Release Notes
What changed in each MARS-Curiosity release, newest first. Each entry is a one-liner with a link to the documentation, the demo or the issue; the GitHub release has the full notes, upgrade notes included.
Unreleased
Changes on the develop branch, part of the next release.
New
- Linux daemon:
--foreground(or-f) runs the server in the current process with logs on standard output, for systemd (Type=simple) and Docker. Deployment - Documentation: Deployment guide (Windows service, systemd, Docker, reverse proxy, HTTPS, IIS/Apache/FastCGI), Why MARS?, FAQ;
llms.txtandllms-full.txtfor AI tools, sitemap.
Fixed
- Linux daemon: the log file only held its last line.
- Documentation: the footer stated the wrong license (MARS is released under the Mozilla Public License 2.0).
1.8.1
latest 7 October 2026 · GitHub release · changes since 1.8.0New
- Client logging:
OnLog,RegisterLogger,LogOptions(content, masking), ready-made sinks, server-sent events streams. Client logging - Server JSON log: custom entries with structured data (
Log<T>),JSONLogging.BuiltInEntries(#211). Custom entries - Shared configuration files:
[Include]section in.inifiles;.iniparameter names are case insensitive. Shared configuration - OpenAPI:
[MetaRequestBody]documents a body read by the method itself (the token resource uses it). OpenAPI - DCS server: HTTPS without a reverse proxy (
PortSSL,DCS.SSL.CertFile,DCS.SSL.KeyFile);IMARSRequest.IsSecure. HTTPS - Indy server:
Indy.KeepAliveparameter, enabled inMARSTemplate. Engine parameters - Templates: one
Server.inishared by all the server flavors;MARSTemplateDCSaligned withMARSTemplate, Windows service and Linux daemon on DCS. MARSTemplate - MARSCmd: choice of the template (
MARSTemplate,MARSTemplateDCS); new projects inDocuments\MARS Projects. MARSCmd - Delphi-Mocks is a git submodule (
ThirdParty/Delphi-Mocks).
Fixed
- DCS server: 404 on every request, content stream leak, query string, cookies not
HttpOnly, static files downloaded as attachments, JSON request bodies not received. - OpenAPI: request body of methods without
[Consumes](#212). - Setup: the uninstaller deleted the user projects in the
Demosfolder. - MCP: OAuth metadata used
http://for a server reached in HTTPS without a proxy.
1.8.0
5 October 2026 · GitHub release · changes since 1.7.1
New
- JWT key rotation:
JWT.KeyId,JWT.PreviousSecret.<kid>, custom key providers (#82). Key rotation - MCP Apps: interactive HTML views for MCP tools (
[MCPToolUI],[MCPAppResource]). MCP Apps · MCPServer demo - MCP: optional tool parameters with
[MCPDefault]. MCP - JSON serialization options from the configuration file (
JSON.*parameters). From the configuration file JSON.EscapeNonASCIIparameter (#208). Non-ASCII characters- TMS Smart Setup:
tms install andreamagni.mars. Installation - delphi-jose-jwt v4 as a git submodule.
Security
- JOSE backend: HS256 only (tokens asking for other algorithms were accepted).
TFileSystemResource: 8.3 short names bypassed the[Exclude]/[Include]masks (#210).
Fixed
MARS.DCSpackage search path (#209); design-time package build; JOSE folder of theMARSTemplateDCSprojects.
Changed
- Delphi 10.4 Sydney is the minimum supported version.
1.7.1
25 September 2026 · GitHub release · changes since 1.7.0
New
- Delphi 13.2 support.
Fixed
- Large arrays of records sent by Win32 clients exhausted memory (#205).
- Large arrays of records read by the server built the whole JSON tree (#206).
- Applications not using JWT required
JWT.Secret(#207). Authentication
1.7.0
17 September 2026 · GitHub release · changes since 1.6.4
New
- MCP server support: tools, resources, prompts, FireDAC tools, per-tool roles, OAuth 2.1 authorization server. MCP servers · MCPServer demo
- Agent Skills for Claude Code and other AI coding agents. AI Agent Skills
- This documentation site.
QUERYHTTP verb, server and client side (#191). HTTP verbsTFileSystemResource:HEADrequests,[DotSegments](#204),[DirectoryListing]. Path safety- OpenAPI: more of the specification through attributes. Enriching the spec
TMARSReqRespLoggerJSON: JSON log files for Grafana/Loki. File logging for Grafana- Tailwind CSS demo. Tutorial
Security
- Path traversal in
TFileSystemResource(#195). - New projects get their own JWT secret (#201, #202).
- In-memory logger always on once its unit was included (#197).
Fixed
- Repeated query parameters (#196), directory listing (#198), JSON to record/object (#199, #200), MCP OAuth behind a proxy (#203).
- A malformed request body answers 400 instead of 500; wildcard routing; tokens and JWT decoding.
1.6.4
5 June 2026 · GitHub release · changes since 1.6.3
New
TMARSHttpClient: client component with server-sent events support. Client components · Server-Sent Events- WebStencils integration. WebStencils
- Demos: SSEDemo, WebStencilsDemo, HtmxDemo.
- JSON:
TList<TPair<string,T>>serialization;TMARSJSONSerializationOptionsreworked. JSON serialization - Tests for parameters, JWT and claims.
1.6.3
15 April 2026 · GitHub release · changes since 1.6.2
New
Access-Control-Allow-Private-NetworkCORS header (#179). CORSIMessageBodyStreamProvider: large responses streamed without loading them in memory. Content negotiation[Headers],[Cookies],[QueryParams],[PathParams]collection binders. Collection binders- Demos: OTPDemo, TokenRenew.
Fixed
- Linux fixes.
1.6.2
22 October 2025 · GitHub release · changes since 1.6.1
1.6.1
30 September 2025 · GitHub release · changes since 1.6.0
- Setup compatible with Delphi 10.2 (#172).
1.6.0
11 September 2025 · GitHub release · changes since 1.5.9
New
- Delphi 13 Florence support (#170).
MARSTemplateServerFCGI: FastCGI server for nginx inMARSTemplate. MARSTemplate
Fixed
- Date serialization options were ignored (#169).
1.5.9b
1 August 2025 · GitHub release · changes since 1.5.9
New
PATCHHTTP verb (#168). HTTP verbs- Error objects: structured error bodies, server and client side. Error handling · ErrorObjects demo
Fixed
- Custom headers of the Indy client.
1.5.9
27 June 2025 · GitHub release · changes since 1.5
New
IMARSEngineandIMARSApplicationinterfaces throughout MARS. Engine- More JSON serialization options, with more granularity. Serialization options
AfterContextCleanuphooks, by attribute and throughTMARSActivation. Request lifecycle- Setup (installer) (#166). Installation
Fixed
- Delphi version detection (#142),
TryISO8601ToDateon Delphi XE7 and earlier (#145), #141 and others (#146), resourceConstructorFuncnot called (#156).
Older releases
See the GitHub releases.
