NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #3592 most downloaded on pub.dev
Dart tools for initial client onboarding, subsequent client enrollment, and enrollment management.
Last release today
07 Oct 2026
Release timing varies
gaps range from 2 weeks to 6 months
Nearly every release is documented
notes for 38 of 38 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
44 releases · first in 2022
build: requires at_client ^3.15.0-rc5.
at_client ^3.15.0-rc5.fix: a storage path set on the preference after AtOnboardingServiceImpl is built is used again, as in 1.x, rather than an empty store opening in the d
AtOnboardingServiceImpl
is built is used again, as in 1.x, rather than an empty store opening in
the default directory. Building the service no longer fills in the
preference's storagePath.at_client ^3.15.0-rc4 and at_auth ^4.0.0-rc4: waiting
for approval of an expired or unknown enrollment fails at once, with the
atServer's reason.One column per quarter.
build: requires at_client ^3.15.0-rc2 and at_auth ^4.0.0-rc3, for their post-quantum sharing and keyfile lock fixes.
at_client ^3.15.0-rc2 and at_auth ^4.0.0-rc3, for their
post-quantum sharing and keyfile lock fixes.fix: at_activate with no command runs onboard again, as 1.x did, and prints a deprecation warning, where 2.0.0-rc1 refused it outright; 3.0 will refus…
at_activate with no command runs onboard again, as 1.x did, and
prints a deprecation warning, where 2.0.0-rc1 refused it outright; 3.0 will
refuse it.BREAKING: at_activate needs a command: a bare at_activate -a @alice -c prints the commands and exits 1. The deprecated lib/src/activate_cli/activate_c…
AtOnboardingService keeps only
AtOnboardingServiceImpl(atSign, preference), authenticate() and
atClient. onboard is Atsign.activate; enroll, sendEnrollRequest,
awaitApproval and createAtKeysFile are Atsign.enroll,
resumeEnrollment and PendingEnrollment.client; close is
atClient.stop(). The other members are removed.authenticate() takes no enrollmentId, since the keyfile
decides. It opens the client with Atsign.open, stopping any client already
live for the atSign, returns true only when online, and no longer copies the
keys into local storage.at_activate needs a command: a bare at_activate -a @alice -c <secret> prints the commands and exits 1. The deprecated
lib/src/activate_cli/activate_cli.dart is removed.*.enrollment.checkpoint file is gone. The keyfile holds
the pending keys, and running at_activate enroll again resumes the wait.--posture legacy|pqReady|pqActive on every command, defaulting to
at_client's posture, and enroll --key-exchange legacy|pq.AtOnboardingPreference takes posture,
authenticationKeyAlgorithm and dataSigningKeyAlgorithms; storage,
storagePath and storageFor(atSign) choose local storage, and lookUps
and proxyLookUps() the transport.createAtClient opens the client with Atsign.open, tries up to
maxConnectAttempts times three seconds apart, and by default waits for its
post-quantum startup..atKeys file now uses at_auth's
version 1 envelope, with a random per-file salt, which older tooling cannot
read. --hashingAlgoType is now ignored and hidden.--version reports the real version, the enrollment commands say what
they did, and at_activate interactive ends on exit, quit or Ctrl-D and
splits its input on any run of whitespace.at_client ^3.15.0-rc1, at_auth ^4.0.0-rc2 and
at_lookup ^3.7.0-rc2. at_server_status is no longer a dependency.fix: onboarding with a passphrase writes the .atKeys file protected by it.
.atKeys file protected by it.refactor: route enrollment crypto — sha256 hashing, AES key generation and RSA keypair generation — through at_chops (SHA256HashingAlgo, AtChopsUtil.g
sha256 hashing, AES key generation and RSA keypair generation — through at_chops (SHA256HashingAlgo, AtChopsUtil.generateSymmetricKey, AtChopsUtil.generateAtEncryptionKeyPair). crypto, encrypt and crypton are no longer imported anywhere in the package and have been dropped from dependencies. Byte-identical by construction.decrypt command outputs a passphrase-decrypted version of the atKeys file--version, --help, and helpat_auth: ^3.2.0, at_lookup: ^3.6.0 — onboarding/auth network
waits are time-bounded (deadline-driven validateAtServer, bounded
atDirectory lookups) only with these versions resolved.feat: add --root-server option to specify root server domain
--root-server option to specify root server domain--license-key alias for --cramkeychore: export createAtClientCli() to be used downstream
build: remove the dependency override on the args package
args packagefeat: export the PrintAllArgParserUsage mixin on ArgParser
add a warning message before onboarding attempts to cut keys that presents a message explaining importance of backing up keys and prompting the user a
--cramkey to the onboard command will skip the warning message inherently--yes | -y flag to the onboard command to skip this warning messageat_activate onboard --rootServer proxy:<host>:<port>at_activate enroll --rootServer proxy:<host>:<port>--root-server option to specify root server domain--license-key alias for --cramkeychore(deps): chalkdart ">=2.0.9<4.0.0"
feat: reuse the authenticated connection from AtAuth.authenticate when creating the AtClient which is handed back to the calling code.
feat: remove unnecessary dependency on at_persistence_secondary_server
feat: better user feedback during onboarding / enrollment / etc
fix: have onboard only perform post-auth activation completion once the atKeys file has been successfully saved.
onboard only perform post-auth activation completion once the
atKeys file has been successfully saved.fix: potential bug handling atSigns which end in data e.g. @foo_data
data e.g. @foo_datafix: path resolution for temporary directory on Windows
fix: Replace legacy IVs with random IVs for encrypting "defaultEncryptionPrivateKey" and "selfEncryptionKey" in APKAM flow
feat: add unrevoke command to the activate CLI
unrevoke command to the activate CLIdelete command to the activate CLIfeat: add auto command to the activate CLI
auto command to the activate CLIbuild[deps]: upgrade: \ at_client to 3.2.2 | at_commons to 5.0.0 | at_lookup to 3.0.49 | at_utils to 3.0.19 \ at_persistence_secondary_server to 3.0.6
fix: .atKeys filename was trimmed when filename has period('.') in it
.atKeys filename was trimmed when filename has period('.') in itfix: .atKeys file was being generated in the wrong location in some cases
.atKeys file was being generated in the wrong location in some casesfeat: save enrollment details to local keystore
feat: add 'status' command to the activate cli to check the status of an atSign
feat: 'activate' CLI is now APKAM-aware, and supports
feat: uptake changes for at_auth 2.0.0
build[deps]: upgrade at_chops to 2.0.0 | at_lookup to 3.0.45 | at_client to 3.0.74
build[deps]: upgrade: \ at_commons to 4.0.0 | at_auth to 1.0.4 | at_chops to 1.0.7 | at_client to 3.0.73 \ at_lookup to 3.0.44 | at_server_status to 1
feat: remove duplicate enrollment code and use at_auth
feat: support for APKAM based authentication
fix: deprecate qr_code based activation
feat: changes to integrate onboarding_cli with pkam secure element
feat: atkeys file now placed in standard location ~/.atsign/keys
fix: Onboarding_cli throws exception when atsign does not start with '@'
- Enable use of AtChops
Minor reformatting of user logs and minor bugfixes
Introducing register_cli that fetches a free atsign and registers it to provided email
Introducing activate_cli, a simple tool to activate atSigns from command-line
Method to check and format atsign.
[Breaking Change] Migrating AtException to AtClientException.
- Initial version.
Your coding agent can read these notes before it upgrades. Set up the MCP server →