v2.0.2 +1d 5h after v2.0.1
Fix Latest

OpenRouter answers again, and says who is asking

Two changes, both of them OpenRouter and nothing else. The first fixes a request the router had always rejected, so every effort tier above the lowest came back with an error instead of an answer. The second adds three headers that say which tool is calling. Neither is a security fix, and nothing here touches any other provider.

  • FixedOpenRouter rejected the request before a model ever saw it. We were sending reasoning.effort and reasoning.max_tokens together in one reasoning object. In OpenRouter's schema those two are alternatives, not a pair, and the router answers 400 with Only one of "reasoning.effort" and "reasoning.max_tokens" can be specified. The request builder asks for reasoning in several dialects at once and drops whichever one a provider does not recognise. That works for a parameter that is merely unknown. It does not work for two that contradict each other. The effort tier is now sent on its own and the router translates it into whatever the destination actually takes.
  • The scope is wider than it sounds. That block is gated on reasoning being requested at all, which is every effort tier except low, including the default, so on stock settings the request was rejected before any model ran. /effort low was the only setting that worked, because it asks for no reasoning. This is not a 2.0.1 regression: the line predates 2.0.0, and the provider client is unchanged between the two tags. We saw it on one model, and the pair is invalid by OpenRouter's own error text, but we have not measured how many models enforce it and are not going to claim every one does.
  • Changedrequests to OpenRouter now identify the app as Monarch CLI. Three headers: the app's page (https://cymela.com/cli), its name, and the category cli-agent. That is what gives the tool a page on OpenRouter with per-model usage analytics, and makes it eligible for OpenRouter's public app rankings. The headers go to OpenRouter only, they carry a name and a URL and nothing about you, and nothing is sent to Cymela. It does mean your OpenRouter usage through this tool counts toward the app's public numbers. Running entirely on your machine is unchanged.
  • To head off the obvious misreading: the listing is the tool, not a model. Nothing of ours is served through OpenRouter. The models you reach are whichever ones you choose and pay for yourself, exactly as before. Thirteen providers are supported, none ships enabled, there is no default, and monarch --doctor on a fresh install still prints Provider — none chosen yet.
  • Upgradingthe two package names are published from separate accounts, so the alias can land after the main package rather than beside it. On this release it landed 10m later, and npm install -g cymela served 2.0.1 until it did.
  • Nothing was removed, renamed or deprecated. Requirements are unchanged: Node 20+, and monarchai installs with no runtime dependencies.
v2.0.1 +4d 12h after v2.0.0
Fix

Hooks that stop when you stop them

Two fixes and nothing new. The first matters only if you use hooks. The second moves no data and adds no feature: it tells the agent something about cross-session messaging that was already true. Neither is a security fix, and neither is urgent.

  • Fixeda hook that timed out kept running. Hooks run through a shell, so the process the CLI starts is sh -c with your command inside it. On timeout the CLI signalled that shell and stopped there, so anything the shell had started was orphaned and ran to completion while the CLI reported the hook as timed out and carried on. A PreToolUse hook runs on every tool call, so one that hangs left another stray process behind each time, for as long as the session lasted. The whole process group is killed now. The timeout is 30s by default, set per hook, capped at 300s.
  • Windows has no process group to kill, so that branch uses taskkill instead, and it has not yet run on a real Windows machine. It ships because leaving the leak in is worse, and it is under test there now.
  • Fixedthe agent is told where a session message goes. Delivery has always been a file in your own config directory, with no server and no port, and the receiving session has always read that file into its context, which goes to whichever provider that session is configured with. Both halves are the same in 2.0.1 as they were in 2.0.0. What changed is that the model doing the sending is now told the second half exists, and told to keep keys and tokens out of a message. It is the only party positioned to judge what belongs in one, and it was not being told.
  • Upgradingthe two package names are published from separate accounts, so the alias can land after the main package rather than beside it. On 2.0.1 it landed 8h 38m later, and npm install -g cymela served 2.0.0 until it did.
  • Nothing was removed, renamed or deprecated. Requirements are unchanged: Node 20+, and monarchai installs with no runtime dependencies.
v2.0.0
Rename

The CLI is now Monarch CLI

The tool published as cymela is now Monarch CLI. Cymela stays the name of the project; Monarch is what it ships. This is the successor to 0.1.5 rather than a patch on it: the binary is renamed, three commands are retired, and the config directory moves. npm install -g monarchai is the package to reach for. npm install -g cymela installs the same tool and updates on the same releases, so an existing install keeps working and keeps moving. Either way you get the monarch command.

  • Upgradingnpm install -g cymela replaces the old install outright and keeps the cymela command working, now pointing at the new build.
  • UpgradingSettings, API keys, saved model choices, themes and custom personas are carried from ~/.cymela to ~/.monarch automatically, once, on first run. Conversations were already per-project and are read in place.
  • UpgradingThe command is now monarch. cymela still works. If you install under the other package name while 0.1.5 is still present, monarch --doctor says so and gives you the one line that cleans it up.
  • Newsub-agents with roles. Scout is read-only, Builder and Checker are tool-gated and depth-limited, and all three stream live into an agents panel.
  • Newcross-session messaging. Two Monarch sessions running on the same machine can send each other messages, including across different projects, so the session working on the frontend can tell the one working on the backend what it just changed. There is no command to type: the agent sends and formats the message itself. Tell it once to keep another session posted and it can do that several turns later without being asked again. Delivery is to a session that is running; if the other side is not, the send fails and says so rather than queuing.
  • Delivery is local: the message is a file in your own config directory, readable only by you, with no server and no port. What happens next is not local. The receiving session reads the message straight into its context, so it goes to whichever model provider that session is pointed at, the same as any file the agent opens. A relay chain between sessions is capped at six hops, and the refusal says why: the sessions are talking to each other instead of to you.
  • Newa verification-first engine. A deterministic guard chain sits between the model and "done", so the agent proves its work rather than asserting it.
  • Newthirteen providers across OpenAI-compatible, Anthropic and Gemini wire formats, plus local servers and gateways through MONARCH_BASE_URL.
  • Newsessions, undo and cost. Every turn is persisted and checkpointed, with auto-compaction before the context window overflows. Memory persists across sessions and is stored only on your machine.
  • Newscriptable. monarch -p "..." runs one turn without the UI and now reads piped input, so git diff | monarch -p "review this" works.
  • Changed/execute, /agent and /override are retired in favour of /run-plan, /default and /auto. Typing an old one tells you its replacement, and /mode covers all three.
  • Changedthe instruction file is MONARCH.md. CYMELA.md and HYPER.md are still read. Environment variables are MONARCH_* first, with CYMELA_* and HYPER_* still honoured.
  • Requires Node 20+. Nothing is compiled on install, and there are no runtime dependencies.
v0.1.5
Security

Approvals that hold, and keys that stay put

Three security fixes, found by auditing our own code rather than reported to us, and with no evidence any of them were exploited. Two of the three affect every install, on 0.1.4 or earlier, update. It also adds voice input, which runs entirely on your machine.

  • Securityshell approvals could be escaped by wrapping the command. The permission classifier stripped quoted text before scanning it, so bash -c "npm install" was read as bash -c "" and scored clean, and a clean score is what lets a command join the session's "always allow read-only commands" grant. Approving something harmless like git status once could quietly pre-approve arbitrary commands for the rest of that session, and plan mode's no-mutation guarantee had the same hole. The classifier now reads inside wrapper payloads, treats a command assembled at runtime as unreadable rather than harmless, and never files an interpreter call as read-only.
  • Securityyour provider key reached every command the agent ran. It was published to the environment and inherited by every shell command, script and hook, under the standard names (OPENAI_API_KEY, ANTHROPIC_API_KEY) that credential-harvesting scripts look for, so a repository's own npm test could have read it. Keys are now stripped at every process boundary.
  • Securityweb-fetch had no private-network guard. It is read-only, so it never prompts, which made it the one tool a malicious page could aim back at your own machine, at cloud metadata endpoints or at servers running on localhost. It now refuses private, loopback and link-local addresses, and re-checks after every redirect.
  • Newvoice input. /voice setup downloads and builds whisper.cpp for you; after that Ctrl+S starts recording, Ctrl+S again stops, Esc cancels. Recording and transcription both run on your machine, and the audio is deleted once it has been transcribed, nothing is uploaded, which is the same rule the rest of the CLI follows.
  • Transcription is cleaned up rather than literal. "uhmm, so do this, actually never mind just do that" reaches the agent as "do that". Speech has false starts in it that typing does not, and passing them through verbatim only gives the model something to work around.
  • New/vas, voice auto-send. On, a finished transcript goes straight to the agent. Off, it lands in the composer so you can read and edit it first. /voice model tiny|base trades speed against accuracy, and /voice lang takes an ISO code or auto.
  • Fixeda tool call whose arguments arrived garbled was executed with empty arguments, which turns "the arguments were corrupted" into "delete with no path". Garbled calls are now skipped and reported instead of run.
  • Fixedattached images counted as zero tokens in the context estimator, so a long conversation with screenshots in it could pass the real limit while every number on screen still read comfortable. Sessions no longer store image data at all, which also makes saving and the session list markedly faster.
  • Fixedsending an image with no text now carries a request with it, instead of arriving as an empty prompt that most models answer with "what would you like me to do?".
  • Error messages name the fix: an invalid key points at /provider, a conversation past the limit points at /compact, and a region block is no longer reported as a permissions problem.
  • Cost estimates are per-model rather than one flat rate, and read as estimates instead of to four decimal places.
  • /timers exists. It was referenced on screen but never implemented. /thoughts is now listed in /help.
  • A key already exported in your shell is offered during setup, used for that session only and never written to disk.
v0.1.4
Fix

Windows fidelity, and a screen that never freezes

Two real bugs, fixed within days of being found, plus a correction to how we describe one of the CLI's own settings.

  • Fixedshell commands with double quotes ran mangled on Windows, powershell -Command "…" printed its own text instead of executing, and quoted URLs reached curl broken. Commands are now handed to the shell verbatim.
  • Fixedthe screen could look frozen during long thinking streams on slow terminals. The renderer now emits one scroll and paints only new rows, and skips stale frames when a terminal falls behind.
  • Corrected the CLI's own docs: the default "Hyper" persona is a tone and style preset, not a model or engine, the CLI always runs on whichever provider you configure.
v0.1.3
Fix

Enter submits

The single most disruptive bug in the CLI's short history, and the fastest turnaround so far.

  • Fixedplain Enter didn't submit the prompt, on every terminal, on every platform, since v0.1.0. A terminal-input heuristic misread every Enter as Shift+Enter, so the composer inserted a newline instead of sending.
  • Covered by a new test harness that drives the real UI directly with no pseudo-terminal in the middle, so this class of bug can't hide from CI again.
  • The provider list now opens with the cursor on the first entry.
v0.1.2 +2h 56m after v0.1.1, same day No longer on npm
Chore

Quieter install

A small cleanup, third release of the day.

  • Removed the post-install greeting, npm discards lifecycle-script output, so it never reached anyone anyway. The package now ships with no install scripts at all.
v0.1.1 +1h 16m after v0.1.0, same day No longer on npm
Fix

Linux and macOS become fully supported

Launch day surfaced platform bugs fast. This release is entirely the response.

  • Fixed a crash on Linux/macOS where a hook exiting without reading input took down the whole agent.
  • Terminal state, alternate screen, cursor, mouse mode, bracketed paste, now restored on every exit path, including crashes and signals.
  • Clipboard paste-attach and image resizing now work on macOS (pbpaste, sips) and Linux (wl-paste, xclip, ImageMagick).
  • Provider errors are now reported in plain English instead of raw status codes, rate limits, bad keys, and billing problems each say what to do.
v0.1.0 No longer on npm
Launch

First public release

The origin point of this timeline: a coding agent that lives in your terminal, with real tools instead of a chat window pretending to have them.

  • Plan mode, the provider picker, permission prompts, and the terminal UI, everything the CLI page describes ships here, in the first release, not spread across later ones.
You're all caught up v0.1.0 → v2.0.2

The next entry lands as soon as the next release is public.

Back to install