Changelog
A security release for every Aktar
Aktar 0.18.0 is a security release from a review of every Aktar app, the aktar CLI and the Raycast extension. It closes ways another app, a web page or a shared file could get Aktar to do something you didn't ask for. Most of it works without you noticing. A few things now ask first, and if you use automation apps on Android or Aktar's MCP server, there's one step for you below. Aktar for Windows, the iPhone and Android app get the same fixes. If you're on 0.3.0 or later, Aktar offers it automatically.
- Mac0.18.0
- Windows0.11.0
- iPhone & iPadcoming soon
- Androidcoming soon
Other apps ask before they upload
When another app sends files to Aktar through the Services menu (Upload with Aktar) or the Share menu, Aktar now asks first, naming the files and the destination they'd go to. Uploads you start from Finder go up right away, as before. On the iPhone and Android, aktar:// links from a web page or another app only open the screens they're meant for. On Windows, a link that resumes paused watched folders asks too.
See where an imported destination sends things
A destination from Import from Another Device can bring more than keys. Before anything is saved, Aktar now shows where it sends your files and links: the storage and link hosts, the short link service, each webhook and script, its Use For rules and its output template. Webhooks and scripts come in turned off, and Use For rules and the template are left out, unless you keep them. When you update a destination you already have, its own webhooks, scripts and Use For rules stay as they were unless you keep the imported ones. Aktar for Windows, the iPhone and Android show the same review.
Your token only goes to Aktar
The local API can now prove it's Aktar without anyone sending the token first. The aktar CLI 0.6.0 and the next Raycast extension update check this before they send your token, so if Aktar isn't running and some other program answers on its port, it gets neither the token nor your files. They need Aktar for Mac 0.18.0 or Aktar for Windows 0.11.0 or later, and say so when Aktar needs an update. Connect Raycast also only hands the token to Raycast itself, checked by its signature.
AI agents start with less
aktar mcp in CLI 0.6.0 uploads only from the folders you give with --root, or else from the folder the agent starts it in. If that's your home folder or the top of the disk, as some apps do, it uploads no local files until you add --root. SSH and private keys, .env files, cloud credentials, password databases and browser profiles are never uploaded, wherever they are. replace_file needs --allow-replace (or --allow-delete), since it overwrites a file like a delete would. Temporary links last at most 60 minutes unless --max-link-minutes allows more, the clipboard tool is left out when you give --root, and --log keeps a record of every tool call. The setup on the MCP page now includes --root.
On your phone
If you use Tasker, MacroDroid or another automation app with Aktar on Android, turn on Settings › General › Allow automation apps after updating. Until you do, automation apps can't upload through Aktar or receive its links. While it's on, any app on the phone can, as the setting explains, and each upload's details show which app asked for it. Files shared to Aktar from other apps are deleted once Aktar has its own copy, and a shared web link is no longer fetched in the background. Webhook addresses, which often contain a secret, move to the Keychain or Keystore, and notifications show only the webhook's host. Link shortener and webhook requests no longer follow a redirect to another host, and links in previewed files only open web addresses.
All changes in this release
New
- Local API:
GET /v1/hellolets the CLI and Raycast check they're talking to Aktar before sending the token.
Improved
- Files sent from another app through the Services menu or the Share menu are only uploaded after you confirm. Aktar names the files and the destination. Uploads from Finder aren't asked about.
- Import from Another Device shows where the destination sends files, links, short links, webhooks and scripts before saving it. Webhooks and scripts come in off, and Use For rules and the output template are only kept if you choose to.
- Updating an existing destination from an import keeps its own webhooks, scripts and Use For rules unless you keep the imported ones.
- Connect Raycast only hands over the local API token to Raycast itself. Otherwise nothing is shared and Aktar says why.
- The local API refuses uploads larger than the free disk space (keeping 2 GB free) and more than 32 connections at once.
- Watched folders only upload, move to Trash or move to Uploaded a file that's still the one Aktar checked. An Uploaded folder that's a link to another folder is never used.
- Files from a Shortcuts action always stay in Aktar's temporary folder, whatever their name.
- XSLT stylesheets, .shtml pages and web archives (.mht, .mhtml) download when their link is opened, like HTML, instead of running on your bucket's domain.
- Thumbnails of bucket files are made from a download under a safe file name, whatever the file's key.
- aktar CLI 0.6.0:
aktar mcpuploads only from--rootor the folder it runs in and never secrets, offersreplace_fileonly with--allow-replace, caps temporary links at 60 minutes (--max-link-minutes) and logs tool calls with--log.