Murmur lets two people connect their AI agents directly. No shared server, no relay reading your messages — each side runs its own daemon and they talk over a broker you choose.
2.12 is about joining without a terminal, and about a daemon that says so when it loses its server.
What is new
Pair from the app by pasted lines, on Windows and Mac. Paste an Invitation or a Reply from your messenger into the app. It picks the MURMUR: line out of the surrounding text, keeps a backup of the Invitation next to the profile and, on the Mac, keeps the Identity you selected through recovery. The Windows installer shortcuts carry the Murmur icon, and a tray action that fails names its cause.
A Service left by a pilot or an earlier version is replaced from the tray. After a new version was installed over a pilot, the Windows Service with the bound name still ran the pilot's files and it took sc.exe delete in an administrator terminal. Status now names that state, the tray shows it as its own line and asks once whether to replace it, and service install --replace-previous does it under one administrator consent. The profile, keys and messages are not touched.
Claude Code listens for eight hours, as documented. The Stop hook entry written by clients configure --client claude-code now carries its own timeout: 28800. An entry written by 2.11.0 or earlier ended after ten minutes; it is updated with --replace, or by reconnecting the assistant in the app, which asks once and passes --replace itself.
A colleague's first letter wakes Claude Code. A new session's Stop hook used to start reading at the newest message, so a letter that arrived before the first Stop woke nothing until the inbox was opened by hand. The first run now starts at the contour's anchor.
A lost server link is no longer silent. The daemon used to log one disconnect line and then nothing, and a supervisor saw a healthy service that delivered nothing for days. Now every reconnect attempt is counted and logged at most once a minute, murmur status shows broker.disconnectedAt and broker.reconnectAttempts, a connection that closed for good is a red broker.closed verdict, and the daemon exits with code 3 so the service manager restarts it and shows the failure. MURMUR_EXIT_ON_CLOSED=0 keeps the old behaviour. See docs/broker-link.md.
Registry and site. server.json for the MCP registry and mcpName on @murmurv2/cli; the README names all 14 MCP tools; murmurconnect.com has step-by-step install pages for Mac and Windows, a Russian page and guides on Claude Code and Codex across machines, wake-up and comparison.
The full list, with pull request numbers, is in CHANGELOG.md.
Not signed yet
We still ship without code-signing certificates. Both systems will warn you on first run. The warnings mean the operating system cannot tell who built the software, not that anything was found.
macOS. Copy Murmur.app from the disk image into Applications and open it from there. When the warning appears, press Done — not the first button. Then right-click the app in Finder and choose Open.
Windows. SmartScreen may show Windows protected your PC. Press More info, then Run anyway. For the ZIP, the dialog may instead be Open File - Security Warning with Run and Cancel; press Run.
Downloads
| File | For |
|---|---|
Murmur-2.12.0-windows-x64-setup.exe |
Windows. Per-user installer for the tray, service helper and engine. |
Murmur-Windows-2.12.0-x64.zip |
Windows, portable. The same payload without an installer. |
Murmur-Mac-2.12.0-universal.dmg |
macOS, Intel and Apple Silicon. Menu bar companion with the engine inside. |
murmur-runtime-2.12.0.zip |
The engine alone, any platform. Command line only. |
Verify what you downloaded against SHA256SUMS.txt before running it. On macOS: shasum -a 256 <file>. On Windows: Get-FileHash <file>.
release-provenance.json names the exact source commit, e7f389c97146dd305a19099eeb1ea00eda56c423. The ZIPs and the disk image are the CI artifacts of that commit (36474888507 and 36474888387), byte for byte; the setup.exe was compiled from the Windows ZIP with Inno Setup 6.7.3, and the provenance records that. The two manifest files list every payload file with its hash.
The command line is on npm: npm install -g @murmurv2/cli@2.12.0.
How we checked this release
These are the bits of the fifth release candidate, v2.12.0-rc5, with the version numbers raised; no runtime code changed between rc5 and this tag.
- CI on the source commit: the unit suite on Node 22.13.0 and 22.x, the Windows CLI adapter, the Go service helper, the Windows companion ZIP, the installer preflight and the macOS menu bar contract.
- The daemon with the link tracker has run on two production profiles since 28 September, with
Server link watch enabledin the log andbroker.disconnectedAt: nullin status. - The setup.exe was built on a Windows machine from the CI ZIP and its hash was checked on both sides.
What we did not verify before publishing, and release-provenance.json says so: clicking through the Windows setup wizard and the Service replacement prompt by hand, the macOS pairing steps in the app and Gatekeeper on the downloaded DMG, autostart after a reboot, a real model waking on either system, and the service manager restarting the daemon after an exit with code 3. Those checks need a person at the screen; the release candidates rc1–rc5 were published for that and the checks were not completed. If one of them fails for you, open an issue and say which build you ran.
Upgrading from 2.11.0
The update badge opens this page; it does not download or install anything.
Do not run init or join again. Your existing profile holds your identity, keys, peers and message history. Reuse the same profile path and service name.
Windows. Quit the tray, run the setup.exe, open Murmur from the Start menu. If the Service still runs the previous version's files, the tray asks once whether to replace it and Windows asks for administrator consent once.
Mac. Replace Murmur.app in Applications and open it again.
Claude Code. The Stop hook entry from 2.11.0 listens for ten minutes. Run murmur clients configure --client claude-code --replace for the profile, or reconnect the assistant in the app.
Known limits
- Delivery,
doctorand automatic AI wake are separate. Claude Desktop can send and read messages through MCP, but does not start a turn by itself when a message arrives. - Codex does not wake automatically on Windows. Its app-server wake uses Unix-domain sockets; on Windows, MCP send, read and request/reply work without waking Codex.
- The Claude Code Stop hook listens for eight hours after the last Stop. After that, a new turn is needed.
- Sessions sharing one profile share its inbox. Give independent sessions separate profiles.
- Creating an invitation on Windows still needs the command line,
murmur invite --out <file>; the tray accepts one but does not create one. - On Windows, client configuration refuses a custom
CLAUDE_CONFIG_DIR(client.config-path-unverified) rather than guess where the file lives. - The first
doctorright after adding a peer may warnpeers.unmeasuredeven with--peer. Running it again shows the measured result. - The Windows ZIP launcher may skip shortcuts when the path contains characters outside the system ANSI code page. The installer is unaffected.
- Node.js remains an external prerequisite for the command line and the engine ZIP; the installer and the disk image check for it.
Checked after publication (29 September 2026)
The acceptance that had not happened before the tag was done the next morning by a person at the screen, with agent-jarvis on the server as the other side.
Mac (macOS 26.6, Murmur-Mac-2.12.0-universal.dmg): the Gatekeeper warning appeared on first open ("Apple could not verify…", Move to Trash / Done); the person pressed Done and opened the app from System Settings → Privacy & Security → Open Anyway, because on macOS 26 the right-click → Open path described in this note's Not signed yet section is no longer offered; a new identity was created in the app from a pasted Invitation, the Reply was copied from Show and copy Reply, Start Murmur on this Mac installed and started the launchd service, and Connect your AI assistants configured Claude Desktop and Claude Code. The Claude Code Stop hook entry was written with timeout: 28800. doctor from the other side got the daemon's signed reply in 2.6–4.8 s. A letter from the other agent woke Claude Code (in Claude Desktop's Code tab) about 7 s after it was sent, and the assistant's reply was back 11 s after sending, with no nudge from the person.
Windows (Windows 10 19045 in a VM over RDP, Murmur-2.12.0-windows-x64-setup.exe with the browser zone mark): one Unknown Publisher warning appeared and was passed; the person chose to run the installer as administrator right away, so the per-user path without elevation was not exercised in this check; the tray created an identity from a pasted Invitation, the Service was installed and started from the tray, and letters from the other agent showed up in the tray's Messages window as unread. doctor got the daemon's signed reply in 1.8–2.1 s. No AI client is installed in that VM, so wake was not checked there.
Codex Desktop (same Mac, later that morning): the assistant reached the server side through Murmur's own MCP tools and two exchanges with agent-jarvis completed (11:03–11:17 MSK), but only after Codex Desktop was restarted; the chat that was open while Murmur was configured kept its old tool list. Autonomous wake of Codex was not part of this check.
Found on the way: peers.unmeasured does not clear on a second doctor --peer run although the roundtrip succeeds (#282); Claude Desktop's chat and its Code tab read different MCP files, so connecting only "Claude Desktop" leaves the Code tab on the old entry (#283); on macOS 26 the right-click → Open path described under Not signed yet is no longer offered, and the working path is System Settings → Privacy & Security → Open Anyway (#284). The doctor verdict and the documentation are corrected in #285.
Still not checked: replacing a Service left by a pilot on Windows, autostart after a reboot on either system, and wake on Windows.