v1.4.0 Changelog
This minor version release introduces batch team onboarding capabilities, strict security boundaries via local password confirmation for workspace invitations, and transparent JWT token auto-refresh handling in the background proxy daemon.
What's New in v1.4.0
Additions
Batch Workspace Invites
You can now invite multiple team members to a workspace simultaneously by providing a list of space-separated email addresses:
agentsecrets workspace invite dev1@company.com dev2@company.com dev3@company.com
- Performance: The CLI resolves public keys for all invitees concurrently before executing a single bulk invitation payload to the API, drastically reducing invitation latency.
Mandatory Password Verification for Invites
To uphold the zero-knowledge model, invitations require your local account password to decrypt the symmetric Workspace Key on your machine before re-encrypting it with each invitee's public key. This brings the invite flow in line with allowlist management security rules.
Improvements
Proxy Daemon JWT Auto-Refresh
The background proxy daemon and API client will now automatically detect expired user sessions (401 Unauthorized) during background operations (such as audit log pushes), dynamically trigger a token refresh using the stored refresh token, save the new credentials to disk, and retry the request exactly once. No more manual CLI logins are needed to resume proxy background tasks.
Telemetry Accuracy Improvements
- Corrected the telemetry reporting timeline to filter out the current ongoing (incomplete) day.
- Only fully completed 24-hour daily historical buckets are pushed to the backend, preventing skewed metrics.
- Successfully synced historical days are pruned from the local SQLite database.