Skip to main content
Improvements

0.30.6

Changed

  • Support localhost interception configuration via an MDM provider.
Improvements

0.30.5

Changed

  • By default, transparent mode no longer intercepts loopback traffic. Enable transparent_proxy.intercept_localhost as specified in the managed preferences table to intercept loopback traffic.
New FeaturesImprovementsBug Fixes

0.30.4

Changed

  • Allow using CEL string, list, and set extension functions in network rules.

0.30.3

New

  • Surface input.session.id and input.request.id where applicable as policy evaluation inputs.
  • Surface session ID and request IDs in the default formal block message across technologies

Fixed

  • Allow Netskope and GlobalProtect to work alongside transparent mode on macOS.
Bug Fixes

0.30.2

Fixed

  • Allow OpenVPN Connect to work alongside transparent mode on macOS.
  • Fix AWS SDK uploads that use Content-Encoding: aws-chunked, which the AWS transparent proxy previously rejected.
Bug Fixes

0.30.1

Fixed

  • Recognize Claude Code launched from Claude Desktop as connection_process.is_agent.
ImprovementsBug Fixes

0.30.0

Changed

  • Require forward_to_connector to be true when passing Postgres traffic to the Connector. Note: review your network rules and update them accordingly.

Fixed

  • Fix NetworkManager connectivity checks while transparent mode is enabled on Linux.
New Features

0.29.0

New

  • Support Cursor Desktop & Cursor CLI
  • Support Devin Desktop (windsurf) and Devin CLI
New FeaturesBug Fixes

0.28.4

New

  • Support connection_process.is_agent in network rules
  • Support specifying resource hostnames in formal connect

Fixed

  • Surface tool names for MCP calls initiated by Claude Cowork
ImprovementsBug Fixes

0.28.3

Changed

  • Support intercepting HTTP2 in transparent mode

Fixed

  • Fix an issue in enabling transparent mode with automatic login in macOS
Improvements

0.28.2

Changed

  • Do not support transparent mode until CAs are trusted on macOS.
Improvements

0.28.1

Changed

  • Support dynamic groups for automated MDM deployments of automatic login.
New Features

0.28.0

Fixed

  • Network rules that forward websites to web resources (via a connector) now work.

0.27.0

New

  • Add support for connecting to Redshift resources, both directly and in transparent mode.
Bug Fixes

0.26.4

Fixed

  • Support intercepting MCP tool calls for Claude Prebuilt Integration Connectors in Cowork.
Bug Fixes

0.26.3

Fixed

  • Enable customers to switch Cloudflare WARP modes while transparent mode is enabled.
Bug Fixes

0.26.2

Fixed

  • Fix a bug in the Linux headless deb package where trusting the local CA certificate failed on older Ubuntu versions.
New FeaturesImprovements

0.26.0

New

  • Add support for writing to and reading from a cache from hooks.
  • Add encrypt / decrypt policy actions for HTTP-based protocols.

Changed

  • Add support for allowlisting CIDR ranges for hook outbound traffic.
Improvements

0.25.2

New

  • Support Formal Hooks on macOS.

0.25.1

Changed

  • Block pasting in TUI forms.

0.25.0

Changed

  • Move desktop tokens from “Login” keychain to “Local Items” keychain on macOS. Note: existing installations will have to re-authenticate.
  • Require allowlisting environment variables and upstream network destinations for hooks.
New FeaturesBug Fixes

0.24.0

New
  • Add multi-factor authentication on Windows using Windows Hello (fingerprint, face, or PIN).

0.23.1

Fixed
  • Fix a bug where the Linux headless binary was not statically linked.
New FeaturesBug Fixes

0.23.0

New
  • Initial release of Formal Hooks

0.22.3

Fixed
  • Use posix_spawn internally to work around bug introduced on macOS 26.4+.
Bug FixesNew Features

0.22.2

Fixed
  • Fix a bug with forward-to-connector network rules on Linux endpoints

0.22.1

New
  • Support setting checkForUpdates, hideSystrayIcon, transparentProxyEnable, transparentProxyEnforce, transparentProxyFail, transparentProxyAllowQuic as mcx preference settings.
ImprovementsBug Fixes

0.22.0

Changed
  • Bumped the minimum supported macOS version to 15.0.
  • No longer start the desktop app during the base package postinstall.
  • Replace custom MDM post-install scripts with managed preference settings. Note: MDM deployments that upgrade to this version should remove the custom post-install script.
Fixed
  • Fix transparent proxy toggle knob rendering.
Improvements

0.21.1

Changed
  • Rewrote the macOS menu bar: faster and more efficient.
  • Transparent proxy toggle now stays in sync and gives clearer feedback when toggled.
  • Transparent proxy toggle now requires being logged in with a working CA.
New Features

0.21.0

New
  • Support the Gemini API as an LLM technology.
  • Add support for using the detected resource (hostname and port match) in CEL expressions in network rules.
Bug Fixes

0.20.6

Fixed
  • Support Sequoia macOS versions.
  • Smooth the visual toggling of transparent mode.
New Features

0.20.5

New
  • Add the loaded_files field.
Bug Fixes

0.20.4

Fixed
  • Surface llm and input output tokens as numeric counts in logs.

0.20.3

New
  • Surface available_skills and loaded_skills in LLM logs.

0.20.2

Changed
  • Transparent proxy mode now requires login, avoiding unnecessary TLS interception when logged out
New Features

0.20.1

New
  • Improve experience of intercepting AI agent traffic in network rules

0.20.0

New
  • Add support for GCP APIs as a technology for the transparent proxy
New Features

0.19.1

Changed
  • Avoid CA trust dialog when device login managed preference is set.

0.19.0

New
  • Add support for AWS APIs as a technology for the transparent proxy
Improvements

0.18.2

Changed
  • Updates CA trust at login to not require any CLI commands
New Features

0.18.1

New
  • Allow CA trust prompt to be shown at login time after MDM installation
Improvements

0.18.0

New
  • Support automatic login and CA trust.
Improvements

0.17.1

Changed
  • Fall back to password authentication for MFA challenges when Touch ID is not available
New FeaturesImprovementsBug Fixes

0.17.0

New
  • Support autodetection of Postgres, MySQL, and MongoDB connections via the transparent proxy and in network rules
  • Support TLS interception for Postgres, MySQL, and MongoDB connections through formal connect/formal ls local proxy
Changed
  • Rename the MacOS bundle from Formal Desktop to Formal
  • Surface “Formal” in certificate trust settings dialog instead of “security” during installation
Fixed
  • Fix a bug where the CA trust dialog would not appear during MacOS package installation via MDM
  • Fix a bug where formal transparent-proxy status would report the extension not being installed when it actually was
New FeaturesBug Fixes

0.16.0

New
  • Add first-class support for granular logging and policy evaluation on LLM request bodies

0.15.4

Fixed
  • Fix an issue where MySQL connections could crash the agent when the client did not send connection attributes
Bug Fixes

0.15.3

Fixed
  • Fix a bug where network rules weren’t passing HTTP resources properly to connector listeners with smart routing enabled.
ImprovementsBug Fixes

0.15.2

Changed
  • Allow protocol detection on HTTP requests when the TLS client hello doesn’t specify an ALPN protocol
  • Improve performance of non-interactive formal ls
Fixed
  • Fix a bug where network rules were lost after disabling and re-enabling the transparent proxy
Bug FixesNew FeaturesImprovements

0.15.1

Fixed
  • Fix a bug where transparent connections to a resource would hang if there was a previous direct connection to the local listener for that resource

0.15.0

New
  • Initial release of headless Linux deb package
Changed
  • Automatically generate and trust transparent proxy CA certificate on Linux

0.14.3

Fixed
  • Fix a bug where Postgres connections from GSS-enabled clients could hang when using the local TCP port instead of the Unix socket.

0.14.2

Changed
  • Improve performance of forwarding transparently proxied HTTP traffic to the Connector
New Features

0.14.1

New
  • Support header rewrite actions for HTTP resources
New Features

0.14.0

New
  • Support scenario monitors (LLM-as-a-judge) as a policy evaluation input
ImprovementsNew Features

0.13.1

Changed
  • Improve MFA policy enforcement

0.13.0

New
  • Emit HTTP policy evaluation inputs alongside logs
  • Add support for MongoDB SCRAM-SHA-256 authentication
Changed
  • Improve policy evaluation latency
ImprovementsNew Features

0.12.2

Changed
  • Improve policy block messages for HTTP connections

0.12.1

Changed
  • Improve LLM protocol autodetection

0.12.0

New
  • Support protocol autodetection for LLM requests
  • Persist logs to disk so they survive network outages, capped at 1 GB
  • Support encrypting logs with asymmetric encryption keys
Changed
  • Improve network rule format for readability. See our “Guide: Desktop App Setup” for more information.
  • Simplify the codesigning configuration of our macOS Desktop App. See our “Guide: Desktop App Setup” for more information.
New FeaturesImprovements

0.11.0

New
  • Add an uninstall command to completely remove Formal from the machine
  • Add an input.source field to allow policies to differentiate desktop policy enforcement from connector policy enforcement
Changed
  • Improve performance of fetching updates from the control plane
  • Improve performance of formal ls
New FeaturesImprovements

0.10.1

NewChanged
  • Change macOS CA trust dialog back to the default Security dialog

0.10.0

New
  • Add device trust support for MySQL
  • Forward MySQL policy block messages to clients
New Features

0.9.21

New
  • Support Codex block messages
  • Support HTTP header rewrites for HTTP technology
Changed
  • Decrease bundle size by 50%
  • Rename transparent proxy to transparent mode
  • Rename ca install for Linux to ca trust for macOS-Linux parity
Improvements

0.9.20

Changes
  • Only check for updates if check_for_updates is set in config.toml.
Improvements

0.9.18

Changes
  • Show a custom Formal dialog when asking the user for permission to add CAs
New Features

0.9.17

New
  • By default, block QUIC traffic when the transparent proxy is enabled. Control this via the allow_quic configuration parameter.
  • Support Claude Chat for LLM sessions when allow_quic is false.
New Features

0.9.16

New
  • Support enabling the transparent proxy on desktop app startup via config.toml
New FeaturesImprovements

0.9.15

New
  • Support auto-classification of HTTP and MCP traffic
  • Support device trust for MongoDB
Changed
  • Install the network extension as part of the installer

0.9.14

New
  • Support desktop evaluation and logging of MCP traffic
  • Support network rules that don’t require resources
Fixed
  • Indicate to users that sudo is required for formal ca trust
  • Use total input tokens instead of input tokens
  • Correct CA installation out of sync race conditions
New Features

0.9.13

New
  • Support user identity in policy evaluation
  • Support transparent proxy for Linux
Improvements

0.9.12

New
  • Support LLM header rewrites
  • Remove the --only-agents, --transparent, and --local-tls flags
Improvements

0.9.10

New
  • Support session stage evaluation for the LLM technology
Improvements

0.9.9

New
  • Support policy enforcement for the MCP technology without a connector
  • New formal transparent-proxy install and formal transparent-proxy uninstall commands
Improvements

0.9.8

Changed
  • Add Formal CA to keychain via installer
New
  • Support policy enforcement for HTTP resources without a connector
  • Support connection process and user information in network rules
Improvements

0.9.7

Changed
  • Automatically add Formal CA to Keychain when enabling the transparent proxy
Improvements

0.9.6

Changed
  • Enable the transparent proxy via the system tray.
  • Support users in network rules
Improvements

0.9.5

Changed
  • Support custom block messages for Claude Code tool calls
Improvements

0.9.4

Changed
  • Support network rules in transparent proxy
Improvements

0.9.3

Changed
  • Support policy enforcement of LLM sessions without a Connector
Improvements

0.9.2

Changed
  • Improve performance of transparent mode
New Features

0.9.0

New
  • Add support for machine user auth via AWS SigV4
New FeaturesImprovements

0.8.4

Changed
  • Improve LLM session id saving for replay

0.8.3

New
  • Support connecting to MCP resources
  • Support log encryption for LLM technology
New FeaturesImprovements

0.8.2

New
  • Separate TLS settings for LLM technology
Changed
  • Emit session events for LLM technology sessions
New Features

0.8.1

New
  • Do not require a Connector to use the LLM technology
New FeaturesImprovements

0.8.0

New
  • Support connecting with --transparent mode
  • Support connecting with --only-agents mode
  • Support connecting with --local-tls mode
  • Pass process ancestor information
  • Support LLM technology
Changed
  • Reject CLI arguments for formal-agent
New Features

0.7.3

New
  • Managed Connector SSH host keys in an isolated host keys file.
Bug Fixes

0.7.2

Fixed
  • Fixed a bug where the resource alias was used for smart routing rather than the resource name.
New FeaturesBug Fixes

0.7.1

New
  • Added support for resource aliases
  • Added a --launch argument to formal connect to launch the appropriate CLI program after connecting (for example psql or ssh).
Fixed
  • Fixed a bug where the interactive formal ls parent process didn’t exit when launching a CLI program, obscuring connection errors and policy block messages.
Improvements

0.7.0

Changed
  • Improved formal ls performance by moving search filtering server-side
  • Reduced unnecessary API calls during credential renewal
Bug Fixes

0.6.0

Fixed
  • Fixed a bug where the desktop app CLI would attempt to launch the agent when run without a TTY.
    • Note: this introduces a small breaking change where running formal without a TTY will now exit with an error and show help text. Please run formal agent instead.

0.5.7

Fixed
  • Fix smart routing for MySQL resources
Bug Fixes

0.5.6

Fixed
  • Fix a bug where the desktop app would timeout when listing resources in non-interactive mode
New Features

0.5.5

New
  • Add support for JSONL and YAML output format to formal ls
Bug FixesImprovements

0.5.4

Fixed
  • Fix MySQL authentication with clients that send a null byte for empty passwords

0.5.3

Changed
  • Refresh MFA challenges every second
New FeaturesBug Fixes

0.5.2

New
  • Add support for the new MySQL proxy implementation
Fixed
  • Fix DynamoDB authentication
Improvements

0.5.1

Changed
  • Improve MFA user experience
New Features

0.5.0

New
  • Add support for MFA policy enforcement
Improvements

0.4.4

Changed
  • It is no longer required to specify a resource name with formal disconnect. By default, it disconnects all resources.
New FeaturesImprovementsBug Fixes

0.4.3

New
  • Added support for Windows.
  • Added support for wrapping AWS S3 commands to funnel traffic through the Connector.
Changed
  • Change SSH config configuration to be compatible with SCP via the Connector.
  • Change SSH config configuration to be use resource names as SSH host names.

0.4.2

Fixed
  • Fixed a build issue where the desktop app would not provide an icon on Linux.
New FeaturesBug Fixes

0.2.7

Fixed
  • Fixed a bug that prevented the desktop app from logging out from the command line.

0.2.6

New
  • Added a -y flag to formal auth login to bypass the browser confirmation prompt.
Fixed
  • Fixed a bug where the desktop agent could be launched multiple times.
New FeaturesImprovementsBug Fixes

0.2.5

New
  • Implemented pagination of resources to reduce startup delay of formal ls.
Changed
  • Reworked connecting/disconnecting to resources to be asynchronous, which prevents a connection from blocking the TUI from rendering.
Fixed
  • Fixed a bug where the desktop app would show multiple instances of the same resource while filtering and connecting.
  • Fixed a bug where the autolaunch functionality could freeze the TUI.
New FeaturesImprovements

0.2.4

New
  • Added support for using token authentication in headless mode.
  • Introduced a configurable timeout for the formal agent command with --timeout.
Changed
  • Changed the formal ls command to lazily load resources and show a loading spinner instead of blocking the TUI from launching.
New Features

0.2.3

New
  • Added a formal agent command to launch the Formal Agent through the CLI.
  • Added a headless mode, which can be launched through formal agent --headless and allows usage of the Formal Desktop without a GUI. See Desktop App for more details.
New FeaturesBug Fixes

0.2.2

New
  • Added the ability to open a psql session automatically when connecting to a PostgreSQL resource through formal ls.
  • Added a permanent “latest” URL to download the latest version of the desktop app on Linux.
Fixed
  • Fixed a bug where the desktop app could become unresponsive when connecting to a resource.
New FeaturesBug Fixes

0.2.1

Fixed
  • Fixed a visual bug with the formal ls UI where a resource would not update its status after a connection request

0.2.0

New
  • Added the ability to open an SSH session automatically when connecting to an SSH resource through formal ls
New Features

0.1.4

New
  • Added support for Linux
New Features

0.1.0

New
  • Added support for configuring the SSH client (i.e., ~/.ssh/config) to more seamlessly connect to SSH, EC2, and ECS Fargate resources using the formal ls UI
Improvements

0.0.91

Fixed
  • Fixed versioning issue

0.0.90

Fixed
  • Fixed versioning issue

0.0.89

New
  • Added a link to download the latest version of the desktop app if an update is available

0.0.88

Changed
  • Ensured errors are printed to stderr rather than stdout to provide a clean output stream to users

0.0.87

New
  • Exposed certain classes of connection errors between the local proxy and the Formal Connector to users
Bug FixesNew Features

0.0.86

Fixed
  • Fixed authentication failures

0.0.85

New
  • Added support for using formal@<native-user> as the username to specify the native user

0.0.84

New
  • Added support for json option to formal auth credentials -o

0.0.83

New
  • Added support for json option to formal auth credentials -o

0.0.82

Fixed
  • Avoided crashing on EOF for postgres

0.0.81

Fixed
  • Fixed desktop app auth status
New FeaturesBug Fixes

0.0.80

Fixed
  • Fixed desktop app auth status

0.0.79

New
  • Added support for MongoDB smart routing

0.0.78

Fixed
  • Fixed typo in error message missing S3 resource name

0.0.77

New
  • Added support for TCP Proxy and Relays

0.0.75

Changed
  • Removed the use of AWS profile

0.0.74

Changed
  • Removed the use of AWS profile

0.0.73

Changed
  • Added more efficient routing

0.0.72

Fixed
  • Fixed support for dynamodb

0.0.71

New
  • Added resource subdomain to Kubernetes resources for connectors

0.0.70

New
  • Added support for connectors

0.0.69

New
  • Added support for basic auth for clickhouse

0.0.68

New
  • Added resource to policy evaluation

0.0.67

Changed
  • Updated desktop app to renew key every 18 hours

0.0.66

New
  • Added support for connector in policy evaluation

0.0.65

Changed
  • Updated log message for fetchCABundle

0.0.64

Changed
  • Added more logs to the dynamodb command

0.0.63

Changed
  • Removed posthog

0.0.62

Fixed
  • Fixed AWS CLI

0.0.61

Fixed
  • Fixed AWS CLI

0.0.60

New
  • Added AWS CLI to building process

0.0.59

New
  • Added support for certificate bundle dynamodb

0.0.58

New
  • Added support for API Token expiration