Skip to content
Browse the docs

Changelog

All notable changes to the stoa client. The format follows Keep a Changelog; versions follow Semantic Versioning.

0.3.1

Released 2026-09-29.

Packaging only; the client's behaviour is unchanged from 0.3.0.

0.3.0

Released 2026-09-29.

Security release. Upgrade with uv tool upgrade stoa-cli (or pipx upgrade stoa-cli): 0.2.0 and 0.2.1 are superseded, and the venue now requires this version.

  • Every command needs a signed-in session: categories, assets search, rfq schema and rfq template no longer read from the venue anonymously, and the venue requires the organization's command line access grant plus an enrolled second factor at stoa login.
  • assets search lists the catalog's identity only; the venue's catalog API carries no reference price, in the table or in --json.
  • rfq template --offline and the schema vendored with the package are gone; the template always renders from the venue's schema.
  • The demo environment is gone: --env takes prod or local. A session that 0.2.x saved for demo stays in the operating system keychain (service stoa-cli, account demo; on macOS security delete-generic-password -s stoa-cli -a demo removes it) next to its handshake cache ~/.config/stoa/meta-demo.json; remove both by hand, the client no longer names that environment.
  • Text from the venue or from a dealer is kept to one line where it lands in a table, a summary or a TOML comment, and every message the client prints is stripped of control characters. The version handshake accepts only well-formed version numbers and a docs address under www.stoaexchange.com.
  • Session tokens are stored only in the macOS Keychain, Windows Credential Locker, Secret Service, libsecret or KWallet backends; any other keyring backend is refused.
  • A malformed --base-url, an oversized TOML integer and an unexpected error envelope report an error instead of a traceback.

0.2.1

Released 2026-09-29.

  • Fixed: the signed-out message told the user to run stoa login --env prod, which click rejects because --env belongs to the group; it now reads stoa --env prod login.

0.2.0

First public release.

  • Requests for quote are composed the way the web form composes them: a GPU from the catalog or an unlisted model, a per-node GPU count, the node configuration (firm specs and minimums with optional exact pins), named rack systems, delivery, warranty, fill policy and the seller's condition facts. stoa rfq create posts to the compose endpoint and prints the server's composition before anything is sent.
  • stoa rfq schema prints the request vocabulary the server publishes; stoa rfq template renders a commented TOML file from it (--offline uses the vendored snapshot).
  • stoa rfq get shows the frozen configuration, every dealer, every quote with its terms, and the best full quote, then the web address where a quote is accepted.
  • --json on whoami, categories, assets search, rfq schema, rfq create, rfq list and rfq get, for scripts and coding agents; under --json the binding statement and the prompt go to stderr. stoa agent-guide prints the instructions to paste into an agent's project notes.
  • rfq create --agree-binding-statement records a person's agreement to the binding statement without the prompt (the statement is still printed); the request file may name a US state by its two-letter code; capacities (TB, kW) travel as exact decimal strings; and a replayed idempotency key is reported from the server's Idempotency-Replayed header.
  • Sign-in accepts an SMS code where the account has one enrolled, and asks the server for a session scoped to catalog reads, request composition and request reads.
  • Version handshake against GET /api/v1/meta: the client refuses to run below the minimum the server accepts and points at the upgrade command.
  • Packaged on its own (stoa-cli on PyPI) with Python 3.12 or newer.

0.1.0

Internal release inside the Stoa Markets repository: sign in, browse the catalog, create a request against an existing catalog asset, list and read requests.