v0.9.0

tashfeenahmed/freellmapiv0.9.0Aug 26, 2026by tashfeenahmed

AI Summary

This release introduces an opt-in Fetch Relay transport for outbound proxying, allowing requests to be forwarded through a hosted endpoint like a Cloudflare Worker. It also includes Docker container fixes for volume ownership on specific platforms and updates for macOS app signing/notarization.

Key Highlights

  • New Fetch Relay transport for bypassing regional blocks
  • Docker entrypoint fix for root ownership on Railway and Render
  • macOS app signed and notarized
  • Streaming usage estimation when upstream omits data

New Features

  • Fetch Relay transport
  • Usage estimation for streaming responses

Full Release Notes

## Outbound Fetch Relay (opt-in)

- New **Fetch Relay** transport for the outbound proxy (#975, by @w0fv1). Instead of a CONNECT or SOCKS proxy, provider requests can be forwarded through a relay endpoint you host, such as the Cloudflare Worker in `examples/fetch-relay-worker/`. Useful when a regional block sits between you and a provider and you can deploy a Worker but not run a proxy box.
- Off by default: the transport only activates when you pick it in Keys → Outbound proxy, or set `PROXY_MODE=fetch-relay` alongside `PROXY_URL`. Existing `PROXY_URL` / `HTTPS_PROXY` / `ALL_PROXY` values keep the forward transport.
- Relay URLs must be `https://` (loopback excepted), the relay token is encrypted at rest and never returned by the API, streaming and abort pass straight through, and the Test button now reports a relay side 401/403 as a failure instead of success.
- Bear in mind that a relay terminates TLS, so it sees the provider key and request body. Only point this at a relay you control. See `docs/fetch-relay.md`.

## Docker

- The image now starts through a small root entrypoint that fixes ownership of `/app/server/data` (and the directories behind `FREEAPI_DB_PATH` / `FREEAPI_DB_BACKUP_PATH`) before dropping to the `node` user (#972, by @hiiamwaffledev). This fixes the `SQLITE_CANTOPEN` / `EACCES` failure on Railway, Render and similar hosts that mount persistent volumes as root. The chown is skipped when ownership is already right and never aborts startup if it cannot run.
- Note for Kubernetes users: the image's default user is now root at start. The node process itself still runs as uid 1000, but a `runAsNonRoot: true` policy will reject the image; set `runAsUser: 1000` explicitly, in which case the entrypoint skips the chown.

## Streaming

- When a client asks for usage via `stream_options.include_usage` and the upstream never sends a usage frame, the gateway now emits one with its own estimate, flagged `"estimated": true` so cost tooling can tell it apart from provider-reported numbers (#686, by @oppih). Image tokens are included in the estimate.

## Desktop

- Mac builds are signed and notarized, including the DMG itself, so the right-click → Open workaround is no longer needed (#1034, #1035, #1036). Closes #373 and #943.

Full changelog: https://github.com/tashfeenahmed/freellmapi/compare/v0.8.9...v0.9.0

---
⭐ Like the free router? [Go Premium](https://freellmapi.co/?utm_source=github&utm_medium=release&utm_campaign=premium&utm_content=v0.9.0#pricing) — the live signed catalog, $19/yr, cancel anytime.