github fronalabs/frona v2026.10.0

2 hours ago

This release expands how Frona connects to models and manages their credentials. Named provider connections let you keep multiple accounts or endpoints for the same provider and assign them to different model groups. New adapters add Azure OpenAI, Amazon Bedrock, ChatGPT account access, and GitHub Copilot. The provider editor supports API keys, server environment references, saved credentials, and interactive account sign-in, with connection validation before saving.

Managed credentials are encrypted in the database, refreshed when needed, and shared through stable credential references. The model editor combines live provider discovery with bundled catalogue metadata, shows protocol-specific controls, and provides a separate editor for custom request parameters. Configuration saves now preserve unrelated overrides and environment references, detect conflicting edits, and clearly distinguish saved settings from the running configuration.

Chat failures now include persistent, structured details, making authentication, quota, model, network, and tool problems easier to identify. The release also fixes basic memory compaction without a dedicated memory group, refreshes credentials before launching commands, corrects cached-token cost calculations, and improves streaming fallback behavior.

Supported channels: Slack, Discord, Telegram, Signal, SMS, WhatsApp Cloud, WhatsApp Personal.

Providers and account access

  • Introduce named provider connections so multiple accounts or endpoints can use the same provider brand. Model groups and their fallbacks reference connection handles.
  • Preserve legacy provider entries that infer their brand from the configuration key, including the Gemini, Together, and Moonshot aliases.
  • Add Azure OpenAI with resource endpoints, API-key authentication, configurable API versions, and exact deployment names for Chat Completions.
  • Add Amazon Bedrock Converse with streaming, tool use, structured inference, model discovery, region and profile selection, and bearer-key or AWS credential-chain authentication.
  • Add ChatGPT account sign-in through a device-code flow and subscription inference through Responses. Authentication and model entitlement remain separate checks.
  • Add GitHub Copilot device login, credential exchange, model discovery, and model-specific request routing.
  • Add OpenRouter account authorization that creates a managed API key billed to the user's OpenRouter account.
  • Rework provider settings around a provider catalogue, unique connection handles, authentication choices, validation status, active credential sources, and affected model groups.
  • Allow administrators to reference custom server environment variables through a picker that returns names without exposing their values.
  • Keep provider-specific behavior in dedicated adapters, including Cohere, Together, Hyperbolic, Hugging Face, and Perplexity.

Managed credentials and vaults

  • Store managed static secrets and renewable account credentials encrypted at rest, independently of model-provider configuration.
  • Add stable credential IDs so compatible provider connections can share an authorized saved credential.
  • Resolve and refresh managed credentials before use, coordinate concurrent refreshes, and invalidate cached credentials when they are replaced or revoked.
  • Add cancellable, expiring login attempts for account authorization, with checks that prevent stale attempts from replacing newer credentials.
  • Expose managed credentials through personal and system vaults, with ownership checks, grants, field bindings, and account-login APIs independent of model connections.
  • Include managed credential payloads in encryption-key rotation.
  • Resolve current bound credentials before starting CLI, Python, and Node.js commands and MCP servers. Existing processes retain their current environment.
  • Search enabled vaults through a shared credential picker in chat approval and agent settings, with source labels and retry controls for failed searches or field lookups.
  • Save local vault edits through the settings save flow and preserve unsaved work after failures so it can be retried.

Model selection and request settings

  • Combine live provider model listings, catalogue metadata, saved models, and manual model IDs in a shared model directory.
  • Show available protocols and settings for the selected connection, authentication method, and model. Preserve saved entries when discovery or metadata is unavailable.
  • Default OpenAI-branded connections to the Responses API, including manually entered model IDs. Keep explicit Chat Completions selection and the legacy chat_completions alias.
  • Add extra_params for native request parameters, with recursive object merging and explicit override diagnostics. Protect Frona-owned conversation, tool, streaming, and structured-output fields.
  • Put custom request parameters in their own settings accordion and add inline reset controls to settings inputs.
  • Preserve each fallback model's token and temperature settings. Allow streamed requests to use fallbacks before output begins, without switching models after partial output.
  • Add a shared model-catalogue crate for model and parameter metadata, validation, bounded downloads, source status, and atomic cache updates.
  • Bundle validated catalogues in runtime images, use valid local snapshots at startup, and retain them when background refreshes fail.
  • Calculate usage prices by provider brand and model independently of the connection handle, and normalize cached input according to the provider's token-reporting convention.

Configuration and chat reliability

  • Save only changed settings, preserving unrelated explicit overrides and environment-variable references instead of materializing the entire effective configuration.
  • Separate active and persisted configuration revisions, reject stale saves, and write configuration atomically. Saved settings take effect after restart.
  • Fail startup for malformed or unreadable configuration instead of silently continuing with defaults.
  • Centralize administrator authorization for configuration and provider operations.
  • Persist structured message failures and stream them to chat. Expandable details include the failure category, retryability, provider, model, HTTP status, retry and fallback counts, or tool name when available.
  • Display request and network failures in chat and preserve server-side error details after reloading a conversation.
  • Fall back to the relevant chat agent's model for basic memory compaction when its configured background group is absent. PKM consolidation retains its fallback to primary.
  • Make installed-skill path resolution explicit and allow root metadata access in the Syd sandbox for commands that need it.
  • Show the embedded source revision in server information and the About dialog.

Build, containers, and development

  • Upgrade Rust to 1.98.1 and Node.js to 24.21.0, and refresh Rust, Python, system, and pinned binary dependencies.
  • Replace cargo-watch with a checksum-verified prebuilt Bacon binary in development containers. Watch crate sources, resources, and Cargo manifests, and stop the previous server before rebuilding.
  • Remove host development-server tasks; mise run container:dev is the development entry point.
  • Replace the development compiler cache with Kache, supporting local and shared filesystem caches across workspaces.
  • Build missing or explicitly rebuilt Podman images with parallel stages and add rootless keep-id development overrides.
  • Stop backend and frontend watcher process groups together. Foreground Podman shutdown removes containers and networks while preserving data and caches.
  • Keep frontend and Rust artifacts in mount-safe build directories; cleaning preserves mount roots and retained data.
  • Add staged release preparation, per-architecture native builds, and verified image publication before pushing the release commit and tag.
  • Add isolated provider validation against the release artifact, a low-disk Rust integration runner, and regression coverage for credential workflows, provider adapters, configuration, CLI execution, and development process lifecycle.

Upgrade notes

  • Existing built-in provider configurations remain supported. When adding named connections, set the provider brand explicitly and update model-group references to the connection handle.
  • For OpenAI-compatible proxies that require Chat Completions, set api: completions explicitly. Existing api: chat_completions values remain valid.
  • Back up the database, configuration, and encryption secret together. Newly managed credentials live in the database; a config-file backup alone does not include them.
  • Reload settings after a configuration revision conflict, and restart when prompted to activate saved changes. Credential logout affects subsequent use immediately.
  • Rebuild development images with mise run container:dev:build to install Bacon and Kache.

Get started

Don't miss a new frona release

NewReleases is sending notifications on new releases.