tokenstat
tokenstat

Changelog

Every release, newest first

What shipped in each version of the tokenstat CLI, desktop app, and MCP server.

v1.4.13 changed · 7 fixed
Changed
  • Commit history shows a public picture beside each author when one is available, on Mac, iPhone, iPad and Windows. Your own commits keep your account picture when you have set one.
  • The Windows account page shows the picture, name, tier mark, handle and server, with a link to the profile.
  • Windows toolbar and sidebar icons are drawn at the size they appear.
Fixed
  • A Windows update installs only a release newer than the app already running. A staged copy that is not newer is removed, so a restart cannot replace the app with an older one.
  • Restarting to finish a Windows update asks first while a terminal session or an agent turn is still running. The restart ends that work.
  • The Windows helper starts outside the install folder, so an update can replace the folder. Browser data that an older build stored there moves with the app, and signed-in sites stay signed in.
  • A development copy of the Windows helper left running no longer keeps the installed app attached to that older helper.
  • Windows chat rows keep their action labels visible. A changed file in the project inspector shows its name first, then what happened to it, instead of a path that wraps to one letter per line.
  • Opening a Windows chat tab while its tab strip is still loading no longer quits the app.
  • Installing an agent on Windows runs from the home folder, so the installer does not load the app's own libraries and fail.
v1.4.03 new · 3 changed · 10 fixed
Added
  • Retained iPhone and iPad chat and SSH sessions across wide and compact layouts, with project navigation, recent chats and active terminals in the iPad sidebar. SSH connections appear in a separate Servers section.
  • Android tablet project section navigation keeps Terminals, Chats and Changes within reach. Resizing keeps the open project and chat draft, and Recent Chats stays separate from the project list.
  • Markdown tables in Android chats, with column widths that follow text size.
Changed
  • Chat transcript projection runs away from the Apple UI executor, with bounded tool snippets, shared reads and stable reading-position handoffs.
  • SSH setup keeps wizard progress and drafts, preserves the six-step intro, and uses exact staging receipts when cleaning up pairing codes.
  • Account, vault, tunnel and watching operations retain their original login ownership through reconnects and account changes.
Fixed
  • Empty iOS transcript views reread the latest page on reconnect rather than polling past history. Empty reads cannot replace a known history's offline copy.
  • Apple and Windows conversation lists can load while backend and persona requests are slow or fail. Mac chat views retry on reconnect and foreground.
  • Transcript and conversation-index read failures report errors instead of successful empty history. Directory reads refresh indexes written by another helper, without adding index reads to streaming polls.
  • Same-account relogins cannot reuse an earlier login's pending Apple chat read or publish its late mutation response.
  • Android setup cleanup and watching leases carry the receipts required by the updated shared backend.
  • Pairing cleanup preserves codes belonging to a newer setup attempt, and interrupted setup locks recover without disrupting another active attempt.
  • Encrypted vault operations keep the account and server address that started them, including custom server paths and IPv6 addresses.
  • iPhone and iPad chats keep messages clear above the composer area in portrait, landscape and folded layouts. Layout settings now sit directly below Notifications.
  • Sidebar chat selections retry when a connecting machine's conversation reader finishes loading, instead of leaving the project chat list open.
  • Mac terminals opened from sessions started on another device retain the Mac's measured size instead of replaying the other device's size on display.
v1.3.012 new · 3 changed · 29 fixed
Added
  • Grok chats gain a per-conversation fast-mode switch for models with an available fast variant. Default/Fast applies to the next turn, with guidance about higher cost and faster subscription-allowance use.
  • Plan-limit widgets on Apple and Android with dynamic one/multiple-provider selection, circle/bar percentages, reset times and dated cached readings. Choose 5-hour, weekly, both or highest-usage windows; circle layouts fit four readings in a small widget. Android adds one-row allowance cards, a compact activity layout and a Quick Launch widget down to one cell.
  • Optional charts in Usage at a Glance keep Today and Week totals visible. Widgets show one compact reading age, with clear refresh progress and feedback.
  • Android recent/pinned project shortcuts, account-scoped AppSearch discovery, text Share/Direct Share into chat drafts, and contextual response sharing. Supported system assistants can search projects, read cached usage and create notes through experimental AppFunctions.
  • iPhone Live Activities for foreground-observed chats and project terminals on compatible hosts: branded Lock Screen/Dynamic Island status, elapsed time, waiting and completion states, exact-session navigation and background APNs updates.
  • Android usage widgets with light/dark appearance, per-widget day/week switching and background refresh; launcher shortcuts, a Workspaces Quick Settings tile and a notification action for reviewing live agent requests.
  • Configurable usage and project widgets for Mac, iPhone and iPad, including iPad extra-large layouts and iPhone Lock Screen accessories. Choose a period, appearance, favorite project or screen, and refresh usage from the widget.
  • Clean glass and pure black Apple widget appearances, configurable accent tints, and Lock Screen launchers with the tokenstat logo.
  • Shortcuts and Siri actions for screens, project sections, search, usage and activity streaks, with account-scoped Spotlight project discovery and the latest Apple content-opening and search schemas on supported systems.
  • Quick Access controls for Control Center and supported Lock Screen and Action button slots.
  • A paired Apple Watch app focused on Today/Week activity, plan limits and actionable requests, with branded light/dark/tinted icons, Shortcuts and activity/allowance/request complications. Review pending agent requests, Allow Once, Always Allow for that chat or Deny after the host revalidates the exact live request.
  • iPhone Duo support. Opened, it uses the iPad layout, and folded, the phone layout. It switches as you fold and keeps the open chat, the connection to your computer and the data on screen. iPhone and iPad layouts follow the window's size rather than the device, so Split View and Stage Manager get the wide layout whenever there is room for it.
Changed
  • Shared plan-limit fetches follow the account plan's sync interval, with a five-minute minimum and hourly fallback. Mac widgets pick up updated local readings without fetching vendors again.
  • Watch sync uses a visible refresh icon and clearer instructions to open tokenstat on the paired iPhone for the first sync or when disconnected.
  • Subscription purchase actions show recurring charges and renewal terms beside the button on Apple and Android.
Fixed
  • Chats wait briefly for the process exit status after terminal output closes, so successful runs are not prematurely marked as failed.
  • Refreshing Apple Watch plan limits no longer depends on the usage calendar being available.
  • Apple Watch shows a reminder to review more requests on iPhone when there are more pending approvals than the Watch can display.
  • macOS release signing checks the app and widget profiles before notarization and avoids unsupported stapling attempts on standalone CLI binaries.
  • iPhone Live Activities give the running timer a bounded layout and use a compact Lock Screen layout for larger text. Live Activities and the Apple Watch app use the existing three-color app logo; complications keep system tinting where required by the watch face.
  • Codex runtime diagnostics remain in raw logs instead of appearing as agent replies. Actual tool failures and failed turns remain visible in chat.
  • Stopping a Codex chat interrupts its active turn and lets the agent persist canceled tool results before shutdown, preventing missing-output history on resume. Unresponsive agents still stop within a bounded deadline.
  • Muse compact tool rows recover logged commands, file paths, skill names, search queries and todo counts, including retained older tool results.
  • Grok's paid fast variants are not mistaken for cheaper models for automatic work. Timed-out model-list commands stop their child process trees cleanly on Mac, Linux and Windows.
  • Live Activity starts retry after offline launch or late account verification; streamed chat updates no longer interrupt activation. Tapping an activity opens the correct remote chat or terminal, including retained terminal output after completion. Waiting clears promptly after the last approval, and late status updates cannot revive completed runs or cross an account change. Token registration recovers after an offline start and duplicate activities are avoided.
  • Project refreshes on iPhone and iPad discard late terminal/chat responses after an account or computer change.
  • Android 12 and later retain widget configuration and compact allowance resizing. Widget failures display refresh feedback after account verification, and stale plan-limit readings are explicitly marked as cached.
  • Android shared text stays queued until it has been saved to the chat draft, including when draft storage is full or the incoming text is too large.
  • Android Pull and Push use matching buttons and opaque full-screen review forms. Vault management and unlock fill the phone screen, with actions kept above the keyboard. Empty SSH libraries place their Add action directly below search instead of halfway down the page. Searches with no matches offer Clear search. Recovery codes use a keyboard without autocorrection.
  • Android push recovery distinguishes an unreachable computer from a missing receipt before offering Retry. Closing a Git review ignores late responses. Saved push operations keep their identity while an older computer needs an update, without calling unsupported recovery methods.
  • Android reads capabilities from the connected computer, so Pull in Changes, the New pull request flow and chat-question answers become available on supported computers. Temporary connection failures retry, and changing accounts or computers clears the previous computer's capabilities.
  • Improved async runtime cleanup for child processes, timers and task queues.
  • Rust installer updates preserve the pinned compiler across CI, preview and release builds instead of requesting unreleased compiler versions.
  • Android widgets reject malformed calendars and unknown fetch ages instead of presenting them as fresh or unlocked usage. Sign-out blocks survive process restarts, and launcher update failures no longer interrupt account cleanup or background refresh bookkeeping. Missing widget services and scheduler failures are handled without crashing or leaving a queued refresh indicator stuck.
  • Android signed-out startup completes account verification; late account updates and project indexing cannot restore another account’s metadata.
  • Apple widget configuration labels explain that full-color style/accent settings follow the system in Clear/Tinted mode. Quota refresh remains independent of calendar access, and expired allowances no longer imply fresh zero usage.
  • Replaced an unreadable Watch fallback icon. Apple store-icon checks validate compressed image data as well as metadata, checksums, filters and dimensions.
  • Loading placeholders no longer drift across the screen while a landscape or split layout settles.
  • Profile pictures that fail on a slow or dropped connection load by themselves once the network answers, instead of staying as initials.
  • The Mac sidebar holds a project's chat order while the pointer is over it, so hover cards no longer flash open and shut while chats are running, and a click lands on the chat you aimed at.
  • The Mac app no longer opens with an empty project list when the account finishes loading during launch, and retries while the background service is still starting.
  • Mac sidebars and the inspector follow the window while it is being resized, not only when the drag ends.
  • Home streak figures on the Mac stay whole in a narrow window, moving under the greeting instead of wrapping digit by digit.
  • The iPad sidebar's account picture shows its plan badge clearly.
v1.2.010 new · 10 fixed
Added
  • A lightning control beside chat attachments for Codex and supported Claude Opus models. Default/Priority is saved per conversation, with provider-specific guidance about faster responses, usage limits and paid credits. Supported CLI versions can apply a speed change to the next model request during a turn.
  • A Glass sidebar switch and opacity slider in Settings → This Mac. Full screen and Reduce Transparency use an opaque sidebar.
  • Mac and Windows remember which sidebar sections are open and let you reorder Projects and Servers.
  • A guided New pull request flow on Apple, Windows and Android: choose a branch, select and review files to commit, publish the branch, then write a title and description. Draft is the default, and matching open pull requests are reused when retrying.
  • Chat sign-in guidance for installed coding agents. Open the agent's terminal on the chat's computer, follow browser or code instructions, and check sign-in without losing the chat draft. Cursor and Muse join Claude and Codex. On Mac, iPhone and iPad, Claude, Cursor and Muse authentication failures offer guided sign-in and a retry with the original text and files. Codex and Muse sign-in open the page in your browser and copy the one-time code. A message held for sign-in keeps its text and files until you choose Continue.
  • Cursor chats can ask before running tools in Standard mode. A short note can steer the next step of a running Standard chat. Plan mode stays read-only.
  • Four chat detail levels on Apple, Windows and Android. Compact, the default, shows one quiet line per step, with the lines each edit added and removed, Codex edits included. Opening a line shows the step's output or diff without a card around it. Minimal folds thinking and tool steps between visible replies, Standard folds thinking and runs of reads, and Detailed shows every step with its output open. Every reply, including progress updates between tool calls, shows at every level, as do approvals, failures and handoffs. Existing detail choices are remembered.
  • Finished chat turns list the files they changed and their added and removed lines. Review opens the project's Changes, where files can be read, committed, pushed and turned into a pull request. Desktop chats open Changes in a full tab. Chat lists show the last known pull request state.
  • Pull beside Push in Changes on every client. Review fetches the branch's upstream, then Pull brings in exactly the reviewed commits, fast-forward only. Uncommitted work and branches that need a merge are left for you to resolve. The same panel offers Create PR or the branch's existing request.
  • Agents can ask you a question in the chat, with choices to tap or an answer of your own. In a chat that runs without asking first, the agent never stops for it: it says what it is going with and keeps working, and your answer reaches it on its next step or as the next message. If Stop or a new message means an answer never reached the agent, its question opens again.
Fixed
  • Cursor plan usage reads the current sign-in from the Cursor app as well as the CLI, so an expired CLI login no longer leaves last cycle's limits on screen. Expired sign-ins say when they expired and how to renew them.
  • Cursor reconnects no longer repeat replies when the stream changes its chunk sizes. Cursor's own authentication refusal offers sign-in without treating another tool's login error as a Cursor failure.
  • A Muse chat that needs sign-in ends with a sign-in message instead of waiting indefinitely or showing a device code in the conversation. On Mac, iPhone and iPad, guided Muse sign-in starts waiting for browser approval automatically, including when the chat runs on another computer.
  • Resumed Codex turns use the chat's current project folder and keep earlier messages from appearing again in the new turn.
  • The main Changes review keeps its contents and reading position during background refreshes, avoiding repeated redraws. Chat detail controls use the app's themed selector and action buttons.
  • Codex edit counts start from the files as they were before the turn, including uncommitted work, newly created files and deleted files.
  • Large single-line JSON changes render in bounded pieces on desktop, with access to the complete diff. Inspector previews refresh after file saves, release their source when closed, and offer Retry when a diff cannot load.
  • opencode no longer suggests signing in. Its free models work without an account.
  • Chat links have visible accent underlines. The Mac asks where to open a web link, shows the full URL, and can remember your browser choice.
  • Retained Mac screens keep finite dimensions during startup and resizing, avoiding invalid view geometry that could crash native controls.
v1.1.012 new · 15 changed · 19 fixed

A simpler desktop. Machine-wide places move to an icon rail, the sidebar lists your projects with their chats and terminals, and each screen has one toolbar row. A project can open another branch in a folder of its own. Notes gain formatting, Tasks are a three-stage board, Devices fit in one list, and the characters are plush toys that keep their shape. A short note can steer the next step of a running chat, and desktop terminal tabs can mix local coding tools with saved SSH servers.

Added
  • Worktrees: work on another branch in its own folder, next to the one you have open. Start one from the foot of the branch picker, choose a branch prefix, and it opens as a project. On the Mac, iOS, Windows and Android, for a computer on this version or later.
  • Formatting in Notes on every client: heading, bold, italic, bulleted list, checklist, quote and code, applied to the selection, with Undo. A note can be read as a preview.
  • Search on the Devices screen.
  • A clearer Add your first project screen on every client.
  • Windows chat replies render headings, lists, tables, links and code. Update progress and a restart button appear above the sidebar account row, and updates can be checked from the account menu.
  • Windows project and chat menus can rename, fork a finished chat, and pin work to Home. A browser or terminal can sit beside a chat.
  • Phones gain chat and project menus, terminal rename and duplication, usable Home pins, and automation templates and sorting.
  • Project browsers remember the last page and eight recent ports, separately for each account, computer and project.
  • Send a short note to the next step of a running chat on every client. Pending notes can be edited or cancelled, and survive a host restart.
  • Mac and Windows launch saved SSH servers from the project terminal launcher. Local coding tools and remote terminals share tabs and split panes, including the terminal beside a chat. Split panes can swap their left and right positions.
  • Desktop chat and terminal hover cards show status, model, usage, last activity and Git changes. Additions and deletions use their usual green and red; the changes box uses the app's colours with normal readable text.
  • The Mac keeps local diagnostics for stalls, memory and calls to help investigate performance problems.
Changed
  • The Mac and Windows window is an icon rail beside a project sidebar. Each project lists its five latest chats and its running terminals, and its sections are tabs in the bar. On macOS 26 and later the sidebar is dark frosted glass. The sidebar and inspector are resizable. Both remember their widths. Windows keeps its opaque surfaces.
  • Workspaces are called Projects everywhere a person reads it. On desktop, New chat asks which project the chat belongs to.
  • On Mac and phones, chats that were opened and never used no longer fill the lists, and Home's Continue shows only work that can still open. On Android a chat row is its title and one line, so about twice as many fit.
  • New chats start in Execute, even when the previous chat used Plan. Windows remembers the agent, model, effort, permission choice and persona.
  • Windows project terminals gain a Bypass switch for tools launched there. New Windows chats start on Don't ask unless a saved choice says Ask first.
  • The chat composer names only the settings you changed, and its permission switch reads Ask first or Don't ask instead of Ask or Bypass.
  • On Mac and Windows, Automations are a table that fits a normal window: name, schedule, project, next run and last run, sortable, with Run now at the row's end. Templates and scheduler settings are one click away.
  • Tasks are a To Do, In progress and Done board. On Mac and Windows, To Do and In progress have a New task row. Phones pick the stage at the top.
  • Devices show one row per device with one way into its details, and rarer actions such as rename, revoke and forget sit in one menu. A phone's details explain how to use it instead of offering Connect.
  • Insights draw charts on every client, and daily charts keep a gap for a day without usage instead of closing it up.
  • The characters are soft plush shapes in the same colours: a ball, a star, a heart and a tortilla. Each keeps its shape while it rolls, turns, blinks and shows its mood.
  • Money figures say API list price, and plan limits say how much of each coding tool's subscription is left.
  • Untouched starter personas use familiar names such as Ruby, Milo and Daisy.
  • Account avatars keep their colours. On desktop the profile ring stays subtle until hover or keyboard focus, with gentle motion that respects reduced motion.
  • Server launchers and SSH tabs use friendly names instead of exposing addresses.
Fixed
  • Resizing the Mac window, most of all on Home, does far less work, and hidden screens stop animating.
  • Opening a chat no longer freezes the Mac while the keychain is slow to answer.
  • A file change in one project refreshes only that project, and an idle computer answers about a quarter as many background requests.
  • A long chat shows its latest turn sooner after opening.
  • Phone and iPad project navigation keeps chat actions within reach. Chat rows can delete a conversation on iOS, and file changes wrap to the viewport with scrollable headers so long paths and large text leave room for the diff.
  • Android keeps unsent writing when switching conversations or leaving a chat. Older queued messages can be reviewed and recovered into the current account.
  • Closing or reopening a remote browser keeps its listener ownership intact, and stale account responses cannot replace the current page or saved ports.
  • Starting a coding tool in a remote project waits for the browser tunnel to become ready instead of failing while the connection is still opening.
  • Devices puts remote access controls beside the computer they affect, and offers Sign in when a removed computer or revoked login needs reconnecting.
  • Windows agent replies keep long lines, emoji and accented text intact. Stopping a chat also stops the launcher's child processes. Private chat homes follow the coding tool's sign-in and sign-out, and startup notices no longer appear as replies.
  • In a narrow window the project bar, chat composer and terminal controls stay readable on the Mac, and the chat composer wraps on Windows.
  • Chat rows respond across their full width. Mac project New chat opens the composer reliably, and sidebar menu icons remain visible on macOS 27.
  • Desktop hover cards close after leaving both the row and card. Switching, collapsing or swapping Windows terminal panes keeps their sessions and output.
  • Notes keep formatting, selection and undo history when changing views.
  • Creating, listing and cloning Windows worktrees uses paths Git can open, and the update prompt appears only for computers that need a newer host.
  • Forking a chat starts with fresh permission grants, and reopening a steered Codex chat keeps its session and pending note.
  • Natural-language automation templates launch the coding tool correctly on every client. Windows Run and Stop buttons become available after loading.
  • Android plan upgrades prorate the remaining period, downgrades wait until renewal, and a purchase cannot switch to another account while the sheet opens.
  • Invalid language-table values fall back to readable text and cannot alter technical paths, terminal keys or HTTP headers.
v1.0.82 new · 4 changed · 8 fixed

Windows chat gains Follow, collapse, and Show/Hide output. Switching windows no longer kills a terminal or SSH session, the editor stays responsive on large files, and the branded Windows installer ships on the GitHub Release. Mac terminals keep a drag selection while Codex streams. Linux host auto-update restarts only the host service.

Added
  • Follow, Jump to latest, and Show/Hide output on Windows chat, matching the Mac. Long tool output starts collapsed.
  • A branded Windows installer, tokenstat-<ver>-windows-x64-setup.exe, with the tokenstat mark and LICENSE. It ships on the versioned GitHub Release. The website marks the Windows app as a review build.
Changed
  • The workbench folder chip on Windows is square.
  • The Windows editor waits before re-highlighting, so typing in a large file no longer stalls the window.
  • Installing OpenCode 2 from the launcher uses the official opencode.ai v2 installer. On Windows the tile now offers npm install -g @opencode/cli.
  • Unsigned -dev artifacts stay in GitHub Actions. Preview no longer publishes a GitHub Release.
Fixed
  • Several windows of the same harness in one folder each show their own usage. They used to share one log's totals, including when two windows started close together.
  • Collapsing the Windows left sidebar no longer leaves GLOBAL on screen or hangs the window.
  • Switching windows, terminals, or SSH sessions on Windows no longer closes the process or leaves a blank pane.
  • Drag-selecting text in a Mac terminal keeps the highlight while Codex is streaming. The selection used to vanish on every linefeed.
  • A remote machine without workspace permission cannot check for or apply host updates.
  • Linux host auto-update asks systemd to restart only tokenstat-host.service. It no longer exits the process itself, and it will not stop if it is running inside a login session.
  • Usage money totals cap instead of overflowing or crashing on a huge counter.
  • CLI reports strip control characters from session labels before they reach the terminal.
v1.0.75 new · 3 changed · 4 fixed

The Windows app arrives as a complete desktop client beside the Mac, Android matches the iPhone client screen for screen, and Mac Insights gains an All devices view. The CLI runs faster and shows daily value.

Added
  • A Windows desktop app at Mac parity. Sidebar, Home with the activity heatmap, Insights with the daily chart, Devices, Account, the four boards, and workspace pages with the inspector column. Real terminals, bidirectional screen sharing, the persona characters, live sessions in the sidebar, install and update flows, and a helper that restarts on failure.
  • Android at iPhone parity. Home, tabs, billing, legal, devices, workspaces, SSH, launch, chat queue, notifications, pull requests, and sign-in match the iPhone client, sheets and dialogs use the theme, and push registration reaches Android.
  • All devices in Mac Insights. A scope switcher flips between This device and synced usage across every device, with a filter over models, harnesses, and days.
  • Commit Review all on Windows. A commit opens its whole diff in a workbench tab, like the Mac.
  • A dismiss control on the sidebar connection warning. Dismissing hides it until the failure set changes.
Changed
  • The CLI uses the website's violet and pink palette. Activity heatmaps now shade total tokens including cache, using the website's quartile scale.
  • The interactive CLI opens faster by loading other reports on first visit and reusing model prices. Tab/Shift+Tab switch reports, Page Up/Down move by a screen, and Home/End jump to the beginning/end of a report.
  • Summary and Daily show today's usage and estimated API value. Daily, Weekly, Monthly, Projects, and Sessions show per-model list-rate value totals, including in JSON. Partial values carry +, estimates carry ~.
Fixed
  • The model picker lists Muse and Claude models again. Both showed only Default; the Spark set and the haiku and sonnet aliases are back.
  • Pricing updates apply even after large list-rate moves when the local rates went stale.
  • Monthly session counts respect the selected date range and filters.
  • Scrolling stops at the last full page instead of leaving a nearly blank report below the last row.
v1.0.61 fixed
Fixed
  • An account that has not claimed a handle yet works everywhere. Chat, pins, recent places, search history, saved work, biometric vault unlock, and sign-out cleanup previously needed a handle and silently did nothing without one. They now use the account itself as the identity, and the login output no longer invents one.
v1.0.58 new · 3 changed · 4 fixed

Automation graphs arrive on phone and iPad, the iOS editor gains line numbers with find and replace, tasks run durably across Apple clients, and updates and usage reporting get more careful.

Added
  • Automation graphs on phone and iPad. Create, edit and delete graphs, edit steps and connections, draft a graph from a prompt, and save with revision checks. Run history is kept, and undo is validated by the host.
  • An iOS editor that keeps up. Line numbers and change marks, find and replace, protection against concurrent writes with save states, editing from diffs, and review-all on iOS.
  • Durable tasks across Apple clients, with an adaptive host-wide task board. Task results route to folder changes and history.
  • Scheduled jobs authored from phone and iPad, with complete run history, host-wide queue settings, and the host timezone shown for the next run.
  • Workspace tools beside chats and terminals: a resizable browser pane with a toolbar button, Auto commit started from phone and iPad, and committing reviewed file selections plus pushing reviewed branches from Apple clients.
  • Extended workbench shortcuts with native discovery.
  • A forwarded browser beside work on iPad, and folder expansion that survives navigation. Job context is preserved across adaptive layouts on iOS.
  • A monthly usage view in the CLI, machine-readable scheduler output, and model values inside JSON reports.
Changed
  • Update checks prefer cached release metadata from tokenstat.ai and reuse GitHub authentication. Downloads proceed when the host is already current.
  • Usage blocks follow the CLI timezone, and monthly sessions count distinct sessions. Codex general usage shows first in limits.
  • Recent Mac builds add agent availability, notices and interface fixes.
Fixed
  • The updater extracts archives in a sandbox with size caps, streams downloads while verifying them, matches checksums exactly, and retries after a failed update instead of going quiet for a day. Claude token renewal is serialized, push registration is validated, and background notifications are queued instead of spawning a thread each.
  • Task stop, run and the live terminal stay honest. Concurrent automation edits recover, canvas drag coordinates are stable, and scheduled sync stays coordinated.
  • The CLI rejects contradictory flag pairs at parse time, the dead update flag is gone, budgets reject non-numbers, and unknown export formats error instead of silently emitting JSON. Wide characters no longer shift table columns.
  • Usage parsing is more accurate across sources: unknown stays unknown, session identity no longer collapses, and reasoning figures are clamped.
v1.0.44 new · 6 changed · 5 fixed

Chat opens with cached previews, iPad layouts make better use of available space, and the Mac gains a browser beside chat and clearer workspace tools.

Added
  • A resizable browser beside chat on Mac, with Back, Forward, Reload and an option to open the page in your default browser. Web links in chat open beside the conversation by default; change this in settings if you prefer your usual browser. Local development links open on the Mac running the app.
  • Files, Changes and History alongside Chat settings in the chat inspector.
  • ECDSA P-256 SSH key generation, alongside the default Ed25519 option. On devices with Touch ID, an optional P-256 software key can require biometric access. These keys stay on that device and do not sync to the vault. This is Keychain access protection, not Secure Enclave signing.
  • Dismiss update errors without disabling updates. When GitHub limits update checks, the app shows a retry time and pauses requests until the waiting period ends, including after restarting the app.
Changed
  • Recent chats prepare small, bounded previews when a project opens and when you navigate between conversations. Preloading does not fetch entire conversations or start an agent.
  • Plan-limit and workspace cards on iPad adapt to the available width, returning to a single column in narrower windows. Device rows keep their spend value without the extra bar underneath.
  • Tapping the connected computer in the iPad sidebar opens its device page. Disconnect is an explicit action there; choosing another computer switches the connection.
  • The Mac Changes inspector puts Review all beside the change summary and Select all immediately above the files. Commit help explains selection, publishing and Auto commit. Large inline diffs show a bounded preview with a full-review action.
  • Pull-request lists retain matching cached results while refreshing, with clearer filters and loading states. Detail pages and saved commands use more consistent typography and spacing.
  • Mac devices are ordered by current device, online state and recent activity. Side-by-side connection and permission cards share a height.
Fixed
  • Scrolling near the start of a conversation no longer keeps fetching older pages while previously loaded messages remain hidden behind Show earlier.
  • Inline diffs no longer use a lazy layout that can snap horizontal scrolling back. Browser resizing uses stable drag coordinates and avoids saving each mouse movement to preferences.
  • Opening Chat from the project launcher shows the conversation overview, rather than reopening the last chat.
  • Switching projects clears the previous pull-request detail. Account changes clear browser URLs and pull-request state, and the chat overview no longer exposes settings from the last conversation.
  • SSH key creation rejects overlapping operations, preserves the chosen protection, and cleans up newly stored secrets if saving the key fails.
v1.0.32 new · 10 changed · 7 fixed

Devices and Workspaces on the phone got a clearer layout, plan limits keep Codex's general and secondary names after sync, and the Mac no longer freezes when you flip through the sidebar with a chat open.

Added
  • Customize Workspaces on the phone, next to Customize Home. Drag Folders, Recent chats and All sessions into order, or switch any of them off. Three presets: folders first, chats first, sessions first. The choice is saved on this device, used on the Workspaces tab and on a host opened from Devices, and listed in search. Hosts stay above the arrangement.
  • Skip this version on the update card, including after a download is ready. Automatic checks at launch and after reconnect honour the skip. Check for updates yourself to clear it and hear about that release again.
Changed
  • A host posts each plan window's scope with the reading. The phone and the dashboard then name Codex like the Mac: weekly (general) next to weekly (secondary). Posts without a scope still show the bare label.
  • Insights on the phone always puts three equal panels in one row, and the same row on Chat, tasks, workflows and automations. Event counts use the same short form as tokens: 126k, 1.2M.
  • Devices shows plan capacity as a trailing chip and a thin bar. No "Share of…" line under the title. This device ends the row with a You chip.
  • Devices drops the Always-on host panel. Each row carries awake, asleep or remote-setup status. Always-on copy stays on the detail screen. Order is this device, then awake hosts by spend, then the rest by last active. Phones, tablets and this device hide the spend figure that used to read $0.00.
  • On Legal, the Sync privacy card is written for the phone. Computers put aggregate counts on the account, this device reads them, and remote folders, terminals and agents stay encrypted between devices. The card lists what is on the account, what never leaves the computer, and what remote means.
  • The update check compares the app marketing version and hostd. Mac and Windows send the bundle version. Newer is true when either lags the release. Omit the app version and only hostd is compared, as before.
  • Clicking a folder always opens Launch. The folder row stays selected while Launch is up. Sessions only lights when a terminal is in front.
  • Bypass permissions applies to agent launches as well as shells, on the Mac and on the phone.
  • Switching branch with unsaved files open asks first: save and switch, discard and switch, or cancel. Discard reloads the buffers so a later save cannot write the old branch's text over the new one.
  • Streaming chat markdown parses on a short cadence instead of once per token, and only http, https and mailto links stay tappable.
Fixed
  • iPads draw with the tablet symbol. Non-host rows always used the phone icon first.
  • A large event count on Insights no longer spills out of its panel next to a short token figure.
  • Leaving a terminal for Launch or Sessions no longer collapses the centre pane. The AppKit terminal is hidden for real, and Launch sits as a layout sibling of the terminal surface rather than inside a zero-height reader.
  • Flipping through the sidebar with a chat open no longer freezes the Mac. A chat kept behind another screen stops measuring its transcript until it is front again. Pull requests do the same after a visit.
  • An automation interval under a minute keeps its seconds through edit and save, instead of collapsing to a whole minute.
  • Commit and push banners stay on the folder that produced them. One workspace's result no longer appears over another's panel.
  • A chat approval with time left no longer looks expired while the live list is still loading.
v1.0.26 new · 6 changed · 10 fixed

The composer reads the plan it runs on, access approvals explain themselves, and Codex limits name the account week beside the model's own.

Added
  • A quota badge beside the Mac composer controls reads the agent this conversation runs on, such as 5h 34% and 7d 87%. Tapping it shows every window with reset times and a refresh. A chat on an agent with no reported quota shows no badge rather than somebody else's numbers.
  • A turn clock in the composer and on the sidebar conversation rows shows how long the running turn has been going. Both read the same stamp, so the two never disagree.
  • The SSH Hosts row collapses behind a chevron once folders or live sessions sit under it. It stays open by default and remembers the choice, and opening a folder expands the way to it.
  • Servers show their distribution's own mark after connecting, replacing the invented initials.
  • A todo card's priority can change after creation, from the inspector picker or the card menu. The task tools accept it on update as well as on create.
  • Approving a device explains itself. The phone shows a sheet naming where the request went and what answers it, with copy buttons instead of retyped commands. On the command line, pending requests take a number, a key prefix, or a label, with --all for the whole queue.
Changed
  • On iPhone and iPad, a screen's figures each sit on their own card rather than sharing one strip, and every figure and section heading carries its own icon. Chat, tasks, workflows, automations, notes, insights and the today and this week totals on Home all read the same way now.
  • Codex limits name whose allowance is whose. The composer badge shows the account allowance, and the popover lists all four windows as 5-hour (general), weekly (general), 5-hour (secondary) and weekly (secondary). The account week now survives a session that fell back to a model allowance instead of hiding behind it.
  • OpenCode no longer estimates quota from local message costs against written-down ceilings. An account with no reported quota says so.
  • On the phone, the Insights period strip is three panels instead of one card: tokens, events, and the models, harnesses and days behind the cut. They sit side by side where there is room and stack where there is not.
  • Phone cloud import and setup offer DigitalOcean only, with a link to where the token lives, and the server guide links the referral URL with disclosure.
  • Searching everything carries its own mark, leaving the plain magnifier to the field that filters the page.
Fixed
  • On iPad, the account picture and the tokenstat name stay in one row at the top of the sidebar, in the same place whether the window fills the screen or floats.
  • The encrypted vault row, and the rename control on a device, are tall enough to hit comfortably. Both were under the size a finger is entitled to, and both were cramped with a pointer as well, so they grew on the Mac too.
  • Installing an agent on a server works. A host started by systemd is handed no home directory, and everything it ran inherited that: a vendor's installer stopped with HOME: parameter not set, and a tool that did install read as missing afterwards, because ~/.local/bin had been built from an empty string. The daemon now takes its home from the account itself, so installers, agents, git and ssh all have one.
  • Another machine's folder offers its whole launcher again. Opening a remote folder after a local one never asked the owning machine what it could run, which left one shell tile and no way to install anything from the Mac. It now keeps asking until that machine answers, so connecting later fills the grid in rather than leaving it short.
  • On the Mac, an empty conversation list sits in the middle of the pane, a new terminal opens at the size it keeps instead of redrawing once, and a conversation can be removed from its own menu.
  • Tapping a machine in the phone sidebar connects to that machine. An approval wait no longer hands the dial to the remembered one, and the detail column lands on Workspaces first, so the waiting card and any error stay on screen.
  • The composer and transcript hold still around a new chat. Trailing controls keep one shape, a fresh chat skips the wireframe it has nothing to fill with, sends never cover rows being read, and a double tap makes one conversation, not two.
  • Cloud imports save again on every provider. The importer built refs the records reject, so DigitalOcean and AWS imports failed at save time.
  • The phone chat composer shows one glass surface instead of two, so the pill no longer blooms bright over the bar.
  • On iPad, windowed mode keeps the brand out of the traffic-light row, tabs keep their wordmark, and SSH shows by default instead of hiding as an opt-in.
v1.0.12 new · 3 changed · 9 fixed

Small corrections on top of 1.0.0, most of them invisible.

Added
  • A machine that already has folders can get more from its device page: the folder picker and clone live there as well as in the empty state.
  • Devices carries an auto-connect switch per machine. Off stops the app dialling on its own and leaves a live connection alone; only Disconnect drops it.
Changed
  • The Add this device, clone, and folder bottom bars follow the theme, as do the client search fields and menu separators.
  • On the Mac, Today, Last 7 days, and Busiest are separate panels, like the phone's tiles.
  • On a new Mac, Home opens on Balanced with the work first.
Fixed
  • A finished turn always releases the conversation, so a new message can no longer sit queued with sends doing nothing, and the app says why when a turn is still finishing.
  • Setting up a server retries over a stale pairing file, trusts the new machine before checking it, and goes from the machine straight to a project.
  • The Windows build and its tests are green again.
  • A transcript the meter cannot reach reports an error instead of a zero usage figure.
  • The host runs an existing login shell instead of assuming zsh, so the Shell tile works on machines that have no zsh. An installer that exits zero without delivering reads as a failure with its output.
  • Disconnecting from a machine sticks: the peer sweep no longer re-dials it on the next pass. Removing a remote folder asks the owning machine instead of failing silently.
  • Each machine's launcher list is its own, so a second machine shows its own tools, with a shell tile while its catalog loads.
  • The screen viewer is not offered on headless Linux hosts.
  • The CLI says how to approve a pending device in host access.
v1.0.017 new · 4 changed · 7 fixed

A phone can now produce a working machine. Until this release tokenstat assumed a computer already existed: install the desktop app, register a folder, and the phone became a window onto it. Now somebody holding only an iPhone can end up with a server that runs agents.

Added
  • Set up a machine, from the phone. Four doors: a server you already have, a machine at DigitalOcean or AWS, the Mac you work on, or none of them, which keeps working and is not a failure state. The server door connects over SSH with your own key, checks what is on the machine before writing anything, installs the host, signs it in, and comes back paired. You watch the whole install in a real terminal rather than behind a spinner.
  • The same install, to run yourself. Handing an app an SSH key is a reasonable thing to decline for a server that matters. The command is on screen with a comment per flag, and it is also what the app offers when SSH cannot get through, which a bastion or a provider console will do.
  • A machine nobody is sitting at can let a device in. Being on the account has never been the same as being allowed to open somebody's work, and on a server there is nobody at the keyboard to answer. Three ways now, all of them from the machine's own console: allow a device by name, grant the device that is installing it, or print a one-time code and type it into the app. The code never reaches tokenstat.ai, expires in fifteen minutes, works once, and is retired after five wrong guesses.
  • tokenstat host is a full console. Status that reads in the order you debug in, start, stop, restart, logs, the devices allowed here, invites, an audit log of every grant, and an uninstall that never touches your folders. It says who agents run as at the top, because a root install gives every agent on that machine root.
  • The always-on host ships with the CLI on macOS and Linux, and survives a logout on Linux instead of dying with the SSH session.
  • Choose a folder on a machine with no screen. The machine answers what a directory holds, so a phone can pick a folder on a server the same way a Mac picks one in a panel. It can make a folder, and it can clone a repository onto a machine that has none, in a terminal that can be answered when git asks for a passphrase.
  • Empty screens now offer the thing that is missing rather than describing the hole: no machine offers to set one up, a machine with no folders offers both ways to give it one, and a machine that is not answering says what to run on it when it is a server rather than telling you to wake a Mac.
  • Home is yours to arrange, on iPhone and iPad. Drag the cards into the order you read them in, switch off the ones you never do, or start from one of three arrangements: Balanced, Work first, Usage first. A small preview shows what you are about to get. Every card can be off, and a clear Home is a real answer rather than an empty screen. The arrangement belongs to the device, so a phone and an iPad can be different, and Done applies it in one go while Cancel really cancels. Reordering also works from VoiceOver, not only by dragging. The greeting and anything about your account or your connection stay where they are: hiding Activity must not hide "you are offline".
  • A message is sent once, even when the answer goes missing. A machine that takes a message now keeps a receipt for it, so pressing Send again after a connection that went quiet gets you the conversation rather than a second agent run on the same words. When that happens the message goes back in the field with a line saying the machine did not answer and that sending again is safe, and the app asks the machine what became of it. The machine has to be on this version for the guarantee; an older one behaves as it did, and the app does not repeat a send to one.
  • Half-written messages are kept. What is in a chat's message field stays with that conversation: leave it, open another thread, quit the app, and it is there when you come back, with the files you attached to it. A list marks the conversations holding words you have not sent. Sending a message keeps the words until the machine has taken them, so a refusal puts them back instead of losing them. They are kept on this device only, and if a write ever fails the field says so rather than claiming it saved.
  • Opened conversations are kept on this device, encrypted. Open one again with no connection and it reads from the saved copy, which says when it was saved and what it does not contain. Pin a folder or a conversation to Home to keep it close, on the desktop Home as well as the phone. Saved copies never leave the machine, a damaged store is quarantined rather than deleted, and removing a saved copy clears its history everywhere.
  • Search your saved work, and the machines that are awake. One search covers the conversations on this device and asks the hosts that are up, then merges the answers with live results first. History is shared across windows, and a result that cannot be opened says so instead of dropping the list.
  • Hand work to another device. Start on one, carry on on the other: the draft, the files and the place in the transcript move across, and an import whose files are gone says so instead of guessing.
  • A message queued offline is sent when the machine is back. The send keeps its files, its place and its review state through a crash, a reconnect or a quit, and repeating it is safe: the machine answers from the receipt instead of running the agent twice. The first page of a long conversation reloads once after upgrading, because transcript positions changed format.
  • The update finds the computers too. Devices shows the release a paired host runs. A host downloads its own update, proves the new binaries run, and restarts when nothing it owns is running. Otherwise it waits and says what is in the way, and you can insist, having been told what insisting ends.
  • Assistants can find their way around. The MCP server lists workspaces and manages tasks and notes, so an agent working through it sees the same workplace a person does.
  • New dashboards on macOS and iOS. Usage, activity and rankings read the same on both, with accessible tables and a refreshed look.
Changed
  • The getting-started card no longer says the product starts on a computer, because it no longer does.
  • Devices leads with setting a machine up rather than listing the ones that already exist.
  • The app icon is new: layered glass with the mark over dark and light grounds.
  • Home tells a machine that is offline apart from one that is asleep, and plan cards load only while they are on screen.
Fixed
  • Deleting a local conversation from the Mac sidebar while a remote folder is open now uses the local machine. Host recovery notices also keep their order when several calls finish together, so a healthy helper cannot leave a stale reconnect warning behind.
  • Remembered conversations now belong to their account, machine and folder. Separate windows preserve each other's recent selections; old unscoped selections are not assigned to whichever account signs in next.
  • Cursor chats work. A Cursor turn used to fill the transcript with rows called HookAdditionalContexts and GetMcpTools, none of which ever finished, while every shell command it tried came back refused without saying so and its answer arrived two or three times over. Tool rows now carry the name of the tool that ran, its output, and its verdict; a file it changes shows the red and green lines; each message appears once, including when the CLI loses its connection and says the whole turn again; and the conversation carries over between messages instead of starting again each time. When Cursor itself gives up, the chat says so in a sentence instead of showing you RetriableError: [resource_exhausted] Error as though the agent had replied it.
  • A chat that has been open for a while no longer stops responding. Two causes, both of them a message arriving several times a second into a transcript in the middle of laying itself out. The local helper told the window it was healthy after every call it answered, from whatever thread had answered one; it reports once per change now, on the thread that draws. And the message field told the window its height might have changed on every update, whether or not a word had been typed, which made the conversation beside it measure every message it was holding. It says so when the draft or the width actually changes.
  • The message field no longer answers its own writes. Putting the draft and the caret back where the app said they were made the field report that same position as news, mid-draw, which asked for another draw. It is quiet while it is being set, and it reports a caret only when the caret actually moved.
  • Navigation, chat rendering and remote sessions are steadier on iPhone and iPad. Saved places stop retrying after you have moved on, search preparation stays with its own screen, and recent chats load against the destination they were opened for.
  • A new account with no handle yet can finish setting up: the setup gate no longer reads it as signed out. Setup doors also stay quiet about failures until one is entered, then offer a retry or a sign-in card instead of a dead button. Relay use is metered by what it was for, so a pooled channel reused for chat no longer bills chat bytes to the terminal.
v0.9.25 fixed

Three ways a chat could stop working: a tool that never finished, a transcript that stopped responding behind it, and a notification tap that closed the app.

Fixed
  • A Claude tool call ends when its result arrives. Bash and the rest used to stay marked Running, with an indicator that never stopped, for the rest of the conversation.
  • A chat with several tools running no longer stops responding. Every running row turned its own indicator, and a transcript full of them spent all its time laying itself out again instead of drawing. One row turns now and the rest say Running in words, so however many the computer reports, the conversation stays usable.
  • Tapping a chat notification on iPhone and iPad no longer closes the app. 0.9.1 fixed one cause of that. This is the other one, and it closed the app every time.
  • A notification for a conversation or a terminal that is no longer there lands on Workspaces instead of doing nothing at all. It also stops trying after a minute, rather than dialling the computer again on every later visit to that screen.
  • A long reply is lighter to stream on both the Mac and the phone. The turn being written used to push the rest of the conversation out of the store that keeps finished messages ready to draw, so scrolling back through a long chat had to rebuild what it passed.
v0.9.14 new · 7 changed · 3 fixed

Chat on the phone catches up with the Mac: sends that queue, notifications that open the work, folder history, and a composer that stays on the transcript.

Added
  • Tapping a notification opens the work that needs you. A terminal waiting on a permission prompt opens that session. Otherwise the chat that finished, or is waiting, opens. On a Mac it brings the window forward. On iPhone and iPad it opens over the app, unless that conversation is already on screen, in which case the same window stays.
  • Send while a turn is still running queues the next message. A compact strip above the composer says it is waiting to send after this turn. The next message can be edited or removed there, and Send now stops the current turn so that message goes out next. Two or more waiting messages open from View pending, so the list does not cover the transcript.
  • A folder on iPhone and iPad has History, the same previous-commit list the Mac inspector already showed. A folder that is not a git repository, or one that has no commits yet, gets a drawn empty state instead of a blank list.
  • Sessions on iPhone has the branch picker and the bypass switch the Mac already shows. A launch from the phone can skip permission prompts the same way.
Changed
  • Opening a conversation on iPhone hides the tab bar, so the composer sits on the transcript. Coming back to the list brings the bar back. The chat list and the other folder sections keep the bar throughout.
  • The composer floats on the same glass as the tab bar, including the home-indicator edge, so the lower end is not a grey strip.
  • Sending a chat message on iPhone hides the keyboard and jumps to the latest turn, so the reply is not sitting above a closed keyboard.
  • Jump to latest, Following and Follow share one compact themed capsule with a down arrow, sitting on the transcript. Following is no longer a grey pill.
  • A file the agent edits is one card named after the file, not an Edit tool row plus a second copy of the same patch. A later change of that file in the same turn is marked 2nd change.
  • Account, This device, opens with Notifications. The switch used to sit under the cache, below the fold on a phone.
  • The end-to-end note on Workspaces is a glass divider between the hosts and the chats, not a second device card. The keys are still a tap away.
Fixed
  • Tapping a chat notification on iPhone no longer closes the app. A missing host or an empty recents list lands on Workspaces.
  • A sent chat prompt is on the transcript as soon as it is sent, including when the conversation is just opening. It used to appear only after leaving the composer and coming back.
  • A grok chat in Plan can spawn a subagent. The call came back as cancelled even after you had allowed it, so the agent stopped exploring instead of reading the project. Plan still blocks edits.
v0.9.09 new · 13 fixed

Chat can carry files, Account splits into panes, the vault unlocks with Touch ID or Face ID, and a connected computer shows which path it took, direct or relayed.

Added
  • Attach a file to a conversation. Ask an agent to send, show, or present something and it puts the file in this thread. An agent with a mail or bot tool used to reach for that instead. On the phone, tap a file to open it: video and audio play, text, source and PDF render, images show, and the viewer's own share sheet carries Save to Files, AirDrop and the rest.
  • Files over 1 MiB wait for Download. Smaller ones arrive on their own. A device-local cache holds what you have already fetched, with a size cap and an idle retention you can change. Purging it clears the lot, and a download already in flight cannot put those bytes back. A file the computer refuses for good, because it is too large to transfer or is no longer there, says so instead of offering a retry that cannot work. The setting is named tokenstat cache. Chat files are what it holds so far.
  • Account settings split into panes. On the Mac: Account, Plan limits, and This Mac. On the phone: Account, This device, and Legal. Deleting the account sits at the end of Account, behind its own rule. It used to sit among the legal documents.
  • Account shows this device's own direct and relayed traffic, counted since tokenstat started, separate from the account relay allowance.
  • Workspaces and the device page show which path this phone took to the computer, direct or through the encrypted relay. The screen viewer already did.
  • The phone composer reads as glass, with the conversation moving under it. Send appears when there is something to send instead of sitting greyed out, and a toggle at the top right grows the box for a longer message.
  • The combined agent, model, and effort picker stays open while you change those settings. It shows what is selected, and the phone's targets are larger.
  • Touch ID on the Mac and Face ID or Touch ID on the phone can unlock the vault. The sheet opens straight into it when this device has a saved password, without showing the password form first. The password remains the fallback, and a changed biometric set forgets the saved one.
  • Relayed traffic shares one allowance: 100 MiB on Free, 1 GiB on Supporter, 5 GiB on Patron, and 20 GiB on Legend, covering today and the previous 29 UTC days. Direct connections do not count. Each day the oldest day leaves the window, so there is no monthly reset.
Fixed
  • Downloading one attachment no longer rebuilds every card in the transcript.
  • A downloaded chat file on the phone opens, instead of reporting that the file name is invalid.
  • A few-megabyte chat file failed to download over the relay, while the same file arrived over a direct connection. The tunnel waits for the socket now instead of dropping the burst.
  • Recent chats on the phone dropped a thread you had just used when many conversations were unread. The three newest sit at the top, then five more by what needs a look.
  • The expand control at the top right of the phone composer had no glyph.
  • A phone chat had no way to put the keyboard away once it was open, so the transcript could not grow. Drag the conversation, tap it, or tap the keyboard button above the field. That button is there only while the keyboard is up.
  • Full screen on a Mac watching another Mac did nothing. The viewer is its own window now, so the expand control fills the display.
  • A Mac asking another Mac for the screen or for folders never brought up a permission prompt on the host. The request opens as a sheet, the Mac sidebar asks when a host refuses the work, and the screen viewer asks the moment a connection is refused. It used to wait for a second press. Approving a screen grant also asks macOS for Screen Recording, and for Accessibility when control is included.
  • On older macOS the connecting spinner was a bar that travelled across the screen. It stays circular. The chat composer on those versions packed agent, pills and send against the trailing edge with a gap after attach, and keeps those controls next to attach.
  • A long conversation keeps a fixed window of rows and slides it to earlier turns, instead of growing the stack until layout stalls. On a Mac, a message is selectable once the pointer is on it.
  • Edit and tool rows keep +/− on the right, next to the time and the button. A short path used to leave the counts after the name, and a long one shoved them against the button.
  • Last sync on Account sits with its time and Sync now on one row, at the same size as the rest of the card. It used to be a large title stretched across the panel.
  • An account with no photo shows initials from the name, the same filled bubble the phone already draws. The picture still shows when one is uploaded.
v0.8.36 new · 15 fixed

The model picker has a search, chat follows a turn started on another device, and notifications wait until you have looked away.

Added
  • Type to filter the model list. An agent CLI can offer forty models or more, and "meta 1.3" finds meta/muse-spark-1.3. Agent, model and effort share one panel, each section showing what it is set to. Lists under ten entries stay a plain menu.
  • A Refresh sits beside the models. The list comes from the agent's own CLI and is held for ten minutes, so a provider you added an API key for a minute ago was missing until that expired. Refresh reads the CLI again. Short lists keep Refresh inside the menu.
  • Codex models. A Codex chat had no model picker, so it ran only the model set in its own config file.
  • Muse backend in chat, automations, and transcripts. Automations run it bypass-only. Plan-mode chat drops the bypass flag and turns off its write and shell tools.
  • Quick section tabs in the agent/model/effort picker. Agent, Model, and Effort read as separate settings before any scrolling.
  • Setup guidance for Remote Reach. The phone shows an empty state and a recovery card when a Mac never registered for remote reach, with the exact steps and a retry. Mac machine settings carry the same switch as a compact preference with status text.
Fixed
  • Notifications hold off while you are watching. A turn that ended in the conversation on screen still posted a banner and buzzed your phone. Now both wait for another app to be in front, the window to be away, or the keyboard to go untouched for a while. A phone driving a chat on a desktop no longer notifies itself. Watching one conversation from a Mac and a phone holds a lease per watcher, so leaving on one device no longer drops the other, and iPhone and iPad suppress their own banner for the open chat, same as the Mac.
  • An open conversation keeps reading its events. It polls every 2 seconds while idle and every 400 ms once work appears, so a turn started on another device appears with no tap. A background hiccup no longer pops an error banner on an idle screen.
  • Chat scroll corrections run after layout and combine pending corrections. Image previews keep their frame while decoding and when scrolled back into view, instead of collapsing and growing during row placement.
  • Live follow holds the end while a reply streams and keeps pinning through late resizes from diffs and images. Opening a long chat still settles on the end. Sending a message locks follow until a scroll of your own leaves; estimate shifts no longer park the transcript behind Jump to latest.
  • Scrolling a long transcript no longer stalls the app to a force-quit. The transcript builds a bounded window of rows with a control to reveal earlier ones, an open diff draws as one text instead of hundreds of rows, and hover stays off mid-fling. Fast scrolls stay responsive on conversations of any size.
  • Tool rows classify shell intent by program name, so quoted commands land on the right card and echo "a > b" stays Shell. Repo-relative paths resolve, multi-file edits name each file, and a cancelled command closes as failed. Muse task starts survive replay order. Muse todo answers read as "4 todos (revision 2)" instead of raw JSON, and a failed one fails its card.
  • Handing a long conversation to another agent keeps early turns. The inline summary is unchanged; when turns fall out of it, the new agent gets the path to the full history beside it and reads further only when needed.
  • Model lists parse the Codex answer by id, reap a hung list command with its process group, keep provider-qualified ids visible, and share one run across Refresh taps. Picker Enter stays inside the visible filter and prefers the exact label, so a typed model id no longer selects the Agent row. A stale Effort filter clears when the new agent has no Effort section.
  • A new automation starts on an agent. It opened on Shell, and a shell command belongs in the prompt field. Shell is still in the picker, at the end.
  • A phone that cannot reach a computer names the fix. It showed the transport's own words, "no direct address" and "no_such_peer". Usually that computer has never had "Reach devices from anywhere" turned on, so the relay has never been told where it is. The recovery card now shows only for that never registered case. Timeouts and wakeups get a retry card instead.
  • The vault is password-only. No identity-encrypted copy of the key sits on the server or on disk, and the app asks for the password again after a host restart. Password change and recovery rotation replace the key, both wraps, and every enrollment in one step. Recovery rotation needs Supporter or higher, like the rest of vault sync.
  • A remote machine cannot be talked into reaching a third one: forwarding sent over a peer's own connection is refused at the door. Screen and terminal streams re-check permission for as long as they run, so taking access away ends a live stream, and vault rollbacks are refused.
  • Android private keys live in the Android Keystore. Each key is verified before its plaintext copy is removed, one bad entry no longer blocks the rest, and a wrong vault password leaves the dialog open for another try.
  • Windows model Refresh reports a host failure in a banner instead of crashing. Old hosts answer from cache.
  • On pull requests, the art on the connect card is centred. Choosing which repositories tokenstat may open also stays on that screen after you connect. It used to vanish as soon as one repository worked, which left the Account screen as the only way back to it.
v0.8.22 new · 11 fixed

Chat on the Mac keeps up with the conversation, and a terminal you come back to draws what is on it.

Added
  • Claude's higher effort levels, xhigh and max, are on the picker. Opus at max effort is now a conversation you can start.
  • Windows and Android previews catch up with the Mac. Both open the year at a glance from one call, where they used to rebuild it from a report. Windows grows a diff viewer and a transcript that appends a turn without redrawing the thread. Android grows the Chat and Pull requests sections, and keeps a conversation current while you watch it. Each one hides what the computer it is paired with is too old to answer, so an old pairing says so up front and no longer fails at the tap.
Fixed
  • A long conversation no longer hitches or freezes. Scrolling a turn full of tool output stays smooth, a streaming reply stops rebuilding the thread on every frame, and a shell command that ran to megabytes is split once, not on every redraw. A tool that answers in one long line, which is every tool that answers in JSON, no longer freezes the thread: a web search result arrived as a single forty-kilobyte line and was laid out in full on every pass the transcript made over it. Output is cut to what a row draws, with the whole of it still on the clipboard.
  • Following a live turn stays out of your way. It holds the end while the reply grows, lets go when you scroll back, and stops yanking the thread on tool-heavy turns. A pill reads Following, Follow or Jump, and takes you to the end.
  • A whole reply can be selected in one sweep, and copy appears on the card you are pointing at, with a tick where you pressed it.
  • A tool row reads as what it did: the verb, the file, and how many lines moved. Small diffs open on their own, and one that is still arriving keeps opening as it grows, until you open or close it by hand.
  • Sending an image with nothing typed works, and the image stays in the transcript as a row of its own. It used to disappear into a turn with no visible content.
  • A conversation loaded to its first message says Start of chat. It used to read as stuck part way through history.
  • The sidebar marks the conversation you are in, and clears that mark when you leave. Picking Notes, Home or a server used to leave the old chat lit beside the row you had chosen.
  • A terminal you navigate away from and come back to repaints. It could show a stale or half-drawn screen, and a full-screen program kept the old window size until you typed something.
  • Characters that SSH drew ahead of the far end no longer freeze on screen when you return to a session. A guess that has gone unconfirmed is withdrawn, and the far end draws the line.
  • A terminal nobody can see is left at the size it had. Hidden sessions were being resized, which could collapse one until input revived it.
  • The list of agents and their models answers immediately. One agent whose command hung held it up for seconds at a time, every minute, and a failed check keeps the models it found last time.
v0.8.13 fixed

A hotfix for agents that would not start from chat.

Fixed
  • An agent launched from a conversation is found the same way the launcher finds it: your PATH, then your login shell's PATH, then the places a harness installs itself into. The helper runs from launchd and inherits none of that, so an agent the launcher listed as installed could still fail to start with a short PATH for an error. Chat, automations and workflows all spawned the same way and are all fixed.
  • Node version manager directories and the usual install locations for a few more agents are searched too, so a tool installed under a Node version or in its own directory is picked up without being pointed at.
  • The first conversation on a new machine starts in execute rather than plan. Once you have chosen a mode, your choice is what comes back.

Full history and source on GitHub.