Relmio
GitHub?v0.17.4

Release notes

What changed, in plain language.

Every published release is listed here. The docs build reads CHANGELOG.md, so the website and repository show the same notes.

Changelog

This project follows semantic versioning. Each completed release uses one version across package.json, package-lock.json, this file, the Git tag, and npm. Local checks validate the repository metadata; the publishing guide checks the registry separately after publication.

Unreleased

0.17.4 - 2026-09-21

Added

  • Add a dated official-source review confirming that the canonical-domain change does not alter Relmio's authentication, permissions, model request, data handling, logging, or recipients.

Changed

  • Make relmio.jpfusin.tech the canonical website, documentation, package homepage, and hosted-installer origin.
  • Permanently redirect requests from relmio.vercel.app to the matching path on the new canonical domain so existing links keep working.

0.17.3 - 2026-09-18

Changed

  • Lead bare relmio, NPX, and hosted installer launches with ChatGPT on my server while keeping relmio local as the explicit computer-only route.

0.17.2 - 2026-09-18

Changed

  • Open bare relmio, NPX, and hosted installer launches as a foreground browser wizard without creating persistent Relmio state. A clean first-run machine may have no .relmio directory and no local n8n stack; prerequisite guidance now remains inside the wizard.
  • Run the complete release gate plus focused PowerShell, CMD, browser handoff, ACL, and Codex login checks on native Windows CI.

Fixed

  • Keep a successfully dispatched Windows browser handoff alive even when explorer.exe later returns a nonzero status, preventing the temporary page from disappearing with ERR_FILE_NOT_FOUND.
  • Retry native Command Prompt temporary-runtime cleanup when Windows briefly holds an executable open, and report an actionable nonzero failure if cleanup remains blocked.
  • Give the hosted Git Bash launcher a real native child terminal and normalized Windows runtime path through its bundled winpty and cygpath tools, while replacing GUI-dependent Windows CI coverage with a headless native-console test.
  • Use native Windows Node/npm process boundaries, owner-only temporary browser handoffs, and isolated official Codex login attempts with validated atomic credential promotion and actionable cancellation errors.

0.17.1 - 2026-09-14

Relmio 0.17.1 makes streamed replies calmer and clearer in both the hosted chat and the browser wizard's Test AI Chat console.

Changed

  • Distinguish sending, connecting, waiting for first text, active streaming, completion, interruption, and failure without announcing every text chunk to assistive technology. Reduced-motion mode keeps equivalent static cues.
  • Keep partial text primary and visible when a response is stopped or fails, with stable message sizing and explicit retry-ready terminal states.

Fixed

  • Ignore empty stream deltas as non-visible output and keep pre-token progress monotonic, preventing blank replies or backward status changes.

The Codex Chat Adapter POST /chat protocol and external clients such as n8n are unchanged. Node.js 24+ and the hosted chat's exact gpt-5.6-luna request remain in place.

0.17.0 - 2026-09-14

Relmio 0.17.0 is a pre-1.0 compatibility milestone that moves supported setup paths to Node.js 24 and updates the hosted web chat to GPT-5.6 Luna.

Added

  • Add a dated official-source review for the Node.js 24 runtime and hosted Luna request, including authentication, data-flow, policy, entitlement, and native-platform limits.

Changed

  • Require Node.js 24 or newer across the browser wizard, hosted launchers, package metadata, CI, release validation, and current setup guidance. Portable launchers now select a checksum-verified Node.js 24 runtime; the native CMD launcher pins the reviewed official Node.js 24.21.0 archives.
  • Use the exact gpt-5.6-luna model ID for the hosted web chat request and its visible model label. This does not change n8n, image, audio, console, provider, or local endpoint defaults.

Hosted Luna access still depends on the signed-in account and compatibility transport. This release does not establish broader model entitlement or Terms approval.

0.16.0 - 2026-09-12

Relmio 0.16.0 brings GPT Image 2.5 discovery and selection guidance to the browser installer for new and existing OpenAI OAuth bridges.

Added

  • Discover the exact Flare and Sunburst image model IDs alongside existing models, including GPT Image 2. Both 2.5 variants were tested with n8n's native image generation and editing nodes on the current account.
  • Show discovered image choices and copyable IDs after bridge installation or update, with instructions for n8n's image model selector.

Fixed

  • Recognize the unchanged runtime from Relmio 0.15.0 during a local bridge update instead of rejecting it as file drift. Modified or unowned files still fail closed; updates retain the saved sign-in and leave n8n untouched.

Changed

  • Simplify local and VPS setup with clearer visual choices and plain-language labels. Keep specialist local tools and technical explanations behind expandable details while retaining every setup option and approval step.
  • Keep GPT-Live and Realtime models out of this bridge's discovery response and return explicit unsupported-operation guidance for their session routes. Audio remains a separate unsupported capability through this OAuth bridge.

Security

  • Update the hosted web framework, image-processing dependency, and YAML parser to versions that address the newly reported Next.js, sharp, and js-yaml advisories.

Existing bridges need a reviewed runtime update to receive the new catalog. Exact output dimensions, all image options, and universal account access remain unverified. The bridge remains unofficial and policy-uncertain; this release adds no Platform API-key fallback or new credential permissions.

[0.15.0] - 2026-09-08

Relmio 0.15.0 adds browser-driven updates for existing OpenAI OAuth bridges and repairs n8n OpenAI node compatibility on local Docker and VPS deployments.

Added

  • Update an existing local or VPS OpenAI OAuth bridge from the browser wizard. Local updates preserve the saved sign-in; VPS updates upload the current local sign-in. Both rebuild only the owned sidecar, retain its selected network, leave n8n running, and keep port 10531 private.

Changed

  • Document all 16 n8n OpenAI actions and their current bridge limits. Audio, file management, stored conversations, moderation, video, background jobs, and stored responses return specific unsupported-operation guidance.
  • Make the completion-page Responses API notice dismissible while preserving the required setting in the permanent instructions.

Fixed

  • Allow n8n Message a Model requests with Background Mode off by removing the disabled background parameter before forwarding to the OAuth transport. Both sidecar installers bundle the same compatibility adapter.
  • Explain failed VPS model checks and route rejected ChatGPT credentials back to fresh sign-in. Clear the previous plan and approval before another update.
  • Separate the completion notice from the credential heading and report Docker network refresh failures without claiming the install or SSH session stopped.

Existing bridges need a runtime update from the wizard to receive these fixes. Relmio's ChatGPT connection remains unofficial and does not provide every OpenAI Platform API action.

0.14.0 - 2026-09-06

Relmio 0.14.0 adds experimental SuperGrok OAuth for local apps and existing local or VPS n8n deployments without requiring a ChatGPT sign-in.

Added

  • Add SuperGrok Chat Completions for local apps and private n8n clients using a fresh official Grok device sign-in, isolated provider session, and separate local Relmio bearer. n8n executes its own tool calls.
  • Keep the simple /chat interface through the same direct HTTP transport.
  • Add a dedicated SuperGrok VPS wizard for verified SSH identity, read-only n8n discovery, reviewed installation, device sign-in, model checks, status, sign-out, cancellation, and owned-only removal. The companion joins one selected Docker network and publishes no host port.

Changed

  • Use one guided browser flow for provider, local or VPS destination, discovery, review, sign-in, and completion. Provider changes invalidate stale plans and keep the OpenAI OAuth and SuperGrok instructions distinct.
  • Redesign the public homepage with the original Relmio mascot, a full-width day/night landscape, timed destination labels, and accessible motion controls. Keep the install wizard focused on large controls and plain instructions.
  • Limit provider setup to OAuth. Remove upstream API-key gateways, profiles, registration and selection routes, and the API-key n8n xAI sidecar.
  • Show seven dashboard services and four provider-owned OAuth entries. Keep runtime health, provider readiness, and inventory freshness independent.
  • Preserve the last observed state while inventory is stale and disable maintenance actions until a successful refresh.
  • Document the provider-specific n8n setting prominently: the Relmio OpenAI OAuth recipe uses Responses API on, while SuperGrok requires it off for workflow model nodes and Chat Hub.
  • Keep existing API-key gateways and credential data running but outside the 0.14.0 dashboard. Refuse to adopt an earlier SuperGrok development install that lacks the fresh-session marker.

Fixed

  • Keep endpoint URLs readable on narrow dashboard layouts.
  • Use supported Docker Compose run options for Grok login and version probes.
  • Keep Windows identity and unsafe-path tests portable by forwarding filesystem metadata options and using a directory junction that does not require Developer Mode or administrator-created symbolic links.
  • Document that Git Bash 2.38.1 needs per-process MSYS=enable_pcon for the portable launcher TTY check, with native PowerShell and Command Prompt as the supported alternatives. No global Git setting is required.

Security

  • Pin Grok's executable inside the image and disable automatic update checks.
  • Read only the current runtime's marked private OAuth session. The official CLI remains the credential writer; the HTTP handler does not execute CLI tools, import other applications' credentials, or consume refresh tokens.
  • Preserve existing API installations and credential data without adopting, migrating, or deleting them through the OAuth-only runtime.
  • Require SSH host-key confirmation, an exact reviewed plan, and final human confirmation before every VPS write. Keep the companion under /docker/n8n-openai-oauth, leave n8n unchanged, and remove only resources that pass exact ownership checks.

0.13.0 - 2026-09-04

Added

  • Add owner-scoped local dashboard lifecycle commands: relmio start, relmio status, relmio open, and relmio stop.
  • Reopen Relmio's local launcher to rediscover a fixed inventory of six local services: the OpenAI API endpoint, both Codex endpoints, the owned n8n stack, the OAuth bridge, and the AI Assistant tools.
  • Copy verified service URLs and use only actions supported by the latest inventory state, including Codex sign-in, client-credential rotation, OAuth bridge refresh, owned-stack resume, removal, and a return to setup.

Changed

  • Keep hosted curl, PowerShell, and Command Prompt launches foreground-only when they use a verified temporary runtime, while persistent package installs can manage the dashboard between terminal sessions.
  • Make the persistent dashboard the default local launcher's home while keeping the existing four-step Add connection setup flow intact and the separate VPS flow available through relmio vps.
  • Present Docker availability, service boundaries, component state, and recovery choices in a responsive dashboard that marks stale inventory and refreshes it read-only.
  • Pair every dashboard rail label with an accessible inline SVG icon, using a neutral workflow mark for n8n at the compact navigation size.

Fixed

  • Re-attest exact generated Docker ownership and health before reporting a service as healthy, including each companion's selected external n8n container and Docker network on Windows.
  • Keep owned n8n-stack recovery guidance accurate across Compose validation, image pulls, and startup waits. Safe single-line validation details can now explain the problem without exposing paths, credentials, or raw Docker output, extending the Compose diagnostics introduced in v0.12.2.

Security

  • Open the local dashboard through an owner-only, single-use browser handoff whose route-bound capability expires after 30 seconds and never appears in process arguments, the visible URL, redirects, or cookies.
  • Leave ChatGPT OAuth ownership with the official Codex App Server, keep one active account per Codex target, reject automatic account or key changes after authentication, rate-limit, or quota failures, and deny undocumented provider authentication methods by default.
  • Return only sanitized states, components, and allowlisted endpoints from persistent inventory. Relmio never reveals stored secrets, and one-time values are consumed before returning to the dashboard.
  • Recheck owner-only Windows ACLs at mutation time and fail closed before any Docker or Compose change when a managed path or file no longer has its attested permissions.
  • Let operators disconnect the VPS explicitly and close idle authenticated SSH sessions after 15 minutes without interrupting an active remote operation.

0.12.2 - 2026-09-03

Fixed

  • Let Code Sandbox + SearXNG local n8n setup work on current Docker Desktop (Compose v5) instead of failing before images are pulled, and show the actual Compose validation error when that step still fails.

0.12.1 - 2026-09-02

Fixed

  • Give the first local n8n + ngrok start enough time to pull images and pass health checks, and explain image-download versus startup-wait failures without exposing Docker output or credentials.
  • Explain Windows Docker Desktop WSL 0x800705aa engine-start failures in the local n8n wizard instead of a generic Compose error.

0.12.0 - 2026-09-02

Added

  • Support local Docker endpoint, n8n bridge, Assistant companion, and owned n8n stack workflows on native Windows with Docker Desktop's attested desktop-linux engine.
  • Add manage/edit actions for detected local and VPS n8n integrations, including a fresh ChatGPT sign-in path and Assistant/SearXNG configuration.
  • Add a Ko-fi support link to the GitHub and npm README guides.

Changed

  • Guide beginners through ngrok agent-token and user-created Basic Auth fields with inline validation, missing-field warnings, locked install controls, and visible progress while setup is running.
  • Keep the same reviewed browser wizard behavior across PowerShell, Command Prompt, npm/npx, curl, and Homebrew launch paths instead of relying on shell-specific setup logic.

Fixed

  • Recover interrupted owned n8n-stack operations without moving a newer live lock, including crashed processes, PID reuse, incomplete lock publication, and a preserved partial-stack recovery result when lock cleanup also fails.
  • Wait for generated n8n, ngrok, and sandbox health checks consistently, accept the sandbox API's private 8080/9090 metadata, and continue rejecting UDP or host-published Assistant ports.
  • Preserve existing n8n enabled modules when adding AI Assistant settings and leave existing n8n containers, Compose files, images, and restarts untouched.

Security

  • Protect every Windows managed credential directory and file with a read-back-verified NTFS DACL limited to the current account before writing secrets or invoking a Docker mutation. Remote Docker selectors, Unix sockets, and unrecognized named pipes remain rejected on Windows.
  • Bind lifecycle ownership to the process creation identity, fail closed when liveness is ambiguous, and arbitrate stale recovery before changing the canonical local n8n operation lock.

0.11.0 - 2026-09-01

Added

  • Add a hosted changelog generated from the repository release history.
  • Add a wordless animated sketch banner that keeps Relmio's original two-eyed green mascot and cream doorway.

Changed

  • Rewrite the GitHub and npm guides, hosted site, and browser wizard in shorter, plainer language while keeping credential and safety boundaries explicit.
  • Add clearer step-by-step guidance for local ngrok and n8n companion setup.
  • Use icon-only copy controls with accessible labels, larger touch targets, and responsive layouts across the hosted site and browser wizard.

Fixed

  • Keep a completed local wizard from reopening a consumed setup plan; starting another option now prepares a fresh plan.

[0.10.0] - 2026-08-31

Added

  • Add local n8n companion choices to the browser wizard: an unofficial private openai-oauth sidecar for an existing n8n container and n8n AI Assistant Code Sandbox support with optional SearXNG JSON web search.
  • Add a one-click, separately owned disposable n8n + ngrok stack with mandatory Traffic Policy Basic Auth, loopback-only local ports, and optional Code Sandbox plus SearXNG.
  • Add an animated Gateway Android README banner, a two-lane credential-boundary diagram, package and project badges, and a concise product introduction.

Changed

  • Bind each companion plan to the exact running n8n container and selected existing Docker network; neither path publishes a host port or edits, restarts, stops, recreates, rebuilds, or executes inside n8n. Assistant settings remain operator-applied.
  • Let every completed local setup return to the token-preserving start screen so another endpoint can be configured without restarting the wizard.
  • Use Homebrew's formula-scoped trust command for the public Relmio tap instead of asking users to trust an entire third-party tap.

Fixed

  • Accept only Docker Compose's strict unpublished publisher placeholder while retaining fail-closed rejection for real or malformed host publication.
  • Give disposable n8n's cache an owner-writable temporary filesystem so n8n AI Assistant workspace initialization can complete.
  • Keep bind-mounted ngrok and SearXNG configuration readable by their non-root containers while parent managed directories remain owner-only.

Security

  • Keep credentials separate: the sidecar uses a private local ChatGPT OAuth volume, while the Assistant model-provider credential is configured directly in n8n and is not handled by Relmio. SearXNG remains optional and off by default.
  • Scope the new public exception to the owned n8n route behind mandatory Basic Auth; port 10531, Code Sandbox, and SearXNG remain unpublished, and removal requires exact project-wide ownership attestation.

[0.9.1] - 2026-08-31

Added

  • Add a prominent hosted installer launch option for the separate n8n AI Assistant wizard, while retaining every existing general installer method.

Changed

  • Redesign the hosted app as an Editorial Console with an interactive four-route Signal Plotter and an improved multi-turn chat console that can stop in-flight responses.
  • Describe the AI Assistant's SSH-connected self-hosted target without provider-specific Hostinger or VPS labels, and document that direct local Docker-socket discovery is not supported.

Fixed

  • Stabilize reduced-motion hydration by giving the Signal Plotter a deterministic initial signal state before animation begins.
  • Keep the hosted repository control's offline metadata fallback synchronized with the prepared release version.

0.9.0 - 2026-08-28

Added

  • Add relmio assistant, a dedicated local wizard and isolated companion Compose plan for n8n AI Assistant's self-hosted sandbox and optional SearXNG web search.

Changed

  • Add sourced OpenAI policy context to the GitHub README, npm README, and canonical security guide, including the maintainer's Codex for Open Source acceptance, while preserving the distinction between supported Codex/ChatGPT sign-in patterns and unsupported subscription-to-API conversion, resale, account sharing, or safeguard bypass.

Security

  • Keep the privileged Docker-in-Docker runner separate from the selected n8n network, publish no companion host ports, generate and redact independent sandbox secrets, attest ownership-bound random Compose identities and network aliases, serialize VPS-sidecar and assistant mutations under one single-use plan lock, and retain the strict no-n8n-mutation boundary.
  • Pin every generated AI Assistant companion production image to its reviewed immutable tag and OCI index digest, with regression coverage that rejects floating or digestless references, including the nested sandbox image.

[0.8.1] - 2026-08-26

Changed

  • Adopt the Gateway Android logo across the GitHub and npm READMEs, hosted site, and local wizard, and stop publishing the retired Harbor Gate mark.
  • Refresh the Open Graph and social-preview card with the Gateway Android while preserving the Relmio relay message and visual flow.
  • Add a prominent Legal warning against bypassing rate limits, restrictions, or safeguards.

[0.8.0] - 2026-08-26

Added

  • Let trusted local backends and development servers receive Chat Adapter turns as opt-in Server-Sent Events, with progress and text deltas followed by one explicit terminal outcome so a completed response is distinguishable from a redacted failure.
  • Let the setup-token-protected local wizard tester show that incremental response flow after a short-lived encrypted credential handoff, without a direct browser-to-adapter request.
  • Refresh the hosted chat experience and local installer presentation, and adopt the Harbor Gate abstract mark across Relmio surfaces.

Changed

  • Document the streaming contract, local tester behavior, and its limits in the canonical endpoint/reference guides and generated hosted documentation.

Security

  • Keep the Chat Adapter experimental, loopback-only, and limited to trusted local backends or development servers; it rejects browser origins and is not an OpenAI /v1 endpoint or a substitute for an OpenAI Platform API key.

[0.7.0] - 2026-08-16

Added

  • Add an encrypted in-wizard tester for the experimental Chat Adapter, plus safe sample Chat Adapter and Codex App Server commands for local testing.
  • Add generated hosted guides for getting started, local endpoints, VPS and n8n, troubleshooting, FAQ, security, and reference information.

Changed

  • Synchronize concise root and npm READMEs around product, installation, security, and common-problem overviews that link to hosted guides.
  • Fact-check ChatGPT/Codex token-refresh guidance across documentation: tokens refresh during active use, the official documentation specifies no fixed 10-day lifetime, and the provider credential remains distinct from Relmio's rotatable client capability.

Security

  • Limit tester destinations to literal loopback HTTP addresses, retain private keys only in memory for a bounded lifetime, encrypt entered credentials before they cross the browser boundary, require POST after a completed Chat Adapter install, keep sample bearer values out of process arguments, and erase or abort sessions when forgotten, rotated, or shut down.

[0.6.0] - 2026-08-15

Added

  • Add an experimental loopback-only Codex Chat Adapter for trusted local backends and development servers, with bearer authentication, multi-turn conversation IDs, strict resource bounds, and a small Relmio-specific POST /chat contract.

Changed

  • Make Codex device sign-in target-aware so the experimental Relmio /chat adapter and native App Server retain isolated, persistent ChatGPT credentials; a Platform API key powers neither target and remains reserved for the generic OpenAI-compatible /v1 endpoint.

Security

  • Reject browser-origin adapter requests, keep the adapter separate from Platform-key-backed generic OpenAI-compatible /v1 semantics, explicitly deny model turns access to the private Codex credential store, run chat turns read-only without network access, and preserve loopback-only publication plus credential rotation.

[0.5.0] - 2026-08-15

Added

  • Add a Rotate client credential action for installed local endpoints that shows the replacement capability before activation and preserves the upstream Platform key or Codex credential/workspace volumes.

Changed

  • Keep System, Light, and Dark appearance controls plus Ko-fi, GitHub stars, and the current package version available throughout the local install wizard.

Fixed

  • Install operating-system CA certificates in the isolated Codex image so the official ChatGPT device-code sign-in can establish its trusted TLS connection.
  • Wrap local safety and error notifications instead of clipping longer text.

Security

  • Verify the generated Codex capability with a strict authenticated WebSocket upgrade before reporting installation or rotation success.
  • Serialize installation, sign-in, restart, and credential rotation across Relmio processes, with attested stale-lock recovery and fail-closed rollback that restores the prior verifier and re-attests endpoint readiness.

[0.4.1] - 2026-08-14

Changed

  • Add a manual Stop sign-in action while a fresh ChatGPT login is pending, then detect and reject results from superseded wizard attempts.

Fixed

  • Terminate the OAuth helper process tree when sign-in is stopped or Relmio exits, preventing a rejected or abandoned attempt from continuing to hold the localhost:1455 callback port.

Security

  • Fail closed when OAuth process cleanup or credential promotion cannot be confirmed, blocking another login until Relmio restarts instead of risking an ambiguous helper or credential state.

[0.4.0] - 2026-08-13

Added

  • Add a local Docker wizard for private compatible clients through a Platform-key-backed OpenAI-compatible /v1 endpoint, plus a separate official experimental Codex App Server target for trusted ChatGPT-sign-in clients.
  • Add compact Ko-fi support links to the hosted navigation and public package guides.

Changed

  • Make the local credential boundary explicit across the product: a Platform API key powers compatible /v1 requests, while ChatGPT sign-in powers only the experimental Codex App Server protocol.

Fixed

  • Keep the controlling terminal attached when the macOS/Linux installer is piped through sh, so the Relmio wizard can open its interactive browser setup flow.
  • Install Homebrew dependencies in their required order during release-candidate validation.

Security

  • Bind local endpoints exclusively to loopback, require one-time Relmio capabilities, pin every managed operation to an attested local Docker socket, and isolate provider credentials in target-specific containers.
  • Restrict the managed Codex endpoint to the ChatGPT login method.

[0.3.1] - 2026-08-10

Changed

  • Make the browser wizard beginner-friendly with a modern fixed-viewport layout: all five active steps fit without document scrolling on common 1280x720 laptops, while progress and safety context stay persistent beside the active task.
  • Keep narrow-phone documents fixed to the viewport and contain unavoidable long-form overflow within the active task panel instead of the page.
  • Expand the GitHub and npm walkthroughs with a hosted-install selector and packaged, sanitized screenshots that document the current n8n workflow.

Security

  • Restore a clean hosted-web dependency audit by pinning patched js-yaml and nanoid releases and using the compatible vinext release that does not include the currently vulnerable image-size parser.

[0.3.0] - 2026-08-05

Added

  • Add a copy-ready n8n HTTP Request recipe to the local wizard, including the private Chat Completions URL, Generic Credential Type → Bearer Auth fields, the harmless local-only bearer placeholder, JSON headers, the structured response-format body, and a full recipe copy action.
  • Add the same structured gpt-5.6-sol example and importable cURL recipe to the GitHub README, npm README, and n8n configuration guide.
  • Add a repository-local changelog skill that standardizes Relmio's patch, pre-1.0 feature, and stable major release numbering and metadata checks.

Changed

  • Treat 0.3.0 as Relmio's major feature release within the pre-1.0 series; it consolidates the key improvements shipped from v0.2.10 through v0.2.14: resilient Windows OAuth/bootstrap flows, native Command Prompt installation, compact accessible wizard recipes, verified Homebrew/package-manager preparation, and release-time package checks.
  • Keep the HTTP Request body aligned with n8n's messages format by targeting /v1/chat/completions; the separate OpenAI Chat Model guidance continues to support the Responses API where that node exposes the switch.

[0.2.15] - 2026-08-05

Fixed

  • Exit cleanly when WinGet or another non-interactive validator probes the portable command without arguments, while keeping the browser wizard for interactive Command Prompt and PowerShell sessions.
  • Add a redirected-stdio portable smoke test so future WinGet candidates cannot regress into a never-ending default launch.
  • Exclude local npm cache directories from portable release archives.

[0.2.14] - 2026-08-04

Added

  • Add staged Homebrew formula and WinGet portable-package generation with x64/ARM64 manifests, installed-command smoke tests, and review-only CI artifacts for package-manager publication.
  • Add relmio --version and relmio -v for noninteractive installer and package-manager verification.

Changed

  • Report Homebrew and WinGet publication status in the hosted install page and documentation, while keeping unapproved commands out of the primary picker.

Fixed

  • Replace the hosted Command Prompt installer route's PowerShell launch with a PowerShell-free, non-admin native batch bootstrap that reuses Node.js 22+ when available or verifies a pinned official Windows runtime before use.
  • Keep downloaded checksum-manifest text out of CMD evaluation and use reviewed Node.js 22.23.2 x64/ARM64 digests embedded in the release.
  • Download the CMD bootstrap to a collision-resistant temporary name without overwriting an existing install.cmd, then clean it after execution.
  • Show deterministic download, checksum-verification, and extraction stages in every bootstrap so temporary Node.js runtime setup does not appear stalled.

[0.2.13] - 2026-08-04

Changed

  • Compact the local setup wizard so its active step stays near the top, move safety and status notices into dismissible toasts, and collapse the optional AI Agent and HTTP Request recipes until users choose to open them.
  • Complete the HTTP Request recipe with authorization, content type, and a copyable sample Responses API JSON payload.

Fixed

  • Copy credential values reliably in Opera GX on Windows by preserving the synchronous user gesture for the selection-based clipboard path before falling back to the modern Clipboard API.

[0.2.12] - 2026-08-04

Fixed

  • Install the pinned openai-oauth@2.0.0 helper with its exact compatible zod@4.1.8 peer even when inherited npm settings omit peer dependencies, preventing the Windows sign-in helper from exiting before it prints a URL.
  • Accept the same strictly validated authorization line from either helper output stream, including Windows terminal framing and final drained output.
  • Run npm package builds through the current Node.js runtime on Windows instead of executing npm.cmd directly with shell: false.

[0.2.11] - 2026-08-04

Fixed

  • Open the private Windows wizard URL through the documented default-browser association instead of asking Explorer to treat the URL as a folder, while retaining the printed URL and Enter-to-retry fallback.
  • Make the Command Prompt installer copy call the system Windows PowerShell executable directly, avoiding ambiguous powershell command resolution.
  • Parse the supported openai-oauth@2.0.0 login line across Windows terminal control sequences and chunk boundaries, and report a sanitized, actionable callback-port conflict instead of a generic missing-link error.

Security

  • Pin the hosted web tooling to brace-expansion 5.0.9, which includes the upstream denial-of-service fix required by the release audit.

[0.2.10] - 2026-08-03

Fixed

  • Probe installed Windows Node.js runtimes with the literal node --version output instead of a node -p expression, avoiding the PowerShell [eval]:1 quoting failure while still reusing Node.js 22 or newer.
  • Let interactive wizard terminals reopen the local browser page when the user presses Enter, while retaining the printed private URL as the fallback for noninteractive launches.
  • Navigate the preopened local OAuth tab before severing its opener access, show an immediate preparing state, and close an unnavigated waiting tab if sign-in setup fails.

[0.2.9] - 2026-08-02

Fixed

  • Launch the local ChatGPT OAuth helper through the current Windows Node.js runtime and npm's JavaScript CLI instead of executing npx.cmd directly, preventing spawn EINVAL while preserving the native npx path on macOS, Linux, WSL, and Git Bash.
  • Explain how to recover when a refreshed wizard page no longer has its private session URL.

[0.2.8] - 2026-08-02

Changed

  • Replace the local browser wizard's text appearance selector with compact, accessible System/Light/Dark icons, while keeping the original horizontal Signal Spine flow and touch-friendly behavior.
  • Serve the bundled Lucide SVG assets from the wizard and include them in the npm package so offline and Node-free browser launches render consistently.

[0.2.7] - 2026-08-02

Changed

  • Restore the original Relmio hosted layout and local browser wizard flow, with the horizontal five-step Signal Spine and GitHub star/version control kept visible.
  • Add Astryx's built theme and accessible segmented appearance control to the hosted app, plus lightweight System/Light/Dark preference support to the local wizard.
  • Add responsive dark-mode logo treatment, phone-sized controls, and matching browser-wizard guidance to the GitHub and npm README variants.

Fixed

  • Keep the checksum-verified temporary Node.js 22 runtime on the child process path so Git Bash and other Node-free systems can launch the Relmio package shim without falling back to a missing or outdated system node command.

[0.2.6] - 2026-08-02

Added

  • Add a curl-based wizard bootstrap for macOS, Linux, WSL, and Git Bash that reuses Node.js 22+ or downloads and checksum-verifies a temporary official runtime when Node.js is not installed.
  • Add a native Windows PowerShell bootstrap for PowerShell and Command Prompt that works without Git Bash or a preinstalled Node.js runtime and verifies the temporary official Windows archive before execution.
  • Expand the hosted installer into an accessible macOS/Linux, PowerShell, Command Prompt, and NPX terminal switcher.

Changed

  • Revamp the hosted Vercel experience and local browser wizard around the Signal Spine composition and Patchbay Ledger design language.
  • Integrate the Astryx component system, neutral theme, CLI, and AI-readable setup guidance in the hosted React application while keeping the published wizard dependency-light.
  • Add persistent route context, sanitized preview status, responsive layouts, reduced-motion behavior, and synchronized GitHub/npm setup documentation.

[0.2.5] - 2026-07-31

Added

  • Add a sanitized successful hosted-chat screenshot and a visible guide to the required Sign in with ChatGPT browser extension across the website, GitHub README, npm README, and troubleshooting documentation.
  • Explain that the hosted extension requirement is separate from the local npm wizard callback, where a callback-capturing extension may need to be disabled temporarily during sign-in.

[0.2.4] - 2026-07-31

Changed

  • Add explicit foundation and attribution language for Evan Zhou Dev's openai-oauth project to the GitHub and npm README explanations.

[0.2.3] - 2026-07-31

Added

  • Add sanitized GPT-5.6 Sol and Luna AI Agent examples, a model-selector compatibility preview, and the completed Docker sidecar state to both the GitHub and npm README experiences.

[0.2.2] - 2026-07-30

Added

  • Add aligned npm keywords and GitHub repository topics for Relmio, GPT model variants, n8n, AI agents, and API-key discovery.

[0.2.1] - 2026-07-30

Added

  • Add the hosted ChatGPT site link to the package metadata and public guides.
  • Document the upstream Codex relay model, known limitations, and legal responsibilities in both the GitHub and npm README variants.
  • Add a command-first install page for the current n8n and Hostinger VPS wizard, plus a GitHub control with live package and repository metadata.
  • Credit Evan Zhou Dev's openai-oauth method on the hosted Relmio page.

Changed

  • Refresh the local setup wizard and hosted chat presentation with the Relmio redesign, including clearer progress, copy feedback, responsive layouts, and request-state affordances.
  • Move the hosted chat and package homepage to relmio.vercel.app with Node.js 22 and repository-driven preview and production deployments.
  • Return ChatGPT OAuth callbacks to the deployment that started sign-in so Vercel preview URLs and the production domain both work.
  • Run hosted web linting, type checks, builds, tests, and dependency auditing in GitHub Actions alongside repository-driven deployments.
  • Point package and documentation metadata at the canonical relmio repository.
  • License Relmio under Apache 2.0 and preserve the upstream openai-oauth attribution in the distributed notice.

Fixed

  • Stream hosted chat responses incrementally through deployment proxies and surface safe request errors instead of leaving an empty assistant message.
  • Distinguish a ChatGPT hosting-network challenge from an expired OAuth session without exposing upstream response bodies or credentials.

[0.2.0] - 2026-07-29

Added

  • Add a provider-neutral product roadmap with a gated SuperGrok/xAI OAuth feasibility track, entitlement checks, and explicit security boundaries.
  • Add a trusted-publisher GitHub Actions workflow for short-lived npm authentication after the first package publication.

Changed

  • Rename the public product and npm package to Relmio and relmio so the project can grow beyond its initial n8n setup path.
  • Replace the generic plus icon with an original two-lane relay mark and add a small brand guide with reusable SVG and source concept assets.
  • Publish a concise npm-specific README with absolute image and documentation URLs while preserving the full GitHub README and its Mermaid diagrams.
  • Build and inspect a deterministic npm tarball so the registry receives the npm-specific README instead of the repository README.
  • Keep the legacy n8n-openai-oauth-setup executable alias and every deployed n8n-openai-oauth compatibility and safety identifier unchanged.

[0.1.8] - 2026-07-29

Changed

  • Restore the complete manual sidecar installation path to the README for wizard failures, debugging, and contributor reproduction.
  • Add plain-English Mermaid diagrams that explain the private sidecar and help readers choose between the browser wizard and manual setup.
  • Keep the README and standalone manual Docker templates synchronized with automated documentation checks.

0.1.7 - 2026-07-28

Changed

  • Add prominent workflow-backup reminders to the README, manual guide, troubleshooting guide, and browser wizard before VPS access.

0.1.6 - 2026-07-28

Added

  • Add a public npm quick-start guide with five sanitized setup screenshots, Mermaid architecture diagrams, and a YouTube walkthrough outline.
  • Add individual Base URL/API-key copy controls and n8n recipes for OpenAI Chat Model, AI Agent, Basic LLM Chain, and HTTP Request nodes.
  • Add a release metadata validator that keeps the package, lockfile, changelog, and release tag on one version.
  • Add GitHub Actions checks with immutable action pins, no persisted checkout credential, and the repository's pinned npm 10.9.8 runtime.

Changed

  • Expand troubleshooting for stale wizard sessions, npm versions, local OAuth callbacks, SSH failures, Docker networks, real port mappings, and manual sidecar collisions.
  • Use the wizard-only ~/.n8n-openai-oauth/auth.json path consistently in the manual and maintenance guides.
  • Replace pre-publication wording and add the local context file to the shared ignore policy.
  • Disable npm lifecycle scripts explicitly in every documented and nested npx invocation.
  • Add a prominent workflow-backup reminder before local setup and inside the wizard because VPS access remains a real write boundary even with sidecar-only commands.
  • Separate OpenAI credential fields from OpenAI Chat Model settings and explain the Responses API compatibility behavior for Chat Model node version 1.3.
  • Polish the public README with a collapsible contents list, clickable project links, experimental-use disclaimers, and a contributor guide.
  • Document Graphify as an optional local maintainer map while keeping raw graph exports out of Git and npm.

Fixed

  • Prevent sanitized preview mode from generating or opening a live OpenAI authorization URL.
  • Refuse to show the ready screen when the sidecar returns no usable model ID.
  • Tag the exact commit that passed CI and was published instead of relying on the shell's current HEAD.
  • Make the sanitized preview follow the production OAuth service contract and show the correct private n8n Base URL.
  • Fall back to a temporary selected text field when a browser denies the modern Clipboard API, so the final credential copy buttons still work.
  • Always remove the fallback copy field and restore focus when legacy browser clipboard access throws.
  • Stop and remove only the named wizard-managed sidecar service when its final safety check detects an unexpected host-port publication; report an explicit manual cleanup path if that removal cannot be confirmed.
  • Clean up the sidecar when publication inspection fails or returns malformed metadata, rate-limit install attempts, close the VPS connection after every install outcome, and show actionable browser recovery messages.

0.1.5 - 2026-07-28

Fixed

  • Detect a newly approved ChatGPT credential as soon as its complete file is available instead of waiting for the OAuth helper process to close.
  • Poll the local sign-in state more frequently during the first ten seconds so the wizard responds quickly after browser approval.
  • Show the local credential's update time and announce when a fresh sign-in has been saved.

0.1.4 - 2026-07-28

Fixed

  • Run ChatGPT login against a new wizard-only credential file so the bridge CLI never needs an interactive terminal to confirm replacement.
  • Validate the completed credential before storing it at ~/.n8n-openai-oauth/auth.json with owner-only permissions.
  • Stop reusing or overwriting the Codex app credential at ~/.codex/auth.json.
  • Open the exact fresh authorization URL returned by the pinned bridge CLI and report its completion separately, avoiding stale browser sign-in tabs.
  • Verify Docker Compose publisher metadata so an internal-only 10531/tcp declaration is not mistaken for a published VPS host port.
  • Explain that browser extensions which intercept the localhost OAuth callback must be disabled temporarily during a fresh sign-in.

0.1.3 - 2026-07-27

Fixed

  • Let the explicit Refresh ChatGPT sign-in action confirm replacement of an existing local OAuth credential. Previously, the bridge CLI prompt had no input stream, defaulted to “No,” and the wizard reported that sign-in did not finish.
  • Clarify when the wizard will reuse an existing credential and when to refresh it.

0.1.2 - 2026-07-27

Fixed

  • Provide a writable /home/node/.local tmpfs so the non-root bridge can start while the container root filesystem remains read-only.
  • Use the collision-resistant Docker hostname n8n-openai-oauth so an existing manual openai-oauth sidecar cannot capture n8n requests.
  • Treat a wizard-managed deployment as an update, allowing a fresh local ChatGPT sign-in to refresh its OAuth credential safely.

0.1.1 - 2026-07-27

Fixed

  • Quote the generated Compose healthcheck command so Docker Compose validates it as a string.

0.1.0 - 2026-07-27

Added

  • Local browser wizard for installing the OpenAI OAuth sidecar beside a self-hosted n8n Docker deployment.
  • Read-only n8n and Docker-network discovery.
  • Explicit review and confirmation before remote sidecar writes.
  • Safety checks that prevent changes to the existing n8n Compose project, image, container, or host port mappings.
  • npx-friendly CLI entry point and beginner documentation.

Security

  • OAuth credentials stay on the local computer until the user approves an SFTP upload to the installer-managed sidecar directory.
  • SSH host-key confirmation is required before password authentication.
  • The sidecar uses an internal-only Docker network endpoint and no published VPS port.