## lightninglabs/aperture — v0.4.3…v0.5.0

_101 commits._

### Features
- **skills: add aperture CLI skill for agent discovery** (e07ef51)
- **make: add aperturecli to build and install targets** (08cb9e4)
- **cli: add MCP server exposing admin RPCs as agent tools** (ac2a95e)
- **cli: add admin API commands for services, transactions, tokens, and stats** (1955f3c)
- **cli: add aperturecli foundation with cobra and gRPC client** (a004354)
- **multi: add MPP payment tracking to transaction store** (68846a2)
- **multi: add per-service auth scheme selection and MPP admin API support** (00dc2e3)
- **aperture: add nolint:dupl to both postgres and sqlite cases** (bf3ded4)
- **proxy: add Payment-Receipt injection, Problem Details, and Cache-Control** (c2fad5a)
- **challenger: add LND payment sender for session refunds** (a8bd3dd)
- **aperturedb: add MPP session store with sqlc migration** (f05c560)
- **auth: add MultiAuthenticator for composing auth schemes** (5d5d5e6)
- **auth: add ReceiptProvider, SessionStore, and PaymentSender interfaces** (e995da6)
- **mpp: add Lightning charge/session intent types and RFC 9457 problem details** (fbda711)
- **mpp: introduce core Payment HTTP Auth protocol package** (271be27)
- **embed: use all: prefix to include _next/ assets, add verification tests** (7f937ce)
- **lint: add nodashboard build tag to golangci-lint config** (c26c7cd)
- **make: add nodashboard tag to test builds** (b683514)
- **dashboard: add Prettier with eslint-config-prettier integration** (ccea265)
- **dashboard: add pages with full service management UI** (2845a15)
- **dashboard: add shared UI components** (a8436a6)
- **dashboard: add theme, types, API hooks, and proxy route** (c2e1f7c)
- **dashboard: add Next.js project scaffold and configuration** (4e96c87)
- **challenger: add settlement queue with startup reconciliation** (2df4496)
- **l402/aperturedb: add L402 transaction store and identifier helpers** (fc15ab7)
- **config: add validation and docs for WebSocket ping/pong settings** (210fdb8)
- **feat: rewrite instruction for prefix** (7341979)

### Fixes
- **cli: fix unparam lint for resolveOutputFormat/isJSONOutput** (60000bb)
- **cli: fix lint issues (goconst, dupl)** (d68c855)
- **cli: fix MCP update field clearing and version drift** (e441ef6)
- **cmd/merge-sql-schemas: fix exitAfterDefer lint error** (7f8e0f1)
- **multi: fix gofmt and prettier formatting issues** (5e516fb)
- **multi: fix DB service loading and upgrade migration for token_id** (6c8db68)
- **multi: fix auth_scheme update and add upgrade migration** (815aadf)
- **multi: fix lint issues across new MPP code** (98d073c)
- **dashboard: fix CSV quoting, SPA navigation, revenue, remove dead files** (0c79e5a)
- **aperture: add loopback, CSRF, security headers, query allowlist, trailing slash fix** (e7319c5)
- **make: fix install and clean targets for dashboard embedding** (123fce8)
- **dashboard: add ESLint, fix proxy SSRF, fix CSV injection** (3207244)
- **proxy: fix rewrite path handling and harden configuration** (fef7e1c)
- **Merge pull request #218 from djkazic/fix-timeout-caveat** (15e6431)
- **Merge pull request #221 from starius/2603-alpn-fix-2** (cf0f4fc)
- **fix: missing option in sample config** (6a3fe34)

### Backend
- **Merge pull request #224 from lightninglabs/cli** (311220b)
- **cli: wire rpcTimeout into all command handlers** (3061277)
- **cli: address code review findings from substrate review** (b25fe83)
- **Merge pull request #220 from lightninglabs/mpp-payment-auth-scheme** (6e989a1)
- **multi: address code review findings across MPP auth, admin, and proxy** (70b4ca1)
- **Merge pull request #223 from lightninglabs/dependabot/npm_and_yarn/dashboard/next-16.1.7** (4cf9d30)
- **Merge pull request #222 from lightninglabs/dependabot/npm_and_yarn/dashboard/flatted-3.4.2** (ee348ab)
- **multi: address review findings across MPP authenticator code** (3d89ab4)
- **aperture: suppress dupl lint for sqlite/postgres store init** (e2976b3)
- **aperturedb/sqlc: regenerate with sqlc v1.25.0 to match CI** (945ebdd)
- **multi: wire MPP authenticators into aperture with config flags** (7f3f25d)
- **auth: implement MPP session intent authenticator** (afd11d3)
- **auth: implement MPP charge intent authenticator** (a99c18a)
- **Merge pull request #216 from lightninglabs/admin-rest-api** (a8e9cb5)
- **admin: reject services whose path_regexp matches reserved paths** (6173b8b)
- **proxy: serve dashboard fallback before static 404 handler** (43f02c3)
- **adminrpc: regenerate protos with Docker toolchain** (3d52ff0)
- **aperturedb: consolidate migrations into 000004 and 000005** (63a2230)
- **aperture+dashboard: address re-review findings H-2/H-3/M-2/M-3/M-4/M-5/M-6** (2d5ab25)
- **review: address code review findings for admin API PR** (0d5292e)
- **dashboard: self-host fonts instead of loading from Google CDN** (00a8b7b)
- **dashboard: resolve peer deps via overrides, remove --legacy-peer-deps** (5f39702)
- **proxy: move dashboard catch-all from priority to fallback services** (72f3b01)
- **aperture: gofmt** (da2ce88)
- **dashboard: embed static export in Go binary via go:embed** (3597cfe)
- **dashboard: upgrade to Next.js 16 and React 19.2** (19e0473)
- **dashboard: use macaroon auth instead of Bearer token** (55265e3)
- **adminrpc: regenerate admin.pb.go with protoc-gen-go v1.36.10** (28d59e9)
- **aperture: wire admin API, proxy concurrency, and runtime config** (6f11af8)
- **admin: implement gRPC server with macaroon auth** (5fa266f)
- **adminrpc: define admin gRPC service and REST gateway proto** (1f8c255)
- **Merge pull request #212 from lightninglabs/enable-ws-pings-lnc** (f808154)
- **config: bump default WebSocket pong wait to 15s** (84f6b56)
- **Merge pull request #204 from sergey3bv/feat/config-n-rewrite-option** (be1830d)
- **Merge pull request #211 from lightninglabs/dependabot/go_modules/github.com/docker/cli-29.2.0incompatible** (2675b3f)
- **Merge pull request #219 from lightninglabs/dependabot/go_modules/google.golang.org/grpc-1.79.3** (8efdac9)
- **aperture: don't precompute timeout** (2b51f5e)
- **aperture: use manager TLSConfig for autocert** (1dc2035)
- **Merge pull request #209 from lightninglabs/dependabot/go_modules/go.opentelemetry.io/otel/sdk-1.40.0** (82a60d5)
- **Merge pull request #207 from jbrill/claude-pr-review** (cd8e80f)
- **aperture: enable WebSocket-level pings for LNC connections** (2b212c9)

### Tests
- **test: proxy rewrite prefix** (d3bbbdb)

### Docs
- **docs: update README with admin API, dashboard, and CLI sections** (cf36d26)
- **docs: add CLI and MCP server documentation** (cd8d0f9)
- **docs: add MPP auth scheme documentation to admin API and dashboard** (b4aa959)
- **docs: add admin API and dashboard documentation** (9611f8a)
- **docs: add ALPN guidance for loadbalancer TLS** (6defc24)

### Chore
- **build: bump Go version to 1.26 across build system** (4cf864e)
- **build(deps): bump next from 16.1.6 to 16.1.7 in /dashboard** (2750d57)
- **build(deps-dev): bump flatted from 3.4.1 to 3.4.2 in /dashboard** (9c572cb)
- **ci: fix lint, test, sqlc, formatting, and rpc-check failures** (6201cd5)
- **build: make dashboard opt-in via -tags=dashboard** (bdec681)
- **ci: add Prettier format check to dashboard job** (6c53e9c)
- **ci: add dashboard tsc and lint job** (f65be3f)
- **build(deps): bump github.com/docker/cli** (986a28f)
- **build(deps): bump google.golang.org/grpc from 1.59.0 to 1.79.3** (d663652)
- **build(deps): bump go.opentelemetry.io/otel/sdk from 1.35.0 to 1.40.0** (6161b28)
- **ci: claude review in action** (c0d865b)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/lightninglabs/aperture?utm_source=github-action)._