Releases: LockedinLabs-AI/agent-console
Release list
Agent Console v0.4.1
Agent Console 0.4.1 is a security release. Everything in 0.4.0 is unchanged for users.
What's new
- Code-scanning findings closed. Every runtime finding was traced from its source to its sink. Two real defects, both reachable only by the machine's own operator, are fixed: an oversized
AGENT_CONSOLE_POLL_MSis capped at one hour, and a corrupt saved reading position restarts that transcript. The rest were hardened in code or dismissed with a written reason. - Hardened release pipeline. Release scripts take only validated inputs, run programs without a shell, and every third-party GitHub Action is pinned to a full commit SHA.
- SBOM. Each release now carries a CycloneDX software bill of materials, listed in
SHA256SUMSand attested. - Security documents. Threat model, data flows, NIST SSDF mapping and an enterprise security FAQ. OpenSSF Scorecard runs on every change.
Install
- One line (Node.js 22+):
npx --yes https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.1/lockedinlabs-agent-console-0.4.1.tgz --open - Homebrew:
brew install lockedinlabs-ai/tap/agent-console - Without Node.js: standalone executables for macOS (signed and notarized by Apple), Linux and Windows. See docs/standalone-install.md.
Every file is listed in SHA256SUMS and carries a signed build attestation (gh attestation verify <file> -R LockedinLabs-AI/agent-console).
Full notes: CHANGELOG.md.
Signing, per platform
- macOS, Apple silicon (
agent-console-darwin-arm64and its.tar.gz): signed with an Apple Developer ID (Team ID643FW3ZH6M, hardened runtime) and notarized by Apple. It opens without a Gatekeeper warning, whether installed withinstall.sh, Homebrew or a browser download. - macOS, Intel (
agent-console-darwin-x64and its.tar.gz): signed with an Apple Developer ID (Team ID643FW3ZH6M, hardened runtime) and notarized by Apple. It opens without a Gatekeeper warning, whether installed withinstall.sh, Homebrew or a browser download. - Linux, x64 (
agent-console-linux-x64and its.tar.gz): Linux has no code-signing scheme for it;SHA256SUMSand the build attestation are the check. - Linux, arm64 (
agent-console-linux-arm64and its.tar.gz): Linux has no code-signing scheme for it;SHA256SUMSand the build attestation are the check. - Windows, x64 (
agent-console-win32-x64.exe): not code-signed; there is no Authenticode certificate. Install it withinstall.ps1, which checks it againstSHA256SUMSbefore copying it into place, or use Node.js (npx.cmdor the npm package). Downloaded in a browser instead, SmartScreen may warn before its first start, and Smart App Control refuses it. - npm package (
lockedinlabs-agent-console-<version>.tgz): covered bySHA256SUMSand a signed build provenance attestation (gh attestation verify <file> -R LockedinLabs-AI/agent-console); on npm it carries npm provenance.
The check at the start of every join command has SHA-256 77aea0b4b487f2e39065b5739377f16678d6977b0fbd6d1ab0ef901052e581bc (README, "The check in every command").
Agent Console v0.4.0
Agent Console 0.4.0 is a redesigned console, more accurate data, and signed macOS downloads.
What's new
- A redesigned instrument. Console, Team and Projects keep the dense dark layout, now with raised cards, waves for every activity series, and eight sessions in frame at 1440×900. The light theme and phone layouts match.
- 30 days on first install. The first read goes back 30 days on the console and on every joined machine, and re-reads never double count. Archived Codex threads,
CLAUDE_CONFIG_DIRandCODEX_HOMEare read. - Honest numbers. Every estimate says it is one. Partly counted figures carry a floor mark. Unknown readings are drawn as voids with their reason, never as zero.
- Many machines, one truth. Each machine keeps its own session lanes, retries and restarts never double count activity, and sharing coverage is explicit.
- Presenting mode (P). Every project, machine and person gets a stand-in name, and no folder or program path remains in the page.
- Quieter and safer.
- Idle CPU is down from about 48% of a core to under 2%.
- A newer version never opens an older console that is still running.
- Join links pick a reachable address on Windows and WSL.
- Failed downloads behind a proxy say how to fix it.
Install
- One line, nothing installed (Node.js 22+):
npx --yes https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.0/lockedinlabs-agent-console-0.4.0.tgz --open(add--demoto look around first). - Without Node.js: a standalone executable for macOS (signed and notarized by Apple), Linux and Windows. Windows executables are not code-signed yet; use
install.ps1. See docs/standalone-install.md. - Team hub:
ghcr.io/lockedinlabs-ai/agent-console:v0.4.0on Linux.
Every file is listed in SHA256SUMS and carries a signed build attestation (gh attestation verify <file> -R LockedinLabs-AI/agent-console). The check at the start of every printed command has SHA-256 77aea0b4b487f2e39065b5739377f16678d6977b0fbd6d1ab0ef901052e581bc.
Full notes: CHANGELOG.md.
Signing, per platform
- macOS, Apple silicon (
agent-console-darwin-arm64and its.tar.gz): signed with an Apple Developer ID (Team ID643FW3ZH6M, hardened runtime) and notarized by Apple. It opens without a Gatekeeper warning, whether installed withinstall.sh, Homebrew or a browser download. - macOS, Intel (
agent-console-darwin-x64and its.tar.gz): signed with an Apple Developer ID (Team ID643FW3ZH6M, hardened runtime) and notarized by Apple. It opens without a Gatekeeper warning, whether installed withinstall.sh, Homebrew or a browser download. - Linux, x64 (
agent-console-linux-x64and its.tar.gz): Linux has no code-signing scheme for it;SHA256SUMSand the build attestation are the check. - Linux, arm64 (
agent-console-linux-arm64and its.tar.gz): Linux has no code-signing scheme for it;SHA256SUMSand the build attestation are the check. - Windows, x64 (
agent-console-win32-x64.exe): not code-signed; there is no Authenticode certificate. Install it withinstall.ps1, which checks it againstSHA256SUMSbefore copying it into place, or use Node.js (npx.cmdor the npm package). Downloaded in a browser instead, SmartScreen may warn before its first start, and Smart App Control refuses it. - npm package (
lockedinlabs-agent-console-<version>.tgz): covered bySHA256SUMSand a signed build provenance attestation (gh attestation verify <file> -R LockedinLabs-AI/agent-console); on npm it carries npm provenance.
Agent Console v0.3.0
Agent Console 0.3.0 adds context and cache health, local activity alerts, project policy controls, and background reporters. Console, Team and Projects share the same accounting core and expose missing readings explicitly.
- Inspect sessions, subagents, people, machines and projects from the working view. Graphite and light themes include mobile layouts and keyboard navigation.
- Read token classes, model estimates, partial history and reporting freshness without converting unknown values into zero. Copied subagent records are deduplicated and saved historical estimates are not silently repriced.
- Keep reporters running in the background with one process per state directory, persistent enrollment and explicit leave/stop behavior.
- Opt into project-scoped policy files and separate metrics read/ingest credentials. Starting the Console does not install project policy.
- Install a checked package or standalone executable. Release assets carry SHA-256 checksums and build attestations; installation checks run against the uploaded artifacts.
Upgrade the Console before its reporters. Version 0.3 reporter records are not accepted by a 0.2 Console. Upgrading from 0.2.1 also includes the 0.2.2 sign-in security changes, so sign in again after the upgrade. Networks using the carrier-grade NAT range, including Tailscale, require the explicit --allow-cgnat option. Metrics scraping and ingestion use separate scoped tokens.
Estimates use the documented price basis and are not invoices. Team and Projects activity charts show their labelled last hour even when the headline period changes. Generated demonstration data stays marked and separate from measured activity.
The check at the start of every join command has SHA-256 114422b34fdc2721cd70e125908fe2ef381b4afddf6c7317d3e540710ec03737 (README, "The check in every command").
Agent Console v0.2.2 — security update
Agent Console v0.2.2 fixes join-link command injection, prevents the console's admin key from being sent to another process holding its port, and replaces the reusable session credential with revocable per-browser sessions. Users of v0.2.0 and v0.2.1 should upgrade. Browsers must sign in again after upgrading.
This release also includes accounting conformance fixes and collector performance improvements. See CHANGELOG.md and SECURITY.md in the package for details.
Source: 2910bca. The release workflow passed and attached lockedinlabs-agent-console-0.2.2.tgz and SHA256SUMS with a GitHub build provenance attestation. The downloaded archive passed independent checksum and provenance verification, an offline clean install, console startup, sign-in and authenticated API checks. Anonymous API access was refused as expected.
This is the v0.2.2 security patch. It does not include the pending v0.3 UI redesign or private Enterprise gateway activation.
Agent Console v0.2.1
Safer by default, and the fixes from a first-time install.
Security
- Agent Console now comes only from its GitHub release. The console no
longer serves the package to machines that join, and every command it prints
installs the release over HTTPS. From this release on, CI builds each release's
package with a published SHA-256 and a signed build attestation. - Reports are encrypted and pinned. Joining and reporting go over TLS to a
certificate the console makes for itself; the join link carries its
fingerprint, and the reporter talks to that certificate only. - The console is signed in, and never on the network. It listens on
127.0.0.1 on its own port and needs a sign-in cookie;--openand the
sign-in link printed at start set it. Other machines use a separate port
(normally 6788) that serves only joining and reporting, refuses callers
outside private networks unless--allow-public, and refuses proxied requests
to the console. - Joining is harder to guess. Links carry a 128-bit code that lives at most
an hour; attempts are counted before they are read. - The console checks every record's exact shape, keeps usage one file per
day, reads it back line by line, and limits each machine to 250,000 records a
day, so a bad or hostile reporter cannot stop it from starting. - The reporter trusts nothing it is sent. It checks every identifier a
console returns and strips control characters before printing. Project hashes
use a key only the reporting machine holds. Leaving out
--share-project-namesstops names at once, andleavedeletes everything
the enrolment left behind.
Fixed
- A machine with a large history now finishes uploading. It keeps every batch
the console accepted, resumes where it stopped, honours the console's pacing,
and shows "catching up · N of M records" meanwhile. The console no longer
shows it as "Reporting · now" until everything has arrived. - The reporter says what actually went wrong instead of always "cannot reach
the hub". - Messages count API responses, not transcript lines (the count was 64% high
for Claude). Tokens were never affected. - The burn rate shows "unpriced" instead of "$0.00/hour" for models without a
verified price. - A busy port: a second start points at the console already running; another
program on the default port moves the console to the next free one. - The first read of a long history shows its progress, and the browser opens
after two seconds.
Added
- Claude Opus 5.5 pricing, from Anthropic's published pricing page
(checked 2026-09-22). --version, clearer install steps, the full LockedIn Labs lockup in the
README, and the community and licence files an open-source project needs.
Changed
- Machines that joined a 0.2.0 console join again with a new link.
- The v0.1 detail endpoints (
/api,/api/history) and the embeddable panel
are gone; the Projects view now reads the console's own data.
Agent Console v0.2.0
Many machines, one console. Agent Console now shows the AI coding agents on
every computer you connect, in LockedIn Labs' console design.
- Connect other computers by link. One computer runs the console (the hub);
Add a machine makes a join link with a single-use code that expires in 30
minutes. The other computer opens it and runs one command —npxfetches
Agent Console from the hub itself — and it starts reporting within seconds.
Each machine gets its own device token, stored privately on that machine and
kept on the hub only as a verifier; Remove revokes it at once. The console
shows who joined and when. - A team view. The total across every machine, and per machine and per
person — tokens, share, cache read and cache write shares, model split and
list-price cost, over 24 hours or 7 days. One person's several machines (or
several accounts) roll up into one row; a transcript copied between machines
is counted once. - The console, redesigned. The terminal look is gone. IBM Plex (shipped with
the package, SIL OFL 1.1), a graphite ground, one cobalt accent, colour only
for state, light and dark themes. The band shows tokens for the last 24 hours
with the cache read / cache write / output / input split and each class's share
of all tokens; tokens over time (1H · 24H · 7D); burn right now in tok/min and
tok/s with per-model share and spend; and one lane per session with its model,
hour of activity, five-minute tokens, subagents and machine. Show unavailable
and Pause motion sit in the band's header. One animation loop, text redrawn at
most eight times a second,prefers-reduced-motionhonoured. - Honest gaps. A machine that stops reporting shows when it was last heard
from, is left out of "right now" by name, and its lanes read unknown rather
than zero; the chart marks where it becomes incomplete. A missing token class
makes a total a floor, and an unpriced model is excluded from dollars and named. - The collector. LockedIn Labs' dependency-free collector is now part of the
package (lib/collector/, with its tests and contract):
portable salted record identity, cursors per destination, a write-ahead spool,
bounded retries, and a verified offline price table covering current Claude
and OpenAI models. - Privacy, proven. Only counts, model ids, timestamps and salted hashes leave
a machine. An end-to-end test runs real reporter and hub processes over
canary-filled transcripts and checks every byte on the wire and on disk.
--share-project-namesis the one opt-in, and sends a folder's name, never
its path. - Network posture. The hub still binds
127.0.0.1by default.--listen
opens only the join page, the package, the join exchange and token-checked
reporting to other computers, with a printed warning; the console and every
administrative action answer only on the hub's own computer. - Demo mode is a synthetic team of five machines, stamped DEMO on every
view, reading nothing and accepting no machine. - Projects (tokens and Git delivery evidence for the hub's own computer) is
one click away instead of on the first screen.
Breaking: Node.js 22 or newer is required. The v0.1 session-roster page and its
browser modules are removed; /api, /api/history and <agent-console-panel>
still work.
Limits: the reporter runs while its window is open (no background service is
installed); on Windows, CI covers the hub, collector, joining and reporting but
not yet the Projects view; the hub serves plain HTTP, so use it on a network you
trust or behind a VPN or tunnel.
Agent Console v0.1.0
Agent Console is a standalone local observability tool for Claude Code and Codex. It preserves the compact dark console: sessions, subagents, token composition, model costs, activity history, and delivery evidence. No account or coordination protocol is required.
Install with Node.js 18+:
npm install --global https://github.com/SamSnead85/agent-console/releases/download/v0.1.0/lockedinlabs-agent-console-0.1.0.tgz
agent-console --openOr clone the repository and run node bin/agent-console.mjs --open; no dependency install or build step is required. Use --demo --open for synthetic data.
This release adds verified Fable 5.1/Mythos 5.1 cache pricing, preserves unknown subagent costs, excludes metadata journals from agent counts, makes coordination opt-in, adds configurable transcript paths, and exposes exact history-bucket details on hover.
Validation: 327 tests passed locally. All six GitHub CI jobs passed on macOS/Linux with Node 18, 22, and 24, including isolated packed-install page/API/history checks. Desktop and mobile browser checks passed. Repository screenshots use synthetic data.
Scope: collection is local. Codex lifetime counters remain separate from Claude period totals and are not priced. API-equivalent cost estimates are not subscription bills. Native desktop installers, personal multi-device aggregation, and team views are not implemented in this release.
The tarball and SHA256SUMS are attached. Distribution is through GitHub; no npm-registry publication is claimed. MIT license; redistribution authorization is recorded in PROVENANCE.md.