Releases: EverMind-AI/Raven
Release list
Raven 0.2.3 (2026-09-27)
Raven 0.2.3 is a patch release with two things worth reading before you upgrade. Bare raven now opens the browser page, the way raven web does, and falls back to the terminal UI only where no browser can be opened; raven tui still opens the TUI outright. And the page's own update row now works on a normal raven web install and shows the download's progress, but only once the page is served by this release: a page served by 0.2.2 or earlier still refuses it, so this one upgrade goes through the command line as before (#806). No command, flag or config key is removed or renamed. Two smaller removals on the page: the file viewer no longer offers a download button, and HTML previews run their scripts by default instead of asking (#805).
Highlights
Upgrade from the page
-
The update row at the bottom of the sidebar upgrades a
raven webinstall: the gateway hands the page its own graceful stop on every mount, exits cleanly on upgrade, and the helper waits for the supervisor, installs, and relaunchesraven web --superviseon the same port with the same token and cookie, so the page reloads itself still signed in. It is refused, each with its own reason, while a turn, a sub-agent or a question waiting for an answer is running (including in an IM channel), and for a Raven started by hand withraven gatewayorraven web --foreground, which has nothing to restart it (#806). -
The page shows what is moving. The helper downloads the release itself so the bytes can be counted, then answers
/upgrade/statuson the page's own port with phase, bytes and rate while the old Raven is gone; the card measures the bar while bytes are counted and says when the new Raven is starting. A failed install is held for the page to read before the old version comes back, instead of relaunching it silently. The twenty-minute ceiling now counts silence, not the whole upgrade, so a slow download that is visibly moving is not given up on (#806). -
The terminal
raven upgradeprints each asset's size and the total before downloading, then a live progress line, so a large release on a slow link no longer reads as a stalled install. The downloaded wheels stay under~/.raven/cache/upgrade/<version>(about 75 MB for a release with its engines); earlier versions' files are cleared (#806). -
raven gatewayrefuses a half-written install the wayraven servealready did: a gateway that starts inside an upgrade window waits it out and exits instead of serving the placeholder page until restarted by hand. The gateway also closes its websockets on shutdown, soraven web --stopwith a page open no longer waits on the page's own socket (46 seconds down to 4 ms in the PR's run) (#806). -
Bare
ravenopens the page, leaving the resident gateway thatraven webalways leaves. Where no browser can be opened it runs the TUI instead, decided before anything starts.raven webandraven tuiare unchanged (#806).
Desk panes
-
Every desk pane has one header that names what is on screen. The file path bar, the task status line and the node card's back-and-title row fold into it: a glyph or a back chevron, the title, a muted facts line, then the controls that act on the object. A picked node reads as "task > node"; narrow panes drop the parent crumb and keep the facts on their own line. Dragging a pane by its title works again (#805).
-
Stop leaves the palette's task list and lives in the task pane header, shown only while the task or the picked node is running. The runtime has no per-node cancel for a graph, so on a graph node it stops the whole run, and its tooltip says so (#805).
-
The file viewer no longer offers a download or the binary note's save-a-copy link; the conversation's delivery cards keep theirs. HTML previews run their scripts by default under
sandbox="allow-scripts", neverallow-same-origin, so the page keeps an opaque origin, and the "preview does not run scripts" note and its run button are gone. Trade-off: a previewed page can now make network requests of its own without a click (#805).
Grok Build and GitHub Copilot as coding agents
- Each connection problem the agent sheet asks about gets a named failure, and the command in each sentence is one the CLI's own help prints. A credential refusal says to run
grok loginorcopilot login; a binary that is installed but not on the login PATH Raven launches with is named by its location (Homebrew's prefix,/usr/local/bin,~/.local/bin) instead of being reported as missing; an invalid key, an expired sign-in, a model not served, no credit, an expired Copilot subscription, a rate limit, a network failure, an ACP server that did not start and a CLI too old to speak ACP are each their own sentence. A Copilot refusal that arrives as the assistant text of a finished turn is a failure, not a success (#792, #799).
Unattended turns and research
-
A question that an unattended turn could ask nobody is recorded instead of vanishing: a sub-agent
ask_useror elicitation with no page subscribed, a question that gives up waiting for the conversation lock, and a hostask_usercall whose answer comes back empty. The session stores aquestion_unanswerednotice that a reopened session draws, andraven agent -mprints the questions after the reply. The model is still told to proceed, and the exit status is unchanged: a refusal is still the run that exits 3 (#807). -
An interrupted research turn keeps the configured report structure. The tool-free synthesis is buffered, one format repair is requested when sections are missing, and only the selected reply is emitted; a failed synthesis produces a structured fallback, and wall-clock exhaustion gets an accurate time-limit fallback. The research flow's turn settings (wall-clock and retry budgets, ask labels, interrupted-reply guidance) now reach the loop (#808).
Experimental: the Curator
- The repository gains
experimental/, a first version of worker self-improvement: a Curator that shapes a Raven worker's harness (memory, planning, capability, action) from the task, the materials handed to it and feedback, at both levels of a harness-of-harnesses whose child agents are hosted over ACP. It is not in the wheel andraven/does not import it; the design is inexperimental/docs/design.md, and the README's self-evolution section now describes it (#802, #803).
Install
New install on Linux, macOS, or WSL2:
curl -fsSL https://raven.evermind.ai/install.sh | bashNew install on native Windows, in PowerShell:
irm https://raven.evermind.ai/install.ps1 | iexWindows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:
irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iexThe installer puts uv, Node.js 22, Raven and its plugins in place, downloads the
browser runtime, installs or offers LibreOffice, and then finishes by opening
Raven in your browser. First-run setup happens on that page. The installer holds
the terminal while the page is up; press Ctrl-C to stop it, then start Raven
again with:
raven webThat keeps Raven running in the background and opens the page; raven web --stop
stops it. From this release on, bare raven does the same, and opens the TUI
only where no browser can be opened. Prefer the terminal? raven tui runs the
same first-run setup and opens the TUI, and raven onboard stays the explicit
way to reconfigure later. Set
RAVEN_MINIMAL=1 to skip the browser and LibreOffice downloads, or
RAVEN_NO_LAUNCH=1 to have the installer return without opening the page.
Upgrade
Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved. From this release on the update row at the bottom of the page's
sidebar does this too, but a page served by 0.2.2 or earlier refuses it, so for
this upgrade stop the page first, then upgrade:
raven web --stop
raven upgradeOn Linux and macOS raven upgrade runs the install in the foreground and
returns when it is done. On native Windows it hands the install to a separate
helper and returns at once; wait for the helper's completion message. Then
start Raven again:
raven webraven upgrade installs the latest stable release together with the plugin
wheels it ships. It never picks up a pre-release unless this install has joined
the beta channel (a ~/.raven/beta.json that only the beta installer writes).
raven upgrade --check reports whether a newer release exists without
installing it. Editable source checkouts are never overwritten: raven upgrade
reports the checkout path and how far it is ahead of or behind origin/main,
and the remedy is git pull && ./install.sh in the checkout. Rerunning the
one-line installer also upgrades, and ends on the running page.
Release Status
- Version:
0.2.3 - Tag:
v0.2.3 - Stability: public preview patch
- Assets: the
ravenwheel and source distribution, the three plugin wheels
...
Raven Technical Report v1 (2026-09-27)
Raven: The Harness of Harnesses for Composable Agentic Intelligence
EverMind AI, September 2026
As large language models advance, AI agents are moving beyond isolated, domain-specific tasks toward long-horizon, cross-domain workflows. This transition exposes two challenges: increasing harness complexity makes manual design difficult to scale, while tighter coupling to specific domains limits the generality of a single harness. The central question thus shifts from how to engineer a stronger harness for one domain to how to autonomously construct specialized harnesses, improve them through experience, and orchestrate them across domains. We introduce Raven, The Harness of Harnesses, an open-source multi-agent ecosystem that automatically constructs and evolves modular harnesses for specific models and domains, treating each executable model–harness pair as a composable unit of intelligence. To support an All-Domain Collaboration Network, its Host Agent decomposes goals, matches subtasks to specialized agents, coordinates execution dependencies, and integrates results, while a host archive and EverOS preserve experience across tasks and Skill Forge makes that experience available as reusable procedures. Our theory establishes sufficient conditions for such composition to expand reliable task coverage beyond that of the available individual agents under a shared resource budget. On complex and long-horizon tasks, Raven significantly outperforms the state-of-the-art agent systems, pushing the frontier of composable agentic intelligence.
- PDF:
technical-report.pdf, 82 pages, SHA-25614832f50de158ca431d63acf5dd06dfcad05c54a70a8607a50ecd79170fff831 - The
tech-report-v1tag points at the commit of Raven v0.2.3, the latest software release when this report was published.
This is a documentation release, not a software release. To install Raven, use the latest release.
@techreport{evermind2026raven,
title = {{Raven: The Harness of Harnesses for Composable Agentic Intelligence}},
author = {{EverMind AI}},
institution = {EverMind AI},
year = {2026},
month = sep,
url = {https://github.com/EverMind-AI/Raven/releases/tag/tech-report-v1}
}Raven 0.2.2 (2026-09-25)
Raven 0.2.2 is a patch release with one thing worth reading before you upgrade: memory runs on native Windows now. No command, flag or config key is removed or renamed, and no configured default changes. The memory plugin's EverOS pin moves from 1.2.3 to 1.4.1, which runs on Windows without WSL, so the platform gate that made memory unavailable there is gone. Two guards found while verifying against a copy of a real 1.2.x store come with it: an embedding model narrower than the memory index is refused rather than left to answer 500 on every store and search, and an upgrade no longer leaves the old server answering on the port (#791).
Highlights
Memory on native Windows
-
The platform gate is gone.
everos_platform_noteand its five call sites, theUNSUPPORTEDservice state, the import scan's refusal and the wizard's WSL notice are removed, and Raven looks foreveros.exeon Windows. Spawning, probing and reusing the server were already portable; identifying and stopping one was not. The command line now comes from WMI through PowerShell, the listening port from the TCP table, walking the launcher's descendants to the interpreter that actually holds the socket. -
The server is spawned in a process group of its own, so a Ctrl-C at the gateway's console does not take it down with it, and stopped with Ctrl-Break, which uvicorn takes as a shutdown; one that ignores it for ten seconds is terminated as before. Because Windows cannot replace a running executable,
raven upgradestops whatever still runs from under the tool environment before it installs -- the memory server outlives the gateway by design, and without that stopuvfailed onScripts\everos.exe.
Two guards for the memory store
-
An embedding model narrower than the 1024-wide memory index is refused where it is pinned, and withheld from the server it would otherwise have started. A 768-dimension model saved from the settings page had left every memory store and search answering 500 about a mismatched width, with nothing on the page saying why. EverOS then runs keyword recall and keeps storing, and the notice names the model and its width. A probe that cannot reach the provider is not a verdict: the pin is written and a warning logged.
-
A running EverOS whose version no longer matches the installed one is replaced rather than reused, through the same precheck, stop and spawn chain a rotated credential takes. An upgrade used to leave the old server serving until something unrelated restarted it. A root you manage yourself is never touched. And a gateway that finds nothing listening and no lock held starts the server again, at most once every thirty seconds, so a server that goes away no longer leaves that gateway without memory until you restart it by hand.
Recall and the memory page
-
Recall on the Cases and Know-how tracks searches by vector when no reranker is configured, instead of asking for an LLM rerank that the four-second recall budget can never wait out.
-
The memory page reads the
/api/v2routes, asks/healthbefore a search the way the chat adapter does, and shows the server's own sentence on a refusal. A recalled profile is drawn as lines rather than anamespace(...)repr, a tool-call-only row stores empty content rather than the string"None", an empty query asks nothing, andtop_kstays within 1..100. -
The first-run wizard accepts an embedding model wider than 1024 (EverOS keeps the first 1024, as the settings page already allowed) and re-prompts on a refusal instead of showing a traceback.
Under the wire
- Every request body the plugin and the memory page send is validated against EverOS 1.4.1's own request models in the suite, so a schema move on the next upgrade fails a test rather than a gateway log. The upgrade is recorded in
docs/memory-plugin-architecture.mdsection 7.4.
Install
New install on Linux, macOS, or WSL2:
curl -fsSL https://raven.evermind.ai/install.sh | bashNew install on native Windows, in PowerShell:
irm https://raven.evermind.ai/install.ps1 | iexWindows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:
irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iexThe installer puts uv, Node.js 22, Raven and its plugins in place, downloads the
browser runtime, installs or offers LibreOffice, and then finishes by opening
Raven in your browser. First-run setup happens on that page. The installer holds
the terminal while the page is up; press Ctrl-C to stop it, then start Raven
again with:
raven webThat keeps Raven running in the background and opens the page; raven web --stop
stops it. Prefer the terminal? raven runs the same first-run setup and opens
the TUI, and raven onboard stays the explicit way to reconfigure later. Set
RAVEN_MINIMAL=1 to skip the browser and LibreOffice downloads, or
RAVEN_NO_LAUNCH=1 to have the installer return without opening the page.
Upgrade
Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved. Stop the page first, then upgrade:
raven web --stop
raven upgradeOn Linux and macOS raven upgrade runs the install in the foreground and
returns when it is done. On native Windows it hands the install to a separate
helper and returns at once; wait for the helper's completion message. Then
start Raven again:
raven webraven upgrade installs the latest stable release together with the plugin
wheels it ships. It never picks up a pre-release unless this install has joined
the beta channel (a ~/.raven/beta.json that only the beta installer writes).
raven upgrade --check reports whether a newer release exists without
installing it. Editable source checkouts are never overwritten: raven upgrade
reports the checkout path and how far it is ahead of or behind origin/main,
and the remedy is git pull && ./install.sh in the checkout. Rerunning the
one-line installer also upgrades, and ends on the running page.
Release Status
- Version:
0.2.2 - Tag:
v0.2.2 - Stability: public preview patch
- Assets: the
ravenwheel and source distribution, the three plugin wheels
(everos_memory,design_engine,ppt_engine), the locked constraints file
raven-constraints.txt, and the plugin listraven-plugins.txt
Notes
- Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
- PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.
Raven 0.2.1 (2026-09-24)
Raven 0.2.1 is a patch release: no command, flag or config key is removed or renamed and no configured default changes, but three behaviour changes are worth reading before you upgrade. The web first-run wizard now asks only for a model and, optionally, a search tool; its agents and data-sync steps are held back until they are ready, so a first run no longer offers to connect local agents, and until the step returns an import runs from raven import on the CLI (#784). exec on this computer now refuses a typed ssh to a machine the connection registry knows and names the two paths meant for it, while scp and rsync are untouched and an unreadable registry refuses nothing (#552). And a permissions.tools deny rule now stops the program it names however the command runs it, so bash -c, env, sudo, xargs, find -exec, a $(...) substitution or a redirection no longer walk past it (#783). The rest of the release is the agent connector (what a refused connect says, and where it is drawn), a round of web page fixes, and a -P guard that keeps a source checkout off the engine's sys.path.
Highlights
Connecting coding agents
-
A failed connect or test is now said under the agent rather than instead of it. Every card keeps one fixed shape with a slot that always speaks -- a grey word for the row's state, a single-line strip naming what failed and a short reason read off the remedy, amber while a write is in flight -- and the sheet keeps its 520x500 box, with the why and the how as a note at the top of the body: a title per remedy kind, the fix, the command on its own line, and the agent's own sentence folded under it. The card no longer carries the raw English sentence a server returned (#754, #785).
-
A refused Qwen Code connect names the fix and the command. A provider status the agent reports is classified (401/unset credential, 404 for a model it will not serve, 402 for credit, 429 for a rate limit, an unreachable provider, a launch that quit, a binary too old for
--acp), and the sheet shows the fix as two numbered steps: runqwen, then type/auththere./auth, not/model--/modelonly picks among the models already registered in~/.qwen/settings.json, and qwen 0.24.4's own OpenRouter preset registers two free models that OpenRouter has since withdrawn (#779, #786). -
A Qwen Code started on a Node.js that is too old says so. Qwen Code runs on whichever
nodecomes first on its launch PATH, and on 18.x it dies at import with aSyntaxErrorthat names no version. Raven now resolves the interpreter from the agent's shebang, reads the floor from the agent's ownpackage.json(>=22.0.0), and names both versions, withnvm install 22 && nvm alias default 22orbrew upgrade nodeonly where the installer shows in the path (#786). -
A refused Kimi Code connect says why instead of always asking for a sign-in. Kimi Code reports a session it cannot start as a bare
Authentication required, so Raven asks it once more the way a reader in a terminal would (kimi -p, in the launch's own environment, capped at 20 s), checks a config it cannot parse withkimi doctor config, and reads a signed-in account's own plan limits (a spent usage window as 403, a model above the tier as 401, an unverifiable membership as 402) before the status (#781). -
A missing
npxis answered with Node.js, not with the agent's own npm installer, and a connect gives a first download time to finish: the start gets the row'sreadyTimeoutMs(120000 ms on the npx presets) with the answer keeping its 60 s cap, and an npx fetch that failed is named by npm's own error-code line rather than reported as an agent that did not answer (#754). -
"Check again" finds an agent installed after the gateway started. The login-shell environment is captured once per process, so an installer's new PATH line was invisible until a restart; the sheet's re-check now asks
subagents.listfor a fresh capture (refresh_login_env, default false, so no other listing pays for a login-shell run), and the connect that follows launches on the PATH the probe found (#768). -
A row that has just connected stops wearing a stale warning. The writes a server answers by running the agent now ask for the probe on their follow-up read instead of carrying the previous verdict over it, the card's dot and the sheet's status line read one ranked verdict, and a write refused while a later one landed repaints from a fresh listing instead of from the rows it started with (#773, #769). The TUI's
/subagentsoverlay gets the same fix for its!glyph (#774). -
An API key already stored for an agent can be replaced from the sheet. An openai row whose stored key the endpoint rejects used to offer Connect, be refused with "change the key and press Retry", and have no field to change it in; the field is now drawn at every stage but live and stale, a typed key turns the press into Connect, and saving a key on a row that is off is followed by the switch that proves it (#788).
The web page
-
The first-run wizard draws its step before the data lands. The model step used to hold a "Loading..." line for 6.4 s on a warm install while the whole settings payload arrived; it now draws its real (empty) cards at 148 ms and fills in behind them (#771).
-
Task-board DAG edges no longer hide under the boxes they pass. Layout moves to
@dagrejs/dagrefor in-layer ordering and edge routing: an edge that skips a layer bends through the gap, edges meeting one face of a box get their own ports, and a root that feeds only a deep node stays on the first layer (#761). -
Running tasks get a stop button in the floating tasks list, so a stuck sub-agent can be stopped without opening its read-only context view. It reuses the existing calls --
subagent.cancel_instancefor a spawn,subagent.interruptfor a task graph (#764). -
The file bar gains a download button for every kind, so a file read on a remote serve can be saved to the reader's own machine; a file this session delivered is saved from its delivery, anything else from the route the viewer already reads it through (#770). In the same bar the rendered/source pair is now offered only on
md,svg,html,csvandjson, where the two positions actually differ -- a PDF no longer fetches its whole body to draw it as numbered lines -- and the new-tab, download and folder buttons form one group (#778). -
A spawn's task row opens the task pane however soon it is clicked. A click landing before the tasks store had filed the run used to open the agents panel's instance window instead; the opener now reads that one row with
tasks.listand retries while the record is still being written, falling back to the tasks list (#772). -
Settings pages get real empty states that tell "nothing here" apart from "service down": usage, archive, plugins, skills, providers, schedules, channels and memory share one shape (a mark, a title, one line, at most one control), a failed memory read takes the whole frame with a retry, and only rows with a panel to expand look clickable. The memory pager no longer slides under the pointer on a page turn (#775). Reopening the dialog no longer swallows the first click either: a reload that answers the same values leaves the page mounted instead of rebuilding every control about 670 ms in (#782).
Runtime, tools and providers
-
The machine registry has one reader and one writer, and the coding agent can add a machine. A sub-agent reads the owner's registry in
RAVEN_HOMErather than the empty state directory beside its rendered config, a host started with--configkeeps the list beside that config, andops_connection_addis a trunk tool served ontools.connectionAdd(off by default; on in raven-code and raven-oncall). It probes a machine the way the owner's own terminal would resolve it (ssh -G, each candidate key offered on its own) and writes nothing until the machine answers;raven ops connection addcalls the same functions (#690). -
A user
execdeny rule stops its program however the command runs it. Deny rules are asked first, about every command the string can be seen to run: shell wrappers and runners,$(...)and backtick substitutions read off the raw text, a keyword in front of a command,env -S,find -exec, a redirection, and the program compared by its bare name so a path prefix or a Windows.exesuffix does not hide it. Allow and ask rules are unchanged, and a heredoc body no shell reads is dropped first (#783). -
DeepSeek's shown API base is now
https://api.deepseek.com, nothttps://api.deepseek.com/beta, so saving a working key stops answeringCouldn't verify (http_404), saved anyway; `/b...
Raven 0.2.0 (2026-09-23)
Raven 0.2.0 is the first minor release since 0.1.13, and much of what it carries is new to a 0.1.13 install: a Web UI that raven web serves in the browser (rail, composer, transcript, settings dialog, Agent Connector and a desk with file, agent and task panes), permission modes at the tool-dispatch door, four built-in agents under agents/, the playbook engine, the ACP and A2A surfaces, the three plugin wheels the release publishes, and a Dockerfile with a Compose file that run the whole of it in one container. It also retires and moves several things. The built-in deep_research tool goes, with its raven deep-research command group and tools.deepResearch config section, in favour of the research agents; the tracing module's begin_attempt / end_attempt / current_attempt functions go with the span-level attempt.id, attempts now being grouped after recording with raven trajectory merge; and the installers finish by opening Raven in the browser and holding the terminal on raven web --foreground (export RAVEN_NO_LAUNCH=1 before a non-interactive install to exit as before). Conversations are gated by a new permission mode, smart by default; a turn the model loop gives up on now fails instead of answering and raven agent -m exits 3 when an action needed an approval nobody could give; a streamed model call that fails before any reply text is retried on a new ladder (agents.defaults.llmErrorRetryDelays, default 15/30/60 s) where 0.1.13 answered with the first failure, and one that fails after output is retried only where agents.defaults.llmRetryAfterOutput says so; the sub-agent memory block, the EverOS role settings and the retired embedding shape move, most of them with load-time migrations, and tools.toolSearch.enabled is now on by default. On the page, a four-step wizard and a cold-start import replace the terminal first run; the frontend follows the Figma design, with a settings dialog that absorbs skills, plugins, schedules, channels and memory, an Agent Connector, a desk task pane, a composer that starts a conversation in a folder of your choosing and sends a message into a running turn, and typeset mathematics. The provider catalogue grows from 21 to 55, Raven speaks Agent2Agent 1.0, the model can drive the shared browser, playbooks include a many-round stint mode, WhatsApp and WeChat pair from Settings > Channels, raven trajectory gets an interactive browser and a bug-report flow, and a bilingual documentation site takes over the README's reference sections.
Highlights
- Breaking: The built-in
deep_researchtool is retired: theraven deep-researchcommand group, the MiroThinker HTTP tool and its unconfigured stand-in, thetools.deepResearchconfig section, the settings row with its MiroThinker key panel and the deep-research entry in the ACP command menu are all gone. Research keeps two surfaces, the Raven-Research agent and the MiroThinker sub-agent preset. An existing config losestools.deepResearch/tools.deep_researchthrough a load-time migration that prints one notice (#717) - Breaking:
install.shandinstall.ps1finish by holding the terminal open onraven web --foreground, which opens the browser, instead of exiting after a hint: after probingraven web --helpthey runraven web --stopand thenraven web --foreground, so a non-interactive install -- a CI job, a DockerfileRUNstep, any piped install with no TTY to Ctrl-C -- hangs unlessRAVEN_NO_LAUNCH=1is exported first, which restores the exit-after-install behaviour. A piped install against a release without that subcommand ends onravenitself instead of exiting 2 withNo such command 'web'(#476, #588) - Breaking: Tool dispatch is gated. Permission modes are new in 0.2.0 --
permissions.modetakesask,smartorfulland defaults to"smart"-- so a turn now stops and asks where 0.1.13 ran straight through. Smart mode states what ordinary work is -- reading and writing files in the workspace, building, testing, formatting, installing project dependencies with a package manager, committing, pushing a branch -- and escalates by effect: sending files, secrets or conversation content off the machine, touching credentials and keys, changing shell startup files, system services or permission settings, deleting user data outside the workspace, force-pushing or rewriting shared history, dropping databases. The reviewer takes a verdict only from its ownreport_permission_reviewcall; a timeout, a raising provider or a prose answer escalates to the human (#585, #631, #645) - Breaking: Failures fail instead of answering. A model call the loop gives up on -- a first-byte or idle timeout, a stream cut before its terminal chunk, an error from the non-streaming fallback, or an exhausted empty-response recovery -- raises
AnswerlessTurnError: the turn is saved with statusfailedand the error's own words as its reason, the page and the TUI draw "Turn failed - ",raven agent -mno longer exits 0 with the explanation as its reply, a node of arun_subagent_daggraph is recorded as failed rather than counted as finished, and a cron job record carries the turn's own failure sentence rather than a generic one (#666, #705, #675).raven agent -mlists the actions it refused after the reply and exits 3 (EXIT_ACTIONS_REFUSED) when an action needed an approval nobody could give -- a refusal from a deny rule is listed but leaves the status at 0, and--permission-mode fullrestores a clean exit -- andraven trajectoryrun with no subcommand on a non-interactive stream prints "Re-run with: raven trajectory list" and exits 2 (#708, #370) - Breaking: Config keys and defaults move, most of them with a load-time migration. A sub-agent's memory block is spelled
memory--subagents.agents[].memoryinconfig.json,memoryin an agent folder'ssubagent.json-- and a row still using the oldeverosspelling keeps working, read under the new name (#414); EverOS's four roles (llm, embedding, rerank, multimodal) are configured in Raven's own config as a model pin plus the vendor serving it, never a credential, reach EverOS asEVEROS_<ROLE>__*environment variables on every spawn, and Raven now writes only[api]intoeveros.toml(#614); a config still holding the retired embedding endpoint shape is adopted onto the configured provider that answers at that address, or dropped with the address named in the log, instead of breaking every command that reads the extension blocks (#453); a sub-agent row still carrying the stock command of a retired Codex or Claude Code adapter pin is moved onto the current one (#752).tools.toolSearch.enablednow defaults to true: at or belowtools.toolSearch.compactionThreshold(default 50) live tools nothing changes; above it most tool schemas are withheld and reached throughtool_searchandtool_call, a pair reserved fromtools.disabledTools(#616). A model no catalogue knows falls back to 200,000 context tokens instead of 65,536, logged once with the hint to pinagents.defaults.contextWindowTokens(#634) - Breaking:
trace.begin_attempt,trace.end_attemptandtrace.current_attempt(raven.tracing.trace, shipped in v0.1.13) and the span-levelattempt.idattribute are removed, with no shim. Group attempts after recording instead, withmerge_attempts()fromraven.trajectoryorraven trajectory mergeon the CLI; existing logs carrying a span-levelattempt.idstay addressable through the reader fallback and need no data migration (#370) - Raven has a Web UI.
raven webstarts a supervisor and a resident gateway that serve a page in your browser -- rail, composer, transcript, settings dialog, Agent Connector and a desk with file, agent and task panes -- fromui-web/distor the wheel's packaged copy,raven web --stopends them, and the installers finish by opening the page. 0.1.13 shipped no served page and nowebcommand; the TUI stays, and bareravenstill opens it the wayraven tuidoes. Also new since 0.1.13 are permission modes at the tool-dispatch door, the four built-in agents underagents/(raven-code, raven-design, raven-oncall, raven-research;raven-pptsits beside them as a hidden engine that Raven-Design routes.pptxwork to, not a fifth agent on the roster), the playbook engine, the ACP and A2A surfaces, the three plugin wheels the release publishes, and nine commands or command groups:raven a2a,raven acp,raven agents,raven mcp,raven ops,raven playbook,raven plugin,raven serveandraven web(#476, #588, #612) - The settings dialog absorbs Skills, Plugins, schedules, channels and memory, each drawn in a shared two-pane frame; there is no separate Skills, Plugins, Knowledge or Playbooks page, and Knowledge has no page, CLI command or agent tool at all. The memory section has no delete control and the RPC has no `memor...
Raven 0.1.13 (2026-08-25)
A patch release that binds the model to the conversation instead of the process, adds raven trajectory for turning an agent failure into a deterministic regression test, and stops one failed MCP server from cancelling the whole turn. TUI input is more responsive and its clipboard path is honest about which mechanism it used, ask_user keeps the contract its schema advertises, and raven doctor finally says which tool capabilities this install actually has.
Highlights
- The model follows the conversation, not the process: each session keeps its own choice, switching in one session no longer moves the others, and every turn binds model, provider credential, and context window as one group so a switched model cannot run against a stale credential or window. Concurrent sessions can use different models, and a resumed session keeps the one it had (#284, #349)
- A failed MCP server no longer takes the turn down with it. A transport or handshake failure collapses into that one server's connection error instead of unwinding the caller as a task-group exception, so the remaining servers still register and the turn reaches the model loop (#365)
raven trajectoryturns a single agent failure into a permanent regression: record, judge, label, pin, save, and report, with deterministic replay off recorded model responses and tool results rather than live tools. A failing trajectory minimizes into a redacted cassette that pytest can run, and reports strip config secrets, environment credentials, and sensitive paths (#362)web_searchis no longer registered when no key resolves, so the model is not offered a tool it cannot run and its setup error stops reaching whoever is in the chat -- the same gate applies to the sub-agent surface. The check asks the tool, so an install that only exportsSERPER_API_KEYstill counts as configured (#312)raven doctorgrows a Tool capabilities section listing all five capabilities configured or not, ordered by how much setup each needs, naming the config key that holds the credential and distinguishing a genuinely reused credential from a missing one. An unconfigured capability does not move the exit code (#312)ask_userkeeps one deadline for a whole batch instead of granting each question a fresh timeout, drops the interaction capabilities no client ever implemented, and caps a call at four questions. Duplicate questions, invalid options, and undeliverable prompts fail fast with a specific error. The TUI shows batch progress, the recommended option, and the remaining time, and pickingOtherby number now opens free-text entry (#354)- TUI input keeps up: a coalesced run of bytes over SSH, under tmux, on a busy event loop, or from an IME sending several characters at once is read as typing rather than misclassified as a paste and held in debounce. Continuous input, CJK, and wide characters take the fast echo path (#355)
- Select-to-copy works on macOS, Linux, and Windows, and the status line names the path actually used -- native, tmux, or OSC 52 -- instead of reporting success the clipboard never received (#360)
- The full-screen cover drops after the first turn, and user input renders as a filled block so turn boundaries are legible in a long session (#361)
- Config migration notices move to stderr, so
doctor --jsonandimport --jsonkeep stdout parseable as JSON. A new config saves only the values you actually changed instead of freezing the whole default set, so later default upgrades still reach you (#346) - An invalid EverOS memory identity names the config key and the legal format instead of presenting itself as a service failure or a bare traceback (#350)
- Skill Hub truncates a long catalog query at the gateway's real byte limit, so a non-ASCII query no longer loses skill retrieval silently (#348)
- EverOS moves from 1.2.1 to 1.2.3, with no Raven adapter change and no data migration (#351)
Install
New install on Linux, macOS, or WSL2:
curl -fsSL https://raven.evermind.ai/install.sh | bashNew install on native Windows, in PowerShell:
irm https://raven.evermind.ai/install.ps1 | iexWindows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:
irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iexOpen a new terminal, then run:
ravenThat sets you up on first run and then opens the TUI. raven onboard stays
the explicit way to reconfigure later.
Upgrade
Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved:
raven upgraderaven upgrade installs the latest stable release, so it does not pick up a
pre-release; rerun the installer above for that. Editable source checkouts are
never overwritten -- pull the checkout and rerun its development setup. On
native Windows the upgrade finishes in an external helper; wait for its
completion message before running Raven again.
Release Status
- Version:
0.1.13 - Tag:
v0.1.13 - Stability: public preview patch
- Assets: wheel and source distribution attached to this release
Notes
- Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
- PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.
Raven 0.1.12 (2026-08-18)
A patch release that makes cron reminders fire where they were created, puts skill hub installs behind a safety policy gate, and lifts the stale 64k context window off upgraded installs, plus fixes to first run, provider auth errors, and the one-line installer. Interactive chat is raven tui now: bare raven agent no longer opens a REPL.
Highlights
- Breaking: bare
raven agentno longer hosts a REPL. It prints a pointer toraven tuiand exits 2, whileraven agent -m "..."keeps working for scripted one-shot turns. Theclicron channel retires with it, and jobs stored withchannel="cli"migrate totuiat load (#329) - Breaking:
--wait-skill-extractand--flush-skill-bufferare gone. Both promised a boundary-detection workflow that has been a no-op since extraction moved to the memory backend, so a script still passing them now fails on an unknown option (#334) - Cron reminders fire at their origin: a job is claimed and delivered only by the runner that owns its creation-time channel binding, ending the case where a reminder created in the CLI never fired while a headless gateway was running (#326)
- A recurring reminder nobody engages with disables itself once it crosses a per-job fire limit (default 12), and
cron list/cron getsurface the live counter (#333) - Reminders that lapsed while the TUI was closed are shown at startup as one "missed N reminders" block, instead of a warning log the user never sees (#332)
- Skill hub installs go through a single policy gate: safety scores are actually checked, every install is recorded to disk, and
skillForge.blocklistrefuses a named skill everywhere (#327) skillForge.autoInstallpicks the consent mode (auto/prompt/off, defaultauto), andskill listgains an Installed column plus a[blocked]marker (#328)- An install upgraded from 0.1.10 or earlier is no longer capped at a 64k context window by the
contextWindowTokens: 65536those builds wrote into config.json. The stale pin is dropped once at config load, with a one-line notice, and a value you set yourself is never second-guessed (#341) - Model output is no longer capped at 8192 tokens by a shadowed default, and a truncated response is reported as truncation instead of nudging the model into resending the same oversized call (#308)
- Provider authentication failures print classified guidance and exit non-zero, instead of dumping a raw exception as if it were the agent's reply and exiting 0 (#330)
- First run is one command again: the installers send a fresh machine to bare
raven, a zero-provider install no longer names a vendor you never chose, and the model the wizard recommends is priced again instead of reporting an unknown cost (#342) - Choosing to run on the host rather than the sandbox now warns that injected commands would execute with full host privileges, and asks for an explicit confirmation that defaults to No (#321)
channels enablestops exiting 0 on missing credentials, and enabling a channel whoseallow_fromresolves to*(anyone who can message it can command the agent on this host) now requires an acknowledgement (#323)- Sessions are auto-titled from the first user message (capped at 40 characters), and
sessions createpersists immediately so create / list / delete round-trips work (#324) - EverOS memory ownership is a recorded decision instead of a per-call guess: onboarding asks once whether Raven runs the server, a root you run yourself is left alone, and a memory failure no longer stalls the session for up to a minute (#310, #343)
raven statuslists only configured providers and folds the rest into one line, every turn ends with a usage summary, andraven doctorreports the config as valid / invalid / missing and exits 1 on a broken one (#331, #322)- The identity block carries the gateway-resolved routed model id, so the agent stops answering "which model are you" from pretraining memory (#325)
- The tracing dashboard no longer reuses a viewer whose UI files were deleted, which served an unstyled page that never connected (#316)
- Running the one-line installer from inside a clone no longer silently installs that working tree as an editable checkout instead of the released wheel; an editable install is now an explicit
RAVEN_LOCAL_SRCopt-in (#294) - When the unauthenticated GitHub API quota is spent,
raven upgradeand the installers fall back to the release page to resolve the latest version, and the launch-time update check no longer spends an API request at all (#299) - Skill retrieval fusion is retuned: the RRF damping constant is configurable (
rrf_k) and the source weights are rebalanced (#290)
Install
New install on Linux, macOS, or WSL2:
curl -fsSL https://raven.evermind.ai/install.sh | bashNew install on native Windows, in PowerShell:
irm https://raven.evermind.ai/install.ps1 | iexWindows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:
irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iexOpen a new terminal, then run:
ravenThat sets you up on first run and then opens the TUI. raven onboard stays
the explicit way to reconfigure later.
Upgrade
Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved:
raven upgraderaven upgrade installs the latest stable release, so it does not pick up a
pre-release; rerun the installer above for that. Editable source checkouts are
never overwritten -- pull the checkout and rerun its development setup. On
native Windows the upgrade finishes in an external helper; wait for its
completion message before running Raven again.
Release Status
- Version:
0.1.12 - Tag:
v0.1.12 - Stability: public preview patch
- Assets: wheel and source distribution attached to this release
Notes
- Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
- PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.
Raven 0.1.11 (2026-08-10)
Endpoint failover for provider requests, image attachments for vision-capable models, and a hermes import source, plus fixes to live model switching, OAuth sign-in, and media understanding.
Highlights
- Provider requests now fail over across endpoints instead of dying on the first unreachable one (#287)
- User attachments are sent to the model when it supports vision (#285)
- Hermes joins the cold-start import sources (#264)
- Sign in to an OAuth provider directly from
/model(#279) - Switching models mid-session now reaches every provider holder, not just the agent loop (#282)
understand_mediaparsing works again against the current everos parser (#273)- Ctrl+C means the same thing across all credential prompts (#266)
Install
New install on Linux, macOS, or WSL2:
curl -fsSL https://raven.evermind.ai/install.sh | bashNew install on native Windows, in PowerShell:
irm https://raven.evermind.ai/install.ps1 | iexWindows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:
irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iexOpen a new terminal, then run:
raven onboardUpgrade
Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved:
raven upgraderaven upgrade installs the latest stable release, so it does not pick up a
pre-release; rerun the installer above for that. Editable source checkouts are
never overwritten -- pull the checkout and rerun its development setup. On
native Windows the upgrade finishes in an external helper; wait for its
completion message before running Raven again.
Release Status
- Version:
0.1.11 - Tag:
v0.1.11 - Stability: public preview patch
- Assets: wheel and source distribution attached to this release
Notes
- Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
- PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.
Raven 0.1.10 (2026-07-31)
A patch release that opens provider support up to everything LiteLLM routes to, adds an approval flow for protected shell commands, and reworks the TUI transcript into episodes.
Highlights
- Every provider LiteLLM can route to is now configurable from the onboarding picker: 21 registered providers in four groups (key, OAuth, local, fallback), plus a searchable step for vendors Raven carries no spec for (#252). LiteLLM is now the single execution layer behind them, including knn routing (#249).
/modellists the providers that can actually serve a model first, ending with one row that opens the rest, instead of twenty-one rows to scroll (#260).- Protected shell commands go through a runtime-owned approval flow: recognized deletion commands ask for one-shot approval in interactive TUI turns, and fail closed for non-interactive origins, expiry, disconnects, and parse failures (#239).
- The TUI transcript reads as collapsible episodes, one per model call, each holding its reasoning, narration, and tool rows (#217).
read_filecan read images, and image tokens are now estimated from the image instead of the length of its base64 data URI (#251).- MiniMax Token Plan OAuth for both Global and CN regions, with device-flow login and proactive token refresh (#209).
- The TUI status bar nudges
raven upgradewhen the running version is behind (#220). - A static read no longer starts a login: resolving a model's metadata with no token file on disk used to print device codes and block for minutes (#255).
/model <bare-id>no longer keeps the previously pinned provider, which could send one vendor's key to another (#256).Backon a required EverOS memory role no longer drops back into the provider picker forever (#258).- Switching provider after a failed verification no longer carries the credential flags into the next pass (#253).
raven[sandbox]installs on Windows again; boxlite is marked posix-only and the unused retrieval extra is gone (#226).
Install
New install on Linux, macOS, or WSL2:
curl -fsSL https://raven.evermind.ai/install.sh | bashNew install on native Windows, in PowerShell:
irm https://raven.evermind.ai/install.ps1 | iexWindows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:
irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iexOpen a new terminal, then run:
raven onboardUpgrade
Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved:
raven upgraderaven upgrade installs the latest stable release, so it does not pick up a
pre-release; rerun the installer above for that. Editable source checkouts are
never overwritten -- pull the checkout and rerun its development setup. On
native Windows the upgrade finishes in an external helper; wait for its
completion message before running Raven again.
Release Status
- Version:
0.1.10 - Tag:
v0.1.10 - Stability: public preview patch
- Assets: wheel and source distribution attached to this release
Notes
- Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
- PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.
Raven 0.1.9 (2026-07-23)
A patch release with reliability and CLI/TUI polish fixes.
Highlights
- Add a configurable
llm_call_timeoutso a stalled LLM call is bounded instead of hanging a turn indefinitely (#204). - Make
raven onboardreadable on light-background terminals (#199). - Pick the first Node >= 22 found across all PATH entries, fixing setup on machines with multiple Node versions (#189).
- Surface the real turn-failure detail in the TUI instead of just an error code (#190).
- Unify commit and PR length limits to a single
header-max-lengthrule (#196).
Install
curl -fsSL https://raven.evermind.ai/install.sh | bashThen reload your shell and run:
raven onboardRelease Status
- Version:
0.1.9 - Tag:
v0.1.9 - Stability: public preview patch
- Assets: wheel and source distribution attached to this release
Notes
- Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
- PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.