v0.18.1
This is the first published 0.18 release. It packages the output-contract, human-readable workflow governance, authentication, and release-integrity work validated in the v0.18.0 release commit.
Output contract
Section titled “Output contract”-
Human-readable text remains the default output.
-
--output jsonemits the compact, versionedayx.output.v1envelope. Compact list responses default to 20 projected rows and reporttotal_count,shown_count,truncated, andnext_page_token. -
--output json-fullemits the complete recursively redacted envelope for diagnostics, exports, compatibility migration, and raw-field inspection. -
--output-limit Nchanges the compact-list cap;0means unlimited. -
Put output selection after the command path:
ayx one flows list --output jsonayx one flows list --output json-full
This is a breaking machine-interface change from 0.17.0: automations that
consumed the former lossless --output json shape should use json-full while
migrating to the compact contract.
Human-facing One workflows
Section titled “Human-facing One workflows”Every One leaf command now has an output descriptor so compact responses have
stable command identity, resource kind, and intended fields. The default
ayx one workflows list view now shows:
ID NAME OWNER LAST UPDATED VERSIONWorkflow governance data is assembled from the workflow list, workflow-assets
metadata, and the people directory. Owner names are resolved where available;
the full response retains raw fields and owner_id. Build-oriented fields such
as checksums and compiler versions remain available in json-full but no longer
crowd the default human view.
The CLI intentionally keeps /v4 as the canonical gateway for resources that
belong there. The richer workflow-asset operations remain on the separate
/svc-workflow service, and the endpoint matrix documents that boundary.
Authentication and reliability
Section titled “Authentication and reliability”- OAuth2.0 API access/refresh credentials are the recommended authentication
method for unattended CLI, CI, and agent use. Import the refresh token once
with
--refresh-token-env NAMEor--refresh-token-stdin; secure persistence keeps the credential pair in the operating-system keyring and automatically renews short-lived access tokens. - OAuth credentials are bound to the selected workspace and do not silently fall back to email OTP. Email OTP remains the default interactive method.
- Refresh-token rotation is persisted when the credential is keyring-backed. Because provider exchange and local keyring storage cannot be one atomic transaction, the CLI fails closed after a local persistence error and tells the operator to re-import a fresh provider-issued pair rather than retrying blindly.
- Wizard email-OTP authentication is the default for
ayx one login. - Legacy remains available only as an explicit rollback lane through
--auth-flow legacyorAYX_AUTH_ROLLOUT=legacy. - Workspace-password retry and saved-password persistence support the same constrained-environment path used by Legacy.
- The keyring-unavailable onboarding test seam is scoped to the current test thread, eliminating process-global environment-variable races under parallel execution.
Release integrity
Section titled “Release integrity”The GitHub release workflow builds Linux, Windows, and macOS packages, runs formatting, clippy, and the locked workspace test suite, and publishes:
- platform archives for Linux, Windows, Intel macOS, and Apple Silicon macOS;
- SHA256 checksums;
- CycloneDX SBOMs;
- Sigstore bundles for release artifacts; and
- GitHub build-provenance attestations when supported by the repository.
macOS signing and notarization remain conditional on the repository’s signing secrets. The workflow reports that posture in the build summary.
Upgrade note
Section titled “Upgrade note”The existing v0.17.0 binary cannot discover this release until the GitHub
release is published. After publication, run:
ayx updateayx --versionThe expected version is 0.18.1.