Changelog
Every release, newest first
What shipped in each version of the tokenstat CLI, desktop app, and MCP server.
vUnreleased3 fixed
- Installing an agent on a server works. A host started by systemd is handed no home directory, and everything it ran inherited that: a vendor's installer stopped with
HOME: parameter not set, and a tool that did install read as missing afterwards, because~/.local/binhad been built from an empty string. The daemon now takes its home from the account itself, so installers, agents, git and ssh all have one. - Another machine's folder offers its whole launcher again. Opening a remote folder after a local one never asked the owning machine what it could run, which left one shell tile and no way to install anything from the Mac. It now keeps asking until that machine answers, so connecting later fills the grid in rather than leaving it short.
- On the Mac, an empty conversation list sits in the middle of the pane, a new terminal opens at the size it keeps instead of redrawing once, and a conversation can be removed from its own menu.
v1.0.12 new · 3 changed · 9 fixedSmall corrections on top of 1.0.0, most of them invisible.
- A machine that already has folders can get more from its device page: the folder picker and clone live there as well as in the empty state.
- Devices carries an auto-connect switch per machine. Off stops the app dialling on its own and leaves a live connection alone; only Disconnect drops it.
- The Add this device, clone, and folder bottom bars follow the theme, as do the client search fields and menu separators.
- On the Mac, Today, Last 7 days, and Busiest are separate panels, like the phone's tiles.
- On a new Mac, Home opens on Balanced with the work first.
- A finished turn always releases the conversation, so a new message can no longer sit queued with sends doing nothing, and the app says why when a turn is still finishing.
- Setting up a server retries over a stale pairing file, trusts the new machine before checking it, and goes from the machine straight to a project.
- The Windows build and its tests are green again.
- A transcript the meter cannot reach reports an error instead of a zero usage figure.
- The host runs an existing login shell instead of assuming zsh, so the Shell tile works on machines that have no zsh. An installer that exits zero without delivering reads as a failure with its output.
- Disconnecting from a machine sticks: the peer sweep no longer re-dials it on the next pass. Removing a remote folder asks the owning machine instead of failing silently.
- Each machine's launcher list is its own, so a second machine shows its own tools, with a shell tile while its catalog loads.
- The screen viewer is not offered on headless Linux hosts.
- The CLI says how to approve a pending device in host access.
v1.0.017 new · 4 changed · 7 fixedA phone can now produce a working machine. Until this release tokenstat assumed a computer already existed: install the desktop app, register a folder, and the phone became a window onto it. Now somebody holding only an iPhone can end up with a server that runs agents.
- Set up a machine, from the phone. Four doors: a server you already have, a machine at DigitalOcean or AWS, the Mac you work on, or none of them, which keeps working and is not a failure state. The server door connects over SSH with your own key, checks what is on the machine before writing anything, installs the host, signs it in, and comes back paired. You watch the whole install in a real terminal rather than behind a spinner.
- The same install, to run yourself. Handing an app an SSH key is a reasonable thing to decline for a server that matters. The command is on screen with a comment per flag, and it is also what the app offers when SSH cannot get through, which a bastion or a provider console will do.
- A machine nobody is sitting at can let a device in. Being on the account has never been the same as being allowed to open somebody's work, and on a server there is nobody at the keyboard to answer. Three ways now, all of them from the machine's own console: allow a device by name, grant the device that is installing it, or print a one-time code and type it into the app. The code never reaches tokenstat.ai, expires in fifteen minutes, works once, and is retired after five wrong guesses.
tokenstat hostis a full console. Status that reads in the order you debug in, start, stop, restart, logs, the devices allowed here, invites, an audit log of every grant, and an uninstall that never touches your folders. It says who agents run as at the top, because a root install gives every agent on that machine root.- The always-on host ships with the CLI on macOS and Linux, and survives a logout on Linux instead of dying with the SSH session.
- Choose a folder on a machine with no screen. The machine answers what a directory holds, so a phone can pick a folder on a server the same way a Mac picks one in a panel. It can make a folder, and it can clone a repository onto a machine that has none, in a terminal that can be answered when git asks for a passphrase.
- Empty screens now offer the thing that is missing rather than describing the hole: no machine offers to set one up, a machine with no folders offers both ways to give it one, and a machine that is not answering says what to run on it when it is a server rather than telling you to wake a Mac.
- Home is yours to arrange, on iPhone and iPad. Drag the cards into the order you read them in, switch off the ones you never do, or start from one of three arrangements: Balanced, Work first, Usage first. A small preview shows what you are about to get. Every card can be off, and a clear Home is a real answer rather than an empty screen. The arrangement belongs to the device, so a phone and an iPad can be different, and Done applies it in one go while Cancel really cancels. Reordering also works from VoiceOver, not only by dragging. The greeting and anything about your account or your connection stay where they are: hiding Activity must not hide "you are offline".
- A message is sent once, even when the answer goes missing. A machine that takes a message now keeps a receipt for it, so pressing Send again after a connection that went quiet gets you the conversation rather than a second agent run on the same words. When that happens the message goes back in the field with a line saying the machine did not answer and that sending again is safe, and the app asks the machine what became of it. The machine has to be on this version for the guarantee; an older one behaves as it did, and the app does not repeat a send to one.
- Half-written messages are kept. What is in a chat's message field stays with that conversation: leave it, open another thread, quit the app, and it is there when you come back, with the files you attached to it. A list marks the conversations holding words you have not sent. Sending a message keeps the words until the machine has taken them, so a refusal puts them back instead of losing them. They are kept on this device only, and if a write ever fails the field says so rather than claiming it saved.
- Opened conversations are kept on this device, encrypted. Open one again with no connection and it reads from the saved copy, which says when it was saved and what it does not contain. Pin a folder or a conversation to Home to keep it close, on the desktop Home as well as the phone. Saved copies never leave the machine, a damaged store is quarantined rather than deleted, and removing a saved copy clears its history everywhere.
- Search your saved work, and the machines that are awake. One search covers the conversations on this device and asks the hosts that are up, then merges the answers with live results first. History is shared across windows, and a result that cannot be opened says so instead of dropping the list.
- Hand work to another device. Start on one, carry on on the other: the draft, the files and the place in the transcript move across, and an import whose files are gone says so instead of guessing.
- A message queued offline is sent when the machine is back. The send keeps its files, its place and its review state through a crash, a reconnect or a quit, and repeating it is safe: the machine answers from the receipt instead of running the agent twice. The first page of a long conversation reloads once after upgrading, because transcript positions changed format.
- The update finds the computers too. Devices shows the release a paired host runs. A host downloads its own update, proves the new binaries run, and restarts when nothing it owns is running. Otherwise it waits and says what is in the way, and you can insist, having been told what insisting ends.
- Assistants can find their way around. The MCP server lists workspaces and manages tasks and notes, so an agent working through it sees the same workplace a person does.
- New dashboards on macOS and iOS. Usage, activity and rankings read the same on both, with accessible tables and a refreshed look.
- The getting-started card no longer says the product starts on a computer, because it no longer does.
- Devices leads with setting a machine up rather than listing the ones that already exist.
- The app icon is new: layered glass with the mark over dark and light grounds.
- Home tells a machine that is offline apart from one that is asleep, and plan cards load only while they are on screen.
- Deleting a local conversation from the Mac sidebar while a remote folder is open now uses the local machine. Host recovery notices also keep their order when several calls finish together, so a healthy helper cannot leave a stale reconnect warning behind.
- Remembered conversations now belong to their account, machine and folder. Separate windows preserve each other's recent selections; old unscoped selections are not assigned to whichever account signs in next.
- Cursor chats work. A Cursor turn used to fill the transcript with rows called HookAdditionalContexts and GetMcpTools, none of which ever finished, while every shell command it tried came back refused without saying so and its answer arrived two or three times over. Tool rows now carry the name of the tool that ran, its output, and its verdict; a file it changes shows the red and green lines; each message appears once, including when the CLI loses its connection and says the whole turn again; and the conversation carries over between messages instead of starting again each time. When Cursor itself gives up, the chat says so in a sentence instead of showing you
RetriableError: [resource_exhausted] Erroras though the agent had replied it. - A chat that has been open for a while no longer stops responding. Two causes, both of them a message arriving several times a second into a transcript in the middle of laying itself out. The local helper told the window it was healthy after every call it answered, from whatever thread had answered one; it reports once per change now, on the thread that draws. And the message field told the window its height might have changed on every update, whether or not a word had been typed, which made the conversation beside it measure every message it was holding. It says so when the draft or the width actually changes.
- The message field no longer answers its own writes. Putting the draft and the caret back where the app said they were made the field report that same position as news, mid-draw, which asked for another draw. It is quiet while it is being set, and it reports a caret only when the caret actually moved.
- Navigation, chat rendering and remote sessions are steadier on iPhone and iPad. Saved places stop retrying after you have moved on, search preparation stays with its own screen, and recent chats load against the destination they were opened for.
- A new account with no handle yet can finish setting up: the setup gate no longer reads it as signed out. Setup doors also stay quiet about failures until one is entered, then offer a retry or a sign-in card instead of a dead button. Relay use is metered by what it was for, so a pooled channel reused for chat no longer bills chat bytes to the terminal.
v0.9.25 fixedThree ways a chat could stop working: a tool that never finished, a transcript that stopped responding behind it, and a notification tap that closed the app.
- A Claude tool call ends when its result arrives. Bash and the rest used to stay marked Running, with an indicator that never stopped, for the rest of the conversation.
- A chat with several tools running no longer stops responding. Every running row turned its own indicator, and a transcript full of them spent all its time laying itself out again instead of drawing. One row turns now and the rest say Running in words, so however many the computer reports, the conversation stays usable.
- Tapping a chat notification on iPhone and iPad no longer closes the app. 0.9.1 fixed one cause of that. This is the other one, and it closed the app every time.
- A notification for a conversation or a terminal that is no longer there lands on Workspaces instead of doing nothing at all. It also stops trying after a minute, rather than dialling the computer again on every later visit to that screen.
- A long reply is lighter to stream on both the Mac and the phone. The turn being written used to push the rest of the conversation out of the store that keeps finished messages ready to draw, so scrolling back through a long chat had to rebuild what it passed.
v0.9.14 new · 7 changed · 3 fixedChat on the phone catches up with the Mac: sends that queue, notifications that open the work, folder history, and a composer that stays on the transcript.
- Tapping a notification opens the work that needs you. A terminal waiting on a permission prompt opens that session. Otherwise the chat that finished, or is waiting, opens. On a Mac it brings the window forward. On iPhone and iPad it opens over the app, unless that conversation is already on screen, in which case the same window stays.
- Send while a turn is still running queues the next message. A compact strip above the composer says it is waiting to send after this turn. The next message can be edited or removed there, and Send now stops the current turn so that message goes out next. Two or more waiting messages open from View pending, so the list does not cover the transcript.
- A folder on iPhone and iPad has History, the same previous-commit list the Mac inspector already showed. A folder that is not a git repository, or one that has no commits yet, gets a drawn empty state instead of a blank list.
- Sessions on iPhone has the branch picker and the bypass switch the Mac already shows. A launch from the phone can skip permission prompts the same way.
- Opening a conversation on iPhone hides the tab bar, so the composer sits on the transcript. Coming back to the list brings the bar back. The chat list and the other folder sections keep the bar throughout.
- The composer floats on the same glass as the tab bar, including the home-indicator edge, so the lower end is not a grey strip.
- Sending a chat message on iPhone hides the keyboard and jumps to the latest turn, so the reply is not sitting above a closed keyboard.
- Jump to latest, Following and Follow share one compact themed capsule with a down arrow, sitting on the transcript. Following is no longer a grey pill.
- A file the agent edits is one card named after the file, not an Edit tool row plus a second copy of the same patch. A later change of that file in the same turn is marked 2nd change.
- Account, This device, opens with Notifications. The switch used to sit under the cache, below the fold on a phone.
- The end-to-end note on Workspaces is a glass divider between the hosts and the chats, not a second device card. The keys are still a tap away.
- Tapping a chat notification on iPhone no longer closes the app. A missing host or an empty recents list lands on Workspaces.
- A sent chat prompt is on the transcript as soon as it is sent, including when the conversation is just opening. It used to appear only after leaving the composer and coming back.
- A grok chat in Plan can spawn a subagent. The call came back as cancelled even after you had allowed it, so the agent stopped exploring instead of reading the project. Plan still blocks edits.
v0.9.09 new · 13 fixedChat can carry files, Account splits into panes, the vault unlocks with Touch ID or Face ID, and a connected computer shows which path it took, direct or relayed.
- Attach a file to a conversation. Ask an agent to send, show, or present something and it puts the file in this thread. An agent with a mail or bot tool used to reach for that instead. On the phone, tap a file to open it: video and audio play, text, source and PDF render, images show, and the viewer's own share sheet carries Save to Files, AirDrop and the rest.
- Files over 1 MiB wait for Download. Smaller ones arrive on their own. A device-local cache holds what you have already fetched, with a size cap and an idle retention you can change. Purging it clears the lot, and a download already in flight cannot put those bytes back. A file the computer refuses for good, because it is too large to transfer or is no longer there, says so instead of offering a retry that cannot work. The setting is named tokenstat cache. Chat files are what it holds so far.
- Account settings split into panes. On the Mac: Account, Plan limits, and This Mac. On the phone: Account, This device, and Legal. Deleting the account sits at the end of Account, behind its own rule. It used to sit among the legal documents.
- Account shows this device's own direct and relayed traffic, counted since tokenstat started, separate from the account relay allowance.
- Workspaces and the device page show which path this phone took to the computer, direct or through the encrypted relay. The screen viewer already did.
- The phone composer reads as glass, with the conversation moving under it. Send appears when there is something to send instead of sitting greyed out, and a toggle at the top right grows the box for a longer message.
- The combined agent, model, and effort picker stays open while you change those settings. It shows what is selected, and the phone's targets are larger.
- Touch ID on the Mac and Face ID or Touch ID on the phone can unlock the vault. The sheet opens straight into it when this device has a saved password, without showing the password form first. The password remains the fallback, and a changed biometric set forgets the saved one.
- Relayed traffic shares one allowance: 100 MiB on Free, 1 GiB on Supporter, 5 GiB on Patron, and 20 GiB on Legend, covering today and the previous 29 UTC days. Direct connections do not count. Each day the oldest day leaves the window, so there is no monthly reset.
- Downloading one attachment no longer rebuilds every card in the transcript.
- A downloaded chat file on the phone opens, instead of reporting that the file name is invalid.
- A few-megabyte chat file failed to download over the relay, while the same file arrived over a direct connection. The tunnel waits for the socket now instead of dropping the burst.
- Recent chats on the phone dropped a thread you had just used when many conversations were unread. The three newest sit at the top, then five more by what needs a look.
- The expand control at the top right of the phone composer had no glyph.
- A phone chat had no way to put the keyboard away once it was open, so the transcript could not grow. Drag the conversation, tap it, or tap the keyboard button above the field. That button is there only while the keyboard is up.
- Full screen on a Mac watching another Mac did nothing. The viewer is its own window now, so the expand control fills the display.
- A Mac asking another Mac for the screen or for folders never brought up a permission prompt on the host. The request opens as a sheet, the Mac sidebar asks when a host refuses the work, and the screen viewer asks the moment a connection is refused. It used to wait for a second press. Approving a screen grant also asks macOS for Screen Recording, and for Accessibility when control is included.
- On older macOS the connecting spinner was a bar that travelled across the screen. It stays circular. The chat composer on those versions packed agent, pills and send against the trailing edge with a gap after attach, and keeps those controls next to attach.
- A long conversation keeps a fixed window of rows and slides it to earlier turns, instead of growing the stack until layout stalls. On a Mac, a message is selectable once the pointer is on it.
- Edit and tool rows keep +/− on the right, next to the time and the button. A short path used to leave the counts after the name, and a long one shoved them against the button.
- Last sync on Account sits with its time and Sync now on one row, at the same size as the rest of the card. It used to be a large title stretched across the panel.
- An account with no photo shows initials from the name, the same filled bubble the phone already draws. The picture still shows when one is uploaded.
v0.8.36 new · 15 fixedThe model picker has a search, chat follows a turn started on another device, and notifications wait until you have looked away.
- Type to filter the model list. An agent CLI can offer forty models or more, and "meta 1.3" finds meta/muse-spark-1.3. Agent, model and effort share one panel, each section showing what it is set to. Lists under ten entries stay a plain menu.
- A Refresh sits beside the models. The list comes from the agent's own CLI and is held for ten minutes, so a provider you added an API key for a minute ago was missing until that expired. Refresh reads the CLI again. Short lists keep Refresh inside the menu.
- Codex models. A Codex chat had no model picker, so it ran only the model set in its own config file.
- Muse backend in chat, automations, and transcripts. Automations run it bypass-only. Plan-mode chat drops the bypass flag and turns off its write and shell tools.
- Quick section tabs in the agent/model/effort picker. Agent, Model, and Effort read as separate settings before any scrolling.
- Setup guidance for Remote Reach. The phone shows an empty state and a recovery card when a Mac never registered for remote reach, with the exact steps and a retry. Mac machine settings carry the same switch as a compact preference with status text.
- Notifications hold off while you are watching. A turn that ended in the conversation on screen still posted a banner and buzzed your phone. Now both wait for another app to be in front, the window to be away, or the keyboard to go untouched for a while. A phone driving a chat on a desktop no longer notifies itself. Watching one conversation from a Mac and a phone holds a lease per watcher, so leaving on one device no longer drops the other, and iPhone and iPad suppress their own banner for the open chat, same as the Mac.
- An open conversation keeps reading its events. It polls every 2 seconds while idle and every 400 ms once work appears, so a turn started on another device appears with no tap. A background hiccup no longer pops an error banner on an idle screen.
- Chat scroll corrections run after layout and combine pending corrections. Image previews keep their frame while decoding and when scrolled back into view, instead of collapsing and growing during row placement.
- Live follow holds the end while a reply streams and keeps pinning through late resizes from diffs and images. Opening a long chat still settles on the end. Sending a message locks follow until a scroll of your own leaves; estimate shifts no longer park the transcript behind Jump to latest.
- Scrolling a long transcript no longer stalls the app to a force-quit. The transcript builds a bounded window of rows with a control to reveal earlier ones, an open diff draws as one text instead of hundreds of rows, and hover stays off mid-fling. Fast scrolls stay responsive on conversations of any size.
- Tool rows classify shell intent by program name, so quoted commands land on the right card and
echo "a > b"stays Shell. Repo-relative paths resolve, multi-file edits name each file, and a cancelled command closes as failed. Muse task starts survive replay order. Muse todo answers read as "4 todos (revision 2)" instead of raw JSON, and a failed one fails its card. - Handing a long conversation to another agent keeps early turns. The inline summary is unchanged; when turns fall out of it, the new agent gets the path to the full history beside it and reads further only when needed.
- Model lists parse the Codex answer by id, reap a hung list command with its process group, keep provider-qualified ids visible, and share one run across Refresh taps. Picker Enter stays inside the visible filter and prefers the exact label, so a typed model id no longer selects the Agent row. A stale Effort filter clears when the new agent has no Effort section.
- A new automation starts on an agent. It opened on Shell, and a shell command belongs in the prompt field. Shell is still in the picker, at the end.
- A phone that cannot reach a computer names the fix. It showed the transport's own words, "no direct address" and "no_such_peer". Usually that computer has never had "Reach devices from anywhere" turned on, so the relay has never been told where it is. The recovery card now shows only for that never registered case. Timeouts and wakeups get a retry card instead.
- The vault is password-only. No identity-encrypted copy of the key sits on the server or on disk, and the app asks for the password again after a host restart. Password change and recovery rotation replace the key, both wraps, and every enrollment in one step. Recovery rotation needs Supporter or higher, like the rest of vault sync.
- A remote machine cannot be talked into reaching a third one: forwarding sent over a peer's own connection is refused at the door. Screen and terminal streams re-check permission for as long as they run, so taking access away ends a live stream, and vault rollbacks are refused.
- Android private keys live in the Android Keystore. Each key is verified before its plaintext copy is removed, one bad entry no longer blocks the rest, and a wrong vault password leaves the dialog open for another try.
- Windows model Refresh reports a host failure in a banner instead of crashing. Old hosts answer from cache.
- On pull requests, the art on the connect card is centred. Choosing which repositories tokenstat may open also stays on that screen after you connect. It used to vanish as soon as one repository worked, which left the Account screen as the only way back to it.
v0.8.22 new · 11 fixedChat on the Mac keeps up with the conversation, and a terminal you come back to draws what is on it.
- Claude's higher effort levels, xhigh and max, are on the picker. Opus at max effort is now a conversation you can start.
- Windows and Android previews catch up with the Mac. Both open the year at a glance from one call, where they used to rebuild it from a report. Windows grows a diff viewer and a transcript that appends a turn without redrawing the thread. Android grows the Chat and Pull requests sections, and keeps a conversation current while you watch it. Each one hides what the computer it is paired with is too old to answer, so an old pairing says so up front and no longer fails at the tap.
- A long conversation no longer hitches or freezes. Scrolling a turn full of tool output stays smooth, a streaming reply stops rebuilding the thread on every frame, and a shell command that ran to megabytes is split once, not on every redraw. A tool that answers in one long line, which is every tool that answers in JSON, no longer freezes the thread: a web search result arrived as a single forty-kilobyte line and was laid out in full on every pass the transcript made over it. Output is cut to what a row draws, with the whole of it still on the clipboard.
- Following a live turn stays out of your way. It holds the end while the reply grows, lets go when you scroll back, and stops yanking the thread on tool-heavy turns. A pill reads Following, Follow or Jump, and takes you to the end.
- A whole reply can be selected in one sweep, and copy appears on the card you are pointing at, with a tick where you pressed it.
- A tool row reads as what it did: the verb, the file, and how many lines moved. Small diffs open on their own, and one that is still arriving keeps opening as it grows, until you open or close it by hand.
- Sending an image with nothing typed works, and the image stays in the transcript as a row of its own. It used to disappear into a turn with no visible content.
- A conversation loaded to its first message says Start of chat. It used to read as stuck part way through history.
- The sidebar marks the conversation you are in, and clears that mark when you leave. Picking Notes, Home or a server used to leave the old chat lit beside the row you had chosen.
- A terminal you navigate away from and come back to repaints. It could show a stale or half-drawn screen, and a full-screen program kept the old window size until you typed something.
- Characters that SSH drew ahead of the far end no longer freeze on screen when you return to a session. A guess that has gone unconfirmed is withdrawn, and the far end draws the line.
- A terminal nobody can see is left at the size it had. Hidden sessions were being resized, which could collapse one until input revived it.
- The list of agents and their models answers immediately. One agent whose command hung held it up for seconds at a time, every minute, and a failed check keeps the models it found last time.
v0.8.13 fixedA hotfix for agents that would not start from chat.
- An agent launched from a conversation is found the same way the launcher finds it: your PATH, then your login shell's PATH, then the places a harness installs itself into. The helper runs from launchd and inherits none of that, so an agent the launcher listed as installed could still fail to start with a short PATH for an error. Chat, automations and workflows all spawned the same way and are all fixed.
- Node version manager directories and the usual install locations for a few more agents are searched too, so a tool installed under a Node version or in its own directory is picked up without being pointed at.
- The first conversation on a new machine starts in execute rather than plan. Once you have chosen a mode, your choice is what comes back.
v0.8.013 new · 5 changed · 6 fixedChat comes to the Mac, along with the pull requests around a folder and the branches and files they touch.
- Every workspace has conversations. Choose the agent and the mode before the first turn, and the conversation still has them when you come back to it days later. The transcript draws tool calls, diffs and markdown instead of pasting them in as text, each tool carrying how long it took and whether it failed, and a meter says what the conversation has spent.
- A long conversation opens on the latest turn with history behind it, and holds your place while older messages load in above.
- A tool that needs permission stops the turn and asks in place, showing what it wants to do. Nothing runs on an answer you did not give, and a request nobody answers expires. You can see what an agent is allowed to do before you choose it.
- Personas: a name, a brief, and a face. A persona is yours, not one chat's, so you can give a workspace a default one, reuse it across folders, or have none. The face is a small physical character, so it leans, lands and follows through as the conversation moves, and it finds something to do while a long turn runs rather than holding a pose.
- Drop or paste files anywhere in a conversation, or attach them from the composer. Images go to the backends that take them natively.
- Hand a conversation to another agent with its working context intact. The transcript records the handoff.
- The Mac says when a conversation needs an answer and when a turn has finished. Those notifications are local. Nothing about the folder, the prompt or the command leaves the machine.
- Pull requests are a workspace of their own. Connect GitHub or GitHub Enterprise, choose the repositories you care about, then read changes, checks and conversation, and approve, request changes, merge, or check the branch out without leaving the app.
- An SSH session suggests paths on the far machine, your saved commands, and where recent sessions were working, while you type. It keeps them in memory only. Nothing is run to produce them and no password is kept.
- Muse, Devin CLI, Kimi Code and Qwen Code usage now appears in your reports, each under the tool's own mark. Devin CLI, Kimi Code and Qwen Code are on the launcher as well, so you start them where you start the others.
- Recent conversations sit above folders on iPhone and iPad, with their last activity and a per-device unread mark, and open straight into the thread.
- A phone reconnects on its own to the computer you were last on: when the app opens, when that machine wakes, and when you come back to it. Every host card carries the switch, so a computer you would rather dial by hand stays that way.
- Patron and Legend are available monthly as well as yearly.
- Reports and background scanning no longer wait on each other, and scanning takes what the machine has. An older Mac stays responsive while a newer one finishes sooner.
- Sheets across the app look like each other: headers line up, colours match, and there is room around what they are asking.
- Committing and pushing say what happened in words. You no longer get the command's own output to read.
- Antigravity's CLI and IDE count as one tool in your reports, where they used to be two.
- Scrolling with a terminal open no longer searches the whole window on every wheel tick.
- Text fields are on the app's own surface again. Sixteen had reverted to the platform bezel, which on a dark panel is a flat grey that matches nothing else in the app.
- Entering or leaving full screen from the traffic lights no longer aborts the app on the newest macOS.
- The paywall no longer promises "Switch at next renewal" for a plan change Apple charges on the spot, and it offers a free trial only to people Apple will actually give one to.
- A branch name shaped like a command-line option is refused rather than passed to git.
- The pinned day stays on screen while a refresh or a sync reloads its numbers, instead of emptying to a placeholder and filling back in.
- Install on Windows runs a command Windows can run. Every tile offered the same installer everywhere, and on Windows thirteen of them were a
curlpipeline into a shell that is not there, so the button could only fail. Each tool now carries its own Windows installer, taken from the vendor's own script, and the two with none say so by offering no button rather than a broken one.
v0.7.21 new · 2 changed · 1 fixed
- An account with nothing on it says what to do next. Home draws a numbered rail instead of an empty grid: on the Mac the first step arrives done, because you are looking at the app, and the rest is a scan and an optional account. On the phone it is signing in, already done, and adding a computer. Under it, the shape of the heatmap that is coming.
- Signing in from the Mac opens the approval on its own, in a sheet over the app, rather than dropping you into the whole website to press one button.
- The phone's empty screens offer a way to the first step instead of only confirming there is nothing there.
- The App Review demo account can open a workspace, not only watch a screen.
v0.7.16 new · 3 changed
- A device can ask for screen access from its own screen, and the computer it asked says so: a toast with a way to the question while the app is open, a notification carrying the answers when it is not, and a card in Devices for whoever let either go. View only and Full access are separate answers, and either can be taken back afterwards. Request access used to send a notification that could not carry which device was asking and never reached a Mac at all, so nothing happened and the switch was hard to find.
- Watching a screen over a direct connection now looks far better. A LAN or router-mapped link is your own bandwidth, so the picture is wider, sharper and keyframed twice as often on it, where the relay stays exactly as frugal as before. A Quality menu in the viewer picks between automatic, sharp, smooth and data saver, and changing it never interrupts the picture.
- On a phone, a computer that has not answered yet shows what it is waiting on and connects on its own the moment somebody approves it, rather than leaving a screen that never changes.
- Reaching another of your computers across the same network now asks for the Local Network permission it needs. Without it iOS refused every direct dial silently and every session fell back to the relay, which is slower and further away than the machine in the next room.
- A computer now lets each device open its work by name. Signing in on a new phone no longer reaches the folders, files, terminals and agents on every machine on the account: that is a separate yes, given on the computer being asked. Devices you already use will ask again after this update, once each, from a screen with a Request access button on it. Pairing a device by typing its code still grants it in the same step, because that already is somebody saying yes to one device by name.
- Workspaces has a Chat section under Sessions, on the Mac and on the phone. It is empty and says so: a friendlier way to talk to the agents in a folder is coming, and this is where it will be.
- Open work and View screen on a device now read as the buttons they are, with a glyph and a surface of their own instead of plain text and a chevron.
- Devices lists everything still waiting on you in one place, and one card there now covers all three permissions a device can hold: workspaces, watching the screen, and driving it.
- Syncing refreshes the numbers it just changed. The heatmap, the day under the pointer and the pinned day all re-read, where they used to keep pre-sync figures for up to ten minutes.
v0.7.07 fixed
- Turning on control while watching a remote desktop no longer drops the session. Control is now handed over on the stream that is already running, so the picture never stops, where it used to close the stream and open a new one. Those two raced each other: one screen session is allowed at a time, and the new one usually arrived before the old one had finished closing, so it was refused and the app spent the next half minute reconnecting.
- The relay understands the same handover, so a device reopening the same desktop takes over from itself instead of being turned away. A second desktop on one account is still one too many, and says so.
- A screen session that a viewer left without closing frees up in seconds rather than in up to a minute.
- Dragging a window, or dragging to select text, follows the pointer instead of jumping to its new place when the button comes up.
- Input arrives in the order it was made. A fast drag could previously deliver a movement after the release that ended it, leaving the far end holding a button down.
- A phone coming back to the foreground reconnects to the relay when it finds it has fallen off, instead of looking connected while every call to it says the machine is not there.
- Reaching a machine no longer waits on a local network address that has stopped answering. The address is remembered from the network it worked on, and off that network it was tried first on every call.
v0.6.916 new · 3 fixedEverything since 0.6.8, which is the last release anybody received.
- SSH from the Mac, the iPhone and the iPad, as a place in the sidebar rather than a panel over Devices. Hosts, keys, snippets and trusted servers are sections you navigate to, folders nest under Hosts, the list gets the whole window and the editor opens beside it. Leaving for Home and coming back keeps you where you were, and the rest of the app stays usable throughout.
- A saved server carries what it needs to connect: which key to use, which server to reach it through, a starting directory, environment variables, a keepalive, and a colour and folder to find it by. Snippets can ask for
{{values}}when they run, so one snippet covers every server. - Import servers from
~/.ssh/config, from AWS and from DigitalOcean. tokenstat reads that file and never writes to it, and shows what it found before saving anything. - Credentials live in an encrypted vault that can follow the account. Setting one up takes the servers, folders, keys and snippets already saved on this device with it, syncing runs both ways, and Sync now says when it last ran. It is one quiet row above the server list, saying how many records it holds. Setting it up, replacing the recovery code and deleting it are each one click from there, and each has room to say what it costs. Recovery is confirmed in two steps: the code is on screen to be written down, then off screen while it is typed back, so confirming cannot be done by reading. Deleting the vault on one device removes it from every other one, rather than leaving a second device offering to change the password of a vault that is gone.
- The vault is a Supporter feature and says so as a plan rather than as a locked door. On Free the row reads "not syncing", the screen explains that your servers and keys are saved on this device and work exactly as they do now, and the button on it opens plans instead of doing nothing. A vault that outlives the plan that made it stays readable and says out loud that it has stopped receiving changes.
- Trusted servers are listed with their fingerprints and any of them can be forgotten, so a key that changed can be confirmed again rather than quietly accepted. A key shows its own fingerprint, and its public half can be copied in one press for pasting into a server's authorized_keys. On iPhone and iPad a long press on a key or a snippet offers edit, copy, run on connect and delete.
- SSH typing appears as it is typed rather than a round trip later. A character is drawn locally and replaced by the server's own echo when it arrives, which makes a shell on the other side of the world feel like one in the next room. Nothing is drawn until the line has proved that it echoes, so a password prompt never shows a character of a password.
- Share this Mac's screen with another Apple device on the account. Switch displays, send the system audio, copy both ways, and send a file without leaving the session. macOS is asked for Screen Recording and Accessibility at the moment you turn view or control on, with the prompt that names tokenstat, and the card says which permissions are granted and that the app has to be open for its screen to be shared.
- Control that screen from an iPhone or iPad. One finger moves the pointer, tap clicks, two fingers tap for a right click and drag to scroll, long press then drag holds the button down, and pinch zooms in. A row of keys over the keyboard sends escape, tab, the arrows and sticky ctrl, opt, cmd and shift, and a pull on the bottom edge brings that row back over a full-screen picture. Driving a desktop runs at sixty pictures a second and every pointer move is delivered as it happens, on the same bandwidth a session watched from an armchair costs.
- Notes get an inspector on the Mac, so a note written on a phone can be read and edited on the computer instead of only on the device it was typed on. Deleting one asks first, and clearing the title keeps the edits made in the same visit rather than refusing the whole save.
- Opening a computer, from its device page or from Workspaces, shows what it is doing: power, CPU and memory read over the tunnel and not uploaded with usage, with open work and view screen beside them. On the Mac, a workspace that lives on another machine offers that machine's screen without a trip to Devices.
- A preview Windows desktop app. Its development build installs for the current user, adds a Start Menu shortcut, and exercises the update path while the platform matures outside stable GitHub Releases.
- A preview Android client. Pair it to an account the way the iPhone does, then use this Mac from the phone: terminals, folders, and the rest of the remote surface. Android SSH gains search, folders on saved servers, port and starting directory on the add form, and a snippet editor with room for a real command.
- Install the host as a service on a machine that has no desktop session, so it answers after a reboot the same way Always-on host does on a Mac mini.
- Every control is the app's purple. Switches, pickers, focus rings, selection and prominent buttons were system blue everywhere except eight hand-picked places.
- The app is set in its own typefaces, the same two the website uses. Manrope for everything you read as language, and JetBrains Mono for terminals, code, commands and model identifiers, where a lowercase l and a digit 1 have to be different pictures. Both are bundled, so a Mac and an iPhone showing the same screen now show the same screen. Sizes are unchanged and all of it still scales with your text size setting.
- A long session no longer fails with "Too many open files". The app asked the system for a fraction of the descriptors it is allowed, and the first thing to lose the race reported it as a problem with a file. Connections to another machine are also closed once they have been idle for a minute, rather than being held for as long as the app is open.
- The app no longer reports "unknown method" when this machine's background helper is older than the app. It checks the helper on launch, replaces it, and says something a person can act on if it cannot.
- Opening the Mac app on a recent macOS beta no longer aborts while the window is first laid out. The splash used to animate the split view in, and AppKit refused the extra constraint pass.
v0.6.81 new · 8 fixed
- An agent that stops to ask you something can say so. Turn notifications on in Account and a question waiting in a terminal reaches you the way a finished run does, and it takes itself back when you open that terminal.
- A live session's tokens and cost are counted once per request. A harness that rewrites a request as it streams was being added up chunk by chunk, so a session read about twice what the tool itself reports.
- The context bar stays empty for a tool that only records a session running total, rather than filling to hundreds of percent. Tokens and cost for those sessions are unaffected.
- A terminal no longer repaints and loses its scroll position when a notice appears. The live notices float over the bottom of the terminal instead of taking height from it, each one fades on its own rather than waiting to be clicked away, and the paused notice waits until output has genuinely stalled.
- "Needs attention" goes away when the question does. It used to sit there until the agent printed enough to push the prompt out of view, and opening the session now clears it as well.
- The plans screen no longer shows an error about a purchase nobody made, left behind by a transaction the App Store re-sent while the phone was offline or signed out.
- One Mac going to sleep no longer freezes another. Calls to a machine that has stopped answering used to take every connection the app had, so terminals stopped drawing and screens stopped filling until they gave up. They now have a share of their own and a time limit, and an unreachable machine is reported as unreachable instead of as silence.
- The tasks list arrives when the count does. The board no longer waits behind a report, a sync, or another machine asking this one for a report.
- A workflow no longer announces every step it takes on the way. It tells you how it went when it is done, once, on this Mac and on your phone.
v0.6.72 new · 5 fixed
- Four more tools are read straight off disk: Pi, Hermes Agent, Kilo Code and the DeepSeek Harness. Each one is counted as its own tool, so a machine running Kilo Code and OpenCode side by side sees two rows rather than one.
- Tell me when a run finishes. The Mac watches its own automations and workflows and says so when one ends, fails, or stops to ask a question. It is off until you turn it on, in Account, and nothing about the run leaves the machine. iPhone and iPad carry the same switch, which starts arriving once notifications are switched on for your account.
- Usage from a tool that keeps a SQLite database is picked up on the next scan instead of waiting for that database to be tidied up, which could be hours. This was quietly losing recent work for OpenCode, Cline, Copilot CLI and Zed.
- A machine is only called unreachable when it was answering and stopped, and the card names which one. A phone or tablet paired to the account no longer reports a computer as unreachable, and a machine that is simply off is left to the Machines screen to say so.
- Stop and close takes the session off screen at once rather than waiting on the computer to answer.
- A full-screen agent no longer swallows the window's own clicks, so a confirmation dialog flashes and the window keeps answering.
- The phone's terminal keys no longer cover the last lines of output, and notes are not pressed against the field above them.
v0.6.63 new · 3 fixed
- A left sidebar on iPad when a keyboard is attached, drawing the same folder tree the Mac does, with keyboard shortcuts and pointer-density spacing.
- Notes get their own screen on the client, per folder, and a folder's note count now shows in its summary.
- One model for what the app believes about the network. Connection trouble is reported once, in one place, instead of once per subsystem, and a call fails fast when the device is known to be offline.
- The network verdict clears itself when the network comes back.
- Every device row can be renamed, including the one you are sitting at.
- No on-screen keyboard key on a terminal that already has a hardware keyboard.
v0.6.52 new · 3 fixed
- Close a session straight from the sidebar.
- Harness settings sheets corrected, with compaction on a slider rather than a number field.
- OpenCode: read the version 2 schema, and count a migrated message once rather than twice.
- iPad: the native intro, and no split view nested inside a split view.
- The global tasks screen is gone from iOS, where it duplicated the per-folder boards.
v0.6.43 new · 2 fixed
- Name any device on the account, from any surface.
- Every workspace gets its own Notes section.
- iOS: a colour-highlighted file editor, and drawn empty states instead of a sentence explaining the emptiness.
- The kitty keyboard announcement no longer leaks into the terminal emulator.
- The Sessions wireframe ends when the answer lands, rather than pulsing on.
v0.6.33 new · 3 fixed
- Hermes Agent and Kilo Code in the launcher, with their official marks. Hermes installs without its interactive setup wizard.
- Notes get their own screen, kept per folder or unfiled.
- Harness settings open from the launch tile badge, as a form rather than a popover.
- Terminal clicks are sent as SGR mouse events, so mouse-aware programs see them.
- Recovered Claude Code rows fold into Claude Code instead of appearing as a separate tool.
- A session meter with nothing in it reads
0% ctx · $0.00 · 0krather than a blank.
Full history and source on GitHub.