Skip to content

Releases: StevenACZ/lucas-cli

v0.7.0 — device-auth v2, scopes and the 2026 API surface

Choose a tag to compare

@StevenACZ StevenACZ released this 12 Jul 01:44

Added

  • lucas stats overview — full stats for one period (--period WEEK|MONTH|SIX_MONTHS|YEAR, --currency, --offset for historical
    windows) in a single call.
  • lucas accounts pay-expense and lucas accounts pay-expenses — pay one or
    up to 50 credit-card expenses atomically from ACCOUNT, EXTERNAL, or
    CASHBACK funding sources (batch items via repeatable
    --item <transactionId[=amount]>).
  • Credit-card cashback: lucas accounts cashback-redeem and
    cashback-adjust, --cashback-enabled/--cashback-rate on
    accounts create/update, and --cashback-amount on
    transactions create/update.
  • lucas ai insights get and lucas ai insights generate --period WEEK|MONTH
    for the persisted AI financial insight.
  • lucas trash group: summary, transactions, transfers,
    restore-transaction, restore-transfer, permanent-delete-transaction,
    permanent-delete-transfer, empty-transactions, and empty-transfers.
  • lucas accounts archive / unarchive, lucas accounts stats, and
    lucas accounts balance-history --range --anchor-date.
  • lucas transactions get <id> for a single transaction.
  • lucas transfers update --to-account-id to correct the destination account.
  • lucas subscriptions create/update --payment-start-day (and
    --clear-payment-start-day) for backend payment windows, plus
    lucas subscriptions services for the service catalog.
  • lucas exchange-rate bcr for the USD→PEN reference rate.
  • lucas auth status --remote verifies the token against GET /api/auth/me.
  • API requests now time out (30s default, 120s for AI endpoints), expose the
    backend x-request-id in error details, and surface Retry-After on
    HTTP 429 as retryAfterSeconds.
  • auth login/logout requests time out after 10s, and the login poll fails
    fast when the backend no longer recognizes the device code (404/410).
  • A stderr warning is printed when LUCAS_API_URL overrides the API the
    stored credentials were issued for.

Fixed

  • error.details.code is always RATE_LIMITED on HTTP 429, even when the
    backend payload carries its own error code.

Changed

  • Breaking: lucas auth login uses the new device-auth flow approved from
    the LucasApp iOS app (Settings → Security → CLI Access). The browser/dashboard
    approval step is gone, tokens carry a user-chosen scope (READ_ONLY or
    FULL), and a denied request is reported explicitly. On success the CLI now
    prints the standard JSON envelope (deviceName, scope, expiresAt) to
    stdout. Existing tokens are invalid; run lucas auth login again.
  • Breaking: removed --merchant/--clear-merchant from
    transactions create/update; the backend dropped the merchant field.
  • CLI_READ_ONLY and CLI_FORBIDDEN_ENDPOINT backend errors map to
    actionable CLI messages on every command.
  • Plan copy is no longer hardcoded: backend error messages pass through, with
    neutral fallbacks (no plan numbers or prices) when the backend sends none.
  • CLI version is read from package.json instead of a hand-maintained
    constant.
  • Toolchain: commander 15 (Node >= 22.12), typecheck via TypeScript 7,
    eslint 10.7, typescript-eslint 8.63, vitest 4.1.10, prettier 3.9.5.
  • Homepage now points to the GitHub repository (the web dashboard was
    retired).

Removed

  • Removed hardcoded plan copy (PLAN_FEATURES) and the obsolete dependency
    overrides block.

lucasapp-cli v0.6.8

Choose a tag to compare

@StevenACZ StevenACZ released this 28 May 14:38
18bf34f

Summary

Verification

  • bun run format:check && bun run typecheck && bun run lint && bun run test && bun run build
  • npm pack --dry-run --json --ignore-scripts
  • Production smoke: auth status and investments instruments against https://api.lucasapp.app.
  • Legacy domain search returned no active references outside .bak and ops-log history.

Security

  • Diff-scoped security review found no reportable candidates; no secrets or auth enforcement paths changed.

lucasapp-cli v0.6.7

Choose a tag to compare

@StevenACZ StevenACZ released this 28 May 04:41
a198eba

Summary

  • Adds investments CLI parity for catalog discovery, overview, positions, activity, history, trades, cash adjustments, archives, and refresh actions.
  • Adds subscription groups, subscription charges, and monthly subscription calendar commands.
  • Moves production defaults to dashboard.lucasapp.app / api.lucasapp.app and normalizes legacy stored production API URLs.

Verification

  • bun run format:check && bun run typecheck && bun run lint && bun run test && bun run build
  • npm pack --dry-run --json --ignore-scripts
  • Production smoke: auth status, investments instruments/overview/positions/activity/history, subscriptions calendar, subscription groups, subscription charges pending.

v0.6.6

Choose a tag to compare

@StevenACZ StevenACZ released this 20 May 04:37

Changed

  • Removed the retired lucas ai chat-message command to match the current backend API surface.
  • Kept LucasApp CLI AI focused on usage, parse-expenses, parse-expenses-image, and insights.
  • Updated README and changelog for the supported AI command set.

Verified

  • format, typecheck, lint, tests, build, and npm pack dry-run passed locally.
  • Production CLI smoke tests passed against https://lucas.stevenacz.com.

v0.6.5

Choose a tag to compare

@StevenACZ StevenACZ released this 20 May 01:06

Summary

  • Align list commands with current backend filters and pagination shapes.
  • Include archived accounts explicitly in account list output while preserving active totals.
  • Add client-side converted amounts for exchange-rate conversions.

Verification

  • format:check, typecheck, lint, test, build.
  • npm pack dry-run publishes only LICENSE, README.md, dist/index.js, and package.json.
  • Production read-only smoke covered auth, accounts, debt detail, transactions, transfers, subscriptions, loans, stats, categories, exchange-rate, and usage endpoints.

v0.6.1

Choose a tag to compare

@StevenACZ StevenACZ released this 20 May 00:16

Summary

  • Harden CLI device authorization by separating the visible approval code from the secret polling code.
  • Add stricter local image input validation, safer resource path handling, redacted backend errors, and private credential storage.
  • Move npm publishing to Trusted Publishing/OIDC with provenance.

Verification

  • bun run format:check
  • bun run typecheck
  • bun run lint
  • bun run test
  • bun run build
  • npm pack --dry-run --json --ignore-scripts

v0.6.0

Choose a tag to compare

@StevenACZ StevenACZ released this 09 May 04:11
371cfae

Added

  • lucas ai usage — reads current AI usage and preserves usagePeriods when the backend returns daily, weekly, and monthly windows.
  • lucas ai parse-expenses <text...> — sends text expense parsing requests to POST /api/ai/parse-expenses.
  • lucas ai parse-expenses-image <paths...> — sends up to 10 receipt images to POST /api/ai/parse-expenses-image.
  • lucas ai insights <query...> — sends financial insight prompts to POST /api/ai/insights.
  • lucas ai chat-message <message...> — sends messages to Lucas Chat via POST /api/lucas-chat/message.

Changed

  • Public plan contract is now FREE and PREMIUM only.
  • Premium copy reflects unlimited accounts, unlimited subscriptions, and AI limits of 50/day, 300/week, and 1000/month.
  • Free copy reflects 0 AI calls, up to 3 active accounts, and blocked subscriptions.
  • Backend limit errors now map to CLI-friendly messages for AI, subscription, and account limits.
  • Dev dependency overrides were refreshed so the public repository audit is clean.

For AI agents

Typical AI flow:

lucas ai usage
lucas ai parse-expenses "coffee 4.50 today"
lucas ai parse-expenses-image ./receipt.jpg
lucas ai insights "summarize my spending this month" --period month
lucas ai chat-message "what changed in my finances this week?"

This release expects the LucasApp backend deployed with the FREE/PREMIUM AI contract.

v0.5.0

Choose a tag to compare

@StevenACZ StevenACZ released this 20 Apr 05:11
383dd13

Added

  • lucas accounts debt-detail <id> — credit-card debt breakdown per billing cycle (pass-through over GET /api/accounts/:id/credit-debt-breakdown). Flags: --mode, --anchor-date, --start-date, --end-date, --search, --only-pending, --limit, --offset. Default --mode=current_cycle --limit=100 for AI-friendly single-page responses.
  • lucas accounts create --statement-closing-day <n> — parity with accounts update. Backend now returns creationWarning on the created account when CREDIT is created without this flag (requires backend on 2026-04-20+).
  • lucas accounts list now returns availableCredit (max(0, creditLimit - currentDebt)) for CREDIT accounts with a non-null creditLimit. Field is omitted for all other account types.

For AI agents

Typical flow:

lucas accounts list
# pick a CREDIT id, then:
lucas accounts debt-detail <id>
# -> {"ok":true,"data":{"summary":{"currentDebt":..., "charges":..., "payments":..., "outsideRangeDebt":...}, "items":[...]}}

summary.currentDebt == summary.composedDebt + summary.outsideRangeDebt (±0.01) is the invariant to trust. outsideRangeDebt > 0 indicates carry-over from prior cycles.

v0.4.0

Choose a tag to compare

@StevenACZ StevenACZ released this 03 Apr 22:05

What's New

loans unmark-paid command

  • Reverse loan payments that were incorrectly applied
  • lucas loans unmark-paid <loan-id> — reverses the most recent payment
  • lucas loans unmark-paid <loan-id> --payment-id <id> — reverses a specific payment
  • Restores installment status, account balance, and deletes linked transactions

v0.3.1

Choose a tag to compare

@StevenACZ StevenACZ released this 03 Apr 00:54
a7bed87

Highlights

  • notify interactive users when a newer lucas CLI version is available
  • fix transaction list date and pagination filters to use canonical API query names
  • add --year and --month to stats summary and stats by-category
  • keep compatibility with older installed CLIs via backend aliases for from/to/skip/take