## jacob-bd/gemini-notebook-mcp-cli — v0.13.0…v0.14.0

_34 commits._

### Features
- **feat(auth): pick which profiles to switch, never miss real backups** (29d1a1f)
- **feat(auth): add user awareness, setup wizard prompt, doctor checks, and graceful invitations (Task 7)** (ac16879)
- **feat(auth): optimize MCP hot path, caching, and concurrency safety (Task 5)** (309332e)
- **feat(auth): migrate without losing newer or divergent credentials (Task 4)** (5748bac)
- **feat(auth): route AuthManager through storage mode (Task 3)** (66b9307)
- **feat(auth): add OS key and AES-GCM encrypted credential storage** (4972d10)
- **feat(auth): add per-profile storage mode selection and safe config handling** (bd4f8eb)

### Fixes
- **fix(auth): offer plain backups of every protected profile** (df3182f)
- **fix(auth): make the MCP notice reach the user once, and unify wording** (eea48eb)
- **fix(cli): actually show the one-time Protected mode tip** (7c444ad)
- **fix(smoke): skip keystore cleanup check on the refusal-only path** (34261e4)
- **fix(auth): Task 7 review fixes for notices, doctor, wizard and popup docs** (faa971f)
- **fix(test): start MCP probe only in main() and snapshot storage before collection** (d54178e)
- **fix(test): isolate HOME and add suite-level storage tripwire** (ac44305)
- **fix(auth): fix smoke script APIs, macOS home guard, and doc drift scanning** (69434dc)
- **fix(auth): address Gate 4 feedback, file-mode parity, and compare-and-save safety** (c22eeef)
- **fix(auth): unify file-mode snapshot precedence and fix storage conflict reporting** (3a3ca14)
- **fix(auth): address Gate 3 credential preservation and race conditions** (2c4d369)
- **fix(config): default validate_profile_name to strict=True** (64e6d9e)
- **fix(test): yield in _isolate_storage for e2e test runs** (94c8bf0)
- **fix(auth): permit legacy profile names in file mode and restrict keystores** (e736f81)
- **fix(auth): restore base_host clearing on consumer re-login** (4165245)
- **fix(auth): address Gate 1 review items for OS credential store** (f4f5240)
- **fix(test): harden credential store isolation and fail-closed guards** (2ce1401)

### Backend
- **Merge Protected mode (0.14.0)** (2eee8f9)

### Tests
- **test: pass on headless Linux CI** (b0808be)
- **test(auth): add regression tests for host clearing, legacy profile names, e2e fixture, and corrupt config** (93db613)
- **test(auth): enforce test isolation and fail-closed credential store guard** (a74e86e)

### Docs
- **docs(auth): macOS Keychain prompt needs the login password and outlives the 60 s timeout** (016739d)
- **docs(auth): document protected mode and complete Task 6 release readiness** (ba2d4a1)
- **docs(readme): add Google Terms of Service note to disclaimer** (c601645)

### Chore
- **chore: prepare 0.14.0 release** (647ed81)
- **style: format and clean types in config and contract tests** (2a114e8)
- **chore(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 (#338)** (7d59166)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/jacob-bd/gemini-notebook-mcp-cli?utm_source=github-action)._