Skip to main content
Stay up to date with the latest changes to Figranium. For documentation changes, see the source repository directly.
Figranium releases continuously. Major features are announced here as they ship. Check back weekly for new capabilities.
Vault and scoped API keys

Features

A new Vault screen in the sidebar lets you create, import, rename, and delete cookie states. Start a state empty or import a Playwright storage-state JSON file. In the editor, open States and pick a cookie state for each task. Runs start from that state and save changed cookies back to it. Choose No State to run with an empty, isolated cookie context. This replaces the Stateless Execution toggle, and existing stateless tasks move to No State automatically. See Session state and Stateless execution.

1Password passwords in tasks

Connect a 1Password service account token in Settings > Connections. Figranium uses a dedicated “Figranium” vault, and creates it if it doesn’t exist. Use {$passwords.example^com} in any task to insert the password from the Login item whose website is example.com, replacing dots with ^. Figranium resolves passwords on the server. If no Login item matches, or more than one does, the run fails instead of using an empty value. The editor’s variable list has a new Passwords tab, and Vault > Passwords lets you copy saved passwords. See Variables.

Scoped API keys

Settings > API Keys now lets you create multiple named keys. Give each key only the permissions it needs: Read tasks, Run tasks, Read results, or Manage tasks. You can also limit a key to specific tasks. A key is shown once at creation and can be revoked at any time. Your existing key keeps working as Legacy full access key. See API key.

Updates

  • Baserow connections: save Baserow API keys under Settings > Connections for use as task output destinations.
  • Settings and sign out: Settings now sits at the bottom of the sidebar. Sign out moved to Settings > Advanced.
  • Editor shortcuts: the editor top bar has new Behavior, States, and Output buttons that open task settings directly.
  • Data export and import: archives can now include cookie states and Connections. Archives contain readable API keys, cookies, and connection tokens, so store them securely. See Exporting data.
This week

Features

Selective data import

Settings > Advanced now has an Import data section. Choose a Figranium export ZIP, pick which of the included categories to restore, and click Import selected. Imported categories replace their matching workspace data. Unselected categories stay unchanged. See Exporting data.

Run tasks from CI with the JavaScript SDK

@figranium/sdk 0.5.0 adds a figranium run <task-id> command for running saved tasks from GitHub Actions, GitLab CI, Jenkins, or your terminal. Set FIGRANIUM_URL and FIGRANIUM_API_KEY, pass runtime variables with repeatable --var name=value, and use --timeout and --json as needed. The command exits with 0 on success, 1 when the task completes unsuccessfully, and 2 for configuration, authentication, or network failures. See the JavaScript SDK.

Updates

  • Playwright 1.64: Figranium and its Docker image now use Playwright 1.64 and its matching browsers. See Docker Compose.
  • Refreshed MCP connection page: the hosted MCP server’s OAuth connection page has a new Figranium-branded design that fits small screens.
  • Maintenance: the MCP server now uses @figranium/sdk 0.5.0. No action is needed.

Fixes

  • Safari after restart: Figranium now loads reliably when you reopen Safari, without clearing website data first.
  • Headful viewer in Safari: the headful viewer now connects in Safari.
  • Headful viewer errors: if the viewer can’t load, the headful window now shows an error message instead of staying blank.
  • New headful sessions: closing a previous viewer no longer stops a headful session you just started.
  • Cursor states: buttons, links, and sidebar items now show a consistent pointer cursor.
  • MCP server home page on mobile: the MCP server home page now has a mobile navigation menu. In the Connect Figranium dialog, the close button stays visible while you scroll through client tabs on narrow screens.
This week

Features

Selective data export

Settings > Advanced now has an Export data section. Select any of tasks, executions, captures, API keys, and cookies to download them as a ZIP archive with a manifest. See Exporting data.

Updates

  • New security contact: report vulnerabilities to security@figranium.dev instead of admin@figranium.dev. Include the npm or container version and tag, steps to reproduce, and any relevant logs or screenshots. See Security for hardening guidance.
  • Maintenance: Figranium, the JavaScript SDK, the MCP server, and the CAPTCHA solver received routine dependency updates. No action is needed.
This week

Fixes

  • Results toolbar with pinned controls: in the editor’s results drawer, the Data and Downloads toolbar now wraps its controls when pinned items make it wider than the pane, instead of overflowing. The Unpin button is also easier to read in light themes.
This week

Features

Templates in the JavaScript SDK

@figranium/sdk 0.4.0 adds a templates resource. You can list, search, filter, and paginate the template catalog, fetch a single template by ID, and report a successful import. See the JavaScript SDK and the Templates API.

Template tools in the MCP server

MCP server v1.4.0 adds two read-only tools. template_search searches the template catalog by keyword and category, with sorting and pagination. template_get returns a template’s full workflow and README by ID. Your LLM client can now find a community template before building a task from scratch.

Updates

  • Template popularity from real imports: when you import a template, Figranium reports the import to the Templates Hub, so Most popular sorting and featured templates reflect actual usage. Each installation counts at most once per template, using a random installation ID that is unrelated to telemetry. Reporting is best-effort and never causes an import to fail.

Fixes

  • Captures from other runs: the screenshots and recordings modal in an execution’s detail view now shows only that run’s captures. GET /api/data/captures also matches the run ID exactly, so runs with similar IDs no longer return each other’s files.
v0.20.0

Features

Templates in the app

A new Templates screen (Alt/Option + 2) lets you search, filter by category, sort, and preview community automations, including each template’s README and expected output. Click Import to add a template as a new task and open it in the editor. Empty workspaces show popular templates on the dashboard, and the Create Task menu includes Create from a template. See Templates and the Templates API.

Queued execution status and cancellation

Executions now report a phase of queued, running, or finished, including scheduled runs. Stopping a run with POST /api/executions/stop also cancels it while it is still waiting in the queue. See REST API.

Full results for large executions

When a result exceeds the execution-history size limit, Figranium stores the complete result separately. Load it from the execution detail view or with GET /api/executions/{id}/result. See Captures and storage.

Adaptive headful viewer

The headful viewer lowers image quality, and switches to a lower-bandwidth stream on very slow connections, then restores full resolution when your connection recovers. See Adaptive viewer quality.

Removed

  • Captures page: view a run’s screenshots and recordings from its detail view in Executions.
  • AI features: AI provider keys, AI model settings, AI extraction script generation, and AI selector generation are no longer available. Visual extraction still generates extraction scripts from your field definitions.
This week

Updates

  • Resizable sticky notes: drag the right edge of a sticky note on the editor canvas to make it wider or narrower. Notes keep a minimum width of 180 px, and the new width saves when you release.
  • File type icons: PDF, Word, Excel, and PowerPoint files in Cabinets and the editor results pane now use icons that match the rest of the interface and follow your active theme.

Fixes

  • Loop connectors in light themes: the connector lines that wrap loop blocks in the editor canvas are now visible in Light and Solarized Light.
v0.19.0

Features

Host-aware resource protection

Figranium now sizes browser concurrency to your host automatically, using available memory (including Docker cgroup limits) and CPU count. Extra runs wait in a first-in, first-out queue that pauses under memory or CPU pressure. A full queue or long wait returns 503 RESOURCE_CAPACITY_EXCEEDED with a Retry-After header, and non-headful runs that exceed 15 minutes stop with 504 EXECUTION_TIMEOUT. Tune it with MAX_CONCURRENT_EXECUTIONS, MAX_EXECUTION_QUEUE, EXECUTION_QUEUE_TIMEOUT_MS, EXECUTION_TIMEOUT_MS, RESOURCE_MEMORY_RESERVE_MB, RESOURCE_CPU_THRESHOLD, and RESOURCE_PROBE_INTERVAL_MS. See Host-aware resource protection.

Automatic data retention

Captures, recordings, and execution history are now deleted automatically after 7 days by default. Choose 1 to 365 days or Never in Settings > Advanced. Cleanup runs at startup and hourly for JSON and PostgreSQL storage. See Automatic Retention.

Advanced settings

A new Settings > Advanced page lets you change your account email and password, set data retention, clear captures or execution history, clear all workspace data (with password confirmation), and see local CAPTCHA solver capacity. See UI Tour.

Cabinet context menus

Right-click a Cabinet in the sidebar to rename, clear, or delete it. When you delete a Cabinet, you pick a replacement, and tasks and Upload actions that used the deleted Cabinet point to the replacement. The default Cabinet is protected from deletion in the UI and API. Empty Cabinets now show a crossed-out folder icon. See Cabinets workspace.

Updates

  • API key access to executions, captures, and Cabinets: GET /api/executions/:id, GET /api/data/captures, and GET /api/cabinets now accept an API key as well as a signed-in session. Scripts, SDKs, and integrations can fetch run logs and results, list captures, and list Cabinets without a browser login. See REST API and Cabinets.
  • Settings buttons: the Regenerate API key button and the Add Proxy button now use a blue primary style, so the main action on each settings panel is easier to spot. See API key and Proxy rotation.
  • Health and system APIs: GET /api/health now reports version, non-sensitive resource protection state, and local captcha capacity. New GET and POST /api/settings/system endpoints read and save retention, and GET /api/capabilities describes runtime features. See REST API.
  • Bounded execution history: stored execution records are capped at 256 KB and extraction workers have bounded output and memory, so an oversized result can no longer destabilize the server. See Execution Logs.

Fixes

  • Theme readability: AI Model controls are readable in Light and Solarized Light, and the decorative dot grid was removed from sign-in screens.
  • Extraction script logging: extraction scripts now support console.info() and console.debug(). Scripts that call these methods no longer fail. Their messages appear in the extraction logs with log, warn, and error output.
Earlier this week

Features

Swift SDK

The official Swift SDK is now available as the Figranium Swift package. It supports macOS 13, iOS 16, tvOS 16, watchOS 9, and server-side Swift, with no external dependencies.
  • async/await client with typed models for tasks, actions, and executions.
  • Live execution and selector events streamed as AsyncThrowingStream.
  • Coverage for tasks, executions, schedules, captures, Cabinets, credentials, and headful browser sessions.
  • App Intents to run tasks, stop executions, and check status from Shortcuts and Siri.
  • A Foundation Models tool that lets Apple Intelligence run tasks you approve, on iOS 26, macOS 26, and visionOS 26 or newer.
See the Swift SDK overview and Installation.
Earlier this week

Features

Python SDK

The official Python SDK is now available on PyPI as figranium-sdk. It requires Python 3.9 or newer.
  • Sync (Figranium) and async (AsyncFigranium) clients with the same methods.
  • Typed request and response shapes that work with mypy and pyright.
  • Live execution and selector events streamed over Server-Sent Events.
  • Coverage for tasks, executions, schedules, captures, Cabinets, and headful browser sessions.
  • Typed action helpers for building task workflows, including navigation, extraction, control flow, CAPTCHA, and file upload actions.
See the Python SDK overview and Installation.
Earlier this week

Features

Remove a task schedule

The Schedule tab now includes a Remove Schedule button. After you confirm, Figranium clears the schedule from the task and keeps the task itself. The DELETE /api/schedules/:taskId endpoint now removes the schedule entirely instead of only disabling it. See Task scheduling.

Updates

  • MCP server v1.3.3: the MCP server now rejects workflows that start with a Timed Wait or Navigate To action. Use the task-level wait and url settings instead. It also rejects workflows that end with a Get Content action. Use an extraction script for final output.

Fixes

  • Light-theme colors: text selection follows the active theme again, and the Add Proxy button and active extraction-mode switch use the theme accent color.
  • Long-running tasks over MCP: MCP server v1.3.2 no longer times out after 30 seconds when you run a task. It now waits for the real execution result. Your MCP client can still apply its own timeout.
Earlier this week

Features

Responsive canvas dot magnification

The editor and read-only embeds now animate a compact 48px magnification field around the cursor: nearby canvas dots expand smoothly, settle back to normal when the cursor moves away, and fill an active marquee-selection rectangle. The effect respects the OS reduced-motion preference. Its interaction is inspired by the dot-magnification effect in iOS 27 Photographic Styles.

Improved sticky notes

Sticky notes now render Markdown, use an auto-growing editor, expose an edit-only toolbar, pick theme-aware default colors, and expose clearer copy and delete controls.

Fixes

  • Sticky-note recovery — sticky notes are preserved when older clients or integrations save a Task without the stickyNotes field. Affected notes are recovered from the newest version snapshot that contains them, and notes are retained when restoring pre-note versions.
  • Legacy escaped-newline and run-on numbered-list note content is normalized during recovery and editing.
This week

Fixes

Browser viewer reliability

  • Embedded headful browser sessions now work behind reverse proxies. The noVNC viewer authenticates its WebSocket connection with a short-lived, single-use ticket bound to the signed-in session, so selector inspection keeps working even when a proxy rewrites the internal Host header.
  • Bounded noVNC credential and connection attempts so an unavailable browser viewer no longer leaves the application indefinitely on “Connecting…”.

Live updates and task reliability

  • Task edits and deletions now synchronize live across open editors, with stale-save rejection so an older autosave cannot overwrite a newer remote change.
  • Execution updates propagate live across run-history and execution-detail views, including completed manual and scheduled executions.
  • Corrected Task create/update behavior after live synchronization, and preserved imported Task data when a remotely deleted Task is handled locally.

Updates

  • Theme-aware surfaces — the browser-session modal, overlay, and noVNC loading screen now follow the selected Light or Solarized Light appearance instead of forcing dark surfaces. Editor controls, action palettes, floating/context menus, insert controls, text selection, and hover states pick up matching theme-aware styling.
  • Added an insertion control before the first workflow block and refined the editor toolbar and project visuals.
  • Refreshed project screenshots and banner artwork; the Fiptcha lockfile workflow no longer runs on release tags.
Last week

Features

Auto appearance preference

A new persisted Auto appearance follows the device light/dark setting and updates when that preference changes. Auto is now the default for both new and existing installations. Appearance settings show Auto as a compact image-free option alongside the manual theme cards, and the former first-run theme chooser has been removed.

Updates

  • Reworked light and Solarized surfaces — editor, dialogs, menus, dashboard, drawers, and controls use restrained elevation, semantic borders, readable labels and connectors, blue primary actions in the standard Light theme, and gentle modal backdrops instead of dark-theme shadows and black scrims.
  • Theme-aware sticky notes — including readable Markdown and controls. Default notes use a translucent brand-blue treatment with dark text in light themes, and the visual resize grip has been removed while preserving saved note dimensions.
  • Updated Fiptcha to v0.1.6 for the latest CAPTCHA-solving improvements; the npm lockfile is synchronized.
  • Refreshed the README to reflect the current product.
Last week

Fixes

Browser and editor reliability

  • The headful selector picker is now responsive: only the active page is synchronized, with a bounded timeout, the latest requested inspect state is preserved across delayed evaluations and navigation, and Stop Inspect stays available while synchronization is pending.
  • Sticky-note dragging and resizing keep gesture updates local until pointer release, and stale overlapping autosave responses no longer replace newer task state.
  • Embedded task canvases are fully read-only while retaining viewport panning, and the captures modal closes when a rerun finishes.
  • The initial execution message was replaced with a neutral activity-waiting status.

Updates

  • Updated Fiptcha from v0.1.1 to v0.1.4 for grid-solver fixes and no-scroll CAPTCHA interactions, including per-tile local-model fallback when whole-grid detection finds no match.
  • Repaired the npm lockfile and changed V1 qualification dependency setup to use the repository’s supported install path.
  • Tightened the README introduction around deterministic visual browser automation and API endpoints; removed an obsolete generated verification video artifact.
Last week

Features

Fiptcha extracted as a standalone package

Figranium’s built-in CAPTCHA solver is now the standalone fiptcha package. The existing Agent actions, settings, companion commands, and automatic solving flow are preserved. Figranium is updated to Fiptcha v0.1.1, which correctly detects and clicks interactable reCAPTCHA v2 checkbox controls and improves iframe readiness handling for CAPTCHA providers.

Fixes

  • Headful browser sessions — authenticated tabs no longer reopen unexpectedly while cookie synchronization remains intact.

Updates

  • Tabler icons throughout — Material Symbols were replaced with Tabler icons across the interface, missing icon aliases were completed, global sizing and task controls were refined, and Cabinets adopted Tabler folder icons.
  • Bundled Questrial and Space Mono locally to avoid third-party font latency; refreshed the task-editor product capture and removed obsolete demo video assets and links.
  • Automatically managed control-flow markers are hidden from the visual editor catalog while remaining available through the API/MCP contract.

Configuration

  • PostgreSQL configuration is now environment-only — it moved out of Settings into environment variables, preserving both standard variables and DigitalOcean-friendly lowercase aliases (including SSL configuration).
  • Added the password-manager/injector roadmap item and removed outdated README/tagline material.
Earlier this month

Features

New browser action blocks

Agent mode gained check, uncheck, drag_and_drop, and reload actions, and Click blocks now support single, double, and right-click modes. Drag and drop uses independently selectable source and target selectors, including headful selector picking. The expanded action contract is documented alongside the existing native select action.

Opt-in Task page translation

Tasks can now be configured with a target language for automatic page translation, which is reapplied after browser navigation. Translation is off by default.

Updates

  • Read-only Embed canvas — the canonical read-only Embed canvas is aligned with the editor for layout, block rendering, panning, sticky notes, and context controls.
  • Refined the editor with centered Task titles, direct API and Schedule shortcuts, clearer action/UI icons, normal-case execution terminology, and improved read-only interaction controls.

Fixes

  • False anti-bot outcomes after a CAPTCHA is solved no longer occur; regression coverage added.

Updates

  • Updated proxy-provider branding from Swiftproxy to Thordata, refreshed the README’s Google Maps Lead Scraper screenshot, and documented scoped API-key work on the roadmap.
Earlier this month

Features

Per-Task page translation

A new opt-in per-Task Page Translation setting adds target-language selection. Agent and headful browser runs now load translate.js for enabled Tasks, translate the initial page, and reapply translation after navigation. Translation remains off by default; Scrape mode keeps its HTTP-only behavior.

Updates

  • On Execution defaults — new Tasks include the On Execution configuration panel by default, with a zero-second default wait.
  • Added a Task Variables shortcut in the editor header and made the editor, execution-detail, and browser-page titles contextual to the active Task or page.
  • Unsolicited headful popups no longer steal focus; editor action controls were refined; Cabinet-route sidebar highlighting was corrected.
  • Normalized app typography to normal casing for improved readability.

Updates

  • Cabinet metadata persistence — Cabinet metadata now persists across both JSON and PostgreSQL storage backends, with qualification coverage for Cabinet uploads and persistence.
  • Hardened Docker publishing against Playwright runtime-version drift.
  • Migrated the selected UI, user-journey, and star-prompt verification scripts to TypeScript and updated CI to run the migrated suite.
Updated the README’s product, roadmap, and security guidance; completed the translate.js roadmap item and documented the Task translation field in the agent action contract.
Earlier this month

Features

Cabinets: durable download queues and uploads

Figranium now ships installation-wide Cabinets as durable download queues, including a default Basic Cabinet, legacy-download migration, isolated item storage, upload status, Cabinet item downloads, ZIP creation, and safe archive extraction.
  • Cabinets workspace and API — create, rename, clear, change status, bulk delete, migrate/delete, download, ZIP, and unzip.
  • Per-Task download Cabinet — Tasks can select a Cabinet as the destination for intercepted browser downloads. Migrated legacy capture download links are preserved.
  • Upload actions — two new Agent actions: Upload selects the newest unuploaded Cabinet item and handles ordinary files, ZIPs, compatible folders, native file inputs, file choosers, and drop targets. Finalize Uploads marks all items attached during the execution.
The Cabinet Task field and upload action contract are documented in the agent action contract.

Updates

  • File icons — extension-aware monochrome file icons for Cabinet and execution downloads, plus a dedicated CSV glyph throughout action UI.
  • Direct URLs — Settings tabs and individual Cabinets have direct, reload-safe URLs, and invalid Cabinets fall back to the default Cabinet.
  • Added Option-number sidebar navigation on macOS, improved the sidebar add-button affordance, made loop variables unavailable outside a For Each scope, and refined Cabinet controls and proxy rotation settings.
  • Replaced Cabinet browser prompts with the app’s glass modal treatment, removed the theme introduction prompt, and updated the package description to describe the product directly.

Reliability

  • Added and hardened deterministic v1 qualification coverage for browser execution, control-flow blocks, persistence, scheduler behavior, Docker startup, PostgreSQL migration, headful operation, and concurrent execution.
  • Corrected false-positive qualification assertions and CI setup, isolated qualification API keys, and tightened Docker cleanup and health verification.

Security

  • Added rate limiting to Cabinet download, migrated-capture, Cabinet view, and SPA fallback handlers in response to CodeQL findings.
Last month

Features

Canvas loop redesign

while, repeat, and foreach loop actions are now atomic canvas blocks with rounded return-path connectors, replacing the previous loop layout with a rendering style consistent with if blocks. Shared action-block helpers identify block-start/loop action types, match a block’s start to its end marker, compute a block’s action range, and expand selected action ids to fully include any block they belong to.Cross-scope action dragging on the canvas is now constrained: an action or block can be dragged into a different branch/loop scope while staying within valid drop targets. Closed-loop connector paths were refined to route cleanly around the redesigned loop blocks.

Run through block

The action configuration modal now includes a Run through block tester that executes a single block in a temporary headless browser from the start of the Task through the selected block, without running extraction, recording, or persistent session state.
  • A redesigned block configuration workspace shows resolved inputs, expected output, live variable snapshots, execution logs, and a screenshot of the page after the tested block ran, alongside status (success, error, skipped, stopped, not reached) and duration.
  • In-flight block tests can be stopped, which cancels the underlying execution on the server.

Variable insertion by drag-and-drop

Variables can now be dropped into plain text/code inputs (CodeEditor) and rich text inputs (RichInput), inserting the variable token at the caret position under the cursor. Shared variable-insertion helpers and a reusable variable list/palette component are used by the new block configuration workspace.

Task version deletion

Individual saved Task versions can now be permanently deleted, alongside the existing version preview, rollback, and clear-all actions. The versions panel shows explicit loading state while a version is being created or deleted and no longer allows overlapping requests.

Fixes

  • Block test no longer aborts itself — auto-saving the Task right before the test request was re-creating the test-stop callback, and an effect that treated any change to that callback as a reason to run its cleanup was canceling the test that had just started. Cleanup now only fires on the modal actually unmounting.

Updates

  • Configuration modal split — the action configuration modal is now a shared ConfigModalShell plus dedicated BlockConfigWorkspace and ExecutionConfigModal surfaces, aligning its layout with the new block-testing and variable-insertion functionality.
Last month

Features

New execution outcomes

Agent and Scrape executions now report automatic stopped, crashed, and anti_bot outcomes alongside success and error. Cancellation requests, unhandled runtime failures, and unresolved bot challenges retain distinct final states across the runtime, scheduler, API summaries, run history, execution details, and editor results.Shared outcome classification and normalization use deterministic precedence for overlapping terminal conditions with backwards-compatible handling of historical execution records. The execution-outcome contract is part of the documented agent action contract.

Redesigned Dashboard and application shell

The Dashboard, Executions, Execution Detail, Captures, Settings, loading, and not-found pages are redesigned around the editor canvas’s compact controls, layered surfaces, thin borders, and node-like panels while preserving the existing global icon sidebar and theme system.
  • Dashboard overview — real Task and execution metrics, searchable compact Task rows, sorting by recent activity, name, mode, or action count, and schedule, target, mode, and last-opened metadata.
  • Task actions — inline edit/delete controls are replaced with single-click opening and a canvas-styled overflow menu offering Open, Copy Link, Copy API URL, and Delete.
  • Run History — denser, filterable execution list with summary metrics, clearer outcome hierarchy, and a structured execution-detail header and metadata strip (virtualization and output rendering unchanged).
  • Captures — compact media library with direct open, download, copy, and delete actions, plus redesigned loading and empty states.
  • Settings — responsive secondary navigator for API Keys, AI Models, User Agent, Proxies, Appearance, and About. The standalone Storage section was removed while the capture-management APIs and standalone Captures page were retained.

Updates

  • Reusable select and combobox — native browser selects and datalists are replaced throughout the application with theme-aware custom controls supporting keyboard navigation, portals, viewport-aware positioning, optional icons, and mixed option content.
  • Dropdown labels stay in normal casing and gain monochrome provider icons for reCAPTCHA, hCaptcha, and Cloudflare CAPTCHA choices while retaining the generic Auto icon.
  • Shared extraction-field option definitions between the canvas and Task Settings editors keep both extraction surfaces synchronized.

Fixes

  • Unauthenticated application startup no longer attempts to fetch Tasks before a session is available.
  • Removed the dark background highlight behind block names in the editor canvas.
Last month

Fixes

  • Extraction editor state — hand-written extraction JavaScript is preserved when switching between the Visual and JavaScript editors. Mode changes now update only the selected editor mode, while actual visual field edits still regenerate the visual script.
  • Missing or unknown execution sources are changed to api, so API-triggered runs display and filter correctly in both the execution list and detail view, including historical records.

Updates

  • The On Execution block automatically expands whenever a new task is created (including tasks initialized by navigating directly to /tasks/new); existing tasks still open with the block collapsed.
  • Dashboard task favicons display in their original full color instead of applying a grayscale filter.
  • Replaced the animated README demo GIF with a static product screenshot while retaining links to the video walkthroughs.

Deployment

  • Added docker-compose.deploy.yml as a production-oriented Compose configuration using the published GHCR image, persistent data and capture mounts, exposed application and noVNC ports, and an automatic restart policy.

Cleanup

  • Removed the deprecated OHMYCAPTCHA_URL and OHMYCAPTCHA_CLIENT_KEY aliases and their documentation; remote CAPTCHA solving now uses CAPTCHA_SOLVER_URL and CAPTCHA_SOLVER_KEY. The obsolete ignored OhMyCAPTCHA checkout and ignore rule were also removed.
  • Added a roadmap item for per-automation downloads folders and an upload block that selects files from an automation’s file workspace.
Last month

Updates

  • Full-color task favicons on the dashboard — task cards now display the target site’s favicon in full color at all times. Previously, favicons rendered in grayscale and only gained color on hover. This makes it easier to spot a task by its site branding when scanning the dashboard grid. See UI Tour — Dashboard.
Last month

Features

wait_captcha action block

A new Wait for Captcha block pauses a task until a CAPTCHA checkbox or equivalent provider control is initialized, visible, enabled, pointer-receivable, and stable — without clicking or solving it. Use it to hold the flow until a widget has rendered before your own solving logic, or to confirm a challenge appeared before branching. It supports optional provider filtering (captchaType), container scoping (selector), a configurable timeout (default 120000 ms), and a result variable holding { ready, challenge, duration, siteKey? }.
See Action Blocks — Wait for Captcha and CAPTCHA Solving.

Cloudflare managed challenge support via remote solvers

solve_captcha now handles Cloudflare managed challenges (the full-page “Checking your browser” Challenge interstitial), not just standalone Turnstile widgets. Figranium intercepts the challenge before navigation completes, capturing the one-time site key, action, cData, chlPageData, callback, and user agent that remote solvers need, and formats the payload for both 2Captcha-style and AntiCaptcha-style endpoint dialects. Managed challenges require a configured CAPTCHA_SOLVER_URL; the local solver reports them as unsupported. See CAPTCHA Solving — Cloudflare managed challenges.

Updates

  • Auto-solve covers the initial navigation — the task-level Auto-Solve Captchas setting now runs its detection pass after the initial task navigation too, not just after later navigate, click, and type actions. Each pass is bounded by the new CAPTCHA_AUTO_DETECT_TIMEOUT_MS window (default 5000 ms) so challenge-free pages aren’t stalled.
  • Readiness-gated solving — solve_captcha now waits until the challenge control is actually interactable before attempting a solve, instead of failing on widgets that are still loading.
  • Explicit CAPTCHA diagnostics — failed CAPTCHA blocks now log sanitized [CAPTCHA ERROR] lines with per-route diagnostics and report an errored block status, while keeping the existing On Error or log-and-continue behavior.

Fixes

  • Cloudflare Challenge pages whose site keys appear only inside challenge-frame URL paths are now detected, while standalone Turnstile support is preserved.
  • reCAPTCHA iframes on www.google.com are now recognized, so the solver proceeds from the checkbox into 3×3/4×4 image grids instead of silently skipping the challenge.
  • Local reCAPTCHA/hCaptcha solving hardened with interactable-control checks, delayed grid detection, replacement-tile handling, and verified token completion.
Last month

Features

Solve CAPTCHAs from Agent mode

Agent mode can now solve reCAPTCHA v2, reCAPTCHA v3, hCaptcha, and Cloudflare Turnstile challenges without leaving the task flow. Solves are routed through an optional YesCaptcha/AntiCaptcha-compatible remote endpoint first, then fall back to a built-in active-browser local model (OWL-ViT on 2–7.99 GiB hosts, Florence-2 at 8 GiB+). Local weights are fetched on first use into persistent data/captcha-model/; nothing is bundled into the image.There are two ways to use it:
  • Explicit solve_captcha action block: drop it into a task at the step where you expect a challenge. Optionally pin a captchaType, scope with a selector, and capture { success, challenge, duration, provider, model?, device?, attempts } in a variable.
  • Task-level Auto-Solve Captchas setting: toggle it on in the Behavior tab of Task Settings to run the same detection pass automatically after every navigate, click, and type. Off by default; silently no-ops when no challenge is present.
Configure a remote endpoint with CAPTCHA_SOLVER_URL and CAPTCHA_SOLVER_KEY. Local solving is on by default; set SKIP_LOCAL_CAPTCHA_MODEL=true to disable. Tune the tier with CAPTCHA_MODEL_TIER (auto, owlvit, florence2) and the deadline split between routes with CAPTCHA_REMOTE_TIMEOUT_MS and CAPTCHA_LOCAL_FALLBACK_MIN_MS. On Apple Silicon, an optional native companion (npm run captcha:companion:start:docker) offloads inference to CoreML/MLX.The default solve_captcha timeout is 120000 ms since real solves, especially reCAPTCHA v2 image challenges, commonly take over a minute.See CAPTCHA Solving, Action Blocks — Solve Captcha, and Configuration — CAPTCHA Solving.

Updates

  • Captures page redesigned as a two-column grid: The Captures screen now lays out capture cards in a simple two-column grid (a single column on narrow screens) instead of a virtualized scrolling list. See UI Tour — Captures.
Last month

Features

Do Nothing action block

A new do_nothing action block is available in the block picker. Drop it onto the canvas as a placeholder while you’re drafting a task, or use it as the body of an If or On Error branch when you want the branch to fall through without side effects.
  • The block takes no configuration. It logs Do nothing and completes successfully.
  • noop and pass are accepted as aliases and behave identically.
See Action Blocks — Do Nothing.
Last month

Features

API trigger endpoint now accepts bodyless requests

POST /api/tasks/:id/api no longer requires a JSON body or a Content-Type: application/json header. Requests without a parsed body are treated as {} and the task runs with its default variables. Tools that can’t set request headers on outbound calls (for example, Clay’s HTTP action) can now trigger a task with a bare POST to the endpoint URL.To pass variables, webhookUrl, statelessExecution, or sessionId, keep sending Content-Type: application/json with a JSON body — that path is unchanged.

Full endpoint URL and method in the API trigger panel

The task editor’s Trigger via API panel now shows the complete origin-aware endpoint URL (for example, https://your-figranium.example.com/api/tasks/task_1/api) with a POST method badge next to it. The copy button copies the same full URL, so you can paste it straight into external tools without prefixing your instance origin by hand.See REST API Reference — POST /api/tasks/:id/api.
Last month

Features

Opt-in CloakBrowser browser engine

Figranium now ships two interchangeable browser engines behind the same Playwright API, and you can switch between them with a single environment variable. Agent, Headful, and CLI-launched tasks all use whichever engine is active — no task edits required.
  • Default (USE_CLOAK_ENGINE unset or false): Playwright Chromium patched at the JS level with playwright-extra and puppeteer-extra-plugin-stealth. Same behavior as previous releases.
  • Opt-in (USE_CLOAK_ENGINE=true): the CloakBrowser stealth-patched Chromium binary. Evasions are applied at the binary level rather than injected at runtime, which is harder for modern bot detectors to fingerprint. Use this when the default stack is being detected on a target site — typically CAPTCHA walls that trigger on Playwright/Chromium runtime tells.
  • License key: set CLOAKBROWSER_LICENSE_KEY to unlock the latest stealth binary. Without a key, CloakBrowser falls back to the free legacy binary. You can also run npx cloakbrowser login to write the key to ~/.cloakbrowser/license.key, which cloakbrowser reads natively.
  • Lean installs: the CloakBrowser binary is only fetched during postinstall when the flag is enabled, so the default install stays the same size as before.
.env
See Stealth & Anti-Detection — Browser Engine and Configuration for the full switch behavior and env-var reference.Agent tasks now click through common cookie-consent banners for you before your first action block runs. Figranium injects the community-maintained idcac-playwright ruleset (a port of the “I don’t care about cookies” extension) into every page in the Agent browser context on domcontentloaded.
  • Covers hundreds of providers (OneTrust, Cookiebot, TrustArc, Quantcast, and more). The script always clicks reject or close — never accept.
  • Always on in Agent mode. Headful mode is unchanged (it’s for human interaction), and Scrape mode doesn’t render banners because it no longer launches a browser.
  • If no matching banner is present, the script silently no-ops so your task runs as usual. If a specific site’s dialog isn’t covered, you can still author an explicit Click block.
See Stealth & Anti-Detection — Cookie-Consent Auto-Dismissal for details.

Changes

Scrape mode is now browserless (no screenshots or video)

Scrape mode has been rewritten as a lightweight HTTP fetch. It now issues the request through got-scraping (with the same proxy pool and user-agent rotation as before) and parses the response with Cheerio, instead of spinning up a Playwright/stealth-Chromium browser for each run.
  • Faster and cheaper: No browser process means dramatically lower CPU, memory, and cold-start cost per scrape.
  • Preserved: Selector extraction, HTML cleanup, link extraction, proxy and user-agent rotation, the headful → scrape cookie handoff, and the sandboxed extraction-worker script pipeline all still work exactly as before.
  • Removed: No screenshots and no video recordings in Scrape mode. There is no page to photograph. The Results panel’s Screenshot pane now shows “Scrape mode does not support screenshots” instead of the misleading “Waiting for Frame…” placeholder. If you need visual evidence of the page, run the task in Agent mode.
See Captures & Storage and Architecture for the updated behavior.
Last month

Features

Visual field-mapping mode for extraction scripts

The Extraction Script editor (both the canvas block and the Extraction tab in Task Settings) now opens in a new Visual mode by default. You describe the data you want as a list of named fields with a selector, an attribute type (Text, HTML, Input Value, or Attribute), and an optional Multiple (list) toggle. Figranium generates the underlying JavaScript for you and keeps it in sync as you edit — no raw code required for typical scraping tasks.
  • The mode toggle at the top of the editor flips between Visual and JavaScript. The selected mode now has a solid fill so it’s obvious which one is active.
  • Every field has a target icon that hands off to the Headful Browser inspector. Click an element on the page and the selector, plus a row of alternative candidates, get written back into the field.
  • Playwright-only :has-text(...) selector candidates are filtered out of the pick list for extraction fields only. Extraction scripts run through native document.querySelector, which does not understand that pseudo-selector, so surfacing it would have produced selectors that returned null at extraction time. Action blocks (Click, Type, etc.) still receive the full candidate list because Playwright runs those.
  • Switching to JavaScript mode surfaces the auto-generated script in the code editor, still fully editable. Existing hand-written extraction scripts open in JavaScript mode automatically so your code is never hidden behind an empty field list.
  • The canvas Extraction Script modal no longer closes when you click the backdrop, so a stray click on the dimmed area outside the modal will not throw away in-progress edits. Use the Done button or the close icon in the header to save and dismiss.
See Extraction Scripts — Visual field mapping for the full field reference and an end-to-end example.
Earlier update

Updates

Agent Mode description clarified in Task Settings

The mode picker in the Task Settings cabinet previously described Agent Mode as “Autonomous decision making,” which suggested the runner would decide steps on its own at execution time. That was misleading: Agent Mode runs a fixed sequence of action blocks that you author, and any branching comes from explicit control-flow blocks (If, While, Loop, etc.) on the canvas.
  • The label under Agent Mode now reads “Custom action sequence with logic.”
  • No behavior change. If you were choosing Scraper Mode because you didn’t want the runner making its own decisions, you can safely use Agent Mode — the same author-defined blocks execute in the same order on every run.
  • If you want an actual AI-driven, decision-making runner, that lives in MCP Integration, not in Agent Mode.
Earlier update

Updates

headless flag and automatic fallback for POST /api/browser/open

The programmatic browser launch endpoint now accepts a headless boolean and recovers automatically when no display server is available.
  • Pass "headless": true in the request body to launch Chromium without a display. This is the right choice when you run Figranium directly on a Mac (outside Docker) or on a headless CI runner. The HEADLESS environment variable is also honored.
  • If you don’t set headless and the initial headful launch fails because there is no display, Figranium retries once in headless mode and returns the running session. External orchestrators no longer have to detect HEADFUL_DISPLAY_UNAVAILABLE and reissue the call themselves.
  • The display-unavailable detector now also matches no display server, X11 connection failed, cannot open display, and unexpected target closed errors during launch, so the fallback triggers on Mac hosts where the underlying error text differs from Linux.
See REST API — POST /api/browser/open for the full request and error schema.

Bug fixes

  • Headful VNC viewer no longer gets stuck on “Reconnecting…” — start-vnc.sh was embedding literal double-quote characters into the x11vnc -passwd argument because of unquoted shell word-splitting, so the password x11vnc actually enforced never matched the one served to the noVNC client. Every connection attempt failed authentication and dropped immediately, which showed up in the UI as an endless reconnect loop. The password is now passed through a bash array as a single unmodified argument. If you were affected, pull the latest image and reopen the headful session — no config change is required.
  • Proxy credentials pasted as a full URL are now split out on add — Pasting http://user:pass@host:port into Settings > Proxies > Add Proxy > Server previously stored the whole URL (credentials included) as the server value, which surfaced as a duplicate-looking entry in the list and failed upstream authentication in rotation pools. normalizeProxy now extracts embedded credentials into username and password on both the add and bulk-import paths. Existing broken entries self-heal on next read — no manual cleanup needed. See Proxy Rotation — Adding a proxy.
  • Backdrop blur restored on modals and overlay panels in Dark and Solarized Dark themes — A dark-theme CSS override was force-replacing translucent bg-black/NN backgrounds with a fully opaque color, defeating backdrop-blur on the Task Settings panel, the confirm modal, and other overlays. The override has been removed, and the confirm modal now uses a translucent theme-aware background instead of a hardcoded opaque one.
  • Browser open and inspector highlight on Mac — Launching the managed browser session from POST /api/browser/open and resolving a targetHint through POST /api/inspector/highlight now work when Figranium runs on macOS. Chromium is launched without the --disable-gpu, --window-position=0,0, and --start-maximized flags on Darwin, which were causing the process to exit before the first page was ready. The CDP Browser.setWindowBounds maximize call is also skipped on Darwin. Selector generation, XPath resolution, and the top-match highlight overlay for /api/inspector/highlight now run in a single in-page evaluation, so they don’t lose the element handle to a mid-flight page navigation.
  • GitHub star prompt no longer appears on first run — The in-app prompt asking you to star the Figranium repo is now gated on both 3+ successful task runs and 3 days since your first run (tracked locally in the browser). It also uses a quick slide-in animation instead of the previous fade so it’s easier to notice when it does appear. Dismissing or clicking through still permanently silences it.
Earlier update

Updates

Single self-theming brand icon

The Figranium mark at public/figranium_icon.svg is now a single SVG that adapts to the viewer’s color scheme, instead of shipping as separate dark and light variants.
  • The mark fills black by default and switches to white inside @media (prefers-color-scheme: dark), so it stays legible on both light and dark surfaces.
  • Use this file when you can only supply one logo URL — for example, third-party integrations, README embeds, or partner directories that accept a single <img src>.
  • No configuration change is required. Existing embeds keep working; you can drop the separate dark/light variants from your integration if you were maintaining both.
If your embedding surface forces a fixed background and ignores the OS color scheme, keep pointing at whichever variant matches that background.
Earlier update

Features

Multi-theme support

Figranium now ships with four selectable UI themes: Dark (default), Light, Solarized Light, and Solarized Dark.
  • Switch themes from Settings → System → Theme. Each option shows a preview image plus a surface and accent color swatch.
  • The choice is stored in the browser’s local storage (figranium.theme), so it persists across reloads on the same device.
  • The first time you open Figranium after upgrading, a one-time picker prompts you to choose a theme. Dismissing it also persists locally and it will not appear again.
  • Themes are implemented as CSS custom properties (--app-bg, --app-surface, --app-accent, and the full syntax-highlight palette), so the whole UI — including code blocks — retunes for readability under each background.
See UI Tour — System settings for the switcher location.

Authenticated programmatic browser & inspector API

The programmatic browser endpoints introduced in the previous release now require authentication and are safe to expose to external orchestrators (MCP servers, custom agents, CLIs).
  • POST /api/browser/open launches or reattaches a managed headful session and returns { sessionId, status, wsEndpoint }.
  • POST /api/inspector/highlight activates the inspect overlay on the active session and, given a targetHint, returns up to five candidate elements with CSS selectors, XPath, confidence scores, and an optional base64 JPEG snapshot of the viewport.
  • PATCH /api/tasks/:id performs a partial update on a task. Figranium snapshots the current task into the version history before applying the change.
  • DELETE /api/tasks/:id now also removes any in-process schedule registered for the task, so a scheduled run cannot fire after deletion.
Every endpoint accepts either a signed-in dashboard session or an API key (x-api-key, Authorization: Bearer, or an apiKey body field). External callers should use the API-key path.
See REST API — Browser and REST API — Inspector for full request and error schemas.

Security

VNC and websockify path hardening

  • The noVNC/websockify proxy path now requires authentication before it will accept an upgrade or serve public/novnc.html. Unauthenticated attempts are dropped.
  • websockify binds to the IPv4 loopback (127.0.0.1) explicitly, closing a mismatch where Docker on macOS could bind unpredictably across IPv4/IPv6 loopback and leave the VNC stream unreachable or unexpectedly reachable.
  • sessionId and taskId are strictly validated before they are used to look up files on disk, closing a path-traversal edge case.
  • Raw cron ranges are now validated for correct ordering as well as bounds, so a malformed field cannot slip past the scheduler.
If you built a custom client that reached /websockify directly, update it to authenticate with a session cookie or an API key. See Headful browser — Access control and Security — Headful / VNC access control.

Bug fixes

  • Captures now surface reliably — Runs no longer produce screenshots or recordings that fail to appear in the UI. The capture read path in server.js and src/server/routes/data.js now matches the actual write path, and captures are also served from the alternate public/captures location used inside Docker.
  • Captures survive container restarts — Runtime capture artifacts persist to a host volume instead of being lost when the container is recreated.
  • Persistent browser session ID — Session IDs are stored across reconnects instead of being regenerated on every new session, so external tooling that pins to a sessionId stays valid.
  • Mac/Docker WebSocket disconnects — Loopback WebSocket connections used by the headful viewer no longer drop on Mac hosts, and the HeadfulModal no longer flashes its loading state during a normal reconnect.
  • Apple Silicon headful browser “Connecting… Disconnected” loop — The GHCR publish workflow now builds and pushes a true multi-architecture image (linux/amd64 and linux/arm64). Apple Silicon Macs pull the native ARM64 image instead of running the AMD64 image under Docker Desktop’s QEMU emulation, where Xvfb and x11vnc were prone to crashing seconds after start. That crash also silently broke the selector-picker SSE stream, which shares the same headful browser session.
  • Headful viewer auto-reconnect — Xvfb, x11vnc, and websockify each now run inside restart loops (with per-process logs under data/xvfb.log, data/x11vnc.log, and data/novnc.log), and the noVNC page auto-reconnects with backoff on RFB disconnect. A quick post-connect drop is now surfaced as “Browser session crashed, retrying…” instead of a plain “Reconnecting…” so a genuine crash is visually distinguishable from a normal reconnect.
  • Theme contrast fixes — Dot-grid canvas background, theme-accent buttons, and previously hardcoded blue accent text (API keys, Add API Key button) are readable across all four themes; syntax-highlight colors were retuned to meet WCAG AA contrast on every theme’s actual code background.

Updates

Exported task filename

Exported task bundles are now named figranium-tasks-<date>.json (previously doppelganger-tasks-...).

Font change

The UI now uses Space Mono in place of JetBrains Mono. Custom stylesheets that referenced the old font family should be updated.

Under the hood: CAPTCHA detection scaffolding

Figranium 0.14.0 lands the foundation for a future human-handoff CAPTCHA workflow. This release includes only the internal engine layer — a DOM/shadow-DOM/iframe observer that classifies interactive elements (slider, audio, grid, rotational, distorted-text, widget-frame, form), a 2 GB memory guardrail (os.totalmem() plus cgroup v1/v2 limits), and typed handoff interfaces (onCaptchaDetected, pauseForHuman, submitSolution) that pipe an externally supplied solution into the existing human-like mouse trajectory generator.There is no automated solver and no user-facing API for this yet — the module ships as internal scaffolding only. Tasks continue to pause for manual intervention through the headful browser as they do today.
Earlier update

Features

Model Context Protocol (MCP) server

Figranium now ships an official MCP server so LLM clients like Claude Desktop, Cursor, and Manus AI can discover, run, inspect, and schedule Figranium tasks directly.
  • Prebuilt image: pull ghcr.io/figranium/figranium-mcp:latest — no Node.js install or local clone required.
  • STDIO transport: works with any MCP-compatible client over the standard STDIO transport.
  • Point at your instance: configure FIGRANIUM_BASE_URL and FIGRANIUM_API_KEY in the client’s MCP server config. Use http://host.docker.internal:11345 when Figranium runs on the same host.
  • Registry namespace: clients that support automatic registry resolution can install it as io.github.figranium/figranium-mcp.
See MCP Integration for client-by-client setup, the available tools, and local development instructions.
Earlier update

Features

Named session snapshots (sessionId)

Tasks and API-triggered runs now accept a sessionId field that persists browser cookies and local storage to a dedicated snapshot file per name.
  • Pass sessionId: "acct-alice" on a run and Figranium loads data/sessions/acct-alice.json as the browser’s initial storage state. After the run, the current state is written back to the same file.
  • Different sessionId values give you fully isolated logged-in identities on the same target — one per customer, tenant, or account, without touching the shared profile directories.
  • sessionId is sanitized to [a-zA-Z0-9_-]; other characters are stripped for path safety.
  • Combining sessionId with statelessExecution: true keeps the run stateless — the snapshot is not written.
See Named Session Snapshots for the full walkthrough and POST /api/tasks/:id/api for the API field.

Updates

Async and top-level return in Run JavaScript

The Run JavaScript action block now wraps your code in an async function, so top-level await and top-level return work directly. Existing scripts that used plain expressions or return from eval continue to work — the block falls back to the previous behavior if the async wrapper cannot compile the code.See JavaScript Execution for examples.
Earlier update

Security

Hardened VNC and websockify access

Unauthenticated access to the headful browser’s VNC stack is now closed. This affects anyone who was reaching the VNC or noVNC ports directly (for example, from a custom client or an exposed Docker port).
  • Localhost-only binding: both x11vnc (port 5900) and websockify/noVNC (NOVNC_PORT, default 54311) now listen on 127.0.0.1 only. Publishing these ports on the Docker host no longer exposes them.
  • Password-protected VNC: x11vnc requires a random password generated on first start and stored at data/vnc_password.txt. The embedded viewer fetches it automatically from the new authenticated endpoint GET /api/headful/vnc-password.
  • Authenticated /websockify upgrades: every WebSocket upgrade to /websockify on the main Figranium port must pass the IP allowlist, an Origin/Host match (CSWSH protection), and present either a session cookie or an API key. Unauthenticated attempts are dropped and logged.
What this means for you: if you use the headful browser through the Figranium UI, nothing changes — the embedded viewer authenticates automatically. If you built a custom VNC client that connected directly to port 54311 or 5900, update it to proxy through wss://<host>:11345/websockify with an API key (?apiKey=... or x-api-key header). Retrieve the VNC password from GET /api/headful/vnc-password.See Headful browser — Access control and Security — Headful / VNC access control for the full details.
Earlier update

Updates

Expanded PostgreSQL storage

PostgreSQL is now a first-class backend for nearly all Figranium configuration, not just tasks and logs.
  • More data in Postgres: proxy configuration, saved credentials, AI model selections, and Ollama API keys are now persisted in the database when DB_TYPE=postgres.
  • SSL support: a new DB_POSTGRESDB_SSL=true environment variable enables encrypted connections to managed Postgres providers (RDS, Cloud SQL, Supabase, Neon, etc.).
  • Longer API keys: API key columns are now TEXT instead of VARCHAR(255), and existing tables are migrated automatically on startup.
  • Graceful fallback: if the database is unreachable at startup, Figranium falls back to file-based storage.
See PostgreSQL Support for the full configuration reference.

Expanded SSRF protection

The default SSRF blocklist now covers a much broader set of internal and reserved network addresses, hardening Figranium against requests that target internal infrastructure.
  • More IPv4 ranges blocked by default: in addition to RFC 1918 private ranges and loopback, Figranium now blocks IETF protocol assignments (192.0.0.0/24), TEST-NET ranges, benchmarking (198.18.0.0/15), shared CGN space (100.64.0.0/10), multicast, and other reserved space.
  • Full IPv6 coverage: loopback (::1/128), unique local (fc00::/7), link-local (fe80::/10), unspecified, and multicast ranges are blocked.
  • Hostname blocking: localhost, *.localhost, and host.docker.internal are blocked unless ALLOW_PRIVATE_NETWORKS=true.
  • Proxy server validation: proxy URLs added through Settings or the API are validated against the same blocklist. Invalid entries are rejected with INVALID_URL, and bulk imports fail atomically if any entry is unsafe.
  • Ollama URL validation: Ollama base URLs are validated both at save time and again at request time, with every redirect hop re-checked and sensitive headers stripped on cross-origin redirects.
  • Output provider credentials: baseUrl values (e.g. Baserow) are validated when credentials are saved, rejecting unsafe URLs with INVALID_BASE_URL.
  • Redirect protection: outbound webhook and output provider requests now validate every hop in an HTTP 3xx chain (up to 5 redirects).
What this means for you: if you previously pointed Figranium at a service on localhost, host.docker.internal, or any private network, you’ll need to set ALLOW_PRIVATE_NETWORKS=true for local development. Production deployments are protected by default with no configuration required.See Security for the full list of blocked ranges and configuration details.

Gemini API key transport

Gemini API keys are now sent via the x-goog-api-key HTTP header instead of the ?key= query parameter, preventing keys from leaking through server access logs, reverse-proxy logs, or Referer headers. No configuration is required.If you previously relied on the ?key= form for log inspection or proxy filtering, update your tooling accordingly.