Skip to content

v0.17.0

First stable release of the 0.17.0 authentication rollout.

The binary package version, CLI --version output, updater metadata, release tag, and documentation now all use 0.17.0.

  • The Wizard email-OTP flow is the default for ayx one login.

  • A first interactive workspace-password login offers to save the password in the operating-system keyring. The profile stores only the secure reference.

  • Declining the prompt keeps the password session-only for that login. The standalone login command rejects --secret-policy session because it cannot preserve a session after the process exits.

  • --secret-policy plaintext is an explicit, affirmative fallback when secure storage is unavailable.

  • The Legacy email-OTP flow remains available only as an explicit rollback:

    ayx one login --auth-flow legacy

    The equivalent automation override is AYX_AUTH_ROLLOUT=legacy.

The release publishes Linux, Windows, and macOS artifacts. macOS artifacts are currently unsigned and not notarized, so macOS users may need to clear Gatekeeper quarantine manually; see the installation guidance for details.

The release workflow runs the full platform test/build matrix, emits a CycloneDX SBOM for each workspace package, signs release files with Sigstore, and records GitHub build provenance.

For setup and the complete credential-persistence behavior, see Getting started, Connecting, and Identity and auth.