Release notes
Notable Relay changes and links to the exact notes for each published release.
This page summarizes the notable-change log maintained in the source repository. For the exact notes and artifacts attached to every published tag, use the Relay releases page.
2.1.0
Added
- Relay opens on the request editor — your tabs, or a new request when there are none. Settings → General → On launch can reopen Where you left off or always start on the Workspace overview. See Settings.
- Zoom.
Cmd/Ctrl =,Cmd/Ctrl −andCmd/Ctrl 0scale the whole window from 80% to 150%, as in Postman; on macOS they are also in the new View menu. See Keyboard shortcuts. - Browser emulation goes further. The Headers tab marks the response headers page code cannot read under CORS, a page on HTTPS is checked for mixed content, and a request from a public page to a loopback or private address warns about Local Network Access. See Browser security.
Changed
- One look across the app. Text, buttons, fields, menus, tabs, dialogs, checkboxes and empty states come from one set of sizes, weights, corners and spacing, so the same control looks the same on every screen. Destructive actions and status colours follow the theme, and the last system checkboxes and radio buttons are gone.
Fixed
- CORS follows every redirect — the redirect must pass CORS, a new origin is preflighted, cookies and
Authorizationare dropped as a browser drops them — and header values are checked as the Fetch standard does. A redirect on the same host keepsAuthorization. - Variables resolve as expected. Globals reach
{{...}}, a value set by a pre-request script is used in the same send, names with non-Latin letters, spaces or colons resolve, the Collection Runner hands scripts the data row, andrelay runresolves nested variables. See Environments. - A timeout of
0waits as long as the server takes, in the app and inrelay run. See Request settings. - Large responses scroll without blank frames on the scrollbar, the trackpad and the keyboard, and response search highlights matches across a key and its value.
- Arrow keys stay where you are. In a response, a dialog or Settings they no longer switch the request in the sidebar, and
↓in Settings no longer skips a section. - Streaming and sockets: a
POSTto an event-stream endpoint shows the stream, SSE follows the event-stream specification, a quiet WebSocket with keep-alive off stays open, handshake headers copied from DevTools no longer break connections, and Socket.IO shows binary events. - Pasted cURL commands and generated snippets keep the body —
-d,--json,$'...'quoting,-d @file— and the snippets run as generated in every language. See Code generation. - Also: the mock server replays compressed examples, a hand-written multipart
Content-Typeno longer loses its boundary, force push refuses to overwrite commits it has not seen, common legacy Postman script helpers work, OpenAPI import honours servers on a path or operation, and the Runner’s checkboxes stay checked during a run.
2.0.3
Changed
- A new request opens straight away as HTTP. The
+in the tab bar,Cmd/Ctrl Nand Add request no longer ask for a protocol first. Switch protocol in the picker at the start of the address bar — on a saved request until it has a URL — or run New GraphQL request, New WebSocket request and the rest from the command palette. See Request types. - Shortcuts are drawn as keys in Settings, the command palette and the hints —
⌘ ⇧ ⌥on macOS;Ctrl,Alt,⇧ Shiftand the Windows logo on Windows. - The Windows installer no longer asks for administrator rights. It installs for the current user, so there is no UAC prompt and the in-app updater can replace the app. It offers to remove an older all-users copy; your data is kept. See Installation.
- The Windows icon fills its space on the taskbar and in the Start menu instead of sitting inside the macOS margin.
Fixed
- Updating the MSIX install failed with a permission error. Relay now recognises the packaged install and offers the new
.msixfor this machine instead of trying to replace itself. - Some shortcuts never fired on Windows and Linux — Reopen closed tab, Toggle right sidebar, Switch to next/previous tab and Force close tab. Shortcuts also follow the physical key now, so they work on Cyrillic and other non-Latin layouts.
Cmd/Ctrl+Enterin a WebSocket or Socket.IO message dropped the connection, and in a gRPC message invoked the method twice. It sends once now.- Shortcut hints ignored your own bindings; they show the current binding now.
- Some text kept the previous theme’s colour — the Mock server heading stayed black after switching to Nord — and buttons on light accents were hard to read in Nord, the dark Catppuccin flavours, Dark Pastel and Dark Monochrome.
- Full release notes did nothing in What’s new; it opens the release page now.
2.0.2
Added
- Relay runs on Windows on Arm. Releases now carry an Arm64 installer and MSIX package beside the x64 ones; the x64 installer refused to start on Arm machines. See Installation. (#34)
- A middle click closes a tab, as in a browser — request tabs and the Runner, Git, Mock, collection and History tabs. A tab with unsaved changes still asks first.
Fixed
- Enter in the URL field did nothing. It now sends the request, or connects a WebSocket, Socket.IO or SSE request. It never cancels a request in flight or drops a live connection, and it still picks a suggestion while the variable list is open.
2.0.1
Fixed
- An update on macOS left the old icon behind. The in-app updater replaced only the program inside
Relay.app, so the icon and the version Finder shows stayed from the day Relay was first installed. Updates now replace the whole signed app, and a copy that was updated the old way repairs itself on its next start — the new icon appears from the launch after that. - Every release called itself 1.0.0 to the operating system. The release build stamped its real version into the program but never into the app’s own description, so Finder and About This Mac on macOS, and the file properties and Apps & features on Windows, showed 1.0.0 whatever version was installed. They show the actual version now.
2.0.0
Relay 2.0 is a new look — the Graphite design, from the window chrome to every screen, menu and dialog — plus MCP requests, a command palette, a page for each history entry and the last run of each collection. It needs macOS 12 or later.
Added
- MCP is a request type. Point Relay at a Model Context Protocol server, press Discover, pick a tool, fill the arguments from its schema and send — and read the raw JSON-RPC exchange that went over the wire. An MCP call is an ordinary saved request: diffed in review, run by the collection runner, asserted on by a test script. See Request types.
- A command palette.
Cmd/Ctrl Kfinds a saved request and also runs Relay’s commands — send, save, duplicate, copy as cURL, create, import, jump to any view, change the layout or theme. See Workspaces. - Environments side by side. A Matrix view puts every variable in a row and every environment in a column, edited in place. See Environments.
- A page for each history entry, with what was sent next to the stored response. See Request history.
- Each collection remembers its last run, shown in the runner and on the collection’s page. See Collection Runner.
Changed
- The Graphite design. Neutral greys with hairline borders, colour kept for what carries meaning — methods, status codes, variables — and the accent only on the primary action. An activity rail replaces the sidebar’s section labels, tabs sit in the title bar, the method lives inside the URL field, and the response opens beside the request in a wide window. Every screen, menu and dialog was brought to it, and every screenshot in these docs was retaken.
- A new app icon — two offset chevrons in the brand blue — on the Dock, the installer, the start-up screen and these pages.
- Relay needs macOS 12 Monterey or later, with the system WebKit from Safari 16.2 or newer. Windows and Linux are unchanged.
Fixed
- A dropdown inside a labelled field reopened after an option was picked on macOS. The end-to-end suite now also runs in WebKit, the engine Relay uses there.
- A stored history response over 2 MB could not be read back.
- Response line numbers fell behind the text while scrolling fast on macOS, and a sideways scroll could strand them in the middle of a wide response.
1.8.1
Changed
- One icon everywhere. Relay was drawing its own mark five different ways — the app icon, a redrawn copy in these docs, another as the favicon, a third in the app’s sidebar, and a fourth in the browser extension — in three gradients and four corner radii. Every one of them is now generated from the icon that ships in the Dock and the installer. The icon you launch is unchanged; everything else caught up to it.
- This documentation site was rebuilt around reading. A smaller type scale, tables and code that match it, a landing page the header sits on rather than floating above, and a search dialog that keeps the query in place while results scroll. Screenshots are captured at twice the pixel density, so the app’s own text stays legible.
- Every guide that shows a Relay window now has a screenshot, including response examples and the mock server, which shipped without one.
Fixed
- The README and the landing page had fallen four releases behind: saved examples, cookie sync, the response diff and browser emulation were missing, Digest was described as MD5-only, and the keyboard defaults were spelled with
⌘— wrong on two of the three platforms Relay runs on. See Keyboard shortcuts. - Two guides illustrated their feature with the same broken screenshot, and the privacy page described only one of the three local listeners Relay can open. See Mock server.
1.8.0
Added
- Sync cookies from your browser. The cookie jar’s Sync Cookies tab used to be a disabled placeholder; it now pairs Relay with a browser extension, so the session you already have in Chrome, Edge, Brave or Arc is the session Relay sends with — no more copying a
Cookie:header out of DevTools after every login. See Cookies. - Pairing is a click. The extension finds Relay on its own and asks to connect; Relay shows the request with a six-digit code that the extension shows too, and approving it hands over a token. Matching the codes is what stops anything else on the machine from being approved in the browser’s place. After the first approval the browser reconnects by itself.
- Cookies arrive as they change, over a WebSocket, within a second of the browser setting them — with a full reconciliation on connect and every five minutes, so a cookie cleared while the browser was closed disappears in Relay too. Signing out of a site clears the cookie here as well.
- Three gates stand in front of every cookie: the bridge is loopback-only and off until you turn it on, no token exists until you approve the browser, and a domain is read only if it is on Relay’s allowlist and granted to the extension in the browser. Relay names the domains the browser was never allowed to read instead of quietly covering fewer than the list suggests.
- The extension ships in the repository under
apps/extensionfor Chromium browsers, with a Firefox manifest alongside it.
Fixed
- Open log folder in Settings did nothing. A dependency update started rejecting
file:URLs outright, so the button was refused with no error anywhere you could see it. Relay now hands the folder to the platform file manager directly and reports a failure in the row. - Disconnecting a browser left its extension retrying forever, because the socket closed without saying why. Relay now distinguishes “disconnected on purpose” from “shutting down”, and the extension drops a dead token and asks to connect again instead of reconnecting with a key that will never be accepted.
1.7.0
Added
- A local mock server. Point it at a collection and Relay serves every saved example it holds over HTTP, so a client can be written against an endpoint that does not exist yet — or against the failure cases a staging environment will not produce on demand. No account, no cloud: a port on your own machine, serving files that are already in your Git history. See Mock server.
- Routing is the method plus the example’s path template, so a response captured from
/orders/8123answers/orders/:id. A literal segment beats a parameter, and an example that recorded query parameters only answers requests carrying them — which is how one endpoint serves its empty, its full and its error case from three examples. - A live log of what your client asked for, with the unmatched requests called out. Those are the useful ones: they separate “my client is wrong” from “no example covers this yet”, and a request matching nothing gets a 404 that names the routes which do exist.
- The mock reloads when you edit an example it is serving, so it never answers with something you already changed. Two examples that would answer the same request are flagged, since only the first can ever reply.
- Response examples and the mock server are now documented, and the docs no longer claim Relay has no mock server. See Response examples and Mock server.
Fixed
- Opening a saved request marked it unsaved. In manual-save mode, clicking any request lit the unsaved indicator without a single edit — so the indicator stopped meaning anything. The comparison behind it was order-sensitive where it should not have been.
- A request that failed to send showed a
TypeErrorinstead of the reason. DNS failures, refused connections, TLS problems and unresolved variables all produced a crash in the response panel where the explanation should have been. You can see why a send failed again. - Parts of the interface silently fell back to browser defaults, most visibly in the response viewer’s Diff tab, because they referenced colours that were never defined.
1.6.0
Added
- Import an OpenAPI or Swagger spec from a link. Every import path wanted a file, so bringing in a spec meant downloading it first — and the URL is what teams actually pass around, because it is the one that stays current. Import collection → OpenAPI / Swagger from URL takes the link and builds the same collection the file import would:
{{baseUrl}}as a collection variable, path parameters seeded from the spec, and declared security schemes mapped onto each request’s auth. See Import and export. - A link that turns out not to be a spec explains which of the several things went wrong. Pasting the Swagger UI page instead of the document it renders is the common one, and Relay says so rather than reporting a parse failure.
Fixed
- Uploads went out without a
Content-Length. A file body and a multipart body were sent chunked, which S3 presigned uploads, Azure Blob and a fair number of gateways reject outright — often with nothing more than411 Length Required. Both declare their size now, and a file body survives a redirect instead of abandoning the send. - AWS Signature v4 was rejected by everything except S3 when the path needed escaping. Lambda’s invoke URL carries the function ARN in the path, colons and all, and every service but S3 wants that path encoded twice. Those requests came back
SignatureDoesNotMatch. - The Authorization tab silently replaced a header you typed yourself. It still wins, but the response panel now tells you it did, instead of leaving you looking at a header that never went out.
- Pasted cURL commands lost things Relay can represent: a form part’s
Content-Type, and the-k,--max-timeand--proxyflags, so the request quietly behaved differently from the command. - Copying a request as cURL or as a code snippet mislabelled the body. An XML, HTML or plain-text body arrived as curl’s default
application/x-www-form-urlencoded— a different request from the one you copied. - A second value for a query parameter already in the URL was dropped, so
?tag=ain the URL withtag=bin the Params tab sent only the first. - Capturing a response example rewrote the body even when nothing was redacted, which turned an id larger than JavaScript’s safe integer range into a different number. See Response examples.
1.5.0
Added
- Response examples. Keep what an endpoint actually returned, next to the request that asked for it. Capture one from the response panel or from a history entry, edit it by hand, and keep as many as the endpoint has interesting outcomes. Examples live in the workspace files, so a change to one is a reviewable diff in Git rather than something only you can see — and secrets are redacted on capture, in three passes, because a response body is where a token is most likely to slip into a commit.
- Examples come in with your collections. Postman saved responses, OpenAPI
responses(including one derived from the schema when the spec writes no example), OpenCollection, and HAR — a HAR file is a recording of real request/response pairs, and until now Relay imported only the request half. See Import and export. - Compare a response with a saved example. The Diff tab can use an example as its baseline instead of the previous response, which is how you notice an API that changed shape without anyone saying so. See Response viewer.
- Multipart parts can carry their own Content-Type, so an API that validates the MIME type of an upload stops rejecting them.
Fixed
- An explicit save could write the previous version of a request. In manual-save mode, clicking Save assembled the file while the request was still counted as unsaved — so it wrote the version from before your edit, reported success, and cleared the unsaved marker. The change was gone on the next load. Autosave was never affected. If you use manual saving, this is the reason to update.
- AWS Signature v4 rejected by DynamoDB, Lambda and S3. Only a fixed set of headers was signed, but AWS requires every
x-amz-*header to be part of the signature. Signing also no longer reads a large upload into memory before sending it. - A JSON body left empty sent no
Content-Type, so servers that check the header before reading the body answered 415. - Digest auth with no username sent nothing at all and came back 401 without explanation; it is an error before the request leaves now.
pm.sendRequestignored your proxy and client certificate, so a script could not reach an endpoint the request beside it reached fine.- Send-and-Download saved the compressed bytes when the request asked for an encoding explicitly, producing a gzip file named
report.json. - Importing a Postman collection dropped per-request redirect and TLS settings, and the values behind
:pathVariable— leaving a URL that still said:idand could not be sent. - The header buttons moved when you opened the runner, leaving a gap at the right edge.
1.4.0
Added
- Request history keeps the response. Opening an entry restores what came back alongside the request — no re-sending to find out, which would answer a different question anyway. A row’s ••• menu has View response for looking without reopening. Bodies are stored in their own encrypted files, capped at 2 MB, and deleted with their entry. See Request history.
- Variables can be built from other variables.
baseUrl = {{scheme}}://{{host}}resolves now, so retargeting a whole collection at staging is one edit. See Environments and variables. relay runobtains its own OAuth 2.0 tokens. Client credentials and password grants are fetched from the token endpoint; the interactive grants fall back to a stored refresh token. An OAuth-protected collection can finally run in CI. See CLI runner.- Authorization for WebSocket and Socket.IO. The handshake always carried auth; the tab to configure it was missing.
- SSE reconnection and WebSocket keep-alive are configurable, and the
Hostheader can be set. See Request settings.
Fixed
- Saving a workspace dropped auth fields. A request set to Inherit Auth lost the setting and reverted to sending none, and every OAuth 2.0 field added in 1.2.0 — AWS session tokens, Device Code, Password, client-authentication methods, private-key JWT — was discarded on each save. The workspace file is the only copy, so what the writer dropped was gone.
- Any pre-request script corrupted repeated headers and query parameters.
?id=1&id=2went out as?id=2&id=2, and a disabled row came back enabled — for any request running any script, including one that only logged. - OAuth 2.0 tokens were never refreshed for a request that was not on screen, so a collection run started returning 401 the moment the token expired, and Inherit Auth never refreshed at all.
- Importing an OpenAPI spec produced requests that could not be sent — path parameters resolved to nothing, the server was pasted into every URL, and security schemes were dropped. See Import and export.
- Generated code dropped Basic, Digest, OAuth 2.0 and AWS auth, so a copied request came back 401 without saying anything had been left out. See Code generation.
- The client-certificate passphrase was committed in plain text when typed literally rather than as a variable.
- Collection variables written by a script were lost when it then skipped the request; a parallel run ignored variables written by earlier iterations; SSE offered a Scripts tab that never ran anything; the realtime panel’s tabs wrapped on a narrow window.
Changed
- The frontend no longer restates the Go structs — wire types are derived from the generated bindings, and CI fails when they go stale. Four of the defects above were the same failure, a hand-maintained copy falling behind, and this closes that class.
1.3.0
Added
pm.request.bodyin scripts — read, rewrite, and sign the body that actually goes out..rawis readable and writable,.json()parses it,.update()replaces it, and form or urlencoded bodies are edited field by field through.urlencoded/.formdata. See Scripting API.- JSON Schema assertions —
pm.response.to.have.jsonSchema(schema)validates a response against a draft-07 subset and reports each failure with its path;pm.response.to.have.jsonBody(path, value)checks a single dotted path. require()for the libraries Postman scripts expect —lodash(also as_),ajv,tv4,uuid,crypto-js, andchairesolve to Relay implementations, so imported test scripts run unchanged. Anything outside that surface fails with a message naming what was asked for.- Bulk edit for key/value tables — params, headers, and both form body types switch between the table and a
key:valuetext form,//disabling a line. It is Postman’s format, so a block of headers pastes straight across. - Insertable script snippets — the Scripts tab’s reference row is now a snippet library: set a variable, add a header, sign the body, assert a status or a schema.
Fixed
- Importing a Postman collection dropped scripts, docs, and everything on the collection itself. Pre-request and test scripts, request descriptions, collection variables, collection auth, and collection scripts were all discarded; OAuth 2.0 imports kept only the access token, so a request started failing with a 401 as soon as it expired. All of it carries over now, and Postman environment and globals files can be imported too. See Import and export.
- A collection’s script timeout and
pm.sendRequestpermission were ignored — both were missing from the settings a request inherits, while the Settings tab claimed they applied. They inherit now, they can be set from Collection settings → Settings (alongside the client certificate), andrelay runreads them from the workspace instead of only from its flags. - Scripts could not edit a form or urlencoded body, and
pm.request.body.modereported Relay’s own names instead of Postman’s, so an importedif (mode === "raw")silently took the wrong branch. - A JSON Schema failure list stopped at 20 without saying so.
1.2.0
Added
- OAuth 2.0: Device Code and Password grants — Device Code (RFC 8628) shows the user code, opens the verification page and polls for approval, which is how you sign in on a machine where a browser redirect cannot come back. See Authentication.
- OAuth 2.0: client authentication methods — alongside HTTP Basic, the token endpoint can be given credentials in the body, a client secret JWT, or a private key JWT (RSA/ECDSA, RFC 7523). The private key accepts a
{{variable}}, so it can live in workspace secrets. Anaudienceparameter is sent when set. - Digest auth beyond MD5 —
SHA-256,SHA-512-256and the-sessvariants from RFC 7616, plusqop=auth-intanduserhash. A modern Digest server previously failed before the request went out. - AWS Signature v4: session tokens — temporary credentials from STS, an assumed role or AWS SSO now work.
pm.sendRequest— scripts can make their own HTTP calls, for fetching a token before the send or chaining setup. Off by default; enable Allow pm.sendRequest on a request or pass--allow-send-requestto the CLI runner. See Scripting API.- Request signing in scripts —
pm.cryptofor hashes, HMAC and encodings, plus aCryptoJSshim so signing scripts imported from Postman work unchanged. - The missing
pm.*scopes —pm.collectionVariables(written back to the collection),pm.globals,pm.info,pm.cookies, andpm.execution.skipRequest()for a request that should be skipped rather than failed. - Global variables — persisted across restarts, shared by every workspace, and edited under Environments → Globals. See Environments.
- Response Preview — images and HTML render properly instead of appearing as unreadable text. See Response viewer.
- Configurable script timeout — raise the 2000 ms cap per request or with
relay run --script-timeoutwhen an assertion suite or a signing step needs longer.
Fixed
relay runcould not run a collection that used inherited auth. A request set to Inherit Auth aborted the run withunsupported auth type "inherit", because the runner ignored everything but a collection’s variables. Collection auth, headers, scripts and settings now apply exactly as they do in the app. See CLI runner.- A binary response no longer fills the Body tab with replacement characters. Relay identifies a non-text body from its actual bytes, so a payload mislabelled as
text/htmlis caught too, and shows what it is with links to preview or save it.
1.1.1
Added
- What’s new on first launch — after updating, Relay opens a screen with that release’s notes. It appears once per version: relaunching the same build, downgrading, and a first-ever install stay quiet. Reopen it any time from Settings → About → What’s new. The notes ship with the build, so the screen works offline and always matches the version you are running. See App settings.
1.1.0
Added
- CLI runner —
relay runexecutes a YAML workspace’s HTTP and GraphQL requests and their JavaScript test scripts from the terminal or CI. Data-driven iterations from a CSV/JSON file (--data),cli/json/junitreporters with file export, global and environment variable scopes with export-back,--verbose,--bail,--insecure, and a non-zero exit code when a request errors or an assertion fails. See CLI runner. - Client certificates (mutual TLS) — present a certificate, optional separate key, and passphrase per request or inherited from a collection. See Per-request settings.
- Dynamic variables —
{{$guid}},{{$timestamp}},{{$randomEmail}}and around 50 more under Postman’s names, generated at send time. Imported Postman collections that used them no longer fail with an unresolved variable. .http/.restimport — files from the JetBrains HTTP Client and the VS Code REST Client, including###separators,# @namedirectives, and file variables.- Response Timeline tab — DNS, TCP, TLS and first-byte events on a millisecond scale, connection details (reused or new, addresses, TLS version, cipher, ALPN, SNI), and the request exactly as it went on the wire, one block per redirect hop.
- Response Diff tab — compares the current response body against the previous one for the same request, collapsing unchanged runs.
- Scripting:
pm.iterationData.get(key)reads the current data-file row during a data-driven run.
Changed
- Parallel collection runs take a Max concurrent requests setting (default 8, maximum 64).
- Wails updated to 2.13 along with the Go and frontend dependency sets.
Fixed
- Query parameters keep their order on the wire. They were sorted alphabetically whenever automatic URL encoding was on (the default), breaking APIs that sign the query string verbatim.
- HTTP connections are reused between requests instead of building a fresh transport — and leaking its idle sockets — on every send.
- A parallel collection run no longer fires the entire batch at once, which could exhaust file descriptors on a large collection.
1.0.0
First public release. Relay was developed privately until this point; the source is now open under the MIT license and every release is published from the main repository.
Requests
- All HTTP methods with query parameter, header, and body editors (JSON, form-data, URL-encoded, raw, and binary).
- GraphQL, Server-Sent Events, WebSocket, Socket.IO, and gRPC request types with dedicated realtime panels.
- SSE streams reconnect like a browser
EventSource, resuming withLast-Event-IDand honoring the server’sretry:interval. - cURL import by pasting a command into the URL field.
- Importers for Postman, Insomnia, Bruno/OpenCollection, OpenAPI/Swagger, HAR, cURL, and full backups; exporters for Postman, OpenAPI, OpenCollection, and full backups.
Authentication
- Bearer, Basic, Digest, and API Key schemes.
- OAuth 2.0 Client Credentials and Authorization Code with PKCE — loopback browser sign-in, stored refresh tokens, and automatic refresh before send.
- AWS Signature v4 with specification-compliant query canonicalization.
- Auth defaults inherited from collection and folder level.
Scripting
- Sandboxed JavaScript pre-request and test scripts with a
pm.*API, plus the legacy Tengo engine. Imports, filesystem, process, and network access are disabled; execution is capped at 2 seconds.
Workspaces
- Multiple workspaces, nested collections, drag-and-drop organization, and 14-day request history.
- Git-backed YAML workspaces with diagnostics, conflict helpers, and machine-local secrets.
- Local profile and secrets encrypted at rest with AES-256-GCM, keyed through the OS credential store.
Response viewer
- Syntax highlighting, full-text search with match navigation, headers, test results, and script logs in one panel.
- Paginated rendering for large bodies with accurate truncation reporting.
- Save to file and copy to clipboard, including byte-exact binary downloads.
Updates
- Signed auto-updates:
latest.jsonis read from release assets, and every downloaded binary must match both the manifest SHA-256 and a minisign signature before installation.
Interface
- Dark and light themes with several built-in variations.
- Configurable keyboard shortcuts, global search, quick send, and tab switching.
- Settings search and full keyboard navigation, theme previews, and onboarding empty states.
