Releases: NotTahaAli/sessclone
Release list
v0.5.0
Deploy the web app first: the status bar's link opens /sessions/<id> without a member, which older deployments answer with a 404. Then installs pick the plugin up with /plugin update sessclone@sessclone. No migrations.
Added
- On Claude Code 2.1.287 or newer, a line above the prompt shows whether the key is connected and to which Org, whether this session is synced or how many Turns it is behind, what is queued, and
↗, which opens this session in the dashboard. /sessclone-statusand/sessclone-syncrun at once, without a Claude turn; status also says how many of this session's Turns are not sent yet. Where mods cannot load,/sessclone:statusand/sessclone:syncstill work as before, and are hidden from the menu where they can.- A Session's page opened without
?member=shows the viewer's own Session in the active Org.
v0.4.1
Deploy the web app, then installs pick the plugin up with /plugin update sessclone@sessclone. No migrations.
Added
- Approving an Org from the Admin panel emails its Owners that they are in, with a link to start, when SMTP is set. The waiting page says so instead of asking them to reload it.
- A new key shows the whole setup in order (add the marketplace, install with the key, restart Claude Code), and the empty Costs and Devices pages say what to do next.
Fixed
- On a Node older than 22.18, every session start says which Node Claude Code is running the hooks on, that nothing is being collected, and how to fix it (a newer
nodeon Claude Code's PATH, then a restart), instead of calling it a configuration problem. On a machine, the sessions from meanwhile are sent over the next session starts. - On that old Node, the per-turn archive hook no longer prints a stack trace into the session after every turn in a cloud container, and
scripts/verify-collector.mjsnames the Node instead of crashing.
v0.4.0
Upgrading from 0.3.0: deploy the web app before telling anyone to update the
plugin; the plugin's session-start key check uses the new GET /api/ingest.
No migrations. Installs pick the plugin up with /plugin update sessclone@sessclone. SESSCLONE_API_KEY is no longer read: enter the key at
the plugin's setup prompt instead.
Added
- The plugin carries its own icon, keywords, and documentation, support,
privacy and terms links, so Claude's plugin directory shows the SessClone
mark instead of the publisher's GitHub avatar and links to each page. - The Collector says, once, which Org it is reporting to when a session
starts, and says every session that it is not connected while the key is
missing or refused. /sessclone:statusshows the deployment, whether the key was accepted at
session start and for which Org, this Device, and what is waiting to send./sessclone:syncsends everything waiting at the end of that turn instead
of at the next session start.- A key the deployment refuses stops the Collector sending until a session
starts with a key it accepts, instead of resending history every turn. GET /api/ingestanswers the Org's name for a live key, and the same 401 as
a report otherwise.- The plugin has a README saying what it sends, where, and what it runs.
Changed
- The Collector no longer follows a redirect when it reports. A 301 or 302
would turn the report into the new key check'sGET, which answers 200 and
files nothing, so the Turns would be marked sent and lost. - The deployment URL defaults to
https://sessclone.com, so installing
against the hosted service asks for the key and nothing else. - The API key is read only from the plugin's setup prompt, never from
SESSCLONE_API_KEYin the shell. It may be left empty in a Claude Code
cloud environment whose SessClone API credential adds it, so the setup
script no longer carries a placeholder key. - Every email is restyled in the product's own look.
- Google Search shows the SessClone mark (
favicon.ico). - Sign-in, sign-up, invitation, new-Org and admin pages carry
noindexand
their own titles, and robots.txt no longer blocks sign-in, sign-up and
invitations, so search engines can read thatnoindex(a blocked page can
still be indexed from links). The unusedHost:line is gone. - A signed-out visit to a page that does not exist gets a 404 instead of a
redirect to sign-in, which search engines read as a soft 404. Only the
pages behind sign-in (the dashboard, admin, new Org) still redirect there. - A page that does not exist shows the site's own header and footer, the
address asked for, and links to the home page, docs, pricing and sign-in,
instead of Next's bare 404. - The home page's structured data names an Organization (name, logo, GitHub)
as the application's publisher, and the docs landing page has its own
description.
v0.3.0
Upgrading from 0.2.1: run 20260925190000_history_and_deletion.sql,
20260925190100_tier_limits.sql and 20260925210000_unwindowed_facts.sql
before deploying, and set SUPABASE_SERVICE_ROLE_KEY (server-side only) so the
retention sweep can remove a deleted account's sign-in.
Added
- Delete your account from Settings > You. It needs a recent sign-in and your
email typed out, then waits 14 days, during which you can keep the account.
After that your name, email, memberships, keys and transcripts are removed;
your Turns stay as "Deleted person". - Download all transcripts as one zip from the Transcripts page, filtered by
dates, people, projects and devices. A transcript that was active on any day
in the range comes whole. - Each Tier now has a history window: Personal shows 90 days of Turns, Team
365, Enterprise and Self-Hosted everything. Older Turns are hidden from
Sessions and Costs, not deleted.
Changed
- Transcript retention is capped per Tier: Personal keeps none, Team 90 days,
Enterprise a limit set per Org. Moving to a Tier without transcripts keeps
them 7 days, with a banner, then removes them.
v0.2.0
Upgrading a self-hosted copy from 0.1.0: set ENABLE_LANDING, ENABLE_DOCS
and ENABLE_DEMO to true for whichever parts you serve, since unset now
means off, and rebuild. Run the new migrations before deploying, except
20260925170000_drop_one_argument_accept.sql, which runs after
(docs/self-hosting.md).
Added
- An Org switcher: the Org name at the top of the sidebar, or of the phone
header, opens a list of your Orgs, including one still waiting for approval.
The Org you pick is remembered on that device. - Invitations in the dashboard: the switcher lists the ones sent to your
signed-in address, with Accept and Decline, and keeps an expired one for a
week so you can dismiss it. An Admin sees a declined invitation as declined
and can invite the same person again. - Leave an Org from the switcher. The only Owner is asked to make somebody
else an Owner first. - New Org, at the bottom of the switcher, which now always opens. It asks for
a name and, where sign-up asks for one, a plan; the new Org waits for
approval like a sign-up, or opens at once where approval is off. You can have one
Org of your own waiting at a time. The waiting page carries the switcher
too, so you can switch out of an Org that is waiting. It emails the platform
admins the same way a sign-up does, and just as little: nothing with
approval off, nothing once the Org is active. - A read-only live demo, off unless
ENABLE_DEMO=true: "Try the demo" beside sign-up
on the landing and pricing pages opens two made-up Orgs with six invented
people each and 60 days of generated usage and transcripts. Every page is
visible and every save answers "This is a demo". A daily
/api/demo/refreshkeeps the window current. The demo's Costs and Sessions
pages are cached per day, for the demo visitor only. A signed-in visitor
doesn't see "Try the demo", since their own account opens instead. - Browser tests: the repo's first Playwright suite (
apps/web/e2e, run with
pnpm --filter web e2e) accepts an invitation from the Org switcher and
starts a New Org from it. It signs in without a Supabase project and seeds
a*_testdatabase directly. ENABLE_LANDING,ENABLE_DOCSandENABLE_DEMO, eachtrueorfalse
and off when unset, so a self-hosted copy serves only the dashboard. With
the landing page off,/goes to sign-in or the dashboard and/pricingis
a 404; the privacy and terms pages stay. With the docs off,/docsis a
404 and docs links go to sessclone.com. A signed-in visit to/opens the
dashboard, and the dashboard's logo links back to the landing page.
Changing a flag needs a rebuild. Before deploying: set all three on
Vercel, for Production and Preview (truefor sessclone.com), and remove
DEMO, which nothing reads any more; unset, the landing page, docs and demo
are all off.- A sign-in that Supabase sends to the bare site with
?code=now continues
to/auth/callbackinstead of stopping on the home page. /.well-known/security.txt(RFC 9116), pointing to GitHub private advisories
and, when set, the deployment's contact address. Its expiry is always a
year ahead.
Changed
- The Collector plugin's version now follows the release, starting at
0.2.0. It was pinned at0.0.0, and Claude Code only updates a plugin
whose version changed, so/plugin updatereported every install as
current and kept the code it was installed with. Update once to pick up
everything since.
Removed
- The one-argument
sessclone_accept_invitation(text), kept only while the
Org switcher deployed. Migration20260925170000_drop_one_argument_accept.sql
drops it; nothing calls it.
Fixed
-
A hydration error on every dashboard page and on the waiting page: the Org
switcher was nested inside the brand line's<p>. -
Someone in more than one Org saw every Org's Devices, Keys and transcripts
on each Org's pages, and the oldest Org's appearance; they now show the Org
you are in. Settings, Members, Keys and invitation forms refuse to act on an
Org other than the one the page was opened for.
v0.1.0
The first public release.
Added
- The Collector: a Claude Code plugin that reports each Turn from hooks,
pushing from a per-transcript cursor with a retry queue, and working through
HTTPS_PROXYand in cloud containers. - Ingest: API-key-authenticated routes that record Turns, and archive
transcripts, subagent sidecars and workflow journals straight to storage
through presigned URLs. - Costs: per-model token pricing, spend per Session, Project and Member, a
cost drill-down, and an admin flow to fetch and review published pricing. - Sessions: listing, search, archive and hide, last Turn and last message
times, and a per-model token table. - A transcript viewer that reads as a chat, with Finder-style columns for
subagents and workflow runs, filters and presets, a per-message model and
token breakdown, and downloads of stored transcripts. - Chunked archival (ADR 0008): a growing transcript is stored as sealed ~1 MiB
gzip chunks plus a raw tail, so a steady turn uploads only its new bytes.
Older single-file transcripts and older Collectors keep working. - API keys and Devices per Member.
- Orgs with Roles, invitations, team transcripts, display names, and branding
(accent, theme, Org logo). - Tiers and pricing: Personal, Team and Enterprise per seat, prices edited on
the admin page and read live by the pricing page; paid tiers open as a
waitlist, and new Orgs wait for an admin's approval (SIGNUP_APPROVAL). - Separate sign-in and sign-up, with sign-up choosing a plan first.
- A marketing site and docs at
/docs, in light and dark, with indexing,
analytics and the contact address all driven by environment variables. - Retention: an Org's window, capped by its Tier, enforced by a daily sweep.
- Self-hosting: a Dockerfile,
compose.yamland a guide, free at any size
under AGPL-3.0-only with the additional term inNOTICE.md.
v0.2.1
Fixed
- A signed-in or demo visitor opening
/directly, and a sign-in link that
landed on/?code=…, got a server error on Vercel: the redirect's Location
was relative, which Vercel's Proxy runtime refuses. It now names the
deployment's origin (NEXT_PUBLIC_APP_URL, else the request's).