Changelog
All notable changes to Curva. The format follows Keep a Changelog
and versions follow Semantic Versioning. The HTTP API v1 contract is frozen:
breaking API changes go to /v2.
[Unreleased]
Section titled “[Unreleased]”0.1.0 - 2026-09-30
Section titled “0.1.0 - 2026-09-30”First public release: the curva binary (CLI + HTTP server), the curva-ai Python and
TypeScript SDKs and the n8n-nodes-curva n8n node, all free to use under the Curva Free License.
- Core engine: Choice, Score and Noul questions answered through any OpenAI-compatible
model, read from logprobs or from a constrained JSON reply (
mode: auto | logprobs | verbal), with a label-mass guard, a rate limiter, retries and cost tracking.curva spikeandcurva benchmeasure accuracy, ECE and cost on the eval sets. - Server and Python SDK:
curva servewithPOST /v1/decideandGET /health, clear JSON errors, and an LRU decision cache (repeats in 0 ms at $0). Stdlib-onlycurva-aiSDK with retries andsystem_one/criteria=aliases. - Reliability: order debiasing (on by default), a
none_of_theseescape option,min_confidenceabstain, model fallback chains, a daily budget (CURVA_DAILY_LIMIT) and injection hardening. - Calibration: temperature and Platt scaling per question and per
project, fromPOST /v1/feedback, plus bias scaling (a per-answer offset that fixes a model favouring one answer) for Choice and Score; from 30 labels a calibrator is applied only when it clearly beats the raw probabilities on held-out folds in both log-loss and Brier score, moving cautiously with few labels.GET /v1/calibrationreports held-out before/after numbers. SQLite store (--db),curva bench --saveandcurva report. - Power features:
Multiquestions, Council (blended models withagreement), Cascade (escalate only unsure answers), Race, few-shotexamples,explain: trueattribution, andcurva mapfor large, resumable JSONL jobs. - Production: API keys (
curva keys, stored hashed) with per-key rate limits andRetry-Afteron every 429; the server refuses public addresses without keys. Per-project provider keys encrypted withCURVA_MASTER_KEY, an audit log (GET /v1/audit, state hashed, never stored), pinned configs (curva-1.0.0,curva-1.1.0),privacy: "strict", Prometheus/metrics, graceful shutdown, and a distrolessDockerfile. - Any model, any provider:
@<provider>/<model>ids for OpenAI, Anthropic, Gemini, Groq, Mistral, DeepSeek, Together, Fireworks, xAI and OpenRouter (on when their usual API key is set), local Ollama, LM Studio, vLLM and llama.cpp, and any OpenAI-compatible endpoint (CURVA_PROVIDER_<NAME>_URL). OpenRouter is optional. - Own fast model:
curva exportturns decisions and feedback into fine-tuning data in Curva’s own prompt format; a guide covers fine-tuning and serving a small model. - Cache-friendly prompts: pinned config
curva-1.2.0puts the questions before the state, so provider prompt caches and local prefix caches reuse the repeating part. - Pro features: conditional questions (
whenwith the rule operators; skipped answers cost nothing), a drift monitor (GET /v1/drift), shadow mode (curva shadow), Curva Tune (curva tune), seven recipe packs (curva recipe: support triage, content moderation, lead qualification, phishing check, LLM output QA, RAG check, RAG rerank), and an MCP server (curva mcp) for AI agents. - SDKs: a TypeScript/JavaScript SDK (
curva-aion npm), and in Python an async client (AsyncCurva,decide_many), typed error classes, request ids and level names. - Operations: structured request logs (
CURVA_LOG=json,CURVA_LOG_LEVEL) with anx-request-idon every response. - Docs: a documentation website (MkDocs), a public benchmark page, and a contributor CLA.
- Packaging:
pip install curva-aiships thecurvabinary inside platform wheels, andcurva.local()starts it on a free localhost port and stops it at exit. - Scale and speed: Choice takes up to 255 options (over 20, answered in verbal mode with the
top 5 labels),
racereturns the first valid answer of several models, and a compatiblePOST /v1/systemoneroute withcriteriarequests, plusGET /v1/models. - Workflows in one call:
depends_onon any question runs a request as a graph, stage by stage (one model call per stage, at most 8), each dependent question seeing its dependencies’ answers;@keyfields inwhenand rules branch on earlier answers. Per-questionthink: truereasons in its own concurrent call. Answers getstage. Python.depends()/think=, TypeScriptdependsOn()/think. - Rules: answer a question from the state without a model call (
rules: [{"if": ..., "answer": ...}]), withcontains,starts_with,gt,gte,lt,lteandexists. - Extraction:
text,numberandintegerquestions return a typed value with a confidence. - Images:
imageson a request sends https ordata:images to vision models. - Guaranteed accuracy:
coveragereturns a conformal prediction set that holds the true answer with the chosen probability, once a question has 30 labels. debias: "auto": stops asking the reversed order once a model shows no position bias.- Dashboard and OpenAPI:
GET /dashboardandGET /openapi.json. - n8n node (
integrations/n8n-nodes-curva) and the TypeScript SDK. - RAG recipes:
rag-check(needs retrieval, answerable, grounded, next step) andrag-rerank(passage relevance as a reranking score). - Z.ai (GLM) and Alibaba (Qwen) presets:
ZAI_API_KEY,DASHSCOPE_API_KEY. CURVA_PROVIDER_<NAME>_PRICE: input and output price per million tokens for providers that don’t report cost (fine-tuned or self-hosted models).- Zero-setup server:
curva servewithout--modelpicks a working default from whichever provider key is set, like the Python client. - Costs:
cost_usdfrom the provider’s report, OpenAI and Anthropic list prices, orCURVA_PROVIDER_<NAME>_PRICE. - Batch parity:
curva map,shadow,benchandtunerun questions exactly like the API (stages,when, rules,think);bench --per-setandtunetake label-balanced samples. - Hardening (pre-release audit): at most 64 model calls per request, 60 s provider timeouts,
a 120 s request deadline and a 30 s shutdown grace, a hashed decision-cache key scoped to project,
privacy and provider key, provider errors kept in the server log (never sent to callers), JSON 413s,
a total size limit on question text, reserved control characters in question keys, a
case-insensitive prompt fence, a salted audit hash, SQLite
busy_timeout, and--lockedDocker builds. The server’s provider endpoint variable isCURVA_PROVIDER_URL(the SDK keepsCURVA_BASE_URLfor the Curva server).

