Changelog

Every release, newest first

  1. v0.191.0 2026-10-03 latest
    The Artifact panel shows a .pptx as real slides, not a text outline (#4019).
    A missing work folder no longer takes every filesystem tool with it, and a re-cloned one comes back in the same session (#3643).
    Text the agent streams before a tool call no longer disappears from the chat (#4015).
    A reload or reattach in the middle of a turn keeps the agent's pre-tool text on screen (#4016).
    A chat answer no longer flashes as raw markdown before it renders (#4018).
    A streaming chat answer no longer flashes stray markdown symbols (#4020).
    The Browser panel's address bar now follows the tab (#4021).
    Review at head reads the strictest panel round for a head, as QA panel does (#4022).
    A hung gh call can no longer stall the required Review at head check (#4023).
  2. v0.190.0 2026-10-02
    The code pane updates itself — no more Refresh to see a delegate's edits (#4006).
    A foreground delegate_to that times out on a still-working A2A peer now hands back a collectable task (#3775).
    A2A runs on a2a-sdk 1.2.1, and a HITL answer is still re-routed when its task ends mid-flight (#3950).
    resolve_friction now finds what the agent logged and says when it is already resolved (#4000).
    Context compaction no longer fails anthropic-oauth turns with a fake 429 (#4001).
    An @<name> address now bills the peer's reported spend, and turns no model ran stay out of the per-model breakdown (#4004).
    One oversized image no longer breaks every later turn of a session (#4005).
    The code pane's change poll no longer re-reads touched files, and A2A peers can't fake file changes (#4007).
    A goal now visibly goes green when its verifier passes (#4008).
    /goal new can no longer start a second turn in a tab that is already busy, and goal events refresh only the goals list (#4009).
    A streaming A2A peer's delegation card no longer types out the peer's final answer before the chat renders it (#4010).
    A goal's turn now stops once its check passes, ends on a short summary, and prints "Goal set." once (#4012).
    A2A refuses a send whose contextId / taskId sits on params instead of the message (#4013).
    The fleet console proxy now forwards the raw member path and rejects ambiguous encodings (#3999).
  3. v0.189.0 2026-10-02
    A delegation to another agent over A2A now shows that agent's live work on its card too (#3980).
    Brand & Launch replaces the Social Marketing archetype — a draft-only launch manager for any app, held from the picker until it's been tested (#3981).
    Plugins can find the managed Python runtime through the SDK (#3992).
    Plugins that watch a coding agent through dispatch_tapped now see its plan as it changes (#3995).
    Operator API status codes and validation changed for clients (#3973).
    The parked-sessions index reads the task store once (#3972).
    Console pollers stop on a task state the server can't name (#3972).
    Checkpoint pruning, knowledge forget-delete, and the non-streaming turn's HITL check hardened (#3973).
    Operator API routes no longer leak internals or die on bad input (#3973).
    A fresh install's agent card describes protoAgent instead of a template placeholder, and the default-on cowork pack's optional document libraries no longer warn on first boot (#3976).
    A /<subagent> slash run that keeps working is no longer cut off by the stall guard (#3977).
    "Test connection" and the model list now probe the lead model's own connection (#3978).
    A coding-agent delegation now shows its live work on its card, and its reply no longer opens with the same sentence twice (#3979).
    The Install-from-URL dialog shows the whole git URL (#3982).
    Settings ▸ Plugins no longer says a plugin's console view or background surface needs a restart (#3988).
    Updating, re-installing or uninstalling a plugin no longer asks for a restart it doesn't need (#3990).
    Three small follow-ups from the #3984/#3986/#3987 reviews (#3991).
    A background subagent sees only the tools its fence allows (#3994).
    The agent's set_config tool can no longer point a plugin at a program to run (#3992).
    A plugin can no longer make the core plugin update and enable routes reachable without auth (#3997).
    README is now a launch landing page (#3975).
    New "Network egress" page lists every outbound call protoAgent makes on its own (#3976).
    README states the privacy claim the egress audit backs (#3989).
  4. v0.188.0 2026-10-01
    A long /<workflow> step is no longer cancelled for being quiet (#3940).
    A /<workflow> whose output step failed ends its turn as failed (#3940, #3957).
    Workflow runs record why they stopped (#3940, #3957).
    Steering and workflow cleanup (#3940).
    Restart, schedule and watch edge cases no longer leave stale state or 500s (#3943).
    A rejected chat turn now shows as failed, and parked chats come back in a fresh browser (#3957).
    Smoke follow-ups: honest telemetry, explicit model-override errors, and error statuses (#3957).
    Desktop agents keep their note after upgrading (#3967).
  5. v0.187.0 2026-10-01
    Goal-driven turns get their own round cap, goal.max_rounds_per_turn (#3957).
    A per-request model override now reaches every subagent run (#3955).
    Console: a turn parked on an ask_human question now waits for you live and keeps its form across a reload (#3956).
    Concurrent turns each deliver their own projected context (#3958).
    A resumed turn's context recompose now retrieves for the turn's own input and is logged (#3960).
    Console: a question the agent asked again after a plain message now keeps its form, in a fresh browser and after a reload (#3963).
    A goal-driven turn applies the goal's tool scope before pre-turn dispatch (#3964).
September 2026 34
  1. v0.186.0 2026-09-30
    Background maintenance loops now live in server/maintenance_loops.py (#3807).
    Console: lib/api.ts split into slug-routing, HTTP and A2A-stream modules (#3808).
    Chat session ops now live in server/chat_session_ops.py, and the non-streaming usage helpers in server/turn_telemetry.py (#3810).
    Plugin wiring moved out of server/agent_init.py (#3821).
    Console: the Workflows and Model ▸ Connections surfaces now read the DS radius + spacing scales (#3887, Refs protoContent#525, Refs protoContent#547).
    Console: the Plugins and folder/file Path-picker surfaces now read the DS radius + spacing scales (#3887, Refs protoContent#525, Refs protoContent#547).
    Bump @protolabsai/design to ^0.11.0 and @protolabsai/ui to ^0.66.1; tokenNameGuard accepts _ in token names (#3887).
    Console: the Work hub overview and the app menu drawer read the DS radius + spacing scales (Refs protoContent#525, Refs protoContent#547).
    Console: the Settings surface and the Keyboard rebind list now read the DS radius and spacing scales (protoContent#525/#547).
    Console: app/theme.css + docviewer.css radius & spacing literals now read the DS radius/spacing tokens (Refs protoContent#525, Refs protoContent#547).
    Console: chat.css and hitl.css radius + off-scale spacing now read DS tokens (protoContent#525/#547).
    Console palette button + crash screen adopt the DS spacing scale (#3688, protoContent#547).
    Console: Fleet Room's roster and activity feed now read the DS radius and spacing scales (protoContent#525, protoContent#547).
    Console: the archetype picker's "What's included" control is now a DS Button (#3832, protoContent#551).
    Console: the per-shortcut "reset to default" control in Settings ▸ Keyboard is now a DS Button (#3832, protoContent#551).
    Console: chat action controls now use the DS Button primitive (#3832, protoContent#551).
    Console: the MCP catalog "All servers" back control is now the DS Button (#3832, protoContent#551).
    Console: the month calendar's prev/next controls are DS Buttons (#3832, protoContent#551).
    Console: the mobile header's Back, Menu, Search and New-chat actions now render via the DS Button (#3832, protoContent#551).
    Org Chart view's Refresh and panel Close buttons now use the DS plugin-kit button (#3832, protoContent#551).
    Console: the ScheduleBuilder 12h/24h toggle is now a DS Button (#3832, protoContent#551).
    Console: the chat tool-call value renderers read the DS radius and spacing half-step tokens (protoContent#525, protoContent#547).
    Console: a tree-wide guard pins radius & off-scale spacing literals out of every console stylesheet (Refs protoContent#525, Refs protoContent#547).
    Console: Settings ▸ Devices and the Telemetry dashboard now read the DS radius and spacing scales (protoContent#525, protoContent#547).
    Console: the mobile shell, delegates form and watches panel now read the DS half-step spacing scale (Refs protoContent#525, Refs protoContent#547).
    Console: Activity feed and Identity panel read the new DS radius + spacing tokens (protoContent#525/#547).
    Console: the Tools panel and Goals side-panel CSS read the DS radius and spacing half-step tokens (protoContent#525, protoContent#547).
    Console: Code pane and Fleet manager read the new DS radius + spacing tokens (protoContent#525/#547).
    Console: the schedule builder and agent-snapshot CSS move border-radius and off-scale spacing onto DS radius/space tokens (protoContent#525, protoContent#547).
    Console: the chat inline-component and prompt-viewer surfaces read the DS radius and spacing half-step tokens (protoContent#525, protoContent#547).
    Console: the three sanctioned composite raw-<button> controls carry the DS-audit hand-rolled-control line-level exception (#3832, protoContent#551).
    onboard_project says when it re-cloned a registered project's missing checkout (#3643).
    /v1, /api/chat and plugin turns now recover from a context-window overflow and run /<subagent> commands (#3805).
    Chat stream survives one malformed SSE frame (#3811).
    Windows run_command can run commands with quoted paths (#3813).
    Redacting a secret no longer eats the closing quote or backtick after it (#3816).
    fetch_url reports a redirect loop instead of returning the redirect stub as the page (#3817).
    An ACP turn now stops when its client goes away (#3837).
    A chat turn abandoned mid-stream now releases its thread lock and flushes its trace right away (#3870).
    A failed chat turn is now recorded on the thread it ran on (#3871).
    A no-reply turn is now a failed turn on /v1, and auto-answered turns keep their early text (#3873).
    An A2A turn now releases its thread lock and flushes its trace before the turn returns (#3876).
    Closing a streaming chat turn early now closes its inner turn generators too (#3877).
    Goal turns over /v1, /api/chat and plugin surfaces no longer fail when two approval-gated tools pause at once (#3884).
    Goal-driven and autonomous turns now behave the same on the streaming and non-streaming chat paths (#3891).
    The per-turn tool allowlist now applies to every graph pass of a turn (#3908).
    Tool-fenced turns follow one set of rules across streaming dispatch, resumes and held messages (#3926).
    Native Codex (ChatGPT OAuth) turns no longer fail with Langfuse tracing on (#3928).
    Five server gaps from a dev smoke are closed (#3929).
    A paused HITL turn no longer hangs a fresh browser, and answering it no longer orphans the task that paused (#3930).
    Non-streaming chat surfaces a HITL question even when the turn also wrote text (#3931).
    Three turn-lifecycle leaks closed: orphaned /workflow runs, stranded server-turn controls, stale steering queues (#3933).
    Unfenced turns start unfenced; work a fenced turn leaves behind stays fenced (#3939).
    Concurrent config reads and writes no longer corrupt each other's YAML parse (#3941).
    A turn's model override now reaches its subagents and background jobs (#3944).
    Non-streaming telemetry rows get their trace id and A2A's statuses; failed background jobs keep their error (#3945).
    An unknown goal verifier is refused on every entry point; /v1 answers 502 for an unreachable gateway; workflow replies lose the raw subagent marker; the workflows plugin's config no longer collides with core; a parked turn renders as paused (#3946).
    A fenced message on an ACP-runtime agent is refused instead of run unrestricted (#3846).
  2. v0.185.0 2026-09-29
    execute_code spills long output to a file instead of dropping it (#3701).
    onboard_project(refresh=true) fetches and fast-forwards an existing clone (#3733).
    Langfuse: Claude Code coder runs now trace every model call. Its native OTel spans nest under the acp: span through a local relay that strips account identity and maps token usage (#3742).
    Model in-flight limiter settings (#3760).
    Per-lane in-flight limiter core for model calls (#3760).
    Model lane telemetry: queue depth, wait time, GET /api/telemetry/llm-lanes (#3760).
    Priority classes for the model in-flight limiter (#3760).
    Model calls acquire a per-lane in-flight slot when model.max_inflight is set (#3760).
    Fleet Room composer moves onto the design system (#3683).
    Remaining hand-rolled form controls move onto the design system (#3683).
    Fleet Room roster + diagnostics controls move onto the design system (#3683).
    Background-agents dialog markup moved to design-system Button + Accordion (#3684).
    Mobile session switcher rebuilt on the DS Drawer (#3684).
    Utility-bar pills use the design-system Button (#3684).
    Utility-bar chrome now uses DS Button (#3684).
    App chrome no longer re-implements the design system (#3684).
    App shell, tools rail and the protoLabs icon drop their dark-only token fallbacks and legacy --brand-* aliases (#3685).
    The last legacy --brand-* accent aliases are deleted and the token-hygiene invariants go tree-wide (#3685).
    Chat stylesheets drop dead literal fallbacks in var(--pl-*, …) reads (#3685).
    Code viewer, activity feed and schedule builder drop their dark-only token fallbacks (#3685).
    Settings and Memory stylesheets drop their dark-only hex fallbacks and legacy --brand-* aliases (#3685).
    Console: drop the dead literal var(--pl-X, …) fallbacks in fleet-room / fleet-activity / work / hitl CSS (#3685).
    Drop dead literal var(--pl-*) fallbacks in goals/memory CSS (#3685).
    The stale-fallback cleanup goes tree-wide: no var(--pl-…, <literal>) fallback may ship (#3685).
    Web: dropped dead literal var(--pl-*, <fallback>) font fallbacks in four DS-token sites (#3685).
    Telemetry, schedule and snapshot stylesheets drop their literal var(--pl-…, <literal>) fallbacks (#3685).
    Workflows surface CSS drops its stale dark-only hex fallbacks (#3685).
    Feed pill unread badge is now the DS Count primitive (#3688).
    Tabbed AppShell columns use the DS <Tabs attached> fused-surface layout (#3688).
    Chat ▸ chat / prompt-viewer / chat-component / HITL stylesheets adopt the DS type scale (#3688).
    Console: drop the app-wide .pl-dialog__body padding rule now that dialogs carry the DS padding prop (#3688).
    Console: edge-to-edge content dialogs opt into DS 0.63 <Dialog padding="none"> (#3688).
    Console: mcp-catalog, docviewer, knowledge & memory content dialogs opt into DS 0.63 <Dialog padding="roomy"> (#3688).
    Console: schedule & settings content dialogs opt into DS 0.63 <Dialog padding="roomy"> (#3688).
    Content dialogs opt into DS Dialog padding="roomy" (#3688).
    Console: content dialogs opt into DS Dialog padding="roomy" — utility pills (#3688).
    Console: playbook & plugin content dialogs opt into DS 0.63 <Dialog padding="roomy"> (#3688).
    Content dialogs opt into DS Dialog padding="roomy" (#3688).
    Console: bumped @protolabsai/design to ^0.10.0 and @protolabsai/ui to ^0.62.1 for the DS type scale (#3688).
    Console literal-font-size guard (#3688).
    Composer model menu adopts the DS base .pl-menu scroll cap and Menu className (#3688).
    Settings ▸ Path picker / Telemetry / Providers / Delegates stylesheets adopt the DS type scale (#3688).
    Settings ▸ Plugins / Snapshot / Devices / Keyboard stylesheets adopt the DS type scale (#3688).
    Schedule builder, activity feed and code-pane font-sizes move onto the DS type scale (#3688).
    Console: docviewer + fleet font-size onto the DS type scale (#3688).
    Console: app/theme.css font sizes move onto the DS type scale (#3688).
    Console: fleet-room / fleet-activity / app-drawer / work overview font sizes move onto the DS type scale (#3688).
    Console: shell / mobile font sizes move onto the DS type scale (#3688).
    Console: workflows / goals / watches / agent-identity font sizes move onto the DS type scale (#3688).
    Console DS foundation: bump @protolabsai/ui to ^0.63.0 and @protolabsai/design to ^0.10.1 (#3688).
    The shipped Design System Engineer persona preset now reflects the archetype's current reach (#3719).
    Theme, fleet and devices stylesheets drop their literal var(--pl-…, <literal>) fallbacks (#3774).
    App theme + docviewer stylesheets adopt the DS spacing scale (#3688).
    Workflows / plugins / path-picker stylesheets adopt the DS spacing scale (#3688).
    Providers connections stylesheet adopts the DS spacing scale (#3688).
    Chat + HITL stylesheets adopt the DS spacing scale (#3688).
    Chat-component + prompt-viewer stylesheets adopt the DS spacing scale (#3688).
    Fleet Room / Fleet Activity / Work overview / app drawer stylesheets adopt the DS spacing scale (#3688).
    Activity / code pane / identity / fleet stylesheets adopt the DS spacing scale (#3688).
    Snapshot / devices / schedule / telemetry stylesheets adopt the DS spacing scale (#3688).
    Goals / tools / settings / keybindings stylesheets adopt the DS spacing scale (#3688).
    Mobile-shell / tool-calls / delegates / watches stylesheets adopt the DS spacing scale (#3688).
    Theme / settings / memory stylesheets move rem/em font-sizes onto the DS type scale (#3688).
    Chat ▸ chat / tool-calls stylesheets move their rem font-sizes onto the DS type scale (#3688).
    fontSizeGuard now fails on rem/em CSS font-sizes and inline fontSize literals, not just px (#3688).
    Artifact plugin resolves its store through the instance plugin store, honouring the box root (#3644).
    Notes plugin resolves its note through the instance store, honouring the box root (#3644).
    Chat-scoped keyboard shortcuts now fire whenever the chat panel is the active region, not only while the composer holds focus (#3677).
    The code pane no longer drags a wheel-up back to the bottom after opening a file (#3679).
    execute_code: tools.* calls made from threads no longer cross responses (#3681).
    Memory, chat, workflows and the app-crash screen now follow the theme instead of a frozen dark fallback (#3682).
    Console --pl-* token-name guard (#3682).
    Plugin theming bridge: the six legacy curated keys now read the real --pl-color-* tokens instead of retired aliases (#3682).
    Chat accents now follow the workspace/theme accent instead of a frozen dark fallback (#3685).
    Chat, tool-call and prompt-viewer accents now follow the theme instead of a frozen dark fallback (#3685).
    The desktop launcher panel is now a solid surface and every focus ring is a 2px accent ring (#3687).
    browser_eval sends scripts over stdin (#3689).
    Langfuse: board-dispatched ACP coder runs now carry a session, the agent tag and their input; coder tool spans record the real arguments; and every turn records its output, even one with no final model reply (#3690).
    ACP tool cards now show the real file or command, not just the tool kind (read / execute) (#3691).
    Deleting a referenced delegate names its references (#3692).
    Langfuse: non-streaming turns (/v1, /api/chat, HOST.invoke()) now record their reply as the trace output on every path, not only when the turn ends on a final model reply (#3695).
    Langfuse: a coder run started under a non-exported OTel span (such as an a2a-sdk handler span) is now a proper root trace with its session and tags, not a child of a parent that never reaches Langfuse (#3696).
    Streaming model calls honor request_timeout (#3699).
    Background A2A delegations no longer lose a finished peer's reply (#3700).
    execute_code's Exposed-tools setting describes the real default; new additive extra_tools (#3701).
    ACP coder timeouts now count time the machine spends asleep. An 1800s bound no longer holds a board coder for hours on a Mac that sleeps (#3724).
    Langfuse: ACP coder runs trace their real tool durations, model usage and cost, and why they failed; work interrupted by a restart no longer orphans its trace (#3725).
    Removed the orphaned .util-btn CSS (#3684).
    Removed the now-unused shadcn/Tailwind npm deps and components.json from the console (#3686).
    Dropped the dead shadcn/Tailwind CSS wiring from the operator console (#3686).
    run_command runs project code with a scrubbed environment (#3801).
    ADR 0115: gateway in-flight limiter (#3760).
    Operator guide for the model in-flight limiter (#3760).
  3. v0.184.1 2026-09-27
    Console: pair a remote agent with a code instead of pasting its token (#3650).
    Settings ▸ Devices is on for everyone: the settings.devices developer flag is gone (#3651).
    A paired hub now shows up on the remote under its own name, not "protoagent (fleet hub)" (#3671).
    The CLI no longer crashes on a Windows cp1252 console, which failed the v0.184.0 desktop build (#3675).
    A chat that delegated to a peer agent no longer fails every later turn on Anthropic models (#3676).
    An open hub no longer lends a paired remote's token to other web pages (#3662).
    A tokenless instance only answers its own host names and its own console (#3668).
  4. v0.184.0 2026-09-27
    An agent can ask to register a folder outside the onboarding root — you approve it in chat (#3642).
    Agent pairing codes on the remote side (#3645).
    A fleet hub can pair with a remote protoAgent by code (#3646).
    protoagent pair prints a one-time code a hub claims to pair with this agent, and mDNS only advertises from a reachable bind (#3649).
    Dependencies refreshed to what a fresh install resolves today (#3575).
    Re-attaching to a turn that just started no longer fails with "Task not found" (#3575).
    The Engineer's repo-onboard skill now shows you the project, not just a card (#3641).
    A delegate to a remote fleet member now routes through the hub (#3647).
    A workflow step's Langfuse trace now says which run, step and inputs it belongs to (#3565).
    Traces name their agent, and the delegation ledger records what a delegation cost (#3565).
    A code link opens the code pane on the dock you keep it on (#3640).
    The setup wizard no longer crashes on a partial config (#3654).
    search_files no longer crashes on an unreadable subdirectory (#3663).
    A fresh pip install -r requirements.txt no longer installs an older langchain/langgraph than the release ships (#3666).
    The hub proxy no longer hands hub credentials to remote fleet members (#3647).
    Remote fleet members' WebSockets traverse the hub again, and the hub still never lends a credential (#3648).
  5. v0.183.1 2026-09-26
    Fleet members that build FROM protoagent:latest now rebuild when a new base is published (#3574).
    A config reload no longer leaves a plugin's background surface running on the previous registration (#3593).
    The fleet deck no longer re-sends a steer when two turn-end reconciles judge it (#3622).
    New-agent set-up waits for the bundle's questions before Create / Next (#3632).
  6. v0.183.0 2026-09-26
    A new fleet agent inherits the host's Langfuse tracing (#3630).
    Creating an agent from an archetype is two steps — pick, then set up in a dialog (#3631).
  7. v0.182.0 2026-09-26
    Mermaid and SVG artifacts are navigable, and mermaid diagrams can link to the code (#3628).
  8. v0.181.0 2026-09-26
    Engineer archetype — a hands-on pair-programming navigator (#3625).
    The desktop app asks before installing a plugin's Python packages, with the same dialog as the browser console (#3623).
    A workflow run is one Langfuse trace, not one trace per step (#3626).
    New operator guide for the Friction log (#3621).
  9. v0.180.0 2026-09-25
    Artifact chips in chat open the Artifact panel on the exact artifact and version (#3617).
    Plugin dependency checks honour PEP 508 environment markers, and missing deps install from the banner or right at install time (#3618).
    Friction auto-capture no longer logs every shell command as an escape hatch (#3620).
  10. v0.179.0 2026-09-25
    Use a protoAgent from Zed's Agent Panel over ACP — ADR 0111 (#3598).
    Continue a console chat in Zed's agent panel (#3610).
    The code pane and show_code are now an opt-in toolset, off by default (#3613).
    Console and A2A turns land in Langfuse as proper traces again, with a name, input and output (#3607).
    The boot gate no longer flashes "the engine isn't responding" during a normal slow cold start (#3609).
    The boot gate's "isn't responding" failure now waits for elapsed time, not the probe's retry count (#3611).
  11. v0.178.0 2026-09-25
    The code pane's server half: fenced GET /api/fs/file + GET /api/fs/diff, and a show_code tool (#3605).
    Code pane: a read-only file and diff viewer docked beside chat (#3606).
    Apps launched by the desktop server no longer inherit paths into its temporary bundle dir (#3604).
  12. v0.177.0 2026-09-24
    onboard_project clones from any git host, and a new register_local_project registers a directory already on disk (#3599).
    delegate_to(project=…) sends an ACP coding delegate into one registered project for a call, and returns the diff it made (#3600).
    filesystem.run_auto_approve: a safe-command allowlist so read-mostly run_command calls stop asking for approval (#3602).
  13. v0.176.0 2026-09-24
    File paths in tool results open in your editor — Zed by default (#3596).
    open_in_editor: an agent on your own machine can pop a file open in your editor (#3597).
  14. v0.175.0 2026-09-24
    Langfuse traces carry their input and output, and ACP coder runs are traced (#3587).
    The shipped example config declares its providers: registry explicitly (#3128).
    Large-document knowledge ingest no longer silently loses every vector (#3126).
    npm run --workspaces build no longer hard-fails on the desktop app without a frozen sidecar (#3128).
  15. v0.174.1 2026-09-24
    MCP server env: values now expand ~ (#3580).
    The completion guard's give-up log says what the last turn looked like (#3582).
    A reasoning-only turn ends a subagent lane after one nudge, not two (#3584).
    The small-diff code-review recipe's verify step asks for its status line (#3589).
  16. v0.174.0 2026-09-22
    Subagents get context relief (#3576).
    The verifier is asked once for its status line (#3578).
  17. v0.173.0 2026-09-22
    STATE.workflow_run(..., seed_outputs=) re-runs part of a recipe (#3571).
    A deck test no longer flakes on Windows shards (#3564).
    The findings parser no longer ends a fenced block at a ``` inside a JSON string (#3569).
  18. v0.172.0 2026-09-21
    Fleet discovery now finds agents published on this machine's own tailnet address (#3562).
  19. v0.171.0 2026-09-21
    Guard notes are recognised by a tag, not by their text (#3556).
    Subagents are told when their turn budget is nearly spent, and get one chance to add a closing line their caller requires (#3559).
  20. v0.170.0 2026-09-20
    A workflow step's timeout can come from an input (#3554).
    Removing every connection now means every connection is removed (#3128).
    A connection test no longer borrows another connection's key (#3128).
    The review-at-head gate no longer fails open in three ways (#3543).
    A subagent that stops mid-loop is continued, not reported "completed" (#3552).
    Test-file housekeeping (#3550).
  21. v0.169.0 2026-09-17
    Every reader of the default model route resolves its endpoint and key the same way (#3534).
    Settings → Theme opens on a gallery of 28 theme families, each with a dark and a light variant (#3535).
    Theme reset, saved looks and imports stop picking up the agent's theme (#3536).
  22. v0.168.0 2026-09-15
    A room member the room stopped waiting on is no longer lost: its late answer is collected and posted (#3360).
    A2A delegation to a protoAgent peer is now bounded by lack of progress, not by one held-open request (#3360).
    Review-finder lanes get 60 tool rounds instead of 40 (#3532).
    User messages no longer show a sent time; it appears only in the answer's footer (#3458).
    Agents that get their gateway key from the environment now learn their model's context window (#3502).
    A prompt near the context window no longer fails just because of the output reservation (#3502).
    Agent snapshots travel in the provider-registry shape, without changing where the imported agent's model traffic goes (#3521).
  23. v0.167.0 2026-09-14
    The fleet deck finds the desktop app's box root through infra.paths, the same code the workspace port allocator uses (#3507).
    The sent time sits in the usage stats row under an answer, not on a line of its own (#3505).
    The desktop log keeps its history instead of under a minute (#3508).
    An in-app update no longer moves the desktop hub off port 7870 (#3509).
    A subagent's max_turns now buys the tool rounds it promises, not a third of them (#3511).
    A memory fact harvested from an older conversation no longer replaces a newer one (#3512).
    A goal woken by its own wait or watch no longer stalls forever (#3513).
    Incognito chats are no longer archived into memory by compaction (#3514).
    Compaction archives say which chat they came from and when their messages were written (#3514).
    Deleting or clearing a chat can now forget what it already saved to memory (#3514).
    The desktop build now runs the fleet deck it bundles, on every platform (#3516).
    A config loaded with nothing to read, and the plugin gateway_client() before one is loaded, now carry a provider registry (#3518).
    The docs say how to get the protoagent command (#3501).
    The shipped config template and the configuration reference teach the provider registry (#3520).
  24. v0.166.0 2026-09-14
    protoagent fleet talks to the running hub (#3467).
    The fleet deck: protoagent fleet with no arguments (#3468).
    Talk to a fleet member from the deck (#3469).
    Act on a fleet member's turn from the deck (#3470).
    Manage the fleet from the deck and the CLI (#3471).
    Every hub on the box, from the deck and the CLI (#3472).
    The fleet deck ships: in the desktop binary, in the docs, in the ADRs (#3473).
    Frozen desktop servers keep their heartbeats (#3482).
    A new fleet member never takes a port another instance on the machine records (#3492).
    A watch-woken turn no longer mistakes its own wake for another one (#3494).
    Harvested memories carry the date of the conversation, not the harvest (#3494).
    The fleet deck has its own guide, and member ports are documented as machine-wide (#3496).
  25. v0.165.0 2026-09-12
    Social Studio and Blood Bowl are in Plugins ▸ Discover, and the plugin directory now covers every protoLabs plugin repo with an honest status (#2910).
    Plugins ▸ Discover cards now show what a plugin adds and link its docs, like the website's cards (#2910).
    Word .docx files attach in chat and ingest into Knowledge; the desktop runtime can read PDFs again (#3444).
    A bundled plugin can supersede a git-installed copy of the same id (#3445).
    A delegation is one row in the chat, and a chat shows when it still has background work running (#3447).
    The Cowork knowledge-work skill pack ships with protoAgent (#3450).
    Cowork being on also turns on execute_code (#3450).
    The Agent Browser plugin ships in-tree, with a setup gap, a fenced capture directory and page→PDF (#3451).
    Artifacts can be pinned so history eviction never drops them (#3456).
    Chat messages now show when they were sent (#3458).
    The Agent Browser plugin now installs its own CLI, and its setup banners fix what they report (#3464).
    The MCP quick-add catalog is now checked against upstream every week (#2910).
    python-docx is now a core dependency, so a plain server or Docker install reads .docx out of the box (#3462).
    One plugin route can no longer take down /openapi.json (#3437).
    Routes in a plugin's nested sub-router get the JSON error envelope again (#3437).
    Plugin setup-gap banners now actually appear, with their Configure button and dismiss (#3438).
    Expanding a tool card mid-turn no longer collapses it when the turn finishes (#3438).
    A chat rebuilt from the server shows your questions again, and its answers read as paragraphs (#3439).
    A reply to background reports no longer collapses into a card while you're reading it (#3443).
    A message typed into a background, scheduled or watch-triggered turn now lands in the chat instead of sitting "queued" forever (#3446).
    A chat attachment can no longer forge its own attachment block (#3448).
    pypdf floor raised to 6.8 (#3448).
    An @-addressed member's answer no longer appears twice in the chat (#3449).
    A plugin whose Python packages aren't installed now says so, and installing them clears it without a restart (#3450).
    A plugin that moved into core is uninstalled from the dir the loader actually reads (#3452).
    The Work overview e2e no longer depends on which side of midnight the suite runs (#3453).
    The Artifact panel now acknowledges a Download you started (#3454).
    A plugin you placed by hand stays visible, and removable, after protoAgent starts shipping it (#3455).
    An html artifact's own doctype and <head> now survive the Artifact panel (#3457).
    The console e2e suite no longer flakes with "Response has been disposed" when a mocked request is still in flight at teardown (#3459).
    The artifact store no longer loses writes between processes (#3460).
    Agent processes no longer run forever after their server is force-killed or crashes (#3465, #3463).
    Reloading during a server-fired turn no longer leaves the chat stuck "streaming" (#3474).
    A stuck artifact-store writer no longer blocks every other writer forever, and an evicted file can no longer cut a download short (#3475).
    Install deps runs one pip at a time per environment (#3477).
    Discover shows a bundled plugin's real state, and never offers Install for one (#3477).
    cowork.output_dir is gone (#3477).
    A chat no longer stays stuck "streaming" after its turn has ended (#3478).
  26. v0.164.0 2026-09-11
    Runtime status now publishes structured setup gaps beside warnings[] (#3395).
    Plugin setup gaps now render as actionable, dismissible console banners (#3421).
    Two settings changes at the same moment no longer silently drop one of them (#2743).
    Adding, importing or removing an MCP server no longer freezes the agent while it reloads (#2743).
    A failed share/unshare of an MCP server no longer loses the server, and two creates of one delegate name no longer overwrite each other (#2743).
    Dependency PRs no longer arrive red because the attribution manifest is stale (#3393).
    The regeneration is split in two so a write token never meets unreviewed dependency code (#3393).
    onboard_project now reports tracking-branch drift when it reuses a checkout (#3402).
    load_skill now flags a skill's unavailable required tools (#3403).
    Narrow markdown-table columns no longer collapse to one character per line in the console (#3412).
    Consumed queued-message recall is now visibly duplicate-safe (#3413).
    A delegate's HITL question reaches its caller intact (#3414).
    A2A: reap orphaned WORKING tasks without timing out productive turns (#3418).
    Two environment-dependent test assertions no longer flake the Windows shard (#3422).
    The gateway client no longer lets a model's NAME choose its wire protocol (#3424).
    A bare workspace create on a hosted box can reach a model again, and new agents are created in the provider-registry shape (#3425).
    Quitting no longer leaves agents' shell commands, coding delegates and scripts running (#3428).
    A turn the agent runs off a background result no longer streams duplicated text (#3432).
  27. v0.163.0 2026-09-09
    Addressed participants now answer each other by default (#3404).
    Project onboarding is on by default, so you can find it (#3396).
    Scheduler failure backoff no longer loses a slot (#3381).
    onboard_project no longer clones into the server's working directory when no root is set (#3397).
    Parallel edit_file calls no longer discard each other's edits (#3400).
    Parallel artifact updates no longer lose one of the edits (#3401).
    A delegate's reply reads as prose again, not one unbroken wall (#3408, #3407).
  28. v0.162.0 2026-09-09
    orgChart now shows the work that actually happened, not only the work that could (#3386).
    Subagents appear on the chart for the first time (#3386).
    A detached delegation is now closed out when it lands (#3386).
    A read API for the ledger (#3386).
    Plugin setup gaps can carry a bounded, declarative remediation action (#3389).
    Interjecting mid-turn no longer renders the agent's answer twice (#3387).
    Expanding a tool chip mid-turn no longer collapses the moment the turn finishes (#3390).
  29. v0.161.0 2026-09-08
    A durable delegation ledger — the record of who handed what work to whom (#3378).
    Written through one seam, wired to every dispatch funnel (#3378).
    An unknown cost is stored as NULL, never as zero (#3378).
  30. v0.160.0 2026-09-08
    Structured request telemetry now carries the caller's federation trust tier (#1504).
    Diagnostics session inventory is available to operators (#3171).
    RAG-stage projection provenance on the injection log (#3259).
    Rooms are now bounded by configuration instead of by constants, and can run more than one round (#3359).
    An a2a room participant now keeps one conversation across addresses instead of starting over every time (#3361).
    The lead's delegate_to shares that conversation with your @ addresses (#3361).
    Rewinding, deleting or forking a chat now drops the room's pointer into the peer's copy (#3361).
    A participant that pauses for input, or is still working when the room gives up, no longer poisons the room (#3361).
    An optional memory ceiling so a runaway process degrades one service instead of the whole box (#3365).
    Deterministic ProvidersPanel repoint test (#3357).
    A2A continuity cleanup (#3362).
    Review at head fails closed on incomplete or standing-blocked QA reviews (#3334).
    A2A delegate polling now times out only after no visible task progress (#3360).
    A2A delegates accept an answer only from completed task states (#3362).
    A2A room cleanup (#3362).
    A long-running agent no longer leaks a full copy of every plugin on each graph rebuild (#3365).
    A persona self-edit no longer re-imports every plugin and respawns every MCP server (#3365).
    A tool call no longer dies because the audit logger couldn't be imported (#3366).
    A scheduled job that fails every single run is no longer indistinguishable from a healthy one (#3376).
    A repeatedly failing job now backs off instead of burning a turn every cycle (#3376).
  31. v0.159.0 2026-09-05
    Chat server-turn controls (#3092).
    Priority-now inbox backlog recovery (#3351).
    Fleet diagnostics joins the operator-MCP read-only profile (#3313).
    A failed Stop no longer strands a running server turn (#3092).
    A background report delivered into a chat an operator is actively watching can now stop for input (#3110).
    Priority-now inbox pages now self-deliver through accepted A2A turns (#3351).
  32. v0.158.0 2026-09-02
    Paged effective-config reads (#3341).
    Retain rendered assistant replies across agent switches (#3340).
    A cache read reported under a service tier was counted as zero (#3342).
    Telemetry says when prompt caching isn't engaging at all (#3342).
    The codex lane now keys its requests for cache routing (#3342).
    The cache verdict is per model, so one lane can't vouch for another (#3342).
  33. v0.157.0 2026-09-02
    Fleet diagnostics: roster-only member resolution and the bounded log read (#3170).
    Fleet diagnostics: exact task-by-id read, with redaction and hard output bounds on both reads (#3170).
    Fleet diagnostics model-exposure gate defaults off (#3170).
    Fleet diagnostics binds behind the model-exposure gate (#3170).
    Resolve a connection's blocking slots in a dialog before removing it (#3172).
    Removing an in-use model connection can now repoint/clear its slots in one transaction (#3172).
    Eval harness can now seed past sessions and sweep the prior-session digest policy (#3186).
    expected_tools: [] in an eval case now actually asserts that no tool fired (#3186).
    The friction log became a first-party plugin, and its loop actually closes (#3310).
    /friction lists and resolves the backlog from chat, and a friction_triage delegate drafts what to file (#3310).
    FakeRegistry.emit now namespaces topics the way the real bus does (#3310).
    A friction entry can be filed as a GitHub issue in one step (#3318).
    A hub can roll its fleet's friction up in one view (#3318).
    orgChart draws coding agents and model endpoints, not just A2A peers (#3325).
    Operator MCP profile guard (#3170).
    The fleet roster reorders from one handle now, and the row got its width back (#3197).
    Settings ▸ Telemetry is no longer one long scroll (#3329).
    Eval tool-firing assertions were blind in every sweep arm (#3186).
    Drag-and-drop works in the desktop app again — all of it (#3197).
    The friction log is readable again — crushed cards, an invisible "major" badge, and a dismiss that lied (#3307).
    Friction triage is now server-side, so the console and the agent read one backlog (#3307).
    The friction view is rebuilt on the design system, with search, filters and sort (#3307).
    Four other bundled plugin views stopped silently ignoring the operator's theme (#3307).
    The memory inspector now tells the truth about the prior-session digest (#3308).
    memory.max_sessions and memory.max_tokens actually do something now (#3308).
    KnowledgeMiddleware.load_memory() accepts exclude_session_id (#3308).
    A link clicked in a second desktop window no longer opens a crippled in-app webview (#3316).
    Cross-session search no longer misses on plurals and tense (#3322).
    Follow-ups on the eval audit-path fix (#3324), from a retroactive review.
    A killed gate check is no longer reported as a failed one (#3331).
    The lock gate no longer calls a stale branch a downgrade (#3335).
    The marketing site now states protoAgent's actual install footprint (#3315).
  34. v0.156.0 2026-09-01
    Fleet diagnostics API — inspect any member's logs and A2A tasks without SSH (#3168).
    Fleet Room member diagnostics drawer — read any member's logs and inspect a task from the console (#3169).
    A failed desktop platform no longer has to withhold the whole release (#3274).
    The Design System plugin is now listed in Discover (#3280).
    Plugin manifests can now declare command-palette entries in a commands: block (#3282).
    A client slash command can now be dispatched from outside the chat composer (#3283).
    A fork can now add a ⌘K command that looks and behaves like a built-in one (#3284).
    The command palette switches to any open chat by name (#3290).
    Every Settings section is now a ⌘K deep-link (#3291).
    The chat's slash commands and your user-facing skills are now in the command palette (#3292).
    The command palette now searches the agent's knowledge store while you type (#3293).
    A plugin's manifest commands: block now puts real rows in the command palette (#3294).
    The console's keyboard actions are ⌘K commands now, each showing the chord it is bound to (#3295).
    A plugin can now put its own work queue in the agent's working state (#3297).
    The command palette has a visible way in, on desktop and on mobile (#3300).
    The Settings section table moved into an import-light leaf module, so naming a settings section no longer means depending on the entire settings UI (#3285).
    orgChart rebuilt as a first-class plugin (v0.2.0, #3286).
    A bundle's member pin is now a bounded floor rather than an unbounded chase (#3288).
    The command palette finds your surfaces, and puts what you use first (#3289).
    Config updates can now delete a map member, not just add or replace one (#3275).
    The docs said the command palette opens on ⌘K; it is ⌘⇧K, and now a test says so (#3281).
    orgChart resolves delegate tokens the way dispatch does (#3287).
    Creating a sister agent no longer dead-ends on "the box already has a different login" (#3296).
    A slow work provider no longer silences its own later errors (#3299).
    Typing "shortcuts" in the command palette opens Keyboard settings again (#3302).
August 2026 46
  1. v0.155.3 2026-08-29
    The desktop app no longer bundles the br CLI (#3271).
  2. v0.155.2 2026-08-29
    The Linux desktop build ships again, without a bundled br (#3266).
  3. v0.155.1 2026-08-29
    The desktop build no longer dies loading the board CLI's pin (#3263).
  4. v0.155.0 2026-08-28
    Per-turn context is delivered, not stored (#3188).
    The system prompt describes only the tools the agent actually has (#3190).
    Prompt snapshots capture the context the model was actually given (#3191).
    The fleet roster can be reordered — by drag, or by keyboard (#3197).
    A uv.lock downgrade can no longer slip through behind a one-package title (#3224).
    The subagent roster lists only the subagents the lead can actually pick (#3232).
    Public tapped-dispatch seam on the coding-agent plugin (#3235).
    The desktop app now ships the board's br CLI, pinned (#3236).
    Memory rows now say when they enter the prompt (#3242).
    One context projection for every runtime (#3243).
    The four prompt contracts are documented and size-gated (#3244).
    Every memory now has a write lifecycle (#3246).
    Injected context is now bounded and policy-driven (#3247).
    Confirm, reject, or re-open agent-written memories from the console (#3249).
    The prior-session digest is now evaluated, not blindly injected (#3252).
    The prompt inspector shows the delivery budget and what it shed (#3257).
    Remembering something now records which session you were in when it happened (#3258).
    CI actions bumped, but only the ones a PR actually exercises (#3225).
    The console unit suite runs on Node 25 and 26 again (#3213).
    Cover the queued message the agent already read (#3214).
    The cache warmer and the ACP runtime warm the prompt the agent will actually send (#3230).
    A configured commons no longer breaks memory listing, fact dedup and snapshot export (#3245).
    The external agent is told about the tools its bus actually serves (#3248).
    Prompt snapshots record the turn's projected context again (#3250).
    context.prior_sessions: off now actually turns the prior-session digest off (#3253).
    The self_improvement policy knobs accept a bare on/off in YAML (#3255).
    The context budget follows the model a chat tab is actually using (#3256).
    A negative knowledge.top_k removed the injection cap instead of tightening it, and the default is now the documented 5 (#3260).
    The legacy context/context_sections state channel is gone (#3234).
    Dependency-bump PRs now say what to do about the attribution gate (#3221).
    ADR 0109 — one board, one store, N repos (#3237).
  5. v0.154.0 2026-08-27
    Opt-in self-improvement reviews unify persona, skills, and distillation policy (#3069).
    Typed memory schema (#3072).
    Context Architecture v2 ADR (#3192).
    Persist and serve fleet roster order (#3197).
    Codex/ChatGPT-subscription chats keep their reasoning across turns again (#3207).
    Dependency drift is now tracked instead of discovered (#3209).
    The pinned AI stack is current again (#3208).
    New fleet sisters inherit every configured model connection and credential (#3196).
    A Codex/ChatGPT-subscription chat no longer bricks itself on a reasoning item the backend can't verify (#3199).
    ↑ now pulls a queued message out of the turn instead of copying it (#3212).
    Fix text cramming in durable artifacts (#3210).
    Fleet model-connection documentation now matches box-shared OAuth ownership (#3198).
  6. v0.153.2 2026-08-27
    The console can recover recent chat sessions from the server after local browser history is missing (#2888).
    Prior sessions are searchable by transcript content with session_search (#3073).
    Plugin Configure dialogs can organize schema-backed settings into declarative tabs (#3179).
    Plugins can contribute sandboxed workflow tabs to their Configure dialog (#3180).
    Desktop tray update checks now use the full in-app release dialog (#3175).
    Model connections now share one clear settings hierarchy (#3177).
  7. v0.153.1 2026-08-27
    Desktop startup no longer floods the console with failed panel and event requests (#3173).
  8. v0.153.0 2026-08-26
    Signed-in OAuth connection cards now include an Edit action that opens that connection's settings in place.
    Provider connection forms now open in a focused dialog instead of expanding the Settings list inline (#3162).
    Long chat transcripts no longer re-render on every composer keystroke (#3087).
    Favorite models no longer hide the rest of the chat model picker (#3155).
    Provider-specific request shaping now follows the model used for each lead, subagent, and fallback call, fixing Gateway-to-Codex chat switches that sent forbidden system messages while keeping provider credentials and wire formats isolated.
  9. v0.152.0 2026-08-26
    Mid-turn steering messages now stay where they changed the work (#2959).
    Expose every telemetry and prompt-retention setting in the console
    Render background delegate fan-in as authored room replies
    Show live elapsed progress while an addressed delegate works
    Claude subscription model discovery no longer disguises an expired login as a stale model catalog (#3148).
  10. v0.151.0 2026-08-26
    A direct @member message now falls through to the lead agent when every addressed local fleet member is stopped and unreachable
    Fleet members now have individual Start on boot switches in the Fleet list
    Model connections can no longer be removed out from under the agent without a clear warning (#3127).
    Factory reset now reaches desktop and packaged installs and reports shared OAuth honestly (#3133).
    Claude and Codex can be added from Settings ▸ Model ▸ Connections again (#3138).
    Patched the production nanoid dependency against a denial-of-service advisory (#3140).
    Agent snapshots now preserve real plugin pins without crossing their export/import trust boundaries (#3142).
    Agent tooling now discovers the repository's canonical instructions (#3139).
  11. v0.150.0 2026-08-26
    A delegate that is down can be started from the chat, with your say-so (#3126).
    Removing the last model connection now stays removed (#3126, ADR 0106).
  12. v0.149.1 2026-08-25
    A delegate's reply renders as its reply again, not as a Command(update=…) dump (#3124).
  13. v0.149.0 2026-08-25
    protoAgent owns its ChatGPT login, and one console sign-in serves every instance (#3113).
    The lead moderates multi-agent collaboration (#3042).
    A delegate_to renders as the participant's own chat bubble, not a tool card (#3042).
    Several model connections at once, including more than one OpenAI-compatible gateway (#3119).
    Foreground delegate conversations persist with their turn (#3102).
    The chat model picker is capped to the viewport and scrolls (#3111).
    An expired Codex CLI login is no longer imported, so the error names the sign-in (#3112, ADR 0097).
    A delegation renders inline as a two-sided exchange, in the right place (#3042).
    Delegation bubbles now interleave with the lead's narration (#3042).
    The @ autocomplete now opens anywhere in a message, not only at the start (#3042).
    A delegation's ask and reply no longer truncate in chat (#3042).
    A Codex token that is rejected before it expires now refreshes instead of failing forever (#3122, ADR 0097).
  14. v0.148.0 2026-08-25
    CLI coding-agent runs are recorded in telemetry (#3015, ADR 0006).
    Langfuse tracing is configurable, not env-only (#3017).
    Plugin views can put items in the console's context menu (#3030).
    An @delegate exchange is recorded in the conversation, and the delegate sees the room (#3042).
    The console shows who answered, and @ completes from the roster (#3042).
    sdk.plugin_store() — a plugin's own writable directory, scoped to the instance (#3057).
    A chat shows its cast — derived, never tracked (#3049).
    A chain renders as the several messages it was, not one (#3051).
    Gource visualization scripts — render the repo's history as a growing contribution tree (#3094).
    @ several participants in one message (#3042).
    Agents can change their own operational config, if you let them (tools.self_config_enabled) (#3098).
    Chat messages can address a delegate directly with @name (#3037, S1).
    Flagged-outlier turns are now measured against their own model's median (#3015).
    Compact result cards for scheduled/autonomous turns (#3028).
    The Inbox and Activity utility-bar pills are now one unified feed (#3029).
    The Docs view is the first plugin to use context menus (#3030).
    Settings ▸ Model lists every connected provider instead of gating on the active one (#3097).
    Retry empty ACP delegate replies before counting a failure (#2991).
    A delegation to an A2A peer now bills the peer's reported cost and tokens to the calling turn (#3016).
    One bad member no longer 500s the whole fleet telemetry rollup (#3018).
    prompts.retention_days no longer goes silently inert on a busy agent (#3019).
    A plugin view's page had no namespace, which silently disabled its keyboard shortcuts (#3030).
    The Docs view says when the AGENT is unreachable, instead of blaming the doc (#3037).
    A hostile A2A peer can no longer erase the calling turn's telemetry row (#3038).
    Config can no longer choose the destination for deployment-owned Langfuse credentials (#3039)
    A coder run no longer books another run's effort (#3040).
    Telemetry outliers no longer go silent as evidence accumulates, or when coder rows fill the sample (#3041).
    Finished removing daily_log, and stopped a duplicate eval-case id from hiding regressions (#3056).
    python -m evals.runner --tasks now says when an id doesn't exist (#3059).
    Adding a delegate now shows up in the @ menu without reloading the page (#3042).
    Plugin install and update now land with an atomic directory swap, so a failed move never leaves a broken install (#3075).
    A 401 from an A2A peer now says what to do about it (#3080).
    A reattached paused turn gets its HITL buttons back (#3082).
    A2A delegate replies no longer corrupt or truncate on streaming chunk boundaries (#3085).
    Raise the ACP delegation timeout default to 30 min, and make it overridable per call (#3091).
    A stale generated reference page now says what drifted (#3099).
    A doubled ACP reply is collapsed, loudly (#3100).
    Validate provider/model coherence across ALL model slots at config load, not at first dispatch (#3104).
    Codex OAuth recovers from a burned refresh token instead of wedging (#3108, ADR 0097).
    A reattached, already-completed turn keeps its trailing answer (#3110).
    Removed reply-text agent-to-agent addressing (#3050, reverted).
    Redact secrets from tool output before it reaches the transcript (#3070).
    Docs and module docstrings caught up with the telemetry batch (#3015–#3019).
    The starter-tools reference is a usable index of the core tool set again (#3055).
    The plugin API now has a reference tier, generated from the code (#3057).
    The plugin view bridge, a first-plugin tutorial, and a plugin architecture page (#3057).
    "Extend" is now a top-level docs destination (#3057).
    The event bus has a topic catalog, and the plugins guide stopped duplicating the reference (#3057).
    Three stale doc citations fixed (#3057).
  15. v0.147.0 2026-08-23
    Fleet-shared delegates — register a coder once on the hub, it's on every member's bench (#2987, ADR 0105).
    Scheduled-task results come back to the chat that asked for them (#2990).
    resolve_friction dismisses fixed entries from the friction backlog (#2990).
    Scheduled tasks auto-expire (#2992).
    The console e2e harness covers the archetype picker's hard gate and choose-time capability contract on both pickers (#2986).
    The wizard's capability contract is pinned on the wire (#2998).
    Linux desktop: the server sees your login-shell PATH — gh, br, and per-user ACP adapters resolve (#2988).
    A wizard-installed archetype now gets the capability-contract banner too (#2989).
    Chat answers stream smoothly word-by-word on every provider (#2993).
    Subagent LLM calls now share the lead agent's model failover chain (#2995).
    Clearing a conversation now asks first (#2996).
    Turns from /v1, /api/chat, and plugin surfaces are no longer invisible to telemetry (#3000).
    A HITL turn's pre-approval spend no longer disappears when it resumes (#3001).
    Cost telemetry now prices every current Claude model correctly (#3002).
    Cached prompt tokens are no longer billed at full price (#3003).
    A turn waiting on a human no longer counts as a failed turn (#3004).
    Latency percentiles are percentiles again (#3005).
    Dropped the ACP usage frame's unconsumed context_used_tokens / context_window_tokens fields (#3006).
  16. v0.146.0 2026-08-23
    Plugins can declare federation_paths — a peer-reachable, still-authenticated plugin RPC (#2747).
    Plugin releases now poke their archetypes (#2960).
    Chat shows a streaming activity indicator through mid-turn generation pauses (#2967).
    Escape now stops the streaming response — or cancels the newest queued steer first (#2968).
    Plugin surfaces can fence a turn to a tool allowlist (#2972).
    A Project Manager member created from the picker works out of the box (#2977).
    Plugins can invoke named ACP delegates with isolated conversations and a host-enforced read-only ceiling (#2747).
    ⌘K now clears the chat; the command palette moved to ⌘⇧K (#2949).
    The Project Manager soul preset no longer commands tools a fresh member can't hold (#2978).
    The archetype picker no longer offers a Create that can only fail (#2979).
    One hard-required predicate behind the archetype picker gate (#2984).
    Bundle updates no longer downgrade a member that moved ahead of the archetype's pin (#2960).
    The Project Manager first-run guide matches what ships (#2980).
    Project Manager first-run docs match today's releases (#2982).
  17. v0.145.0 2026-08-22
    ACP plan session updates are recorded instead of dropped (#2945).
    Agents can now propose_delegate — registration still needs your explicit approval (#2953).
    The Project Manager archetype is listed again — the flagship for demos — and the first-run docs now match what the wizard actually does (#2963).
    Creating an agent now lands you in it (#2952).
    The Project Manager persona grounds first and proposes its own bench (#2954).
    A failed conversation harvest no longer costs the thread its knowledge (#2950).
    Parked (HITL) turns now appear in telemetry (#2951).
    Model fallback is no longer silent (#2956).
    "Test connection" now works for a Claude subscription (#2957).
    Infisical host tolerates the CLI's /api suffix (#2958).
    A show_component widget is never hidden inside a folded turn (#2965).
    The docs and marketing sites now unfurl with the same branded social card as the GitHub repo (#2942).
  18. v0.144.0 2026-08-21
    Bundles can declare config_inputs: — setup prompts wired to plugin config (#2934).
    The marketing site no longer installs React for one stylesheet (#2930).
    Fresh installs no longer show the per-turn token/cost footer under chat answers (#2931).
    The Docs view no longer 401s on first load of a token-gated host (#2933).
    Plugin views can no longer 401 on first load — the DS kit itself now waits for the bearer (#2935).
    One-shot scheduled tasks resume the chat that scheduled them (#2939).
    The Project Manager archetype is held from the new-agent picker (#2932).
  19. v0.143.0 2026-08-20
    Queued-steer placeholder hint (#2837).
    Auth-gated e2e mock lane (#2886).
    ACP session observability (#2889).
    Query keys are now slug-namespaced (#2887).
    Background report cards shrink to dismissable chips (#2923).
    Plugin form callbacks survive reload (#2889).
    Background delegation dispatches collapse into a compact chip (#2896).
    Changelog gate now blocks merge (#2906).
    onboard_project registers into the managed-projects registry, so the GitHub plugin sees onboarded repos (#2925).
    Friction and devkit plugin views no longer 401 on first load (#2926).
    The Social Marketing archetype is held from the new-agent picker (#2921).
  20. v0.142.1 2026-08-20
    The Linux desktop release builds again (#2915).
  21. v0.142.0 2026-08-20
    The desktop app ships for Linux — .AppImage and .deb are on the download page (#2866).
    CI renders the desktop app now, and the marketing site builds on PRs (#2878).
    Expose fleet autostart in Settings UI (#2880).
    Archetype repos have a registry.
    "Stack" is retired — archetype is the one product noun.
    The download page no longer offers Android and ChromeOS an x86_64 desktop binary (#2866).
    Turn telemetry includes subagent model calls (#2872).
    The marketing site deploys from its lockfile again (#2875).
    Plugins see the live host config at register time on cold boot (#2877).
    Fix flaky Windows test for workflow run ordering (#2883).
    The Artifact panel works again on bearer-gated instances (#2884).
    Plugin view panels surface persistent fetch failures (#2885).
    delegate_to's A2A poll loop speaks 1.0 now (#2892).
    Unknown /commands are refused inline instead of becoming agent turns (#2893).
    Delegation questions now flow back to the calling agent — and can be answered.
    Discover no longer advertises coding_agent as an enableable plugin.
    A delegate that parks its question inline no longer gets mistaken for an answer.
    Parallel delegations no longer corrupt each other (#2899).
    Renamed archetype repos never double up in the new-agent picker.
    The marketing site no longer tells you to enable coding_agent (or delegates).
  22. v0.141.0 2026-08-20
    The Docs view can point at any folder of markdown (#2842).
    scripts/context_audit.py — one command for "why is this thread at 121k" (#2844).
    The prompt viewer explains the whole window (#2847).
    The plugin devkit enforces the SKILL.md contract (#2854).
    A turn now provably survives the operator walking away (#2857, Swap & Resume S0).
    Switching agents (or reloading) mid-turn now reattaches to the live turn (#2858, Swap & Resume S1).
    Your half-written message survives an agent switch (#2860, Swap & Resume S3).
    A session's chat history is finally readable server-side (#2865, ADR 0104, Swap & Resume S5).
    The workflow builder becomes "Outline & Focus" (#2835).
    Builder flow polish — reorder, duplicate, Save & test (#2839, S3 of the Outline & Focus redesign).
    The workflow builder is a node-and-edge DAG canvas (#2846).
    Workflows is opt-in again (#2848).
    The console stops lying about busy agents after a swap (#2859, Swap & Resume S2).
    Swapping agents can't kill a working agent, and abandoned streams unwind (#2862, Swap & Resume S4).
    /prompt opens the prompt dialog (#2863).
    A mapping-authored inputs: no longer breaks the Studio (#2834).
    Fs tools see mid-turn project registrations (#2836).
    develop_plugin no longer blocks the chat turn — and no longer refuses a multi-delegate roster (#2838).
    plugin_read_file paginates by line (#2840).
    fetch_url strips page chrome from HTML (#2841).
    Web E2E's Playwright apt install waits for the dpkg lock (#2845).
    Subagents declaring tools: [] now run as text-only transforms
    The Web E2E job stops fighting apt (#2864).
    skills.top_k: 0 means "list none" again (#2869).
    The desktop updater can no longer install a stale release (#2832).
  23. v0.140.0 2026-08-19
    Workflow runs are now observable while they execute (#2829).
    The Studio actually shows a workflow run happening (#2830).
    Workflows is GA — the plugin ships enabled by default (#2831).
    The chat model dropdown no longer needs a Settings visit to fill in (#2828).
  24. v0.139.0 2026-08-18
    The PTC graduation bench is an eval suite (#2807, ADR 0103).
    File artifacts get typed previews (#2816).
    The zero-cache-hit watcher now tells "provider ignores caching" apart from "provider doesn't report it" (#2772).
    The trajectory becomes readable: /trajectory + the read API (#2806, ADR 0102 S2).
    PTC reaches GA: binding-path parity for bridged tool calls.
    The artifact plugin is nine modules instead of one 1,800-line file (#2819, #2817 P1).
    The artifact console shell is real HTML/JS files (#2822, #2817 P2+P3).
    plugins.sources.allow: [] now means deny-all, not open (#2743 item 1).
  25. v0.138.0 2026-08-18
    Round governance: long turns get re-grounded, and can be budgeted (#2710, ADR 0101 D8).
    Context pressure is now a persisted series, and the next request's floor is projected (#2773, ADR 0101 D6).
    Rolling cache breakpoints on message history (#2777, ADR 0101 D1).
    Oversized tool results already in history get pruned before summarization ever runs (#2782, ADR 0101 D3/D4).
    A context-window overflow is now a recovered event, not a dead end (#2783, ADR 0101 D4).
    The console surfaces context pressure honestly (#2787, ADR 0101 D6).
    Plugin repos can now own their eval suites (#2804).
    The trajectory writer: "what did the model see" is now answerable (#2806, ADR 0102 S1).
    The dynamic context layer rides the message stream, composed once per turn (#2776/#2779, ADR 0101 D2).
    Subagent delegations get prompt caching (#2778, ADR 0101 D1).
    Prompt-cache TTL resolves by profile (#2780, ADR 0101 D7).
    Auto-compaction archives before it rewrites (#2784, ADR 0101 D5).
    /compact is generally available (#2785, ADR 0101 D5).
    The execute_code tool bridge gets a security posture (#2807, ADR 0103 S1).
    install-deps re-validates source trust at deps time (#2743).
    A turn that composes no dynamic context no longer re-sends the previous turn's (#2774, ADR 0101).
    The per-tool context-cost chip (#2282) actually renders now (#2775, ADR 0101).
    MCP tool results are size-bounded at last (#2781, ADR 0101 D3).
    "Fork from here" gives the fork real memory (#2803).
    PTC S2+S3: the bridge shows its schemas and its calls (#2807, ADR 0103).
    ADR 0101 — Context lifecycle: log, surface, pressure (#2772).
    ADR 0102 — The trajectory: append-only session log + derived surface (#2806).
    ADR 0103 — Programmatic tool calls: agent tools callable from execute_code (#2807).
    Evals guide documents the plugin-suite seams (#2811).
  26. v0.137.2 2026-08-17
    Chat streaming is smoother — text trickles instead of filling in ~10-word blocks (#2766).
  27. v0.137.1 2026-08-17
    The A2A flush-granularity regression test now locks the 60-char frame granularity (#2672).
    The console is on the current design system (#2761).
    The docs site follows your OS colour scheme now, instead of always being dark (#2760).
    anthropic-oauth agents with string-shaped system prompts no longer fail every call with a fake 429 (#2763).
  28. v0.137.0 2026-08-16
    The bundle pin-bump PR lifecycle now has automated test coverage (#2669).
    Agent boot is now instrumented, and there's a /perf chat command for a live performance snapshot (#2245, #2674, #2677, #2678).
    Plugin lifecycle latency is now instrumented per plugin (#2675).
    Knowledge-store op latency instrumentation (#2676).
    Publish a chat thread to a shareable, read-only link — pre-release (#2179 P2, #2682, #2683).
    Published links can now be listed and revoked — Settings ▸ Publish (#2179 P2, #2684).
    The marketing changelog page collapses prior months (#2695).
    Telemetry breaks down latency by tool, not just by model (#2697).
    read_file can page past its 50K-char cap (#2707).
    read_file can skip a redundant re-read within one turn (#2708).
    The project-manager persona now nudges toward task delegation for wide multi-repo investigation (#2711).
    A bundle's archetype: block can now name a soul_preset, and typo'd keys warn at install (#2715).
    Bundles now have a lifecycle past install — update, re-pin, uninstall as one action, and a real guide (#2718).
    The devkit now covers the entire plugin lifecycle (#2719).
    The one-time "this runs code" consent is real.
    Trust & consent foundation.
    A bundle lifecycle smoke joins the #912 single-plugin one (#2724).
    Installed bundles are actionable from the console (#2737).
    One repo-owned fast gate script, shared by local devs and PR CI (#2746).
    The marketing site is rebuilt on the shared protoLabs design system (#2702).
    auth: {token: ""} now correctly disables bearer auth even when A2A_AUTH_TOKEN is set in the environment (#2691).
    A finished background job now has a durable, tab-independent way to be noticed (#2692).
    The boot-phase timing test no longer fails at random on native Windows CI (#2703).
    Telemetry's tool_calls count was silently 2x inflated (#2705).
    Console-created agents now receive their archetype's capability contract (#2713).
    The setup wizard now has the same bundle Configure step and runtime warning as the fleet new-agent picker (#2714).
    Installing a plugin that fails to load no longer toasts "enabled and live" (#2716).
    CLI uninstall of an enabled plugin now warns that a running server keeps it live (#2717).
    Bundle-lifecycle corrections from the #2732/#2736 review findings (#2718).
    Devkit lifecycle-tool fixes from the #2735 review findings (#2719).
    The plugin-install docs no longer claim a consent dialog that doesn't exist (#2720).
    Trust-matcher hardening from the #2733/#2735 review findings (#2721).
    Bundle/archetype docs truth pass + ADR 0100 ratifies the archetype system (#2722, #2723).
    list_verifiers no longer implies core types are usable by set_goal/create_watch (#2744).
    A wait() rescheduled mid-fire no longer gets silently deleted (#2749).
    read_file is now line-addressed, and search_files supports regex + context lines (#2755).
    A2A skill seam hardening — validated registration, owned ids, live served card (#2757).
  29. v0.136.0 2026-08-13
    The federation token is now manageable from Settings, and rotates live (#1504).
    A structured, artifact-aware chat-bundle export now exists alongside the Markdown one (#2680, #2681).
    list_verifiers tool (#2686).
    The self-building loop now closes in the packaged desktop app (#2636).
    The desktop self-building loop actually runs its tests now (#2638).
    An agent is told when its own tools change (#2640).
    Multi-turn tool-call conversations no longer 400 in DeepSeek-style thinking mode (#2642).
    Inbound A2A delegate turns now appear in the receiving agent's Activity feed (#2644).
    The bundle template's pin-bump PRs no longer pile up unverified (#2645).
    python -m server --config <path> now fails loudly instead of silently ignoring the path (#2647).
    The "isolated" live-smoke run no longer probes real local protoAgents (#2651).
    A completed tagged Desktop Build now refreshes the public download page (#2655).
    The markdown smoke e2e no longer races Streamdown's code-block highlight swap (#2659).
    Goal and Watch form data verifiers now resolve relative paths under the managed workspace (#2660).
    Native Windows CI now retries one transient Node syntax-check timeout (#2662).
    Chat answers stream in smaller, more frequent blocks (#2672).
    model.max_iterations now actually caps the agent loop (#2679).
    Goal/watch tools hidden when no verifiers registered (#2686).
    A2A delegate calls now trust what the OS trusts, not just certifi (#2643).
    Locked web dependencies with active advisories have been refreshed (#2649).
    A Windows operator now has one guide covering install through recovery (#2656).
  30. v0.135.0 2026-08-12
    The A2A agent card now describes the credentials the server actually accepts, and multiple credentials are genuinely alternatives (#2620).
    Note for anyone who set both A2A_AUTH_TOKEN and <AGENT>_API_KEY:
    A fleet member that picks its own model no longer inherits an incompatible provider from the host.
    The Hermes ACP runtime preset is deprecated (#2633).
    The legacy <AGENT>_API_KEY credential is deprecated (#2632).
  31. v0.134.1 2026-08-12
    The friction ledger has a console surface — a rail icon, not just an API (#2595).
    Chat code blocks render their line breaks again (#2612).
    The HITL response textarea now sends on Enter, matching the chat composer (#2614).
    The friction list shows the newest signal first, even on a coarse clock (#2616).
    The published PyPI wheel now ships plugins/, so every ACP-backed turn works on a real install (#2624).
    The published PyPI wheel now ships the docs corpus, so docs_search/docs_read and the Docs view work on a real install (#2626).
  32. v0.134.0 2026-08-12
    Project onboarding config (#2555).
    onboard_project tool: clone a GitHub repo and register it as a managed project, bounded by the operator-consented onboarding config section
    Mix a gateway, a Claude subscription and a ChatGPT subscription across model slots.
    The model dropdowns now offer every provider you're signed in to.
    Pick any signed-in provider's model straight from the chat.
    Recorded friction is readable at last — GET /api/friction (#2595).
    Marking a draft PR ready for review now triggers the Windows tests job (#2455).
    Agent names with non-ASCII characters no longer render as mojibake (#2520).
    The whole class is now a build failure, not a bug report.
    protoagent config set no longer writes credentials in plaintext into the tracked config YAML (#2575).
    protoagent up and protoagent status no longer mistake a stranger's listener for your server (#2576).
    /v1/chat/completions now reports a failed turn as an HTTP error instead of a successful completion (#2578).
    protoagent model use no longer invents an API key for a gateway that needs a real one (#2579).
    protoagent model use --key and the Hermes preset store the credential in secrets.yaml, not the tracked config YAML (#2575).
    An agent on a Claude subscription no longer dies when its own coders refresh the login (#2582).
    Purging a fleet member no longer fails with a bare 500 after already stopping it (#2583).
    POST /api/restart restarts the server on Windows instead of killing it (#2585).
    write_file writes the line endings it was asked for, and read_file no longer hides it when it didn't (#2586).
    edit_file no longer converts a whole CRLF file to LF as a side effect of one edit.
    A busy fleet member can no longer freeze the whole console (#2590).
    A turn that fails is now recorded in the conversation, instead of vanishing from it (#2593).
    Config and registry files written on Windows are no longer silently converted to CRLF (#2596).
    A config section that would be invisible in Settings now fails its test with a message saying so (#2598).
    The changelog gate now checks a fragment will actually reach the release notes, not just that it exists (#2600).
    Release PRs pass the changelog gate again.
  33. v0.133.0 2026-08-11
    Fleet telemetry: hub-side read-only rollup across members (#2539).
    Fleet section in the Telemetry console surface (Slice 2, #2539).
    "Operating a fleet" core docs guide (Slice 3, #2539).
    The agent can read its own configuration (#2540).
    "View prompt" now tells the wire truth — and reads like a document (#2527).
    A subscription credential's remaining life is now visible to monitoring (#2549).
    An agent on a Claude or ChatGPT subscription can now fall back to the gateway (#2550).
    The delegate health prober stops relaunching every delegate every two minutes (#2542).
    A one-off schedule can no longer be quietly created for 09:00 (#2159).
    Escape in Settings really does close only the dropdown now (#2466).
    search_files no longer feeds compiled bytecode and cache dirs to the model (#2541).
    Running the test suite from inside a live agent no longer pollutes that agent's chats (#2543).
    Chat code blocks keep their line breaks again (#2546).
    The Connected-account card now sits at the top of Settings → Model.
    Subagents work on Claude and ChatGPT subscriptions (#2552).
    Saving work folders can no longer silently strip the ones you didn't mention (#2556).
    ACP as the agent's main runtime is deprecated (#2548).
    Docs: the coding-agent guides now match the product.
    Docs: the extensibility guides tell you what to do first.
    Docs: run, deploy, and expose guides lead with the command.
    Docs: agent snapshots are findable again.
  34. v0.132.0 2026-08-11
    The download page now links the newest desktop release, not the newest version number (#2514).
    Deleting a chat from the mobile session sheet now confirms and cleans up properly (#2512).
    Switching to a Claude/ChatGPT subscription in Settings no longer dead-ends on gateway models (#2522).
    Windows run_command no longer runs approved PowerShell through a hidden cmd.exe (#2518).
    An OAuth disconnect no longer looks like a broken startup (#2513).
    On ChatGPT/Codex accounts, the agent's system prompt now actually reaches the model (#2519).
    HITL cards format their text now.
    Windows: fresh agents can export snapshots again (#2521).
    Agent names show exactly as you typed them (#2520).
    "Reset to inherited" actually works on fleet members now (#2528).
    The build-with-a-coding-agent guide is now a task-first walkthrough (#2510).
  35. v0.131.3 2026-08-11
    Switching a running instance to Claude or ChatGPT works from the console (#2508).
  36. v0.131.2 2026-08-10
    Install from URL moved to the Plugins panel header (#2506).
    "Rewind to here" no longer appears on the latest message (#2505).
  37. v0.131.1 2026-08-10
    Config-route hardening: no more event-loop stalls or ambiguous responses (#2486).
  38. v0.131.0 2026-08-10
    OAuth account lifecycle controls now live in Settings ▸ Model (#2460).
    An OAuth disconnect no longer makes the server unbootable (#2458).
    OAuth disconnect now signs the live graph out too (#2459).
    Setup Finish no longer leaves stale model/provider UI until a restart (#2462).
    Subscription-provider dollars are now labeled as estimates, not charges (#2463).
    Catalog and theme reads no longer depend on the Windows locale codepage (#2464).
    A legacy non-UTF-8 catalog override degrades safely instead of 500ing (#2465).
    Escape in a Settings dropdown no longer closes all of Settings (#2466).
    The Keyboard settings hint now speaks the viewer's platform (#2467).
    Telemetry timestamps now render in the operator's local timezone (#2468).
    Windows Settings no longer speak macOS (#2470, #2469).
    The bundled Docs view parses again (#2471).
    /model and the composer picker now list native-OAuth subscription models (#2473).
    The chat-focus shortcuts work from any surface (#2474).
    Rewind works on Responses-API / reasoning models (#2480).
    Deleting a chat now deletes its session-summary memory too (#2482).
    /btw asides are truly saved nowhere now (#2483).
    Incognito turns no longer offer a View prompt that 404s (#2484).
    Regenerate replaces the turn everywhere, not just on screen (#2491).
    The bare /effort (and /model) picker is mouse-usable again (#2492).
    Disconnect no longer remotely revokes a credential borrowed from the Codex CLI (#2461).
  39. v0.130.0 2026-08-10
    A persona that commands an action no tool backs now warns instead of failing silently (#2443).
    The New/Edit schedule dialog is a real builder, with validation (#2159).
    More of the test suite runs natively on Windows CI (#2412).
    CHANGELOG.md is now split into dated monthly archives (#2437).
    find_files and search_files return forward-slash paths on Windows (#2446).
    Native OAuth sign-in now has cancel, disconnect, and revocation (#2440).
    Concurrent Codex credential resolution no longer races the single-use refresh token (#2441).
    The review panel can no longer publish its own reasoning to a pull request (#2447).
    The coder plugin's test verifier now runs on Windows (#2450).
    The media URL-signing key is now owner-only on Windows (#2451).
    execute_code runs on Windows (#2453).
    Coding-agent death errors are accurate on Windows (#2454).
  40. v0.129.0 2026-08-09
    Run Claude or ChatGPT on your own coding-agent subscription, natively (#2420).
    Setup wizard: pick a subscription brain, no config-file editing (#2420).
    Sign in to Claude / ChatGPT from the console — no terminal (#2420).
  41. v0.128.0 2026-08-09
    The system-prompt viewer answers "what changed?" and "what's next?" (#2415).
    PRs are now gated by a native Windows test job (#2419).
    One cross-platform process-tree lifecycle — infra/proc (#2424).
    The console now uses the canonical --pl-* design tokens everywhere (#2414).
    Plugin views fail loudly when the DS kit is missing instead of silently 401ing (#2409).
    Windows shell and desktop paths are native (#2416).
    Pure-Python wheel installs now work on Windows and keep dependency pins in the canonical lock schema (#2417, #2418).
    The desktop sidecar now serves the console at /app — mobile QR pairing works from desktop installs (#2423).
    Stopping an ACP delegate on Windows no longer leaks its backend (#2425).
    Rapid persona saves can no longer prune the wrong history snapshot (#2426).
    Fleet stop and protoagent down work on Windows — and take the whole member tree (#2427).
    Concurrent metric writes can no longer be starved into "database is locked" (#2429).
    Windows install/uninstall now sweeps the sidecar's stranded _MEI runtime dirs (#2430).
    Installing a plugin from a local path works on Windows (#2433).
    Watches and goals work on Windows — state writes no longer fail, verifiers no longer hit the WSL stub (#2434).
    Windows credential files now have a real privacy contract (#2431).
    The external-PR path is documented (#2421).
  42. v0.127.0 2026-08-08
    The devkit's rail view is now a live build-status page (#2401).
    Plugin routers hot-remount on reload and unmount on disable (#2404).
    Enabling a plugin on a fleet member no longer 401s its just-added view (#2405).
  43. v0.126.0 2026-08-07
    The shared note is no longer destructively overwritten — it keeps recoverable history (#2022).
    Notes settings: Versions kept (default 50) and Coalesce window (default 300s).
    Merge-on-boot declarative seeding — a baked config seed can now stay live across image rolls (#2071).
    Tool cards show what a call cost you in context (#2282).
    The plugin-devkit now closes the whole build loop — scaffold → edit → test → hot-swap, no restart (#2394).
    develop_plugin — the self-building loop's delegated build lane (#2395).
    Agent-initiated plugin changes now push a live console refresh (#2396).
    register_plugin_project — graduate a self-built plugin to a managed project (#2397).
    The devkit ships a self-building-demo skill (#2400).
    Review findings must quote evidence VERBATIM — the findings contract now says so (#2373).
    The devkit's build loop no longer calls a plugin that loaded with zero contributions "live" (#2398).
    test_plugin now runs a plugin's suite against a disposable copy of the plugin dir (#2399).
    ADR 0096 — the self-building loop (#2393).
  44. v0.125.1 2026-08-06
    Renaming an agent in Settings ▸ Agent ▸ Identity now changes the header and the agent switcher too (#2377).
    The Identity panel no longer reports a save that was refused (#2377).
    Fleet start / stop / remove / activate address agents by their immutable id, not their display name (#2377).
    A reload before setup is complete no longer 500s (#2379).
    An agent name with spaces or punctuation now gets a normalized fleet label instead of a stale one (#2381).
    Renaming an agent no longer orphans its inbox, background results and activity feed (#2382).
    Removing an agent from the fleet no longer deletes its data (#2384).
    The purge path honors PROTOAGENT_BOX_ROOT (#2384).
    Renaming an agent no longer makes its scheduled jobs disappear (#2382).
  45. v0.125.0 2026-08-05
    Export an agent as a portable, secret-free snapshot (#2103, ADR 0091 Slice 1).
    Import a snapshot to stand up a fresh agent (#2104, ADR 0091 Slice 2).
    Opt-in knowledge seed in agent snapshots (#2105, ADR 0091 Slice 3).
    Duplicate an agent from a snapshot in the console (#2106, ADR 0091 Slice 4).
    Settings ▸ Agent ▸ Snapshot — export an agent from the console (#2103).
  46. v0.124.0 2026-08-03
    Copy a background job's full result from the Background-agents panel (#2352).
    A coding-agent delegate whose reply was cut short now says so, instead of handing back a partial answer that looks finished (#2352).
    A server-fired turn that fails now says so in chat, instead of trailing off or vanishing (#2360).
    A server-fired turn is now watchable while it runs, instead of a typing indicator and then the whole answer at once (#2361).
    A background delegate's reply now reaches the orchestrator whole, instead of being cut at 3,000 characters (#2363).
July 2026 57
  1. v0.123.0 2026-07-31
    The delegate form asks for what matters first (#2358).
    The Codex preset pointed at an adapter you couldn't upgrade (#2357).
  2. v0.122.0 2026-07-30
    The Delegates panel now shows whether the last real call worked, not just whether the delegate answers a ping (#2355).
    A failing delegate now says why (#2353).
    Pin mcp<2 — a transitive release turned CI red repo-wide (#2354).
  3. v0.121.0 2026-07-28
    mcp.call_timeout_seconds — an MCP tool call is now bounded (#2347).
    A running tool card now shows how long it has been running (#2348).
    A wedged turn is now failed instead of spinning forever (#2344, #2349).
    The MCP quick-add catalog no longer offers the third-party filesystem server, and a broken entry was fixed (#2350).
    A cancelled MCP tool call no longer comes back as a tool result, and a config reload no longer strands one forever (#2345).
    One slow MCP tool no longer wedges every other call to that server (#2346).
  4. v0.120.0 2026-07-27
    scripts/watch_smoke.py — a live smoke for the watch subsystem, plus the regression guard #2320 never got.
    A provider that goes silent mid-stream is now retried instead of losing the turn (#2305).
    A network blip no longer discards a macOS notarization Apple already accepted.
    scripts/live_smoke.py is now hermetic — it used to inherit the developer's host config.
    A session id can no longer build a path outside the memory dir (#2340).
  5. v0.119.0 2026-07-26
    A watch can be a standing monitor, not just a one-shot tripwire.
  6. v0.118.0 2026-07-26
    GET /api/verifiers — every verifier a goal or watch can use, from every source.
    An operator can set a watch from the console.
    A released changelog fragment is now actually deleted, instead of being published twice.
    The goal creator offers plugin verifiers too.
  7. v0.117.0 2026-07-26
    Semantic tier for persona-drift detection — an opt-in LLM judge (#2272).
    requires_pip entries can declare scope: host | runtime (#2246).
    The ACP layer no longer discards stopReason — a coder can declare a dead end (#2279).
    Keyboard shortcuts work with sandboxed plugin views (#1457).
    A plugin symlinked to a live checkout no longer serves mixed code undetected (#2298).
    Archetypes declare a capability contract, checked against the tools that actually bound (#2277).
    /v1 (OpenAI-compat) can now continue a session across requests (#2119).
    An agent can finally give a watch a lifetime.
    A watch can be edited in place instead of cleared and recreated.
    Watches default ON.
    The changelog gate now requires a changelog.d/ fragment — editing CHANGELOG.md directly no longer satisfies it (#2322).
    Changelog entries are now news fragments — changelog.d/<issue>.<kind>.md (#2322).
    Category filters no longer spill out of the panel (plugin Discover + MCP catalog).
    /v1 disconnect semantics are defined instead of undefined (#2119).
    team-ready now knows about open PRs that already claim the issue (#2278).
    A bind-posture guardrail — a single-IP network.bind no longer locks you out silently (#2147).
    watches.interval is a real setting, and both watch keys reached the Settings UI.
    Finished watches are retired instead of accumulating forever.
    The desktop app can open a second window — "New Window" is no longer a no-op (#1706).
    Plugin endpoint errors answer with a structured JSON error instead of a bare 500 (#2259).
    Watches are no longer coupled to goal mode — and the poller no longer silently skips every watch when goal mode is off.
    The watch tick no longer blocks the event loop on its store scan.
    A watch reaction reports one origin, not two.
    POST /api/fleet/{name}/stop no longer reports a stop it didn't achieve (#2286).
    The cleared watch status, which never existed.
    The Watches panel shows a watch's cadence, expiry and stall threshold.
  8. v0.116.0 2026-07-26
    /api/chat no longer answers with the *previous* turn's reply after a stalled turn (#2300).
    The managed-projects registry now refuses bad entries loudly instead of quietly granting less (or more) than you asked for.
    fs: false on every project now means what it says: no filesystem fence at all.
    An agent you just added from network discovery no longer lingers in the "found" list.
    Every sister agent gets the fleet surfaces, not just the host console.
    Opt-in per-step `timeout` in the workflow engine, with graceful degradation — a hung step degrades (empty Gap, listed in `degraded`) instead of stalling the whole DAG.
  9. v0.115.0 2026-07-25
    Managed projects are visible in the console, and it tells you when they aren't in effect.
    New guide — Build out your protoAgent with a coding agent.
    A Social Marketing archetype — the fifth starter agent.
    The plugins that ship with protoAgent now appear in Discover (#2249).
    Installed plugins say what they do (#2248).
    Fleet rows are clickable, and a delegate can be unlinked where you linked it (#2240, #2266).
    The desktop app uses the real OS folder chooser for path settings (#2265).
    The desktop app now emits system.wake (#1932, ADR 0074).
    One place to declare a project.
    Folder pickers for every path setting — no more typing a path and hoping.
    Middleware warnings now reach the console feed (#2262).
    Artifacts nudge away from the save-loop (#2257).
    Project Manager preset learns fix-round doctrine and stops over-claiming (#2273).
    Prompt caching is attempt-by-default, and failure is loud (#2255).
    Settings stops describing two dead directory fences.
    The generated OpenShell sandbox policy no longer locks the agent out of its own workspace (#2281).
    The artifact panel stops hammering /history (#2256).
    /v1 non-streaming returns the final message with an honest finish_reason (#2234).
  10. v0.114.0 2026-07-24
    See the exact system prompt behind any reply — a View prompt action on every assistant message shows what the model actually received, call by call, with its real token usage.
    The prompt viewer breaks your context budget down by section — persona, skills index, injected memory, working state — so you can see where the tokens go; /prompt drops the latest prompt into the chat as an unsaved note.
    Prompt capture respects your boundaries: incognito chats record nothing, and deleting a chat purges its captured prompts with it.
    A bad work folder no longer silently takes away every filesystem tool — unusable paths are refused with the reason, and the editor flags saved folders that later go missing.
    The Craft plugin's console name and docs now say what it ships — all six commands, including the agent-reachable ADR-authoring skill.
  11. v0.113.0 2026-07-24
    The new-agent picker files advanced archetypes behind a toggle — the everyday starter types stay front and center.
    Installing a bundle on the host now seeds its MCP servers and secrets too — same behavior as creating an agent from it.
    Plugin views and artifacts receive the console's full theme — every token and your overrides, not six approximate colors.
    The header menu is a real modal now: focus stays inside it, the page behind stops scrolling.
    Status colors across chat notes and settings follow your theme and light mode properly.
    New guide: the managed Python runtime — what needs it, the one-click install, and how to read its status surfaces.
    A documentation deep-clean: stale claims fixed everywhere, the ADR index made whole, and the plugin/CLI guides easier to find.
  12. v0.112.0 2026-07-24
    The plugin manager is a real table now — search plugins (and the tools they ship), filter by status, sort any column.
    One plugin directory everywhere: the in-app catalog and the website now share a single curated source — and Discover grew from 12 to 20 plugins.
    Plugins installed by a bundle now say so — a chip names the bundle, and search finds everything it installed.
    Design System Engineer joins the new-agent picker.
    Archetype cards warn at choose-time when this machine still needs the one-click Python runtime install — and Settings flags it with a dot until it's provisioned.
    settings.hidden — keep chosen settings out of the console entirely: hidden means gone, not toggleable back (the settings counterpart to tools.hidden).
    Desktop: the update prompt lands at launch, before the engine loads — update first instead of sitting through startup.
    Fixed: saving filesystem projects no longer stalls the server while it applies.
  13. v0.111.0 2026-07-23
    /btw — ask a quick side question about the chat: answered from its context, saved nowhere and never changing the conversation.
    New-agent panel: Name and Create now sit above the archetype picker, over a scrollable card list.
    Chat export tells you the filename it saved — and says so plainly when a download is blocked.
  14. v0.110.0 2026-07-23
    Export a chat to Markdown — from /export or the tab's right-click menu, with secrets scrubbed.
    A friendlier New Schedule dialog: an inline calendar for one-off runs and a 12/24-hour time toggle.
    Hide a tool from the console entirely (not just disable it) — for restricted or archetype-locked setups.
  15. v0.109.0 2026-07-23
    Export a chat thread to Markdown — secrets scrubbed, ready to read and share.
    Project Manager archetype — a one-click agent type in the new-agent picker.
    Generated documents download again from the artifact panel.
    Plugin panels no longer render dead on a sister agent.
  16. v0.108.0 2026-07-23
    Human approval gates for workflows — pause a run at any step, then approve, edit, or reject.
    execute_code runs in the packaged desktop app — a managed Python runtime, provisioned on demand.
    Cowork's document skills (Word, Excel, PowerPoint, PDF) now work on the desktop app.
    Plugins install their own dependencies on desktop — into the managed runtime, or as pure-Python wheels.
    Fleet Room — summon the fleet from ⌘K, with presence, DMs, and broadcast.
    Workflows honor a recipe's own fan-out width, with per-step timings.
    The agent runtime setting now sits with the model it depends on.
    Multi-server MCP bundles can seed each server with its own input value.
    Fixes: creating a Cowork agent on desktop, knowledge-recall provenance, orphaned paused runs, and a host-gated "New agent".
  17. v0.107.0 2026-07-22
    Generated files are now versioned artifacts — save_file_artifact.
    The desktop app ships the document-generation stack, on by default.
    Fleet agents accept operator inputs + secrets at create time.
    Deterministic persona-drift detection.
    Chat tab context menu — Close Others / Left / Right.
    Cowork and every catalog archetype now appear in the new-agent picker on desktop and pip installs.
    More reliable PyPI publishing — releases fire on the tag push.
  18. v0.106.0 2026-07-21
    A2A client-side spec coverage: resubscribe() and push-notification registration.
    Tutorial: two agents talking over A2A
    A2A conformance reference
    The conformance prober now drives real calls, not just method probes.
    scripts/a2a_conformance.py — point it at any A2A 1.0 agent and get a conformance report.
    Jump from a telemetry row to its Langfuse trace.
    An a2a:<delegate> span around each outbound A2A dispatch.
    Goal detail drawer.
    Goal lifecycle actions.
    Panel goals drive in a dedicated chat tab.
    Shell/filesystem policy and Work folders moved onto the Filesystem tool group.
    The agent card declares only the extensions this runtime actually emits.
    One guided goal-creation wizard.
    A goal set from the console starts driving immediately
    The watch tools are gated behind watches.enabled and now default OFF
    Mobile: the last row of content sat under the home indicator.
    npm 10 can no longer install a silently-wrong dependency tree.
    The A2A docs taught a wire format that 1.0 removed.
    The documented version-negotiation model was wrong, including in our own test docstring.
    Langfuse's A2A root span is a2a-stream, not a2a.task
    docs/reference/a2a-endpoints.md's fleet auth predated ADR 0089 (the proxy *swaps* the Authorization header for the fleet service token; it doesn't forward the caller's verbatim), docs cited modules deleted in #453, ADR 0014 claimed a hitl-mode-v1 capability that exists nowhere, and ADR 0089/0075 statuses were stale.
    No-progress detection now works for fuzzy (llm) goals.
    A goal set could 500 after being persisted
    Retired dead monitor-mode UI
    PR review read the code as it was BEFORE the pull request.
    The installed PWA painted its status bar with the brand accent.
  19. v0.105.2 2026-07-20
    Plugin panels load again on a sister agent viewed from a token-gated hub.
  20. v0.105.1 2026-07-20
    A fleet member's live console streams work again (/api/events).
  21. v0.105.0 2026-07-20
    Plugins work again on sister agents in a fleet — over both HTTP and WebSocket.
    Third-party attribution can no longer be silently wiped to UNKNOWN.
    Fleet members no longer run open on loopback.
  22. v0.104.5 2026-07-20
    A token-gated instance's own desktop app can reach it again.
    The /code-review panel got sharper prompts
    Settings ▸ Devices is hidden behind a developer flag (settings.devices, default off).
    graph.sdk.start_goal_loop / stop_goal_loop are back — watch-based this time
  23. v0.104.4 2026-07-19
    "Allow devices on my network" can no longer stop the app from starting.
  24. v0.104.3 2026-07-19
    Enabling network access no longer hands you a secret you can't see.
    The token prompt says where the token lives.
    The desktop app authenticates itself instead of asking you for a token it already has.
  25. v0.104.2 2026-07-19
    The desktop app no longer hangs on launch after enabling network access.
  26. v0.104.1 2026-07-19
    Pairing works in the desktop app.
  27. v0.104.0 2026-07-18
    Mobile is a chat-first app, not a shrunken console.
    Add a phone by scanning a QR, and revoke it individually.
    A managed Node runtime, provisioned on demand.
    Bundles can seed MCP servers
    A read-write-no-delete fence mode for the filesystem toolset
    Telemetry extensions moved to URI-keyed metadata
    Settings ▸ Integrations is now Plugins, matching what the section actually contains.
    The console consumes @protolabsai/ui 0.57, which ships the touch floor upstream
    A chat tab doing background work shows a processing dot
    "+" no longer piles up empty chats.
    Dropped the per-row "open in new window" action from the fleet switcher, which duplicated the row's own click behaviour.
    uv is pinned to 0.11.29 in both release workflows
  28. v0.103.2 2026-07-17
    Overlays no longer inherit the styles of the surface that opened them
  29. v0.103.1 2026-07-17
    Dialogs opened from inside Settings are usable again.
    QuickSetting chip dialogs honour depends_on.
    uv.lock re-locked after the protolabs-agent PyPI rename: it still recorded protolabs-a2a as a git ref pinned to v0.2.0 while pyproject.toml had moved to the PyPI range >=0.2.1,<0.3
  30. v0.103.0 2026-07-17
    Cowork mode — a prepackaged knowledge-worker archetype.
    Archetype preview — see what you're committing to before you pick.
    The wizard now finishes the mechanical setup it starts.
    Notes render markdown as you type
    Two core settings sections no longer file themselves under Integrations by accident.
    A rejected settings save no longer leaves disk ahead of the running agent.
    The shared note is guarded against lost updates
    Console responses are gzip-compressed
    ADR 0084
  31. v0.102.0 2026-07-16
    Registered ACP coding agents now surface in the runtime + model pickers (#1993).
    The agent can refine its own persona — a guarded edit_soul tool, off by default (#1985).
    Chat: a stalled turn self-heals, so a large answer never spins "Working…" forever (#1982).
    Chat: currency amounts no longer render as LaTeX math (#1983).
    Console: chat report cards and system notes share a quieter, consistent elevation (#1992).
  32. v0.101.0 2026-07-12
    HITL forms honor schema defaults and are fully keyboard-operable (#1978).
    Plugins: uninstall now tears down live state (#1955).
    MCP tool calls reuse one persistent session per server (default ON).
    Favorite models + /model quick-switch (#1957).
    Chat image controls: top-right action cluster + fullscreen Lightbox (#1960).
    Chat image attachments are bridged into the media store so tools can act on them (#1969).
    HITL forms float above the chat instead of shifting it (#1973).
  33. v0.100.0 2026-07-12
    Secrets manager: pull env vars from external secrets managers — Infisical first (#1963).
    Console: Settings ▸ Secrets panel for the secrets manager (#1965).
    Plugins: surfaces reconcile on config hot-reload (#1961).
    Plugins: refresh the last boot-only plugin wiring on hot-reload (#1958).
    MCP: normalize discovered tool names to the documented <server>__<tool> form (#1962).
    Plugins: consolidate the seam reference; fill gaps; fix drift (#1959).
  34. v0.99.0 2026-07-12
    Plugins: an optional tier for requires_pip (#1953).
    CI guard: the public roadmap can't rot silently (#1945).
    Console: wait tool blocks surface a real waiting state (#1914).
    Console: server-relative /media/ URLs render cross-origin (#1946).
    Console: multimodal tool results render their text, not the raw envelope (#1947).
    OpenAI-compat: /v1/chat/completions accepts multimodal content lists (#1943, #1949).
    Console: the selected agent theme renders on first load (#1916).
    Console: the mobile notch/status bar matches the header, not the accent (#1923).
  35. v0.98.0 2026-07-11
    Autonomous operating model — goals · tasks · scheduling · watches as one OODA loop.
    Media output channel for plugin tools (#1929).
    Multimodal ToolMessage — a tool can return an image the vision model actually sees (#1930).
    Reusable gateway HTTP client for plugins (#1931).
    orgChart plugin (#1925).
    Guide: safely exposing a protoAgent to the world (#1920)
    Goal turns fire on turn 1 and are headless-safe (#1910/#1911/#1912).
    Console: a completed long tool-call turn could render its reply twice (#1938).
    Console: the auth dialog is a blocking modal (#1926)
    task_output background-job tool.
    Fleet delegation biases to fire-and-forget.
  36. v0.97.0 2026-07-08
    Fleet trace export → the agent-fleet flywheel (the "Observe" seam, #1897).
    Fleet-trace sink + PII redaction (scripts/sync_fleet_traces.sh, scripts/redact_fleet_traces.py).
    Portable per-rig setup (scripts/setup_fleet_tracing.sh).
    Bigger touch targets on phones.
    Docs reader is a master-detail flow on phones.
    Settings collapses to a single column on phones.
    Modals/overlays use dvh on mobile.
    Mobile viewport correctness for the console.
  37. v0.96.0 2026-07-07
    Hermes is a first-class agent runtime
    Fleet-wide distributed Langfuse tracing.
    filesystem.allow_run defaults OFF on the headless tier
    A fleet member's plugin views 401'd through a token-gated hub
    A subagent hitting max_turns failed its whole delegation (GRAPH_RECURSION_LIMIT).
    Fleet members no longer inherit the hub's identity.
    An agent tracing to its own Langfuse project now produces a whole trace
    A background knowledge-ingest job now wakes the agent when it finishes
    Quieter plugin hot-reload logs
  38. v0.95.1 2026-07-07
    A2A producer tasks GC'd while pending at turn end (#1713).
    Classic A2A message/send got -32601 Method not found (#1854).
    Artifact panel kept the stale palette after an app-theme switch (#1872).
    Installed-plugin workflow recipes were silently invisible (#1867).
  39. v0.95.0 2026-07-06
    Findings source attribution — non-LLM panel members.
  40. v0.93.1 2026-07-05
    Supervisor on_crash bounded retry — RetryAfter + on_crash_max_attempts (#1823).
  41. v0.93.0 2026-07-05
    protoagent model — point at a local LLM in one line.
    Operator-MCP profiles + an env override, so "operate over MCP" is safe by default.
    A first-class protoagent command — the terminal control plane.
    React artifacts get a full design-system component set (@pl/ui), not just 9 primitives.
    The shared ops/ layer — one operation, three projections.
    GET /api/mcp/exposed — see which tools the operator MCP would hand a foreign client.
    BREAKING: the goal API is only under the plural /api/goals* now.
    /v1/chat/completions reports real token usage now, not zeros.
    The plugin update-CHECK now authenticates private repos too, not just install.
    The operator MCP no longer hands a foreign client HITL tools that hang it.
    plugin install of a PRIVATE GitHub repo now works on the default git path.
  42. v0.92.0 2026-07-05
    System lifecycle events
    Bulk delete-by-source in the Knowledge view
    web_search (DuckDuckGo) failed with CERTIFICATE_VERIFY_FAILED in the desktop app.
  43. v0.91.0 2026-07-04
    Goal completion contracts
    Fleet members can autostart on boot
    Guided goal-creation form
    Composer/HITL forms support conditional fields
    /goal {json} carries the completion contract
    delegate_to no longer hard-fails on member turns >60s
    Memory ▸ Injections is legible to non-developers
  44. v0.90.0 2026-07-04
    Background fan-outs report back in ONE briefing, not N
    Career Coach in the plugin catalog
    Server-initiated turns show a "responding…" indicator
    Shift over the add-chat button previews incognito
    Chat errors surface as a toast, not an inline banner
    Browser-style UI zoom (⌘/Ctrl + / - / 0)
    A saved theme survives a reload
    Scaffolded plugins that register a subagent or use Knobs pass their own smoke test
  45. v0.89.0 2026-07-04
    Quick-chat with any fleet agent from the command palette
    SOUL.md keeps a version history — never lose a persona iteration
    Telemetry is tagged with the active persona revision
    Browser-style UI zoom — ⌘/Ctrl + / - / 0
    Plugin setup: a "needs setup" cue + guided config for unconfigured plugins
    Plugins declare required config and degrade gracefully when it's missing
    Opt-in plugin auto-update policy
    coder.solve() can run one forced rung, for testing
    Plugins can open a form in the chat, not just reply
    /effort opens a picker in the composer
    Watches honor their per-watch interval_s cadence
    Hot-reloading a plugin refreshes its goal/watch verifier + hook registries
    Plugin smoke tests can assert surface lifecycle wiring
    The plugin loader no longer nags about the prescribed /api/plugins/<id> data router
    A manifest-less ghost dir under plugins/ no longer blocks install/uninstall
    A dropped provider stream reconnects instead of killing the turn
    A locked checkpoint write no longer silently kills a background turn
  46. v0.88.0 2026-07-03
    The Memory inspector tells the truth about what injects
    Memory view accuracy and polish
  47. v0.87.0 2026-07-03
    wait no longer stacks wake-ups — one pending wait per thread
    Dismiss a hard turn-error bubble in place
  48. v0.86.0 2026-07-03
    Declining a command is no longer a scary full-screen error
    Long commands and errors scroll instead of filling the chat
  49. v0.85.0 2026-07-02
    Semantic recall (embeddings) now ships OFF by default
    Windows reinstall over kept data no longer fails on a running server
    current_time works on Windows (and database-less hosts)
    A hung gateway embedding route can no longer freeze chat
  50. v0.84.0 2026-07-02
    The Windows desktop sidecar no longer self-kills ~2s after boot
    Desktop's system-wide hotkeys are now rebindable, visible, and self-healing
  51. v0.83.0 2026-07-02
    One-line background results render as a compact inline note, not a report card
    Per-subagent tool fences now apply to detached background jobs
    Desktop no longer aborts on launch when a global hotkey is already taken
    Desktop no longer launches into a silently dead window when port 7870 is taken or the server dies
    Release-tag-pinned plugins now see updates.
  52. v0.82.0 2026-07-02
    The console now says what each subagent does
    Plugin metric timeseries — sdk.record_metric / metric_history / metric_last
    Typed event contracts — emits: entries can declare payload schemas
    Knowledge lifecycle — sdk.knowledge_purge + epoch scoping
    Plugin-view event bridge: replay-on-subscribe + hidden delivery
    graph.sdk.react_on — reactive-rule sugar
    Plugins own their recurring cadence — and it dies with them
    Plugins can now enumerate and remove watches
    graph.sdk.spawn_background + graph.sdk.background_status
    Parallel approval-gated tool calls no longer crash the resume.
    Re-installing a plugin from its own origin converges instead of erroring.
    Testkit FakeRegistry now mirrors the full PluginRegistry surface
  53. v0.81.0 2026-07-02
    seccomp-profile.json moved to deploy/.
    The in-app update notes now match the Discord release announcement
  54. v0.80.0 2026-07-02
    Remote fleet members are fully manageable from the console
    A down or mis-tokened fleet agent gives you a way out instead of a boot hang.
    Background results are pushed, indexed, and worker-disposable
    The Work surface is card-first — no tabs
    The background report card is a real card
    /compact is now behind the chat.compact developer flag
    tools.disabled now actually removes any tool — including run_command — and the filesystem knobs are per-agent Settings toggles.
    Fleet: the hub no longer lends a remote member's token over an unauthenticated WebSocket, and live events now work through a token-gated hub.
  55. v0.79.0 2026-07-01
    Memory-regression evals
    Memory inspector console surface
    Incognito thread toggle in the console
    Trust-tiered injection
    Hot-memory write visibility
    Supersede-don't-delete staleness
    Namespace-scoped auto-injection
    Incognito threads
    Per-turn memory-injection record
    Memory-inspector REST surface
    recall_session(session_id) starter tool
    Knowledge Base view — collapsible source grouping + Shift+click quick-delete.
    One-command install
    Agent archetypes are a data-driven registry
    CI workflows are fork-friendly
    Fleet "New agent" now applies the archetype's persona
    Cross-session memory injection is now an attributed digest inside an untrusted-reference envelope
    Memory rows carry provenance.
    The docs build now gates every PR.
    Settings string_list fields can now carry an empty-string entry
    Chat code blocks: no empty header gap, a distinct lighter well, and no panel-stretch.
    Chat session-identity hygiene
    Artifact plugin (0.15.0) — pointer lock now works in games/canvas/3D artifacts.
    Artifact plugin (0.15.0) — SVG / Mermaid now render crisply instead of pixelating on zoom.
    Artifact plugin (0.15.0) — the selected artifact + version now survive a tab switch.
    A stale untracked plugin copy no longer shadows a newer bundled one.
    Plugin install git clone --no-hardlinks
    Console dev server no longer defaults to the prod backend.
    Removed the broken built-in "Project Manager" archetype.
    Instance collision warning no longer false-alarms on a shared box root
    Setup wizard: the archetype bundle-install result is no longer swallowed.
    Setup wizard: picking a persona-less archetype no longer blanks the editor.
  56. v0.78.0 2026-07-01
    Developer panel — view & toggle developer flags
    Developer flags — backend foundation
    Chat composer: terminal-style input history
    Artifact panel: pan & zoom for diagrams
    registerKeybinding on the fork extension seam
    Watch primitive — supervise many external conditions at once
    sdk.run_in_session(session_id, prompt)
    Two-credential auth: auth.federation_token
    Console set-goal form
    Chat: slash commands trigger mid-input + render as command bubbles
    Agent switcher: always available, with a Fleet-settings shortcut
    Chat: Cmd/Ctrl+O toggles the latest tool-call block
    Chat: /compact — summarize + archive a long thread
    Knowledge panel: Upload / Add now open in a dialog
    Goal mode is now drive-only; the monitor disposition is retired
    Goal continuation protocol → tools
    The A2A-streaming and non-streaming goal drive loops are unified (#1497), fixing a fresh-context thread-id drift.
    Settings sub-panels share one container
    wait tool output is conversational
    Desktop app builds are on-demand
    RCE-via-chat closed
    Watch evaluation is serialized per watch id
    New ADR 0066 (federation token + operator channel) and ADR 0067 (watch primitive); ADR 0030 marked superseded
    PROTO.md § Run it
  57. v0.77.0 2026-07-01
    Cross-machine fleet hardening — A2A federation is fault-transparent
    Remote fleet members surface their health immediately
    Discovery auto-sweeps on hub boot
    config explain diagnostic
    Real multi-instance fleet test harness
    Artifact is now a bundled core plugin, on by default
    Artifact render errors feed back to the agent
    Multi-step wizard + choice-card HITL forms
    The agent can ingest documents & media into its knowledge base
    Two-tier instance paths (box / instance) — one resolution rule, no more double-scoping
    React artifacts are more forgiving + the render loop is proactive
    Docs reader: in-content cross-reference links route in-app instead of breaking the iframe
    A crashed co-located fleet member is now detected and restartable
    Autonomous turns no longer deadlock on a human-input pause
    HITL tools are hard-denied to subagents
    Settings surfaces when the agent config shadows a host-scoped field
    The ⌘K command-palette chat survives being closed mid-turn
    Knowledge: fleet/commons sharing + the reusable background-job primitive
June 2026 69
  1. v0.76.0 2026-06-30
    "Manage plugins…" in the rail context menus
    Reveal toggle on secret fields
    Settings true-up — one canonical config system
    Settings surfaces no longer swallow load/save errors
    Identity name and fleet delegates save through the canonical settings cascade
  2. v0.75.0 2026-06-29
    Egress allowlist in Settings
    Custom model gateway no longer blocked on the connection test
    Plugin config appears without a restart
  3. v0.74.0 2026-06-29
    Bypass-permissions mode
    run_command runs shell operators
    Slash-command notices render as system notes
  4. v0.73.0 2026-06-29
    Background batch delegation
    Live tool-card feed for background agents
    Settings ▸ Knowledge split into sub-sections
    Tools view — MCP tools grouped by server
    Settings IA — domain-first
    Tools view — grouped by plugin + subsystem
    Built-in subagents answer natively
    CI off the deprecated Node 20 action runtime
    Structured-output parser retired
    Concurrent same-conversation turns no longer corrupt chat history
    Chat answers no longer truncated; A2A tasks return the real final answer
    Subagent token streams isolated from the live chat
    Cross-tab chat no longer clobbers itself
    ACP coding-agent eviction race closed
    Cross-context streaming guard
    File uploads restore the token prompt on auth failure
    Secure defaults for metrics and MCP secrets
    Backend launch-hardening — ingestion SSRF guard + credential hardening
    Plugin auth-bypass and event-loop hardening
    Fail-safe plugin secret redaction
    Operator-token storage guidance
  5. v0.72.0 2026-06-28
    Context-window meter + per-turn cost/time
    Vision-describe pass for text-only models
    "Get models"
    Inline components re-enabled
    Per-stimulus Activity attribution
    Inline action feedback → toasts
    Deduped inbox/Activity now-item notifications + deliver-before-fire
    Clear error for images on a text-only model
    Chat-tab trash only on the hovered ✕
  6. v0.71.0 2026-06-27
    Panel-focus keybindings
    ⌘K palette chat streams with live text↔tool interleave
    Streaming answer text is full-width, no loading side-bar
    No hardcoded emojis in the UI
    Full-screen document viewer
    Keyboard shortcuts
    Quick-delete a chat tab
    Hide a rail surface without disabling its plugin
    Configure a plugin from its rail icon or util-bar widget
    Chat tab context menu
    Fork-safe console behavior seams
  7. v0.70.0 2026-06-24
    Plugins can own /<name> chat control commands
    "Report a bug" link in the hamburger menu
    GitHub is no longer in core — it's a standalone plugin
  8. v0.69.0 2026-06-24
    Native reasoning — the agent's thinking now streams from the model, not a forced text protocol.
    Chat markdown now renders through the design system's Markdown renderer
    Heavy research turns no longer wedge the server.
  9. v0.68.0 2026-06-23
    scripts/reset.sh — factory-reset the default (prod) instance from the CLI.
    Chat tool-call rendering overhaul.
    show_component (inline component rendering, ADR 0051) is temporarily disabled
    The Goals and Tasks panels refresh on a bus push instead of polling every 5s.
    Failed or user-cancelled task delegations now close as error cards (the X).
    A subagent's own tool calls reliably nest under the delegation card.
    Mid-stream output rendering no longer rescans the whole response on every chunk.
    Empty-rail panel toggles fully disable.
    Console-poll handlers no longer block the event loop.
    The Docker image now serves the React console and stays in dep-lockstep with pyproject.
  10. v0.67.0 2026-06-22
    Per-agent ACP launch overrides are honored.
    ACP delegate health probe is initialize-only — it no longer opens a session every 120s.
    macOS desktop app finds Homebrew/nvm/Volta/asdf-installed binaries.
    Workspace port assignment skips OS-occupied ports.
    The per-agent theme is instance-scoped.
    The browser tab favicon + theme-color follow the active per-agent theme.
    ACP coding-agent subprocesses no longer leak as orphaned processes.
    Dialogs no longer render their content cramped flush to the body edge.
    Coding-agents guide: Codex needs the codex-acp adapter.
  11. v0.66.0 2026-06-21
    The agent's task board is now "tasks", not "beads."
    Create a task from a dialog.
    Dropped the dead br fallback from the core task board.
  12. v0.65.0 2026-06-21
    Schedule view: open a job to read the full prompt + edit it in place.
    Chat: reasoning renders inline, in emission order.
    Deleting a scheduled job confirms first.
    Removed the Workstacean scheduler backend.
    Chat: assistant text and tool calls render in emission order.
    Settings: Host-console edits stop "resetting."
    ACP: load_skill works through the operator sidecar.
    Chat: no stray gap between tool calls.
  13. v0.64.3 2026-06-20
    Adding or editing a delegate now opens in a dialog instead of pushing the Delegates panel around.
    The New/Edit skill dialog has more breathing room — roomier padding and field spacing.
  14. v0.64.2 2026-06-20
    The "Browse common servers" dialog now fills its height with the card grid — search stays pinned, no dead space below the cards.
  15. v0.64.1 2026-06-20
    Desktop: the "Browse common servers" picker now lists the curated MCP servers — they weren't being bundled into the packaged app.
    The "Host · box defaults" badge moved into the Settings dialog header so it no longer pushes the panel content down.
    More breathing room in the "Browse common servers" dialog — the search and cards no longer sit flush to the edge.
  16. v0.64.0 2026-06-20
    Quick-add common MCP servers from a curated picker in Settings ▸ MCP — one click (or a path/token) and the server's tools are live.
    Share MCP servers across the box: a layered agent runs a shared commons of servers alongside its own, with one-click share/unshare and tier badges.
    The desktop in-app updater now shows the curated changelog for the new version instead of raw commit subjects.
  17. v0.63.1 2026-06-20
    Uninstall works again for git-installed plugins — a regression had left them installable and toggleable but not removable.
    Plugin management is consolidated into one surface, and Install-from-URL is now a dialog opened from the Installed toolbar.
    The host-scope cue in Settings is a compact "Host · box defaults" badge instead of a full-width banner.
    Tightened the Execute Code plugin's catalog-card description so it fits the display.
  18. v0.63.0 2026-06-20
    Shared knowledge tier — a commons every agent on the box can read, with tier badges and share/unshare in the console.
    Skills got progressive disclosure (an always-on index + load-on-demand) and tier-aware curation.
    execute_code is now an opt-in plugin — enable it under Plugins; it's out of the default tool set.
    A new desktop download page with a signed macOS installer.
    Honest middleware surfaces — dropped a dormant capture path and made the session-memory and enforcement surfaces say what they actually do.
  19. v0.62.0 2026-06-20
    The Knowledge rail icon no longer disappears.
    The active tab's underline is the brand accent again, not white.
    Removed the "This is the memory the agent retrieves into context…" footer
    Docs accuracy pass.
  20. v0.61.0 2026-06-20
    An ACP coding-agent runtime now gets protoAgent's full toolset by default.
    Removed the redundant "working…" status strip above the chat composer
  21. v0.60.0 2026-06-19
    The app side drawer now has a Changelog link.
    Goal mode is always on.
    The frozen desktop app now bundles config/skills.
  22. v0.56.1 2026-06-19
    The in-app ⌘K palette no longer inherits the desktop launcher's frosted styling.
    Plugin entries in the palette dropped their "open here" hint.
  23. v0.56.0 2026-06-19
    The command palette (⌘K) is now command-driven.
  24. v0.55.1 2026-06-19
    The desktop quick launcher (⌥Space) is now a frosted, rounded floating panel.
  25. v0.55.0 2026-06-19
    Chat can dock at the bottom panel.
    The chat "still streaming" pulse now shows on the right rail and bottom dock.
  26. v0.54.0 2026-06-19
    Raycast-style global quick launcher (desktop).
    Background agents widget no longer needs a page reload to appear.
  27. v0.53.0 2026-06-19
    Docs plugin — read and ask about protoAgent's own docs
    user_only skills
    Desktop update notice is now a full modal with a markdown changelog.
    Plugin views are themed in the desktop app
  28. v0.52.0 2026-06-19
    Desktop app catches up to v0.51.x.
  29. v0.51.1 2026-06-19
    Utility bar in the console.
    Documentation overhaul.
    The marketing changelog no longer shows empty releases.
  30. v0.51.0 2026-06-18
    "Skills loaded" chip in chat.
    Author/edit skills in a modal dialog
    Dropped the never-used emit_skill capture path.
    Desktop sidecar bundles config/plugin-catalog.json
  31. v0.50.0 2026-06-18
    Skills CRUD in the console.
  32. v0.49.1 2026-06-18
    Background-job dialog shows the full result
  33. v0.49.0 2026-06-18
    Native command-palette chat
  34. v0.48.0 2026-06-18
    Command palette (⌘K).
    Unified plugin manager.
    Always-on hamburger menu
    Discord is no longer bundled
    Plugin git refs are validated before fetch
    ADRs 0057 / 0058 / 0059
  35. v0.47.0 2026-06-18
    Google (Gmail + Calendar) and Slack are no longer bundled — they move to standalone external plugins.
  36. v0.46.0 2026-06-17
    In-app update notice with the changelog
  37. v0.45.0 2026-06-17
    Real chat streaming in the desktop app
    Desktop in-app updater no longer 404s
  38. v0.44.0 2026-06-17
    Desktop updater public key now matches the signing key
  39. v0.43.0 2026-06-17
    Portfolio plugin.
    Mid-turn steering.
    Drag-to-reorder chat session tabs.
    Setup wizard + forms rebuilt on the design system
    Instance-scoped agents resolve their installed-plugin config correctly
    ADR 0056
  40. v0.42.0 2026-06-17
    ACP forget_session — start a coder fresh when its workdir was recreated.
    dream & distill — scheduled self-curation subagents.
    New-user setup wizard, rebuilt around archetypes.
    ACP coding-agent client: a real coding turn died on its own output.
    operator.project_dir actually drives the workspace root.
    Setup probe could 500 or hang the runtime step.
    Out-of-graph subagent runs now see the lead's full tool set.
  41. v0.41.0 2026-06-15
    Knowledge search returns the RRF relevance score.
    wait resumes now appear live in the chat tab.
    Inbox: a fired now item is now marked delivered.
    The fallback-models setting picks from the gateway list.
    Scheduler startup catch-up no longer logs scary tracebacks.
    The scheduler retries the jobs.db owner-lock instead of giving up.
    **set_goal rejects an unknown verifier instead of creating an unsatisfiable
    Settings model fields offer the gateway's model list.
    The settings schema is cached client-side.
    Per-tab model selection.
    One-call goal-driven recurring loop (graph.sdk.start_goal_loop / stop_goal_loop).
    **Plugin telemetry + agent decision-log kit (graph/telemetry.py, `from graph.sdk import
    **Runtime knobs + presets control surface (graph/knobs.py, `from graph.sdk import Knobs,
    Host-free plugin test harness (graph/plugins/testkit.py).
    Supervised background-task helper (graph/supervisor.py, from graph.sdk import supervise).
    The Tools tab shows exactly what the agent can call.
    Slash-command palette can't drift from the dispatcher.
    Background subagent results are delivered back to the chat that started them.
    Non-streaming chat no longer returns a silent empty 200.
    First-party web-research skill is reachable again.
    set_goal is now actually bound to the agent.
    wait's same-session resume now works.
  42. v0.40.0 2026-06-14
    Left panel no longer springs back to ~50% when resized smaller.
    Opt-in JSON logging (LOG_FORMAT=json)
    Deploy guide: backup/restore + shutdown semantics.
    wait resumes in the same conversation
    Background-agent notifications render legibly again.
    wait tool — yield instead of busy-polling
    Paste images + large text as attachments
    File-only chat send
    User-facing skills — trigger a skill with a slash command
    Chat message toolbar — copy, fork, regenerate
    scheduler.fired event + orphaned push-config sweep
    Native vision in chat
    A2A alignment polish + realtime cost/goal events
    Renderable chat components over A2A
    Background jobs: realtime progress + stop/inspect controls
    Reasoning display in chat
    Background-jobs console widget
    Chat file upload (composer UI).
    Background subagents wake the agent on completion
    Chat attachments — tiered context (backend)
    Background subagents
    Smarter subagent delegation
    Audio & video ingestion
    Document ingestion engine
    Contextual enrichment on knowledge ingest
    Document chunking on knowledge ingest
    Retrieval-quality eval harness
    Host config settings regrouped
    Chat composer migrated to the design-system PromptInput
    Batched embedding on document ingest
    Parallel contextual enrichment on ingest
    Semantic recall tuned + made tunable
    Setup wizard slimmed to the essentials.
    GitHub Copilot is now selectable as the ACP runtime
    Chat composer focus polish.
    Embedding circuit breaker clears on a passing connection test.
    Knowledge embeddings default to qwen3-embedding.
  43. v0.39.0 2026-06-13
    Restart the server from the console — a gated POST /api/restart plus a Settings▸Plugins button (no terminal needed for a change that can't hot-load)
    The left console panel can be dragged down to 200px without snapping back to 280
    OpenShell deploy path validated end-to-end against OpenShell v0.0.59
  44. v0.38.0 2026-06-13
    ACP client: restart-surviving sessions + thought streaming
    Settings: a scalar multiline text field + conditional depends_on visibility
    SSRF: the model-probe and fleet-remote registration now run egress checks
    **A plugin's declared secret can no longer slip into the tracked config YAML when
  45. v0.37.0 2026-06-13
    graph.sdk.complete() — a bare LLM completion for plugins.
    Settings is a vertical-nav + collapsible-groups layout now.
    Design system bumped to @protolabsai/ui 0.30.0
    The topbar Settings overlay panel fills the full dialog height
  46. v0.36.0 2026-06-13
    The committed plugins.lock now ships empty.
    One-click plugin sync from the console.
    Knowledge base CRUD from the console.
    Harvest-on-delete is now opt-in.
    Drag-and-drop rail positions for plugin views now survive a reload.
    A render error no longer white-screens the console
    The documented kit-loading pattern for plugin views was broken
    The console prompts for the operator token on 401
    The Notes plugin editor adopts the DS plugin kit (rule 4)
    Design system bumped @protolabsai/ui 0.26.2 → 0.29.0 (+ @protolabsai/design 0.5.1).
    ADR 0049 — bundle pin lifecycle
    Force re-install no longer claims a live hot-mount it can't deliver (#942).
    Annotated-tag pins no longer report a permanent false "Update available".
  47. v0.35.3 2026-06-12
    **Identity panel: the "Saving writes SOUL.md…" helper + save status now sit
    Desktop first-run: panels no longer flash "Load failed" and need a reload.
    macOS desktop: the brand again clears the native traffic lights.
  48. v0.35.2 2026-06-12
    Switching agents in the desktop app no longer breaks the window.
    The app version is shown in Settings ▸ Host / App ▸ Overview
  49. v0.35.1 2026-06-12
    **The desktop app's backend now actually starts (it was dead on arrival in
    Desktop release builds now write logs.
  50. v0.35.0 2026-06-12
    **Box-runtime knobs (bind interface, fleet ports, discovery, warm policy) are now
    An app update can no longer silently strand fleet members on the old binary
    The desktop app updates itself in place.
    **Session memory now persists on non-container hosts (and stops writing to the drive
    The console is an installable PWA (manifest-only — deliberately no service worker).
    **A secret saved for an installed-but-DISABLED plugin now routes to secrets.yaml,
    **The devkit's "edit then reload_plugins" loop now picks up edits to EVERY file, and
    Settings are reorganized around *scope* — a two-home shell + contextual quick-settings.
    The shared-skill commons is now legible in the console.
    macOS desktop releases are now verified pristine — and the DMG itself is notarized.
    Desktop builds for Linux and Windows.
    A configured plugin/model secret now shows a clear "set" badge in Settings.
    Adopt @protolabsai/ui@0.26.2
    **A fleet member's plugin secret (e.g
    Switching to a not-yet-running fleet agent no longer flashes errors in its panels.
    A declined or failed tool now shows the red X on its card, not a green "done".
    Approving a gated action no longer dumps an "approved" bubble into the chat.
    Resizing panels felt sloppy and "wouldn't close right" over plugin views.
    Swapping between fleet agents wiped the chat view.
    The fleet proxy now forwards WebSocket upgrades (#883).
    Installing a plugin from the console now auto-enables + runs it
    Grouped the loose root-level modules into packages
    The Gradio chat UI (the --ui full tier).
    **The desktop app reported its version as 0.0.0 (version-coherence Cross-cutting
    **Fleet members render plugin views with no design system (version-coherence
    The plugin devkit can now build a plugin AND run it live — no restart
    plugin new / plugin new-bundle CLI
    Spin local fleet members down when the host exits (version-coherence Axis 1).
  51. v0.34.0 2026-06-10
    CSS comment corruption that silently shrank plugin iframes (build guard).
    Design-system 0.26 + slug-aware plugin-kit apiFetch/apiUrl (protoContent#208).
    Plugin update / version-awareness.
  52. v0.33.0 2026-06-10
    Architectural import contracts in CI
    Hub↔remote version handshake — fleet version skew is visible now
    Design-system 0.25 adoption + theme.css decomposition (#832).
    Layered settings cascade + settings IA.
    Plugin-view authoring hardening (#884).
    Light mode works on the hand-rolled chrome (#842).
    **Enabling a plugin's console view works immediately
    Plugin views resolve on fleet members, not the hub (#879).
    Host defaults renders as one cohesive panel (#878)
    A single Ctrl-C shuts the server down cleanly (#882).
    config_to_dict now emits the complete plugins section
    A2A task records no longer accumulate forever on an always-on agent
    Webhook DNS resolution no longer blocks the event loop
    min_protoagent_version is actually enforced
    Autostart launches the server again
    Knowledge embedding no longer blocks the event loop
    Chat no longer rewrites localStorage on every streamed token
    Token-less non-loopback binds now refuse to start.
    **Persistence hardening
    Pinned the release-tools clone in the PR gate
  53. v0.32.0 2026-06-10
    Layered settings cascade — host-shared defaults agents inherit and override
    Remote fleet members — the agent there, the UI here
    Tenant guard
    Tailnet discovery
    Co-located-instance warning
    Cross-agent "turn finished" toasts
    Opaque agent ids + rename
    Enable delegates without a restart
    Cold agents resume on navigation
    Discover no longer lists a co-located agent twice
    mDNS advertise actually works
    A2A task reconcile had rotted against a2a-sdk 1.1
    Each fleet hub owns its own registry
    pyproject.toml is the dependency source of truth
    Config is a single source of truth
    Shell + settings banners are the design system's Alert
    Retired the deprecated peer_consult / peer_list tools
  54. v0.31.0 2026-06-10
    Intro splash shows once per session
    Plugin devkit refreshed (v0.2.0)
    Artifact plugin is now external
    Design system → @protolabsai/ui 0.18, with console polish
    The /active global-pointer proxy machinery
    Retired Module Federation
    Fleet console — run a fleet of agents from one console.
    Chat panel is a slot
    Plugin-driven console navigation
    Goals come alive in the console
    Goals broadcast on the event bus
    Telemetry opt-out in Settings
    Plugin notification dots + event relay
    Plugin event bus
    Fork extension seam
    Generative-UI artifacts
    Generative-UI artifacts
    Secret-scan CI gate
  55. v0.30.0 2026-06-09
    Notes plugin — the first-class React reference plugin
    Plugin trust gate
    Plugin-UI SDK: host bridge + reference remote
    Plugin-UI SDK foundation
    Mobile shell
    Everything-swappable rails
    Right-click context menus
    Design-system foundation
    Swap surfaces between rails
    Resizable right panel — real handle
    Symmetric dual rails
    Persisted UI state
    Plugin UI — first-class React
    ACP persona reaches GitHub Copilot
    ACP turns attributed correctly in telemetry
    Console upgraded to React 19
  56. v0.29.0 2026-06-08
    ACP answer-text streams
  57. v0.28.0 2026-06-08
    ACP tool calls surface as cards
    ACP runtime adopts your persona
    Runtime selector leads the Agent settings
    Auto-scoping for co-located instances
    ACP-only setups need no gateway
    Agent runtime selectable in the console
    ACP delegate teardown
    ACP runtime: agent now uses protoAgent's operator tools, not its own
    ACP runtime: request-metadata scope cross-context reset
    Instance-scoped config
    code_with tool + the coding_agent plugin
  58. v0.27.0 2026-06-08
    Run protoAgent's brain on a coding agent — proto, Codex, or Claude can now drive the runtime over ACP, while protoAgent stays the operable A2A / console / goals / scheduling shell around it.
    Publish protoAgent's tools as an MCP server — point Claude Desktop, Cursor, or a coding agent at an instance and operate it (notes, beads, memory, workflows), allowlist-gated.
    Context is assembled cache-friendly under the hood — a stable persona prefix plus per-turn deltas — so the coding agent's own prompt caching stays intact.
  59. v0.26.0 2026-06-08
    Settings now live where they belong — agent settings in the Agent view, memory settings in Knowledge, and a leaner central Settings (Overview, Telemetry, Plugins, System).
    The Plugins page is tabbed (Local, Market, Download) with one-click enable/disable — no config editing or restart for most plugins.
    Add MCP servers right from the console — fill a quick form or paste a standard JSON config blob, and they connect live.
  60. v0.25.0 2026-06-08
    Reorganized console — the agent's makeup (identity, tools, MCP, subagents, skills, middleware) lives in one Agent section; Knowledge is a single panel; status + telemetry moved to Settings.
    Schedule is now a one-click right-rail panel with a friendly editor — calendar, presets, and timezones, no hand-written cron.
    Plugins can contribute middleware and right-rail panels now, and a plugin view can use any icon (no allowlist).
    Leaner core — GitHub tools are an opt-in plugin and the tool list is grouped by subsystem.
    Reliability — scheduled tasks no longer fire duplicates or run away, and goals no longer leak between agents.
  61. v0.24.0 2026-06-08
    A new Features page comparing protoAgent to the alternatives, plus headless docs — run it over the OpenAI-compatible API or A2A with no UI.
    Telemetry you can act on — export to CSV, see on-disk size, and a retention guardrail so it can't grow unbounded.
    Pin a specific model per subagent from config.
    A friendlier Schedule tab and a consistent panel layout across the console.
  62. v0.23.0 2026-06-07
    Pluggable knowledge backend — swap the default SQLite store for your own vector database as a plugin.
    Monitor goals — long-running objectives the agent checks on a cadence and reacts to.
    A communication-plugin standard with a first-party Slack plugin, alongside Discord and Telegram.
    "Playbooks" renamed to "Skills" for clarity.
  63. v0.22.0 2026-06-07
    The agent can set its own standing goals, ground-truthed by plugin verifiers, with lifecycle hooks.
    Plugins can contribute goal verifiers and a wider set of console-view icons.
  64. v0.21.0 2026-06-07
    Plugin Devkit — a featured plugin that teaches the agent to build its own plugins (a scaffold tool, a plugin-architect subagent, and the authoring skill, in one bundle).
    Clean plugin delete — uninstall now also removes a plugin's enabled reference, with --purge to wipe its config + secrets too.
  65. v0.20.0 2026-06-06
    Install plugins from a git URL — `python -m server plugin install <url>`, pinned in a lockfile, with the safety model built in (install ≠ enable ≠ trust).
    A plugin repo is a full bundle: tools, subagents, skills, workflows, and console views all come in.
    Console Plugins panel — paste a URL, review, install, uninstall.
  66. v0.19.0 2026-06-06
    Plugins can add their own console rail views — a dashboard or page, no console rebuild.
  67. v0.18.0 2026-06-06
    Token-by-token answer streaming in the console chat.
    Chat keeps going when you navigate away and back, and self-heals an interrupted stream.
    Brand favicon across the app + docs.
  68. v0.17.0 2026-06-06
    Unified delegate registry + a hot-swappable console panel — manage the agents and endpoints your agent talks to (a2a / openai / acp) from Settings.
  69. v0.16.0 2026-06-06
    Spawn CLI coding agents over ACP — hand a real coding job to protoCLI, Claude Code, Codex, or Gemini CLI.

Full release notes + source on GitHub.