Changelog
All notable changes to the stoa client. The format follows Keep a Changelog; versions follow
Semantic Versioning.
0.3.1
Released 2026-09-29.
Packaging only; the client's behaviour is unchanged from 0.3.0.
- The package metadata points at the documentation site: https://www.stoaexchange.com/docs/cli and this changelog at https://www.stoaexchange.com/docs/cli/changelog.
- The README is a short pointer to the documentation; the source distribution carries the client, this changelog, the security note and the license.
0.3.0
Released 2026-09-29.
Security release. Upgrade with uv tool upgrade stoa-cli (or pipx upgrade stoa-cli): 0.2.0 and
0.2.1 are superseded, and the venue now requires this version.
- Every command needs a signed-in session:
categories,assets search,rfq schemaandrfq templateno longer read from the venue anonymously, and the venue requires the organization's command line access grant plus an enrolled second factor atstoa login. assets searchlists the catalog's identity only; the venue's catalog API carries no reference price, in the table or in--json.rfq template --offlineand the schema vendored with the package are gone; the template always renders from the venue's schema.- The
demoenvironment is gone:--envtakesprodorlocal. A session that 0.2.x saved fordemostays in the operating system keychain (servicestoa-cli, accountdemo; on macOSsecurity delete-generic-password -s stoa-cli -a demoremoves it) next to its handshake cache~/.config/stoa/meta-demo.json; remove both by hand, the client no longer names that environment. - Text from the venue or from a dealer is kept to one line where it lands in a table, a summary or a TOML comment, and every message the client prints is stripped of control characters. The version handshake accepts only well-formed version numbers and a docs address under www.stoaexchange.com.
- Session tokens are stored only in the macOS Keychain, Windows Credential Locker, Secret Service, libsecret or KWallet backends; any other keyring backend is refused.
- A malformed
--base-url, an oversized TOML integer and an unexpected error envelope report an error instead of a traceback.
0.2.1
Released 2026-09-29.
- Fixed: the signed-out message told the user to run
stoa login --env prod, which click rejects because--envbelongs to the group; it now readsstoa --env prod login.
0.2.0
First public release.
- Requests for quote are composed the way the web form composes them: a GPU from the catalog or
an unlisted model, a per-node GPU count, the node configuration (firm specs and minimums with
optional exact pins), named rack systems, delivery, warranty, fill policy and the seller's
condition facts.
stoa rfq createposts to the compose endpoint and prints the server's composition before anything is sent. stoa rfq schemaprints the request vocabulary the server publishes;stoa rfq templaterenders a commented TOML file from it (--offlineuses the vendored snapshot).stoa rfq getshows the frozen configuration, every dealer, every quote with its terms, and the best full quote, then the web address where a quote is accepted.--jsononwhoami,categories,assets search,rfq schema,rfq create,rfq listandrfq get, for scripts and coding agents; under--jsonthe binding statement and the prompt go to stderr.stoa agent-guideprints the instructions to paste into an agent's project notes.rfq create --agree-binding-statementrecords a person's agreement to the binding statement without the prompt (the statement is still printed); the request file may name a US state by its two-letter code; capacities (TB, kW) travel as exact decimal strings; and a replayed idempotency key is reported from the server'sIdempotency-Replayedheader.- Sign-in accepts an SMS code where the account has one enrolled, and asks the server for a session scoped to catalog reads, request composition and request reads.
- Version handshake against
GET /api/v1/meta: the client refuses to run below the minimum the server accepts and points at the upgrade command. - Packaged on its own (
stoa-clion PyPI) with Python 3.12 or newer.
0.1.0
Internal release inside the Stoa Markets repository: sign in, browse the catalog, create a request against an existing catalog asset, list and read requests.