NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1465 by repository stars
Last release 8 days ago
29 Sep 2026
Ships unpredictably
gaps range from 2 weeks to 1.1 years
Most releases are documented
notes for 13 of 18 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
26 releases · first in 2024
One column per month.
404133e fix(release): ignore .zig-cache so the add-members fix can ship
Released by GoReleaser.
xurl chat add-members fix. The v1.3.3 release stopped before publishing them because a restored Zig build cache left the checkout dirty; that cache directory is now ignored.xurl chat add-members no longer fails with "Invalid action signature" on a group whose message timer (message_ttl_ms) or screen-capture blocking setti
xurl chat add-members no longer fails with "Invalid action signature" on a group whose message timer (message_ttl_ms) or screen-capture blocking setting (screen_capture_blocking_enabled) has been set. The signed group state left both out; it now carries the values from the conversation.a28b91b chore: add changelog entry for Homebrew postflight fix
postflight is deprecated" warning when loading the xurl cask. The cask now uses postflight_steps for the same macOS quarantine cleanup.95853a1 build: ship cgo-enabled xurl chat in release binaries
Released by GoReleaser.
xurl chat XChat client on macOS (arm64/amd64) and Linux (amd64) — installing via Homebrew, npm, or a GitHub release tarball no longer prints the "not available in this build" stub on those platforms. The Linux amd64 binary is statically linked against musl, so it runs on both glibc and musl (e.g. Alpine) distros. Platforms without a chat-xdk library (Windows, Linux arm64/i386) still ship the graceful stub.Nothing published for this version
49ea3b8 ci: publish npm from Cut Release via release.yml dispatch
xurl chat — an end-to-end encrypted XChat client. Commands: keys status|restore|import, conversations, read, send, listen, download, rotate, add-members, mark-read, and typing. Encryption, decryption, and signing happen locally via the chat-xdk library; the server only sees ciphertext. send supports encrypted attachments (--file) and threaded replies (--reply-to); reading and sending mark the conversation read automatically. xurl never generates or registers keys — an account must already have XChat keys from another client, brought to this machine via Juicebox PIN recovery or an exported key blob, and stored in ~/.xurl/keys.yml (mode 600). Requires a cgo build on macOS (amd64/arm64) or Linux (amd64); prebuilt release binaries ship a stub explaining how to build with chat enabled.~/.xurl is now a directory: tokens and app credentials live in ~/.xurl/auth.yml, and XChat private keys live in ~/.xurl/keys.yml. An existing single-file ~/.xurl migrates automatically (rename-based and non-destructive) on first use, and the existing legacy migrations still apply on top of the new layout: pre-v1.0 JSON-format token files are converted to YAML, and .twurlrc import is unchanged. Older xurl binaries cannot read the new layout.Nothing published for this version
9785821 ci: add Cut Release workflow for patch/minor/major cuts
Released by GoReleaser.
workflow_dispatch) to promote CHANGELOG.md, commit + tag on main, and publish (GitHub release, Homebrew, npm) in one run.xurl auth oauth2 no longer always warns that the "default" app has no client credentials when --app is omitted. The check used GetApp("") (empty-key map lookup, always nil) instead of the real default app, so it false-alarmed even when the active default (e.g. app-2) had credentials. The warning now resolves default_app and names that app correctly.Nothing published for this version
Nothing published for this version
Nothing published for this version
bfb0f36 docs(mcp): correct mcp --help to document first-run browser login
mcp --help no longer contradicts the bridge's behavior. The v1.2.1 help text still said the bridge "never opens a browser itself; if no token exists it exits with that instruction", but v1.2.1 changed the bridge to open the browser for a first-run OAuth2 login when no token is cached. The help now documents that, and points remote/headless hosts to xurl auth oauth2 [--app NAME] --headless.a312d5d ci: harden release workflow (split npm job + workflow_dispatch, OIDC-ready)
Released by GoReleaser.
mcp bridge now runs the interactive browser OAuth2 login on first run when no token is cached (using CLIENT_ID/CLIENT_SECRET from its environment), instead of failing fast. This lets the bridge authenticate with no prior xurl setup — e.g. straight from npx … mcp — and then caches/auto-refreshes the token. The MCP handshake is held until the login completes (set a generous startup_timeout_sec on the server), and login diagnostics stay on stderr so the stdout JSON-RPC channel is unaffected. On a headless host, authenticate out-of-band first with xurl auth oauth2 --headless.b8d4863 Fix media category README typo
Released by GoReleaser.
install.sh now uses id -u instead of the bash-only $EUID to detect root, so curl ... | sh (POSIX/dash) installs to /usr/local/bin as root instead of silently falling back to ~/.local/bin. (#68)install.js extracts the .zip with PowerShell's Expand-Archive instead of the Unix unzip command. (#56)whoami (and user) now request verified_type and subscription_type, so Premium/blue accounts are reported correctly instead of verified: false. (#41)client_id in the body for public clients — instead of relying on autodetection, which could fail against X with unauthorized_client: Missing valid authorization header.mcp bridge no longer launches a browser at startup: it still refreshes an existing token silently, but when none is available it fails fast with instructions (xurl auth oauth2 [--app NAME] [--headless]) instead of opening a browser mid-startup (which could hang an MCP client's handshake) and printing to the JSON-RPC stdout channel. OAuth2 diagnostics now go to stderr.mcp bridge no longer lets a strict client hang: a request that cannot be answered — transport failure, a failed token refresh/retry after a 401, or a response with an empty/non-JSON body — now gets a synthesized JSON-RPC error keyed to its id. Notifications (e.g. notifications/cancelled) are no longer head-of-line blocked behind an in-flight streaming response, large but valid JSON error bodies are forwarded whole instead of being truncated, the standalone server->client stream stops probing a non-event-stream 200 and only resets its reconnect backoff after a healthy stream, and stdin memory stays bounded when an oversized line is dropped.mcp bridge hardening: serialized token-store access (fixes a fatal data race when a token expires mid-session), strict newline-delimited-JSON stdout (SSE/JSON responses are validated and compacted, non-JSON keep-alives dropped), a forced token refresh on HTTP 401, cancelable stdin so SIGINT/SIGTERM shuts the bridge down, resilience to oversized input lines, a server->client stream that resets its backoff/supports stateless servers/retries 408 & 429, and a best-effort session DELETE on shutdown.media upload --wait now also waits for animated GIFs (auto-detected as tweet_gif), and a media type that cannot be detected — or is recognized but unsupported (e.g. application/pdf) — now fails with a clear message instead of guessing tweet_image and getting an opaque API error.timeline --max-results minimum corrected to 1 (matches the reverse-chronological endpoint).media upload --wait now actually waits for processing and no longer always sends the trace header — the waitForProcessing and trace arguments were passed in the wrong order.null when a request fails before getting an HTTP response (e.g. DNS or connection failures).--auth value, now fail with a clear authentication error instead of silently sending an unauthenticated request.xurl dm now JSON-encodes message text correctly; quotes, backslashes, and newlines no longer produce a malformed request body.--max-results is clamped to each endpoint's accepted range for timeline, mentions, bookmarks, likes, following, followers, dms, and posts.fetchUsername now uses a 10s HTTP timeout, and PKCE verifier generation now handles RNG errors instead of ignoring them.webhook start help now references the correct -P pretty-print flag and serves on an isolated ServeMux..gitignore now correctly ignores .DS_Store (a missing newline had merged it with a comment).127.0.0.1:8080. For localhost, xurl now listens on both 127.0.0.1 and ::1, which fixes browser-dependent loopback resolution failures while still supporting non-default callback paths./2/users/me succeeding. If username discovery fails, xurl keeps the refreshed token instead of failing the request.--username lookups when /2/users/me is unavailable.GetOAuth2Header now consistently returns a Bearer header even when it has to trigger a fresh OAuth2 flow.xurl auth oauth2 --headless for authenticating on remote/headless machines where the localhost OAuth callback is unreachable: xurl prints the authorization URL, you open it on any device and approve, then paste the resulting redirect URL (or just the code) back at the prompt. No callback listener or local browser is required. (Closes the headless half of #62 / #40.)mcp bridge's 401 recovery.xurl token's missing-token error now names the requested user, and token/mcp errors omit ANSI color when stderr is not a terminal (cleaner piped/logged output). The auto-generated help/completion commands now appear under the Management group.xurl token: prints a valid (refreshed, persisted) OAuth2 access token for the active app to stdout without opening a browser, so it can be scripted. Respects --app and -u/--username.xurl mcp [URL]: a stdio↔Streamable-HTTP MCP bridge for the hosted X API MCP server (default https://api.x.com/mcp). It injects Authorization: Bearer <token>, maintains the MCP session id, handles plain-JSON and SSE responses, refreshes the token in-process, and triggers the browser login on first run if needed. Usable from any MCP client via npx -y @xdevplatform/xurl mcp.xurl auth app-only [TOKEN] (named for the auth mode, not the "bearer" token scheme that OAuth2 user tokens also use), taking the token as an argument or from stdin via -. It removes the old app vs apps confusion and the redundant auth bearer --bearer-token. Back-compat: auth app and auth bearer remain aliases and --bearer-token is still accepted.xurl --help now groups subcommands into "Posting & Engagement", "Users & Social Graph", "Reading & Lists", and "Management" sections instead of one flat list.xurl posts USERNAME to list a user's recent posts.xurl --version is now supported in addition to xurl version.POST when -d is supplied (curl-like), and media upload auto-detects the media type and category from the file extension when they are not provided.xurl skill now recommend authenticating registered apps with xurl auth oauth2 --app APP_NAME and explain that omitting --app saves the token to the current default app./2/users/me lookup is unavailable. Status output makes that state visible as (unknown user) instead of silently dropping the token.redirect_uri behavior.redirect_uri in ~/.xurl, REDIRECT_URI from the environment still takes precedence, and xurl auth apps redirect-uri get/set plus auth apps update --redirect-uri make that configuration visible and editable from the CLI.client-forbidden / client-not-enrolled read failures: moving the app to the Pay-per-use package and the Production environment fixed live /2/* reads after OAuth had already succeeded.Nothing published for this version
618d55c warn: oauth2 without --app saves token to credential-less app
Released by GoReleaser.
OAuth2 UsernameNotFound workaround — xurl auth oauth2 USERNAME now passes the username through to the OAuth2 flow, skipping the broken /2/users/me loo
OAuth2 UsernameNotFound workaround — xurl auth oauth2 USERNAME now passes the username through to the OAuth2 flow, skipping the broken /2/users/me lookup that has been returning 403 for many developers. (#60)
Windows OAuth2 authentication — Fixed xurl auth oauth2 on Windows where cmd /c start truncated the authorization URL at the first &, stripping required PKCE parameters. Now uses rundll32 to open the browser with the full URL intact. (#61)
--app flag fully functional — The --app flag now correctly switches credentials for all commands. Previously it was silently ignored — token reads, saves, clears, auth auto-detection, and webhook CRC signing all used the default app regardless of --app. (#46)
OAuth2 callback localhost resolution — The OAuth2 callback listener now binds to both 127.0.0.1 and ::1 when using localhost, fixing failures on systems where the browser resolves localhost to IPv6. The listener also starts before opening the browser, eliminating a race condition. (#64)
OAuth2 token resilience — Token refresh no longer fails when /2/users/me is unavailable. Tokens are preserved with or without a username label, and unnamed tokens are automatically migrated once username lookup succeeds. (#64)
Firehose endpoint typo — Fixed /2/tweets/firehose/strea/lang/en → /2/tweets/firehose/stream/lang/en in stream detection. (#49)
Per-app redirect URI — Apps can now store a redirect_uri in ~/.xurl. Precedence: REDIRECT_URI env var → stored app config → built-in default. New CLI commands: xurl auth apps redirect-uri get/set and --redirect-uri flag on auth apps add/update. (#64)
--username fallback for shortcut commands — Commands that need your user ID (timeline, mentions, like, etc.) now fall back to username lookup when /2/users/me is unavailable. Use -u USERNAME as a workaround. (#64)
Nothing published for this version
Nothing published for this version
595ed07 fix: auto-detect version from go module info for go install
Released by GoReleaser.
94ef6f1 fix: use github.com/xdevplatform/xurl module path for go install
Released by GoReleaser.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →