Kin / Maintainers

Changelog

Recent Kin changes, release notes, and compatibility updates.

Read as Markdown

A curated, user-facing summary of what landed recently. Kin’s immutable journal of record is Git history; STATUS.md is the bounded present-tense operator board. This page is the friendlier surface: what’s new, what changed, what to know.

2026-09-24 — GPT-6 ChatGPT choices (0.28.0)

ChatGPT model selection now offers GPT-6 Astra, Sol and Luna when available to your connected account. Older generations are no longer offered for new selections. Existing conversations, saved configuration and job assignments are not silently moved to another model. The Kinra Gateway default is unchanged.

Space receives the new catalogue when its installed Kin companion is updated.

2026-09-24 — Headless outcomes, explicit providers, and submitted words (0.27.0)

  • Exit 2 means needs-human only. Invalid command lines now use 64 (EX_USAGE), including terminal and subcommand usage errors. Configuration, protocol and service-start failures use 1. Schedulers can distinguish a refused invocation from a trust or approval gate without reading stderr.
  • Content-free status: -p --status-file FILE writes only a version, exit code and fixed reason. Exit 2 distinguishes workspace_trust from human_gate; no prompt, reply or approval detail enters this file.
  • Selected presets fail closed. Unknown ids and invalid first matching custom provider rows fail before inference instead of falling back to a different provider. This applies to the winning CLI, environment or saved preset selection.
  • Submitted words stay distinguishable from attachments. User journal records keep additive user_text beside the unchanged expanded message. It preserves the original input through file mentions and client context; old journals still replay unchanged. Known generated input uses null.

Space adoption is separate: releasing Kin does not update a home’s installed companion.

2026-09-22 — A client tells Kin how its home works (0.26.0)

An application that hosts a conversation, such as Kinra Space, can now say in its handshake how its home works — where its notes and tasks files are, what its widgets are — and Kin keeps that as one labelled block of its instructions for as long as that application is the writer. Until now a home learnt about its own application only from a starter AGENTS.md written once at setup, so features added afterwards went unmentioned. Your own AGENTS.md is unchanged and still read. Observers offer no guidance, and a writer that steps down takes its guidance with it.

2026-09-21 — An image inspection says why it failed, and a managed job comes back (0.25.2)

With a Kinra connection and no route assigned to Vision, inspecting an image was refused by the service for its application role, and the model concluded that vision was unavailable. Kin now labels a request with a role only when it resolved a placement for it — an assigned route, the Utility binding, or a model you named — so an unassigned inspection asks Main honestly, as it always has with other providers. When an inspection fails, Kin adds its own sentence outside the untrusted provider text: either no route is assigned to Vision and how to assign one, or the service refused the route you assigned.

A Kin-managed Vision or Utility assignment that has gone missing is restored by the next ordinary profile refresh while Kinra is your active provider. An assignment you wrote or changed is still yours and is never moved, and a Kinra connection installed beside another provider keeps track of the assignments it wrote instead of forgetting them.

2026-09-20 — Release bundles stay readable from private workstations (0.25.1)

Release bundles now carry explicit public file and directory modes rather than inheriting the publishing workstation’s default. A workstation that keeps new files private can therefore publish the same readable channel bytes as any other release machine.

2026-09-20 — Local clients see attachments, titles and phases (0.25.0)

A file you attach in a local client is now looked at, not just named: images among a turn’s attached paths are inspected through your Vision route, under the same gates an @image mention uses. A conversation hosted for a local client also names itself in its idle gaps, on an assigned Utility route, and tells the client when it has — and hosted Kinra inference may now advertise its own utility model, which Kin adopts as a separate route instead of sharing the vision endpoint’s one slot. Delegated runs report what they are doing between tool calls — thinking, responding or retrying — so a client can show live work without forwarding any of the child’s content.

2026-09-19 — A retried round replaces its partial reasoning (0.24.0)

When the model’s stream fails after Kin has shown its reasoning but before any answer, Kin now retries the round instead of ending the turn in an error. The partial reasoning is withdrawn and the retry’s takes its place. A turn that had already shown answer text still ends with the error, as before. Local clients opt in with reasoning_retry; see Local clients.

2026-09-18 — Person-owned plan mode and local client additions (0.23.0)

Plan mode is now yours to start. Kin does the work by default; when it thinks a task needs design agreement first it asks to enter plan mode and you approve or decline. Writing a plan no longer freezes the session, and Kin no longer dispatches a planner or an adversarial review on its own. Review plan first remains your choice when a plan is presented.

Local clients can opt in to the checklist and task list, queue a message while a turn runs, list and run slash commands, run your own shell command, and see the conversation’s agents. Each is off until a client asks for it. The attached terminal now runs /plan, the text-result commands, and a contextual ! through the service. See Local clients.

2026-09-17 — Retained workspace maintenance and guarded Depot publication (0.22.0)

Workspace maintenance now retains ownership of native Git and Depot work that outlives its original command or conversation. Lost ownership evidence keeps cleanup blocked for recovery. With compatible Depot and Space companions, Kin can now ask for fresh approval of a deliberate workspace close or its exact pre-effect cancellation. A cancelled request cannot later remove the files; after file effects begin, the original close must finish.

Depot-canonical publication stops when Git configuration points at a different checkout, staging area or interpretation of history. Original work and interrupted publication records remain available for recovery. Release and receipt retries retain their original source and destination.

2026-09-16 — Reviewed workspace lists and Depot portfolio services (0.21.0)

Capable local clients can present one explicit workspace list for review. Kin records separate, revocable grants for the exact directories; added members and replaced folders need new review. The first trust decision names the session folder and explains any enclosing Git root. Reopening a conversation now keeps failed tool calls visibly failed.

A compatible Depot companion adds inspection of external checks, GitHub synchronization, incoming contributions, LFS custody and workspace use. Kin can prepare checks for exact revisions, request a freshly approved synchronization configuration change, and reconstruct retained pending work before retrying its original request. Installed support remains separate from server readiness.

Once a repository’s canonical origin is Depot, structured publication uses Depot and refuses direct GitHub push or PR creation. Ordinary Git/GitHub repositories keep their existing flow; the personal GitHub login supplies no Depot role or synchronization credentials.

Kin now protects active conversations and owned writers during coordinated workspace maintenance, retaining reservations across lost replies and restart. Destructive workspace closure remains unavailable until every participant’s protocol is qualified. Kin’s own release coordinator is prepared for Depot-canonical custody with an atomic, freshly verified release and recovery under the original human authorization; existing origins remain unchanged.

2026-09-16 — Depot history, branches and recovery, and client workspace observations (0.20.0)

With a compatible Depot companion, Kin can page through complete branch and tag inventories, read a tag’s original object, and import selected existing Git history into private custody. Import keeps its request identity across interruption, leaves local files and conflicting Depot copies intact, and never changes remotes. Custody import and cancellation still need fresh approval; credentials and the destination stay with the native companion.

Kin can start work from a chosen branch, tag or commit with an explicit merge target, resume owned Depot Changes and branches, and recover retained closed or interrupted local work at its original path. It can create, rename and retire branches, select a default, inspect effective protection and replace repository policy with fresh approval. Named versions preserve original signed tags without reconstructing signatures, and published tags stay fixed. Repository roles still govern every operation; installation authority grants no review, merge or policy authority.

Interrupted staging, local commits, sync, import, abort and publication keep their exact original requests. Kin can read retained staging and conflict versions, finish the original prepared commit or integration while preserving later edits, and distinguish an earlier publication result from current remote history. kin depot status reports each installed feature; installed support does not certify the live server. LFS assets, external automation and the complete Space move remain separate.

Local clients that declare workspace_context give the root session get_workspace_context, a bounded read of the client’s current work, saved versions, review state and interrupted operations. Kin treats the result as untrusted observations and rechecks exact state before acting; standalone and terminal use need no client. The environment reminder points to the tool without fetching anything. open_workspace now allows five minutes for the person’s review, and success means the destination conversation opened with any staged draft still unsent. Explicit context attached to a turn now follows the person’s words in the journal, so default session names start with what they typed.

2026-09-14 — Installed Depot discovery and saved-file presentations (0.19.0)

Kin discovers the installed Depot companion’s personal operation schemas, with credential-free help, fixed permission authority and immutable model-round schemas. Status identifies supported features and separates installed capability from verified server support. Structured failures retain exact recovery facts.

Capable local clients can receive a saved-file descriptor containing repository, full commit OID and path. The new present_depot capability uses network permission alongside the existing presentation acknowledgement. File fetching and access-controlled preview lifetime belong to the receiving client.

2026-09-14 — GitHub repository management in local clients (0.18.0)

Local clients can browse repository metadata from the connected GitHub account and disconnect that account on this machine. Listing includes repositories owned by, collaborated on, or available through organizations to that account; bounded pages share a short-lived snapshot. GitHub CLI keeps credentials, errors expose no raw provider output, and sign out leaves existing clones intact.

2026-09-13 — Model names in local clients (0.17.0)

Local clients can display the resolved model name separately from its configured alias and retain that identity on reconnect. The native model catalog also supplies account model labels and the official Kinra Gateway default, even when ChatGPT is selected globally. Reading the catalog keeps credentials in Kin and does not change the selected provider or conversation.

2026-09-13 — Reasoning in capable local clients (0.16.1)

Local clients can opt into bounded root reasoning text with the reasoning hello capability. Each writer and observer chooses independently. Reconnecting can recover the current turn’s reasoning from a limited memory cache; completed turns and service restarts leave no reasoning to replay. Session listings now include last activity time alongside creation time.

2026-09-13 — Git decisions and GitHub connection in local clients (0.16.0)

Capable local clients can answer Git credential decisions in the current conversation, with the exact identity and chosen lifetime still owned by Kin. The service can also carry GitHub CLI’s browser device login and account readiness. Credentials stay with GitHub CLI. Connecting an account leaves a separate Git access review for the person; observers cannot answer it. Reconnecting preserves the original decision, and stopping or cancelling a connection joins its credential-owning process group.

2026-09-13 — Personal Depot custody (0.15.0)

An environment can install a native Depot companion and expose personal custody through Kin’s existing, explicitly scoped connection. The optional depot tool and kin depot commands cover private repository setup, worktree maintenance, reviewed Changes, ordinary Git export and access controls, without a separate key or MCP registration. Human review and custody choices remain explicit. Child agents cannot acquire this tool; planning and workspace write authority still apply.

2026-09-13 — Personal home clients (0.14.0)

Local clients can recover canonical conversation history, including an unfinished answer after reconnecting. The writer can change model, mode and effort through typed controls. A service-owned ChatGPT device connection survives closing its client and reports account model readiness separately from saved sign-in. Capable clients can present workspace artifacts and loopback applications in isolated interactive views.

2026-09-12 — Safer recovery and everyday editing (0.13.1)

Saved turns and prompt history remain readable around malformed records, including a journal write interrupted halfway through a Unicode character. Whitespace-tolerant file edits preserve requested leading and trailing line breaks, avoiding extra blank lines in LF and CRLF files.

Attachment cleanup skips symlinks and stays with the directory it opened if that path changes during the sweep. Quoted and shell-escaped file paths work in multiline pastes, including a single path followed by a newline.

/editor preserves the draft and reports failure when the editor cannot run or return readable UTF-8 text. Temporary files are cleaned up on those failure paths too.

2026-09-11 — A compact terminal welcome (0.13.0)

Kin’s welcome uses a compact Kinra emblem that stays visible through remote terminals, including Kinra Spaces and Herdr. The full-width frame places the name, version, model, and workspace beside a divided notices column. Notices wrap within that column; narrow panes keep the trust posture below the identity.

The session id remains available in hover and copy. A tip appears in the timeline each launch, and the welcome shows release highlights once after an update. KIN_MARK=0 hides the emblem; ASCII mode uses the plain text treatment.

2026-09-10 — More reliable mouse input (0.12.2)

Kin keeps mouse input in character cells inside Herdr, avoiding a coordinate mismatch that could send hovering and clicking toward the upper-left corner. Hover tooltips dismiss before clicks reach the controls beneath them, keeping the composer accessible when a popup overlaps it.

Regression tests cover the coordinate fallback and real terminal clicks. The original trigger reported through remote macOS Ghostty remains unconfirmed.

Repository development uses task setup and task run (or uv run kin). The obsolete scripts/setup-dev.sh bootstrap and unused .env.example have been removed. Kin reads exported environment variables and layered TOML settings; its first-run starter now links directly to the full settings reference.

2026-09-08 — More reliable workspace context (0.12.1)

After compaction or tool-output pruning, touching a directory can reload its current instructions. Guidance reads skip special files, remain bounded when files grow, and count complete Unicode reminders against their byte limit.

The environment block distinguishes the tool’s /bin/sh from the login shell, honors locale precedence, and reports unavailable Git status accurately. Git state handles non-UTF-8 filenames and both rename forms. File-read guidance now names its actual character budget and continuation offsets.

2026-09-08 — Activity previews, Spaces account handoff and cooler reading colours (0.12.0)

File edits show compact diffs outside the activity fold, and scripts show a bounded live terminal excerpt. Later activity starts below each pop-out. Git reads stay folded, and routine tool errors keep their marker without opening a dropdown. The spinner adds grey shimmering words for work the transcript does not already name, including compaction and retry waits.

Markdown headings now use cyan-blue, with a deeper shade for smaller headings; strong text and table headers use blue instead of cream. Lavender inline code and sage quotes and list markers remain. The composer shares the new heading colour on both Kin themes; the welcome and status colours are unchanged.

The private Spaces build can prepare your personal Kinra connection when you sign into Spaces. Existing accounts, provider choices and inherited model roles are preserved; interrupted setup can resume with the same enrollment. Signing out of Kin suspends automatic setup until you choose Reconnect Kinra. Browser sign-out leaves native work connected. The ordinary local installation keeps its native login flow.

Hosted web search and context retrieval now honor the configured HTTP(S) proxy, so they work alongside Kinra login in environments that require proxied access.

2026-09-07 — Polished dialogs and smoother long sessions (0.11.0)

Dialogs now share flat, padded buttons, clearer focus, and quiet keyboard hints. Configuration fields keep their names visible, scroll in short terminals, and distinguish staged changes from Save & apply. Both model and MCP managers confirm before discarding an edited draft; MCP environment and header fields are masked.

Model and activity panels gain clickable tabs and first-letter shortcuts. r revokes grants, t tests model connections, r rejects proposals, and a applies nudges; existing aliases remain available. Shift+Tab moves backward inside dialogs. Multiple-choice questions now submit on Enter, and moving the grant selection cancels a pending revoke confirmation.

Kin can ask you to approve one related directory for structured file writes throughout a conversation, including retained children. Revoke the scope in /grants; protected paths keep their own review.

Shell guidance now accurately names /bin/sh and explains explicit Bash invocation. After a child continues, agent_output returns its current run by default; all_runs=true retrieves earlier reports too. Saved journals gain small diagnostic runtime identity records for future troubleshooting.

2026-09-07 — A warmer reading palette (0.10.5)

Markdown now uses soft apricot headings, warm cream emphasis, lavender inline code, and sage quotes and list markers. The composer shares those colours, the workspace label wears muted sage, and the welcome wordmark keeps cyan. Both Kin themes keep their quiet dark surfaces, grey borders and activity, and familiar live and status cues.

2026-09-07 — Visible default effort for Kinra chat (0.10.4)

The managed Kinra connection now requests xhigh for its default Qwen3.8-27B model and displays the full effort word beside the model in the session line and in the /effort picker. Saved connection defaults remain active when you switch away and back. Profile refreshes preserve supported explicit effort choices, and the display follows the request actually sent.

Older managed profiles refresh on the next TUI launch without waiting for the usual twelve-hour cache expiry. Offline failures retain the previous settings. Explicit row pins, inherit clears and one-run effort overrides retain their precedence. Subscription Astra keeps its existing medium default.

2026-09-07 — A spinner-only status line and timeline clocks (0.10.3)

While a turn runs, the status line above the composer now shows only the spinner. The phase words, elapsed clock, and escape hint that used to sit beside it are gone; the terminal tab title still names the phase, F1 lists ++esc++, and the welcome tips now include it. In their place, every activity title in the timeline carries the time it has spent live, from two seconds onward: reading files… · 3 tool calls · 12s while it works and done · 3 tool calls · 45s once it settles. A group that resumes for a later round keeps adding to that sum; replayed history shows no duration.

The auto mode badge no longer appears, because auto is the default; strict still shows its dot. Your messages keep their rounded box and drop the YOU title. The session line below the composer gains two quiet hues: the model and effort word in a muted cyan, the workspace in cool steel.

2026-09-07 — Contextual activity, a calmer welcome, and useful help (0.10.2)

The welcome panel removes an extra interior rule and keeps long session details on tidy rows. Small terminals retain the workspace-trust posture, and hover reveals the full identity. ASCII frames follow the same responsive layout.

F1 help now puts everyday controls first and filters by key, command, or action, including available skills. The welcome drops its opening question and closes with one dim tip per launch; on the first start after an update that line lists what changed instead. The status line above the composer stays blank until a turn runs or a menu opens, and open menus show their actual Enter and Tab actions. The status line, menus, session line, todos, and background strip now align with the text inside the composer’s frame. Transcript search highlights matching words, displays a bounded result count, and gives a useful next step when nothing matches.

The consolidated activity line now shimmers in grey and follows the work happening now: reading files, running commands, searching the web, preparing a tool, or waiting for agents. It settles to a quiet done · N tool calls, while failures, interruptions and incomplete results stay explicit. Reduced motion keeps the line still, and hidden details do no animation work.

Every model round inside a group shares one reasoning row. Its live caption can use a summary’s bold opening headline; completion reads reasoned with the accumulated duration. A missing round-ending event no longer loses that time, and late content cannot rename the next round. Blank model prefaces no longer split activity or spend the KIN label on an empty block, while real Markdown retains its leading indentation even when it arrives in a separate stream chunk. Release preparation also commits newly stamped welcome highlights with the version files, avoiding an interrupted release.

2026-09-06 — Quiet activity titles and flat single rows (0.10.1)

Activity group titles now count what they hold, such as reasoning · 3 tool calls · 1 failed, and never repeat a command or path onto the timeline. A lone reasoning trace or tool call is its own row rather than a wrapper around a wrapper; the group title appears with the second entry and folds unless you had already opened the first row. Tool captions return to one short row with a fixed budget, ending in an ellipsis on wide terminals too, while the full invocation waits in the expanded body and streaming progress stays a bounded excerpt beneath it. Browse, search, and copy follow the same rows.

One model round’s reasoning is one row: when Kin narrates between thoughts, the trace keeps growing in place instead of reappearing below the prose. The busy line reads Working… or reasoning… again, and whatever follows the word, such as the elapsed clock and the escape hint, is one dim parenthesised aside.

2026-09-06 — Quiet activity and effective Astra effort (0.10.0)

Routine tools and delivered reasoning now fold into shallow activity groups. Successful edits stay quiet too, retaining their change badges and full bounded diff on expansion; failures reveal once. Browse, complete-copy and hidden-content search reach the retained detail. Reasoning is neutral grey without a sweep, and interleaved prose/reasoning stays in arrival order.

The transcript, composer and input menus lose extra horizontal outer insets. Todos move immediately below the session line, before background agents, with a fitting active headline and wrapping bounded detail. Tool captions use the available width, keeping commands or paths above live progress.

Effort uses full words without a prefix. Exact gpt-6-astra on the ChatGPT subscription connection immediately sends and displays medium when unpinned. Applied explicit effort and service-policy inherit take priority; the implicit default is not saved as your choice and does not apply to aliases or other providers. Discovery can withdraw unsupported medium, and attachment reads the current model/effort without restarting the conversation. Bare subscription resume retains its ChatGPT transport identity. Existing journal behavior still ignores empty effort resets; an older saved choice may be retried on resume.

2026-09-06 — Verification-first benchmark coverage (0.9.2)

Maintainer checks now distinguish small repairs verified through their owning checks from work that accumulates unverified changes, even when the final files match. The synthetic recovery fixture also checks preservation of existing work and a handoff that leaves native acceptance open. This does not establish real Docker/native recovery or improvement across long sessions.

Benchmark summaries no longer report dry_run=false as a failed check. They retain declared failure reasons, show timeouts, identify first-attempt metrics in repeated runs, and report total measured attempt time. Cache comparisons correctly name steady-state share rather than overall mean share. Production prompts and user-facing tools are unchanged.

2026-09-06 — Complete evidence for delegated reviews (0.9.1)

Kin’s review guidance now calls for the comparison base, candidate scope, and complete diff when handing a change to a read-only reviewer. The patch may be inline or in a readable workspace file; missing comparison material remains an explicit review limit. Reviewers retain their existing tool permissions.

The task guidance and manual also clarify that an isolated child conversation shares the parent’s working directory and files. Keep edits serial in that checkout; concurrent writers need separate checkouts.

2026-09-05 — Conversational skills and focused terminal context (0.9.0)

Scripted workflows are retired. /critique, /security-review, /revise, /research, and /deep-research now run as ordinary instruction skills, with results available to follow-up and resume, optional supervised delegation, and headless invocation. cite_check remains the citation-liveness tool.

The workflow tool, /workflow, /workflow-save, /workflows, and the workflow-first nudge are removed. Saved kind: workflow bundles report a migration diagnostic; rewrite their Python bodies as instructions before using kind: prompt. Old route settings are inert and do not grant task placement. Existing files and journals are retained. See Workflow migration for the transition.

Session identity, explicit effort, clock, and context usage now sit below the composer, leaving the top edge for a compact Git branch and changed-entry summary. Bounded todos, menus, and background-agent previews keep input and fitting context counts visible in short panes without collapsing your todo list.

Targeted file edits now preserve untouched line endings and an initial UTF-8 BOM. Invalid UTF-8 is refused without changing the file. Previously, an edit could silently convert CRLF endings throughout the file or replace unrelated invalid bytes while reporting success.

Streaming tool rows keep their command or path visible above an indented progress line, making it easier to see which action is still running.

2026-09-05 — ChatGPT model favorites survive provider switches (0.8.3)

ChatGPT sign-in could succeed while subscription favorites later showed unavailable after switching providers or restarting Kin. The login was saved, but those favorites had lost their connection identity. /model now lists signed-in subscription models even while another provider is active and saves their favorites with the ChatGPT connection. Model-list failures also show their reason without removing saved sign-in.

For a favorite saved by an older version, remove the unavailable entry with f, then favorite its model under ChatGPT subscription. Signing in again is unnecessary when /login chatgpt status already reports a saved login.

2026-09-05 — Astra workflow guidance and harness reliability (0.8.2)

Selecting gpt-6-astra now applies model-specific guidance for following authorized work through, choosing useful planning and delegation, and reporting verification clearly. Routine multi-file work no longer triggers planning or delegation solely from its file count. The guidance follows model switches, resumed sessions and each child’s own model. Permissions and planning approval retain their existing behavior.

Model streams now allow ten minutes without an event before reporting a stall, and inactive children become advisory stale after ten minutes. Workflow scripts have a one-hour run allowance, giving longer reasoning and multi-stage work more room. The separate three-second frozen-script watchdog remains.

Failed and cancelled model attempts now contribute their reported usage to the run totals and token budget exactly once. A failed request cannot spend the remaining budget and then silently retry as though it cost nothing.

Short-line shell output now batches available lines before capture and live-tail updates, then coalesces redundant tails before they occupy the terminal UI queue. This reduces processing during large command output. Final tool results, captured output and journals retain their existing behavior.

2026-09-04 — More reliable harness boundaries (0.8.1)

ChatGPT effort controls now load the selected model’s usable levels before the picker opens. Switching models and resuming a saved higher effort no longer leave Astra stuck on three fallback choices; temporary discovery failures keep the saved choice intact. Astra offers low, medium, high, xhigh, and max; the catalog-only ultra delegation mode is excluded because the request endpoint rejects it.

Interrupting a tool batch preserves completed results and distinguishes calls that never started from calls whose effects need checking. Partial assistant prose remains marked as interrupted, and closing a session waits for owned workers and processes. Incomplete model turns cannot execute tool calls or replace conversation history with a truncated summary.

Delegated tools stay within the parent’s available tools, and agent profiles stay isolated by workspace. Large newline-free shell and Python output no longer breaks the pipe reader; foreground shell capture stays bounded and reports when a spill retains only a tail. Structured workflow replies now share token budgets, context checks, and route capacity, including fallback attempts and their reported usage.

2026-09-04 — Personal ChatGPT connections and terminal refinements (0.8.0)

You can now use your own ChatGPT subscription directly in Kin. Run /login chatgpt or kin login chatgpt, sign in with OpenAI, and Kin discovers your available models and selects one for the main conversation. The connection also appears in /models, with browser and device sign-in. Device authentication supports SSH hosts without a callback tunnel.

Kin keeps its own private sign-in and runs its native tools and conversation loop directly against OpenAI. Your subscription limits apply. /logout chatgpt removes Kin’s local sign-in; other applications keep theirs. See Your ChatGPT subscription for setup and the endpoint’s model-setting limits.

The terminal layout now makes better use of both wide windows and small split panes. User messages wrap at the available width instead of an 80-column cap, and the welcome card fits narrow terminals. Long drafts leave room for the conversation. Model, MCP, and web-search panels stack in narrow panes; dialogs scroll to keep fields and actions reachable. Chrome reserves space for context usage and permission mode while shortening secondary information.

Busy status keeps elapsed time and the Escape hint visible for long activity labels, and reduced-motion mode keeps its elapsed clock running. Colour pulses now pass smoothly through their peak. Long approval scopes stack their choices so every action remains reachable; narrow help reads in one column, and short search views retain room for results and their close hint. Inspection lists use the existing outer frame without a second inner border.

2026-09-04 — Long tool output no longer stalls the screen (0.7.1)

A shell command that printed thousands of lines could make Kin look hung: the status clock froze, input waited, and the call’s reported duration grew far beyond what the command actually took. Kin was rebuilding the row’s hidden live-output detail once per line on the same loop that drives the interface.

Live output is now a transient preview. When lines arrive faster than the screen can paint them, only the newest tail for that call is drawn; a closed row records new detail without redrawing it until you open it, and the detail body keeps a bounded preview with an honest count of what it left out. The complete tool result, its retention cap, spill file, and session journal are unchanged, and parallel calls and subagent starts keep their own ordering.

2026-09-04 — Versions describe the change (0.7.0)

Kin’s release number now distinguishes corrections from capability changes. While Kin remains below 1.0, a patch release is a compatible fix, hardening, or refinement; a minor release adds an externally usable capability or marks an intentional compatibility change. The AI peer performing the release reads the complete change since the previous tag and selects the highest applicable class without asking the operator to translate the work into a version.

The ordinary release path cannot produce or publish 1.0. That boundary needs a separate authored decision defining the stable compatibility commitment and a source change that deliberately opens it. This release establishes 0.7.0 as the prospective baseline; historical tags remain unchanged. Kin’s runtime, commands, and user configuration are otherwise unchanged.

2026-09-04 — Readable help map (0.6.31)

The /help overlay (also F1) no longer squeezes its descriptions into a thin strip on the right. One long command key was sizing the whole key column, so every description in the commands section wrapped a few words per line on an ordinary terminal. The key column now has a fixed cap; a command whose argument shape would exceed it shows that shape on a second line beneath its name, and the descriptions get the rest of the card.

2026-09-03 — Composer shows markdown structure (0.6.30)

The composer now highlights markdown as you type: headings in bold, list and quote markers and code fences in grey, and a reference link’s destination in kin’s link accent. What you send is unchanged. Clickable surfaces — the click-to-copy code fence, a running workflow card, and the completion menus — show a hand pointer on terminals that support it, and Textual’s Rust geometry accelerator is installed with Kin.

The interface also had a uniformity pass. Every overlay now shares one of two chrome templates, so the agent panel, workflow, search, and viewer overlays line up exactly; the route picker inside model configuration is styled and closes on Esc. Titles, key hints, buttons, and empty states follow one grammar, a live child agent reads running everywhere, a failed or interrupted workflow uses the same word in the transcript and the overlay, and the accent cyan retreats to where Kin is speaking or working: help columns, group headers, panel titles, and rails are grey again, and the welcome frame sits on the same structural grey as every other frame.

2026-09-03 — Honest context headroom (0.6.29)

The top bar now shows only the current prompt against its hard admission limit, for example 100k / 195k. It stays blank until both numbers are trustworthy, keeps routine auto-compaction muted, and warns only near the hard limit. Hover and /tokens expose the full model window, output reserve, and distinct auto-compact point. Each successful compaction also leaves a short receipt with its measurable before/after prompt size and retained recent-turn count.

2026-09-02 — Hosted search is unmistakable in /web-search (0.6.28)

The /web-search panel now puts the active route in a colored card in its left column and explicitly names the Gateway’s hosted Brave + Exa providers. The local-key field also says Connected · key optional while hosted search is active, so it no longer looks like a required credential form. Brave remains the only local direct-egress override; Exa is already available through the provider-neutral Gateway route, including Exa-first semantic retrieval.

2026-09-02 — Clearer web-search setup (0.6.27)

The TUI now has one /web-search action in place of /brave-key and /search-key. Its panel leads with a green Connected to Kinra Gateway line when authenticated hosted retrieval is ready, before offering a local Brave key as the optional direct override. The shorter route, provider, and key-status copy keeps the active connection visible without asking the user to read through setup instructions first. The model-facing web_search and web_context tool names and their Gateway routing are unchanged.

2026-09-02 — Web route status on the login surfaces (0.6.26)

Every human surface that describes web search now shares one reading of the active route: hosted through your Kinra login, an explicit local Brave override, or off. /login status and kin login status report it offline beside the saved identity, with the two ways out when it is off. The login note says when a device key brought no hosted web access instead of staying silent, the logout note says when hosted retrieval was withdrawn from the running session, and a background profile refresh that adds or removes the tools posts one note. The /brave-key picker reports the same route, so its status line says when hosted retrieval already covers search and the key is optional, and marks a set key as the override of that hosted route; it no longer presents the local key as the way to enable web search. See Web tools.

2026-09-01 — Hosted search and a sharper direct fetch (0.6.25)

Kin can now discover web_search and web_context from an authenticated kinra-api service profile, so hosted Brave/Exa retrieval can arrive through ordinary /login without copying either vendor key onto each device. The provider-neutral auto, semantic, and diverse strategies keep provider selection at the Gateway while results retain visible provider provenance. An explicit local Brave key remains the direct-egress override and takes precedence. Existing inference-only device credentials are never silently broadened; they need a deliberate new login or replacement once the service advertises hosted-web access.

web_fetch remains local and independent rather than becoming a duplicate vendor fetch route. It now reports direct-retrieval provenance and accepts an optional local lexical focus: the inline answer contains the most relevant source passages in source order, while the complete extracted capture is offered to the ordinary bounded spill store when persistence is available. The result says when no ref was written or the store cap retained only part of the capture. Its DNS-pinned SSRF boundary, per-hop validation, no-cookie/no-auth shape, and exact-URL job remain intact. See Web tools.

Managed login also explains the fixed-port SSH tunnel when Kin cannot launch a browser itself, so a loopback callback on a remote Linux host can be completed from the operator’s workstation without falling back to a shared API key.

2026-08-31 — Root exact search can choose its shape (0.6.23)

Kin keeps the built-in grep tool, its stable name, read permission kind, workspace confinement, bounds, arguments, and output shape. For one exact search it remains the predictable structured route, including in read-only profiles. Root sessions may now use shell search when batching or command composition is the better fit; those calls follow ordinary shell policy and host command availability rather than inheriting grep’s dedicated contract.

2026-08-31 — Open another workspace from a local conversation (0.6.22)

A capable local client can now declare open_workspace, giving only the current root writer one conditional tool. When the person’s current words name work in another repository or directory, Kin can propose one existing absolute directory through the same exact correlated handoff family as open_url. The environment confirms with the person, may refuse, and opens its own new conversation under that workspace’s ordinary trust flow; the calling conversation, workspace, journal, permissions, and writer do not move. Relative paths, files, missing directories, the current room, capability-less clients, every child session, and a caller still in the read-only planning freeze stay closed. See Local clients and decision 0239.

2026-08-30 — Scheduled work finds the person (0.6.21)

kin -p --attach hosts a headless run’s conversation in the per-user session service (Phase 4 of the session-service roadmap, decision 0238). A completed run behaves exactly as before, but a human-gated question or approval no longer dead-ends into a structured tool error: the turn stays parked on the exact pending block inside the service while the headless process releases its writer role, detaches, and exits 2 naming the conversation. Attach the terminal (kin --attach --resume <id>) or claim the conversation from an OS client — the pending block replays with its original id and display signature, the person’s answer resolves it, and the original turn continues, through repeated gates if the model asks again. --idle SECONDS declares how long the service keeps the unattended conversation alive; the journal survives every ending.

Local clients can also discover what is waiting: a hello with conversations: true returns one bounded, content-free listing of the service’s live conversations and their pending block ids and kinds, then the connection ends — pull-only, no subscription or push channel. The --output sidecar gains additive service and turn_sent fields plus a per-item block id, and a waiting service-hosted run reports done_reason: "waiting". The serviceless kin -p envelope, exit codes, trust rules, and one-writer contract are unchanged; an absent service is a stated failure, never a silent fallback. See Headless runs and Local clients.

2026-08-30 — Separate Kin’s Python runtime roles (0.6.20)

Kin’s repository tooling now requests exact CPython 3.14.7 while the installable wheel continues to support Python 3.11 and newer. The periodic compatibility proof requires final GIL-enabled CPython and also retains Python 3.13 as the mandatory Kinra OS parity line; the packaged-artifact gate verifies universal py3-none-any wheels with Requires-Python: >=3.11. Python 3.14 compatibility repairs use APIs already available at the 3.11 floor, and a template-string regression keeps workflow reflection policy closed on the preferred runtime. There is no model, protocol, permission, or session behavior change.

Linux and Apple Silicon macOS remain the qualified platforms. Intel macOS is a best-effort, unqualified source-build path because the locked native dependency stack no longer has upstream x86-64 macOS wheels; it is not a release gate. See Install and decision 0237.

2026-08-30 — Preserve systemd-owned Kin sockets across service restarts (0.6.19)

kin --serve now keeps socket-path ownership aligned with the process that created it. On Python 3.13, closing the asyncio server no longer removes a systemd-activated pathname, so a clean service stop or restart leaves the name available and a replacement Kin accepts new clients through it. A path Kin creates without socket activation is still mode 0600 and is removed on exit. A real Python 3.13 activation regression stops the service, starts its replacement on the same listener, and reconnects through the surviving path. Peer credentials, the local-only Unix socket, the no-port boundary, and the conversation protocol are unchanged. This is the v0.6.19 hotfix.

2026-08-30 — The terminal attaches to the session service (0.6.18)

kin --attach runs the ordinary terminal as one more client of kin --serve. With --resume ID or --continue it joins the named or newest conversation as its writer — or, with --observe, as an observer — and with nothing it opens a fresh conversation that lives in the service. The existing transcript is painted from the journal, then the same live events, questions, approvals, tools, and subagents the in-process terminal renders. /role shows who writes, /role release hands the role on, and /role claim takes it once released — the service’s own explicit transfer, never a takeover — and a pending question or approval survives the transfer and answers only for the new writer with its original id and signature. Quitting the window detaches and leaves the conversation in the service (the shell shows how to come back); only the writer’s /close ends it. Commands that act on the session in-process refuse with the route to run them there. A future Kinra OS candidate can make “Open in Kin” one conversation: the Front Door releases, the terminal attaches, and the Front Door observes until it claims the role back. See The terminal attaches and decision 0236.

2026-08-29 — Kin as a per-user session service (0.6.17)

kin --serve makes Kin something the machine runs rather than something a window starts. One Kin per user listens on $XDG_RUNTIME_DIR/kin.sock — mode 0600, peer credentials checked against its own uid, systemd socket activation honored, never a port — and hosts conversations for local clients over the same JSON lines kin --stdio speaks. A client’s hello gains one conversation object naming the workspace, an optional conversation id or continue, its role, and an idle policy. Each conversation has exactly one writer, which holds the lease, sends turns, and answers questions, and any number of observers, which receive the same events and may only close or claim the writer role after an explicit release. A writer that disconnects without closing leaves its conversation open — a running turn keeps running and a pending question is replayed to the next writer — until the writer closes it, it idles past the declared policy, or the service stops, each reported to the other clients with a stated reason. Trust, tools, journal, and permissions are exactly the interactive session’s; kin --stdio is unchanged as the spawned form. This is Phase 1 of decision 0235; Kinra OS connects to it in its own next generation. See Local clients and the CLI reference.

2026-08-29 — Typed model-round phases for local clients (0.6.16)

Every root turn now carries one canonical thinking.phase lifecycle across the Textual and local stdio clients. requesting marks a model round before its first delta, reasoning arrives before the first private reasoning delta, answering arrives before visible answer text, and tools precedes tool calls; compaction, approved plans, and saved workflows keep their existing status words under named phases. The stdio host still drops reasoning content, but no longer drops the fact that reasoning is happening. One guarded inactive event closes every normal, error, cancellation, loop, and budget edge before the terminal event, while child phases remain behind their correlated agent entries and cannot overwrite the root. No event was renamed and stdio protocol 1 is unchanged. See Event vocabulary and Local clients.

2026-08-29 — Correlated subagent lifecycle for local clients (0.6.15)

Every registered foreground or background physical run now emits one subagent_started / subagent_completed pair. Agent id, current parent tool-call id, run sequence, profile, execution mode, and launch kind repeat through progress and completion, so a terminal or local stdio client can fold concurrent child work into one truthful delegation entry without parsing tool prose. Retained agent_message continuations increment the run sequence and belong to the current call; interactive kills and foreground turn cancellation settle the same lifecycle rather than leaving a visible entry running. The existing background-dispatch and foreground-spawn hints remain for compatibility, with no change to the protocol, capability negotiation, journal, or authority. See Event vocabulary and Local clients.

2026-08-28 — Continuity skills for a stdio workspace (0.6.14)

Kin’s installed library gains remember and recall. remember offers, inside its ordinary answer, to record one durable fact — a correction, a stated preference, constraint, or decision, or a hard-won finding — and writes it only after you say yes, as an ordinary approved file write into the document that owns it or, where no owning document exists, into context/<area>/<slug>.md with a context/INDEX.md line. recall reads that index only when a request calls for it, verifies a note against current source before acting on it, and proposes deleting, rewriting, or promoting notes that are wrong, superseded, or belong elsewhere. A local client’s workspace may also carry its own .kin/skills/ library beside its AGENTS.md; Kin composes it only after the trust answer. Nothing in the harness triggers a note: no memory tool, store, timer, end-of-session pass, or reminder. See Local clients and Skills.

2026-08-28 — Workspace trust carried by a local client (0.6.13)

A local stdio client can now declare workspace_trust. When a fresh launch’s workspace is not yet trusted, Kin sends its own trust question — the resolved path, whether it was replaced, and whether persistent trust is available — as one trust_request before reading any workspace material, and the client returns the person’s answer in the terminal prompt’s own words: persistent, session, or decline. Kin records the grant exactly as the terminal would; the client never creates, infers, or remembers trust. A resume still cannot ask, and a client without the capability still receives the untrusted fatal. See Local clients.

2026-08-28 — Attention context only when requested (0.6.12)

Local stdio clients can now declare an attention_context capability. It gives the root conversation one get_attention_context tool that asks the local environment for an exact subset of the current window, workspace, output, or selection. Kin uses that door only when the person’s request explicitly calls for current context; ordinary turns remain just the person’s words. The client cannot widen the requested kinds, and every returned value is bounded and untrusted-framed. Terminal, headless, and child sessions never receive the tool.

The original push-side turn.context field remains protocol-1 compatibility, but current clients should leave it empty by default. This change does not add memory or a parallel context store: visible workspace files and Kin’s existing file tools remain the continuity mechanism. See Local clients.

2026-08-28 — Messages compatibility, MCP v2, and exact Responses replay (0.6.11)

Kin’s provider = "anthropic" setting is now documented and qualified for what it actually selects: a Messages-compatible wire for Z.ai, MiniMax, official Anthropic, and local servers that expose /v1/messages. The client SDK moves to its 1.x line on the existing full/replay and Z.ai live evidence; an official Anthropic account is optional, and Kin does not turn third-party evidence into claims about vendor-specific behavior it did not exercise.

MCP moves to the v2 client and automatically negotiates current 2026-07-28 servers or handshake-era servers on stdio and Streamable HTTP. Current list subscriptions refetch and re-vet every change, recover by re-listening and snapshotting, and never serve the trust-bearing catalog from the SDK cache. Legacy notifications and elicitation remain supported, while the OAuth callback now preserves the authorization-response issuer for validation.

Stateless OpenAI Responses replay now explicitly preserves assistant commentary and final_answer phase labels across turns and journal resume. Kin’s compatibility claim remains the deliberate Open Responses-aligned HTTP/SSE subset—streaming, functions, structured output, images, and local item replay—not remote conversation state, server compaction, WebSocket continuation, hosted tools, or full upstream conformance.

2026-08-27 — Local clients over stdio (0.6.10)

kin --stdio hosts the ordinary interactive session for one local program that owns Kin’s standard input and output: the same journal, workspace trust, conversation lease, tools, modes, and questions as the terminal, projected as typed JSON lines. It is the boundary an OS-native surface such as the Kinra OS Front Door uses to carry a live Kin conversation — not headless mode, which still runs one unattended turn, and not a network service. The client speaks first with hello, sends one turn at a time, cancels, and answers questions exactly; a wrong, duplicate, or late answer is refused rather than guessed at, and closing the pipe releases the conversation for the terminal’s --resume. A client that declares the open_url capability gives Kin one extra tool, which asks the environment to open one exact web page and takes the environment’s answer as a fact. See Local clients.

2026-08-27 — Remove dead-end layout actions (0.6.9)

The Ctrl+P palette no longer offers Textual’s contextual Maximize and Minimize rows. Maximize targeted the focused widget — in Kin, the composer — and the maximized view hid the transcript, the status bar, and the slash, mention, and history menus: a fullscreen text input whose menus kept running invisibly. The composer is now non-maximizable from any route, and the palette offers only Quit beside Kin’s own rows.

2026-08-27 — Manageable trust and focused command discovery (0.6.8)

Ctrl+P now fuzzy-searches Kin’s built-in commands and user-invocable skills. Choosing a Kin result stages an undoable slash gesture in the composer instead of running it immediately, so arguments and the replaced draft remain under human control. Textual’s stock Theme, Keys, and Screenshot palette rows are gone: /theme and F1 already own those, and the stock theme picker silently forgot its choice on restart. Textual’s contextual Maximize and Minimize layout actions remain.

Every persistent workspace-trust record is now visible and revocable through /grants, including stale paths and malformed hand-edited rows. The launch note names the affected records without rendering malformed row fields, so its recommended cleanup path can always reach the state it reports.

Non-cooperative workflow scripts now stop reliably across supported Python versions. Their frozen-loop timeout cannot be swallowed through a computed base-exception handler, and cancellation joins the watchdog before the event loop closes.

2026-08-26 — Truthful startup model identity (0.6.5)

Kin’s welcome banner and top bar now keep an explicitly selected model when a provider’s /v1/models endpoint lists several available models. A catalogue’s first row is no longer mistaken for the model serving the session, so a Z.ai session configured for glm-5.3-flash does not briefly present glm-4.5 at startup. The default alias and single-model compatible servers retain their existing resolved-model discovery behavior.

2026-08-26 — GLM-5.3 defaults and trustworthy live evaluation (0.6.4)

The curated Z.ai preset now defaults to multimodal glm-5.3-flash, adds the text-only glm-5.3, and pins both plain wire-level IDs to their documented 1M-token context windows. The /effort picker follows the GLM-5.3 family’s max / high / low Messages contract, and opt-in cost display uses durable list rates rather than Flash’s temporary launch discount.

Maintainer live-drive and live-bench runs now share one terminal-error classifier, so root and delegated-child backend failures cannot masquerade as model-routing results. Live-soak identity also includes non-ignored untracked source, and late model-discovery presentation is safely ignored after Textual has detached its chrome during shutdown.

2026-08-25 — Retired Peer surface and honest live-bench errors (0.6.3)

Kin no longer ships the undeployed Kinra OS Peer protocol and socket-free service packages. No product consumed that proposed integration, and Kinra OS has retired; the complete contract and its tests remain available in Git history if a future consumer earns a new compatibility and authority decision. The ordinary Kin CLI, TUI, sessions, credentials, and authority model are unchanged.

Maintainer live benchmarks now promote a root or delegated-child production turn’s terminal backend error to runner ERROR before any grader interprets missing tool calls as a model choice. The report keeps a fixed privacy-safe diagnostic while provider detail remains in local, gitignored forensics.

2026-08-24 — More trustworthy live qualification (0.6.2)

Kin’s maintainer live checks now distinguish product failures, unexercised control conditions, and runner errors instead of collapsing them into one pass/fail signal. Shared monotonic deadlines prevent a series of individually bounded waits from silently exceeding a scenario’s wall-clock allowance, and the resulting reports retain only fixed-vocabulary diagnostics rather than prompts or model output.

A new bounded task live-soak campaign composes the existing live-drive and performance-shape lanes in fresh serial processes. It covers every applicable lane before repeating any, checkpoints atomically, stops if its source revision changes, and has independent eight-hour and 141-attempt limits. The patch changes maintainer evaluation evidence; it does not change Kin’s user-facing runtime or authority model.

2026-08-23 — v0.6 upgrade compatibility (0.6.1)

Upgrading from v0.5 no longer prevents Kin from starting when a managed Kinra configuration still contains the retired Review model assignment. Kin accepts that predecessor key only as inert migration input: it cannot select a model or grant authority, while genuinely unknown assignment names remain configuration errors.

2026-08-23 — Trusted workspaces and Outpost’s retirement (0.6.0)

Kin now asks once at launch whether to trust the exact workspace, before it reads project-owned instructions or configuration and before it contacts a model. Persistent trust binds path plus filesystem identity; session-only trust is available interactively, while headless and resumed runs fail closed with exit 2 unless a valid persistent row already exists.

After trust, Auto shell and Python run directly with the launching user’s real local authority. Strict keeps its ask-first posture, and protected file tools, MCP trust, structured Git/GitHub checks, planning freeze, and guarded deploy commands remain explicit safety rails. The local Seatbelt/bubblewrap wrapper, typed expansion, independent classifier, modal, and workload gates are gone; old settings and journal items remain only as inert/readable migration input and never become workspace trust.

kin gateway-usage gives trusted local integrations one narrow way to read the current device credential’s own hosted generation activity. Kin keeps the saved bearer inside its process, calls only the fixed Kinra Gateway endpoint, validates and reprojects the closed response, and prints identity-free aggregate JSON.

The response covers seven UTC days ending with the current, partial day. Its request and token counters include only generation calls made through that device credential; direct-provider and local work, other credentials, older history, billing, quota, and productivity judgments remain outside the command’s scope.

Outpost is retired end to end. Kin no longer ships the durable-agent appliance, its protocol, remote Git handoff, schedule and dispatch tools, attention surfaces, or operated deployment path. The independent outpost-get container that serves get.kinra.ai is unchanged; its name is a historical collision, not an agent runtime.

For recurring or unattended work, use cron, systemd, launchd, CI, or another host scheduler to invoke a fresh local kin -p process in the intended workspace. The environment owns timing, availability, retries, and whole-process isolation; Kin keeps its existing exit-code and report contract. Existing local ~/.kin/outpost/ state is inert and may be removed when it is no longer needed as historical recovery material.

Paddock is no longer a public Kinra product or download channel. Kin’s Get front door is Kin-only, while custom providers continue to support explicitly qualified OpenAI-compatible Responses endpoints, including compatible local llama.cpp servers.

2026-08-23 — Minimal identity and retired edges (0.5.17)

Kin’s frame is now monochrome: the composer, speech boxes, overlays, toasts, top bar, menus, headings, and a healthy context meter all render in one structural border tone, and the accent survives only where Kin is speaking or working. The manual’s screenshots follow this re-make.

Two edges are retired rather than deferred. Dynamics 365 Business Central is no longer a named MCP target: the oauth block for providers without dynamic client registration is unchanged and documented generically, but the Business Central worked example and its planned sign-in proof are withdrawn. Native Windows is not a supported or planned platform; WSL2 remains the Windows path, and the installer and get.kinra.ai now say so without a “yet”.

2026-08-23 — One-process runtime, unified skills, and hosted Kinra (0.5.10–0.5.16)

Kin can now open the interactive TUI with a first turn already supplied: kin [options] -- "prompt". The prompt waits for the session handshake and any saved-transcript replay, then follows the same visible turn, approval, retry, interrupt, and journal lifecycle as composer input. It is literal turn data—a leading ! or / does not invoke a composer-only action—and a non-TTY caller is directed to the existing kin -p headless contract.

Kin now runs as one ordinary foreground process. For persistent interactive work, use Herdr as the outer terminal runtime: it keeps the PTY alive across detach/reattach and receives Kin’s working, needs-input, idle, conversation, and title metadata through a best-effort reporter. Plain terminal use remains fully supported; after any process exit, resume from the append-only journal with kin --resume <id>.

Every persistent root or resumable child conversation now holds a process-lifetime lease. A second --resume, /resume, or headless continuation refuses clearly while the original Kin is live; /fork creates a new id and lease. The hidden tmux runtime, /detach, /sessions, --bg, its settings, and ++ctrl+l++ switcher are removed. kin ls now lists saved conversations in the current workspace plus Outpost work. For one release, kin doctor reports legacy Kin tmux sessions and prints a manual rescue path.

AI-assisted configuration now has one narrow proposal boundary per surface. /config starts visible root conversations backed by read_settings / propose_settings, the live skill-creator procedure and propose_skill, or the /init procedure and propose_agents_md. Agent profiles and MCP keep the quiet isolated editor. The old /new-skill, /edit-skill, /edit-settings, and /edit-agents built-ins are removed immediately, freeing those names for custom skills.

Skill proposals are source-aware and default to project overrides; persistent user-wide edits are explicit and prominently warned. One fresh approval covers the complete validated text bundle, with stale-state checks, locked atomic publication, rollback/restart recovery, and no temporary fall-through to a shadowed source. Root guidance gets the same fresh-diff and stale-state protection. Applied guidance changes take effect on the next root turn or resume, while children spawned afterward receive fresh configuration.

Skills are now one bundle with two optional doors. A model can load a <name>/SKILL.md bundle through the skill tool, and a human can invoke the same instructions as /name arguments; typed frontmatter can make either door private. The former .kin/commands/ tree is gone, built-in slash names are reserved, saved workflows live under .kin/skills/, and the complete /skills view now explains invalid and shadowed entries.

Every accepted skill use is now explicit in the chat timeline. Human slash gestures keep their visible /name arguments message and gain a settled skill invocation /name · by you row; model calls use the same vocabulary, including inside folded subagents and workflow cards. Failed lookups and tool errors remain visibly failed instead of receiving a success marker.

The model catalog is live and truthful to each agent’s tools. It is the final system-prompt segment only when that session has skill, refreshes on content changes without a restart, keeps the last complete view through a scan race, and never drops a model-invocable name when its fixed budget requires shorter descriptions. Skill bundles may carry sibling guides, scripts, and attribution; loading any of them still grants no filesystem, network, credential, tool, or approval authority.

The installed skill baseline now adds test for focused, framework-native test authoring and docs for source-grounded repository documentation. Review skills may return a clean result when the evidence supports it, security-review reports preserve the attack path, and commit/PR drafts follow local conventions and branch evidence instead of assuming Conventional Commits or main.

The composer status line now uses one bold Working label for an ordinary model round instead of rotating speculative phase words. When Kin knows the specific activity, labels such as running read file…, drafting shell…, or a retry reason replace it; the transcript’s private reasoning section keeps its separate thinking… title.

Connecting to Kinra hosted inference is now one short command: kin connect kinra-api --base-url https://api.kinra.ai/v1 --refresh-profile. The wire shape, model, vision route, and role assignments come from the live service catalog instead of fourteen flags, and a connection made this way joins the same 12-hour background profile refresh /login uses — so a later service change (a new effort vocabulary, a different per-role output recommendation, a capacity change) lands without re-running anything. Your own pins always win, and the explicit long-form command keeps working.

Kin now also coordinates concurrency with the service. The gateway advertises its enforced per-credential admission cap; Kin sizes its parallel-subagent limit from it (leaving the root session a slot) unless you pinned one yourself. Retries at the hosted origin are now a single visible budget — the status bar shows “gateway busy (global) — retrying in 2s (2/5)” instead of silent SDK retries stacking on harness retries — and a run that exhausts that budget settles as its own capacity outcome: the work is intact, the agent parks, and agent_message resumes it once admission frees up. Headless kin -p runs exit non-zero on a capacity settlement, so automation cannot mistake a stalled run for a clean one.

2026-08-20 — One-command releases (0.5.9)

For maintainers, task release now owns the ordinary patch-release path end to end: final Kin verification, fast-forward promotion and tag, manual pin and Site verification, Site-before-channel deployment, apex binding, and the two generated Ops receipts. One invocation is the release approval; revisions, targets, checksums, and receipt paths are resolved by the repositories rather than transcribed through chat.

The command also stamps this authored Unreleased heading with the actual release date and version before it verifies and publishes the Site.

The separately operated Outpost appliance now has the same one-command shape without becoming part of a Kin release. task outpost:deploy resolves and builds the exact released appliance, stages and switches fresh state, verifies the private and public appointment, restores the predecessor on failure, and finalizes only its matching Ops receipt. Invoking that command is the separate fresh-state approval; maintainers no longer prebuild an image or copy a Git revision through chat.

The lower-level deploy check, dry-run, resume, and rollback commands remain available for diagnosis and recovery. Clean pushed source, atomic publication, public semantic probes, and predecessor restoration remain enforced behind the simpler interface.

2026-08-20 — Hosted Qwen headroom and clearer context feedback (0.5.8)

Kin now consumes the hosted model profile’s output recommendation when you have not pinned max_tokens. The Qwen3.8 primary profile recommends 32,768 tokens inside its 204,800-token context and keeps its checkpoint-native xhigh reasoning default, avoiding the generic 8K OpenAI fallback that could exhaust the response while the model was still thinking. Explicit file, environment, route, and resumed-session caps remain authoritative, and a smaller configured context window prevents an oversized automatic recommendation.

The Console header now shows one measured N% context left value instead of a dense token meter. /tokens retains the prompt, cache, limit, and compaction detail when you need to inspect it; before Kin has a trustworthy measurement, the header says context —. Successful manual, proactive, and emergency compaction now share the same concise Context compacted notice.

The Console’s --reasoning-effort inherit refresh now stores a provider-local service-managed sentinel, so a broad top-level effort setting cannot silently reappear. Hosted qualification also requires a semantically completed Responses terminal; an HTTP 200 carrying response.incomplete is still truncation.

For maintainers, task release:deploy now preflights the exact pushed Kin and Site candidates, deploys the manual before the channel, rechecks candidate and public state between effects, and resumes by skipping a leg already live at the exact approved revision.

2026-08-19 — Release-review hardening (0.5.7)

The shared token leash now grants its final tools-off wrap-up only to the root agent, so a fan-out cannot multiply the allowance after a child crosses the budget. Provider usage counters are normalized before they reach budgets, cost ledgers, or context reporting: malformed and negative values cannot reduce spend, and cached tokens cannot exceed the prompt total.

Workflow edit branches are retained even when an agent commits everything and leaves a clean checkout. Bounded tool output keeps Kin’s completeness and retrieval notices separate from untrusted captured text, structured Git and GitHub checks validate their complete captures, and spill storage refuses planted links. The Outpost switch also proves the tooling revision against live remote heads and removes a partially started candidate when staging fails.

2026-08-18 — Cache-aligned compaction (0.5.6)

Compaction’s own summarizer call used to be the context hazard it existed to manage: a flattened transcript under a different system prompt is a novel prompt on every wire, and on a shared local server its cold prefill also evicted concurrent sessions’ cached warmth. The summary now replays the head exactly as the next live turn would send it — the same system prompt, tool definitions, and messages, plus one trailing instruction — so the call rides the provider’s prefix cache. Measured on the production lane: a 128K-token session’s /compact summary round hit 96.5% prompt cache, and a concurrent lane kept 96% of its reuse through the compact. The turn after a compact re-seeds the reshaped context cold once — inherent to compaction on any prefix-caching server, and now paid on the smaller post-compact context.

Retention gains a ceiling beside the turn floor: the retained tail is bounded to compact_keep_fraction of the window (default 0.16, about 32K tokens at a 200K window; 0 disables), and when the two limits disagree the ceiling wins, down to a single kept turn. Auto-compaction re-verifies relief and may compact again — bounded — instead of assuming one pass was enough, and a summary that would be no smaller than the history it replaces is refused. The deterministic pruner also declines configurations whose rewrite could only lengthen a message.

Every compaction now records provenance in the journal — trigger, shadowed extent, model, and the summary call’s token usage — and /history renders one line per event, so “what did this cost, and on what?” has an answer in the log itself.

2026-08-18 — Reliable channel publication (0.5.5)

0.5.5 carries the Outpost v2 release from 0.5.4 and hardens its public release channel. Status-only checks no longer download or decode wheel bodies, text checks fail safely on malformed bytes, and an unexpected public-probe failure now enters the same guarded restore path as an ordinary verification mismatch. The release tests exercise a genuinely non-UTF-8 wheel and both reported and raised probe failures through exact predecessor recovery.

0.5.4 was tagged and its manual published, but it was superseded before channel or appliance promotion when this issue appeared during the first direct channel publish. The v0.5.3 channel backup was restored and verified before 0.5.5 was prepared; the v0.5.4 tag was not moved.

2026-08-18 — Outpost v2 and a complete appliance lifecycle (0.5.4)

Outpost now has a bounded v2 control protocol and one end-to-end release path. Large agent, schedule, and attention collections continue through opaque pages; transcript and output reads resume by byte offset; public snapshots name their exact protocol, schema, source, and release identity. This is a coordinated breaking change: current Kin uses /v2/outpost, while authenticated v1 requests receive 426 and must upgrade.

Scheduled work also cleans itself up without sacrificing exceptions. Quiet success closes after 24 hours. Failures, Needs You, other attention, and returned changes stay available until attention is resolved and then for seven days; every close keeps a final recoverable 24-hour tombstone before private artifacts are purged.

For operators, Kin now stages a fresh revision-scoped appliance, proves five real flows through the public Gateway—including Git return, steering, Needs You, a scheduled occurrence, and recovery across restart—and promotes only a complete result. The old appliance remains intact for exact rollback. Release completion now verifies the live channel, a public site identity, and the private current appliance against the same revision, with no deployment machinery or declarations hidden in Ops records.

2026-08-18 — The mycelium is the memory

Kin no longer keeps an invisible agent-memory store. The memory tool, recall index and injections, end-of-run reflection turn, /memory command, and memory settings are removed. Six weeks of daily use did not produce a session that recalled memory improved, while automatic capture competed with the visible, versioned workspace context that did work.

Cross-session continuity now lives in the workspace mycelium: AGENTS.md, maintained documentation, decisions, and other files both peers can inspect and correct. Existing ~/.kin/memory/ data is left untouched. Old session journals remain compatible; Kin still hides their historical reflection spans from replay, export, rewind counts, forks, and compaction summaries.

2026-08-17 — Truthful checklist progress and readable long-run clocks

Kin now treats the visible todos list as an evidence-backed lifecycle rather than a loose note. Multi-step work keeps one current item active, completes an item only after its proof succeeds, updates before the next step, and leaves the completed list visible. Lists with multiple in_progress items are rejected without replacing the current panel. Kin still never infers completion from generic tool success; one bounded reminder can instead ask the model to reconcile an unchanged active checklist, without claiming progress.

Every elapsed clock in the TUI now graduates at exact boundaries: 59s, 1m 00s, and 1h 00m 00s. The shared format covers the status bar, reasoning, foreground and background agents, Agent Panel rows, workflow cards, and the workflows panel while leaving relative ages, configured timeouts, headless reports, and machine duration fields unchanged.

2026-08-16 — Qwen3.8 reasoning and resilient Responses streams (0.4.2)

Kin now carries the Kinra-hosted Qwen3.8 reasoning vocabulary explicitly through the Responses path, with the bounded reasoning and application-role contracts preserved across hosted model selection. Clean-close, typed-terminal, and ragged or undecodable Responses streams now share a bounded retry posture when the provider ends without a usable terminal event.

2026-08-14 — Durable Outpost agent runtime (0.4.0)

Kin now has one durable-agent runtime for work that must continue while every Kin client is disconnected. The co-versioned Outpost appliance keeps agent identity, checkpoints, supervision, schedules, attention, and bounded output in a fresh WAL-backed state model. Kin remains the only human surface: local and Outpost agents appear together in the Agent Panel, and exact Git result refs are the way work comes back.

The release also replaces the predecessor dashboard-era service with a signed metadata-only control path, jailed workers, an inference broker, safe-boundary steering and pause/resume, exact Needs You continuation, and immutable image provenance. Existing predecessor state is retained for rollback rather than imported into the new runtime.

2026-08-14 — Release handoff and Outpost configuration hardening (0.4.1)

Kin’s release tooling now binds a tagged Kin revision to the site-authored manual and the Operations-owned deployment declaration before publication. The Outpost configuration helper is root-only, and the appliance’s source revision and release version remain explicit build metadata for inspection and rollback.

This was a release-tooling update with no additional product behavior.

2026-08-13 — Immutable Outpost image provenance (0.3.13)

Production Outpost deployments now build and run an image tagged with the exact 40-character Kin source revision. The image and container carry OCI revision/version labels, and the deploy gate verifies both against the running container before retiring the mutable kin/outpost:latest alias. The immediately superseded image remains available under a timestamped predecessor tag for explicit rollback.

2026-08-13 — Hosted application profiles and guarded release handoff (0.3.12)

Kinra-hosted connections now follow versioned default and vision service profiles instead of copying concrete runtime policy into every client. The credential-preserving kin connect --refresh-profile migration advances old primary and vision selectors, removes obsolete connection-local reasoning pins, and assigns the secondary route explicitly to Vision, Utility, and independent Review work. Each side-call carries its bounded application role; the gateway keeps image reasoning for Vision while Utility titles and sandbox classification use its non-thinking policy.

Detailed discovery metadata now tells Kin which typed Responses history shapes the exact count endpoint accepts. Unsupported images and encrypted reasoning stay intact for generation without a predictable failed count, while legacy boolean-only providers keep their existing probe behavior. Application-role headers remain generation-only and never leak onto the count route.

The release ritual now makes the separately owned kinra.ai documentation snapshot part of the deployment handoff. A production Outpost deploy refuses until tagged Kin origin/main, current Kinra Site origin/main, and the fresh Cloud Ops appointment form one exact deployed chain.

2026-08-13 — Governed Peer boundary and explicit operational truth (0.3.11)

Kin now owns a typed Kinra OS Peer v1 contract and a socket-free execution core for proving it. The boundary is proposal-only: Kinra OS retains every capability, dispatch, consequence, approval, journal, and human-authority decision, while exact receipts are the sole model continuation. Cancellation, bounded replay, one safe retry, hostile inputs, and terminal cleanup are executable conformance rather than implied behavior. This does not deploy a Peer host or turn the ordinary Kin harness into Kinra OS authority.

Root auto turns can assign sandbox permission review to a separate, context-isolated model. Only a clearly authorized low-risk exact call may be allowed once; sensitive, ambiguous, mutating, or failed reviews remain at the human gate. Kinra-hosted routes now use the operations-owned stable default text contract while retaining the concrete served model identity in results.

Public documentation rendering moved to the kinra.ai apex platform; Kin continues to own the documentation source and compatibility build.

2026-08-12 — Routine sandbox approvals can review themselves

Kin can now assign sandbox permission review to a separate small model. In a live root auto turn, that isolated reviewer sees the current user request and the exact immutable operation—not the whole conversation—and may approve only a clearly authorized low-risk call, exactly once. It cannot create session or workspace authority, cannot choose its own endpoint, and never falls back to the main working model. Strict mode, headless work, children, restored requests, sensitive paths, failures, and uncertain or risky work still go to the normal human modal.

The current Qwen3.5-9B route passed Kin’s 10-case live classifier gate: five read-only remote storage inspections were allowed, while deletion, identity changes, secret reads, deployment, and an injected command stayed human-owned. Configure it under the Sandbox permission review job in /models, or with kin connect --review-route <route-id>.

The SSH failure that motivated the work is fixed at its source as well. A kernel-proven private-key read denial can no longer produce the nonsensical suggestion to grant write access to ~/.ssh; Kin now requests the one capable, denial-bound exact retry instead.

2026-08-10 — Stable hosted model and visible DS4F reasoning

Kinra-hosted connections now select the stable public default model alias, so inference operations can advance the concrete primary model without asking every user to edit Kin. The actual served identity still comes back through live discovery and each Responses result. The gateway retains previously shipped concrete ids as exact compatibility aliases, so current installations receive the same no-edit transition rather than being stranded on the first model name.

kin connect also accepts --reasoning-effort. The hosted and direct DS4F recipes persist max, which makes Kin send the Responses reasoning-summary opt-in and fixes the silent thinking phase that previously looked like a missing trace (and could eventually resemble a stalled stream). The setting is connection-local, so compatibility endpoints do not receive it accidentally. The Kinra gateway applies the same default to primary requests only when a client omitted reasoning entirely, preserving every explicit client choice. Kin’s direct live gate now mirrors the selected DS4F deployment as well: one 262,144-token session with a 32,768-token output ceiling and max reasoning, instead of the displaced 128K/high contract.

2026-08-09 — Bounded reasoning for Qwen routes (0.3.10)

Named Qwen routes can now opt into explicit llama.cpp thinking budgets on both Chat and Responses without changing DS4 or unrelated providers. The Model Hub, kin connect, resume journals, and route fingerprints share the same closed qwen-llamacpp contract, including Utility title headroom and fail-closed output validation. The pinned Kinra gateway uses reasoning_budget_tokens; Kin sends no alternate field speculatively.

Route clones now keep their request metadata independent, and resumed conversations restore the persisted reasoning effort on the provider wire as well as in the interface.

2026-08-08 — DS4 and Qwen become the live fleet (0.3.9)

Kin’s executable live-model contract now matches production inference: the main route is DeepSeek V4 Flash over OpenAI Responses with its advertised 131K context, 32K output ceiling, and exact input counting; single-image vision and utility calls use the independently qualified Qwen route. The current gates exercise both routes directly, while historical vLLM, Laguna, and llama.cpp probes now require an intentional endpoint instead of silently falling back to the retired fleet.

Outpost carries that identity all the way through unattended work. Jobs and recipes snapshot the selected provider profile as well as endpoint and model, so a kin connect configuration keeps its Responses wire and credential route. Authenticated model-drift checks resolve the current credential without putting it in the jobs database, refuse to send it across origins, and disable redirects. Existing job snapshots remain untouched until an operator re-pins or recreates them.

Container recovery now seeds settings.toml and the 0600 credentials.toml independently, without overwriting a live named volume. The background governor also tells the truth about DS4: portable running, queue, and token caps remain active, while vLLM request priority and pressure metrics are explicitly configured compatibility features rather than assumed production capabilities.

2026-08-08 — Clean resumes and resilient launches (0.3.8)

Kin’s memory reflection is internal housekeeping: it distills durable memories between turns, but it is not part of the conversation. Those reflection turns were correctly hidden while a session was live, then could reappear after a resume — in the terminal or Outpost transcript, prompt history, a forked agent’s labels, compaction input, or rewind state. Replay now recognizes the whole bounded reflection span everywhere it consumes a journal, so the conversation you resume is the conversation you had. The journal still keeps the internal work for recovery, and ordinary user text that merely resembles a reflection marker is not hidden.

Launching Kin from a terminal whose current directory was deleted or moved into a protected Trash location no longer crashes before even --help can run. With no explicit project path, Kin re-anchors to your home directory and falls back to / if home itself cannot be entered, while reporting what happened. An explicit relative --workdir still fails closed when its original base directory is gone rather than quietly targeting somewhere else. kin doctor also re-anchors before invoking repair installers, so diagnosis and repair follow the same recovery contract.

The release dependency set was refreshed through the pre-release vulnerability gate as well, including patched aiohttp, cryptography, PDF parsing, and documentation/build dependencies. The published Outpost image and wheel are built from that audited lock.

2026-08-07 — Pseudo-terminals just work, and “run it unconfined” is one click (0.3.7)

A sandbox-friction release. Commands that allocate a real pseudo-terminal — the kind a full terminal UI, an interactive REPL, or the verify-pty gate needs — used to hit a wall in auto mode: the OS sandbox denied the allocation, the failure hid behind a misleading “out of pty devices” message, and the peer had to manufacture throwaway probes just to surface something it could ask you to approve. The sandbox now allows pseudo-terminal allocation natively, so those commands run contained with no approval at all.

And when the peer genuinely needs the sandbox lifted for a specific command, it can now ask you before running it — one prompt that shows you the exact command — instead of provoking a failure to earn the right to ask. That prospective request is always shown, never silently granted, is scoped to the one command, and can’t be widened into a standing “run anything unconfined” pass.

Both changes went through an adversarial security review before shipping, which is worth knowing about: the review caught that the pseudo-terminal rule, as first written, would have let a sandboxed command paint text onto your actual terminal (where the approval prompts are drawn), and that a long command in the approval prompt could scroll a payload out of view. Both were fixed — the terminal grant is now scoped to the pseudo-terminals a command allocates for itself, and the approval prompt shows the whole command — and the review’s other findings hardened the new escape hatch so it can’t become a durable bypass. See decision record 0158.

2026-08-02 — The shell door gets the same rules as everything else (0.3.3)

A security-and-workflow release. The theme: things Kin already refused to do through its structured tools could still be done through the shell, and things the shell learned from the network were trusted more than they deserved. Both doors now follow the same rules.

The shell-door audit (four decision records) closed the gaps one class at a time. Reading a credential store through cat/grep used to auto-run because those commands are “provably read-only”; any shell command that names a secret path now asks first, and that approval deliberately can’t be remembered. Rewriting hook-manager configs (.envrc, .pre-commit-config.yaml, kin’s own trust files) through a sandboxed sed -i used to succeed where the same edit through the edit tools asks; the sandbox now denies those writes at the kernel. run_code approvals never join the “always allow” tier. And when the model runs its own curl/wget — or Python networking through run_code — the output now arrives wrapped in the same untrusted frame a fetched web page gets, so instructions planted in remote content read as data, not as your voice.

GitHub got friendlier without getting looser. A recognized GitHub remote with gh installed but not signed in now parks the exact Git call on one plain-language web-login handoff and resumes it, instead of failing with credential-helper archaeology — and if you’d already trusted your SSH route, that keeps working untouched. Project MCP config moved to kin-owned .kin/mcp.json (a root .mcp.json — other harnesses’ convention, and older kin’s — is adoption material in /mcp, never auto-executed). Picking a model whose provider has no stored key now asks for the key right there. And the nested AGENTS.md guidance that file tools always surfaced now also triggers when a shell command touches a guided subtree, bounded so a wide ls can’t flood a turn.

A ten-finding adversarial review of all of the above landed with it: quoted pipes in rg/sed/awk no longer trip endless un-rememberable prompts, git sync names the real reason it stops after upstream squash-merges instead of “unexpected state”, a checkout the sandbox half-blocked reports the stale files instead of claiming success, and a parked login modal no longer blocks sibling sessions’ syncs.

2026-07-25 — Clearer refusals and a correct key map (0.3.2)

A polish release for the terminal UI, and most of it is Kin telling you the truth about itself.

When Kin refuses something you just asked for, it now names what is actually in the way. Twenty-one surfaces used to answer with one of two stock lines: “while a turn is running” — which was simply wrong if a /compact was what held the session — or “while kin is busy”, which named nothing at all. That second one was the worse of the two: pressing ++ctrl+l++ while an approval dialog waited for an answer read as an unexplained refusal instead of “answer the dialog first”.

The ++f1++ key map was describing an app that no longer existed. It listed the old provider picker with a key that surface has not had since 0.3.0, and never mentioned the /models hub that replaced it. The overlay hints and the map are now one declaration read from two places rather than two copies that drifted, which immediately surfaced three more gaps: the sandbox-access dialog binds a w “grant for this workspace” key its hint never named, /grants never named the n that backs out of an armed revoke, and the /models and /mcp hint lines were long enough to render cut off mid-word.

Peeking a file with v or /view showed its size and line count where the esc / q closes hint belongs, so the only way out of that view was undocumented on screen. Both are shown now.

Every overlay hint reads in one voice — each key followed by what it does (enter picks, esc closes) — and a hint no longer repeats what the dialog’s own buttons already say. See Keybindings & cursor mode.

Two places where text Kin did not author reached a notification without being treated as literal — another session’s folder name and conversation summary, and an error line from tmux — could render as markup or be dropped. Both are fixed.

2026-07-24 — Streaming, transcript, and launch fixes (0.3.1)

A maintenance release. The headline is a quiet one: long assistant replies could stop rendering partway through. When a streaming reply arrived before its message body existed, Kin built the stream around nothing, the write failed once in the background, and everything after that point was dropped with no error shown — the reply simply looked shorter than it was. Nothing was lost from the journal, so /resume always showed the full text; only the live view was truncated.

Two more fixes you may have hit. Starting Kin in a workspace where another launch already held the lock could fail with an internal error instead of falling back to a plain session. And the Outpost run-page transcript rendered the internal environment block that the terminal UI hides, so remote transcripts carried noise the local ones did not.

/model on a provider with no key now opens the /models hub directly rather than the retired provider modal, finishing the 0.3.0 move to one configuration surface. /brave-key (alias /search-key) is unchanged and remains where search credentials live. See Providers.

The rest is internal: the Textual client joined the type gate, every rendered inline script is now parsed by the test suite rather than only the landing page, and the Outpost transcript shares the harness’s journal decoder instead of a drifted copy of it.

2026-07-22 — Model hub and local Responses (0.3.0)

Kin 0.3.0 makes model configuration job-first. The /models hub now separates Jobs, Connections, and Routes so the plain-language jobs — main conversation, images, computer screenshots, tasks, and workflows — can each use a stable named assignment without exposing provider credentials or endpoint details to the model. Connection editing, secret updates, model discovery, and route assignment share one staged, conflict-aware apply flow. /providers [id] and /routes are now deep links into that hub rather than modals of their own, so the Brave Search key lives on /brave-key (alias /search-key) instead of a section inside the old provider modal. Bare /model is unchanged — it is still the cross-provider model picker. See Providers.

The release also adds an explicit OpenAI Responses wire with Kin-owned typed item replay, journal resume, strict parallel tools, structured output, usage reporting, and endpoint-safe reasoning persistence. vLLM 0.25.1 and Paddock-managed llama.cpp with Laguna S 2.1 have reproducible live qualification gates. Laguna’s long-context profile gains conservative first turn admission and completed-history compaction while preserving tool continuations intact; because Laguna S 2.1 is text-only, that profile now predeclares nested tool-result images unsupported rather than probing for them, so screenshots reach the serve as stable text references while the canonical bytes stay available to a separate vision route. See Models & providers.

Two of those changes are not profile-scoped, and are worth a look before you upgrade. Output-aware prompt admission now runs before every model round on any backend that reports a response cap: if the reserved output budget plus the prompt Kin may not summarize still cannot fit the context window, no model call is made. Interactively that is an admission error; in headless it is the new done_reason: context_limit with exit 1, so a scheduler that branches on done_reason needs the new value. And tool arguments are now validated against each tool’s JSON Schema on every wire — malformed, non-object, or schema-invalid arguments return an error to the model before any permission prompt or tool execution. If you ship a custom or MCP tool whose declared schema is stricter than its implementation, re-check that schema. See Headless.

The final review hardened secret writes, concurrent settings edits, endpoint switches, headless context-limit exits, Responses content filtering, and TUI shutdown so background git refreshes cannot fail after the chrome detaches.

2026-07-21 — Named model routes (0.2.5)

Kin 0.2.5 introduces operator-defined named model routes (DR 0139): global [model_routes.<id>] tables bind a provider preset + model behind a stable handle, and [model_assignments] steer the main agent, subagents, workflows, and vision work onto them — including semantic media dispatch, so a text-only main model can hand images to a vision-capable route via inspect_media. The model sees only the handles it may choose, never provider identity or endpoints. See Models & providers. The release also carries a verified review pass over the feature: route telemetry now attributes child rounds correctly, a custom [[providers]] row without a base_url keeps its ambient endpoint, and bare --resume again reuses the saved backend even with KIN_* exported in the shell.

2026-07-18 — Code reads like code

Fenced code blocks now follow conventional editor cues instead of repainting the brand palette (DR 0134): strings render in a muted content-only green, functions and builtins in bold bone, with cyan confined to keywords and amber confined to numbers. Inline code drops its amber and renders in body text on the code band — amber in a transcript once again means attention, nothing else. See the identity page for the reasoning.

2026-07-18 — get.kinra.ai becomes the Kinra product front door

get.kinra.ai now introduces two independent products: Kin, the native AI peer for the terminal, and Paddock, the Linux x86-64 alpha for operating local llama.cpp models. Each has a complete product page and installer; one quiet integration note explains that Kin can use Paddock’s loopback OpenAI-compatible endpoint without making either product depend on the other. Outpost remains an optional Kin deployment.

  • The site is three static pages with shared CSS and JavaScript, system fonts, no analytics, keyboard-operable OS tabs, accessible copy feedback, reduced-motion support, and screenshots sourced from each owning product.
  • Kin’s same one-liner is now universal on a fresh machine. It keeps every existing checkout on the editable path, but automatically uses a manifest-selected, SHA-256-pinned public wheel when Git or authorized GitHub SSH is unavailable. PyPI supplies public dependencies without becoming a candidate source for Kin itself. --check remains non-mutating and never probes SSH.
  • Kin 0.2.4 repairs the wheel resolver boundary caught by the production fresh-install drive: making Kinra the only package index also hid Kin’s third-party dependencies. The installer and kin update now make Kin a checksum-pinned direct requirement and expose PyPI only as the dependency index.
  • Paddock owns an independent manifest-last publication channel under /paddock/, including immutable archives, checksum sets, SPDX SBOMs, build metadata, compatibility evidence, and its bootstrap installer. Both source repositories remain private.
  • Public support and private-security inquiries use support@kinra.ai, a stable role address rather than an individual operator’s account.
  • get.kinra.ai now serves from a durable host docroot. Kin and Paddock publish disjoint allowlists, so a Kin deploy cannot delete a retained Paddock release. The old worktree docroot remains an explicit emergency rollback mount.

2026-07-17 — Subagents run until completion

Bundled subagent profiles no longer carry arbitrary model-round caps. A registered child runs until it finishes or the main coding agent pauses, interrupts, restarts, or kills it. Omitted or max-turns: 0 now means unlimited for custom profiles too; a positive value remains available as an explicit operator leash.

The supervision runtime, shared root token budget, doom-loop guard, depth and parallelism limits remain the real runaway controls. This removes the old failure mode where productive work hit a profile cap, parked, and required the main agent to spend another round resuming it with a freshly reset window.

2026-07-16 — kin tells you when there’s an update, and one command applies it

kin 0.2.0 opens the update channel (DR 0121):

  • You get told. At session start kin makes one best-effort, 24h-cached check of the get.kinra.ai release manifest and shows a one-line note when a newer release is out. Version-only, fixed endpoint; opt out with update_check = false / KIN_UPDATE_CHECK=0.
  • kin update does the rest — it detects how kin was installed (checkout vs wheel) and applies the right update, including the tool-venv dependency refresh that a bare git pull used to silently skip. kin update --check and a new kin doctor line report without applying.
  • Releases are verified by construction. get.kinra.ai and docs.kinra.ai now publish only from task ship-gated builds of main, and the wheel only from a tagged release — with older wheels retained, so each immutable versioned wheel URL remains a working rollback.
  • Re-running the install one-liner fully heals an existing install. Kin 0.2.4 supersedes the original index-only resolver shape with the checksum-pinned direct-wheel boundary described above.

2026-07-16 — Supervision branch hardened by a full multi-agent review

A high-effort multi-agent review of the model-owned-supervision branch surfaced 13 confirmed correctness defects and 10 cleanups; all are fixed. What you’ll notice:

  • Headless runs report honestly and always finish. A failed kin -p main turn can no longer be flipped to exit 0 by a later clean supervisor continuation, and a hung background agent now ends the run with a clear agent quiescence stalled error (~5 minutes of true silence) instead of hanging a cron job forever.
  • Sandboxed git-over-SSH actually works on Linux. A stock ssh-agent socket under /tmp is now bound back through bubblewrap’s private /tmp, and a successful command that merely quotes “Permission denied (publickey)” (a grep over logs) is no longer misread as a sandbox denial. With sandbox_network = false, uv run/task work again offline (UV_NO_SYNC=1 is restored for that posture).
  • Agent control is safer. Pausing a foreground child (a guaranteed deadlock) is refused; an interrupted agent can’t be double-run; pressing ++escape++ during an interrupt/restart wait actually interrupts; resuming a turn-capped agent gets fresh rounds; stale-health detection covers resumed and foreground agents; and agent_wait’s any_change wakes on real activity instead of sleeping to its timeout.

2026-07-15 — Model-owned subagent supervision

Registered task agents are now first-class supervised resources. The MCA can inspect, wait for, steer, cooperatively pause/resume, promptly interrupt, restart, and close them; lifecycle events automatically regain its attention without a human sending another message. Child prose and diagnostics stay behind explicitly untrusted-framed tools. Headless runs wait for agent quiescence, the TUI renders hidden-input autonomous continuations without a fake user bubble, and stale activity is advisory after a configurable bounded timeout. The old completion-reminder off switch is retired because lifecycle delivery is now correctness, not presentation.

2026-07-10 — get.kinra.ai installer + kin doctor + this site goes public

One pasted command now takes a fresh Linux/macOS machine to a running kin:

bash <(curl -fsSL https://get.kinra.ai/install.sh)
  • get.kinra.ai is a single static page (no framework) with per-OS prereq notes (Fedora / Ubuntu·Debian / macOS / Windows-via-WSL2) and the one-liner above. install.sh installs uv if missing, clones kinra-ai/kin to ~/kin (~/kin-textual is reused for existing pre-rename installs), uv syncs, installs kin via uv tool install --editable, and writes a starter ~/.kin/settings.toml — idempotent, no sudo, never edits shell rc files. Needs an SSH key with repo access (private repo).
  • No SSH key? uv tool install kin --index https://get.kinra.ai/simple/ installs the latest built wheel from a static index instead — read-only, no checkout, no dev loop.
  • kin doctor — a new subcommand that verifies any install: tools on PATH, a resolvable model provider (and which source supplies it), and the endpoint’s reachability (--offline skips the last check). Exit 0/1. See Install § Verify the install.
  • kin --version — prints kin <version> and exits before any TUI import; the installer’s success gate.
  • This site is now public at docs.kinra.ai, overriding the earlier “docs hosting LOCAL-ONLY” decision. A companion outpost-install.sh (also from get.kinra.ai) brings up the Outpost on a fresh server the same way.

2026-07-10 — Composer drag-drop + paste attach files by reference

Dropping files onto the composer, or pasting a Finder multi-file selection or an absolute path, now attaches them as @-mentions instead of dumping raw path text into the prompt — the same untrusted-content framing and secret-file guard an @-mention typed by hand already gets.

  • Whole-paste file detection — when the entire paste is one or more absolute, existing file paths (Finder’s newline-joined drop, Ghostty’s backslash-escaped spaced path, iTerm’s newline join), each becomes an @-mention at the caret in one toast; a prose paste that merely mentions a path is left untouched.
  • Oversize images (over 5MB) auto-downscale via macOS’s sips before attaching, to fit the vision-model edge budget.
  • ctrl+v captures a clipboard image directly — no intermediate file needed.
  • More than 10 files in one drop warns and inserts the paste verbatim instead of silently attaching a partial set.
  • Opt out with KIN_PASTE_MENTIONS=0 (or paste_file_mentions = false in settings.toml) to get the old verbatim-paste behavior back.

2026-07-10 — read_file learns Word + Excel (.docx/.xlsx)

read_file classified files by extension — image / PDF / SVG / text — and everything else fell through to the text reader, which opens a file with errors="replace". A .docx or .xlsx (zip containers of XML, not UTF-8 text) therefore came back as silent mojibake — a wall of replacement characters the model would hallucinate against. That fallthrough is now dead.

  • Word (.docx, .docm) → clean text: paragraphs plus tables rendered as Markdown rows, in document order.
  • Excel (.xlsx, .xlsm) → each sheet as a ## title heading + a Markdown table (cached values, not formulas), capped at 10 sheets × 100 rows × 30 columns with a truncation footer, then the same 50 KB char cap as PDF. @-mentioning an Office file works too.
  • Macros are never read. The .docm/.xlsm variants are handled, but the VBA blob is not a paragraph or a worksheet — it’s structurally unreachable.
  • Two security guards, verified engaged (not just installed): a zip-bomb cap that rejects an archive whose declared decompressed size exceeds 50 MB (checked before any parse), and the XML entity-expansion guard (defusedxml, openpyxl’s billion-laughs defense). A four-pin test battery proves both fire.
  • No silent garbage, ever: a corrupt or non-Office file with one of these extensions returns an explicit error: — never a mojibake decode.

2026-07-04 — Unlimited main-session turns (KIN_MAX_TURNS)

The main session’s per-turn round cap was hardcoded at 40 model↔tool round-trips — fine for typical interactive turns, but it cut short the long agentic runs a large model can sustain for hours. The cap is now unlimited by default, configurable end-to-end, and the subagent caps are raised to match.

  • KIN_MAX_TURNS env / max_turns settings key / --max-turns headless flag — 0 = unlimited (the default). A non-zero value caps the model↔tool round-trips in one user turn (done reason turn_cap, headless exit 1). Mirrors the existing token_budget resolution chain.
  • Subagent caps raised: default max-turns 20 → 100, hard cap 100 → 1000 (a subagent profile’s frontmatter).
  • The doom-loop guard (3× identical call+result) remains the real no-progress backstop, so an unbounded cap is safe — a stuck loop still trips it. max_turns is an operator leash (deliberately not model-writable), just like the per-run token_budget.

2026-07-04 — TUI polish pass + docs audit

A 10-commit TUI polish pass (POLISH r1-r10) landed on dev (the 746535b fix commit followed), then a separate docs-audit pass cleaned up drift in the user-facing docs.

POLISH r1-r10 + 746535b (the visual identity series):

  • r1 — every functional glyph consolidated into theme.py constants (POLISH-r1 audit-fail for any drift site; zero diffs).
  • r2#transcript { margin-bottom: 1 } always-on transcript↔StatusBar gap; the old .-turn-end re-tagging machinery deleted; the docked Footer replaced with the placeholder’s F1 help hint.
  • r3UserMessage is a rounded titled box with a you border-title (auto-width hugs short prompts, wraps long ones).
  • r4 — connector vocabulary: G_RUNNING flipped to , carets on Collapsible, ╰ tail elbow for the live tail of a running tool, border-left rails on Contents.
  • r5Reasoning title two-tone (thinking…thought · 4s), body italic dim, left rail $accent 35%.
  • r6 — new shimmer.py primitive (cosine-swept raised-cosine sweep, 2.0s period, 5.0-char band) + StatusBar phase-word state machine (thinking / mulling / tracing / sifting / weaving / kindling / distilling rotation).
  • r7 — subagent dedup (single set_activity(f"agent working ({profile})…") on the bg path) + task · <profile> agent-mode title.
  • r8tool_call_draft end-to-end (new Chunk("tool_draft", …) on both wires — name + chars only, NO argument content; loop-side ≤250ms throttle; ForwardingEmit drops it from subagent children; StatusBar shows drafting <name>… N chars with char-count tiers).
  • r9 — WorkflowCard shimmer + tooltips + HelpModal audit (cursor-mode + expand-all + ctrl+p added; scrollable body fixed-height+1fr-scroll).
  • r10 — snapshot baselines regen + docs sync (docs/reference/events.md got tool_call_draft; docs/getting-started/first-run.md mentions the shimmer + phase-word state machine + TEXTUAL_ANIMATIONS=none fallback; REFERENCE.md § UI widgets & theme got the four invariants).
  • 746535b — fix pass for the adversarial-review findings from the polish series.

Docs audit (this pass):

  • vLLM example model id refreshed across README.md + the vLLM recipe in docs/guide/models-and-providers.md + the banner mock-ups in docs/BANNER_SPEC.md + the example in research/README.md — fleet is now Qwen3.6-35B-A3B on vLLM 0.23.0 (was 27B-FP8).
  • src/kin/tui/CLAUDE.md synced with POLISH r1-r10 — new shimmer.py row in the UI map, new “POLISH r1-r10 invariants” subsection under Theme & visual identity.
  • TRACKER line 16 (the former TRACKER backlog) stale wording fixed (“NOT yet pushed, NOT on main” → “PROMOTED to main 2026-07-03, clean FF to 6e32d6b”); the §23-31 STRATEGY closure block collapsed to a 5-line recap pointing at research/2026-07-02-strategy.md and the 2026-07-03 review (now docs/decisions/0009 + 0010).
  • Verify-suite count reconciled: task verify runs eleven wired-in suites (was “ten”); verify-memory and verify-workflow added to README’s verify command list.
  • MCP servers added to CLAUDE.md’s operator-tour block.
  • New docs/internals/extending-tools.md — the user-facing mirror of src/kin/harness/CLAUDE.md’s tool-author guide, plus walkthroughs for adding a permission kind and a subagent profile.
  • docs/concepts/architecture.md extended — “Compared to other agent harnesses” table (kin in-process vs Claude Code / Gemini / Codex subprocess vs Aider/Continue LSP vs OpenHands/Devin remote), Mermaid turn-flow diagram.
  • New docs/getting-started/first-session.md — 10-exercise TUI tutorial (welcome banner, slash history, cursor mode, planning freeze, sessions).
  • KIN_BASE_URL heuristic anchor made explicit (#the-kin_base_url-heuristic) on docs/guide/models-and-providers.md; docs/getting-started/first-run.md uses the explicit anchor.
  • The former HARNESS_PLAN planning doc’s “Dynamic workflows DESIGN” section collapsed (~279 lines → ~62 lines pointer + recap).
  • docs/kin-console.md deleted (76-line placeholder predating the Outpost; superseded by docs/guide/outpost.md).
  • Duplicate trailing line removed from docs/guide/sessions.md.
  • docs/404.md (this 404 page) + docs/changelog.md (this page) added.

2026-07-03 — STRATEGY build PROMOTED to main

All 11 rocks landed (Tier 0 + Tier 1 + Tier 2 + ALL of Tier 3: 3a/3b/3c/3d/3e), verified, and PROMOTED to main (clean FF to 6e32d6b, 2026-07-03 ~21:00). Outpost was redeployed with all three riders (2a scheduler / 3b chromium / 3c Memory card). Verify baseline: 2500/0 across 11 suites.

Tier 3 (the maturation tier):

  • 3a MCP maturation — hardening + elicitation + resources + OAuth (auth-code+PKCE, NOT device flow: research overturned the hunch).
  • 3b Computer-use Tier-1browser tool (Playwright chromium, text-only, action-enum, scheme allowlist, two-layer SSRF guard).
  • 3c Agent-memory floormemory tool (Anthropic’s memory_20250818 command set 1:1) + FTS5 recall index + session-end consolidation side-call + Outpost Memory card.
  • 3d Multi-agent artifact storepublish/ref verbs + agent() opt-in {ref, summary} handle + ride-alongs /revise + /research.
  • 3e Code-interpreterrun_code stateful per-Session kernel under the OS sandbox (kind=perm.SHELL reuses the shell decision path; zero permission-plumbing edits).

Half-rock gap (still open): Tier 2b “GPU governor” landed a per-run token leash, NOT the cross-run GPU-fairness gate STRATEGY asked for. Live session + scheduled job still race one GPU. See the 2026-07-03 review (now docs/decisions/0009 + 0010) Tier-2b section.

2026-07-02 — Headless run mode

kin -p <prompt> (the Tier 0 keystone from the STRATEGY research) — one turn, no UI, real Backend, collecting emit sink, exit 0/1/2 contract. The Outpost scheduled-jobs centerpiece (2a) consumes this via kin -p SUBPROCESSES. Closes the gate for scheduling / evals / cron work. See the Headless guide for the full surface.

2026-07-01 — Live reasoning-effort controls

/effort slash command + per-serve picker (low / medium / high / xhigh / max for Anthropic; low / medium / high for OpenAI-compat; auto / on / off for Qwen). The KIN_REASONING_EFFORT env var overrides per session.

2026-06-30 — Git network tools

git-push / git-pull / git-fetch modeled on ssh.py (structured args only, argv assembled element-by-element, runs OUTSIDE the OS sandbox). push / pull reuse kind=perm.MCP (ASK both modes); fetch gets the new kind=perm.NETWORK (ALLOW auto / ASK strict / freeze-DENY). force only ever emits --force-with-lease (no raw --force).

2026-06-28 — v3 §4-7 batch

  • §4 ssh egressssh tool (kind=MCP, outside the sandbox, honors ~/.ssh/config, opt-in global ssh_hosts, host-scoped approvals).
  • §5 bundled exemplar skills — 9 SKILL.md exemplars (deep-research / brainstorm / code-review / simplify / debug / commit-message / plan / skill-creator / pr-description).
  • §6 search_workspace Tier 1 — stdlib FTS5 build/search, secret
    • gitignore exclusion, off by default (KIN_SEARCH=1). Tier 2 (vector / embed / rerank) DEFERRED.
  • §7 settings toolread_settings READ + propose_settings META with an explicit MODEL_WRITABLE_KEYS allowlist.

2026-06-27 — auto-first two-mode collapse + plan lifecycle

The two-mode core (auto + strict, the CYCLE for shift+tab) plus the planning freeze (a transient read-only overlay, not a mode). defaultstrict, accept-editsauto, planstrict legacy aliases. /plan enters the freeze; present_plan presents the tracked plan file (3-option modal: keep / clear & re-inject / hand to critic).

2026-06-26 — Dynamic workflows (“ultracode”) MVP

The seven primitives (agent / parallel / pipeline / phase / log / publish / ref) + the workflow tool + the TUI WorkflowCard + the /workflows modal. Closed namespace (capability by absence, NOT a sandbox) + AST filter + SIGALRM busy-loop watchdog. See the Workflows guide for the user-facing walkthrough.

2026-06-26 — Background subagents + Ctrl+O panel

The task tool spawns a bg subagent and returns an agent id immediately; the model sees a metadata-only <system-reminder> on the next depth-0 turn (never subagent prose). MAX_BG_SUBAGENTS = 3 is the runaway guard. Ctrl+O opens the panel (shells / agents / tasks panes, Tab cycles).

2026-06-26 — Tasks DAG + --agent CLI

The tasks tool with action enum (add / update / complete / remove / list / blocked), cycle-checked, auto-unblock on complete. Sidecar at <KIN_SESSION_DIR>/<session_id>.tasks.json. kin --agent <name> runs the main session as a profile (TTY-only).

2026-06-25 — kin CLI packaging

The installable kin uv CLI (src layout, hatchling). macOS Ghostty “Open in kin” Finder Quick Action in extras/macos/.

2026-06-24 — File-extraction refactor + security fixes

The read_file tool gained PDF (via pypdf) + image (PNG / JPEG / GIF / WebP as image blocks; SVG as text) support, with a 50k char cap and a coerce_int discipline for numeric args.

2026-06-23 — Spine landed, verified, live-tested + hardened

The kin-textual → native Python harness pivot. In-process harness (src/kin/harness/) + Textual UI (src/kin/tui/) + the event vocabulary seam (src/kin/harness/events.py). No subprocess, no NDJSON, no wire between the two. The Go ../kin/ repo became the design reference only.