> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getbifrost.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# v0.9.2

> Edge v0.9.2 changelog - 2026-10-02

<Update label="Bifrost Edge" description="v0.9.2">
  ## Changelog

  v0.9.2 extends Cursor governance: Edge now discovers Cursor MCP plugins and syncs their inventory and enablement to Bifrost, resolves plugin tool catalogs through Cursor's native executor, supports general-purpose and installed custom subagents with MCP access, and routes Cursor Tab autocomplete through the gateway. Newer Cursor builds are no longer rejected on unfamiliar protocol fields, and an MCP inspection failure returns an immediate error instead of leaving Cursor waiting. The background service is hardened against ambiguous session refresh outcomes, stalled trust checks, startup failures, and unclean shutdowns: startup retries in place, a lost refresh response retains credentials instead of replaying a rotated token, and shutdown drains capture before credentials are reverted on every platform. Support reports now carry operating system service evidence, and the Claude Code model picker always reflects the governed catalog.

  ## ✨ Features

  * **Cursor MCP Plugin Discovery** - Edge discovers active Cursor MCP plugins from Cursor's runtime exports (`~/.cursor/projects/*/mcps`), the plugin cache, and local plugins, reads their enablement state from Cursor's state database in read-only mode, and syncs server inventory, exported tool names, package versions, and enablement to Bifrost. Enablement toggles are picked up live. Plugin files are never rewritten by the configuration enforcer, no plugin command is ever launched, stdio plugin servers are inventory-only, and remote plugin servers are inspected natively. [Docs](https://docs.getbifrost.ai/edge/mcp-governance)
  * **Native MCP Execution for Cursor Plugins** - When Cursor sends only descriptor metadata for a plugin's MCP servers, descriptors with complete schemas become tools immediately and a new `get_mcp_tools` native tool fetches the remaining schemas through Cursor's own executor, refreshing the catalog for the next model step. Previously such plugin tools were invisible to the model. Approval checks and inspection apply unchanged.
  * **Cursor Subagents with MCP Access** - Writable Cursor modes gain `agent_task` (a general-purpose child that keeps MCP tools) and `custom_task` (installed custom agents with their configured model, permission mode, prompt, and explicit tool list). Background custom agents are awaited to a correlated completion rather than reported from the launch acknowledgement. The Explorer child remains read-only and cannot call MCP, Ask and Plan modes never receive `agent_task`, and no child may delegate further.
  * **Cursor Tab Autocomplete Through the Gateway** - Cursor Tab completions are translated to a gateway chat request and back into native replacement, text, and cursor-prediction frames, using the `cursor.tab_model` configuration field. A configured Tab model outside the allowed catalog is refused with an explicit message. Previously Tab failed closed. Cursor file sync is disabled: the capability answers false locally and requests that rely on it are rejected.
  * **Cursor Protocol Forward Compatibility** - Unknown Cursor protocol fields are retained instead of rejecting the request; only nesting depth is bounded. Fields introduced in Cursor 3.23.12 are typed, and the split Run transport (`RunSSE` plus unary `BidiAppend`) is governed through the same engine with sequence reordering, retry dedup, and a 30-second attach timeout.
  * **Cursor Model Picker Shows Auto** - The Auto entry is visible and default-on in the Cursor model picker, and a gateway default change no longer overwrites the user's explicit selection.
  * **Native Cursor Services Relayed** - Local subscription tools, the agent mailbox, and background composer storage calls are relayed to Cursor with native credentials, with local tool calls gated by the native execution inspector. Cloud agent launch and telemetry are answered as disabled locally, and remote control and private workers are forced off in settings responses.
  * **Unknown MCP Installations Relayed and Logged** - A remote MCP endpoint that is registered under a different application (for example registered for Claude Code but called by Cursor) is now relayed with native credentials and logged to Bifrost MCP logs as an unknown installation, with no decision and no invented result. Previously the call was refused or attributed to the other application. Requires a matching server update.
  * **Background Service Startup Retries** - In service mode, a failed startup (capture device creation, gateway or configuration problems) now retries in process with a backoff from 1 second doubling to a 60-second cap until the service is stopped, instead of exiting. Each failed attempt removes routes and closes the capture device it created. A local IPC listener failure retries separately (1 second to a 30-second cap) while capture and authentication keep running, and Status and Diagnostics answer during retries with the current phase, attempt, and next retry time.
  * **Session Refresh Safety** - A refresh whose outcome is uncertain (lost response, conflict, or an ambiguous server error) now retains credentials and asks for a new sign-in instead of replaying a token the server may already have rotated. The tray shows "Session refresh could not be confirmed. Sign in again to restore the session." Concurrent refresh callers share one rotation, a late rejection of an old session can no longer erase a newer login, and a server storage outage is no longer treated as revocation.
  * **Trust Verification Isolation** - An unavailable native trust check (timeout or subprocess failure) keeps the previous verdict for the same trust root and reports a pending state instead of untrusted, so the tray and Diagnostics never prompt for trust installation while evidence is still being collected. On macOS, status polling no longer depends on the signing service, and a stalled check is killed after 5 seconds. On Windows, the trust check depends only on the system trust store.
  * **Ordered Shutdown and Service Recovery** - Shutdown now drains workers, removes routes, and closes capture before managed application credentials are reverted and configuration is saved, so clients regain connectivity before rollback. A second termination signal no longer kills the service mid-cleanup. macOS launchd allows 120 seconds for exit, the install and restart scripts wait up to 110 seconds for the old service to leave, the Linux systemd unit sets a 120-second stop timeout, and the Windows service reports stop progress with a 120-second wait hint. The Windows MSI configures service recovery to restart after 10 seconds, and an unexpected exit now returns a failure code so recovery fires. A capture listener failure restarts the runtime after 5 seconds instead of looping.
  * **Route Journals (TUN)** - A per-runtime route journal is written before each operating system route change. Failed removals are retained for a later retry, prior journals are kept across restarts as recovery evidence, route cleanup has a 30-second budget, and DNS lookups and route commands are bounded to 3 seconds. Journals are included in support exports.
  * **Operating System Service Evidence in Support Reports** - Support ZIPs now collect every log file and rotation in the service and user log directories, including launchd stdout and stderr. On macOS they add filtered service state for the daemon and tray, 24 hours of launchd and installer log lines mentioning Bifrost, an index of Bifrost crash reports, and installer log lines. On Windows they add service status, service control events, shutdown events, and application crash events for the last 24 hours. Each command is bounded to 8 seconds and 2 MiB, and collection failures are written into the archive instead of failing the export. macOS maintenance scripts also log each phase to syslog under `bifrost-maintenance`.
  * **Diagnostics Updates** - "Observed AI traffic" replaces the ChatGPT-only inspection check and passes once any decrypted request to a configured AI platform has been seen. A pending signing verification shows as Unknown with an automatic-retry note instead of a failure, and interception readiness reports a specific reason (`signer-dns-failed`, `signer-timeout`, `signer-unreachable`, or `signer-http-NNN`). Collection shares one in-flight snapshot and returns partial evidence within 7 seconds when a source stalls, with a "Diagnostic collection" check naming the pending phase. Status reports the data directory, lifecycle phase, trust check time, and recovery state.
  * **Diagnostic Log Safety** - Management API errors omit response bodies and strip credentials, query strings, and fragments from logged URLs. Logged headers use an allowlist with values collapsed to one line and capped at 256 characters, and `code`, `token`, `secret`, `password`, `api_key`, `apikey`, `authorization`, and `cookie` query parameters are masked. Every management call carries a per-request ID and the build version, and every log line carries a boot ID and process ID for cross-restart correlation.
  * **Claude Code Model Picker Always Governed** - Conditional request headers are stripped before relaying Claude model selector requests, and the governed list is returned with `Cache-Control: no-store` and no validators, so a cached native picker can no longer survive a policy or identity change. A catalog snapshot older than 1 hour is treated as missing, and a catalog miss relays the native list untouched without blocking the picker.
  * **Bounded Memory for Withheld Streams** - Streamed responses held for native tool inspection spill to private temporary files beyond 1 MiB per payload or 32 MiB per process instead of failing with an inspection limit error. Buffered request bodies above the capacity limit are answered with 413.
  * **Windows Tray Menu Theme** - On Windows 10 version 1903 and later, the tray menu follows the light or dark app theme and re-checks every second so a theme switch applies live. High contrast keeps the system default.

  ## 🐞 Fixed

  * **Newer Cursor Builds Rejected** - Any unknown protocol field (Cursor 3.23.12 and later) failed every request with "unsupported Cursor fields or nesting".
  * **Resumed Cursor Conversations Refused** - Stored messages with vendor history, unfamiliar content parts, or legacy reasoning details returned "use a new conversation"; they are now projected where recognized and otherwise preserved.
  * **Cursor Resume After Interruption Failed** - Stale pending bookkeeping produced "cannot recover a pending tool without its saved call identity"; recovery now records an unknown-outcome notice and never replays operations or invents results.
  * **MCP Inspection Failure Left Cursor Waiting** - A response inspection failure only closed the stream, so Cursor waited until its idle timeout; the client now receives a correlated JSON-RPC error immediately, output is withheld, and the tool is not retried automatically.
  * **MCP Inspection Sessions Broke on Server Rename** - A catalog refresh that renamed a server mid-call caused a 409; sessions are now bound to stable installation identity (requires the matching server update).
  * **Native Tool Approval Failed After Token Refresh** - A routine credential refresh during a held tool batch raised "native inspection identity changed during inference"; a verified refresh keeps the session and the batch is re-inspected up to 3 times.
  * **Cursor Agent Streams Orphaned on Token Rotation** - The stream owner key no longer includes the gateway bearer, so later appends reach the in-flight Run.
  * **HTTP/1.1 Connection Reuse After Abandoned Uploads** - A request whose body was replaced or not fully consumed could leave stale framing on a reused connection; Edge now answers with `Connection: close` and interrupts the unfinished upload. Recognized unary Cursor support uploads up to 1 MiB are made replayable without buffering duplex streams.
  * **Shared Session Refresh Failed When the First Caller Gave Up** - The refresh now runs on a service-owned context with a 30-second timeout, so other waiters are not failed by one cancelled caller.
  * **Stalled Trust Check Blocked the Tray** - A hung native verifier made status polling wait and could flip trust to untrusted with a reinstall prompt.
  * **Diagnostics Window Hung** - A blocked source exceeded the 20-second header timeout, and on TUN the page could stall behind slow DNS lookups or route operations; both paths are now bounded.
  * **Local IPC Refused During Startup** - Status and Diagnostics now answer while startup is retrying instead of connection refused.
  * **Failed Route Removals Forgotten** - Removals that failed during domain updates or cleanup are now retained for retry.
  * **Managed Credential Ownership Guard Disabled by Transient File Replace** - A momentarily missing target file during an atomic replace no longer disables ownership enforcement for the rest of the session.
  * **Late Policy Callback Re-planted Managed Credentials** - Managed credential reconcile becomes a no-op once stopped, so rollback at shutdown is not undone.
  * **Cursor BYOK Reported Unsupported on Cursor 3.22.12** - Its migration code is now recognized, and helper failures that were silently lost (truncated or missing replies) now surface with new configured and verification-pending statuses.
  * **Cursor BYOK Helper Relaunched at Full Speed** - A successful launch now records a cooldown equal to the 15-second reconcile period and a failure one minute, so watcher bursts no longer retrigger it immediately.
  * **OpenCode Catalog Watcher Feedback Loop** - The catalog cache timestamp is refreshed at most once per minute instead of on every reconcile pass, which had retriggered OpenCode's file watcher.
  * **Windows "Working in Background" Cursor Persisted** - Headless helper processes now acknowledge GUI startup so the busy cursor clears promptly.
  * **Windows Service Not Restarted After Unexpected Exit** - A clean return without a stop request now exits with a failure code so service recovery applies.
  * **macOS Scripts Double-Started Jobs** - Install and restart scripts no longer kill and relaunch a job that was just bootstrapped.
  * **Shutdown Hooks Ran Before Route Removal** - A stalled hook can no longer leave routes installed.
  * **Configuration Sync Sent a Fixed Version** - The real build version is now reported instead of a hard-coded value.
  * **Claude Plugin Configuration Discarded on One Bad Entry** - A single malformed MCP server entry no longer drops the whole file.
  * **Windows ARM64 Package Build** - The resource compiler is now built for the build host rather than the target architecture.
</Update>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.