibility toggling and prefix support, a Link that opens URLs in the browser, a MiddleTruncate for file paths, and a full Modal system (Modal, ModalHeader, ModalBody, ModalFooter) for dialogs. Additionally, a PromptButton is added for confirmation workflows, a Select for dropdown choices, and a Switch for toggles, all leveraging React Aria Components and Tailwind CSS for styling.
packages/insomnia/src/ui/components/base · high confidence
New client-side route handlers for authentication, AI, and credential management
The application now uses a new set of client-side route handlers in the \src/routes\ directory to manage core user workflows. This includes a complete authentication flow (login, logout, vault key management, and OAuth authorization), AI integration endpoints for generating commit messages and MCP sampling responses, and dedicated routes for managing Git and cloud credentials (create, update, delete, and sign-in). These changes replace previous patterns by moving these logic paths into explicit React Router client loaders and actions, improving the separation of concerns for user-facing interactions.
packages/insomnia/src/routes · high confidence
New cloud credential forms for AWS, GCP, and HashiCorp
The Cloud Credential Modal now includes dedicated UI forms for configuring credentials for AWS, GCP, and HashiCorp providers. Users can now create and edit AWS credentials (supporting temporary, file-based, and SSO types), GCP service account key files, and HashiCorp Vault credentials (including On-Premises, Vault Dedicated, and Vault Secrets with AppRole or Token auth methods). This replaces the previous generic input approach with provider-specific validation and file-picking capabilities.
packages/insomnia/src/ui/components/modals/cloud-credential-modal · high confidence
New command search and request helper utilities in insomnia-data
The \insomnia-data\ package now includes a new \command-search\ helper that provides fuzzy matching for requests, files, and environments, partitioning results by current workspace or project and supporting cancellation via AbortController to prevent UI freezes. Additionally, new helper modules (\request-operations\, \response-operations\, \query-all-workspace-urls\) have been added to standardize operations across request types (HTTP, gRPC, WebSocket, SocketIO, MCP), including logic to find requests by parent ID, retrieve specific request types by ID, remove responses (including associated file paths), and query unique workspace URLs while excluding the currently selected request.
packages/insomnia-data/node-src/services/helpers · high confidence
New curl-based HTTP engine and comprehensive test coverage
Insomnia introduces a new curl-based HTTP engine (curl.ts) to handle request execution, replacing the previous implementation. This new engine supports authentication headers, request bodies, and connection registry management, while also enforcing URL validation to disallow local file URIs. The change is accompanied by the addition of a new get-auth-header.ts module to centralize authentication logic for various auth types (Basic, Bearer, OAuth1/2, API Key, Hawk, ASAP). To ensure reliability, new test files (curl.test.ts, libcurl-promise.test.ts) have been added to verify the new curl connection behavior, proxy configuration, and event log parsing, including regression tests for SSE/EventStream handling.
packages/insomnia/src/main/network · high confidence
New database adapters for importing Insomnia data via YAML/JSON exports and Git repositories
The inso CLI now supports importing data from Insomnia v4 and v5 YAML/JSON export files and from local Git repository directories containing \.insomnia\ folders. The new \insomnia-adapter\ parses these export files, handling type name conversions (e.g., \api\_spec\ to \ApiSpec\) and validating export formats, while the \git-adapter\ reads model files from directory structures, respecting sync permissions to exclude non-syncable types like Settings. Both adapters support filtering by model type and are accompanied by comprehensive tests using Vitest.
packages/insomnia-inso/src/db/adapters · high confidence
New mock server response pane and URL bar components
The mock server interface now uses dedicated UI components for managing requests and viewing results. The new MockUrlBar component provides controls to send mock requests, copy the full mock URL, and schedule requests with delays or intervals. The new MockResponsePane component displays the response details in a tabbed interface, allowing users to view the response body with different preview modes, inspect headers, and monitor the request timeline and history.
packages/insomnia/src/ui/components/mocks · high confidence
New native Git credential provider and provider registry
Insomnia now includes a new 'System Git Credentials' provider that delegates authentication to the operating system's native git credential manager (e.g., macOS Keychain, Windows Credential Manager) via \git credential fill\, rather than storing tokens in the app. This is part of a broader provider registry that also introduces dedicated implementations for GitHub (with OAuth and repository fetching), GitLab (with OAuth, refresh tokens, and PKCE), and a generic 'Access Token' provider for custom servers. The registry centralizes provider initialization and URL detection, while the new provider logic ensures that reauthorizing an account updates the specific existing credential instead of overwriting others.
packages/insomnia/src/sync/git/providers · high confidence
New plugin context API for app, data, network, request, response, and store operations
The plugin system now exposes a structured context object that plugins can use to interact with the application. This includes app-level utilities like alerts, dialogs, prompts, and clipboard access; data operations for importing and exporting workspaces (including HAR exports with private environment support); network capabilities to send HTTP requests and retrieve responses; request manipulation methods to modify headers, parameters, and cookies; response inspection to read status codes, headers, and bodies; and a persistent key-value store for plugin-specific data. This context provides a consistent interface for plugins to perform common tasks without directly accessing internal application state.
packages/insomnia/src/plugins/context · high confidence
New project navigation sidebar with Konnect sync and search
The sidebar now features a dedicated project navigation interface that includes a search field for filtering projects, a button to create new projects, and a sync bar for managing Konnect gateway integrations. This update introduces visual indicators for different Konnect deployment types (such as self-managed, serverless, and Kubernetes) and provides onboarding flows to guide users through their first sync and environment configuration.
packages/insomnia/src/ui/components/sidebar · high confidence
New proto file list component with selection and management actions
A new ProtoFileList component has been introduced in the proto-file UI area to display a hierarchical view of proto files and directories. This component allows users to select individual proto files via checkboxes, re-upload existing files, delete specific files, and delete entire directories. It handles the recursive rendering of nested directory structures and provides visual feedback for the currently selected file, integrating with the insomnia-data model types for file and directory entities.
packages/insomnia/src/ui/components/proto-file · high confidence
New request and response pane components with improved empty states and test coverage
The \packages/insomnia/src/ui/components/panes\ directory has been restructured with new components to handle request and response panes, including \RequestPane\, \GrpcRequestPane\, \GrpcResponsePane\, and \RequestGroupPane\. These components introduce visual indicators (colored dots and counts) on tabs for Auth, Headers, Scripts, and Body to show when they contain data. Empty states have been improved with dedicated views like \NoProjectView\ (which handles Konnect sync states) and \NoSelectedProjectView\. The response pane now supports downloading large responses from disk and correctly handles JSON prettification versus raw binary exports. Additionally, new unit tests have been added for the request test result filtering logic and response pane download utilities.
packages/insomnia/src/ui/components/panes · high confidence
New response viewers for passwords, cookies, CSV, errors, headers, multipart, PDF, and timeline
The response viewer panel now includes dedicated components for displaying passwords (with toggleable visibility and masking), response cookies (with a 'Manage Cookies' button and notices for disabled auto-storing), CSV data (with a 'Select All' keyboard shortcut), and error details (with context-aware buttons for SSL validation or proxy setup). Headers are now displayed in a table with clickable links and a 'Copy All' button. Multipart responses can be browsed part-by-part, with headers viewable and individual parts savable as files. PDFs are rendered in an iframe, and the request timeline is shown in a read-only code editor. The main response viewer also handles large responses by blocking display until confirmed, detects content types from body content, and unescapes forward slashes in JSON previews.
packages/insomnia/src/ui/components/viewers · high confidence
New sandbox demo plugin for testing template tag capabilities
Added the \insomnia-plugin-sandbox-demo\ example plugin, which serves as a manual test fixture for the new QuickJS template-tag sandbox. It includes template tags that verify execution context (sandbox vs. main-process), exercise the async host bridge, demonstrate manifest-gated module resolution (including vetted libraries like \uuid\ and \events\), showcase ambient sandbox globals (Buffer, URL, process, crypto), test capability-gated features (storage), and validate multi-file plugin support via sibling module requires.
examples · high confidence
New shared analytics package with centralized event definitions
The \insomnia-analytics\ package has been introduced as a shared library to consolidate analytics logic. It provides the \InsomniaAnalytics\ class, which wraps the Segment SDK to automatically attach app context (name, version, OS) and platform tags to all tracked events, while handling errors via a configurable callback. The package also exports a comprehensive \AnalyticsEvent\ enum covering UI interactions, request lifecycle events, and new experiment-tracking capabilities, alongside an \InsoEvent\ enum for CLI-specific actions. This centralizes event naming and tracking behavior across the application.
packages/insomnia-analytics · high confidence
New shared utility library for Insomnia's data layer
The \packages/insomnia-data/common-src\ package introduces a new shared library of utilities used across the application. This includes a comprehensive hotkey registry with default bindings for UI actions, a fuzzy search implementation for command palette and filtering, and helpers for deterministic JSON stringification, NDJSON serialization, and query string parsing. It also provides platform detection, string localization definitions, and settings type definitions covering proxy scopes, HTTP versions, and plugin sandbox configurations.
packages/insomnia-data/common-src · high confidence
New test suite generation logic with fixture-based validation
The \packages/insomnia-testing/src/generate\ module now includes a new implementation for generating test suites, featuring a \generate\ function that converts JSON test suite definitions into JavaScript code using Chai assertions and Mocha-style \describe\/\it\ blocks. This change introduces a robust fixture-driven testing approach, where input JSON files (e.g., \01\_empty.input.json\, \03\_basic-suite.input.json\) are matched against expected JavaScript output files (e.g., \01\_empty.output.js\) to verify correct generation behavior, including handling of nested suites, empty tests, and active request management via \insomnia.clearActiveRequest()\. The implementation also includes utility functions for string escaping and indentation, validated by dedicated unit tests.
packages/insomnia-testing/src/generate · high confidence
New version-control package with local VCS engine and encrypted sync support
The \insomnia-vcs\ package introduces a local version-control system for Insomnia workspaces, enabling branch management, commit snapshots, and three-way merging with conflict resolution. It features a pluggable storage layer (file-system or in-memory) with automatic compression and atomic writes, and supports encrypted data synchronization via AES-GCM and RSA-OAEP-256. The package exposes a \VCS\ class for workspace-scoped operations, backend project management for linking local documents to remote projects, and GraphQL-based session handling for cloud sync.
packages/insomnia-vcs · high confidence
Redesigned settings interface with new reusable components and AI capabilities
The settings UI has been rebuilt using new, reusable form components (BooleanSetting, EnumSetting, NumberSetting, TextSetting, MaskedSetting) to provide a consistent experience across all preference panels. This update introduces a dedicated AI Settings panel for configuring LLM backends (Claude, Gemini, OpenAI, GGUF, custom URL) and toggling features like auto-generated mock servers, smart commits, and MCP response sampling. It also adds a new Cloud Service Credential management interface for enterprise users to configure AWS, GCP, HashiCorp, and Azure integrations, and refreshes the Git Credentials view with a modern OAuth flow and per-repo email selection.
packages/insomnia/src/ui/components/settings · high confidence
Smoke-test server now supports gRPC, WebSocket, Socket.IO, and OAuth flows
The smoke-test server has been expanded to include dedicated handlers for gRPC (Route Guide service), WebSocket (echo, binary, and cookie support), Socket.IO (custom handshake path), and OAuth/OIDC (authorization code, PKCE, implicit, client credentials, and resource owner flows). It also now serves mock endpoints for GitHub and GitLab authentication, basic authentication, mutual TLS (mTLS), cloud sync, and GraphQL, providing a comprehensive local environment for testing these protocols and integrations.
packages/insomnia-smoke-test/server · high confidence
Socket.IO request editing UI
The Socket.IO request pane now includes dedicated tabs for configuring the request body and event listeners. Users can add, edit, and delete multiple arguments in the Body tab, choosing between JSON and plaintext content types, and toggle acknowledgment (ack) for messages. The Events tab allows users to define unique event names, add descriptions, and enable or disable listeners, with validation to prevent duplicate event names. These components provide a structured interface for managing Socket.IO request parameters and event handling within the Insomnia UI.
packages/insomnia/src/ui/components/socket-io · high confidence
Removals
Removal of Font Awesome 4.0.3 assets
The Font Awesome 4.0.3 icon library files (CSS and SVG font) have been removed from the application's static assets. This change eliminates the legacy icon set from the build, which may affect any UI components that previously relied on these specific icon classes.
app/css/lib · high confidence
Removal of legacy Redux-based Todo application scaffold
The legacy Redux-based Todo application scaffold has been removed from the app directory. This change deletes the entry point (app/index.js), the store configuration (app/stores/configureStore.js) which previously set up Redux with thunk and logger middleware, and the action creators (app/actions/index.js) that handled local storage persistence for todo items. Users will no longer have access to this specific demo implementation within the application structure.
app · high confidence
Removal of legacy request reducer and root reducer configuration
The application has removed the legacy Redux reducer structure, specifically deleting the \app/reducers/index.js\ file that combined the root state and the \app/reducers/requests.js\ file that handled request state management. This change eliminates the previous implementation where adding a request simply appended a placeholder object with static properties (\foo: 'bar'\) to the state array, indicating a significant restructuring or removal of this specific data handling logic within the reducers directory.
app/reducers · high confidence
Removed legacy App container and Header component scaffolding
The legacy \app/containers/App.js\ container and \app/components/Header.js\ component have been removed from the application. This deletion eliminates the previous static sidebar layout, hardcoded request/response pane structure, and the associated \Header\ component, along with the now-unused \app/constants/actionTypes.js\ file. This change cleans up the codebase by removing obsolete UI scaffolding that is no longer part of the current application architecture.
app/containers · high confidence
Security
Renderer process security hardening and architecture migration
The renderer process has been migrated to a secure, isolated architecture that removes Node.js integration and enforces context isolation. This change introduces a strict IPC boundary where the renderer no longer accesses the database or services directly; instead, it communicates via a new \database.client.ts\ bridge and a \services-proxy\ that forwards calls to the main process. Authentication and session handling have been moved to the renderer with a new \auth-session-provider.client.ts\ that manages keypairs and login flows locally. Additionally, the renderer now hosts the global modal registry (\modals.tsx\), manages its own event bus for UI state, and initializes Sentry tracing, ensuring that sensitive operations and UI logic are decoupled from the main process while maintaining security.
packages/insomnia/src/ui · high confidence
Secure specification export and linting with SSRF protection
The Inso CLI now includes a new \export-specification\ command that supports a \skipAnnotations\ option to optionally strip \x-kong-\ vendor extensions from OpenAPI specs. Additionally, the \lint-specification\ command has been updated to enforce strict security controls when resolving remote references, blocking non-HTTPS URLs and resolving hostnames to ensure they do not point to private, loopback, or link-local addresses, thereby preventing Server-Side Request Forgery (SSRF) attacks during linting.
packages/insomnia-inso/src/commands · high confidence
Updated macOS code-signing entitlements for stricter security
The macOS build now enforces stricter code-signing policies by disabling the use of DYLD environment variables and library validation. This change improves the security posture of the application on macOS by preventing potential exploitation of dynamic linker behaviors and unsigned library injection.
packages/insomnia/src/static · high confidence
Windows secure wrapper mitigates DLL hijacking and fixes Squirrel update issues
A new C++ secure wrapper for the Windows installer mitigates a local search path vulnerability by enforcing Windows Process Mitigation Policies (signature and image load policies) to prevent loading hijacked DLLs from writable installation directories. This wrapper also resolves a bug where Squirrel-based updates failed to start the new version correctly and handles UTF-16 characters in installation paths, ensuring a stable and secure upgrade experience for Windows users.
packages/insomnia/src/cpp · high confidence
Architecture
Application initialization and security architecture overhaul
The application's startup sequence and security model have been significantly restructured. The main process now initializes the database, services, and runtime before creating any windows, ensuring a consistent state. A new hidden browser window is introduced to execute pre-request and post-response scripts in an isolated environment, improving stability and security. The renderer process now uses a dedicated preload script to expose a secure IPC bridge for services like sync, git, and MCP, replacing direct access to Electron APIs. Additionally, the entry point now handles deep-link imports and Konnect project migrations before the React app hydrates, and session data is migrated from localStorage to the new service layer.
packages/insomnia/src · high confidence
Centralized data access via new service layer
The application now routes all database operations through a dedicated service layer in \packages/insomnia-data/node-src/services\. This change introduces standardized CRUD APIs for core data models—including requests, environments, workspaces, and certificates—alongside specialized logic for features like request versioning, OAuth2 token management, and team project synchronization. A new \CONVENTIONS.md\ file establishes naming standards for these services, and the \index.ts\ file exposes the complete service registry to the renderer process via IPC, ensuring consistent and type-safe data access across the application.
packages/insomnia-data/node-src/services · high confidence
Data model and database layer restructured into the insomnia-data package
The data models and database access layer have been extracted into the new \insomnia-data\ package, introducing a unified \BaseModel\ schema and a dependency-injection pattern for the database (allowing different implementations for the main and renderer processes). This change adds support for new data types including MCP requests and responses, Git credentials with native provider support, and project lint rulesets, while also introducing a new 'Control Planes' organization structure for Konnect projects.
packages/insomnia-data/src/models · high confidence
Extracted insomnia-data into a standalone workspace package
The data layer for Insomnia has been extracted into a new \insomnia-data\ workspace package, providing a runtime-agnostic interface for database and service operations. This change introduces a structured layout with \src/\ for runtime-agnostic contracts and \node-src/\ for Node-specific implementations (such as NeDB), allowing the main, renderer, and Inso processes to share a consistent API while decoupling business logic from Electron and IPC details. The package includes configuration for TypeScript and Vitest testing, establishing the foundation for injecting different database implementations at startup.
packages/insomnia-data, packages/insomnia-data/node-src, packages/insomnia-data/src · high confidence
Behavioural changes
4 commits (2 fixes) modifying packages/insomnia/src/icons
A change to existing behaviour in packages/insomnia/src/icons — 4 commits (2 fixs), 5 files.
packages/insomnia/bin, packages/insomnia/src/icons · medium confidence · unverified
Add TypeScript type definitions for external libraries and global environment
This update introduces a new set of TypeScript declaration files in the \packages/insomnia/types\ directory to resolve type-checking issues with third-party dependencies and the application's runtime environment. The changes include definitions for \apiconnect-wsdl\, \codemirror-graphql\, \codemirror\, \httpsnippet\, \jsonlint-mod-fixed\, \objectpath\, and \tough-cookie\, ensuring type safety for these external modules. Additionally, \global.d.ts\ and \vite.d.ts\ define the global \Window\ interface (exposing Electron bridges, environment variables, and services) and Vite-specific constants, providing the necessary type context for the renderer process.
packages/insomnia/types · high confidence
Apply patches to npm dependencies to fix bugs and improve compatibility
This change introduces patch files to modify the behavior of three npm dependencies. The apiconnect-wsdl patch removes artificial limits on example generation size and nesting depth to prevent truncation of large schemas. The json-order patch fixes a bug where null values were incorrectly treated as objects during parsing. The tinykeys patch adds TypeScript type definitions to the package exports to improve type safety for consumers.
patches · high confidence
Auth editors migrated to new component structure with MCP OAuth support
The authentication editor UI in the Insomnia app has been restructured into a new modular component system located in \packages/insomnia/src/ui/components/editors/auth\. This change introduces dedicated React components for each authentication type (Basic, Bearer, OAuth 1/2, API Key, AWS, Hawk, Digest, NTLM, Netrc, ASAP, and Single Token), all orchestrated by a new \AuthWrapper\ that handles type selection and rendering. A key behavioral addition is support for the MCP (Model Context Protocol) OAuth flow, which adds a new 'MCP Auth Flow' grant type option to the OAuth 2 editor and includes specific UI controls for state, scope, and manual browser launch configuration. The migration also standardizes input handling across all auth types using shared sub-components like \AuthInputRow\ and \AuthTableBody\, ensuring consistent masking of sensitive fields (passwords, secrets, tokens) and uniform toggle behavior.
packages/insomnia/src/ui/components/editors/auth · high confidence
Automatic data migration for legacy Insomnia workspaces
Insomnia now automatically migrates legacy data structures when opening workspaces, ensuring compatibility with the current data model. This process extracts embedded client certificates into their own records, normalizes workspace scopes (mapping old 'spec' and 'designer' values to 'design'), and fixes request bodies and authentication types. Additionally, it assigns missing IDs to cookies, sets a default 'manual' source for legacy cookies, and resolves hotkey conflicts between creating requests and opening the sidebar dropdown. Users with older data will see their workspaces updated seamlessly without manual intervention.
packages/insomnia-data/node-src/database/init-model · high confidence
Basic authentication header generation now supports Latin-1 encoding
The basic-auth module now allows users to specify 'latin1' as an encoding option when generating the Authorization header, in addition to the existing UTF-8 support. This change ensures that credentials containing non-UTF-8 characters are correctly encoded according to the specified character set, improving compatibility with servers that expect Latin-1 encoded Basic Auth headers.
packages/insomnia/src/network/basic-auth · high confidence
Bearer authentication header generation trims whitespace from tokens and prefixes
The Bearer authentication logic in the network layer now automatically trims leading and trailing whitespace from both the authentication token and the optional prefix before constructing the Authorization header. This ensures that headers like 'Authorization: Bearer my-token ' are normalized to 'Authorization: Bearer my-token', preventing authentication failures caused by accidental extra spaces in user input.
packages/insomnia/src/network/bearer-auth · high confidence
CSS architecture overhaul with Tailwind v4 and layered imports
The application's styling system has been restructured to use Tailwind CSS v4, introducing a new \styles.css\ entry point that leverages CSS cascade layers to manage import precedence for libraries like CodeMirror, Monaco Editor, and Font Awesome. This change replaces the previous \main.css\ reset and boilerplate with Tailwind's native reset and integrates custom theme animations and grid layouts directly into the new configuration, ensuring consistent styling across the UI components.
packages/insomnia/src/ui/css · high confidence
Centralize IPC handlers in the main process
The application now routes critical operations—including gRPC requests, cookie management, file system access, secret storage, and Git synchronization—through dedicated IPC handlers in the main process. This shift ensures that sensitive tasks like reading files, managing OAuth tokens, and handling gRPC reflection are executed in the secure main context rather than the renderer, improving security and enforcing stricter execution-context boundaries.
packages/insomnia/src/main/ipc · high confidence
Centralized application lifecycle hooks
The application now uses a dedicated \AppHooks\ component to manage global side effects at startup. This component consolidates logic for settings synchronization, global keyboard shortcuts, theme changes, and Customer.io integration into a single location, ensuring these features are initialized consistently when the app loads.
packages/insomnia/src/ui/containers · high confidence
Circular dependency checks now use dependency-cruiser with Windows support and baseline drift detection
The project has replaced the previous circular-reference checking tool with dependency-cruiser, introducing a new script in scripts/circular-references that scans npm workspaces for circular imports. This change adds Windows compatibility by bypassing the dependency-cruiser binary shim to avoid shell-execution issues, and introduces a baseline file (known-violations.json) that distinguishes between new circular dependencies (regressions) and removed ones (drift), allowing CI to report the specific nature of any failure.
scripts · high confidence
Cloud sync now uses one VCS instance per workspace
The cloud sync system has been restructured to maintain a separate Version Control System (VCS) instance for each workspace, replacing the previous singleton approach. This change, implemented in the main process cloud-sync module, ensures that sync operations for one workspace do not interfere with others, particularly when handling concurrent backend project pulls or local modifications. The new architecture introduces dedicated initialization logic to set up backend projects and mark them for sync, an IPC bridge to route workspace-specific VCS commands (like checkout, pull, push, and conflict resolution) to the correct instance, and a dedicated handler for pulling remote backend projects that correctly updates local database records and workspace parent IDs.
packages/insomnia/src/main/cloud-sync · high confidence
Deferred service initialization with pre-init destructuring support
The services module now supports deferred initialization, allowing application code to destructure service methods before the underlying implementation is ready. A new \initServices()\ function registers the implementation, and a Proxy-based \services\ object ensures that any method calls made prior to initialization throw a clear error, while calls made after initialization are correctly routed to the registered implementation. This change also introduces strongly-typed interfaces for workspace children (e.g., \CollectionWorkspaceChildren\, \DesignWorkspaceChildren\) that map specific workspace scopes to their respective data structures, improving type safety for workspace data access.
packages/insomnia-data/src/services · high confidence
Dropdown component rewritten using React Aria
The base dropdown component in the UI library has been completely rewritten as a set of React function components leveraging the React Aria and React Stately libraries. This change replaces the previous implementation with a new architecture that uses React Aria's hooks (such as useMenuTrigger, useMenu, and usePopover) to handle accessibility, keyboard navigation, and state management. The new structure includes dedicated components for the dropdown trigger, menu, menu items, sections, and popovers, along with a new DropdownHint component to display keyboard shortcuts. This refactor improves accessibility compliance and interaction consistency for all dropdown menus within the application.
packages/insomnia/src/ui/components/base/dropdown · high confidence
Dropdowns migrated to React Aria and modernized
The dropdown components in the sidebar and request editor have been rewritten as function components using React Aria (react-aria-components), replacing the previous implementation. This migration introduces a consistent, accessible UI for authentication, content type, HTTP method, and preview mode selection, while also adding new dropdowns for Git project synchronization and MCP client actions.
packages/insomnia/src/ui/components/dropdowns · high confidence
Editor undo history now persists across tab switches and remounts
The CodeMirror-based editors in Insomnia now retain their undo/redo history when you switch between tabs or when the editor component remounts (for example, toggling between markdown write and preview modes). This is achieved by caching the editor state using a stable \historyKey\ and purging that cache only when the owning tab closes or a key-value row is deleted, preventing stale entries from crowding out live editors. A unified app-level undo handler ensures that keyboard shortcuts and the Edit menu correctly drive either the CodeMirror history or the native browser stack depending on which element is focused, resolving previous conflicts where native undo commands would interfere with CodeMirror's internal state.
packages/insomnia/src/ui/components/.client/codemirror · high confidence
Enhanced CodeMirror editor extensions for autocomplete, clickable links, and Nunjucks tags
The CodeMirror editor now includes new extension modules that improve the editing experience: environment autocomplete is now triggered by configurable hotkeys and context (variables, constants, snippets, and tags) with a custom hint container; URLs in the editor content are automatically detected and made clickable for direct interaction; and Nunjucks template tags are highlighted with live rendering previews, support drag-and-drop, and open a modal for editing when clicked.
packages/insomnia/src/ui/components/.client/codemirror/extensions · high confidence
Enhanced code linting for JavaScript and JSON editors
The code editor now provides improved validation for JavaScript and JSON content. JavaScript linting has been updated to support top-level await expressions by wrapping code in an async function during analysis, ensuring accurate error reporting for modern syntax. JSON linting now pre-renders Liquid templates before parsing, allowing the linter to validate the final rendered values rather than the raw template syntax, which reduces false positives when using dynamic content.
packages/insomnia/src/ui/components/.client/codemirror/lint · high confidence
Git sync now stores Insomnia data as YAML files on disk alongside the .git directory
Git-synced projects now use a new on-disk layout where Insomnia workspace data is persisted as YAML files inside an \.insomnia\ directory, rather than being stored exclusively in the local NeDB database. This change introduces a bidirectional sync pipeline: the \RepoFileWatcher\ keeps the on-disk YAML files and the NeDB database in sync, allowing external tools and native Git CLI commands to interact directly with the repository's files. Existing repositories are automatically migrated to this new structure via a versioned migration process that moves data from the old \git/\ and \other/\ directories to the new layout. The sync engine also now uses a custom HTTP client to respect system proxy and certificate settings, and routes file operations through specialized clients to handle the new directory structure correctly.
packages/insomnia/src/sync/git · high confidence
Improved Git authentication status and re-authentication flow
The Git connection UI now proactively detects and displays warnings when OAuth access tokens have expired or when repository operations fail with HTTP 401/403 errors. A new banner component allows users to re-authenticate directly from the interface, supporting both automatic redirects and manual pasting of authentication codes. Additionally, a new connection info panel displays the current base branch, and a warning banner guides users when a branch tracks a non-origin remote, providing copyable CLI commands to fix the upstream configuration.
packages/insomnia/src/ui/components/git · high confidence
Improved cURL detection and environment key validation
The application now more accurately detects cURL commands in the input UI, correctly handling shell prompts, case variations, and preventing false positives on URLs like curl.se. Additionally, environment variable keys are now strictly validated to prevent NeDB storage errors by rejecting keys that begin with '$' or contain periods, while also enforcing reserved key restrictions for templating and vault paths.
packages/insomnia/src/common/utils · high confidence
Improved cURL import accuracy and expanded OpenAPI 3 schema support
The cURL importer now correctly handles complex data flags (such as -d, --data, --data-binary, and --data-urlencode) including raw text bodies with multiple equals signs, file references, and URL-encoded characters, while also fixing issues with missing equals signs and Bearer authorization headers. Additionally, the OpenAPI 3 importer now supports schema composition keywords (allOf, oneOf, anyOf) for example request generation and correctly flattens nested object-type query parameters into bracket notation.
packages/insomnia/src/main/importers/importers · high confidence
Improved tab navigation and deletion fallback behavior
The tab interface now supports closing tabs with a middle-mouse click and includes keyboard shortcuts to navigate between and reopen closed tabs. Additionally, when a request tab is deleted, the application intelligently navigates to the request's parent folder or collection root instead of bouncing back to the project dashboard, ensuring a smoother workflow when managing open tabs.
packages/insomnia/src/ui/components/tabs · high confidence
Inso CLI build and test infrastructure modernization
The Inso CLI package has been restructured to use esbuild for bundling, replacing the previous build system, and has migrated its test runner from Jest to Vitest. This change introduces a new \esbuild.ts\ configuration that targets Node 22 and handles platform-specific module resolution, alongside updated \tsconfig.json\ and \vitest.config.ts\ files to support the new tooling. Additionally, a Dockerfile has been added to facilitate CI-based packaging of the CLI binary, and the \.gitignore\ has been updated to manage the new \artifacts\ directory structure.
packages/insomnia-inso · high confidence
Insomnia app package restructured with new build and test tooling
The \packages/insomnia\ directory has been reorganized to support a modernized build and development workflow. A new \esbuild.entrypoints.ts\ script now handles the bundling of Electron main, preload, and hidden window processes, while \vite.config.ts\ and \react-router.config.ts\ configure the renderer and routing. Build artifacts are now managed via a new \.gitignore\ and \electron-builder.config.js\ for packaging. Additionally, testing infrastructure has been updated with new \vitest\ configurations (\vitest.config.ts\, \vitest.sandbox-vendored-regression.config.ts\) and a \setup-vitest.ts\ file to initialize the database and services for tests.
packages/insomnia · high confidence
Introduce Mocha-based test runner with request interception
The \packages/insomnia-testing/src/run\ directory now implements a new test execution engine using Mocha instead of the previous runner. This change introduces an \Insomnia\ global helper that allows tests to send HTTP requests via a provided \sendRequest\ callback, enabling integration testing of API calls. A custom \JavaScriptReporter\ is included to capture test results as structured data rather than printing to stdout, and a \require\ interceptor is injected to safely resolve modules like \chai\ and \chai-json-schema\ within the test sandbox. The \runTests\ function now returns structured pass/fail statistics, and the \runTestsCli\ function provides a boolean success indicator.
packages/insomnia-testing/src/run · high confidence
Introduce inso-specific database model layer with enhanced identifier matching
The inso CLI now uses a dedicated database model layer in \packages/insomnia-inso/src/db/models\ to load and prompt for resources like workspaces, API specs, environments, and unit test suites. This implementation adds support for matching resources by their \name\ or \fileName\ in addition to the existing ID-based matching, allowing users to select items using more human-readable identifiers. It also introduces improved environment selection logic that distinguishes between base and sub-environments, providing clearer error messages in CI mode when multiple environments are present, and adds a unified prompt for selecting documents or test suites.
packages/insomnia-inso/src/db/models · high confidence
Introduces a unified runtime adapter layer for cross-process capability execution
The application now routes core capabilities—network requests, templating, secret storage, crypto operations, and imports—through a new adapter layer in \src/runtimes\ that distinguishes between Node (main process/CLI) and Renderer (UI) execution contexts. This change enables user-installed plugins to execute their request and response hooks inside an isolated QuickJS sandbox by default, with elevated plugins and the CLI running hooks in-process as before. It also adds support for user prompts in the main process and ensures that plugin hook mutations are safely merged without exposing internal object identities to sandboxed code.
packages/insomnia/src/runtimes · high confidence
Invite modal restructured with encryption logic and role-based access control
The invite modal has been refactored to support inviting team members from both Organizations and Electron contexts, introducing a new encryption module that handles RSA-based key re-encryption for secure project key sharing. The UI now includes a role selector that enforces Role-Based Access Control (RBAC), restricting role changes to users with appropriate permissions or upgraded plans, and integrates seat-checking logic to manage invitation limits based on the user's subscription tier.
packages/insomnia/src/ui/components/modals/invite-modal · high confidence
Key-Value Editor reimplementation with drag-and-drop and improved persistence
The Key-Value Editor component has been rewritten to use React Aria components, introducing native drag-and-drop reordering for key-value pairs and a more robust persistence model. The trailing blank row is now purely visual and is not persisted to the data model until the user begins typing, preventing empty rows from appearing in diffs. Additionally, the editor now ensures unique IDs for rows to avoid stale state issues and supports read-only pairs with disabled states, improving usability for headers and environment variables.
packages/insomnia/src/ui/components/key-value-editor · high confidence
Migrate common utilities to insomnia-data and introduce API spec parsing
The \packages/insomnia/src/common\ module has been refactored to rely on the new \insomnia-data\ package for core data models and database operations, replacing the previous NeDB-based implementation. A new \api-specs.ts\ utility has been added to parse, detect, and convert OpenAPI/Swagger specifications between JSON and YAML formats, and the import logic has been updated to use Zod schemas for validating Insomnia v5 export files.
packages/insomnia/src/common · high confidence
Migrate core application state to a new database layer and restructure main process
The application's main process has been reorganized into a new directory structure, introducing a dedicated database layer (insomnia-data) that replaces previous storage mechanisms. This change migrates user settings and session data from LocalStorage to the new database service, introduces a new Electron-based storage implementation for legacy compatibility, and establishes a centralized analytics module that hashes user account IDs for privacy. Additionally, the main process now handles custom protocol registration for internal networking and provides a proxy for database access to plugin windows, ensuring consistent data access across the application.
packages/insomnia/src/main · high confidence
Migrate templating engine from Nunjucks to LiquidJS
The templating engine used for rendering templates in Insomnia has been switched from Nunjucks to LiquidJS. This change updates the core rendering logic in the \templating\ module to use the LiquidJS library, introducing new syntax for variable interpolation (\{{ }}\) and control flow (\{% %}\), while maintaining compatibility with existing template tags and plugin integrations through a new Liquid-based tag extension system.
packages/insomnia/src/templating · high confidence
Migration to Vitest with updated mock implementations
The test infrastructure has been migrated to Vitest, replacing the previous testing setup. This change updates the mock files in the common and gRPC network modules to use Vitest's \vi\ API instead of the previous framework's mocking functions. Specifically, the \render\ mock now uses \vi.requireActual\ and \vi.fn()\ to mock gRPC request rendering functions, while the gRPC module mock exports standard functions like \start\, \sendMessage\, and \commit\ as Vitest mocks. This ensures that tests relying on these mocked behaviors continue to function correctly under the new Vitest runner.
packages/insomnia/src/common/\\mocks\\, packages/insomnia/src/network/grpc/\\mocks\\_ · high confidence_
Modals migrated to functional components and React Aria
The modal dialogs in the application have been refactored from class-based components to functional components and now utilize the React Aria component library. This change standardizes the modal architecture, improving accessibility and aligning the UI implementation with modern React patterns.
packages/insomnia/src/ui/components/modals · high confidence
New Git credentials management interface
The Git credentials workflow has been redesigned with a dedicated setup screen that allows users to authenticate via GitHub or GitLab OAuth, or manually add a custom access token. A new credential selector component displays the provider, display name, and author for each saved credential, and includes a link to manage credentials in Preferences. Repository and branch selection components now support fuzzy matching for easier searching, and the repository picker provides specific guidance and configuration links for GitHub App users.
packages/insomnia/src/ui/components/git-credentials · high confidence
New Playwright-based smoke test infrastructure with robust process management
The smoke test suite has been migrated to Playwright, introducing a new test runner that launches the Insomnia Electron application with configurable environment variables for API mocking, OAuth providers (GitHub, GitLab), and Konnect integration. This change adds a dedicated launch utility that tracks all running Electron instances to ensure graceful cleanup, including a custom process-tree killer to prevent hanging worker processes by terminating child processes on Windows and Unix systems. The test fixtures now support pre-seeding settings and copying fixture databases to isolated temporary data paths, allowing tests to start with specific configurations without relying on app defaults.
packages/insomnia-smoke-test/playwright · high confidence
New UI tags for request methods, status, and timing
The response view now displays dedicated tags for HTTP method, status code, response size, and timing. Method tags use color-coded badges for standard HTTP verbs as well as WebSocket (WS), Socket.IO (IO), gRPC, and MCP, with shortened labels for longer methods. Status tags color-code responses by class (1xx–5xx) and handle unknown messages. Size tags show read vs. content bytes, and time tags break down request timing steps in a tooltip.
packages/insomnia/src/ui/components/tags · high confidence
New build, schema, and sandbox tooling scripts
The \packages/insomnia/scripts\ directory now includes several new build and tooling scripts. \build.ts\ enforces Node 24 for building and copies static assets and hidden/plugin window HTML files. \generate-schema.ts\ produces a versioned JSON Schema for Insomnia v5 files from the Zod source of truth. \nsisInstall.nsh\ adds custom NSIS installer logic for uninstalling previous versions and writing installer metadata. A new sandbox-vendored toolchain (\check-sandbox-vendor-guardrail.ts\, \generate-sandbox-vendored.ts\, \sandbox-vendored-lib.ts\, \sandbox-vendored-libs-list.ts\, \upgrade-sandbox-vendored.ts\) manages vetted npm libraries (uuid, ajv) for the template-tag sandbox, ensuring version pins and guardrails. Finally, \install-x64-native-dependencies.ts\ handles native dependency extraction for macOS x64, and \verify-bundle-plugins.ts\ checks for required bundle plugins in CI.
packages/insomnia/scripts · high confidence
New build, signing, and documentation scripts for Inso CLI
This change introduces several new scripts in the \insomnia-inso\ package to support the release and distribution of the Inso CLI. The \artifacts.ts\ script handles compressing binaries for macOS, Windows, and Linux. A new \macos-pkg.sh\ script automates the code signing and notarization of macOS installers using specific entitlements defined in \codesign.entitlements\ (which allows library validation and unsigned executable memory access for compatibility with \node-libcurl\ and older Node versions). Additionally, \docs.ts\ adds the capability to automatically generate Markdown documentation from the CLI's source code, while \verify-pkg.js\ provides a smoke test to verify the packaged binary functions correctly.
packages/insomnia-inso/src/scripts · high confidence
New editor components for environment, mock, and request configuration
This change introduces a suite of new UI editor components in the \packages/insomnia/src/ui/components/editors\ directory, replacing or refactoring previous implementations. The \EnvironmentEditor\ now uses \orderedJSON\ to preserve property ordering and includes a Windows-specific fix for Nunjucks file-tag backslash escaping. The \MockResponseExtractor\ component allows users to transform active request responses into mock server routes, with logic that restricts cloud mock creation in local projects and handles self-hosted server constraints. New \MockResponseHeadersEditor\ and \RequestHeadersEditor\ components provide both bulk text editing and key-value pair interfaces for headers, with the latter introducing read-only pairs for WebSocket and HTTP requests (e.g., \Connection\, \Upgrade\, \User-Agent\) that can be disabled. The \RequestParametersEditor\ handles query parameters with bulk editing support, and the \RequestScriptEditor\ provides a comprehensive code editor with snippets for variable management, request manipulation, and testing, including support for folder-level environment variables.
packages/insomnia/src/ui/components/editors · high confidence
New environment key-value editor with vault support and improved stability
The environment editor now uses a dedicated key-value component that supports text, JSON, and secret types, with automatic decryption for secrets stored in the vault. The implementation prevents UI flickering and state corruption by ensuring unique IDs for list items and avoiding the reuse of blank-row IDs, while also disabling the persistence of trailing empty rows to keep diffs clean.
packages/insomnia/src/ui/components/editors/environment-key-value-editor · high confidence
New gRPC method dropdown with package grouping
The gRPC method selection interface has been replaced with a new dropdown component that groups available methods by their protobuf package. This component uses react-aria-components to provide an accessible select menu, displaying methods in sections labeled by package name (or 'No package' for ungrouped methods) and showing a short path for each method. It also displays an acronym indicating the method type (unary, server-streaming, client-streaming, or bidirectional) alongside the method name.
packages/insomnia/src/ui/components/dropdowns/grpc-method-dropdown · high confidence
New modular auth editor components
The authentication editor now uses a set of new, reusable UI components (AuthAccordion, AuthInputRow, AuthPrivateKeyRow, AuthSelectRow, AuthToggleRow, etc.) to render authentication settings. These components provide a consistent, table-based layout for editing auth properties, support masking passwords with show/hide toggles, handle private key editing via a modal, and allow toggling auth on/off or selecting options, all while integrating with the request loader data and patchers to update the active request or request group.
packages/insomnia/src/ui/components/editors/auth/components · high confidence
New plugin infrastructure and theme validation
This change introduces new files that establish the core plugin system and enforce stricter theme rules. A new sealed-box encryption utility is added to the main process utils, and a plugin creation helper is exposed to the UI. Crucially, the plugin theme system now validates against Nunjucks template syntax, which was removed in July 2022; themes containing such syntax will now trigger console errors rather than silently failing, and theme names are automatically normalized to lowercase with spaces replaced by hyphens.
packages/insomnia/src/main/utils, packages/insomnia/src/ui/plugins · high confidence
New scripting environment object model and Liquid templating engine
The scripting environment now uses a new set of object models (located in \packages/insomnia-scripting-environment/src/objects\) to represent requests, responses, environments, variables, and other entities, replacing the previous implementation. This change introduces a new templating engine based on LiquidJS for variable interpolation, which affects how placeholders are resolved in scripts. The \Environment\ class now supports automatic conversion of objects to strings when passed to \replaceIn\, and the \InsomniaObject\ now exposes a \baseEnvironment\ for global base environment support. Additionally, the \Console\ class provides a structured logging interface with levels (debug, info, log, warn, error) and the \Execution\ class allows scripts to control request flow via \skipRequest\ and \setNextRequest\.
packages/insomnia-scripting-environment/src/objects · high confidence
New unified body editor components for request bodies
The request body editing interface has been restructured into a new set of dedicated components located in \packages/insomnia/src/ui/components/editors/body\. This change introduces a central \BodyEditor\ that dynamically renders specific editors based on the content type: \RawEditor\ for arbitrary text, \GraphQLEditor\ for GraphQL requests, \FormEditor\ and \UrlEncodedEditor\ for form data, and \FileEditor\ for file uploads. The \GraphQLEditor\ now includes a dedicated \prettify-graphql\ utility for formatting queries, while the form editors utilize a shared \KeyValueEditor\. These components handle body state updates via a \useRequestPatcher\ hook, providing a consistent and modular editing experience for all request body types.
packages/insomnia/src/ui/components/editors/body · high confidence
OAuth2 request logs now appear in the Console timeline
Users can now see the full details of OAuth2 authentication requests (including token exchanges, refresh attempts, and errors) directly in the main Console (Timeline) tab alongside the API request, instead of only seeing them in a hidden debug modal. This change threads OAuth2 timeline entries from the token retrieval process into the main request's timeline, making it easier to debug authentication failures.
packages/insomnia/src/main/network/o-auth-2 · high confidence
Optimized Nunjucks rendering with promise caching in the editor
The Nunjucks template rendering engine used in the editor now utilizes a promise-based caching mechanism to avoid redundant context resolution and race conditions during parallel renders. This change improves performance by reusing previously fetched render contexts for the same cache key within a short window, ensuring faster template evaluation for users writing or previewing Nunjucks templates in requests and workspaces.
packages/insomnia/src/ui/context/nunjucks · high confidence
Plugin sandboxing with per-plugin permission declarations and elevated trust opt-in
Insomnia now supports a plugin sandboxing model that restricts third-party plugins to a default-deny execution environment. This change introduces a new \insomnia.permissions\ manifest field where plugins can explicitly declare the Node.js modules and host capabilities they require. By default, user plugins run in a restricted sandbox; however, users can opt specific plugins into full host access (the 'elevated' escape hatch) via the plugin's configuration or the Preferences → Plugins pane. The system also displays validation warnings for malformed permission declarations and distinguishes between plugins that explicitly declare no permissions versus those with no manifest at all.
packages/insomnia/src/common/plugins · high confidence
Plugin system restructured with sandboxed execution and strict validation
The plugin loading and execution logic in \packages/insomnia/src/plugins\ has been restructured to support a new security model where user-plugin template tags and actions are discovered and executed within a QuickJS sandbox rather than the main Node.js context. This change introduces stricter validation for plugin names to prevent prototype pollution and path traversal attacks, and enforces a trust model where user plugins must opt-in to elevated permissions. The plugin manifest now exposes an export map that is used to build stub modules, with actual execution routed through a dedicated templating worker database protocol. Bundle plugins and those with the sandbox flag disabled continue to run in-process, while user plugins run in the sandbox, improving isolation and security for custom code.
packages/insomnia/src/plugins · high confidence
Plugin template tags now run in an isolated QuickJS sandbox with manifest-gated permissions
When the 'Run template tags in sandbox' preference is enabled, plugin template-tag \run()\ methods execute inside an isolated QuickJS environment rather than the host Node process. This sandbox enforces a default-deny security model where plugins must explicitly declare required permissions in their \package.json\ manifest. Access to modules is restricted to a curated registry of vetted safe equivalents (such as \path\, \crypto\, \events\, \uuid\, and \ajv\), preventing access to raw Node builtins. Host-side capabilities like network access, storage, and file reading are gated behind specific capability grants, ensuring plugins can only perform actions they have been explicitly authorized to perform.
packages/insomnia/src/templating/sandbox · high confidence
Redesigned project creation and settings workflows with Git Sync and organization management
The project creation and settings interfaces have been rebuilt to support a unified workflow for Local, Cloud Sync, and Git Sync projects. Users can now select a project type, manage Git credentials, and clone or adopt Git repositories directly from the project modal, including the ability to choose a custom local folder for Git projects. The organization selector has been enhanced with local filtering and options to join or create organizations based on the user's plan. Additionally, the new flow includes a scan step for Git repositories to detect existing Insomnia files and a migration banner for legacy content, while the empty project view now tracks analytics for user actions.
packages/insomnia/src/ui/components/project · high confidence
Redesigned templating and variable editors with vault integration
The templating and variable editing interfaces in the Insomnia UI have been refactored to support external vaults and improved usability. The new Tag Editor component now dynamically renders specialized configuration forms (such as the ExternalVaultForm) for supported tags, allowing users to manage vault credentials directly within the tag argument interface. The Variable Editor has been updated to provide live preview functionality for environment variables, including specific handling for vault variables that may display masked values, and allows selection of custom template logic alongside standard environment variables.
packages/insomnia/src/ui/components/templating · high confidence
Refactored account session management and credential deletion logic
The account session handling in the renderer process has been reorganized into a dedicated \session.ts\ module, which now centralizes logic for absorbing encryption keys, managing user sessions, and handling logout. A key behavioral change is the robustification of the logout flow: it no longer throws if the API call fails, ensuring users can always sign out even during network issues. Additionally, the credential removal process has been expanded to systematically clear Git provider credentials, custom Git repository associations, LLM provider API keys, and proxy authentication details, ensuring a complete cleanup of sensitive data upon logout.
packages/insomnia/src/ui/account · high confidence
Refactored importers to run in Node with a new conversion pipeline
The import logic in the main process has been refactored to run in Node.js, introducing a new \convert.ts\ pipeline that iterates through available importers and normalizes results. This change adds a new \entities.ts\ schema for import requests and a \utils.ts\ module that applies default values (such as setting the parent ID to \\_\_WORKSPACE\ID\\\ for requests and \\\_BASE\_ENVIRONMENT\ID\\_\ for environments) and validates keys to prevent errors with nested properties. The update also includes tests for these new utility functions.
packages/insomnia/src/main/importers · high confidence
Refactored network request execution into a modular runtime architecture
The network layer in \packages/insomnia/src/network\ has been restructured to support distinct execution contexts (renderer, Node.js, and unit tests) via new entry points like \send-request.node.ts\ and \unit-test-feature.ts\. This change introduces explicit handling for request cancellation via \cancellation.renderer.ts\, enforces folder-level inheritance for authentication and headers through \network.ts\, and adds support for API Key authentication in headers, query parameters, and cookies. Additionally, cookie persistence logic has been refined in \set-cookie-util.ts\ to correctly track cookie provenance (distinguishing between manual and response-sourced cookies) and certificate matching now supports wildcard patterns and fallback port checks.
packages/insomnia/src/network · high confidence
Removal of legacy Webpack configuration files
The project has removed the legacy Webpack configuration files (base.config.js, dev.config.js, and prod.config.js). This change eliminates the previous build setup, which included specific loaders for Babel, SCSS/CSS, HTML, and various font formats, as well as development-specific settings like hot module replacement and source maps. Users should expect that the build process will no longer rely on these specific configurations, implying a migration to a new or different build system or configuration structure.
webpack · high confidence
Removal of legacy layout SCSS modules
The specific layout styles for forms, headers, and panes have been removed from the application. This deletes the dedicated SCSS files that previously defined visual properties for form controls, buttons, header sections, and pane containers, indicating a shift in how these UI components are styled or structured.
app/css/layout · high confidence
Removal of legacy request, response, and sidebar component styles
The specific SCSS files defining styles for the request, response, and sidebar components have been deleted. This removes the previous visual definitions for these areas, including background colors, header styling, and sidebar item layouts, indicating a structural or thematic overhaul of the user interface.
app/css/components · high confidence
Removed SCSS constants for colors and dimensions
The application no longer uses the SCSS files defining global color variables (such as primary, light, and dark backgrounds) and dimension constants (including font sizes, padding, header height, and sidebar width). This removal indicates a shift in how styling is managed, likely moving towards a different CSS preprocessor or inline styling approach, which will affect the visual appearance and layout of components that previously relied on these specific SCSS variables and utility classes.
app/css/constants · high confidence
Removed legacy CSS reset and base layout styles
The application has removed several foundational CSS files, including the Meyer Web CSS reset, base typography and body styles, and the previous flexbox-based grid system. This cleanup eliminates redundant global resets and the old grid implementation, likely as part of a broader shift to modern CSS Grid or a new styling architecture.
app/css · high confidence
Renamed CLI entry point from insomnia-cli to insomnia-inso
The command-line interface tool has been renamed from 'insomnia-cli' to 'insomnia-inso'. This change updates the binary entry points in the bin directory, replacing the previous executable scripts with new ones that invoke the underlying Node.js module. A new debug helper script was also added to support VS Code launch configurations, allowing developers to pass extra arguments for debugging purposes.
packages/insomnia-inso/bin · high confidence
Support for Unix sockets and secure proto file handling in gRPC
gRPC requests now support Unix sockets via the 'unix:' URL scheme, allowing connections to local endpoints. Additionally, proto files are now written to a dedicated temporary directory ('insomnia-grpc') with path validation to prevent directory traversal, ensuring safer and more isolated file operations during request execution.
packages/insomnia/src/network/grpc · high confidence
Templating engine overhaul and expanded test coverage
The templating system has been significantly refactored to support a new LiquidJS engine alongside the existing Nunjucks engine, introducing features such as strict variable checking, sandboxed file access, and a web-worker bridge for plugin hooks. This change also adds a comprehensive suite of local template tags (including Faker, Base64, UUID, and OS info) and introduces robust serialization logic to safely pass render contexts across process boundaries. Additionally, the update includes extensive new test coverage for template tag behavior, argument tokenization, and context serialization, ensuring reliability for these core templating capabilities.
packages/insomnia/src/common/templating · high confidence
Unified database loading with multi-source support in Inso CLI
The Inso CLI now uses a centralized database loading mechanism that automatically detects and loads data from three distinct sources: Insomnia export files, Git repositories, and local Insomnia application data directories. This change replaces previous ad-hoc loading logic with a unified adapter pattern, allowing users to specify a working directory or file path and have the CLI intelligently resolve the correct data source, while providing clear guidance via error messages if no valid source is found.
packages/insomnia-inso/src/db · high confidence
Updated icon library and added code editor styling
The application's icon library has been upgraded to Font Awesome 6.2.0, introducing new brand icons, animations, and size utilities while maintaining backward compatibility through v4 shims. Additionally, new CSS styles have been added for the CodeMirror editor, including a default theme, a Material color scheme, and a dark theme specifically for the merge-view addon to support side-by-side diff comparisons.
packages/insomnia/src/ui/css/lib · high confidence
Updated legacy database fixtures for smoke tests
The \insomnia-legacy-db\ fixture files have been refreshed to include new \ApiSpec\ records (containing Swagger Petstore OpenAPI definitions) and updated \CookieJar\, \Environment\, and \GitRepository\ entries. This change ensures the smoke-test fixtures remain consistent with the current application state, preventing test failures caused by stale or missing legacy data.
packages/insomnia-smoke-test/fixtures/insomnia-legacy-db · medium confidence
VCS sync initialization and project migration logic
The VCS sync module now includes logic to initialize local backend projects for workspaces, automatically staging all descendants and lint rulesets for the initial snapshot, and handles race conditions during workspace activation. It also provides migration utilities to move legacy projects (without organizations) into the new organization hierarchy by updating parent and remote IDs, and introduces error handling for user-aborted merge conflicts in the VCS resolution process.
packages/insomnia/src/sync/vcs · high confidence
Workspace pane header and navigation breadcrumbs updated
The workspace pane header now displays dynamic breadcrumbs that reflect the current navigation path (project, workspace, request group, or request) using a new ResourceIcon component to visually distinguish resource types. The header also integrates an EnvironmentPicker that supports both workspace and project-level environment selection, along with buttons for managing cookies and certificates, with specific handling for MCP workspaces to adjust UI elements like cookie visibility and certificate status indicators.
packages/insomnia/src/ui/components/workspace · high confidence
Fixes
Database layer reimplementation with NeDB and repair utilities
The database implementation in the node environment has been replaced with a new NeDB-based backend (database-nedb.ts), introducing change buffering, automatic flush timers, and explicit change notifications for operations like document duplication. Additionally, a repair-database module was added to automatically fix legacy data issues, including merging multiple base environments or cookie jars per workspace, correcting API spec filenames, and appending .git to old Git URIs.
packages/insomnia-data/node-src/database · high confidence
Fix for missing user plugin template tags after reload
Resolves an issue where user-installed plugin template tags (such as those from HMAC plugins) would remain unavailable in templating even after clicking the 'Reload' button in Settings. This occurred because the templating web worker cached its Liquid engine at startup; if a plugin was discovered after that initial build, the worker never re-scanned for it. The fix ensures that reloading the plugin registry now properly invalidates the worker's cached engine, allowing newly discovered or re-enabled plugin tags to be used in subsequent renders.
packages/insomnia/src/ui/worker · high confidence
Fix missing CA and certificate fixtures in CLI database loading
Added placeholder CA, certificate, and key fixture files (fake\_ca.pem, fake\_cert.pem, fake\_key.pem) to the inso CLI package. This resolves an issue where these certificate resources were not included when loading the database from the CLI, ensuring that tests and operations relying on these fixtures now have the necessary data available.
packages/insomnia-inso/src/db/fixtures/certs · high confidence
Insomnia schema migration to version 5.1
The application now includes a schema migration system that automatically upgrades legacy Insomnia data files to version 5.1 upon import. This migration cleans up internal bookkeeping fields by removing \id\ properties from headers, parameters, and body params, and strips timestamp metadata (\creation\, \lastAccessed\) from cookies. It also filters out empty or invalid entries from these arrays and normalizes script objects, ensuring that imported collections are consistent with the current data model without altering the underlying OpenAPI specification contents.
packages/insomnia/src/common/insomnia-schema-migrations · high confidence
User-installed plugin template tags now resolve correctly in rendered templates
Fixed a bug where template tags defined by user-installed plugins (e.g., {% requestbodyhmac %}) were not found during rendering, despite being available in the editor autocomplete. The templating worker now correctly fetches and merges user plugin tags into the Liquid engine, routing their execution back to the main process via IPC. Additionally, the system now properly resolves variable references (like \_.body) within tag arguments, ensuring dynamic content is evaluated rather than treated as literal strings.
packages/insomnia/src/ui/templating · high confidence
Test coverage
Added Electron mock for testing; Added Playwright page objects for Insomnia Preferences tabs; Added bare Git repository fixture for smoke tests; Added compatibility tests for the LiquidJS templating engine migration; Added critical smoke tests for backup, bundling, certificates, and scratchpad; Added gRPC test fixtures for smoke testing; Added integration tests for the testing package; Added mock for @grpc/grpc-js to support Vitest testing; Added sample fixture data for inso git-repo testing; Added smoke test fixtures for validation, data upload, and content preview; Added smoke tests for Git migration onboarding and local-to-cloud data migration; Added smoke tests for after-response scripting and core application workflows; Added smoke-test fixture data for inso-nedb; Added test coverage for Git Sync core components; Added test coverage for insomnia-data models and services; Added test coverage for main-process security, Git sync, and LLM configuration; Added test coverage for the plugin system; Added tests for Postman data dump extraction; Added tests for basic authentication header generation; Added tests for gRPC URL parsing and proto file writing; Added tests for importer conversion and key validation; Added tests for system change detection in diff view; Added tests for the API specification export functionality; Added unit tests for Konnect integration components; Added unit tests for common utility modules; Added unit tests for modal utilities and import/export logic; Added unit tests for network authentication, certificate matching, and multipart body building; Added unit tests for plugin context modules; Added unit tests for plugin creation and installation logic; Added unit tests for scripting-environment objects; Added utilities for export smoke tests; Deterministic UUID generation in test mocks; Expanded smoke-test fixtures for Insomnia v5.1 collections; Expanded test fixtures for importers; Initial setup of Playwright-based smoke test infrastructure; Mock for node-libcurl added to support testing; Mocking Sentry Electron for Vitest testing; New Playwright Page Object Model for E2E tests; New page objects for export modal, navigation sidebar, and statusbar; New page objects for project dashboard and workspace list in smoke tests; Regenerated test certificates for smoke tests; Snapshot tests added for cURL import fixtures; Updated inso database fixtures with new test data and settings.
Dependencies
Initialize monorepo workspace structure and add sandbox demo plugin
The project is initialized as a monorepo with a root \package.json\ defining workspaces for core packages including \insomnia\, \insomnia-inso\, \insomnia-data\, \insomnia-vcs\, \insomnia-analytics\, \insomnia-api\, \insomnia-testing\, and \insomnia-scripting-environment\. A new example plugin \insomnia-plugin-sandbox-demo\ is added to demonstrate the QuickJS template-tag sandbox path, requesting \events\ and \uuid\ modules and \storage\ capability. The root dependencies include \@getinsomnia/node-libcurl\ and \ajv\, while dev dependencies establish the tooling stack with \esbuild\, \vitest\, \typescript\, and \eslint\ v9.
(dependencies) · high confidence
Housekeeping
Repository initialization with Apache 2.0 license and modern tooling configuration
The repository has been initialized with a new project structure and configuration. The software license has been updated to Apache Version 2.0. Development tooling is configured via \.prettierrc\ (enforcing 120-character line widths and Tailwind CSS plugin support for the Insomnia package), \.markdownlint.yaml\ (standardizing list styles and allowing specific HTML elements), and \.clang-format\ (setting a 120-column limit). The Node.js runtime is pinned to version 24.18.0 via \.nvmrc\, and npm is configured with strict engine checking and a registry alias for the Kong GitHub package repository in \.npmrc\. Additionally, \.gitattributes\ is set to enforce LF line endings for text files and mark the vendored Yarn binary as generated to reduce diff noise.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 44 → 50 (+6.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 61 → 65 (+3.9)
- Architecture 45 (new)
- Maturity 62 → 75 (+12.6)
- Readiness 29 → 54 (+24.5)
- Security 54 → 64 (+9.6)
- Accessibility 48 (new)
- Performance 60 (new)
Resolved (77)
- Change coupling: cli.ts ↔ environment.ts (packages/insomnia-inso/src/cli.ts)
- Change coupling: cli.ts ↔ export-specification.ts (packages/insomnia-inso/src/cli.ts)
- Change coupling: cli.ts ↔ workspace.ts (packages/insomnia-inso/src/cli.ts)
- Change coupling: entry.preload.ts ↔ electron.ts (packages/insomnia/src/entry.preload.ts)
- Change coupling: export-specification.ts ↔ index.ts (packages/insomnia-inso/src/commands/export-specification.ts)
- Change coupling: git-service.ts ↔ project-routable-fs-client.ts (packages/insomnia/src/main/git-service.ts)
- Change coupling: project-create-form.tsx ↔ project-settings-form.tsx (packages/insomnia/src/ui/components/project/project-create-form.tsx)
- Change coupling: templating-worker-database.ts ↔ invoke-method.ts (packages/insomnia/src/main/templating-worker-database.ts)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (packages/insomnia-component-docs/package-lock.json)
- Critical CVE: [GHSA redacted] (packages/insomnia-component-docs/package-lock.json)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 57 more
New (1301)
- Boundary-crossing change coupling: interfaces.ts ↔ request-script-editor.tsx (packages/insomnia-scripting-environment/src/objects/interfaces.ts)
- Change coupling: cancellation.renderer.ts ↔ network.ts (packages/insomnia/src/network/cancellation.renderer.ts)
- Change coupling: entry.preload.ts ↔ main.ts (packages/insomnia/src/entry.preload.ts)
- Change coupling: git-branches-modal.tsx ↔ git-staging-modal.tsx (packages/insomnia/src/ui/components/modals/git-branches-modal.tsx)
- Change coupling: git-service.ts ↔ git-project-sync-dropdown.tsx (packages/insomnia/src/main/git-service.ts)
- Change coupling: mock-response-extractor.tsx ↔ mock-url-bar.tsx (packages/insomnia/src/ui/components/editors/mock-response-extractor.tsx)
- Change coupling: organization.$organizationId.project.$projectId.workspace.$workspaceId.environment.tsx ↔ workspace-environments-edit-modal.tsx (packages/insomnia/src/routes/organization.$organizationId.project.$projectId.workspace.$workspaceId.environment.tsx)
- Change coupling: raw-editor.tsx ↔ response-pane.tsx (packages/insomnia/src/ui/components/editors/body/raw-editor.tsx)
- Change coupling: request-group-pane.tsx ↔ request-pane.tsx (packages/insomnia/src/ui/components/panes/request-group-pane.tsx)
- Change coupling: request-group-settings-modal.tsx ↔ request-settings-modal.tsx (packages/insomnia/src/ui/components/modals/request-group-settings-modal.tsx)
- Change coupling: request-pane.tsx ↔ websocket-request-pane.tsx (packages/insomnia/src/ui/components/panes/request-pane.tsx)
- Change coupling: request-url-bar.tsx ↔ action-bar.tsx (packages/insomnia/src/ui/components/request-url-bar.tsx)
- Change coupling: response-pane.tsx ↔ response-multipart-viewer.tsx (packages/insomnia/src/ui/components/panes/response-pane.tsx)
- Change coupling: sync-branches-modal.tsx ↔ sync-history-modal.tsx (packages/insomnia/src/ui/components/modals/sync-branches-modal.tsx)
- Change coupling: sync-history-modal.tsx ↔ sync-staging-modal.tsx (packages/insomnia/src/ui/components/modals/sync-history-modal.tsx)
- Change-coupling hub: organization.$organizationId.project.$projectId._index.tsx → sidebar-project-dropdown.tsx, workspace-sync-dropdown.tsx, workspace-duplicate-modal.tsx (packages/insomnia/src/routes/organization.$organizationId.project.$projectId._index.tsx)
- ClassTooLong: GitVCS (packages/insomnia/src/sync/git/git-vcs.ts)
- ClassTooLong: RepoFileWatcher (packages/insomnia/src/sync/git/repo-file-watcher.ts)
- ClassTooLong: VCS (packages/insomnia-vcs/src/vcs.ts)
- Cookie.parse (cognitive 17) (packages/insomnia-scripting-environment/src/objects/cookies.ts)
- …and 1281 more
Changes since last survey
- 125 commits — 51 feature/other, 74 fixes
By area
- packages/insomnia — 90 commits
- packages/insomnia-smoke-test — 11 commits
- (root) — 7 commits
- .github/workflows — 7 commits
- packages/insomnia-data — 2 commits
- packages/insomnia-scripting-environment — 2 commits
- .claude/settings.json — 1 commit
- .claude/skills — 1 commit
- .github/scripts — 1 commit
- packages/insomnia-inso — 1 commit
- packages/insomnia-vcs — 1 commit
- scripts/circular-references — 1 commit
Notable commits
- fix: Fix: Secret type environment input hanging and data update issue (#10420)
- fix: chore: fix playwright port detect (#10462)
- fix: fix expand issue when no request group meta (#10453)
- fix: fix shortcut creation issue & workspace dropdown context menu issue (#10432)
- fix: fix sidebar data not updated when offline (#10369)
- fix: fix the tag editor update issue (#10537)
- fix: fix(INS-2766): Land on the parent folder/collection root when deleting a request's last open tab (#10375)
- fix: fix(INS-3507): restrict git-sync and legacy-folder writes to canSync model types (#10531)
- fix: fix(INS-3620): tag cookie assignment origin (#10475)
- fix: fix(INS-3836): don't show the Konnect-moved notice before a migration conflict is resolved (#10521)
- fix: fix(INS-3850): re-check the Konnect organization's visibility before restoring it on cold start (#10518)
- fix: fix(INS-3850): revalidate a project's old organization cache when it moves parents (#10513)
- fix: fix(INS-3906): parse quoted CSV fields in collection runner data (#10557)
- fix: fix(build): macos latest (#10400)
- fix: fix(ci): skip circular refs PR comment when count is unchanged (#10391)
- fix: fix(cloud-sync): surface stale/reverted staged changes instead of silently committing them [INS-3520] (#10438)
- fix: fix(database): emit change notifications on document duplication (#10387)
- fix: fix(deps): security dependency bumps (#10347)
- fix: fix(environment-editor): treat empty JSON content as invalid JSON (#10540)
- fix: fix(error-boundary): log full error stack for better diagnostics (#10379)
- …and 105 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Kong/insomnia was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7de40fe4a7bb9add31dbee8e01dd4347ff6920b5 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.