Release notes
From 0.0.10 onward the app updates itself — Check for Updates finds, downloads, and installs new versions with your approval. On 0.0.9 or earlier? Download the latest installer once from the download page, and you're on automatic updates from then on.
v0.0.38 — 2026-08-13
- A retired password-manager connector remains unavailable. Existing links are paused rather than deleted; it cannot be reconnected or called, while other connectors, grants, and Master Keys are unaffected.
- Removed app-usage analytics from the macOS app. Crash reporting is unchanged: it asks first, sends only if you choose
Send report
, and is scrubbed on your Mac before it leaves. - Custom connector authentication placements AMK cannot perform are now rejected before anything is saved, with a clear typed error instead of a raw server failure.
- Damaged local state fails closed with a sanitized recovery message instead of appearing as an empty connector list or exposing internal parser details.
v0.0.37 — 2026-08-08
- Fixed credential Save routing across Firecrawl, Groq, and Perplexity: provider hostnames now remain intact for HTTP and TLS while the connection stays pinned to prevalidated public addresses.
- Pasted API keys now trim harmless leading and trailing whitespace, while embedded spaces, controls, and unsafe Unicode are rejected locally before any network or vault access.
- Credential checks now use current read-only provider endpoints and return short, correlated, retry-safe errors without exposing provider HTML, authorization data, or runtime internals.
- The release gate now exercises the packaged credential path with deliberately false keys. This is synthetic routing proof only; valid-key and real-account compatibility remain unclaimed.
v0.0.36 — 2026-08-08
- Approval, denial, key-revocation, clipboard, and protected-read failures now stay honest on screen instead of showing success or an empty all-clear when the broker refused or could not confirm an action.
- Removed the misleading one-hour approval option until a real duration-scoped grant exists; every visible approval control now matches what the broker actually enforces.
- Release identity and proof are now bound fail-closed, so a new build cannot inherit the previous release's signing or notarization evidence.
- Strengthened clean-build packaging, browser-journey evidence isolation, and dependency security checks used by the release factory.
v0.0.35 — 2026-08-07
- The packaged dashboard now shows the exact app version and build it shipped with, so a current install cannot look outdated because stale release numbers were compiled into the dashboard.
- Clean release builds now compile their workspace dependencies before direct test and packaging gates, preventing missing build output from slipping into a candidate.
- Updated the packaged networking runtime and site-build dependencies to patched releases; the production dependency audit is clean.
v0.0.34 — 2026-08-06
- The embedded dashboard now recovers cleanly after a WebKit interruption: it reloads the current trusted local dashboard, rechecks the rendered page, and avoids a false failure.
- Completed installs stay out of the minimal first-run welcome when setup completion is already saved, including while the local service is reconciling.
- Connector search counts connector cards only and labels "Add your own" separately, so the result count matches the visible connector cards.
- Password managers now receive the right vault semantics: new-password during setup and current-password when unlocking.
- Active connection work now says "Connecting", while an in-progress app relaunch says "Restarting"; the two operations no longer share one progress label.
v0.0.33 — 2026-08-04
- Solved the "an old version of the app came up" family for good: the screen that read as "the old app" is actually the current app's native Overview, shown while the local service restarts after a password reset, repair, or update. It now shows its version right beside the title, and while the service heals it says so plainly — "Updating this Mac's local service — takes about a minute and finishes by itself" — instead of reading like a fault.
- Launching a new build while an old one was still running silently kept the OLD one active (menu-bar apps keep running after their window closes). Launch now compares build stamps and the version you actually launched wins: a different or unreadable build is asked to quit, force-quit only if it hangs.
- Connect receipts are honest end to end: the "one step left" receipt now carries the actual "Restart {agent} for me" button it tells you to tap (it used to quote a button that wasn't there), an already-connected agent gets "nothing left to do" instead of a stale restart instruction, and the receipt always calls the agent by the same name as its tile.
- A freshly connected agent no longer instantly claims "Connected — {agent} is calling AMK": that green state was being minted by AMK's own connection self-check rather than the agent. Green now requires the agent's own first call after its restart, so the amber "Restart needed" step tells the truth again.
v0.0.31 — 2026-08-03
- After updating, resetting a forgotten AMK password could leave the PREVIOUS version's background service running — and the app then rendered that old version's dashboard. Fixed at every layer it slipped through: the dashboard render gate now binds trust to THIS build and refuses a listener reporting a different or missing build id (fail-closed, routed to Repair & Restart with plain-language copy); the service installer replaces a stale old broker instead of failing open; the password-reset flow verifies the service it started is the current build and reports an honest, actionable error when it is not; and a vault reset clears the embedded dashboard's website data so no cached shell from an earlier version can render after a reset.
v0.0.30 — 2026-08-03
- Approvals now reach you: when an agent's call is waiting on your decision, AMK posts a macOS notification (tap it to open the approvals window) and keeps the menu bar badge live — an agent blocked on approval is never a silent hang again. Notifications are redaction-safe by construction (agent, tool, and risk band only — never call parameters), bursts collapse into one summary banner, and permission is asked on first use, not at install.
- First-task suggestion: the moment an agent's tile flips green, the dashboard offers a concrete read-only starter derived from your connected apps ("try asking it: 'list my open GitHub issues'") with one-tap copy — so "connected" immediately becomes "doing something".
- Plain-language activity digest on the home view: "Today: 14 tool calls · 2 approvals · 1 blocked", derived from the same tamper-evident audit trail the activity table shows.
- Local-only activation milestones (stored on your Mac, nothing leaves it): setup → first connect → first call-in → first tool call, surfaced during early sessions.
- Fixed: automatic update checks were never actually enabled — the packaged app was missing the setting, so fresh installs only checked on demand. Checks are now automatic; installing an update still always asks you first.
v0.0.29 — 2026-08-03
- One-tap finish: after connecting a GUI agent (Claude Desktop, Cursor, VS Code, ...), the amber tile becomes "Restart {agent} for me" — AMK quits and reopens the app for you (graceful quit only, operator-gated, audited; never force-killed). CLI agents honestly say they connect on their next run.
- The tile flips green live: while an agent owes its restart, the dashboard watches for its first call-in and flips the tile to "Connected — {agent} is calling AMK" in front of you, no refresh needed. The watch stops itself once every connected agent has called in.
v0.0.28 — 2026-08-03
- Connecting an agent now walks you to the finish line: the tile shows an amber "Restart needed — restart {agent} to finish connecting" state after the config is written, and only turns green ("Connected — {agent} is calling AMK") once the agent has actually restarted and used its key. The post-connect receipt headlines the restart step and suggests asking your agent "what AMK tools do you have?" to confirm the link.
- Every agent now learns what AMK is for automatically: the MCP handshake carries server instructions ("reach for AMK first when a task needs an external service, never ask the user to paste secrets"), so a freshly restarted agent knows to use its AMK tools without any manual prompting.
- Settings > General: "Start Agent Master Key at login" — a standard macOS login item (System Settings-visible, revocable there too) so agent connections keep working after a reboot without reopening the app.
- Release factory: every candidate now boots its own packaged service in a scratch environment and must pass customer-journey checks (build provenance, catalog/manifest parity, install detection truth including fail-closed config remnants) before it can be receipted, notarized bytes included — no more relying on the founder to catch regressions by hand.
v0.0.27 — 2026-08-03
- OpenCode installs without a linked CLI are now detected: detection accepts the OpenCode.app bundle as install evidence instead of requiring the `opencode` binary on PATH (same failure class as the Grok Build miss, found by auditing every harness detect spec against a live-machine census).
- The release pipeline refreshes the rollback-runbook proof receipt during promote, so publishing a version no longer leaves the repository's receipt-freshness gate red for the next change.
v0.0.26 — 2026-08-03
- Grok Build installs are now detected: the xAI installer ships its launcher as `grok` (linked into `~/.local/bin`, self-managed under `~/.grok/bin`), but detection only looked for a binary named `grok-build`, so a real install kept reading "Install to connect" no matter how many times the app was refreshed or relaunched.
v0.0.25 — 2026-08-03
- First-run "Let AMK do it" and the dashboard now present the same agents: the dashboard's one-click grid is derived from the harness manifest (every auto-write agent, including Claude Code, VS Code, and OpenClaw) instead of a hand-maintained list that had drifted, with a parity gate so the two surfaces can never disagree again.
- The first-run agent chooser uses the same names and brand logos as the dashboard tiles — one agent never appears under two different labels.
- When AMK cannot reach its local service to detect installed agents, first-run now fails closed with "Couldn't check which agents are installed" plus retry/manual recovery instead of presenting a stale "Detected" list.
- Connecting an agent from the dashboard now reacts visibly: the clicked tile flashes its connected state ("Connected ✓"), and the success/error receipt scrolls into view and is announced to assistive tech. Paste-only agents are never shown as connected before the snippet is applied.
v0.0.24 — 2026-08-03
- Agent tiles no longer show "Connected" for agents that are not installed on this Mac. Connect is refused fail-closed for missing agents (leftover config files never count as presence), rejected attempts are recorded in the audit trail, and the tile reads "Install to connect" with the connect action disabled (#531, #667).
- "Check for Updates…" in the app menu now runs a real Sparkle update check on production builds instead of a manual window with stale v0.0.1 copy (#1042).
- The scheduled Sparkle update alert now comes to the front instead of opening behind the main window (#1043).
- The first status-item click after launch no longer risks crashing the app — the menu-bar popover defers model reads past the install-time sizing pass (#482 crash family, #1045).
- The menu-bar popover now reflects kill-switch changes made from the embedded dashboard (EMERGENCY STOP) by reconciling from `GET /v1/killswitch` on every refresh (#1041).
- Repeated same-value kill-switch toggles no longer append duplicate audit events (#1044). Current limitation: an authenticated toggle clears the recovery marker before attempting to save the new state. A failed write is logged without rejecting the toggle, so clearing that marker does not prove a clean state was saved.
- Install detection is driven by the harness manifest (app bundles, launchers, home-relative binaries) instead of a hand-maintained list, with a coverage gate so every supported agent ships a detection path.
v0.0.12 – v0.0.23
These releases shipped between July and August 2026 and are covered by the automatic updater. Detailed per-version notes for this range were not recorded at the time of release; rather than reconstruct them after the fact, we are stating that plainly. Notes resume in full from v0.0.24 onward.
v0.0.11 — 2026-07-07
- Fixed a rare crash when opening Settings from the menu bar.
- Vault recovery: if a system restore ever leaves your vault in a stuck state, you now get a clear choice — unlock in place with your passphrase, or reset just this Mac's vault (you re-link your connected apps; nothing else is touched and no data leaves your Mac).
- Revoking an agent key now fully removes its key files from disk.
- First-run agreement to the Terms of Service and Privacy Policy (existing installs are unaffected).
v0.0.10 — 2026-07-07
- Check for Updates now actually updates. The built-in updater checks automatically, verifies every download against the key compiled into the app, and installs with your approval — nothing happens silently. This is the last version you need to download by hand.
- Retired commercial access experiments from customer-facing surfaces for the Public Preview.
v0.0.9 — 2026-07-06
- New app icon with proper macOS treatment (no more square slab on your desktop and Dock).
- Agent tiles now show Connected when your agent is already set up — no more being asked to connect an agent that's working.
- Honest detection: an agent only shows "Detected" when the app is actually installed on your Mac, not when a leftover config file exists.
- Redesigned installer window.
v0.0.8 — 2026-07-06
- Signed update feed published — the groundwork for the built-in automatic updater arriving in 0.0.10.
- Historical reliability work added atomic, serialized writes to affected settings and connection stores. This did not cover every state file: current kill-switch persistence uses a direct, best-effort write without atomic replacement.
- License integrity hardening: entitlements now carry a bounded validity window and re-confirm automatically, and the app's verification key is compiled in.
v0.0.7 — 2026-07-06
- New installer: planned disk image distribution, after signing and notarization, with drag-to-Applications install.
- Hardened entitlement concurrency and state transitions.
v0.0.6 — 2026-07-05
- Fixed Firecrawl search returning empty results (responses now read the nested
data.webpayload correctly). - Fixed 14 connector API-contract bugs found in a full 27-connector audit — connectors that returned malformed or empty responses now work.
- Additional crash hardening on top of the 0.0.5 fixes.
v0.0.5 — 2026-07-05
- Fixed a first-run crash caused by an observed-state tooltip.
- Fixed a crash when creating an agent key from the Make Agent Key button (latent teardown bug).
v0.0.4 — 2026-07-04
- More reliable signed release delivery — clean-zipped artifact and signed update feed.
- Stabilized the packaged app launch.
- Hardened legacy entitlement fulfillment with crash-safe, live-mode-guarded minting.
v0.0.3 — 2026-07-02
- Historical release: a public download was previously available at downloads.agentmasterkey.com with Developer ID signing, notarization, and stapling (sha 606ece45…).
- Added the first server-backed entitlement lifecycle.
v0.0.2 — Launch hardening
- First public notarized release: signed with Developer ID and notarized by Apple — no Gatekeeper warnings.
- Fixed a first-run dead-end where the app could demand an operator passphrase that setup never created.
- The unlock screen now accepts your vault passphrase directly and shows plain-language status instead of raw errors.
- Faster, more reliable dashboard loading (no more stuck "Loading dashboard" overlay).
- Added server-backed entitlement enforcement while preserving offline launches.
- Stability hardening around app relaunch and system accessibility queries.
v0.0.1 — Private beta
- Local-first credential broker: provider keys stay in an AES-256-GCM encrypted local vault on your Mac, never uploaded to us.
- Scoped, revocable agent keys (
amk_live_…) with approvals and a redacted audit trail. - Kill Switch to pause every agent at once. Current restart persistence depends on a successful save; write failures remain a known limitation.
- Added the original signed entitlement and offline-grace flow.
- Beta connector posture: Early site copy advertised a limited connector set (GitHub, Gmail, Telegram); superseded 2026-07-04 — the homepage now lists the shipped 20-connector catalog, and Gmail was removed because it never shipped.
© 2026 AM Accelerated LLC.