Changelog
Format: Added, Changed, Fixed, Security, Known issues. Versions follow SemVer; REST stays under /api/v1 and MCP tool names are frozen within a major.
Unreleased
Added
- MCP tools
searchandfetchfor ChatGPT Deep Research and company knowledge (OpenAI compatibility schema).search(query)returns{results: [{id, title, url}]}, one result per Page;fetch(id)returns{id, title, text, url, metadata}. Both are read-only, declare anoutputSchema, returnstructuredContentplus the same JSON as text, and use absolute<PUBLIC_URL>/n/<id>links. They go through the same vault calls ascontext_searchandcontext_get, so grants, ceiling, redaction and audit are unchanged. 16 tools in total. context_get,context_related,context_archiveandcontext_restoreacceptnode_idas an alias ofid, matching the field namecontext_searchreturns.
Changed
- MCP tool input schemas are strict: an unknown argument returns an error that names the key instead of being dropped silently.
- MCP capabilities advertise
listChanged: falsefor tools, resources and prompts; the stateless server never sends change notifications.
0.1.0 (2026-09-29)
First release, built and deployed to staging in one night.
Added
- Git-backed store: one repository per workspace, every write a commit authored by the principal, single writer queue,
If-Match/base_shawith three-way merge, 409 plus automatic proposal on conflict. - Sensitivity levels
public,internal,confidential,secretper Page and per block, redaction to the caller's ceiling, AES-256-GCM sealed secret blocks inside git. - SQLite FTS5 index with optional local embeddings (
Xenova/bge-small-en-v1.5), hybrid ranking, andcontext_bundletoken-budgeted bundles with nonce fences and cited sources. - Identity: sign-up with a personal workspace, members and invites (link only, no mailer), owner seeding from
OWNER_EMAIL/OWNER_PASSWORDon first boot only, argon2id passwords, TOTP, step-up, CSRF double-submit, session management. - Agents with per-agent grants, ceilings and
nxc_keys; creator-bounded permissions; time-boxed elevations for secret access; workspace lockdown. - OAuth 2.1 authorization server for MCP clients: protected resource and authorization server metadata, dynamic client registration, PKCE S256, consent screen, audience-bound access tokens, rotating refresh tokens with reuse detection.
- MCP endpoint (
/mcpand/w/:slug/mcp, stateless streamable HTTP) with 14 tools:context_bundle,context_search,context_get,context_tree,context_related,context_propose,context_write,context_log,context_archive,context_restore,context_whoami,collab_post,collab_inbox,collab_ack; resourcenexara://index; promptload_project_context. - REST API under
/api/v1(98 routes including auth, OAuth and git), see REST API. - Threads on every Page mirrored to
<page>.threads.md, inbox with long-poll, agent loop and spam guard. - Proposals with accept, edit-and-accept and reject.
- Lifecycle: relevance decay, nightly 03:00 UTC archive candidates (
LIFECYCLE_MODE=dryby default), Page and Folder archive and restore. - Git smart HTTP for Obsidian Git with
nxg_tokens and a pre-receive hook (main only, no symlinks or submodules, no unsealed secrets or raw credentials, no sensitivity downgrades). - Importer (CLI and zip upload), reindex and audit-verify CLIs, hash-chained audit log.
- Web app: sign-in and sign-up, home, tree, page editor with conflict panel, search palette, threads, inbox, proposals, agents with ready-made client snippets, audit, archive, import, settings, OAuth consent, workspace switcher; light and dark themes; mobile layout.
- Dockerfile, CI (typecheck, tests, build, Docker smoke),
scripts/smoke.sh, staging on Coolify athttps://dev.nexara.ac. nexaraCLI incli/(login, whoami, bundle, search, get, tree, propose, log, capture, inbox, doctor) and themcp-proxystdio bridge. Built from source; not yet on npm.- This documentation site (
docs/site/) with API and MCP references generated from the code.
Fixed
OWNER_*variables now seed only the very first human, so a stale environment cannot add a second owner.- Docker build installs dev dependencies even when Coolify injects
NODE_ENV=production. - Web: readable tree titles, inbox and audit show page names, relevance score removed from search, keyboard handler crash, 390 px overflow on home, honest session labels.
Known issues
- Open red-team findings C1, C2, H1 to H3 and M1 to M7, listed on the Security page.
- Not yet built: CLI OAuth login and npm package, ChatGPT
search/fetchtools, capture endpoint, email for invites, automated backups, OpenAPI document, passkeys. - Production app exists in Coolify but has not been deployed.