- Selected the direct CommandCode
/alpha/generatebridge design instead of per-requestcmd -psubprocess wrapping. - Created isolated workspace:
~/workspace/commandcode-bridge. - Recorded PRD and implementation plan before production implementation.
- TDD policy: tests are written before source implementation.
COMMANDCODE_SANDBOX=true COMMANDCODE_API_URL=http://127.0.0.1:<port>allows capturing CLI traffic without spending upstream tokens.GET /alpha/whoamisucceeds with the API key in~/.commandcode/auth.json.POST /alpha/generatesucceeds withparams.stream=trueand returns JSON-line/SSE-like events.params.stream=falseis rejected with HTTP 400.- Live bridge smoke found a stale process on
127.0.0.1:9992; always check/clear port ownership before validating a fresh build. - Current account state returns an application-level stream error over HTTP 200:
Insufficient BalancewithstatusCode: 402. The bridge now maps this to non-streaming HTTP 502commandcode_event_errorand streaming SSE error +[DONE]. - Start-only upstream streams are treated as
commandcode_empty_response; blank OpenAI 200 completions with zero usage are not accepted as success. - Independent review found and fixed two release blockers: Docker build inputs now include
tsconfig.build.json/vitest.config.ts, and streaming upstream exceptions are converted into SSE error frames plus[DONE]instead of resetting the client stream. - Added
.dockerignore, logger secret-header redaction, env model-alias normalization, and removed unverifiedMemoryDenyWriteExecute=truefrom the systemd unit because it can break Node/V8 JIT.
- Updated default CommandCode CLI header to
0.26.7. - Added multi-key upstream credential loading:
COMMANDCODE_CREDENTIALS_FILE,COMMANDCODE_CREDENTIALS,COMMANDCODE_API_KEYS, and legacyCOMMANDCODE_API_KEYfallback. - Added
round_robinanddepletion_awarerouting. Depletion-aware routing caches/alpha/billing/credits,/alpha/billing/subscriptions, and/alpha/usage/summarysnapshots per credential and routes expiring credits first. - Added credential health rules and failover: 401 disables, 402 drains/cools down, 429/5xx/timeouts cooldown, and pre-visible-output stream errors can retry on another credential.
/healthnow reports credential count and routing policy without exposing raw upstream keys.
- Renamed the workspace/package from
commander-commandcode-bridgetocommandcode-bridge; removed the old internal remote pending future GitHub publication. - Added Hermes/OpenAI
developerrole compatibility by folding developer messages into the upstream system prompt. - Fixed two tool-call reliability blockers found during strict review: malformed
tool_callsnow fail OpenAI-style validation, and normal Fastify request close no longer aborts upstream generation. - Hardened follow-up tool history conversion: assistant
tool_callsare no longer flattened into visible prose such asAssistant requested tool calls, tool results no longer expose OpenAI call IDs, and a system guard marks prior function context as internal bridge context. - Verification:
npm run typecheck, all 72 Vitest tests,npm run build, LaunchAgent restart,/health, and Hermes provider tool-loop smoke all passed.
- Extracted the model catalog, aliases, and pricing into
src/model-catalog.ts. - Added startup configuration smoke coverage and hardened server configuration validation.
- Added a Korean, English, and Chinese dashboard language switcher with persisted selection, plus
README.zh.md. - Kept the bridge aligned with CommandCode releases from
0.26.7through0.40.3; most intervening commits were version and catalog synchronization.
- Aligned request conversion, types, the model catalog, and tests with the CommandCode
1.3.1contract. - Preserved
developermessages and tool-call history across the revised upstream request shape.
- Established CommandCode
1.14.0as the release baseline and added per-model context-window metadata. - Added
DESIGN.mdand refreshed the architecture, deployment, security, and multilingual README documentation. - Expanded credential routing, dashboard, server configuration, and contract test coverage for the new release.
- Released bridge version
1.14.0.c. - Made the official CommandCode Provider API the default path, with startup model-catalog refresh and the legacy
/alpha/generatetunnel retained for unsupported plans and Claude models. - Added quota-aware multi-key routing, soonest-expiring balance drain priority, pre-output failover, and a configurable five-attempt transient retry budget.
- Hardened admin authentication and credential updates with timing-safe comparison and secret preservation.
- Consolidated the admin API key field into the server configuration card and surfaced backend save errors in the dashboard.
- Released bridge version
1.14.0.d. - Forwarded OpenAI follow-up tool history to Alpha as native
tool-call/role:toolparts instead of flattening it into user text, so non-streaming tool loops can complete after the first call.
- Released bridge version
1.14.0.e. - Added warn-level empty-visible diagnostics, a one-shot non-streaming retry for
finish_reason=lengthwith no visible text or tool calls, JSON guidance for compatibility-probe 404s, and runtimebridgeApiKeySourceon/healthand/admin/config.
- Released bridge version
1.14.0.f. - Retrieve unencoded slash model ids on
GET /v1/models/*, and treat Alpha forced/requiredtool_choiceas auto instead of returning 400.
- Released bridge version
1.25.0.aaligned with CommandCode CLI1.25.0. - Added
zai-org/GLM-5.3,google/gemini-3.7-flash, andxai/grok-4.6to the static catalog (55 models). CLI 1.22 itself only mergedread_multiple_filesintoread_fileand does not change the bridge wire.
- Released bridge version
1.25.0.b. - Added dashboard enable-all / disable-all controls beside the models heading.
- Released bridge version
1.28.1.aaligned with CommandCode CLI1.28.1. - Added
Qwen/Qwen3.8-27Bto the static catalog (56 models). GPT-5.6 Sol advertised price stays $5/$30 after the 1.27.1 standard-pricing note.
- Released bridge version
1.31.0.aaligned with CommandCode CLI1.31.0. - Added
stealth/ox-alpha(free stealth preview, 1,048,576 context) to the static catalog (57 models) and added theclaude-haiku-4-5alias now published by the CLI. - Repriced DeepSeek V4 Pro/Flash (off-peak $0.66/$1.98 and $0.22/$0.66; peak rates noted) and GPT-5.6 Terra/Luna ($2/$12, $0.2/$1.2) to the current published rates.
- Filled static context windows from the live Provider API (GLM-5.1, MiniMax M2.7, Qwen 3.6 Max Preview/Plus, GPT-5.5) and corrected Qwen 3.8 27B/Tencent Hy3 to 262,144 and Gemini 3.7 Flash/Muse Spark/Ox Alpha to 1,048,576.
- Released bridge version
1.32.1.aaligned with CommandCode CLI1.32.1. - Added
deepseek/deepseek-v4-flash-vision-expto the static catalog (58 models). - Client disconnects during a completion now release the credential slot without recording a failure or cooldown, abort the upstream body read, and log a single info line instead of a 500 "Unhandled chat completion error"; previously an abort parked the credential in cooldown and burst requests failed 503.
- Tool-call events whose name arrives as multiplexed XML-ish frames (observed on
stealth/ox-alpha) are split into separate OpenAItool_callswith deterministic ids, with acommandcode_multiplexed_tool_callwarn log. - Live QA against
stealth/ox-alphaverified: streaming tool calls, forced single tools, parallel tool calls, three-result tool history follow-ups, and abort-then-burst recovery.
- Merged PR
ef7e64d(author 이재현, branchpr-2-rebased):fix(openai): forward CommandCode cache usage— OpenAI usage objects now carryprompt_tokens_details.cached_tokensfrom upstreamcachedInputTokens/inputTokenDetails.cacheReadTokens, in both non-stream and stream usage chunks. Merged into localmainvia fast-forward; combined tree passes all gates. - Released bridge version
1.32.1.b. - CLI 1.32.1 bundle drift audit (one-shot field-level diff of
/alpha/generate): the bridge now defaultsmax_tokensto the CLI wire value64000when the client omits it, forwards OpenAIreasoning_effortinto Alpha params, drops the vestigialx-co-flagheader the CLI no longer sends, and sendsx-cmd-zdr: 1whenCOMMANDCODE_ZDRis on (matching the CLI'sbuildCommandAuthHeaders). Verified parity: body envelope (config/memory/taste/skills/permissionMode/threadId),toWireMessages/toWireToolsshapes, and the remaining header set.
- Updated the locally installed CommandCode CLI from
1.32.1to1.32.2. - Audited the npm package diff and installed bundle. The release fixes the BYOK model picker and malformed tool-result session recovery; the Alpha endpoint constants and adjacent wire contract remain unchanged, so no bridge protocol change was required.
- Confirmed the static catalog remains at 58 models. CommandCode's reference table only corrected the unexposed cache-read price for
deepseek/deepseek-v4-flash-vision-expfrom$0.01to$0.007. - Released bridge version
1.32.2.a, updated the default advertised CLI version, and aligned all English, Korean, and Chinese README version references.
- Updated the locally installed CommandCode CLI from
1.32.2to1.36.0and audited the complete npm package diff across releases 1.33.0 through 1.36.0. - Added
z-ai/glm-5.3-flash,minimax/minimax-m3-free,minimax/minimax-m2.7-free, andQwen/Qwen3.8-Flash; retiredstealth/ox-alpha. The static catalog now contains 61 models. - Compared the Alpha request function around
/alpha/generate: request envelope, headers, message/tool conversion, reasoning effort, 64K default output limit, and stream contract remain semantically unchanged. Existing generic multiplexed tool-call handling covers GLM-5.3 Flash without a model-specific parser. - Released bridge version
1.36.0.a, updated the default advertised CLI version, and aligned all English, Korean, and Chinese README version references and model tables.
- Updated the locally installed CommandCode CLI from
1.36.0to1.38.2and audited npm releases 1.37.0 through 1.38.2. - Added
tencent/hy4-previewwith a 1,048,576-token context window and published$0.834/Minput,$2.501/Moutput pricing. Updated Gemini 3.7 Flash to the corrected$1.5/Minput and$7.5/Moutput pricing. The static catalog now contains 62 models. - Audited the Alpha request and stream implementation for reasoning effort and tool-call changes. Custom-agent reasoning effort and Tencent tool-efficiency improvements are CLI-local; the bridge already forwards
reasoning_effortand emits canonical tool messages, so no protocol parser change was required. - Released bridge version
1.38.2.a, updated the default advertised CLI version, and aligned English, Korean, and Chinese README version references and model tables.
- Aligned the bridge from
1.38.2.ato1.49.0.awith CommandCode CLI1.49.0. npm metadata confirms both CLI releases require Node.js>=22; runtime dependencies are unchanged, with only development-dependency ordering changed in the package manifest. - Audited
npm diff [email protected] [email protected] --diff-name-only, the changelog, and every changed readable bundled reference. The published model table adds eight models and removes the two MiniMax Free models, leaving 68 visible canonical models. No retained model's advertised input/output prices or context windows changed. - Added
deepseek/deepseek-v4-flash-fast(1,000,000 context; $0.28/$0.56 input/output per million tokens),Qwen/Qwen3.8-Max-0902(1,000,000; $2/$6),meituan/LongCat-2.0:free(1,048,576; $0/$0),claude-fable-5-1(1,000,000; $10/$50),gpt-6-astra(1,050,000; $10/$50),google/gemini-3.8-flash(1,000,000; $1.5/$7.5),meta/muse-spark-1.3(1,048,576; $1.25/$4.25), andmeta/muse-spark-1.3-contributor(1,048,576; $0.1/$0.2). Prices come from the shipped officialmodels.md; exact context integers come from the installed bundle's model definitions/context map, not rounded table labels. Existing Provider-derived context metadata remains intact. - Retired
minimax/minimax-m3-freeandminimax/minimax-m2.7-free, including their four previously shipped aliases. The CLI still recognizes these historical ids but marks their definitions hidden; the changelog explicitly retires them and the current model table omits them. Persisted retired entries and allowlists are filtered, retired defaults fall back to DeepSeek V4 Pro, and unknown-model mode cannot bypass retirement. Custom models and the six established enabled defaults are preserved; all eight additions are opt-in. - Independent read-only wire audit found no upgrade-specific protocol change: Alpha envelope, headers, 64,000 default output limit, reasoning-effort serialization, message/tool conversion, and stream consumption remain unchanged apart from binding renames. Provider-binding auth selection, browser sign-in, feature-model ZDR filtering, compaction, document reads, and TUI/config behavior are CLI-local. No protocol code changed; this is not a claim of full bridge/CLI parity. Existing text-only EOF acceptance, string-error loss, and tool input/args precedence are separate audit candidates, not part of this release.
- Updated all current English, Korean, and Chinese README version/catalog badges and tables, deployment defaults, environment example, package/lockfile versions, and dashboard/version assertions. Preserved earlier process-log entries and the untracked local
AGENTS.md. - Regression-first verification observed 10 expected failures before implementation (version, catalog, context, dashboard, and six retired-id cases). Focused config/dashboard/Alpha/Provider/server tests then passed: 122 tests in five files. Full
npm testpassed once: 222 tests in 15 files. LSP diagnostics on all five changed TypeScript files,npm run typecheck,npm run lint, andnpm run buildpassed. - Built-artifact HTTP QA used isolated HOME/config/auth, a local unused port, Alpha mode, and a non-routable upstream. The listening log event signaled readiness without polling.
/healthreturned1.49.0.a,/v1/modelsreturned all 68 canonical models (192 entries with aliases) with matching context fields, and an empty chat request returned structured400 invalid_request. Both QA processes were stopped.node dist/index.js --helpstill starts the HTTP server rather than printing help; this existing behavior was observed and its process stopped.
- Released bridge-only version
1.74.0.don CommandCode CLI1.74.0: deleting a credential from the dashboard no longer needs the bridge API key. Saving a deletion failed with401 Unauthorizedin any browser without the stored client key, and the Credentials tab gave no hint where to enter it. - New
DELETE /admin/config/credentials/:id, exempt from bridge-key auth by owner decision. It removes the credential from the dashboard file, removes it from the running Alpha and Provider routers (with its session pins) so it stops serving at once, and returns the saved configuration. When the file lists no credentials yet (env or CLI auth keys), it writes the remaining keys to the file so the deletion survives a restart. It refuses an unknown id (404) and the last credential (409last_credential). Other settings, adding keys, and restarts still require the key. - The Credentials tab's delete button now asks for confirmation and applies the deletion immediately; unsaved new rows are still removed locally. The tab description says deletions apply on confirm.
- Security: anyone who can reach the bridge can delete credentials (not add or replace them). Cross-origin pages are stopped by the CORS preflight a
DELETEneeds; DNS rebinding against a loopback-only bridge is not covered. Documented indocs/SECURITY.md. - Verification: regression-first, 4 expected failures before implementation (router removal, keyless delete persisted and listed while
PUTstill returns 401, env-sourced deletion written to the file, last/unknown refusal).npm run verifypassed with 311 tests in 16 files. Headless-browser QA against the built bridge with no stored client key: the delete button asked for confirmation, removedbetaat once with a success toast, the row stayed gone after the 5-second refresh, the file keptalphaandbridgeApiKey, live requests without a restart used onlyalpha, and deleting the last key showed the localized refusal. The same QA first caught Fastify rejecting the body-lessDELETEsent withcontent-type: application/json; the dashboard now sends{}.
- Released bridge-only version
1.74.0.con CommandCode CLI1.74.0, fixing dashboard credential deletion (and editing) that did not take effect. - Cause 1: the dashboard saves credentials to
resolveConfigFilePath()(COMMANDCODE_CREDENTIALS_FILE, else$XDG_CONFIG_HOME/commandcode-bridge/credentials.jsonor~/.config/commandcode-bridge/credentials.json), but startup credential loading read that file only whenCOMMANDCODE_CREDENTIALS_FILEwas non-empty.install.sh,.env.example, andrelease/env.production.exampleleave it empty, so on those installs every dashboard credential edit was saved and then ignored after restart in favour ofCOMMANDCODE_API_KEY(S)or CLI auth. Startup now reads credentials from the same path the dashboard writes. - Cause 2: after a save,
GET /admin/configkept returning the running configuration until restart, so the dashboard's 5-second refresh redrew a just-deleted key. While a restart is pending it now returns the saved configuration (stilldirty: true,restart_required: true). - Cause 3: when the file did not yet list an env- or CLI-sourced key (for example
default), saving kept that row without a secret and the writer dropped it. Secret lookup now also uses the running configuration's credentials. - Unchanged by design: a file with no credentials still falls back to
COMMANDCODE_CREDENTIALS/COMMANDCODE_API_KEYS,COMMANDCODE_API_KEY, then CLI auth, so deleting the last dashboard key brings back an env/CLI key; remove that key from the env file or auth file instead. Existing installs whose credentials file already lists keys saved earlier from the dashboard will start using those keys after updating. - Verification: regression-first, 3 expected failures before the fix (default-path loading, saved list after save, env-key secret on first save) plus a guard for the empty-file fallback.
npm run verifypassed with 307 tests in 16 files. Built-artifact QA with the installer's env (COMMANDCODE_API_KEYset,COMMANDCODE_CREDENTIALS_FILE=""): deletingbfrom a dashboard file holdinga,b, adding a key next to the env key, and deleting the env-sourceddefaultwhile keeping a dashboard key each showed the saved list immediately, on the next refresh, and after restart; deleting the last dashboard key fell back to the env key as documented.
- Released bridge-only version
1.74.0.bon CommandCode CLI1.74.0with PR #7 (commit187107e, merge278e83a) and PR #8 (commit5f5141a, merge0eea7eb) from WhatAHappyPig (A8Cl233395). - PR #7: CommandCode reports a drained key as HTTP 400 with an "insufficient credits" message rather than 402, and the bridge treated every 400 as client-scoped, so the key stayed in rotation and kept failing. Both paths now pass the upstream error message to the router; a 400 matching
insufficient (credits|balance)is credential-scoped and starts aninsufficient_creditscooldown ofmax(COMMANDCODE_CREDENTIAL_COOLDOWN_MS, billing refresh). Unlike 402, a billing refresh does not clear it, because upstream pre-charges the estimated cost and a positive balance can still be too small. The installed CLI 1.74.0 uses the same check (400 === status && message.toLowerCase().includes("insufficient credits")). - PR #8: one shared
shouldRetryStatus(statusCode, errorMessage)now drives both paths. Insufficient-credits 400s and 403s rotate to another key within the request (the Alpha path did not retry 403 before), with the failed key excluded for the rest of the request. Other 400/404/422 fail fast; 429/5xx keep retrying without a cooldown. - With a single key, a drained key now returns
NoAvailableCommandCodeCredentialError(503) for the cooldown window instead of repeating the upstream 400. The dashboard shows the new state as "Cooling" because it readsdisabledUntil.PREMIUM_CREDITS_EXHAUSTED, which the CLI also recognizes, is not classified. - Updated the README routing paragraph (English, Korean, Chinese),
docs/KNOW_HOW.md,docs/ARCHITECTURE.md, and both deployment guides. - Verification: PR CI passed on Node 20/22/24 for both PRs; locally #7 alone passed 299 tests and #7 + #8 on
mainpassed 303 tests in 16 files, andnpm run verifypassed on the release commit. Built-artifact HTTP QA with two keys against a mock Alpha upstream: a key answering 400 "Insufficient credits" made the first request rotate to the other key and succeed (200), later requests skipped the drained key, and a plain 400 made exactly one upstream call and failed.
- Updated the locally installed CommandCode CLI from
1.66.0to1.74.0and released bridge version1.74.0.a. - Audited the changelog for 1.67.0 through 1.74.0,
npm diff [email protected] [email protected](changed:package.json,CHANGELOG.md, bundled knowledge/config/mod-builder references,dist/cli.mjs, and the VS Code extension archive), and the bundledmodels.md. - Added four opt-in models from the installed bundle, in
models.mdrow order:deepseek/deepseek-v4.1-flash-fast(1,000,000 context; $0.16/$0.58),inclusionai/ling-3.1-flash:free(262,144; $0/$0),claude-sonnet-5-5(1,000,000; $2/$10), andgpt-6.1-sol(1,050,000; $2/$10). Context integers come from the bundle's context map. - Retired
stealth/pixel-canary: 1.73.1 hides it after its stealth preview ended on 2026-09-30 at 11 PM Pacific (get hidden(){return isPixelCanaryEnded()}) and the currentmodels.mdomits it. It joinsLEGACY_RETIRED_MODEL_IDSinstead of being aliased. - Repriced
xai/grok-4.7from$1.2/$3.6to$2/$6. - Re-derived the text-only image set from
isKnownTextOnlyModel: the only addition isinclusionai/ling-3.1-flash:free. The other three new models declare image input. - Reasoning effort: 1.73.3 adds
offto the DeepSeek V4/V4.1 effort lists, and the Alpha body builder forwards the selected effort unchanged (...a?{reasoning_effort:a}:{}), so the CLI now sendsreasoning_effort: "off". The bridge request schema accepted onlyminimalthroughmaxand returned 400 foroff; it now acceptsoffand forwards it on the Alpha path. The Provider path still never forwardsreasoning_effort, which matches the CLI provider bindings that drop reasoning options foroff. The 1.73.4maxeffort for Space Bunny Alpha needs no bridge change because the bridge does not gate efforts per model. - Wire audit of both bundles found no other bridge-facing change: the
/alpha/generatebody envelope andparamskeys, the 64,000 defaultmax_tokens,toWireMessages, and the billing/usage probes are identical apart from minifier renames.buildCommandAuthHeadersgained an optionalx-cli-surfaceheader, but it is set only bycmd acp(acp) andcmd rpc(rpc), never by the regular CLI the bridge mirrors, so the bridge does not send it. ACP mode,/rcremote control, separate planning/implementation models, mod toggles, and BYOK package bumps are CLI-only. - Aligned current version references in
package.json,package-lock.json,src/version.ts, the defaultCOMMANDCODE_CLI_VERSION,.env.example,release/env.production.example,install.sh, the deployment guides, the dashboard demo data, and the English, Korean, and Chinese READMEs (badges, catalog baseline, example version, and model tables). - Regression-first verification observed 9 expected failures before implementation (CLI version, catalog, contexts, four opt-in merges, the Ling 3.1 image limit, and
reasoning_effort: "off").npm run verifythen passed with 293 tests in 16 files, followed bynpm run build,npm pack --dry-run(commandcode-bridge-1.74.0.a.tgz, 53 files), andgit diff --check. - Built-artifact HTTP QA against a mock Alpha upstream:
/healthreported1.74.0.a,/v1/modelslisted opted-inclaude-sonnet-5-5andgpt-6.1-solbut notstealth/pixel-canary, an empty chat body returned400 invalid_request,reasoning_effort: "off"reached the upstream body unchanged withx-command-code-version: 1.74.0and nox-cli-surface, and an explicitly allowedstealth/pixel-canarywas still refused with400 model_not_allowed.node dist/index.js --helpstill starts the server instead of printing help.
- Released bridge-only version
1.66.0.don CommandCode CLI1.66.0with PR #6 from WhatAHappyPig (A8Cl233395, commit48f0bbb, mergeec97dcd). - Incident: every terminal upstream failure used to call
recordFailure, including at-capacity errors that arrive as statusless streamerrorevents and transient failures that were retried and then succeeded. On a single-key deployment that benched the only key forCOMMANDCODE_CREDENTIAL_COOLDOWN_MS(60 s), and every request in that window failed in about 1 ms withNoAvailableCommandCodeCredentialError. - Both the Alpha (
/alpha/generate) and Provider (/provider/v1/chat/completions) paths now record a failure only for credential-scoped statuses (401/402/403). HTTP 429/5xx, empty bodies, streamerrorevents, network errors, and caller aborts release the in-flight slot without a cooldown. Retries within a request and the per-request exclusion of already-tried keys are unchanged. - When every credential is cooling down at attempt zero, selection retries with
ignoreCooldown, so a cooled key still serves; auth-disabled and billing-disabled keys stay excluded. COMMANDCODE_CREDENTIAL_COOLDOWN_MSnow only sets the minimum 402 cooldown. The router still maps 429/5xx/statusless failures to a cooldown whenrecordFailureis called with them, but neither request path does so any more. With several keys, a key-specific 429 no longer steers later requests away for 60 s; only the failing request fails over.- Updated the README routing paragraph (English, Korean, Chinese),
docs/KNOW_HOW.md,docs/ARCHITECTURE.md, and both deployment guides, which still described 429/5xx/timeout cooldowns. - Verification: PR CI passed on Node 20/22/24;
npm run verifyon mergedmainpassed with 284 tests in 16 files.
- Released bridge-only version
1.66.0.con CommandCode CLI1.66.0, importing two routing ideas from kiro-lb (design only; no kiro-lb code, which is AGPL-3.0). - Session affinity: the credential router remembers which key served a conversation, keyed by a SHA-256 of the system text plus the first user message, and prefers that key on later turns so the upstream prompt cache stays warm. The pin is a preference only: health, capacity, urgent-expiry, and exclusion filters run first, and failover re-pins the conversation to the next choice. Pins expire after
COMMANDCODE_SESSION_AFFINITY_TTL_MS(default 2 hours,0disables) and are capped at 10,000 with least-recently-served eviction. Applies to the Alpha and Provider paths. - Stable conversation identity: the CLI keeps one random v4 UUID as
threadId/x-session-idfor a whole conversation, while the bridge sent a new one per request. The bridge now derives a v4-shaped UUID from the conversation key so every turn shares it. The conversation key itself stays bridge-local and is never sent upstream; the Alpha body keeps exactly the CLI key set. - Diagnostics and the dashboard credential table report live pinned conversations per key (
activeSessions). - Not imported: Rust rewrite, off-request-path billing refresh (it would weaken the pre-selection expiry filter), client setup commands, prompt reduction, and binary releases.
- Verification:
npm run verifypassed with 280 tests in 16 files. A built bridge with three keys against a mock upstream sent three turns of one conversation on one key with onex-session-id, moved a second conversation to another key, and reportedactiveSessions1/1/0.
- Released bridge-only version
1.66.0.bon CommandCode CLI1.66.0: the dashboard was rebuilt with the kiro-lb operations-console layout in the yelixir.dev palette and typography. - The new dashboard is three static files in
dashboard/(index.html,app.css,app.js) with no build step or dependency.GET /dashboard/serves them from a fixed whitelist (unknown names and path traversal return 404);/and/dashboardredirect to/dashboard/and keep the query string. The packagefileslist and the Docker runtime image now includedashboard/. - Tabs: Overview (five KPI cards, a browser-sampled dithered live-load chart, a balance-by-key donut, credential health with 5-hour and weekly limit meters), Credentials, Models (grouped by provider with search), Settings (bind, client API key, routing policy, per-key concurrency), and Info. It keeps the Korean, English, and Chinese locales, adds a light theme, and adds
?demosample data that never calls a write endpoint. It uses only the existing/healthand/admin/*endpoints, so no API contract changed. - The previous inline dashboard (
src/dashboard.ts) and its 29 string-level tests (tests/dashboard-ui.test.ts) were removed. The last revision serving it is commitdfc0761, taggedlegacy-dashboard-1.66.0.a, which also introduced the preview at/test-page/; that preview route is gone now that the page is the dashboard. - Verification: server tests cover the whitelist, redirects, query preservation, and CSP. Headless Chromium against the built bridge confirmed live and demo rendering, tab and keyboard navigation, model search, the save bar, theme and language switching, no console errors, and no page-level horizontal overflow at 375 px.
- Updated the locally installed CommandCode CLI from
1.53.0to1.66.0and released bridge version1.66.0.a. - Audited
npm diff [email protected] [email protected], the changelog for 1.53.1 through 1.66.0, and the bundledmodels.mdreference. Changed files werepackage.json,CHANGELOG.md, the bundled knowledge references, the new bundledloopskill,dist/cli.mjs, and the VS Code extension archive. - Added 13 opt-in models from the installed bundle:
z-ai/glm-5.3-flashx,xiaomi/mimo-v2.6-pro,xiaomi/mimo-v2.6-pro-ultraspeed,xiaomi/mimo-v2.6-flash,Qwen/Qwen3.8-Omni-Flash, paidmeituan/LongCat-2.0,stepfun/Step-5-Preview,stealth/space-bunny-alpha,stealth/pixel-canary,claude-opus-5-5,gpt-6-sol,gpt-6-luna, andxai/grok-4.7. Retiredmeituan/LongCat-2.0:free(the CLI now marks it hidden and non-selectable) throughLEGACY_RETIRED_MODEL_IDS, taking the static catalog from 70 to 82 models. The six established enabled defaults are unchanged. - Repriced
deepseek/deepseek-v4-flash-vision-expto$0.15/$0.6andstepfun/Step-3.5-Flashto$0.09/$0.3;stepfun/Step-3.5-Flashcontext moved from 1,000,000 to 262,144. Context integers come from the bundle's context map, not the rounded table labels. - Re-derived the text-only image set from
isKnownTextOnlyModel: the only addition is paidmeituan/LongCat-2.0, sosrc/model-images.tsstrips images for it as the CLI does. All other new models declare image input. - Wire audit of both bundles found no bridge-facing contract change: the
/alpha/generatebody envelope andparamskeys, the 64,000 defaultmax_tokens,buildCommandAuthHeadersheader names, andtoWireMessagesare identical apart from minifier renames. New additive items stay out of the bridge: acache-write-tokensstream event the CLI folds into usage (the bridge ignores unknown events and never reported cache-write counts), aconversationIdon the local telemetry span, the Provider API OpenAI Responses endpoint and/provider/v1/systemonefortypesafe/jev(the bridge keeps using/provider/v1/chat/completions), and CLI-local/loop, herdr, clipboard paste, plan-review, sub-agent card, telemetry, BYOK session-id, and usage-display changes. - Aligned current version references in
package.json,package-lock.json,src/version.ts, the defaultCOMMANDCODE_CLI_VERSION,.env.example,release/env.production.example,install.sh, the deployment guides, the dashboard version assertion, and the English, Korean, and Chinese READMEs (badges, catalog baseline, and model tables). - Regression-first verification observed 17 expected catalog, image, and version failures before implementation.
- Bridge-only release
1.53.0.cincorporates PR #3 and the image-input policy from issue #5; the CLI baseline remains1.53.0and the 70-model catalog is unchanged. - With
INCLUDE_REASONING=true, streaming and non-streaming responses return reasoning separately inreasoning_content, rather than appending it tocontent. Clients displaying reasoning must read the separate field. Provider empty-response retries count reasoning only when it is exposed. - Alpha forwards base64 image inputs as native image parts with
mimeType; remote URLs remain text placeholders. Both transports apply the CLI's 23-model text-only input policy, including aliases, while preserving vision-capable and unknown-model fallback behavior. - Contributor commits are preserved in the merge of PR #3. The release contains no deployment credentials or environment changes.
- Released bridge version
1.53.0.bagainst an unchanged CommandCode CLI1.53.0; this is a bridge-only bugfix release and no catalog, model, or version default other than the bridge version string changed. - Fixed the dashboard restart path reported in issue #4.
auth()skippedfullBridgeKey()wheneverpendingBridgeKeywas set, while the server reported the configured key as[REDACTED]andlocalStoragewas written only after a successful restart, so the restart request left without an Authorization header and returned 401. The pending key now participates in authentication directly. - Replaced the silent
restartBridge()no-op with an explicitresolveRestartMode({ platform, env })returningsystemd,exit,launchctl, orunsupported. An unsupervised linux process now answersPOST /admin/restartwithrestart_requested: false, arestart_mode, and a reason, keeps the configuration marked dirty, and the dashboard shows an instruction to restart the service by hand instead of polling for a restart that cannot happen. The bridge still refuses to exit without a declared supervisor, because an unsupervised exit would end the service rather than restart it. - Set
COMMANDCODE_BRIDGE_RESTART_MODE=exitindocker-compose.ymlandrelease/docker-compose.ymlbeside the existingrestart: unless-stopped, and documented the prerequisite in both deployment guides and all three READMEs. - Stopped forwarding
top_pandstopin the generate body. The CLI wire body built bytoWireMessages/postStreamin[email protected]carries onlymodel,messages,tools,system,max_tokens,stream, and optionaltemperatureandreasoning_effort, so both fields made bridge traffic distinguishable from CLI traffic. Clients may still send them; they are dropped before the upstream request. - Reviewed PR #3 (
reasoning_content) against the CLI bundle. Assistant{type:"reasoning"}parts and emitting tool-result images as a followingusermessage matchtoWireMessagesexactly, but the image part field ismimeTyperather thanmediaTypeand the CLI only ever builds image parts from data URIs; those two changes plus a commit split were requested before merge. - Opened issue #5 for the remaining CLI behavior the bridge cannot yet mirror: the CLI drops image parts for models without an image input modality (
supportsVisionthenstripImages), and the bridge model catalog carries no modality data. - Closed PR #1 as superseded. Three catalog alignments landed since it was opened, its additions other than
commandcode/taste-1are already present,commandcode/taste-1appears nowhere in the shipped CLI bundle, and the retirement it performed is already handled throughLEGACY_RETIRED_MODEL_IDS. - Verification:
npm run verifypassed end to end (typecheck, eslint, Prettier, 233 tests in 15 files, build). Seven tests were added for restart-mode resolution, the droppedtop_p/stopfields, and the two dashboard behaviors; two existing assertions that pinned the old buggyauth()expression and a hardcodedrestart_requested: truewere updated to the corrected contract.
- Updated the locally installed CommandCode CLI from
1.49.0to1.53.0and released bridge version1.53.0.a. - Audited
npm diff [email protected] [email protected], the changelog, and every changed readable bundled reference. Onlypackage.json,CHANGELOG.md, the bundledmcp.md/models.md/product-help.mdreferences,dist/cli.mjs, and the VS Code extension archive changed; npm metadata keepsengines.node >= 22and unchanged runtime dependencies. - Added
deepseek/deepseek-v4.1-flash(1,000,000 context; $0.15/$0.6) andinclusionai/ling-3.0-flash-sante:free(262,144 context; $0/$0), taking the static catalog to 70 models. Both are opt-in; the six established enabled defaults are unchanged, and the historicalinclusionai/ling-3.0-flash-freeid stays retired and distinct from the new Sante model. - Repriced
deepseek/deepseek-v4-flashto the published$0.15/$0.6and dropped its obsolete peak/off-peak note. No other retained model's advertised price or context window changed. Context integers come from the installed bundle's model definitions rather than the rounded table labels. - Release notes classified as CLI-local: MCP env-placeholder resolution with
${VAR:-default}, WSL2 screenshot pasting andAlt+Vimage paste, MCP OAuth RFC 8707 resource indicators, stable process title, UNIX-socket idle/working/blocked status reporting, Anthropic caching improvements, org spend-cap messaging, MiniMax M3 effort tiers, and the withdrawn DeepSeek V4.1 Flash Beta. No bridge-facing wire contract difference was found, so no protocol code changed. - Aligned all current version references:
package.json,package-lock.json,src/version.ts, the defaultCOMMANDCODE_CLI_VERSIONinsrc/config.ts,.env.example,release/env.production.example,install.sh, the deployment guides, the dashboard version assertion, and the English, Korean, and Chinese README badges, catalog baselines, and model tables.install.shandrelease/env.production.examplealso moved off their stale1.14.0CLI default. - An independent read-only differential audit of both npm bundles found the Alpha caching work of 1.50.0 to be additive rather than breaking:
params.systemmay now be a structured block list withcache_control,promptCacheis an optional top-level field, and one-hour cache-write counts arrive as extra provider metadata. The bridge keeps sending a string system prompt with nopromptCache, its parsers ignore unknown metadata, and existingcacheReadTokens/cacheWriteTokensmapping stays correct, so no protocol code changed. Adopting cache blocks or org spend-cap surfacing would be separate feature work./alpha/generatetransport,buildCommandAuthHeaders,toWireMessages/toWireTools, the 64,000 default output limit, and the NDJSON stream reader are unchanged. - Regression-first verification observed 6 expected catalog/version failures before implementation, then 30 passing focused config tests. The full suite passed once with 226 tests in 15 files, alongside
npm run typecheck,npm run lint, Prettier checks on the changed parser-supported files,npm run build,npm pack --dry-run, andgit diff --check.
- Branch:
main, synchronized withorigin/mainwhen this status audit began. - Package:
commandcode-bridge1.74.0.d, Node.js>=20, withcommandcode-bridgeandcommandcode-routerexecutables. - API surface: authenticated OpenAI-compatible
/v1/modelsand/v1/chat/completions, health endpoint, and the static/dashboard/operations console over same-origin admin configuration. - Model surface: 85 statically aligned models (CommandCode CLI 1.74.0) with live Provider API refresh when available.
- Routing surface:
daily_burn_priority,balance_priority,round_robin, anddrain_first, with per-key model scope, concurrency, cooldown, failover, and retry controls. - Deployment surface: Docker/Compose, Linux install/uninstall scripts, nginx and systemd release assets, and GitHub/GitLab CI definitions.
- Verification baseline: merged PR #3 passed 265 tests in 17 files, local HTTP QA, and GitHub CI on Node 20, 22, and 24. Release and deployment checks are performed separately for each version.
- Local workspace instruction file
AGENTS.mdremains untracked and is excluded from release commits. - Local HTTP QA verifies
/healthreports the current bridge release,/v1/modelsreturns the configured model list, and an empty chat request returns the expected structured400 invalid_request. - Session recovery note: the current Senpi transcript exists at the path in
PI_SESSION_FILE. Cross-platform local session search found no recoverable project implementation transcript covering the missing period, so the entries above were reconstructed from Git history and verified against the current source and test suite.