---
title: looot CLI 1.1.0
description: "What changed for looot customers in looot CLI 1.1.0."
type: changelog
date: 2026-09-26
changelog:
  version: 1.1.0
  category: CLI
---

`npm install -g looot` now installs 1.1.0.

## A change you may need to make

`looot token` prints your secret to stdout, so it now needs `--reveal`, on a terminal and in a
pipe alike. Before this release it printed into any pipe, and an agent's shell is always a pipe,
so an agent's token could land in its own logs.

If your shell profile has:

```bash
export LOOOT_TOKEN="$(looot token)"
```

change it to:

```bash
export LOOOT_TOKEN="$(looot token --reveal 2>/dev/null)"
```

With the old line, `LOOOT_TOKEN` is empty after upgrading. `looot doctor` flags this. The CLI
itself keeps working from your saved login either way.

## Fixed

- Signed-out `looot catalog endpoints` follows the paging cursor to the end (it used to repeat
  page 1), and says when your `--limit` was capped.
- `--wait` is validated before sending: `--wait=abc` or a value outside 0 to 60 whole seconds now
  gets a clear message. It used to get a generic error or a silent cap.
- `looot search` with no text says it needs search text, with an example.
- `looot runs evidence` shows evidence fields (an input fingerprint, ledger references), separate
  from `runs attempts`.

## Better results, no upgrade needed

These landed on the gateway, so they apply to every CLI version:

- For a job the catalog doesn't cover, search says "no provider does this job yet". It used to
  list unrelated endpoints.
- Filtering by a job name search already recognizes returns that job's endpoints.
- The cheapest reliable provider ranks first for phone lookup, scraping to markdown and
  backlinks.
- Validation errors name the field that failed.
- Run results never include a provider account's own remaining credits.
