Skip to content
CAI
Software that uses CAICheck a score

Kong/insomnia

49.7

Weak · 28 September 2026

162.8k

lines of production code

TypeScript

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a modernized, cross-platform API client and development environment that supports HTTP, gRPC, WebSocket, and GraphQL protocols. It features a robust data layer with local and Git-based version control, secure plugin sandboxing, and a unified scripting environment for request automation. The application provides comprehensive tools for API design, testing, and synchronization with cloud services, all built on a secure, isolated architecture.

How it got here

2016–2022 — Monorepo migration and modernization

91 changes.

The project underwent a comprehensive architectural overhaul, migrating from a legacy Redux and Webpack setup to a modern monorepo structure using esbuild, Vitest, and React Aria. This period focused on rebuilding core infrastructure, including a new database layer, a sandboxed plugin system, and a unified CLI, while simultaneously replacing the UI with accessible, component-based designs and LiquidJS templating.

2023–2026 — Architecture overhaul and security hardening

91 changes.

This period focused on a comprehensive architectural restructuring of the Insomnia codebase, extracting the data layer into the insomnia-data package and implementing a new service layer for centralized database access. Significant security improvements were introduced, including a QuickJS sandbox for plugin execution, a secure Windows installer wrapper, and a new VCS package for encrypted sync. The work also involved migrating the templating engine to LiquidJS, overhauling the UI with Tailwind v4, and expanding support for MCP, Konnect, and external vault integrations.

Features

Add Electron API shim for request sending in non-electron environments

A new shim file has been added to the send-request package to provide minimal implementations of Electron-specific APIs (app.getPath, ipcMain, BrowserWindow). This allows the request-sending logic to function correctly in environments where the full Electron runtime is not available, by mocking these dependencies with standard Node.js alternatives like os.tmpdir().

packages/insomnia/send-request · high confidence

Add build and test configuration for the scripting-environment package

The \insomnia-scripting-environment\ package now includes dedicated configuration files to support its build and testing workflows. An \esbuild-runner.config.js\ file is introduced to mark \@getinsomnia/node-libcurl\ and \electron\ as external dependencies, ensuring they are not bundled. A \tsconfig.json\ file establishes the TypeScript compilation settings, targeting ES2022, enabling strict type checking, and configuring path aliases to resolve \\~/\*\ to the \insomnia\ source directory. Additionally, a \vitest.config.ts\ file is added to configure the test runner, including an alias for the \\~\ path and settings to hide skipped tests.

packages/insomnia-scripting-environment · high confidence

Add themed Button and AsyncButton components

The Insomnia UI now includes a new set of reusable button components in the \themed-button\ package. The \Button\ component supports configurable sizes (default, small, medium, xs), variants (outlined, contained, text), and themes (default, surprise, info, success, notice, warning, danger), allowing for consistent styling across the application. Additionally, an \AsyncButton\ component is provided to handle asynchronous actions, automatically managing a loading state and disabling the button while an operation is in progress.

packages/insomnia/src/ui/components/themed-button · high confidence

Added code snippet type definitions and autocomplete generation script

The application now includes TypeScript interfaces for HTTP snippet clients and targets (code-snippet.ts) to support code generation features, alongside a new build script (generate-autocomplete.ts) that statically derives autocomplete snippets from the scripting API for use in the renderer without requiring Node.js integration.

packages/insomnia-scripting-environment/scripts, packages/insomnia/src/types · high confidence

Added sync delta diff and patch utilities

New \diff\ and \patch\ modules have been added to the sync delta package to support content synchronization. The \diff\ function generates a sequence of COPY and INSERT operations by comparing source and target strings using SHA-1 hashed blocks, while the \patch\ function applies these operations to reconstruct the target content. This logic is foundational for the sync feature's ability to calculate and apply changes between document versions.

packages/insomnia/src/sync/delta · high confidence

Define sync model schemas for Insomnia data models

The sync module now includes explicit schema definitions for core Insomnia data models (Workspace, Request, GrpcRequest, RequestGroup, and Environment) via a new \model-schemas.ts\ file. These schemas, built using \fluent-builder\ and derived from \insomnia-data\ model initializers, standardize the structure of data objects used during synchronization, ensuring consistent field presence and types for sync operations.

packages/insomnia/src/sync/\\schemas\\_ · high confidence_

Experimental QuickJS sandbox for pre-request and after-response scripts

Insomnia introduces an opt-in QuickJS-based sandbox for running pre-request and after-response scripts, designed to run off the main thread via a dedicated Web Worker to prevent UI blocking. This experimental feature is disabled by default (controlled by \QUICKJS\_SANDBOX\_ENABLED\ and the \settings.useQuickJsScriptSandbox\ flag) and provides a restricted scripting environment that blocks dangerous Node.js built-ins (such as \fs\, \child\_process\, and \crypto\), prevents prototype pollution, and limits access to global objects like \process\ and \globalThis\. The sandbox exposes a minimal \insomnia\ API for reading/writing environment and transient variables, accessing the request object, and sending HTTP requests via \insomnia.sendRequest()\, while supporting a curated set of external libraries including \lodash\, \moment\, \chai\, and \cheerio\. Comprehensive test coverage has been added for the security policy, module interception, and the QuickJS engine's behavior.

packages/insomnia/src/scripting · high confidence

Initial release of the Insomnia Component Documentation site

A new Docusaurus-based documentation site has been added for Insomnia's shared UI component library. This site provides detailed API references, usage examples, and styling guidelines for base components including Button, Input, Checkbox, Select, Switch, Tabs, Banner, and InputNumber. It features live-editable code examples powered by React Aria and Tailwind CSS, with a dark/light theme system and an autogenerated sidebar for easy navigation.

packages/insomnia-component-docs · high confidence

Inso CLI adds telemetry, collection run reporting, and test output formatting

The Inso CLI now collects anonymous usage analytics via Segment, respecting the new INSO\_TELEMETRY\_DISABLED environment variable and the user's enableAnalytics setting in local settings. Collection runs can now save a detailed result report (RunCollectionResultReport) that includes execution stats, timing, and redacted or plaintext data. Additionally, the CLI introduces multiple test output reporters (dot, list, min, progress, spec, tap) to format test results in the console, and supports reading iteration data from CSV files with proper handling of quoted fields.

packages/insomnia-inso/src · high confidence

Introduce MCP client UI with elicitation, sampling, and server primitive management

Insomnia now includes a dedicated UI for interacting with Model Context Protocol (MCP) servers. This update adds a new \mcp\ component area featuring \McpPane\ for browsing and filtering server primitives (tools, resources, prompts), and \McpRequestPane\ for configuring request parameters, authentication, and file roots. It introduces \ElicitationForm\ and \SamplingForm\ to handle interactive server requests, allowing users to submit data, approve/reject sampling, or use an AI-assisted response generator. The \McpNotificationTab\ and \EventView\ provide a searchable log of server events with raw and formatted viewing options, while \McpUrlActionBar\ manages connection states and transport types (HTTP/STDIO).

packages/insomnia/src/ui/components/mcp · high confidence

Introduce insomnia-api package for shared API functionality

The new \insomnia-api\ package centralizes API client logic and types for use across both the Insomnia application and inso-cli. It provides a unified, proxy-aware fetch mechanism to ensure requests respect system proxies and OS certificates, and exposes modules for user profiles, vault operations, organizations, spaces, collaborators, enterprise features, trials, and VCS integration.

packages/insomnia-api · high confidence

Introduce new GraphQL Explorer UI components

The GraphQL Explorer now features a comprehensive set of new React components to enhance schema exploration. Users can now see default values for arguments, view deprecation warnings with tooltips, and navigate between types and fields via clickable links. The explorer includes a dedicated search interface with fuzzy matching for types and fields, lazy-loaded results to maintain performance, and detailed views for enums, object types, interfaces, and unions, including their descriptions, implementations, and field arguments.

packages/insomnia/src/ui/components/graph-ql-explorer · high confidence

Introduce new MCP client implementation with OAuth and transport support

The MCP client logic in the main process has been rewritten to use the Model Context Protocol SDK, introducing dedicated transports for both STDIO and Streamable HTTP connections. This change adds full OAuth 2.0 support for MCP servers, including a new 'mcp\_auth\_flow' grant type that allows users to authorize via a browser window with options to disable automatic browser launching and disable SSL validation. The new implementation also supports resource subscriptions, server-side elicitation and sampling requests, and integrates with the insomnia-data package for persisting responses and environments.

packages/insomnia/src/main/mcp · high confidence

Introduces shared basic component library

Insomnia now provides a new shared component library at \\~/basic-components\, consolidating UI primitives like Button, Modal, Tabs, Banner, Card, and SelectPopover into a single, consistent API built on React Aria and Tailwind CSS. This library standardizes styling conventions (using CSS variables and Tailwind utilities) and accessibility patterns across the application, serving as the foundation for future UI migrations and theme customization.

packages/insomnia/src/basic-components · high confidence

Konnect sync now supports Kong Expressions router and proxy configuration

The Konnect integration has been expanded to handle Kong's new Expressions router DSL. When syncing routes that use expressions, Insomnia now parses the expression to extract standard HTTP fields (methods, paths, hosts, headers) so they can be represented as requests; routes relying on unsupported features like TLS SNI matching are skipped. Additionally, the sync process now automatically configures proxy settings by deriving environment variables (proxy\_host, grpc\_proxy\_host, grpcs\_proxy\_host) from the Control Plane's proxy URLs, and it sanitizes incoming data by stripping Liquid template syntax to prevent injection issues.

packages/insomnia/src/konnect · high confidence

New AI assistant skills for component documentation and scripting troubleshooting

The AI assistant now includes dedicated skills to streamline two key workflows: maintaining Docusaurus component documentation and debugging the scripting environment. The new component-docs skill provides a structured procedure for authoring and updating MDX docs for shared UI components, including instructions for registering live code examples in the ReactLiveScope. Additionally, the fix-scripting-feature skill offers detailed architectural context and reference documentation for the pre-request, after-response, and test scripting APIs (pm/insomnia), helping to resolve common issues like sandbox violations, module import errors, and unexpected behavior in the Postman-compatible API surface.

.claude · high confidence

New FancyReporter for inso CLI output

The inso CLI now includes a new FancyReporter that formats log output with colored icons, badges, and Unicode support. This reporter handles various log types (info, error, warn, etc.) with distinct visual indicators, formats error stacks and chained causes, and adapts layout based on terminal width. It also supports character formatting for backticks and underscores in log messages.

packages/insomnia-inso/src/reporters · high confidence

New Git Repository Settings modal for project configuration

A new Git Repository Settings modal has been introduced to allow users to view and manage the configuration of a connected Git repository. This interface displays the associated Git provider and connection details, the selected author email for commits, and the local folder path where the repository is stored, including a 'Reveal' button to open the directory in the file system. Users can also disconnect the Git repository directly from this modal.

packages/insomnia/src/ui/components/modals/git-repository-settings-modal · high confidence

New Import Modal with Bulk Project and cURL Support

The Import modal has been replaced with a new implementation that supports importing entire projects by selecting a root folder containing multiple sub-projects, in addition to the existing single-file import. It now explicitly supports cURL scripts (alongside Insomnia, Postman, Swagger, OpenAPI, HAR, and WSDL) and provides a drag-and-drop interface for files and directories. The modal also includes a security disclaimer warning users to only import files from trusted sources due to potential automatic code execution.

packages/insomnia/src/ui/components/modals/import-modal · high confidence

New LLM provider settings components with model selection and parameter controls

The AI Settings UI now includes dedicated configuration panels for OpenAI, Anthropic (Claude), Google Gemini, local GGUF models, and custom URL-based endpoints. Users can enter API tokens to dynamically load available models from the provider's API (or local directory for GGUF), select a specific model, and activate it. The OpenAI, Claude, and Gemini panels allow toggling the active provider and deactivating it, while the GGUF and URL panels expose advanced generation parameters (such as temperature, top\_p, and max\_tokens) with validation schemas to fine-tune model behavior.

packages/insomnia/src/ui/components/settings/llms · high confidence

New UI components and editor modes for Insomnia

The application introduces a suite of new UI components and editor modes to enhance the user experience. A new AppLoadingIndicator provides visual feedback during startup. The Command Palette has been implemented to allow quick searching and navigation between requests and workspaces. The Environment Picker has been redesigned to simplify selecting and managing project and global environments. New components include Avatar and AvatarGroup for user representation, a CollectionTab for switching between API specs and tests, a DiffViewEditor for comparing document changes, an EditableInput for inline text editing, and an EncodingPicker for file encoding selection. Additionally, new CodeMirror syntax highlighting modes have been added for Clojure, cURL, Nunjucks (used for templating), and OpenAPI specifications, improving code readability in the editor.

packages/insomnia/src/ui/components · high confidence

New UI forms for AWS, Azure, GCP, and HashiCorp external vaults

The templating tag editor now includes dedicated configuration forms for external secret managers. Users can configure AWS Secrets Manager (with plaintext or key-value secret types), Azure Key Vault (with URL validation for secret identifiers), GCP Secret Manager, and HashiCorp Vault (supporting both on-premises KV v1/v2 engines and HCP Vault Dedicated, including namespace header options). These new forms replace the previous generic JSON input, providing structured fields, help tooltips, and credential editing capabilities directly in the UI.

packages/insomnia/src/ui/components/templating/external-vault · high confidence

New UI hooks for navigation, state, and integrations

This change introduces a suite of new React hooks in the \packages/insomnia/src/ui/hooks\ directory to support the application's new navigation model and feature set. \useInsomniaNavigation\ and \useInsomniaTab\ manage the new URL-based routing and tab state for requests, workspaces, and MCP resources. \useAccountServerData\ centralizes account, user, and plan data fetching with TanStack Query. \useCio\ initializes the Customer.io SDK and ensures events are only tracked for identified users to prevent anonymous profiles. \useKonnectSync\ handles the Konnect synchronization process with progress tracking and analytics. Additional hooks include \useImageCache\ for avatar caching, \useThemes\ for theme management, \useCloseConnection\ for managing WebSocket/SSE/GRPC connections, \useCommandSearch\ for the command palette, and \useGitFileIssues\ for Git sync conflict detection.

packages/insomnia/src/ui/hooks · high confidence

New UI icon assets added to the Insomnia package

The \packages/insomnia/src/ui/components/assets\ directory now includes a comprehensive set of new SVG icon files (such as \icn-arrow-right.svg\, \icn-bitbucket-logo.svg\, \icn-sparkles.svg\, and \icn-gitlab-logo.svg\) and their corresponding React component wrappers (e.g., \IcnArrowRight.tsx\). These assets provide the visual icons required for the application's user interface components.

packages/insomnia/src/ui/components/assets · high confidence

New UI utility functions and tests for sync, formatting, and mock routing

This change introduces a suite of new utility functions and their corresponding tests in the UI layer. It adds \dedupeCollectionItems\ to remove duplicate items from collections while preserving order, and \first-request-treatment\/\first-request-latch\ to manage an A/B experiment for the first-request onboarding experience, including account-aware request counting and server-side threshold latching. It also adds \insomnia-sync\ to handle sync merge conflict modals, \git-folder-trust\ and \git-repo-path\ to manage Git folder trust prompts and path resolution, \method-colors\ to map HTTP methods to theme-aware UI colors, \mock-route\ to enforce unique method+path constraints for mock routes, \grpc\ to provide user-friendly error messages for gRPC connection issues, and \prettify\ (JSON and EDN) to format request bodies. All new functionality is accompanied by comprehensive test coverage.

packages/insomnia/src/ui/utils · high confidence

New WebSocket, Socket.IO, and MCP real-time debugging interface

Insomnia now includes a dedicated real-time debugging experience for WebSocket, Socket.IO, and Model Context Protocol (MCP) connections. This update introduces a new action bar for managing connection states (connect, disconnect, disconnect all), a unified event log view that tracks and displays incoming and outgoing messages for all three protocols, and a detailed event viewer with support for JSON previewing, raw text export, and binary data handling. The interface also features a request pane for configuring connection parameters and a response pane that visualizes real-time streams, including stream summaries for SSE-like patterns and specific handling for MCP notifications and unsupported methods.

packages/insomnia/src/ui/components/websockets · high confidence

New and updated theme definitions for Insomnia

The application now includes a refreshed set of built-in themes, adding new options such as Colorblind Dark, Gruvbox Dark, High Contrast Light, Hyper, and a Designer Light/Dark pair, while also introducing a Legacy theme to preserve previous visual styles. These theme definition files in the plugins/themes directory provide the specific color palettes, background/foreground settings, and UI style overrides (for components like the sidebar, pane headers, and dialogs) that users can select to customize the application's appearance.

packages/insomnia/src/plugins/themes · high confidence

New app-data service for efficient workspace and organization data retrieval

A new \app-data\ service has been introduced in the \insomnia-data\ package to provide optimized, batched retrieval of workspace and organization data. This service includes functions to fetch comprehensive organization data (including projects, linked Git repositories, workspaces, and metadata) and to efficiently walk nested collection structures, aggregating all requests, request groups, and their associated metadata (for REST, gRPC, WebSocket, and SocketIO) in a single pass. This change supports the sidebar cache logic by providing a structured way to load hierarchical workspace children and their states, improving performance for UI components that need to display complex workspace trees.

packages/insomnia-data/node-src/services/app-data · high confidence

New application-level React contexts for state management and data caching

The application now introduces several new React contexts in the \packages/insomnia/src/ui/context/app\ directory to centralize and improve state handling. The \InsomniaTabContext\ manages multi-tab navigation, including adding, closing, and reordering tabs with history support. The \InsomniaEventStreamContext\ handles real-time collaboration presence and server-side event streams (such as file changes and storage rule updates) via Server-Sent Events. The \AppDataCacheProvider\ and \ServerDataCacheProvider\ establish dedicated TanStack Query clients for local database queries and remote server data respectively, ensuring appropriate caching and refetch strategies. Additionally, the \RunnerContext\ manages state for the request runner, and the \SidebarContext\ controls sidebar collapse state.

packages/insomnia/src/ui/context/app · high confidence

New base UI component library

Insomnia introduces a new set of base UI components in the \packages/insomnia/src/ui/components/base\ directory, providing a consistent foundation for the application's interface. This release adds a Badge for status labeling, a Checkbox and CheckboxGroup for selections, a CopyButton for clipboard operations, a DatePicker for date input, a FileInputButton for file selection, an IndeterminateCheckbox for tree-like states, an InputNumber for numeric entry, a versatile Input with password visibility toggling and prefix support, a Link that opens URLs in the browser, a MiddleTruncate for file paths, and a full Modal system (Modal, ModalHeader, ModalBody, ModalFooter) for dialogs. Additionally, a PromptButton is added for confirmation workflows, a Select for dropdown choices, and a Switch for toggles, all leveraging React Aria Components and Tailwind CSS for styling.

packages/insomnia/src/ui/components/base · high confidence

New client-side route handlers for authentication, AI, and credential management

The application now uses a new set of client-side route handlers in the \src/routes\ directory to manage core user workflows. This includes a complete authentication flow (login, logout, vault key management, and OAuth authorization), AI integration endpoints for generating commit messages and MCP sampling responses, and dedicated routes for managing Git and cloud credentials (create, update, delete, and sign-in). These changes replace previous patterns by moving these logic paths into explicit React Router client loaders and actions, improving the separation of concerns for user-facing interactions.

packages/insomnia/src/routes · high confidence

New cloud credential forms for AWS, GCP, and HashiCorp

The Cloud Credential Modal now includes dedicated UI forms for configuring credentials for AWS, GCP, and HashiCorp providers. Users can now create and edit AWS credentials (supporting temporary, file-based, and SSO types), GCP service account key files, and HashiCorp Vault credentials (including On-Premises, Vault Dedicated, and Vault Secrets with AppRole or Token auth methods). This replaces the previous generic input approach with provider-specific validation and file-picking capabilities.

packages/insomnia/src/ui/components/modals/cloud-credential-modal · high confidence

New command search and request helper utilities in insomnia-data

The \insomnia-data\ package now includes a new \command-search\ helper that provides fuzzy matching for requests, files, and environments, partitioning results by current workspace or project and supporting cancellation via AbortController to prevent UI freezes. Additionally, new helper modules (\request-operations\, \response-operations\, \query-all-workspace-urls\) have been added to standardize operations across request types (HTTP, gRPC, WebSocket, SocketIO, MCP), including logic to find requests by parent ID, retrieve specific request types by ID, remove responses (including associated file paths), and query unique workspace URLs while excluding the currently selected request.

packages/insomnia-data/node-src/services/helpers · high confidence

New curl-based HTTP engine and comprehensive test coverage

Insomnia introduces a new curl-based HTTP engine (curl.ts) to handle request execution, replacing the previous implementation. This new engine supports authentication headers, request bodies, and connection registry management, while also enforcing URL validation to disallow local file URIs. The change is accompanied by the addition of a new get-auth-header.ts module to centralize authentication logic for various auth types (Basic, Bearer, OAuth1/2, API Key, Hawk, ASAP). To ensure reliability, new test files (curl.test.ts, libcurl-promise.test.ts) have been added to verify the new curl connection behavior, proxy configuration, and event log parsing, including regression tests for SSE/EventStream handling.

packages/insomnia/src/main/network · high confidence

New database adapters for importing Insomnia data via YAML/JSON exports and Git repositories

The inso CLI now supports importing data from Insomnia v4 and v5 YAML/JSON export files and from local Git repository directories containing \.insomnia\ folders. The new \insomnia-adapter\ parses these export files, handling type name conversions (e.g., \api\_spec\ to \ApiSpec\) and validating export formats, while the \git-adapter\ reads model files from directory structures, respecting sync permissions to exclude non-syncable types like Settings. Both adapters support filtering by model type and are accompanied by comprehensive tests using Vitest.

packages/insomnia-inso/src/db/adapters · high confidence

New mock server response pane and URL bar components

The mock server interface now uses dedicated UI components for managing requests and viewing results. The new MockUrlBar component provides controls to send mock requests, copy the full mock URL, and schedule requests with delays or intervals. The new MockResponsePane component displays the response details in a tabbed interface, allowing users to view the response body with different preview modes, inspect headers, and monitor the request timeline and history.

packages/insomnia/src/ui/components/mocks · high confidence

New native Git credential provider and provider registry

Insomnia now includes a new 'System Git Credentials' provider that delegates authentication to the operating system's native git credential manager (e.g., macOS Keychain, Windows Credential Manager) via \git credential fill\, rather than storing tokens in the app. This is part of a broader provider registry that also introduces dedicated implementations for GitHub (with OAuth and repository fetching), GitLab (with OAuth, refresh tokens, and PKCE), and a generic 'Access Token' provider for custom servers. The registry centralizes provider initialization and URL detection, while the new provider logic ensures that reauthorizing an account updates the specific existing credential instead of overwriting others.

packages/insomnia/src/sync/git/providers · high confidence

New plugin context API for app, data, network, request, response, and store operations

The plugin system now exposes a structured context object that plugins can use to interact with the application. This includes app-level utilities like alerts, dialogs, prompts, and clipboard access; data operations for importing and exporting workspaces (including HAR exports with private environment support); network capabilities to send HTTP requests and retrieve responses; request manipulation methods to modify headers, parameters, and cookies; response inspection to read status codes, headers, and bodies; and a persistent key-value store for plugin-specific data. This context provides a consistent interface for plugins to perform common tasks without directly accessing internal application state.

packages/insomnia/src/plugins/context · high confidence

The sidebar now features a dedicated project navigation interface that includes a search field for filtering projects, a button to create new projects, and a sync bar for managing Konnect gateway integrations. This update introduces visual indicators for different Konnect deployment types (such as self-managed, serverless, and Kubernetes) and provides onboarding flows to guide users through their first sync and environment configuration.

packages/insomnia/src/ui/components/sidebar · high confidence

New proto file list component with selection and management actions

A new ProtoFileList component has been introduced in the proto-file UI area to display a hierarchical view of proto files and directories. This component allows users to select individual proto files via checkboxes, re-upload existing files, delete specific files, and delete entire directories. It handles the recursive rendering of nested directory structures and provides visual feedback for the currently selected file, integrating with the insomnia-data model types for file and directory entities.

packages/insomnia/src/ui/components/proto-file · high confidence

New request and response pane components with improved empty states and test coverage

The \packages/insomnia/src/ui/components/panes\ directory has been restructured with new components to handle request and response panes, including \RequestPane\, \GrpcRequestPane\, \GrpcResponsePane\, and \RequestGroupPane\. These components introduce visual indicators (colored dots and counts) on tabs for Auth, Headers, Scripts, and Body to show when they contain data. Empty states have been improved with dedicated views like \NoProjectView\ (which handles Konnect sync states) and \NoSelectedProjectView\. The response pane now supports downloading large responses from disk and correctly handles JSON prettification versus raw binary exports. Additionally, new unit tests have been added for the request test result filtering logic and response pane download utilities.

packages/insomnia/src/ui/components/panes · high confidence

New response viewers for passwords, cookies, CSV, errors, headers, multipart, PDF, and timeline

The response viewer panel now includes dedicated components for displaying passwords (with toggleable visibility and masking), response cookies (with a 'Manage Cookies' button and notices for disabled auto-storing), CSV data (with a 'Select All' keyboard shortcut), and error details (with context-aware buttons for SSL validation or proxy setup). Headers are now displayed in a table with clickable links and a 'Copy All' button. Multipart responses can be browsed part-by-part, with headers viewable and individual parts savable as files. PDFs are rendered in an iframe, and the request timeline is shown in a read-only code editor. The main response viewer also handles large responses by blocking display until confirmed, detects content types from body content, and unescapes forward slashes in JSON previews.

packages/insomnia/src/ui/components/viewers · high confidence

New sandbox demo plugin for testing template tag capabilities

Added the \insomnia-plugin-sandbox-demo\ example plugin, which serves as a manual test fixture for the new QuickJS template-tag sandbox. It includes template tags that verify execution context (sandbox vs. main-process), exercise the async host bridge, demonstrate manifest-gated module resolution (including vetted libraries like \uuid\ and \events\), showcase ambient sandbox globals (Buffer, URL, process, crypto), test capability-gated features (storage), and validate multi-file plugin support via sibling module requires.

examples · high confidence

New shared analytics package with centralized event definitions

The \insomnia-analytics\ package has been introduced as a shared library to consolidate analytics logic. It provides the \InsomniaAnalytics\ class, which wraps the Segment SDK to automatically attach app context (name, version, OS) and platform tags to all tracked events, while handling errors via a configurable callback. The package also exports a comprehensive \AnalyticsEvent\ enum covering UI interactions, request lifecycle events, and new experiment-tracking capabilities, alongside an \InsoEvent\ enum for CLI-specific actions. This centralizes event naming and tracking behavior across the application.

packages/insomnia-analytics · high confidence

New shared utility library for Insomnia's data layer

The \packages/insomnia-data/common-src\ package introduces a new shared library of utilities used across the application. This includes a comprehensive hotkey registry with default bindings for UI actions, a fuzzy search implementation for command palette and filtering, and helpers for deterministic JSON stringification, NDJSON serialization, and query string parsing. It also provides platform detection, string localization definitions, and settings type definitions covering proxy scopes, HTTP versions, and plugin sandbox configurations.

packages/insomnia-data/common-src · high confidence

New test suite generation logic with fixture-based validation

The \packages/insomnia-testing/src/generate\ module now includes a new implementation for generating test suites, featuring a \generate\ function that converts JSON test suite definitions into JavaScript code using Chai assertions and Mocha-style \describe\/\it\ blocks. This change introduces a robust fixture-driven testing approach, where input JSON files (e.g., \01\_empty.input.json\, \03\_basic-suite.input.json\) are matched against expected JavaScript output files (e.g., \01\_empty.output.js\) to verify correct generation behavior, including handling of nested suites, empty tests, and active request management via \insomnia.clearActiveRequest()\. The implementation also includes utility functions for string escaping and indentation, validated by dedicated unit tests.

packages/insomnia-testing/src/generate · high confidence

New version-control package with local VCS engine and encrypted sync support

The \insomnia-vcs\ package introduces a local version-control system for Insomnia workspaces, enabling branch management, commit snapshots, and three-way merging with conflict resolution. It features a pluggable storage layer (file-system or in-memory) with automatic compression and atomic writes, and supports encrypted data synchronization via AES-GCM and RSA-OAEP-256. The package exposes a \VCS\ class for workspace-scoped operations, backend project management for linking local documents to remote projects, and GraphQL-based session handling for cloud sync.

packages/insomnia-vcs · high confidence

Redesigned settings interface with new reusable components and AI capabilities

The settings UI has been rebuilt using new, reusable form components (BooleanSetting, EnumSetting, NumberSetting, TextSetting, MaskedSetting) to provide a consistent experience across all preference panels. This update introduces a dedicated AI Settings panel for configuring LLM backends (Claude, Gemini, OpenAI, GGUF, custom URL) and toggling features like auto-generated mock servers, smart commits, and MCP response sampling. It also adds a new Cloud Service Credential management interface for enterprise users to configure AWS, GCP, HashiCorp, and Azure integrations, and refreshes the Git Credentials view with a modern OAuth flow and per-repo email selection.

packages/insomnia/src/ui/components/settings · high confidence

Smoke-test server now supports gRPC, WebSocket, Socket.IO, and OAuth flows

The smoke-test server has been expanded to include dedicated handlers for gRPC (Route Guide service), WebSocket (echo, binary, and cookie support), Socket.IO (custom handshake path), and OAuth/OIDC (authorization code, PKCE, implicit, client credentials, and resource owner flows). It also now serves mock endpoints for GitHub and GitLab authentication, basic authentication, mutual TLS (mTLS), cloud sync, and GraphQL, providing a comprehensive local environment for testing these protocols and integrations.

packages/insomnia-smoke-test/server · high confidence

Socket.IO request editing UI

The Socket.IO request pane now includes dedicated tabs for configuring the request body and event listeners. Users can add, edit, and delete multiple arguments in the Body tab, choosing between JSON and plaintext content types, and toggle acknowledgment (ack) for messages. The Events tab allows users to define unique event names, add descriptions, and enable or disable listeners, with validation to prevent duplicate event names. These components provide a structured interface for managing Socket.IO request parameters and event handling within the Insomnia UI.

packages/insomnia/src/ui/components/socket-io · high confidence

Removals

Removal of Font Awesome 4.0.3 assets

The Font Awesome 4.0.3 icon library files (CSS and SVG font) have been removed from the application's static assets. This change eliminates the legacy icon set from the build, which may affect any UI components that previously relied on these specific icon classes.

app/css/lib · high confidence

Removal of legacy Redux-based Todo application scaffold

The legacy Redux-based Todo application scaffold has been removed from the app directory. This change deletes the entry point (app/index.js), the store configuration (app/stores/configureStore.js) which previously set up Redux with thunk and logger middleware, and the action creators (app/actions/index.js) that handled local storage persistence for todo items. Users will no longer have access to this specific demo implementation within the application structure.

app · high confidence

Removal of legacy request reducer and root reducer configuration

The application has removed the legacy Redux reducer structure, specifically deleting the \app/reducers/index.js\ file that combined the root state and the \app/reducers/requests.js\ file that handled request state management. This change eliminates the previous implementation where adding a request simply appended a placeholder object with static properties (\foo: 'bar'\) to the state array, indicating a significant restructuring or removal of this specific data handling logic within the reducers directory.

app/reducers · high confidence

Removed legacy App container and Header component scaffolding

The legacy \app/containers/App.js\ container and \app/components/Header.js\ component have been removed from the application. This deletion eliminates the previous static sidebar layout, hardcoded request/response pane structure, and the associated \Header\ component, along with the now-unused \app/constants/actionTypes.js\ file. This change cleans up the codebase by removing obsolete UI scaffolding that is no longer part of the current application architecture.

app/containers · high confidence

Security

Renderer process security hardening and architecture migration

The renderer process has been migrated to a secure, isolated architecture that removes Node.js integration and enforces context isolation. This change introduces a strict IPC boundary where the renderer no longer accesses the database or services directly; instead, it communicates via a new \database.client.ts\ bridge and a \services-proxy\ that forwards calls to the main process. Authentication and session handling have been moved to the renderer with a new \auth-session-provider.client.ts\ that manages keypairs and login flows locally. Additionally, the renderer now hosts the global modal registry (\modals.tsx\), manages its own event bus for UI state, and initializes Sentry tracing, ensuring that sensitive operations and UI logic are decoupled from the main process while maintaining security.

packages/insomnia/src/ui · high confidence

Secure specification export and linting with SSRF protection

The Inso CLI now includes a new \export-specification\ command that supports a \skipAnnotations\ option to optionally strip \x-kong-\ vendor extensions from OpenAPI specs. Additionally, the \lint-specification\ command has been updated to enforce strict security controls when resolving remote references, blocking non-HTTPS URLs and resolving hostnames to ensure they do not point to private, loopback, or link-local addresses, thereby preventing Server-Side Request Forgery (SSRF) attacks during linting.

packages/insomnia-inso/src/commands · high confidence

Updated macOS code-signing entitlements for stricter security

The macOS build now enforces stricter code-signing policies by disabling the use of DYLD environment variables and library validation. This change improves the security posture of the application on macOS by preventing potential exploitation of dynamic linker behaviors and unsigned library injection.

packages/insomnia/src/static · high confidence

Windows secure wrapper mitigates DLL hijacking and fixes Squirrel update issues

A new C++ secure wrapper for the Windows installer mitigates a local search path vulnerability by enforcing Windows Process Mitigation Policies (signature and image load policies) to prevent loading hijacked DLLs from writable installation directories. This wrapper also resolves a bug where Squirrel-based updates failed to start the new version correctly and handles UTF-16 characters in installation paths, ensuring a stable and secure upgrade experience for Windows users.

packages/insomnia/src/cpp · high confidence

Architecture

Application initialization and security architecture overhaul

The application's startup sequence and security model have been significantly restructured. The main process now initializes the database, services, and runtime before creating any windows, ensuring a consistent state. A new hidden browser window is introduced to execute pre-request and post-response scripts in an isolated environment, improving stability and security. The renderer process now uses a dedicated preload script to expose a secure IPC bridge for services like sync, git, and MCP, replacing direct access to Electron APIs. Additionally, the entry point now handles deep-link imports and Konnect project migrations before the React app hydrates, and session data is migrated from localStorage to the new service layer.

packages/insomnia/src · high confidence

Centralized data access via new service layer

The application now routes all database operations through a dedicated service layer in \packages/insomnia-data/node-src/services\. This change introduces standardized CRUD APIs for core data models—including requests, environments, workspaces, and certificates—alongside specialized logic for features like request versioning, OAuth2 token management, and team project synchronization. A new \CONVENTIONS.md\ file establishes naming standards for these services, and the \index.ts\ file exposes the complete service registry to the renderer process via IPC, ensuring consistent and type-safe data access across the application.

packages/insomnia-data/node-src/services · high confidence

Data model and database layer restructured into the insomnia-data package

The data models and database access layer have been extracted into the new \insomnia-data\ package, introducing a unified \BaseModel\ schema and a dependency-injection pattern for the database (allowing different implementations for the main and renderer processes). This change adds support for new data types including MCP requests and responses, Git credentials with native provider support, and project lint rulesets, while also introducing a new 'Control Planes' organization structure for Konnect projects.

packages/insomnia-data/src/models · high confidence

Extracted insomnia-data into a standalone workspace package

The data layer for Insomnia has been extracted into a new \insomnia-data\ workspace package, providing a runtime-agnostic interface for database and service operations. This change introduces a structured layout with \src/\ for runtime-agnostic contracts and \node-src/\ for Node-specific implementations (such as NeDB), allowing the main, renderer, and Inso processes to share a consistent API while decoupling business logic from Electron and IPC details. The package includes configuration for TypeScript and Vitest testing, establishing the foundation for injecting different database implementations at startup.

packages/insomnia-data, packages/insomnia-data/node-src, packages/insomnia-data/src · high confidence

Behavioural changes

4 commits (2 fixes) modifying packages/insomnia/src/icons

A change to existing behaviour in packages/insomnia/src/icons — 4 commits (2 fixs), 5 files.

packages/insomnia/bin, packages/insomnia/src/icons · medium confidence · unverified

Add TypeScript type definitions for external libraries and global environment

This update introduces a new set of TypeScript declaration files in the \packages/insomnia/types\ directory to resolve type-checking issues with third-party dependencies and the application's runtime environment. The changes include definitions for \apiconnect-wsdl\, \codemirror-graphql\, \codemirror\, \httpsnippet\, \jsonlint-mod-fixed\, \objectpath\, and \tough-cookie\, ensuring type safety for these external modules. Additionally, \global.d.ts\ and \vite.d.ts\ define the global \Window\ interface (exposing Electron bridges, environment variables, and services) and Vite-specific constants, providing the necessary type context for the renderer process.

packages/insomnia/types · high confidence

Apply patches to npm dependencies to fix bugs and improve compatibility

This change introduces patch files to modify the behavior of three npm dependencies. The apiconnect-wsdl patch removes artificial limits on example generation size and nesting depth to prevent truncation of large schemas. The json-order patch fixes a bug where null values were incorrectly treated as objects during parsing. The tinykeys patch adds TypeScript type definitions to the package exports to improve type safety for consumers.

patches · high confidence

Auth editors migrated to new component structure with MCP OAuth support

The authentication editor UI in the Insomnia app has been restructured into a new modular component system located in \packages/insomnia/src/ui/components/editors/auth\. This change introduces dedicated React components for each authentication type (Basic, Bearer, OAuth 1/2, API Key, AWS, Hawk, Digest, NTLM, Netrc, ASAP, and Single Token), all orchestrated by a new \AuthWrapper\ that handles type selection and rendering. A key behavioral addition is support for the MCP (Model Context Protocol) OAuth flow, which adds a new 'MCP Auth Flow' grant type option to the OAuth 2 editor and includes specific UI controls for state, scope, and manual browser launch configuration. The migration also standardizes input handling across all auth types using shared sub-components like \AuthInputRow\ and \AuthTableBody\, ensuring consistent masking of sensitive fields (passwords, secrets, tokens) and uniform toggle behavior.

packages/insomnia/src/ui/components/editors/auth · high confidence

Automatic data migration for legacy Insomnia workspaces

Insomnia now automatically migrates legacy data structures when opening workspaces, ensuring compatibility with the current data model. This process extracts embedded client certificates into their own records, normalizes workspace scopes (mapping old 'spec' and 'designer' values to 'design'), and fixes request bodies and authentication types. Additionally, it assigns missing IDs to cookies, sets a default 'manual' source for legacy cookies, and resolves hotkey conflicts between creating requests and opening the sidebar dropdown. Users with older data will see their workspaces updated seamlessly without manual intervention.

packages/insomnia-data/node-src/database/init-model · high confidence

Basic authentication header generation now supports Latin-1 encoding

The basic-auth module now allows users to specify 'latin1' as an encoding option when generating the Authorization header, in addition to the existing UTF-8 support. This change ensures that credentials containing non-UTF-8 characters are correctly encoded according to the specified character set, improving compatibility with servers that expect Latin-1 encoded Basic Auth headers.

packages/insomnia/src/network/basic-auth · high confidence

Bearer authentication header generation trims whitespace from tokens and prefixes

The Bearer authentication logic in the network layer now automatically trims leading and trailing whitespace from both the authentication token and the optional prefix before constructing the Authorization header. This ensures that headers like 'Authorization: Bearer my-token ' are normalized to 'Authorization: Bearer my-token', preventing authentication failures caused by accidental extra spaces in user input.

packages/insomnia/src/network/bearer-auth · high confidence

CSS architecture overhaul with Tailwind v4 and layered imports

The application's styling system has been restructured to use Tailwind CSS v4, introducing a new \styles.css\ entry point that leverages CSS cascade layers to manage import precedence for libraries like CodeMirror, Monaco Editor, and Font Awesome. This change replaces the previous \main.css\ reset and boilerplate with Tailwind's native reset and integrates custom theme animations and grid layouts directly into the new configuration, ensuring consistent styling across the UI components.

packages/insomnia/src/ui/css · high confidence

Centralize IPC handlers in the main process

The application now routes critical operations—including gRPC requests, cookie management, file system access, secret storage, and Git synchronization—through dedicated IPC handlers in the main process. This shift ensures that sensitive tasks like reading files, managing OAuth tokens, and handling gRPC reflection are executed in the secure main context rather than the renderer, improving security and enforcing stricter execution-context boundaries.

packages/insomnia/src/main/ipc · high confidence

Centralized application lifecycle hooks

The application now uses a dedicated \AppHooks\ component to manage global side effects at startup. This component consolidates logic for settings synchronization, global keyboard shortcuts, theme changes, and Customer.io integration into a single location, ensuring these features are initialized consistently when the app loads.

packages/insomnia/src/ui/containers · high confidence

Circular dependency checks now use dependency-cruiser with Windows support and baseline drift detection

The project has replaced the previous circular-reference checking tool with dependency-cruiser, introducing a new script in scripts/circular-references that scans npm workspaces for circular imports. This change adds Windows compatibility by bypassing the dependency-cruiser binary shim to avoid shell-execution issues, and introduces a baseline file (known-violations.json) that distinguishes between new circular dependencies (regressions) and removed ones (drift), allowing CI to report the specific nature of any failure.

scripts · high confidence

Cloud sync now uses one VCS instance per workspace

The cloud sync system has been restructured to maintain a separate Version Control System (VCS) instance for each workspace, replacing the previous singleton approach. This change, implemented in the main process cloud-sync module, ensures that sync operations for one workspace do not interfere with others, particularly when handling concurrent backend project pulls or local modifications. The new architecture introduces dedicated initialization logic to set up backend projects and mark them for sync, an IPC bridge to route workspace-specific VCS commands (like checkout, pull, push, and conflict resolution) to the correct instance, and a dedicated handler for pulling remote backend projects that correctly updates local database records and workspace parent IDs.

packages/insomnia/src/main/cloud-sync · high confidence

Deferred service initialization with pre-init destructuring support

The services module now supports deferred initialization, allowing application code to destructure service methods before the underlying implementation is ready. A new \initServices()\ function registers the implementation, and a Proxy-based \services\ object ensures that any method calls made prior to initialization throw a clear error, while calls made after initialization are correctly routed to the registered implementation. This change also introduces strongly-typed interfaces for workspace children (e.g., \CollectionWorkspaceChildren\, \DesignWorkspaceChildren\) that map specific workspace scopes to their respective data structures, improving type safety for workspace data access.

packages/insomnia-data/src/services · high confidence

The base dropdown component in the UI library has been completely rewritten as a set of React function components leveraging the React Aria and React Stately libraries. This change replaces the previous implementation with a new architecture that uses React Aria's hooks (such as useMenuTrigger, useMenu, and usePopover) to handle accessibility, keyboard navigation, and state management. The new structure includes dedicated components for the dropdown trigger, menu, menu items, sections, and popovers, along with a new DropdownHint component to display keyboard shortcuts. This refactor improves accessibility compliance and interaction consistency for all dropdown menus within the application.

packages/insomnia/src/ui/components/base/dropdown · high confidence

The dropdown components in the sidebar and request editor have been rewritten as function components using React Aria (react-aria-components), replacing the previous implementation. This migration introduces a consistent, accessible UI for authentication, content type, HTTP method, and preview mode selection, while also adding new dropdowns for Git project synchronization and MCP client actions.

packages/insomnia/src/ui/components/dropdowns · high confidence

Editor undo history now persists across tab switches and remounts

The CodeMirror-based editors in Insomnia now retain their undo/redo history when you switch between tabs or when the editor component remounts (for example, toggling between markdown write and preview modes). This is achieved by caching the editor state using a stable \historyKey\ and purging that cache only when the owning tab closes or a key-value row is deleted, preventing stale entries from crowding out live editors. A unified app-level undo handler ensures that keyboard shortcuts and the Edit menu correctly drive either the CodeMirror history or the native browser stack depending on which element is focused, resolving previous conflicts where native undo commands would interfere with CodeMirror's internal state.

packages/insomnia/src/ui/components/.client/codemirror · high confidence

The CodeMirror editor now includes new extension modules that improve the editing experience: environment autocomplete is now triggered by configurable hotkeys and context (variables, constants, snippets, and tags) with a custom hint container; URLs in the editor content are automatically detected and made clickable for direct interaction; and Nunjucks template tags are highlighted with live rendering previews, support drag-and-drop, and open a modal for editing when clicked.

packages/insomnia/src/ui/components/.client/codemirror/extensions · high confidence

Enhanced code linting for JavaScript and JSON editors

The code editor now provides improved validation for JavaScript and JSON content. JavaScript linting has been updated to support top-level await expressions by wrapping code in an async function during analysis, ensuring accurate error reporting for modern syntax. JSON linting now pre-renders Liquid templates before parsing, allowing the linter to validate the final rendered values rather than the raw template syntax, which reduces false positives when using dynamic content.

packages/insomnia/src/ui/components/.client/codemirror/lint · high confidence

Git sync now stores Insomnia data as YAML files on disk alongside the .git directory

Git-synced projects now use a new on-disk layout where Insomnia workspace data is persisted as YAML files inside an \.insomnia\ directory, rather than being stored exclusively in the local NeDB database. This change introduces a bidirectional sync pipeline: the \RepoFileWatcher\ keeps the on-disk YAML files and the NeDB database in sync, allowing external tools and native Git CLI commands to interact directly with the repository's files. Existing repositories are automatically migrated to this new structure via a versioned migration process that moves data from the old \git/\ and \other/\ directories to the new layout. The sync engine also now uses a custom HTTP client to respect system proxy and certificate settings, and routes file operations through specialized clients to handle the new directory structure correctly.

packages/insomnia/src/sync/git · high confidence

Improved Git authentication status and re-authentication flow

The Git connection UI now proactively detects and displays warnings when OAuth access tokens have expired or when repository operations fail with HTTP 401/403 errors. A new banner component allows users to re-authenticate directly from the interface, supporting both automatic redirects and manual pasting of authentication codes. Additionally, a new connection info panel displays the current base branch, and a warning banner guides users when a branch tracks a non-origin remote, providing copyable CLI commands to fix the upstream configuration.

packages/insomnia/src/ui/components/git · high confidence

Improved cURL detection and environment key validation

The application now more accurately detects cURL commands in the input UI, correctly handling shell prompts, case variations, and preventing false positives on URLs like curl.se. Additionally, environment variable keys are now strictly validated to prevent NeDB storage errors by rejecting keys that begin with '$' or contain periods, while also enforcing reserved key restrictions for templating and vault paths.

packages/insomnia/src/common/utils · high confidence

Improved cURL import accuracy and expanded OpenAPI 3 schema support

The cURL importer now correctly handles complex data flags (such as -d, --data, --data-binary, and --data-urlencode) including raw text bodies with multiple equals signs, file references, and URL-encoded characters, while also fixing issues with missing equals signs and Bearer authorization headers. Additionally, the OpenAPI 3 importer now supports schema composition keywords (allOf, oneOf, anyOf) for example request generation and correctly flattens nested object-type query parameters into bracket notation.

packages/insomnia/src/main/importers/importers · high confidence

Improved tab navigation and deletion fallback behavior

The tab interface now supports closing tabs with a middle-mouse click and includes keyboard shortcuts to navigate between and reopen closed tabs. Additionally, when a request tab is deleted, the application intelligently navigates to the request's parent folder or collection root instead of bouncing back to the project dashboard, ensuring a smoother workflow when managing open tabs.

packages/insomnia/src/ui/components/tabs · high confidence

Inso CLI build and test infrastructure modernization

The Inso CLI package has been restructured to use esbuild for bundling, replacing the previous build system, and has migrated its test runner from Jest to Vitest. This change introduces a new \esbuild.ts\ configuration that targets Node 22 and handles platform-specific module resolution, alongside updated \tsconfig.json\ and \vitest.config.ts\ files to support the new tooling. Additionally, a Dockerfile has been added to facilitate CI-based packaging of the CLI binary, and the \.gitignore\ has been updated to manage the new \artifacts\ directory structure.

packages/insomnia-inso · high confidence

Insomnia app package restructured with new build and test tooling

The \packages/insomnia\ directory has been reorganized to support a modernized build and development workflow. A new \esbuild.entrypoints.ts\ script now handles the bundling of Electron main, preload, and hidden window processes, while \vite.config.ts\ and \react-router.config.ts\ configure the renderer and routing. Build artifacts are now managed via a new \.gitignore\ and \electron-builder.config.js\ for packaging. Additionally, testing infrastructure has been updated with new \vitest\ configurations (\vitest.config.ts\, \vitest.sandbox-vendored-regression.config.ts\) and a \setup-vitest.ts\ file to initialize the database and services for tests.

packages/insomnia · high confidence

Introduce Mocha-based test runner with request interception

The \packages/insomnia-testing/src/run\ directory now implements a new test execution engine using Mocha instead of the previous runner. This change introduces an \Insomnia\ global helper that allows tests to send HTTP requests via a provided \sendRequest\ callback, enabling integration testing of API calls. A custom \JavaScriptReporter\ is included to capture test results as structured data rather than printing to stdout, and a \require\ interceptor is injected to safely resolve modules like \chai\ and \chai-json-schema\ within the test sandbox. The \runTests\ function now returns structured pass/fail statistics, and the \runTestsCli\ function provides a boolean success indicator.

packages/insomnia-testing/src/run · high confidence

Introduce inso-specific database model layer with enhanced identifier matching

The inso CLI now uses a dedicated database model layer in \packages/insomnia-inso/src/db/models\ to load and prompt for resources like workspaces, API specs, environments, and unit test suites. This implementation adds support for matching resources by their \name\ or \fileName\ in addition to the existing ID-based matching, allowing users to select items using more human-readable identifiers. It also introduces improved environment selection logic that distinguishes between base and sub-environments, providing clearer error messages in CI mode when multiple environments are present, and adds a unified prompt for selecting documents or test suites.

packages/insomnia-inso/src/db/models · high confidence

Introduces a unified runtime adapter layer for cross-process capability execution

The application now routes core capabilities—network requests, templating, secret storage, crypto operations, and imports—through a new adapter layer in \src/runtimes\ that distinguishes between Node (main process/CLI) and Renderer (UI) execution contexts. This change enables user-installed plugins to execute their request and response hooks inside an isolated QuickJS sandbox by default, with elevated plugins and the CLI running hooks in-process as before. It also adds support for user prompts in the main process and ensures that plugin hook mutations are safely merged without exposing internal object identities to sandboxed code.

packages/insomnia/src/runtimes · high confidence

Invite modal restructured with encryption logic and role-based access control

The invite modal has been refactored to support inviting team members from both Organizations and Electron contexts, introducing a new encryption module that handles RSA-based key re-encryption for secure project key sharing. The UI now includes a role selector that enforces Role-Based Access Control (RBAC), restricting role changes to users with appropriate permissions or upgraded plans, and integrates seat-checking logic to manage invitation limits based on the user's subscription tier.

packages/insomnia/src/ui/components/modals/invite-modal · high confidence

Key-Value Editor reimplementation with drag-and-drop and improved persistence

The Key-Value Editor component has been rewritten to use React Aria components, introducing native drag-and-drop reordering for key-value pairs and a more robust persistence model. The trailing blank row is now purely visual and is not persisted to the data model until the user begins typing, preventing empty rows from appearing in diffs. Additionally, the editor now ensures unique IDs for rows to avoid stale state issues and supports read-only pairs with disabled states, improving usability for headers and environment variables.

packages/insomnia/src/ui/components/key-value-editor · high confidence

Migrate common utilities to insomnia-data and introduce API spec parsing

The \packages/insomnia/src/common\ module has been refactored to rely on the new \insomnia-data\ package for core data models and database operations, replacing the previous NeDB-based implementation. A new \api-specs.ts\ utility has been added to parse, detect, and convert OpenAPI/Swagger specifications between JSON and YAML formats, and the import logic has been updated to use Zod schemas for validating Insomnia v5 export files.

packages/insomnia/src/common · high confidence

Migrate core application state to a new database layer and restructure main process

The application's main process has been reorganized into a new directory structure, introducing a dedicated database layer (insomnia-data) that replaces previous storage mechanisms. This change migrates user settings and session data from LocalStorage to the new database service, introduces a new Electron-based storage implementation for legacy compatibility, and establishes a centralized analytics module that hashes user account IDs for privacy. Additionally, the main process now handles custom protocol registration for internal networking and provides a proxy for database access to plugin windows, ensuring consistent data access across the application.

packages/insomnia/src/main · high confidence

Migrate templating engine from Nunjucks to LiquidJS

The templating engine used for rendering templates in Insomnia has been switched from Nunjucks to LiquidJS. This change updates the core rendering logic in the \templating\ module to use the LiquidJS library, introducing new syntax for variable interpolation (\{{ }}\) and control flow (\{% %}\), while maintaining compatibility with existing template tags and plugin integrations through a new Liquid-based tag extension system.

packages/insomnia/src/templating · high confidence

Migration to Vitest with updated mock implementations

The test infrastructure has been migrated to Vitest, replacing the previous testing setup. This change updates the mock files in the common and gRPC network modules to use Vitest's \vi\ API instead of the previous framework's mocking functions. Specifically, the \render\ mock now uses \vi.requireActual\ and \vi.fn()\ to mock gRPC request rendering functions, while the gRPC module mock exports standard functions like \start\, \sendMessage\, and \commit\ as Vitest mocks. This ensures that tests relying on these mocked behaviors continue to function correctly under the new Vitest runner.

packages/insomnia/src/common/\\mocks\\, packages/insomnia/src/network/grpc/\\mocks\\_ · high confidence_

Modals migrated to functional components and React Aria

The modal dialogs in the application have been refactored from class-based components to functional components and now utilize the React Aria component library. This change standardizes the modal architecture, improving accessibility and aligning the UI implementation with modern React patterns.

packages/insomnia/src/ui/components/modals · high confidence

New Git credentials management interface

The Git credentials workflow has been redesigned with a dedicated setup screen that allows users to authenticate via GitHub or GitLab OAuth, or manually add a custom access token. A new credential selector component displays the provider, display name, and author for each saved credential, and includes a link to manage credentials in Preferences. Repository and branch selection components now support fuzzy matching for easier searching, and the repository picker provides specific guidance and configuration links for GitHub App users.

packages/insomnia/src/ui/components/git-credentials · high confidence

New Playwright-based smoke test infrastructure with robust process management

The smoke test suite has been migrated to Playwright, introducing a new test runner that launches the Insomnia Electron application with configurable environment variables for API mocking, OAuth providers (GitHub, GitLab), and Konnect integration. This change adds a dedicated launch utility that tracks all running Electron instances to ensure graceful cleanup, including a custom process-tree killer to prevent hanging worker processes by terminating child processes on Windows and Unix systems. The test fixtures now support pre-seeding settings and copying fixture databases to isolated temporary data paths, allowing tests to start with specific configurations without relying on app defaults.

packages/insomnia-smoke-test/playwright · high confidence

New UI tags for request methods, status, and timing

The response view now displays dedicated tags for HTTP method, status code, response size, and timing. Method tags use color-coded badges for standard HTTP verbs as well as WebSocket (WS), Socket.IO (IO), gRPC, and MCP, with shortened labels for longer methods. Status tags color-code responses by class (1xx–5xx) and handle unknown messages. Size tags show read vs. content bytes, and time tags break down request timing steps in a tooltip.

packages/insomnia/src/ui/components/tags · high confidence

New build, schema, and sandbox tooling scripts

The \packages/insomnia/scripts\ directory now includes several new build and tooling scripts. \build.ts\ enforces Node 24 for building and copies static assets and hidden/plugin window HTML files. \generate-schema.ts\ produces a versioned JSON Schema for Insomnia v5 files from the Zod source of truth. \nsisInstall.nsh\ adds custom NSIS installer logic for uninstalling previous versions and writing installer metadata. A new sandbox-vendored toolchain (\check-sandbox-vendor-guardrail.ts\, \generate-sandbox-vendored.ts\, \sandbox-vendored-lib.ts\, \sandbox-vendored-libs-list.ts\, \upgrade-sandbox-vendored.ts\) manages vetted npm libraries (uuid, ajv) for the template-tag sandbox, ensuring version pins and guardrails. Finally, \install-x64-native-dependencies.ts\ handles native dependency extraction for macOS x64, and \verify-bundle-plugins.ts\ checks for required bundle plugins in CI.

packages/insomnia/scripts · high confidence

New build, signing, and documentation scripts for Inso CLI

This change introduces several new scripts in the \insomnia-inso\ package to support the release and distribution of the Inso CLI. The \artifacts.ts\ script handles compressing binaries for macOS, Windows, and Linux. A new \macos-pkg.sh\ script automates the code signing and notarization of macOS installers using specific entitlements defined in \codesign.entitlements\ (which allows library validation and unsigned executable memory access for compatibility with \node-libcurl\ and older Node versions). Additionally, \docs.ts\ adds the capability to automatically generate Markdown documentation from the CLI's source code, while \verify-pkg.js\ provides a smoke test to verify the packaged binary functions correctly.

packages/insomnia-inso/src/scripts · high confidence

New editor components for environment, mock, and request configuration

This change introduces a suite of new UI editor components in the \packages/insomnia/src/ui/components/editors\ directory, replacing or refactoring previous implementations. The \EnvironmentEditor\ now uses \orderedJSON\ to preserve property ordering and includes a Windows-specific fix for Nunjucks file-tag backslash escaping. The \MockResponseExtractor\ component allows users to transform active request responses into mock server routes, with logic that restricts cloud mock creation in local projects and handles self-hosted server constraints. New \MockResponseHeadersEditor\ and \RequestHeadersEditor\ components provide both bulk text editing and key-value pair interfaces for headers, with the latter introducing read-only pairs for WebSocket and HTTP requests (e.g., \Connection\, \Upgrade\, \User-Agent\) that can be disabled. The \RequestParametersEditor\ handles query parameters with bulk editing support, and the \RequestScriptEditor\ provides a comprehensive code editor with snippets for variable management, request manipulation, and testing, including support for folder-level environment variables.

packages/insomnia/src/ui/components/editors · high confidence

New environment key-value editor with vault support and improved stability

The environment editor now uses a dedicated key-value component that supports text, JSON, and secret types, with automatic decryption for secrets stored in the vault. The implementation prevents UI flickering and state corruption by ensuring unique IDs for list items and avoiding the reuse of blank-row IDs, while also disabling the persistence of trailing empty rows to keep diffs clean.

packages/insomnia/src/ui/components/editors/environment-key-value-editor · high confidence

New gRPC method dropdown with package grouping

The gRPC method selection interface has been replaced with a new dropdown component that groups available methods by their protobuf package. This component uses react-aria-components to provide an accessible select menu, displaying methods in sections labeled by package name (or 'No package' for ungrouped methods) and showing a short path for each method. It also displays an acronym indicating the method type (unary, server-streaming, client-streaming, or bidirectional) alongside the method name.

packages/insomnia/src/ui/components/dropdowns/grpc-method-dropdown · high confidence

New modular auth editor components

The authentication editor now uses a set of new, reusable UI components (AuthAccordion, AuthInputRow, AuthPrivateKeyRow, AuthSelectRow, AuthToggleRow, etc.) to render authentication settings. These components provide a consistent, table-based layout for editing auth properties, support masking passwords with show/hide toggles, handle private key editing via a modal, and allow toggling auth on/off or selecting options, all while integrating with the request loader data and patchers to update the active request or request group.

packages/insomnia/src/ui/components/editors/auth/components · high confidence

New plugin infrastructure and theme validation

This change introduces new files that establish the core plugin system and enforce stricter theme rules. A new sealed-box encryption utility is added to the main process utils, and a plugin creation helper is exposed to the UI. Crucially, the plugin theme system now validates against Nunjucks template syntax, which was removed in July 2022; themes containing such syntax will now trigger console errors rather than silently failing, and theme names are automatically normalized to lowercase with spaces replaced by hyphens.

packages/insomnia/src/main/utils, packages/insomnia/src/ui/plugins · high confidence

New scripting environment object model and Liquid templating engine

The scripting environment now uses a new set of object models (located in \packages/insomnia-scripting-environment/src/objects\) to represent requests, responses, environments, variables, and other entities, replacing the previous implementation. This change introduces a new templating engine based on LiquidJS for variable interpolation, which affects how placeholders are resolved in scripts. The \Environment\ class now supports automatic conversion of objects to strings when passed to \replaceIn\, and the \InsomniaObject\ now exposes a \baseEnvironment\ for global base environment support. Additionally, the \Console\ class provides a structured logging interface with levels (debug, info, log, warn, error) and the \Execution\ class allows scripts to control request flow via \skipRequest\ and \setNextRequest\.

packages/insomnia-scripting-environment/src/objects · high confidence

New unified body editor components for request bodies

The request body editing interface has been restructured into a new set of dedicated components located in \packages/insomnia/src/ui/components/editors/body\. This change introduces a central \BodyEditor\ that dynamically renders specific editors based on the content type: \RawEditor\ for arbitrary text, \GraphQLEditor\ for GraphQL requests, \FormEditor\ and \UrlEncodedEditor\ for form data, and \FileEditor\ for file uploads. The \GraphQLEditor\ now includes a dedicated \prettify-graphql\ utility for formatting queries, while the form editors utilize a shared \KeyValueEditor\. These components handle body state updates via a \useRequestPatcher\ hook, providing a consistent and modular editing experience for all request body types.

packages/insomnia/src/ui/components/editors/body · high confidence

OAuth2 request logs now appear in the Console timeline

Users can now see the full details of OAuth2 authentication requests (including token exchanges, refresh attempts, and errors) directly in the main Console (Timeline) tab alongside the API request, instead of only seeing them in a hidden debug modal. This change threads OAuth2 timeline entries from the token retrieval process into the main request's timeline, making it easier to debug authentication failures.

packages/insomnia/src/main/network/o-auth-2 · high confidence

Optimized Nunjucks rendering with promise caching in the editor

The Nunjucks template rendering engine used in the editor now utilizes a promise-based caching mechanism to avoid redundant context resolution and race conditions during parallel renders. This change improves performance by reusing previously fetched render contexts for the same cache key within a short window, ensuring faster template evaluation for users writing or previewing Nunjucks templates in requests and workspaces.

packages/insomnia/src/ui/context/nunjucks · high confidence

Plugin sandboxing with per-plugin permission declarations and elevated trust opt-in

Insomnia now supports a plugin sandboxing model that restricts third-party plugins to a default-deny execution environment. This change introduces a new \insomnia.permissions\ manifest field where plugins can explicitly declare the Node.js modules and host capabilities they require. By default, user plugins run in a restricted sandbox; however, users can opt specific plugins into full host access (the 'elevated' escape hatch) via the plugin's configuration or the Preferences → Plugins pane. The system also displays validation warnings for malformed permission declarations and distinguishes between plugins that explicitly declare no permissions versus those with no manifest at all.

packages/insomnia/src/common/plugins · high confidence

Plugin system restructured with sandboxed execution and strict validation

The plugin loading and execution logic in \packages/insomnia/src/plugins\ has been restructured to support a new security model where user-plugin template tags and actions are discovered and executed within a QuickJS sandbox rather than the main Node.js context. This change introduces stricter validation for plugin names to prevent prototype pollution and path traversal attacks, and enforces a trust model where user plugins must opt-in to elevated permissions. The plugin manifest now exposes an export map that is used to build stub modules, with actual execution routed through a dedicated templating worker database protocol. Bundle plugins and those with the sandbox flag disabled continue to run in-process, while user plugins run in the sandbox, improving isolation and security for custom code.

packages/insomnia/src/plugins · high confidence

Plugin template tags now run in an isolated QuickJS sandbox with manifest-gated permissions

When the 'Run template tags in sandbox' preference is enabled, plugin template-tag \run()\ methods execute inside an isolated QuickJS environment rather than the host Node process. This sandbox enforces a default-deny security model where plugins must explicitly declare required permissions in their \package.json\ manifest. Access to modules is restricted to a curated registry of vetted safe equivalents (such as \path\, \crypto\, \events\, \uuid\, and \ajv\), preventing access to raw Node builtins. Host-side capabilities like network access, storage, and file reading are gated behind specific capability grants, ensuring plugins can only perform actions they have been explicitly authorized to perform.

packages/insomnia/src/templating/sandbox · high confidence

Redesigned project creation and settings workflows with Git Sync and organization management

The project creation and settings interfaces have been rebuilt to support a unified workflow for Local, Cloud Sync, and Git Sync projects. Users can now select a project type, manage Git credentials, and clone or adopt Git repositories directly from the project modal, including the ability to choose a custom local folder for Git projects. The organization selector has been enhanced with local filtering and options to join or create organizations based on the user's plan. Additionally, the new flow includes a scan step for Git repositories to detect existing Insomnia files and a migration banner for legacy content, while the empty project view now tracks analytics for user actions.

packages/insomnia/src/ui/components/project · high confidence

Redesigned templating and variable editors with vault integration

The templating and variable editing interfaces in the Insomnia UI have been refactored to support external vaults and improved usability. The new Tag Editor component now dynamically renders specialized configuration forms (such as the ExternalVaultForm) for supported tags, allowing users to manage vault credentials directly within the tag argument interface. The Variable Editor has been updated to provide live preview functionality for environment variables, including specific handling for vault variables that may display masked values, and allows selection of custom template logic alongside standard environment variables.

packages/insomnia/src/ui/components/templating · high confidence

Refactored account session management and credential deletion logic

The account session handling in the renderer process has been reorganized into a dedicated \session.ts\ module, which now centralizes logic for absorbing encryption keys, managing user sessions, and handling logout. A key behavioral change is the robustification of the logout flow: it no longer throws if the API call fails, ensuring users can always sign out even during network issues. Additionally, the credential removal process has been expanded to systematically clear Git provider credentials, custom Git repository associations, LLM provider API keys, and proxy authentication details, ensuring a complete cleanup of sensitive data upon logout.

packages/insomnia/src/ui/account · high confidence

Refactored importers to run in Node with a new conversion pipeline

The import logic in the main process has been refactored to run in Node.js, introducing a new \convert.ts\ pipeline that iterates through available importers and normalizes results. This change adds a new \entities.ts\ schema for import requests and a \utils.ts\ module that applies default values (such as setting the parent ID to \\_\_WORKSPACE\ID\\\ for requests and \\\_BASE\_ENVIRONMENT\ID\\_\ for environments) and validates keys to prevent errors with nested properties. The update also includes tests for these new utility functions.

packages/insomnia/src/main/importers · high confidence

Refactored network request execution into a modular runtime architecture

The network layer in \packages/insomnia/src/network\ has been restructured to support distinct execution contexts (renderer, Node.js, and unit tests) via new entry points like \send-request.node.ts\ and \unit-test-feature.ts\. This change introduces explicit handling for request cancellation via \cancellation.renderer.ts\, enforces folder-level inheritance for authentication and headers through \network.ts\, and adds support for API Key authentication in headers, query parameters, and cookies. Additionally, cookie persistence logic has been refined in \set-cookie-util.ts\ to correctly track cookie provenance (distinguishing between manual and response-sourced cookies) and certificate matching now supports wildcard patterns and fallback port checks.

packages/insomnia/src/network · high confidence

Removal of legacy Webpack configuration files

The project has removed the legacy Webpack configuration files (base.config.js, dev.config.js, and prod.config.js). This change eliminates the previous build setup, which included specific loaders for Babel, SCSS/CSS, HTML, and various font formats, as well as development-specific settings like hot module replacement and source maps. Users should expect that the build process will no longer rely on these specific configurations, implying a migration to a new or different build system or configuration structure.

webpack · high confidence

Removal of legacy layout SCSS modules

The specific layout styles for forms, headers, and panes have been removed from the application. This deletes the dedicated SCSS files that previously defined visual properties for form controls, buttons, header sections, and pane containers, indicating a shift in how these UI components are styled or structured.

app/css/layout · high confidence

Removal of legacy request, response, and sidebar component styles

The specific SCSS files defining styles for the request, response, and sidebar components have been deleted. This removes the previous visual definitions for these areas, including background colors, header styling, and sidebar item layouts, indicating a structural or thematic overhaul of the user interface.

app/css/components · high confidence

Removed SCSS constants for colors and dimensions

The application no longer uses the SCSS files defining global color variables (such as primary, light, and dark backgrounds) and dimension constants (including font sizes, padding, header height, and sidebar width). This removal indicates a shift in how styling is managed, likely moving towards a different CSS preprocessor or inline styling approach, which will affect the visual appearance and layout of components that previously relied on these specific SCSS variables and utility classes.

app/css/constants · high confidence

Removed legacy CSS reset and base layout styles

The application has removed several foundational CSS files, including the Meyer Web CSS reset, base typography and body styles, and the previous flexbox-based grid system. This cleanup eliminates redundant global resets and the old grid implementation, likely as part of a broader shift to modern CSS Grid or a new styling architecture.

app/css · high confidence

Renamed CLI entry point from insomnia-cli to insomnia-inso

The command-line interface tool has been renamed from 'insomnia-cli' to 'insomnia-inso'. This change updates the binary entry points in the bin directory, replacing the previous executable scripts with new ones that invoke the underlying Node.js module. A new debug helper script was also added to support VS Code launch configurations, allowing developers to pass extra arguments for debugging purposes.

packages/insomnia-inso/bin · high confidence

Support for Unix sockets and secure proto file handling in gRPC

gRPC requests now support Unix sockets via the 'unix:' URL scheme, allowing connections to local endpoints. Additionally, proto files are now written to a dedicated temporary directory ('insomnia-grpc') with path validation to prevent directory traversal, ensuring safer and more isolated file operations during request execution.

packages/insomnia/src/network/grpc · high confidence

Templating engine overhaul and expanded test coverage

The templating system has been significantly refactored to support a new LiquidJS engine alongside the existing Nunjucks engine, introducing features such as strict variable checking, sandboxed file access, and a web-worker bridge for plugin hooks. This change also adds a comprehensive suite of local template tags (including Faker, Base64, UUID, and OS info) and introduces robust serialization logic to safely pass render contexts across process boundaries. Additionally, the update includes extensive new test coverage for template tag behavior, argument tokenization, and context serialization, ensuring reliability for these core templating capabilities.

packages/insomnia/src/common/templating · high confidence

Unified database loading with multi-source support in Inso CLI

The Inso CLI now uses a centralized database loading mechanism that automatically detects and loads data from three distinct sources: Insomnia export files, Git repositories, and local Insomnia application data directories. This change replaces previous ad-hoc loading logic with a unified adapter pattern, allowing users to specify a working directory or file path and have the CLI intelligently resolve the correct data source, while providing clear guidance via error messages if no valid source is found.

packages/insomnia-inso/src/db · high confidence

Updated icon library and added code editor styling

The application's icon library has been upgraded to Font Awesome 6.2.0, introducing new brand icons, animations, and size utilities while maintaining backward compatibility through v4 shims. Additionally, new CSS styles have been added for the CodeMirror editor, including a default theme, a Material color scheme, and a dark theme specifically for the merge-view addon to support side-by-side diff comparisons.

packages/insomnia/src/ui/css/lib · high confidence

Updated legacy database fixtures for smoke tests

The \insomnia-legacy-db\ fixture files have been refreshed to include new \ApiSpec\ records (containing Swagger Petstore OpenAPI definitions) and updated \CookieJar\, \Environment\, and \GitRepository\ entries. This change ensures the smoke-test fixtures remain consistent with the current application state, preventing test failures caused by stale or missing legacy data.

packages/insomnia-smoke-test/fixtures/insomnia-legacy-db · medium confidence

VCS sync initialization and project migration logic

The VCS sync module now includes logic to initialize local backend projects for workspaces, automatically staging all descendants and lint rulesets for the initial snapshot, and handles race conditions during workspace activation. It also provides migration utilities to move legacy projects (without organizations) into the new organization hierarchy by updating parent and remote IDs, and introduces error handling for user-aborted merge conflicts in the VCS resolution process.

packages/insomnia/src/sync/vcs · high confidence

Workspace pane header and navigation breadcrumbs updated

The workspace pane header now displays dynamic breadcrumbs that reflect the current navigation path (project, workspace, request group, or request) using a new ResourceIcon component to visually distinguish resource types. The header also integrates an EnvironmentPicker that supports both workspace and project-level environment selection, along with buttons for managing cookies and certificates, with specific handling for MCP workspaces to adjust UI elements like cookie visibility and certificate status indicators.

packages/insomnia/src/ui/components/workspace · high confidence

Fixes

Database layer reimplementation with NeDB and repair utilities

The database implementation in the node environment has been replaced with a new NeDB-based backend (database-nedb.ts), introducing change buffering, automatic flush timers, and explicit change notifications for operations like document duplication. Additionally, a repair-database module was added to automatically fix legacy data issues, including merging multiple base environments or cookie jars per workspace, correcting API spec filenames, and appending .git to old Git URIs.

packages/insomnia-data/node-src/database · high confidence

Fix for missing user plugin template tags after reload

Resolves an issue where user-installed plugin template tags (such as those from HMAC plugins) would remain unavailable in templating even after clicking the 'Reload' button in Settings. This occurred because the templating web worker cached its Liquid engine at startup; if a plugin was discovered after that initial build, the worker never re-scanned for it. The fix ensures that reloading the plugin registry now properly invalidates the worker's cached engine, allowing newly discovered or re-enabled plugin tags to be used in subsequent renders.

packages/insomnia/src/ui/worker · high confidence

Fix missing CA and certificate fixtures in CLI database loading

Added placeholder CA, certificate, and key fixture files (fake\_ca.pem, fake\_cert.pem, fake\_key.pem) to the inso CLI package. This resolves an issue where these certificate resources were not included when loading the database from the CLI, ensuring that tests and operations relying on these fixtures now have the necessary data available.

packages/insomnia-inso/src/db/fixtures/certs · high confidence

Insomnia schema migration to version 5.1

The application now includes a schema migration system that automatically upgrades legacy Insomnia data files to version 5.1 upon import. This migration cleans up internal bookkeeping fields by removing \id\ properties from headers, parameters, and body params, and strips timestamp metadata (\creation\, \lastAccessed\) from cookies. It also filters out empty or invalid entries from these arrays and normalizes script objects, ensuring that imported collections are consistent with the current data model without altering the underlying OpenAPI specification contents.

packages/insomnia/src/common/insomnia-schema-migrations · high confidence

User-installed plugin template tags now resolve correctly in rendered templates

Fixed a bug where template tags defined by user-installed plugins (e.g., {% requestbodyhmac %}) were not found during rendering, despite being available in the editor autocomplete. The templating worker now correctly fetches and merges user plugin tags into the Liquid engine, routing their execution back to the main process via IPC. Additionally, the system now properly resolves variable references (like \_.body) within tag arguments, ensuring dynamic content is evaluated rather than treated as literal strings.

packages/insomnia/src/ui/templating · high confidence

Test coverage

Added Electron mock for testing; Added Playwright page objects for Insomnia Preferences tabs; Added bare Git repository fixture for smoke tests; Added compatibility tests for the LiquidJS templating engine migration; Added critical smoke tests for backup, bundling, certificates, and scratchpad; Added gRPC test fixtures for smoke testing; Added integration tests for the testing package; Added mock for @grpc/grpc-js to support Vitest testing; Added sample fixture data for inso git-repo testing; Added smoke test fixtures for validation, data upload, and content preview; Added smoke tests for Git migration onboarding and local-to-cloud data migration; Added smoke tests for after-response scripting and core application workflows; Added smoke-test fixture data for inso-nedb; Added test coverage for Git Sync core components; Added test coverage for insomnia-data models and services; Added test coverage for main-process security, Git sync, and LLM configuration; Added test coverage for the plugin system; Added tests for Postman data dump extraction; Added tests for basic authentication header generation; Added tests for gRPC URL parsing and proto file writing; Added tests for importer conversion and key validation; Added tests for system change detection in diff view; Added tests for the API specification export functionality; Added unit tests for Konnect integration components; Added unit tests for common utility modules; Added unit tests for modal utilities and import/export logic; Added unit tests for network authentication, certificate matching, and multipart body building; Added unit tests for plugin context modules; Added unit tests for plugin creation and installation logic; Added unit tests for scripting-environment objects; Added utilities for export smoke tests; Deterministic UUID generation in test mocks; Expanded smoke-test fixtures for Insomnia v5.1 collections; Expanded test fixtures for importers; Initial setup of Playwright-based smoke test infrastructure; Mock for node-libcurl added to support testing; Mocking Sentry Electron for Vitest testing; New Playwright Page Object Model for E2E tests; New page objects for export modal, navigation sidebar, and statusbar; New page objects for project dashboard and workspace list in smoke tests; Regenerated test certificates for smoke tests; Snapshot tests added for cURL import fixtures; Updated inso database fixtures with new test data and settings.

Dependencies

Initialize monorepo workspace structure and add sandbox demo plugin

The project is initialized as a monorepo with a root \package.json\ defining workspaces for core packages including \insomnia\, \insomnia-inso\, \insomnia-data\, \insomnia-vcs\, \insomnia-analytics\, \insomnia-api\, \insomnia-testing\, and \insomnia-scripting-environment\. A new example plugin \insomnia-plugin-sandbox-demo\ is added to demonstrate the QuickJS template-tag sandbox path, requesting \events\ and \uuid\ modules and \storage\ capability. The root dependencies include \@getinsomnia/node-libcurl\ and \ajv\, while dev dependencies establish the tooling stack with \esbuild\, \vitest\, \typescript\, and \eslint\ v9.

(dependencies) · high confidence

Housekeeping

Repository initialization with Apache 2.0 license and modern tooling configuration

The repository has been initialized with a new project structure and configuration. The software license has been updated to Apache Version 2.0. Development tooling is configured via \.prettierrc\ (enforcing 120-character line widths and Tailwind CSS plugin support for the Insomnia package), \.markdownlint.yaml\ (standardizing list styles and allowing specific HTML elements), and \.clang-format\ (setting a 120-column limit). The Node.js runtime is pinned to version 24.18.0 via \.nvmrc\, and npm is configured with strict engine checking and a registry alias for the Kong GitHub package repository in \.npmrc\. Additionally, \.gitattributes\ is set to enforce LF line endings for text files and mark the vendored Yarn binary as generated to reduce diff noise.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 44 → 50 (+6.1)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 61 → 65 (+3.9)
  • Architecture 45 (new)
  • Maturity 62 → 75 (+12.6)
  • Readiness 29 → 54 (+24.5)
  • Security 54 → 64 (+9.6)
  • Accessibility 48 (new)
  • Performance 60 (new)

Resolved (77)

  • Change coupling: cli.ts ↔ environment.ts (packages/insomnia-inso/src/cli.ts)
  • Change coupling: cli.ts ↔ export-specification.ts (packages/insomnia-inso/src/cli.ts)
  • Change coupling: cli.ts ↔ workspace.ts (packages/insomnia-inso/src/cli.ts)
  • Change coupling: entry.preload.ts ↔ electron.ts (packages/insomnia/src/entry.preload.ts)
  • Change coupling: export-specification.ts ↔ index.ts (packages/insomnia-inso/src/commands/export-specification.ts)
  • Change coupling: git-service.ts ↔ project-routable-fs-client.ts (packages/insomnia/src/main/git-service.ts)
  • Change coupling: project-create-form.tsx ↔ project-settings-form.tsx (packages/insomnia/src/ui/components/project/project-create-form.tsx)
  • Change coupling: templating-worker-database.ts ↔ invoke-method.ts (packages/insomnia/src/main/templating-worker-database.ts)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (packages/insomnia-component-docs/package-lock.json)
  • Critical CVE: [GHSA redacted] (packages/insomnia-component-docs/package-lock.json)
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 57 more

New (1301)

  • Boundary-crossing change coupling: interfaces.ts ↔ request-script-editor.tsx (packages/insomnia-scripting-environment/src/objects/interfaces.ts)
  • Change coupling: cancellation.renderer.ts ↔ network.ts (packages/insomnia/src/network/cancellation.renderer.ts)
  • Change coupling: entry.preload.ts ↔ main.ts (packages/insomnia/src/entry.preload.ts)
  • Change coupling: git-branches-modal.tsx ↔ git-staging-modal.tsx (packages/insomnia/src/ui/components/modals/git-branches-modal.tsx)
  • Change coupling: git-service.ts ↔ git-project-sync-dropdown.tsx (packages/insomnia/src/main/git-service.ts)
  • Change coupling: mock-response-extractor.tsx ↔ mock-url-bar.tsx (packages/insomnia/src/ui/components/editors/mock-response-extractor.tsx)
  • Change coupling: organization.$organizationId.project.$projectId.workspace.$workspaceId.environment.tsx ↔ workspace-environments-edit-modal.tsx (packages/insomnia/src/routes/organization.$organizationId.project.$projectId.workspace.$workspaceId.environment.tsx)
  • Change coupling: raw-editor.tsx ↔ response-pane.tsx (packages/insomnia/src/ui/components/editors/body/raw-editor.tsx)
  • Change coupling: request-group-pane.tsx ↔ request-pane.tsx (packages/insomnia/src/ui/components/panes/request-group-pane.tsx)
  • Change coupling: request-group-settings-modal.tsx ↔ request-settings-modal.tsx (packages/insomnia/src/ui/components/modals/request-group-settings-modal.tsx)
  • Change coupling: request-pane.tsx ↔ websocket-request-pane.tsx (packages/insomnia/src/ui/components/panes/request-pane.tsx)
  • Change coupling: request-url-bar.tsx ↔ action-bar.tsx (packages/insomnia/src/ui/components/request-url-bar.tsx)
  • Change coupling: response-pane.tsx ↔ response-multipart-viewer.tsx (packages/insomnia/src/ui/components/panes/response-pane.tsx)
  • Change coupling: sync-branches-modal.tsx ↔ sync-history-modal.tsx (packages/insomnia/src/ui/components/modals/sync-branches-modal.tsx)
  • Change coupling: sync-history-modal.tsx ↔ sync-staging-modal.tsx (packages/insomnia/src/ui/components/modals/sync-history-modal.tsx)
  • Change-coupling hub: organization.$organizationId.project.$projectId._index.tsx → sidebar-project-dropdown.tsx, workspace-sync-dropdown.tsx, workspace-duplicate-modal.tsx (packages/insomnia/src/routes/organization.$organizationId.project.$projectId._index.tsx)
  • ClassTooLong: GitVCS (packages/insomnia/src/sync/git/git-vcs.ts)
  • ClassTooLong: RepoFileWatcher (packages/insomnia/src/sync/git/repo-file-watcher.ts)
  • ClassTooLong: VCS (packages/insomnia-vcs/src/vcs.ts)
  • Cookie.parse (cognitive 17) (packages/insomnia-scripting-environment/src/objects/cookies.ts)
  • …and 1281 more

Changes since last survey

  • 125 commits — 51 feature/other, 74 fixes

By area

  • packages/insomnia — 90 commits
  • packages/insomnia-smoke-test — 11 commits
  • (root) — 7 commits
  • .github/workflows — 7 commits
  • packages/insomnia-data — 2 commits
  • packages/insomnia-scripting-environment — 2 commits
  • .claude/settings.json — 1 commit
  • .claude/skills — 1 commit
  • .github/scripts — 1 commit
  • packages/insomnia-inso — 1 commit
  • packages/insomnia-vcs — 1 commit
  • scripts/circular-references — 1 commit

Notable commits

  • fix: Fix: Secret type environment input hanging and data update issue (#10420)
  • fix: chore: fix playwright port detect (#10462)
  • fix: fix expand issue when no request group meta (#10453)
  • fix: fix shortcut creation issue & workspace dropdown context menu issue (#10432)
  • fix: fix sidebar data not updated when offline (#10369)
  • fix: fix the tag editor update issue (#10537)
  • fix: fix(INS-2766): Land on the parent folder/collection root when deleting a request's last open tab (#10375)
  • fix: fix(INS-3507): restrict git-sync and legacy-folder writes to canSync model types (#10531)
  • fix: fix(INS-3620): tag cookie assignment origin (#10475)
  • fix: fix(INS-3836): don't show the Konnect-moved notice before a migration conflict is resolved (#10521)
  • fix: fix(INS-3850): re-check the Konnect organization's visibility before restoring it on cold start (#10518)
  • fix: fix(INS-3850): revalidate a project's old organization cache when it moves parents (#10513)
  • fix: fix(INS-3906): parse quoted CSV fields in collection runner data (#10557)
  • fix: fix(build): macos latest (#10400)
  • fix: fix(ci): skip circular refs PR comment when count is unchanged (#10391)
  • fix: fix(cloud-sync): surface stale/reverted staged changes instead of silently committing them [INS-3520] (#10438)
  • fix: fix(database): emit change notifications on document duplication (#10387)
  • fix: fix(deps): security dependency bumps (#10347)
  • fix: fix(environment-editor): treat empty JSON content as invalid JSON (#10540)
  • fix: fix(error-boundary): log full error stack for better diagnostics (#10379)
  • …and 105 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Kong/insomnia was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7de40fe4a7bb9add31dbee8e01dd4347ff6920b5 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.