v1.0.1
What changed for looot customers in v1.0.1.
The public CLI release. Since the last internal build (2026-09-22):
For customers
loooton npm. One command, zero dependencies, no source code shipped. The old install script and package name are gone.- Browse before signing up.
looot search "<task>"andlooot inspect <id>work with no account, from the public catalog, with full endpoint ids and prices. - Sign in without copying a secret.
looot loginprints a link and a code and opens the approve page on looot.ai. You check the code, machine and organization, choose a label, scopes and an expiry, and approve. Only a one-way digest of the token ever leaves your machine. The token then appears in Settings, Agent tokens, as “CLI on <machine>”.looot logoutrevokes it on the server, verified dead within seconds. - Safer agent setup.
looot initwrites a reference to your token, never the secret itself;init --dry-runshows only looot’s own entry, never another tool’s configuration. - Clearer errors. One line, exit code 1, no stack trace. Unknown commands say so.
- Catalog truth. Endpoints looot’s platform keys can’t actually serve are no longer offered as runnable.
Fixed the same day, from the first customer test
- Clicking Deny in the browser now stops the terminal by itself. It used to leave it waiting.
looot loginandlooot whoamishow the organization’s name and the token’s expiry date.- Every customer-facing surface (docs, dashboard, the plain-text agent docs, the MCP tool descriptions, the npm page) says looot consistently.
- The money rule is stated everywhere: browsing needs no account, running needs sign-in and a funded balance (no trial credit). The insufficient-balance message shows one short link to pay.
runs listshows $0 or “pending” where it used to show a broken number; receipts no longer show an internal placeholder value.
How it was verified
Four rounds of a fresh, unassisted customer test: install from npm, browse, sign in with a human
approving in the browser, one paid call, sign out, and confirm the token is revoked. Round 1
found 8 problems; round 2 found a secret leaking into init --dry-run’s JSON and a broken install
link in the docs; round 3 found an endpoint the platform key couldn’t actually serve. All were
fixed. The verdict on the published 1.0.0 build: yes, install, browse, sign-in, a paid call with
an exact balance change, sign-out and revocation all worked. On 1.0.1: yes again, with Deny
stopping the CLI on its own, the organization name and token expiry showing, a paid call
reconciling to the cent, and sign-out revoking the token.