Repository navigation
Releases: yelixir-dev/commandcode-bridge
Release list
CommandCode Bridge 1.74.0.d
CommandCode Bridge 1.74.0.d lets you delete a credential from the dashboard without the bridge API key. The CommandCode CLI baseline remains 1.74.0; the 85-model catalog is unchanged.
What changed
- Deleting a credential and pressing Save used to fail with
401 Unauthorizedin any browser that had not stored the client key, and the Credentials tab gave no place to enter it. - The delete button on the Credentials tab now asks for confirmation and applies the deletion immediately. No Save, no restart, and no key are needed: the bridge stops using that key for new requests at once, and the deletion is written to the credentials file so it survives a restart.
- Keys that came from
COMMANDCODE_API_KEY(S)or the CLI auth file can be deleted too; the remaining keys are written to the credentials file. - The last credential cannot be deleted (add another key first). Unknown ids return 404.
- Adding or replacing keys, other settings, and restarts still require the bridge API key.
Security notice
Anyone who can reach the bridge can now delete credentials (not add or replace them). A web page on another origin cannot trigger it, because a DELETE needs a CORS preflight that the bridge answers only for the same hostname; DNS rebinding against a loopback-only bridge is not covered. Keep the bridge on a trusted network. See docs/SECURITY.md.
Updating an installation
Install or rebuild this version using the deployment method already in use and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.74.0.d afterward. After that, delete keys directly from the Credentials tab.
The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.
Verification scope
npm run verify passed with 311 tests in 16 files, and GitHub CI passed on Node 20, 22, and 24. A headless browser against the built bridge, with no stored client key, deleted a credential after confirmation, kept it deleted across the dashboard refresh, routed live requests only to the remaining key without a restart, and refused the last key. Live upstream calls and Windows are not covered by those checks.
CommandCode Bridge 1.74.0.c
CommandCode Bridge 1.74.0.c fixes dashboard credential deletion and editing that did not take effect. The CommandCode CLI baseline remains 1.74.0; the 85-model catalog is unchanged.
What was wrong
- The dashboard saves credentials to
~/.config/commandcode-bridge/credentials.json(orCOMMANDCODE_CREDENTIALS_FILE, or$XDG_CONFIG_HOME/commandcode-bridge/credentials.json), but at startup the bridge read that file only whenCOMMANDCODE_CREDENTIALS_FILEwas set to a non-empty value.install.shand the env examples leave it empty, so on those installs deleted or added keys were saved and then ignored after restart; the key fromCOMMANDCODE_API_KEY(S)or the CLI auth file kept appearing. - After saving, the dashboard's 5-second refresh redrew the running (old) credential list until restart, so a deleted key looked like it came back.
- The first save could drop an env-sourced key such as
defaultfrom the file because its secret was not found.
Fixes
- Startup now reads credentials from the same file the dashboard writes, whether or not
COMMANDCODE_CREDENTIALS_FILEis set. - Until restart, the dashboard shows the saved configuration (still marked as needing a restart).
- Saving keeps the secret of a credential that currently comes from the env or CLI auth.
Compatibility notice
- Saved dashboard keys start being used. If you edited credentials in the dashboard on an install where
COMMANDCODE_CREDENTIALS_FILEwas empty, those saved keys were ignored until now. After updating and restarting, the bridge uses the keys listed in the credentials file instead ofCOMMANDCODE_API_KEY. Check the Credentials tab after the restart. - The last key cannot be removed from the dashboard if an env key exists. When the file lists no credentials, the bridge still falls back to
COMMANDCODE_CREDENTIALS/COMMANDCODE_API_KEYS,COMMANDCODE_API_KEY, then the CLI auth file. To retire that key, remove it from the env file (or auth file) and restart.
Updating an installation
Install or rebuild this version using the deployment method already in use, preserve the existing credentials and dashboard configuration, and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.74.0.c afterward, then delete the unwanted credential, save, and restart once more.
The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.
Verification scope
npm run verify passed with 307 tests in 16 files, and GitHub CI passed on Node 20, 22, and 24. The built bridge, run with the installer's env layout, kept deletions and additions across the save, the next dashboard refresh, and a restart. Live upstream calls and Windows are not covered by those checks.
CommandCode Bridge 1.74.0.b
CommandCode Bridge 1.74.0.b releases PR #7 and PR #8, which change how a drained CommandCode key is handled. The CommandCode CLI baseline remains 1.74.0; the 85-model catalog is unchanged.
Compatibility notice: drained keys
CommandCode reports a key with no usable credit as HTTP 400 with an "insufficient credits" message, not 402. The bridge used to treat every 400 as a client error, so a drained key stayed in rotation and kept failing requests.
- A 400 "insufficient credits" response now cools the key down for the larger of
COMMANDCODE_CREDENTIAL_COOLDOWN_MSand the billing refresh interval (5 minutes by default). Unlike 402, a billing refresh does not clear it early, because upstream pre-charges the estimated request cost and a positive balance can still be too small. This matches the CLI's own check. - The failing request moves to another key instead of failing. 403 responses now rotate on the Alpha path too, as they already did on the Provider path.
- With a single key, a drained key returns
503(NoAvailableCommandCodeCredentialError) for the cooldown window instead of repeating the upstream 400. After topping up, requests may stay refused for up to that window. The dashboard shows the key as "Cooling". - Other 400, 404 and 422 responses still fail immediately with no retry and no cooldown. 429/5xx keep retrying without a cooldown, as in
1.66.0.d.
Updating an installation
Install or rebuild this version using the deployment method already in use, preserve the existing credentials and dashboard configuration, and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.74.0.b afterward.
The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.
Verification scope
npm run verify passed with 303 tests in 16 files, and GitHub CI passed on Node 20, 22, and 24. The built bridge passed local HTTP QA with two keys against a mock upstream: an insufficient-credits 400 rotated the request to the other key, later requests skipped the drained key, and a plain 400 failed after one upstream call. Live upstream billing behavior and Windows are not covered by those checks.
CommandCode Bridge 1.74.0.a
CommandCode Bridge 1.74.0.a aligns the bridge with CommandCode CLI 1.74.0 and is the first GitHub release since 1.53.0.c. It rolls up the untagged-until-now bridge versions 1.66.0.a through 1.66.0.d, which are now tagged individually. The static catalog has 85 models.
Compatibility notices
- Dashboard replaced (1.66.0.b).
/dashboard/is now a static operations console served fromdashboard/(Overview, Credentials, Models, Settings, Info; Korean, English, and Chinese; light theme;?demo)./and/dashboardredirect to/dashboard/. It uses the existing/healthand/admin/*endpoints, so no API contract changed. The previous inline dashboard is kept under the taglegacy-dashboard-1.66.0.a. - Cooldown policy (1.66.0.d, PR #6). Only credential-scoped failures (401/402/403) disable or cool down a key. HTTP 429/5xx, empty bodies, stream
errorevents, and network errors are retried within the request but no longer bench the key, so a single-key deployment no longer fails every request for 60 s after one at-capacity error.COMMANDCODE_CREDENTIAL_COOLDOWN_MSnow only sets the minimum 402 cooldown. With several keys, a key-specific 429 no longer steers later requests away for 60 s. - Retired model (1.74.0.a).
stealth/pixel-canaryis removed because the CLI hides it after its stealth preview ended on 2026-09-30. Persisted entries and allowlist entries for it are dropped, and requests for it return400 model_not_allowed. - Session affinity (1.66.0.c). Turns of one conversation (same system text and first user message) stay on the key that served it, and the bridge sends one stable
threadId/x-session-idper conversation, as the CLI does.COMMANDCODE_SESSION_AFFINITY_TTL_MS=0disables it. It has been verified against a mock upstream only.
Catalog changes
- CLI 1.74.0 (1.74.0.a): adds opt-in
deepseek/deepseek-v4.1-flash-fast,inclusionai/ling-3.1-flash:free,claude-sonnet-5-5, andgpt-6.1-sol; retiresstealth/pixel-canary; repricesxai/grok-4.7to$2/$6. Images are stripped for the new text-onlyinclusionai/ling-3.1-flash:free. - CLI 1.66.0 (1.66.0.a): adds 13 opt-in models (
z-ai/glm-5.3-flashx,xiaomi/mimo-v2.6-pro,xiaomi/mimo-v2.6-pro-ultraspeed,xiaomi/mimo-v2.6-flash,Qwen/Qwen3.8-Omni-Flash, paidmeituan/LongCat-2.0,stepfun/Step-5-Preview,stealth/space-bunny-alpha,stealth/pixel-canary,claude-opus-5-5,gpt-6-sol,gpt-6-luna,xai/grok-4.7), retiresmeituan/LongCat-2.0:free, and repricesdeepseek/deepseek-v4-flash-vision-expandstepfun/Step-3.5-Flash. - New models are disabled by default; the six established defaults are unchanged. Enable new models from the dashboard or
COMMANDCODE_ALLOWED_MODELS.
Fixes and improvements
reasoning_effort: "off"is accepted and forwarded on the Alpha path. CLI 1.73.3 sends it for DeepSeek V4/V4.1 when thinking is disabled; the bridge used to reject it with 400.- The default
COMMANDCODE_CLI_VERSIONis1.74.0. A wire audit of the 1.66.0 and 1.74.0 bundles found no other bridge-facing change; the newx-cli-surfaceheader is sent only bycmd acp/cmd rpc, so the bridge does not send it. - Tests no longer read the host's real dashboard config or CLI auth files, so
npm testandnpm run verifypass on a host that also runs a deployment.
Updating an installation
Install or rebuild this version using the deployment method already in use, preserve the existing credentials and dashboard configuration, and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.74.0.a afterward. Docker images must be rebuilt to pick up dashboard/, which is now part of the runtime image.
The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.
Verification scope
npm run verify passed with 293 tests in 16 files, and GitHub CI passed on Node 20, 22, and 24. The built bridge passed local HTTP QA against a mock upstream (/health, /v1/models, request validation, reasoning_effort: "off", retired-model refusal). Live upstream inference, real multi-account session affinity, and Windows are not covered by those checks.
Thanks to WhatAHappyPig for PR #6.
CommandCode Bridge 1.53.0.c
CommandCode Bridge 1.53.0.c incorporates PR #3 and the text-only image policy from issue #5. The CommandCode CLI baseline remains 1.53.0; the 70-model catalog is unchanged.
Compatibility notice: reasoning output
With INCLUDE_REASONING=true, reasoning is no longer appended to content:
- Streaming clients receive
delta.reasoning_content. - Non-streaming clients receive
message.reasoning_content.
Clients that display reasoning must read the separate field. Assistant history containing reasoning_content is forwarded as native reasoning parts on the Alpha path. With reasoning disabled, Provider responses strip that field.
Fixes and improvements
- Provider non-streaming visibility and retry checks now agree: exposed reasoning-only responses return without an unnecessary retry, while hidden reasoning does not turn an empty
lengthresponse into blank success. - Alpha sends base64 image data URIs as native image parts with the CLI's
mimeTypefield. Remote URLs remain text placeholders; the bridge does not download them. - Both Alpha and Provider apply the CLI 1.53.0 text-only model list, including aliases. Images are removed for those models and replaced with numbered/omission text markers without mutating the original conversation.
- Vision-capable models retain image input. Unknown/custom models follow the CLI's image-capable fallback; that fallback is not a guarantee that a particular upstream model supports vision.
Thanks to the PR #3 contributor for the image and reasoning implementation. The original contributor commits are preserved.
Updating an installation
Install or rebuild this version using the deployment method already in use, preserve the existing credentials and dashboard configuration, and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.53.0.c afterward.
For Docker deployments still using files older than 1.53.0.b, take the updated Compose file and recreate the container. The dashboard restart button needs both COMMANDCODE_BRIDGE_RESTART_MODE=exit and an external restart policy.
The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.
Verification scope
The merged implementation passed 265 tests across 17 files, local HTTP QA, independent review, and GitHub CI on Node 20, 22, and 24. Release validation checks the versioned build and npm package separately. Windows and live upstream inference are not covered by those local checks.
CommandCode Bridge 1.53.0.b
Bridge-only bugfix release against an unchanged CommandCode CLI 1.53.0. No catalog, model, or configuration default changed other than the bridge version string.
Fixed
Dashboard restart under Docker (#4) — two cascading bugs made saved model changes impossible to apply in a container.
- The restart request lost its Authorization header after a save and returned
401.auth()skippedfullBridgeKey()whenever a pending client key was set, while the server reported the configured key as[REDACTED]andlocalStoragewas written only after a successful restart. The pending key now participates in authentication directly. POST /admin/restartanswered{"ok":true}while doing nothing on an unsupervised process. It now returnsrestart_requested: falsewith arestart_modeand a reason, keeps the configuration marked dirty, and the dashboard tells the operator to restart the service instead of polling for a restart that cannot happen.
Upstream request shape — top_p and stop are no longer forwarded to CommandCode. The CLI wire body carries only model, messages, tools, system, max_tokens, stream, and optional temperature and reasoning_effort, so forwarding those two fields made bridge traffic distinguishable from CLI traffic. Clients may still send them; they are dropped before the upstream request.
Action required for Docker users
The dashboard restart button needs a supervised process. systemd is detected automatically; every other supervisor, including Docker with a restart policy, requires COMMANDCODE_BRIDGE_RESTART_MODE=exit.
Both shipped Compose files now set it, so pull the updated docker-compose.yml (or release/docker-compose.yml) and recreate the container:
git pull
docker compose up -d --buildRunning the new code with an old Compose file leaves the restart button reporting that the deployment cannot restart itself. That message is accurate; restart the container by hand, or adopt the updated Compose file.
Verification
npm run verify passes end to end: typecheck, eslint, Prettier, 233 tests in 15 files, and build.