- Refactor deep imports by targeting specific sub-modules in `@oh-my-pi/pi-ai` to reduce barrel file overhead.
- Utilize jitless ArkType scopes in schema definitions to reduce startup JIT codegen costs by approximately 65%.
- Reorganize internal `auth-storage` exports to maintain clean boundaries between core and broker-specific functionality.
- Added AuthStorage.listResetCredits to query each stored Codex account from the reset-credits endpoint and return live availability plus active or error state.
- Exposed the new status fetch through AgentSession and switched reset-usage selectors and commands to consume it via toResetUsageAccounts.
- Updated reset-usage UI and slash-command output to show per-account errors and updated empty-state messaging when resets could not be loaded.
- Extracted `limitMatchesActiveAccount`/`reportMatchesActiveAccount` into `slash-commands/helpers/active-oauth-account.ts` as the single definition of the report-to-account matching rules, including projectId matching against `limit.scope.projectId`/metadata.
- Dropped the duplicated `ActiveAccountIdentity`/`OAuthAccessResolver` shims, `as unknown` session casts, the dead `getOAuthAccountId` fallback, and the email-vs-scope-accountId comparison from `command-controller.ts` and `usage-report.ts`.
- Replaced the async per-provider `resolveActiveAccountsForReports` map with one synchronous typed `authStorage.getOAuthAccountIdentity()` call per render, gated to the session's current provider.
- Re-exported `OAuthAccountIdentity` from `session/auth-storage.ts` and added `active-oauth-account.test.ts` covering the matching rules.
- Added `getCredentialOrigin` and `getEnvApiKeyName` to classify auth source.
- Surfaced provenance tags in the `/login` and `/logout` provider picker.
- Made the picker search filter match credential origin and env var name.
- Added coverage for credential-origin precedence and env naming.
- Added AES-GCM cache for at-rest broker snapshots keyed on token, with URL as additional data.
- Added `onSnapshot` hook to RemoteAuthCredentialStore for persisting applied snapshots.
- Exposed cache read/write and TTL defaults through the coding-agent re-exports.
- Added `getAuthBrokerSnapshotCachePath` with `OMP_AUTH_BROKER_SNAPSHOT_CACHE` override.
- Added `AuthBrokerClient`, `RemoteAuthCredentialStore`, `AuthBrokerRefresher`, and `startAuthBroker` server in `packages/ai/src/auth-broker`.
- Renamed `AuthCredentialStore` class to `SqliteAuthCredentialStore`; extracted `AuthCredentialStore` as a persistence interface.
- Added `exportSnapshot`, `forceRefreshCredentialById`, `disableCredentialById`, and `upsertCredential` to `AuthStorage` for broker wire protocol.
- Added `omp auth-broker` CLI subcommand (serve, token, login, logout, import, status) and `discoverAuthStorage` broker-mode path keyed on `OMP_AUTH_BROKER_URL`.
- Replaced all StringEnum(...) usages with z.enum([...]) across tools, examples, and tests.
- Removed StringEnum re-export from @oh-my-pi/pi-coding-agent public API.
- Condensed verbose tool parameter descriptions to minimal lowercase phrases.
- Renamed AuthCredentialStore to SqliteAuthCredentialStore at usage sites.
- Extracted credential storage to shared @oh-my-pi/pi-ai package with AuthCredentialStore and AuthStorage classes.
- Consolidated UI formatting logic from ToolUIKit class into standalone utility functions across render-utils and output-meta modules.
- Moved utility functions (parseCommandArgs, substituteArgs, expandPath, normalizeUnicode) to dedicated modules for improved code reuse.
- Extracted JTD type definitions and type guards to jtd-utils module for shared use across schema conversion tools.
- Updated Claude model pricing and added cache read costs in models.json for accurate billing calculations.
- Refactored agent-storage to delegate credential management to AuthCredentialStore instead of direct SQLite operations.
- Added GitLab Duo provider with support for Claude, GPT-5, and Duo Chat models via GitLab AI Gateway.
- Added OAuth authentication for GitLab Duo with automatic token refresh, PKCE security, and 25-minute token caching.
- Added 16 new GitLab Duo models including Claude Opus/Sonnet/Haiku and GPT-5 variants with reasoning and multimodal support.
- Added `isOAuth` option to Anthropic provider for OAuth bearer token authentication mode.
- Exported `streamGitLabDuo`, `getGitLabDuoModels`, and `clearGitLabDuoDirectAccessCache` functions for GitLab Duo integration.
- Exported readModelCache and writeModelCache functions for SQLite-backed model cache access.
- Migrated model cache storage from per-provider JSON files to unified SQLite database (models.db).
- Renamed cachePath option to cacheDbPath in ModelManagerOptions for database-backed storage.
- Improved non-authoritative cache handling with 5-minute retry backoff instead of per-startup retries.
- Added peekApiKey method to AuthStorage for non-blocking API key retrieval during model discovery.
- Added <turn_aborted> guidance marker as synthetic user message for aborted/errored assistant messages.
- Improved OAuth token refresh error messages to include provider-specific error details from API responses.
- Separated rate limit and usage limit error handling in OpenAI response handler with distinct error messages and retry timing.
- Enhanced error message propagation in OAuth refresh flow to preserve original error reasons for better debugging.
- Fixed regex pattern in auth storage to use word boundaries for accurate HTTP status code matching.
- Added `includeDisabled` parameter to `listAuthCredentials()` to optionally retrieve disabled credentials.
- Added `disableAuthCredential()` method for soft-deleting auth credentials while preserving database records.
- Changed auth credential removal to use soft-delete (disable) instead of hard-delete when OAuth refresh fails, keeping credentials in database for audit purposes.
- Added `disabled` column to auth_credentials table schema with automatic migration from v3 to v4.
- Added prepared statements for querying active (non-disabled) credentials with optional provider filtering.
- Added support for 11 new AI providers (Hugging Face, NVIDIA, Together, Ollama, LiteLLM, Xiaomi, Moonshot, Venice, Qwen Portal, vLLM, Cloudflare AI Gateway) with API key authentication and login flows.
- Implemented $pickenv() utility for environment variable fallback chains, enabling multi-key resolution for providers with alternative credential names.
- Extended KnownProvider and OAuthProvider types to include all 11 new providers with corresponding model manager functions and OAuth handlers.
- Expanded models.json with thousands of new model entries across all new providers and replaced deprecated opencode provider with cloudflare-ai-gateway.
- Refactored model generation script to use unified fetchProviderModelsFromCatalog() and centralized API key resolution for all providers.
- Fixes deferred `--model` resolution to match extension-provided models before fallback
- Fixes CLI `--api-key` handling to support deferred model selection
- Adds OAuth provider support for extensions with source-scoped registration cleanup
- Adds custom API registration helpers with built-in collision checks
- Expands `Api` type to support extension-defined identifiers
- Adds tests for runtime provider registration and model selection
- Added Perplexity OAuth authentication support with native macOS app extraction and email OTP login flows.
- Implemented loginPerplexity and refreshPerplexityToken functions for OAuth token management.
- Created PerplexitySocket class providing Socket.IO v4 client over Engine.IO v4 WebSocket transport with RPC support.
- Added OAuth authentication to Perplexity web search provider with automatic token refresh and SSE streaming support.
- Extended SearchResponse interface with authMode field to track authentication method (oauth or api_key).
- Changed PerplexityProvider.isAvailable() to async to support OAuth token availability checking.
Add support for z.ai's GLM Coding Plan as a provider accessible via `/login`.
Implements API key-based authentication similar to Kimi Code.
Changes:
- Create login flow in `utils/oauth/zai.ts` with browser redirect to API keys page
- Add API key storage methods (`saveApiKey`, `getApiKey`) to CliAuthStorage
- Register Z.AI in OAuth provider types, exports, and CLI handler
- Add GLM-5 model to Z.AI provider
Users can now authenticate with:
bunx @oh-my-pi/pi-ai login zai
- Migrated authentication storage from JSON-based (auth.json) to database-based (agent.db) format across test files and configuration.
- Simplified auth storage discovery in sdk.ts by removing manual path construction and fallback logic in favor of centralized getAgentDbPath() function.
- Removed dbPath instance property from AuthStorage class as database path is now managed centrally.
- Updated environment variable precedence documentation to reflect agent.db instead of auth.json as the lowest priority source.
- Removed OAuth provider section header comments from multiple test files for cleaner test organization.
- Added support for JSON and JSONC configuration file formats without requiring migration to YAML.
- Removed legacy auth.json file-based authentication migration system and simplified AuthStorage to use only agent.db for credential storage.
- Simplified AuthStorage API by removing authPath and fallbackPaths parameters, now accepting only dbPath for improved startup performance.
- Deleted storage-migration.ts module containing legacy JSON-to-SQLite migration logic that is no longer needed.
- Removed getAuthPath() configuration function from config.ts as auth.json file-based storage is no longer supported.
- Refactored SSE stream parsing to use generic `readSseJson` utility instead of domain-specific handlers across multiple packages.
- Migrated from Node.js Buffer API to Web standard APIs (Uint8Array, TextDecoder, DataView) for cross-platform compatibility.
- Simplified stream transformation pipeline by consolidating multiple stream operations into unified `createTextLineSplitter` utility.
- Refactored `ptree.ts` to remove complex stream pumping infrastructure and simplify stderr handling with direct async iteration.
- Rewrote stream utilities to operate at binary level with byte-level parsing for improved efficiency and reduced string allocations.
- Updated TypeScript configuration to include DOM.AsyncIterable type definitions for async iterable DOM API support.
- Converted class properties to TypeScript parameter properties across 51 files to reduce boilerplate code.
- Removed explicit field declarations and manual assignments in constructors by using TypeScript's parameter property syntax with access modifiers.
- Applied consistent pattern of declaring private readonly and public readonly properties directly in constructor parameters.
- Added OpenCode Zen provider with API key-based authentication supporting multiple AI models.
- Added four new free models via OpenCode provider: glm-4.7-free, kimi-k2.5-free, minimax-m2.1-free, and trinity-large-preview-free.
- Added glm-4.7-flash model via Zai provider.
- Updated pricing and configuration for multiple models across Kimi, MiniMax, OpenRouter, Anthropic, Vercel AI Gateway, and Zai providers.
- Removed google/gemini-2.0-flash-exp:free from OpenRouter and stealth models from Vercel AI Gateway.
- Improved OAuth token refresh error handling to distinguish between definitive auth failures and transient errors.
- Added logic to only remove credentials for definitive failures (invalid_grant, revoked, expired tokens) while temporarily blocking credentials for transient errors like network timeouts.
- Enhanced error message handling in commit agent to display error messages when stopReason is 'error'.
- Added debug stack trace output for agent errors when DEBUG environment variable is set.
- Added Kimi Code provider integration with OAuth device authorization flow and token management.
- Added four new Kimi Code models (kimi-for-coding, kimi-k2, kimi-k2-turbo-preview, kimi-k2.5) with reasoning support and 262K context window.
- Added kimiUsageProvider for fetching and caching Kimi Code API usage quota information.
- Added kimi-code login command to CLI for OAuth authentication with Kimi Code.
- Updated openai-completions provider to support Kimi-specific headers and cached token formats.
- Updated MiniMax-M2 model pricing: input 1.2->0.6, output 1.2->3, cacheRead 0.6->0.1.
- Removed Prettier configuration files (.prettierignore and .prettierrc) and migrated formatting to Biome.
- Updated Biome configuration from version 2.3.11 to 2.3.12 and changed arrowParentheses rule from 'always' to 'asNeeded'.
- Pinned @biomejs/biome dependency to exact version 2.3.12 in package.json and bun.lock.
- Applied consistent arrow function formatting across 489 files by removing unnecessary parentheses around single parameters.
- Removed blank lines after comment blocks and reorganized imports for consistency across the codebase.
- Converted readdirSync, readFileSync, and statSync to async readdir, readFile, stat across skills and agent discovery.
- Made scanDirectoryForSkills async and refactored custom directory scanning to use Promise.all for concurrent processing.
- Updated agent discovery to use fs/promises for async file reading and refactored helper patterns.
- Added AgentParsingError exception class for better error handling during agent parsing.
- Added filesystem error type guards (isEnoent, isEacces, isPerm, etc.) to pi-utils for safe error checking.
- Added color manipulation utilities to pi-utils for accessibility features.
- Added color-blind mode setting to settings manager.
- Migrated plugins, settings, and config modules from sync to async file operations.
- Updated error handling to use new pi-utils type guards for type-safe checking.
- Removed WASM generation script; use Bun `wasm?raw` loader for imports.
- Added bunfig.toml with loaders for `.md`, `.py`, and `.wasm?raw` text imports.
- Added types/assets/index.d.ts for global TypeScript module declarations.
- Unified TypeScript configuration with tsgo-based checking across monorepo.
- Removed build and WASM steps from install and publish pipelines.
- Added tsconfig.publish.json files to all packages with optimized publish-time configuration.
- Updated all package.json scripts with prepublishOnly hooks for correct type checking during publish.
- Added @oh-my-pi/omp-stats path mappings to root tsconfig.json for consistent imports.
- Added WASM generation script for photon module and integrated into install:dev script.
- Added retry utility functions `isRetryableError` and `extractHttpStatusFromError` to the @ai package for identifying transient errors suitable for retry operations.
- Made `AgentStorage.open()` asynchronous with exponential backoff retry logic to handle SQLITE_BUSY errors during concurrent database access.
- Refactored `AuthStorage` to use async factory pattern with `create()` method instead of synchronous constructor for proper async initialization.
- Added graceful error handling in terminal operations to exit cleanly when terminal becomes unavailable due to EIO errors instead of crashing.
- Added error handling during emergency terminal restore to prevent errors when terminal is already dead during crash cleanup.