Releases: FORIFOR/oathra
Release list
Oathra v0.1.19
Oathra v0.1.19
v0.1.19 replaces the Arena with the Oathra app. oathra demo now opens the same app that runs as the Gateway, in practice mode on your computer: no sign-in, no API key, nothing dials.
The app (oathra demo)
- 練習 (practice): watch the AI call a built-in character, or choose 自分が相手役 and answer the AI's call yourself as the shop, in text. A field is settled only by the other party's own words; the settling words are marked in the conversation.
- 記録 (records): practice runs and
oathra playcalls are saved to.oathra/calls/and can be replayed. - Other devices:
--allow-remote(same network) and--tunnelprint a sign-in link; only this computer opens without one. - Other AIs in practice:
--allow-modelslets OpenAI, Gemini or Ollama make the practice call; the screen says the conversation is sent and charged. - Real calls:
--live --tunneluses this machine's carrier and voice keys; readiness is shown at start and in 設定. - 電話を頼む by kind of call, 予約を取る (the one request that may book), 予定 (dates the calls settled), the report with each settled value and its quote, AIが判断したこと (the AI's own account, not used for the verdict), voice samples, a monthly cap, email and password sign-in for the server.
Voice and runtime
- Gemini Live (
gemini-3.8-live) as a second speech-to-speech engine, with session resumption; an acting voice (Deepgram → OpenAI → Gemini TTS) for the pipeline engine. - No stale replies after the callee has spoken again, no turns without words, and a check-in when the line goes quiet.
- The runtime hangs up on brain/TTS exceptions and ends silent lines at
maxDurationMs.oathra --version;doctorchecks ngrok instead of unused keys.
Evidence
- Fixes from the 2026-09-26 audit: a bare 「承りました」 does not confirm; English "not confirmed yet" never does; 「2万5千円」 parses as 25,000; per-head prices are not party sizes; durations are not times; cancellation policies are not cancellations; 「その時間は難しい」 after a booking takes it back.
Removed
- The Arena (
apps/arena) and its local web phone. v0.1.18 and earlier still open it.
Verification
pnpm test: 1113 passed, 1 skipped credential-gated test.pnpm test:gateway: 334 passed.pnpm lint:depspasses.oathra eval: False Completion 0.oathra eval --adversarial 10000: 0 / 10000.- Browser checks (local Chrome over CDP): the Gateway flow, the app (54 checks), the local app (12 checks: no sign-in here, sign-in link from a LAN address at 390 px, practice with another AI via a stand-in, records and seeking), the managed screens.
- The packed tarball was installed into an empty directory and
npx oathra demoserved the app. - Not verified by the assistant: a real phone call on this build, a tunnel, a physical phone on the LAN, external model practice (paid), Windows and Linux.
Oathra v0.1.18 — appointment-style completion, agreement fixes
Oathra v0.1.18
v0.1.18 makes "a meeting was agreed" an evidence-engine verdict, closes the agreement gaps that made that necessary, and brings the omnichannel gateway under the same rule.
Appointment-style completion
Reservations complete when a shop says 「ご予約承りました」. A sales meeting is the other way round: the caller proposes a slot and a person commits to it. Contracts can now say so:
defineCall({ goal: "sales.meeting", require: { date: true, time: true, confirmed: true }, confirmation: "callee_acceptance" });confirmed is then verified by the callee's clean commitment (「はい、9月25日の15時でお願いします」) once date and time are stated or settled. A bare 「はい」 answers only the caller turn right before it. A later refusal or hedge from the callee takes the commitment back. The default (callee_statement) is unchanged, and reservation results are identical to v0.1.17.
What no longer counts as agreement
Found by probing the gateway and by a new fuzz, fixed in packages/evidence for every mode:
- Scheduling conflicts next to a polite word: 「承知しました。ただ9月25日の15時は別の会議が入っています」, 先約, 出張, dialect 「できまへん」.
- Deferrals: 「上司に聞いてから折り返します」, 持ち帰り, 「検討します」, 「それから判断します」.
- 「…でお願いします、と言いたいところですが」 and 「ただ…」 without a comma are contrasts.
- A callee asking to cancel is a retraction.
- 「問題ありません」 / 「問題ございません」 were being read as refusals; they are agreements again.
Before this, the first two groups verified the caller's proposed date and time. Reservations were protected only because confirmed is a separate field.
Omnichannel gateway
apps/gateway (LINE, Slack, Telegram, Web and iOS as remote controls for an approved call, plus separately approved Gmail / Calendar / SMS / HubSpot follow-ups) landed on main after v0.1.17. Its meeting verdict was a gateway-local regex that reported five ordinary hedged replies as COMPLETED and put a contact who said 「それで結構です」 on the do-not-contact list. It now delegates to evaluate(); a slot needs both sides. The gateway requires the built engine and has no fallback to the old rules.
The gateway is implemented and tested offline only. No real LINE / Slack / Telegram / Google / HubSpot account and no live line has been verified; the default mode is the scripted simulator, and live mode needs an explicit policy flag. Outbound sales calling is regulated; check the rules that apply to you before turning it on. The gateway, SDKs and plugins are not part of the npm package.
Verification
packages/evidence/src/appointment-fuzz.test.ts: 10,000 seeded sales dialogues with ground truth, 18 kinds. 0 false completions; clean commitments complete > 99%.appointment.test.ts: 145 cases including an 8 × 14 agreement × spoiler matrix in both orders.pnpm test: 877 passed, 1 skipped credential-gated LiveKit test. Gatewaynode --test: 145 / 145.oathra eval: False Completion 0, same scores as v0.1.17.oathra eval --adversarial 10000: 0 / 10000, same 3262 completable runs.pnpm lint:depsnow also enforcessdk → nothing,plugins → sdk,gateway → sdk, plugins, built packages.- Site: the Evidence Clarity redesign is live; measured at 390 px (chips 48–68 px, nav 44 px, buttons 46–50 px, no horizontal scroll).
- Not verified: real telephony, real messaging accounts, ASR errors. The agreement rules are a bounded vocabulary, not a guarantee over all Japanese.
Readiness=USER_APPROVED_RELEASE · ManualSmoke=NOT_RUN_BY_ASSISTANT · UserOverride=YES · ReleaseRisk=ACCEPTED_BY_USER
Oathra v0.1.17 — MCP server, permission-flow fix
Oathra v0.1.17
v0.1.17 adds a local MCP server, fixes a call-ending bug in the permission flow, and gives the call loop and the phone bridge their first dedicated tests.
oathra mcp
An MCP server over stdio. From Claude Code, Claude Desktop or any MCP client, one tool call runs a simulated phone call and returns a result backed by evidence from the callee's own words.
{ "mcpServers": { "oathra": { "command": "npx", "args": ["--yes", "--package=https://github.com/FORIFOR/oathra/releases/download/v0.1.17/oathra-0.1.17.tgz", "oathra", "mcp"] } } }simulate_call— built-in agent against a scripted callee. Same seed, same result. Returns fields, the evidence behind each one with utterance ids, the callee's ground truth andfalseCompletion.verify_transcript— the same check asoathra verify, for your own transcripts.inspect_call— result and evidence of a saved call;at: "00:12"shows what was verified at that moment.list_calls,list_scenarios.
Everything runs locally with no API key and no cost. There is deliberately no tool that dials a real phone and no argument that selects a paid LLM; call, intervene and cancel_call wait until the real-call path has been re-verified. inspect_call accepts call ids only, never paths. It does hand the contents of .oathra/calls/ to the MCP client, so keep that in mind where real-call recordings are stored.
Fix: a permission request no longer ends the call
When a brain asked for an action the contract had not pre-authorised (for example payment), the runtime moved VERIFYING -> AWAITING_PERMISSION, a transition the state table did not allow. The exception ended the whole call as error before the PermissionGate was asked. LLM brains are instructed to make such requests and the built-in agent does so for share_name, so this was reachable. It failed safe — it could not produce a false completion — but the call was lost. The transition is now allowed and covered by tests for deny, human approval and policy approval.
Tests
packages/runtime and packages/phone had no test files. They now cover evidence-only completion, an agent's self-claim not completing, voicemail, turn budget, hangup and error paths, cancel(), utterance coalescing, the repeat guard, permissions, speech-to-speech transports, consent-gated intake, bridge audio conversion (PCM 24 kHz to μ-law 8 kHz keeps signal energy), idempotent close, carrier and engine failures, routing and list prices.
Verification
pnpm test: 731 passed, 1 skipped credential-gated LiveKit test (676 before this work).pnpm build,pnpm lint:deps,oathra eval(False Completion 0) andoathra eval --adversarial 10000(0 / 10000) pass.- The MCP server was driven end to end over stdio against the bundled binary: stdout carries JSON only.
- Not verified: a real MCP client UI, and real telephony. No phone call was placed for this release; the post-fix live-call path from 2026-09-15 still has no successful verified conversation (
docs/launch/real-calls.md).
Readiness=USER_APPROVED_RELEASE · ManualSmoke=NOT_RUN_BY_ASSISTANT · UserOverride=YES · ReleaseRisk=ACCEPTED_BY_USER
Oathra v0.1.16
Oathra v0.1.16
v0.1.16 adds ActionProof, a typed contract for tracking how a phone-agent action is supported from the conversation through confirmation, system evidence and the observed outcome.
claimed(V0) is kept separate from independently observed proof.conversation(V1) adapts the existing callee-utterance evidence without changing the current verifier.confirmation(V2),system(V3) andoutcome(V4) observations require an explicit source, stable reference and valid timestamps; no provider-specific credentials or adapters are bundled.- A higher-level observation never replaces a valid lower-level result when it is unverified, expired or conflicting.
- The SDK exports the proof types, evaluator and source contracts from
oathra/evidence.
This release does not claim that a provider account, reservation system or PSTN call was verified. Real email, SMS, webhook, reservation API, browser, calendar and POS adapters still require the target system's authentication and contract.
Verification
pnpm test: 664 passed, 1 skipped credential-gated LiveKit test.pnpm typecheck,pnpm lint:deps,pnpm build,pnpm build:siteandgit diff --checkpass.- The packed
oathra@0.1.16tarball exportsPROOF_LEVELSand includestypes/evidence/proof.d.ts. - The Arena recording remains a simulator demonstration, not a real phone call or a PSTN success-rate claim.
v0.1.15 — time-pressure safe intake
Oathra v0.1.15
v0.1.15 makes consented follow-up intake stop when the callee signals time pressure, and keeps live voice models aware of the profile fields already answered.
- Japanese and English time-pressure phrases such as 「今ちょっと急いでおります」, “I’m busy” and “call me back later” end optional intake without saving a guessed value or repeating the question.
- OpenAI Realtime and GPT-Live context updates now include recorded answers, declined or skipped fields and the field currently awaiting an answer. The runtime remains authoritative and still allows only one declared field per turn.
- Decision memos now include each intake answer’s utterance ID and timestamp alongside the transcript, matching the audit detail in
intake.json.
The profile remains an explicit operational profile: fields, purpose, question limit and consent are declared in the contract. Oathra does not infer personality, demographics or sensitive traits, and it does not continue after refusal, ambiguity, a hold or a time-pressure signal.
Verification
pnpm test -- --runInBand: 655 passed, 1 skipped credential-gated LiveKit test.pnpm exec vitest run providers/openai-realtime/src/realtime.test.ts providers/simulator/src/simulator.test.ts: 25 passed.pnpm build,pnpm typecheck,pnpm lint:deps,pnpm build:siteandgit diff --checkpass.oathra play scenarios/restaurant/restaurant-reservation-intake.yaml --fast --json --no-savereturnsresult.status: completed,intake.status: complete, two explicit answers and no declined fields.
The Arena recording remains a simulator demonstration, not a real phone call or a PSTN success-rate claim. Real phone providers still require their own credentials and staged testing.
Oathra v0.1.14
Oathra v0.1.14
v0.1.14 makes optional intake consent transparent in the spoken call.
- The runtime now reads the declared collection purpose before asking the consent question when the configured
consentPromptdoes not already contain that purpose. - Brain-kit, GPT-Live and OpenAI Realtime instructions use the same rendered consent line, so local simulation and phone transports share the wording.
- A prompt that already states its purpose is kept unchanged; callers do not hear duplicate wording.
- The existing boundary remains: required mission details and constraints settle first, consent is asked once, one declared field is asked per turn, and refusal, hold, ambiguity or an unmatched choice stops collection.
The resulting record still contains only explicit answers to contract-declared fields. intake.json and summary.md keep the consent provenance, answers, utterance IDs and timestamps; no caller attribute is inferred.
Verification
pnpm test -- --runInBand: 655 passed, 1 skipped credential-gated LiveKit test.pnpm build,pnpm typecheck, andpnpm lint:depspass.oathra play scenarios/restaurant/restaurant-reservation-intake.yaml --fastspeaks the purpose before consent and records both declared answers.
The Arena recordings remain simulator demonstrations, not real phone calls or a PSTN success-rate claim. Real phone providers still require their own credentials and staged testing.
Oathra v0.1.13 — latest CLI and intake fixes
Oathra v0.1.13
v0.1.13 is a patch release that aligns the public CLI package with the latest main fixes after v0.1.12.
What changed
oathra play --jsonnow emits machine-readable JSON only, including the verified result, explicit intake answers, metrics and (when enabled) the saved call path.- Replay remains compatible with calls created before
intake.jsonexisted. - Declined or ambiguous follow-up intake is labeled as a follow-up record, never as a consented profile.
- Optional intake waits for every required mission constraint to be known and satisfied before asking for consent.
The scene-aware, consented intake boundary from v0.1.12 remains unchanged: questions are contract-declared, one field is asked per turn, and refusal, hold, ambiguity or an unmatched choice stops collection without saving a guessed value.
Run the public package without an API key:
npx --yes --package=https://github.com/FORIFOR/oathra/releases/download/v0.1.13/oathra-0.1.13.tgz oathra demoThe Arena recordings are simulator demonstrations, not real phone calls or a PSTN success-rate claim. Real phone providers still require their own credentials and staged testing.
Validation on the tagged source: typecheck, 654 passing tests with one credential-gated LiveKit test skipped, scenario validation, build, site build, dependency lint, package smoke, false-completion evaluation and adversarial evaluation.
Oathra v0.1.12 — scene-aware consented intake
Oathra v0.1.12
v0.1.12 makes consented follow-up intake aware of the conversation scene. A phone agent can gather a small, purpose-bound operational profile after the required outcome is settled without repeatedly pressing the callee or guessing unstated traits.
What changed
- Added
startAfterprerequisites so optional intake begins only after the declared mission conditions are verified. - Added
dependsOnbranching so a later question is asked only after its prerequisite field has an explicit answer. - Added
choicesfor canonical answers; unmatched or ambiguous choices are treated as non-answers. - Refusal, hold, hedge, question, ambiguity or any other non-answer ends optional intake immediately, even when an older contract sets
stopOnDecline: false. - Decision memos include explicit operational-profile answers, skipped dependency branches, utterance IDs and timestamps.
- The Arena, simulator and provider prompts use the same boundaries, so local demonstrations and phone integrations share the contract.
Scope
The profile is built only from answers the callee explicitly gives to declared questions. Oathra does not infer attributes or sensitive traits, ask undeclared questions, or continue after refusal. maxQuestions defaults to three and is hard-capped at eight.
Run the public package without an API key:
npx --yes --package=https://github.com/FORIFOR/oathra/releases/download/v0.1.12/oathra-0.1.12.tgz oathra demoThe 48-second intake recording at https://forifor.github.io/oathra/#intake-video uses the built-in Arena simulator; it is not a real phone call or a PSTN success-rate claim. Real phone providers still require their own credentials and staged testing.
Validation: typecheck, 652 passing tests with one credential-gated LiveKit test skipped, scenario validation, build, site build, dependency lint, package smoke, false-completion evaluation and adversarial evaluation all passed before publication.
Oathra v0.1.11 — provisional confirmation guard
Oathra v0.1.11
v0.1.11 carries the provisional-confirmation guard into the public package. Phrases such as 仮押さえ, 未確定, 承認待ち and 確認待ち no longer satisfy a reservation confirmation until the callee gives a later, unambiguous commitment.
What changed
- Expanded conservative hedge detection for provisional, pending-approval and confirmation-needed Japanese phrases.
- Added 500 regression cases covering 25 provisional phrasings across 20 numeric conditions; a later independent confirmation can still complete the call.
- Added the enterprise-readiness evidence record and reproducible validation commands.
- Kept the v0.1.10 consent-based intake flow: consent once, one declared field per turn, stop on decline, hold or ambiguity, and save only explicit answers.
Scope
The guard is tested against the scripted simulator and does not establish a live PSTN success rate. Oathra still does not infer a callee profile or collect undeclared or sensitive attributes.
Install the public GitHub asset:
npx --yes --package=https://github.com/FORIFOR/oathra/releases/download/v0.1.11/oathra-0.1.11.tgz oathra demoValidation on the release source: typecheck, build, 648 passing tests with one credential-gated live test skipped, scenario validation, false-completion evaluation, adversarial evaluation and package smoke. The main branch has since added intake provenance hardening and now reports 649 passing tests; the tagged tarball remains immutable for reproducibility.
For first-time setup, see the Japanese setup guide or English setup guide. The current branch also documents security reporting and the integration contract.
v0.1.10 — consented intake Arena demo
Oathra v0.1.10
v0.1.10 packages the consent-based follow-up intake demo and the YAML scenario handoff in the public GitHub asset.
What changed
- Added the built-in
restaurant-reservation-intakeArena mission and an intake panel that shows consent, question count and explicit answers. - Added Japanese and English simulator recordings with captions, plus the scenario and local command in the README.
- Hardened the video renderer's Chrome startup wait and made its capture/render ports configurable.
Safety and scope
Intake starts only after required mission fields settle. It asks one declared field per turn, records explicit answers with utterance IDs and timestamps, and stops on decline, hold or ambiguity. Oathra does not infer a callee profile or collect undeclared or sensitive attributes.
The public package is distributed as the GitHub Release asset until npm publishing credentials are configured:
npx --yes --package=https://github.com/FORIFOR/oathra/releases/download/v0.1.10/oathra-0.1.10.tgz oathra demoValidation: local typecheck, build, 148 passing tests with one credential-gated live test skipped, scenario validation, false-completion eval, 10,000-run adversarial eval and package smoke are required in CI.