providers/anthropic:
- Bump claudeCodeVersion to 2.1.63; system instruction identifies as Claude Agent SDK
- X-Stainless-Os and X-Stainless-Arch now runtime-computed via mapStainlessOs/mapStainlessArch
- Remove X-Stainless-Helper-Method; update package version to 0.74.0, runtime to v24.3.0
- Remove fine-grained-tool-streaming-2025-05-14 from default beta set; add
context-management-2025-06-27 and prompt-caching-scope-2026-01-05
- Accept-Encoding updated to 'gzip, deflate, br, zstd'
- Inject x-anthropic-billing-header block (SHA-256 payload fingerprint) and
Claude Agent SDK identity block with ephemeral 1h cache-control for OAuth requests
- Auto-generate cloaking user IDs for OAuth metadata.user_id when absent/invalid
- applyClaudeToolPrefix / stripClaudeToolPrefix skip Anthropic built-in tool names
- buildClaudeCodeTlsFetchOptions attaches SNI + default TLS ciphers for api.anthropic.com
- Non-Anthropic base URLs now use Bearer auth regardless of OAuth status
- Prompt-caching no longer strips then re-applies; skips if blocks already have cache_control
oauth/anthropic:
- Token URL changed from platform.claude.com to api.anthropic.com
- OAuth scopes trimmed to org:create_api_key user:profile user:inference
- Code exchange strips URL fragment from callback code (fragment used as state override)
- AnthropicOAuthFlow exported
- OAuth callback server timeout extended from 2 min to 5 min
usage/claude:
- user-agent updated to claude-cli/2.1.63 (external, cli)
- anthropic-beta header extended with full production beta set
coding-agent web search:
- Anthropic provider uses buildAnthropicSearchHeaders instead of buildAnthropicHeaders
Tests: anthropic-alignment, anthropic-oauth, claude-usage-headers, web-search-anthropic
- Replaced node-html-parser with linkedom library across all web scrapers for improved DOM API compatibility.
- Updated DOM property access from .text to .textContent and .parentNode to .parentElement for linkedom API.
- Refactored extractDocumentLinks() to use regex-based parsing with 20-link limit instead of full DOM traversal.
- Added type assertions and Array.from() wrappers for querySelectorAll() results to ensure proper typing.
Support Perplexity web search via session cookies extracted from
the desktop app (Electron/AppImage). Accepts either a raw cookie
string or a bare session token value.
Auth resolution order: PERPLEXITY_COOKIES > agent.db OAuth > PERPLEXITY_API_KEY
Request contents.summary from Exa /search API and combine up to
3 non-empty summaries into SearchResponse.answer, replacing the
previous 'No answer text returned' output.
Changes:
- Add contents.summary to every Exa search request body
- Add summary field to ExaSearchResult interface
- Export synthesizeAnswer() to build combined answer from summaries
- Export buildExaRequestBody() for testability
- Export normalizeSearchType() (was private)
- Prefer summary over text/highlights for snippet field (falsy check)
- Only synthesize answer from results that have a URL (mirrors sources filter)
Tests: 37 new tests covering normalizeSearchType, buildExaRequestBody,
synthesizeAnswer (pure unit tests) and searchExa (mocked fetch)
- Consolidated @oh-my-pi/pi-utils subpath imports into single package root import across 100+ files.
- Moved tryParseJson utility from local web scrapers module to @oh-my-pi/pi-utils package for centralized JSON parsing.
- Renamed loadSkillsFromDir to scanSkillsFromDir and refactored skill discovery to use fs.promises.readdir instead of glob-based approach.
- Replaced custom parseJSON with tryParseJson across discovery modules for consistent error handling.
- Removed emitCustomToolSessionEvent method and cleanupSshResources function, consolidating shutdown logic into dispose method.
- Updated glob pattern construction to use GlobBuilder with literal_separator(true) for improved path handling.
- Added retry logic to PubMed and OpenLibrary fetches.
- Implemented XML parsing fallback for Chocolatey package details.
- Restructured Hackage scraper to use .json and .cabal for metadata.
- Generated informative markdown for OpenCorporates API failures.
- Updated User-Agent headers for Repology.
- Moved artifact management from ToolSession to SessionManager for centralized lifecycle control and caching.
- Replaced getArtifactManager() with allocateOutputArtifact() async method in ToolSession interface for simplified artifact allocation.
- Updated bash, fetch, python, and ssh tools to call session.allocateOutputArtifact() directly with optional chaining fallback.
- Fixed Lobsters scraper to handle user fields as strings instead of nested objects in API responses.
- Extracted credential storage to shared @oh-my-pi/pi-ai package with AuthCredentialStore and AuthStorage classes.
- Consolidated UI formatting logic from ToolUIKit class into standalone utility functions across render-utils and output-meta modules.
- Moved utility functions (parseCommandArgs, substituteArgs, expandPath, normalizeUnicode) to dedicated modules for improved code reuse.
- Extracted JTD type definitions and type guards to jtd-utils module for shared use across schema conversion tools.
- Updated Claude model pricing and added cache read costs in models.json for accurate billing calculations.
- Refactored agent-storage to delegate credential management to AuthCredentialStore instead of direct SQLite operations.
- Consolidated truncation and output utilities from tools/truncate.ts and tools/output-utils.ts into session/streaming-output.ts with improved UTF-8 boundary handling.
- Renamed formatSize() to formatBytes() across codebase for consistency and clarity in byte-level formatting.
- Refactored OutputSink to use windowed byte truncation instead of full-buffer encoding, improving memory efficiency on large outputs.
- Migrated from Buffer to Uint8Array in web scrapers for better cross-platform compatibility and native browser support.
- Added getArtifactManager() lazy-initialization method to ToolSession for deferred artifact manager instantiation.
- Simplified API surface with wildcard exports from tools and session modules, reducing import complexity.
- Consolidated Gemini CLI and Antigravity headers into central definitions.
- Split Antigravity headers into distinct authentication and streaming sets.
- Enabled User-Agent configuration via environment variables.
- Ensured consistent header usage across relevant services.
Export getAntigravityHeaders() from pi-ai and replace duplicated
ANTIGRAVITY_HEADERS constants in gemini-image tool and Gemini search
provider with calls to the centralized function.
Fixes#132
Replace hardcoded "antigravity/1.11.5 darwin/arm64" User-Agent strings with
the centralized getAntigravityUserAgent() function from @oh-my-pi/pi-ai in
gemini-image tool and Gemini search provider.
Fixes#132
- Exported readModelCache and writeModelCache functions for SQLite-backed model cache access.
- Migrated model cache storage from per-provider JSON files to unified SQLite database (models.db).
- Renamed cachePath option to cacheDbPath in ModelManagerOptions for database-backed storage.
- Improved non-authoritative cache handling with 5-minute retry backoff instead of per-startup retries.
- Added peekApiKey method to AuthStorage for non-blocking API key retrieval during model discovery.
- Added <turn_aborted> guidance marker as synthetic user message for aborted/errored assistant messages.
- Added docs:// internal URL protocol handler for accessing embedded markdown documentation files with path traversal validation.
- Added support for executable tool files (.ts, .js, .sh, .bash, .py) in custom tools discovery from .omp/tools/ and .claude/tools/ directories.
- Added generate-docs-index build script to automatically scan and embed markdown documentation files at build time.
- Updated system prompt to document docs:// protocol usage and identify agent as operating within Oh My Pi harness.
- Export SEARCH_PROVIDER_ORDER from provider.ts as single source of truth
- Remove duplicate provider arrays from web-search.ts and web-search-cli.ts
- Add missing 'kimi' to CLI command validation (was causing --provider kimi to reject)
- Move perplexity to top of auto-resolve priority
- Fix kimi position in priority order to match documentation
- Implemented API client for the Synthetic web search provider.
- Configured Synthetic as a selectable option for web searches.
- Integrated Synthetic into the automatic provider fallback chain.
Fixes#102
- Set Authorization: Bearer header in buildAnthropicHeaders when using OAuth
(raw fetch path was sending no credentials)
- Use plain web_search tool name instead of prefixed web_search_20250305
(Anthropic API rejects the prefixed name)
- Remove dead applySearchToolPrefix function and unused import
Fixes#102
- Added Brave web search provider with support for query, result count, and recency filtering.
- Added BRAVE_API_KEY environment variable configuration for Brave search authentication.
- Updated web search provider priority order to include Brave as second-highest priority after Exa.
- Extended recency filter support to Brave search provider alongside Perplexity.
- Implemented BraveProvider class with API integration, response mapping, and parameter validation.
- Added helper functions for recency mapping, result clamping, and snippet building in Brave provider.
- Added pagination support for fetching GitHub issue comments, allowing retrieval of all comments beyond the initial 50-comment limit.
- Added comment count display showing partial results when not all comments could be fetched (e.g., '5 of 10 comments').
- Changed GitHub issue comment fetching to use paginated API requests with 100 comments per page instead of single request with 50-comment limit.
- Extracted comment fetching logic into dedicated fetchGitHubIssueComments function for improved code organization.
- Added GitHubIssueComment interface to provide type safety for comment data structures.
- Added Z.AI web search provider with MCP integration for remote web search capabilities.
- Added 'zai' as a selectable web search provider option in settings and CLI.
- Added Z.AI to the automatic provider fallback chain for web search after Gemini and Codex.
- Implemented ZaiProvider class with support for multiple Z.AI API response formats and retry logic.
- Added comprehensive error handling and response parsing for Z.AI MCP endpoint integration.
- Fixed binary output handling in bash-interactive sessions by sanitizing terminal output before truncation.
- Fixed fetch tool to prevent treating HTML content as plain text or markdown by adding content-type validation.
- Fixed output truncation notice to correctly display byte limit using maxBytes field.
- Fixed Cloudflare compression-related corrupted bytes issue by disabling HTTP compression negotiation in web scraper.
- Improved error handling in bash-interactive output appending with fallback normalization.
- Extracted directory path utilities from multiple packages into a centralized '@oh-my-pi/pi-utils/dirs' module.
- Moved 30+ path helper functions (getAgentDir, getConfigRootDir, getPluginsDir, getMCPConfigPath, etc.) from scattered locations into a single shared utility module.
- Consolidated APP_NAME, CONFIG_DIR_NAME, and VERSION constants into the centralized dirs module for reuse across packages.
- Updated 70+ import statements across packages/ai, packages/coding-agent, packages/stats, and packages/tui to use the new centralized module.
- Removed local path construction logic and replaced with utility function calls for improved maintainability and consistency.
- Deleted packages/coding-agent/src/extensibility/plugins/paths.ts as its functions were moved to the centralized dirs module.
- Added Perplexity OAuth authentication support with native macOS app extraction and email OTP login flows.
- Implemented loginPerplexity and refreshPerplexityToken functions for OAuth token management.
- Created PerplexitySocket class providing Socket.IO v4 client over Engine.IO v4 WebSocket transport with RPC support.
- Added OAuth authentication to Perplexity web search provider with automatic token refresh and SSE streaming support.
- Extended SearchResponse interface with authMode field to track authentication method (oauth or api_key).
- Changed PerplexityProvider.isAvailable() to async to support OAuth token availability checking.
- Added computeHashlineDiff function to compute diffs for hashline-based edits without applying them.
- Added support for hashline edits in tool execution with caching mechanism to avoid redundant diff computations.
- Added formatStreamingHashlineEdits function to format and display hashline edits with configurable limits.
- Enhanced EditRenderArgs interface with optional previewDiff and edits fields for hashline mode support.
- Refactored import paths from absolute package-scoped imports to relative imports for better module resolution.
- Replaced ASCII ellipsis characters (three dots '...') with Unicode ellipsis character ('...') throughout the codebase for improved typography.
- Adjusted string truncation logic to account for single-character Unicode ellipsis instead of three-character ASCII ellipsis, reducing reserved space from 3 to 1 character in truncation calculations.
- Updated truncation offsets in multiple files (session-manager, agent, executor, footer) to preserve 2 additional characters before ellipsis due to more compact Unicode representation.
- Implemented caching for tool output block rendering to avoid redundant computations on re-renders.
- Enhanced read tool grouping to prevent coalescing across narrative boundaries (text/thinking blocks between tool calls).
- Improved string preview formatting to detect multi-line strings and display line counts with ellipsis indicators.
- Refactored tool execution component to use reactive render state tracking for better state management.
- Enhanced error handling in tool renderers with logging for failures.
- Fixed truncation indicator to use ellipsis character instead of verbose suffix.
- Extracted stream parsing utilities into reusable functions in pi-utils package (readLines, readJsonl, parseJsonlLenient, readSseJson).
- Replaced manual buffer management with ConcatSink class for efficient stream handling across multiple modules.
- Simplified SSE stream parsing in google-gemini-cli provider by using readSseJson utility instead of manual reader setup.
- Refactored MCP stdio transport to use readLines utility for cleaner line-based stream processing.
- Updated RPC client and mode to use readJsonl utility, removing duplicate JSONL parsing logic.
- Optimized buffer allocations by using allocUnsafe where data is immediately populated and reusing empty buffer instances.
- Migrated authentication storage from JSON-based (auth.json) to database-based (agent.db) format across test files and configuration.
- Simplified auth storage discovery in sdk.ts by removing manual path construction and fallback logic in favor of centralized getAgentDbPath() function.
- Removed dbPath instance property from AuthStorage class as database path is now managed centrally.
- Updated environment variable precedence documentation to reflect agent.db instead of auth.json as the lowest priority source.
- Removed OAuth provider section header comments from multiple test files for cleaner test organization.
- Added support for JSON and JSONC configuration file formats without requiring migration to YAML.
- Reorganized web search provider system to use individual provider classes in separate files under providers/ directory.
- Moved SearchProvider base class and SearchParams interface to dedicated providers/base.ts module.
- Consolidated provider management logic into provider.ts, replacing provider-info.ts.
- Updated web search execution to pass maxOutputTokens, numSearchResults, and temperature parameters to providers.
- Changed Perplexity search context size from 'high' to 'medium' and increased default max tokens from 4096 to 8192.
- Updated Anthropic and Gemini search providers to support max_tokens and temperature parameters.
- Removed legacy auth.json file-based authentication migration system and simplified AuthStorage to use only agent.db for credential storage.
- Simplified AuthStorage API by removing authPath and fallbackPaths parameters, now accepting only dbPath for improved startup performance.
- Deleted storage-migration.ts module containing legacy JSON-to-SQLite migration logic that is no longer needed.
- Removed getAuthPath() configuration function from config.ts as auth.json file-based storage is no longer supported.
- Renamed web search types and functions to remove 'Web' prefix for broader applicability (WebSearchProvider -> SearchProviderId, WebSearchResponse -> SearchResponse, WebSearchTool -> SearchTool, etc.).
- Refactored web search provider system from object-based configuration to class-based architecture with abstract SearchProvider base class and concrete provider implementations.
- Refactored ModelRegistry to use direct constructor instantiation instead of discoverModels() helper function, simplifying model discovery pattern.
- Refactored config system to use new ConfigFile class with schema validation, caching, and multi-format support (JSON, JSONC, YAML).
- Simplified Exa API key discovery to check environment variables only, removing .env file reading logic.
- Added new `omp q` CLI subcommand for testing web search providers with query, provider, recency, and limit options.
- Added web search provider information API with centralized provider-info module supporting authentication requirements and provider metadata.
- Added support for `hour` recency filter option in Perplexity web search.
- Refactored web search provider definitions into centralized provider-info module for improved maintainability.
- Updated web search result rendering to support long-form answers with text wrapping in CLI mode.
- Removed related questions section from web search result rendering.
- Added 'pro' search type to Perplexity API requests for improved search quality and relevance.
- Implemented fallback to search results when Perplexity API returns no citations, ensuring search results are always available to users.
- Added search_type field to PerplexityRequest web_search_options interface.
- Refactored SSE stream parsing to use generic `readSseJson` utility instead of domain-specific handlers across multiple packages.
- Migrated from Node.js Buffer API to Web standard APIs (Uint8Array, TextDecoder, DataView) for cross-platform compatibility.
- Simplified stream transformation pipeline by consolidating multiple stream operations into unified `createTextLineSplitter` utility.
- Refactored `ptree.ts` to remove complex stream pumping infrastructure and simplify stderr handling with direct async iteration.
- Rewrote stream utilities to operate at binary level with byte-level parsing for improved efficiency and reduced string allocations.
- Updated TypeScript configuration to include DOM.AsyncIterable type definitions for async iterable DOM API support.
- Converted class properties to TypeScript parameter properties across 51 files to reduce boilerplate code.
- Removed explicit field declarations and manual assignments in constructors by using TypeScript's parameter property syntax with access modifiers.
- Applied consistent pattern of declaring private readonly and public readonly properties directly in constructor parameters.