v0.17.0
First stable release of the 0.17.0 authentication rollout.
The binary package version, CLI --version output, updater metadata, release
tag, and documentation now all use 0.17.0.
Authentication
Section titled “Authentication”-
The Wizard email-OTP flow is the default for
ayx one login. -
A first interactive workspace-password login offers to save the password in the operating-system keyring. The profile stores only the secure reference.
-
Declining the prompt keeps the password session-only for that login. The standalone login command rejects
--secret-policy sessionbecause it cannot preserve a session after the process exits. -
--secret-policy plaintextis an explicit, affirmative fallback when secure storage is unavailable. -
The Legacy email-OTP flow remains available only as an explicit rollback:
ayx one login --auth-flow legacyThe equivalent automation override is
AYX_AUTH_ROLLOUT=legacy.
Platform and verification
Section titled “Platform and verification”The release publishes Linux, Windows, and macOS artifacts. macOS artifacts are currently unsigned and not notarized, so macOS users may need to clear Gatekeeper quarantine manually; see the installation guidance for details.
The release workflow runs the full platform test/build matrix, emits a CycloneDX SBOM for each workspace package, signs release files with Sigstore, and records GitHub build provenance.
For setup and the complete credential-persistence behavior, see Getting started, Connecting, and Identity and auth.