changelog
Changelog
Upgrade with uv tool upgrade keygrant (or pipx upgrade keygrant). Releases are on PyPI.
0.1.6 2026-10-10
- Fix: base64 redaction now catches a secret at any byte alignment. A key encoded after a prefix whose length isn't a multiple of 3 (for example
Authorization: Bearer) previously slipped through.
0.1.5 2026-10-10
- Fix: an unanswered desktop dialog now really escalates to the phone approver (0.1.4 always fell through to deny).
- Audit trail with
off,metadataandfulllevels, uploaded on sync (keygrant cloud audit). keygrant devices remove, with automatic vault key rotation when a machine is removed.
0.1.4 2026-10-10
- Fix: pairing prompts on macOS and Linux (0.1.3 couldn't pair there).
keygrant recover: join a new machine with the Emergency Kit alone;keygrant cloud enable-recoveryfor older accounts.- Phone approver: pair a browser at app.keygrant.app; unanswered requests escalate to it (see 0.1.5).
listandexecpull cloud changes first, at most once a minute, silently when offline.keygrant cloud delete.- Clearer errors when a device was removed or a proxy is in the way.
0.1.3 2026-10-09
- Security: grants are bound to the exact command and held in memory only. Before this, a grant covered every command using that secret for 15 minutes and lived in a file another process could edit.
- End-to-end encrypted cloud sync, as an opt-in preview (
keygrant[cloud]). The default install has no dependencies.
0.1.2 2026-10-08
- Listed in the official MCP Registry as
io.github.bazingaedward/keygrant.
0.1.1 2026-10-08
- PyPI page renders the demo images.
0.1.0 2026-10-08
- First release on PyPI.