Skip to content

Houston Cloud v0.5.28

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 24 Jul 16:32
· 257 commits to main since this release

Houston v0.5.28

Features

  • feat(ci): sign Windows MSI via Azure Artifact Signing to clear SmartScreen (#1082)
  • feat: rebuild landing page — Night Launch design on a single token layer
  • feat: one card system — branded ask_user replaces the approval gate (HOU-885)
  • feat(teams): teammate names and avatars from the gateway profile source
  • feat: agent design process — DESIGN.md + frontend-design/design-review skills
  • feat: visual regression suite + design-token hex cleanup
  • feat: ask_user defaults to options; honest optionless placeholder (HOU-880)
  • feat: forward composerOverrideMode through the board panel (HOU-870)
  • feat: interaction cards replace the composer, free-text escape on every step (HOU-870)
  • feat: integration approvals become a plain confirmation card (HOU-869)
  • feat: make display name optional in the creator profile forms (#1064)
  • feat(migration): emoji space-invaders + progress screen polish (#1063)
  • feat: rename Coworker mode to Ask first
  • feat: run read-only integration actions without the approval card
  • feat(chat): upload whole folders as chat attachments (HOU-808) (#1045)
  • feat: label Linear issues at the cut, not just at publish (#1049)
  • feat: presence-style status dot on catalog rows (#1040)
  • feat: sign-in referral panel reads Coming soon; localize panel strings (#1039)
  • feat: Linear release stamp on cloud train publish (#1038)
  • feat(store): starter-agent publish pipeline, admin grant UI, docs and i18n cleanup
  • feat(integrations): turn the catalog spotlight into a "Most used" section
  • feat(analytics): stamp the display name as a person property on sign-in
  • feat(analytics): emit user_signed_up on first sign-in of a new GCIP account
  • feat(providers): 2026-07 catalog QA sweep + Gemini 3.6 Flash / 3.5 Flash-Lite
  • feat(analytics): emit $ai_generation per model turn to light up the AI Usage dashboard
  • feat(routines): chat-first redesign of the Routines tab
  • feat(catalog): add Kimi K3 (kimi-coding) by backporting the pi-ai 0.80.9 entry
  • feat(store): creator profiles - in-app editor, @handle pages, analytics, verified badges
  • feat(app): unified catalog search across integrations, AI hub, and skills
  • feat(ui): two-section catalog shell with unified search grammar
  • feat(providers): hide regional duplicate deployments from the catalog
  • feat(store): one-click Open in Houston install from the website
  • feat(analytics): instrument usage, permissions, org, AI hub, skills, cloud migration
  • feat(analytics): instrument feature-adoption gaps + model/provider on sends
  • feat(sentry): tag client events with their deployment (#991)
  • feat(dev): add pnpm dev:staging to run the desktop against remote staging (#994)
  • feat(app): send app-version header to the gateway + blocking required-update screen (#985)
  • feat(host): build identity on /v1/version + pod-level /activity busy probe (#984)
  • feat(chat): apply AI Mode changes to the running turn, like Claude Code's shift+tab
  • feat(files): transparent files panel + move-conflict dialog (#966)
  • feat(store): app parity wave - categories, integration filter, reporting, owner dashboard
  • feat(store): extract @houston/agentstore-client SDK and migrate both frontends
  • feat(teams): agent-centric Permissions, on-agent mount, and permission-aware agents (#954)
  • feat(teams): admin Permissions hub — People access lens + blocked-state deep links (#948)
  • feat(usage): split the Usage page into Compute usage / Model usage panes
  • feat(integrations): review and revoke always-allowed actions per agent (#942)
  • feat(integrations): surface connected-but-ungranted apps on the agent tab (#939)
  • feat(files): redesign the Files tab as a Drive-style card grid (#960)
  • feat(analytics): enable session recordings + heatmaps (masked)
  • feat(chat): add conversation map
  • feat(onboarding): email steps - floating brand marks, one clear final action
  • feat(onboarding): preselect the OS locale on the language gate
  • feat(chat): toast when a mode change lands on the next message
  • feat(usage): show time worked instead of engine up-time + chart legibility (#936)
  • feat(usage): split accounts into AI subscriptions and AI per token sections
  • feat(sentry): debuggable engine events — synthetic stacks, version tag, severity correctness (#937)
  • feat(ios): move auth to GCIP with Apple, Google, Microsoft, and email-code sign-in (#938)
  • feat(secrets): use gateway custody for managed agents (#899)
  • feat(usage): show how long agents ran (compute usage, hosted cloud) (#925)
  • feat(models): curate provider model lists via one shared visibility table (#928)
  • feat(create-agent): model picker in the Create-with-AI step (#927)
  • feat(usage): meter token spend locally for API-key providers with no usage API
  • feat(chat): preview + download files the agent created from chat (#923)
  • feat(onboarding): larger Gmail/Outlook rows on the connect-email step
  • feat(onboarding): centered pill-grid segment screen with skip + PostHog person property
  • feat(analytics): enable rage + dead click capture, fully masked
  • feat(engine): Sentry crash reporting for the TS engine (pods + desktop sidecar) (#907)
  • feat(onboarding): add reset segment setting
  • feat(onboarding): add segmentation screen
  • feat(website): unlisted bootcamp landing page at /bootcamp/ (#906)
  • feat: Admin > Agents drill-in to manage one agent's access in place
  • feat: visible workspace policy everywhere and a settings-style Admin page
  • feat: move org allowlists to an Admin page, keep Integrations personal
  • feat(dev): one pnpm dev — full local stack, multiplayer included (#900)
  • feat(migration): reconnect checklist from the legacy Composio consumer account (#895)
  • feat(local-model): share a tunnelled local model with your team (#860)
  • feat(auth): provider pill row + six-box pin input on the login screen
  • feat(design): visible sidebar selected state via sidebar-active token
  • feat(board): say Archive/Archived instead of Complete/Completed
  • feat: per-account provider usage page (top-level Usage view) (#890)

Fixes

  • fix(release): stamp the whole train in Linear; clean up superseded drafts (#1074)
  • fix(teams): bridge team spaces into the switcher; invite follow-through; spaces e2e
  • fix(teams): personal space never offers a broken invite flow
  • fix(auth): register the houston:// scheme at runtime on Windows
  • fix: surface the real cause when a creator profile save or photo upload fails (#1062)
  • fix(i18n): translate the pre-auth sign-in screen (es/pt)
  • fix(analytics): let session replay start by not disabling flags
  • fix(providers): report a provider connected only when it can actually serve a turn (#1054)
  • fix(credentials): make the desktop reconcile a fill-only push so it cannot revoke the token family (HOU-855) (#1056)
  • fix(runtime): show the connect card in Autopilot mode (HOU-853) (#1055)
  • fix(chat): flush a stranded reconnect auto-continue with a history-probe watchdog (HOU-849) (#1052)
  • fix(integrations): serve the secure credential card through the per-agent surface so managed-cloud saves stop 404ing (HOU-823) (#1053)
  • fix(app): accept the Claude sign-in code when the browser hand-off is blocked (HOU-839) (#1043)
  • fix: keep the open chat when clicking outside the board panel (#1048)
  • fix(teams): resume abandoned agent moves so a wedged move can't brick the agent (HOU-817) (#1044)
  • fix(ci): green-main guard must ignore the cut's own failed runs
  • fix(host): stop exhausting the Linux inotify watch budget (HOU-841) (#1042)
  • fix(ci): surface GitHub's rejection message in the cut token probe
  • fix(ci): tokenless checkout + API-validated PAT for the daily cut
  • fix: show the full email on the sign-in continue button (#1041)
  • fix: never sign users out on secure-storage read faults (#1037)
  • fix(integrations): platform-correct custom-secret file permissions
  • fix(integrations): never dead-end the secure credential save on schemeless specs
  • fix(host): quiesce of an absent runtime is a no-op, not a launcher sleep error
  • fix(analytics): identify the person before emitting user_signed_up
  • fix(providers): route Copilot Business connects through github.com
  • fix(providers): drop the two Cloudflare providers from the catalog
  • fix(runtime): classify no-credit provider errors as quota_exhausted
  • fix(host): quiesce the agent runtime before a rename so the old name cannot resurrect
  • fix(host): serve the Rust-era agent color so migrated agents keep their colors
  • fix(integrations): pin Composio tool version to latest on search + execute
  • fix(chat): block image attachments when the active model has no vision
  • fix(host): no-auth Composio toolkits are not connectable apps (#1012)
  • fix(chat): render URL-labeled links inline instead of a clipped black pill
  • fix(app): repair Linux AppImage sign-in end to end (#1019)
  • fix(providers): friendly toast for a GitHub account without Copilot access (#1017)
  • fix(providers): verify Google keys against the models list and surface typed connect errors (#1016)
  • fix(providers): repair the Windows shell env for Claude sign-in and turns (#1014)
  • fix(app): guard agent-JSON reads against wrong top-level container shape (#1013)
  • fix(website): download buttons serve the newest cloud prerelease (#1009)
  • fix(routines): adapt intake connect card to per-slug connect-flow states
  • fix(onboarding): migration-flow polish, durable onboarding-completed signal, deleted-account sign-out (#999)
  • fix(store-sync): skip an over-cap file instead of letting it block every sync pass (#989)
  • fix(runtime): size Claude context fill from per-request usage, not the turn aggregate (#988)
  • fix(sentry): stop expected operational failures from spamming error events (#986)
  • fix(runtime-client): retry transient object-store failures instead of failing hydrate/sync (#987)
  • fix(runtime-client): tolerate files vanishing mid-walk in syncBack (#983)
  • fix(host): cover all delivery paths of the recursive-watcher ENOENT race (#981)
  • fix(app): reconnect card for a disconnected local model + unknown-state polish (#980)
  • fix(local-model): connect directly when the deployment has no tunnel relay (#978)
  • fix(chat): unwedge the reconnect auto-continue from the send queue (#979)
  • fix(host): disconnect a terminally-rejected credential instead of retrying its dead refresh token forever (#977)
  • fix(skills): require a description before creating a skill from scratch (#976)
  • fix(app): keep the Codex sign-in relay off for a loopback hosted gateway (#955)
  • fix(website): unblock download gate and de-jank modal open (#975)
  • fix(providers): report unknown, not signed-out, when the engine is unreachable (#973)
  • fix(host): demote the Linux recursive-watcher ENOENT race to a warning (#970)
  • fix: stop a double-fired first send from losing a mission (#969)
  • fix(usage): only show the user's own agents, count messages not tasks (#967)
  • fix(onboarding): skip only on failure; the sent payoff says check your inbox
  • fix(onboarding): email mission runs in Autopilot; skip waits for the agent's reply
  • fix(providers): fail Codex sign-in port conflicts fast, loud, and localized (#945)
  • fix(e2e): conversation map spec earns its 3-moment minimum on the fake host
  • fix(agentstore): pin folder-entry timestamps — reproducible skill zips (#961)
  • fix(sentry): count orgs as users-affected, trim the runtime capture frame (#957)
  • fix(usage): hide system/ghost agents from the Time worked list (#956)
  • fix(analytics): admit detected_locale through the branch cleanProps filter
  • fix(chat): conversation map floats over the transcript + clean marker previews
  • fix(onboarding): ask the work-segment question at most once per user
  • fix(web): provider connect no longer reports success it did not earn
  • fix(auth): desktop Apple sign-in returns via gateway bridge + houston:// deep link
  • fix(app): paint cached mission cards on cold open while the pod wakes (#950)
  • fix(sentry): attach the synthetic stack as a thread, keep the message as the issue title (#949)
  • fix(design): floating surfaces are solid everywhere, no glass modals
  • fix(chat): approval card drops the technical param rows
  • fix(host): satisfy noUncheckedIndexedAccess in the provider-usage route test
  • fix(usage): Copilot usage no longer reads "sign in again" on a healthy connection
  • fix(onboarding): require initial email action
  • fix(chat): pin the agent's configured model on setup-chat kickoffs
  • fix(runtime): expire abandoned OAuth logins so they release the callback port (#932)
  • fix(settings): remove onboarding segment reset from production settings
  • fix(design): solid dialog + create-agent cards, no see-through surfaces
  • fix(e2e): scope usage-compute agent rows to the Running time section
  • fix(design): opaque floating surfaces on desktop (WebView2 backdrop-filter)
  • fix(chat): make pasted links readable inside the user message bubble
  • fix(usage): honest OpenRouter balance + "not metered yet" copy
  • fix(routines): stop cron routines vanishing after an edit (#924)
  • fix(fake-host): split the setup-runtime connect surface into gate + first-run slots
  • fix(e2e): onboarding connect spec survives the connected setup-runtime
  • fix(providers): live-verify a pasted API key before storing it
  • fix(web): make the engine gate reachability-only; onboarding owns connect
  • fix(chat): make the in-chat integration approval card work on hosted cloud + stop the footer overflowing (#919)
  • fix(fake-host): serve the /setup-runtime connect surface the WebApp gate probes
  • fix(web): point the standalone connect gate at /setup-runtime
  • fix(e2e): teach the fake host the /setup-runtime connect surface
  • fix(web): probe the host's /setup-runtime connect surface, not a flat /auth/status
  • fix(web): point the connect gate at the host's /setup-runtime surface
  • fix(providers): curate key-dashboard URLs for the remaining api-key providers
  • fix(providers): connect any pi api-key provider from the UI
  • fix(integrations): never mint a bare custom OAuth auth config (Meta Ads)
  • fix(onboarding): email test-send card shows only the option; Omitir actually skips
  • fix(app): paint sidebar needs-you badges through a pod cold start (#914)
  • fix(onboarding): drop the "Another provider" row from the connect-email step
  • fix: cloud-migration wizard recovery — keep the Settings retry after partial runs, escape hatch on errors (#908)
  • fix(anthropic): repair OAuth connect + credential lifecycle end to end (#910)
  • fix(app): keep cached mission cards painted while an asleep pod wakes (#911)
  • fix(ai-hub): stop curating OAuth providers' model lists — hub now matches the chat picker (#909)
  • fix(onboarding): adapt segmentation screen to current main after rebase
  • fix: cloud-migration backup fails on Windows with 'Acceso denegado (os error 5)' (#905)
  • fix(sidebar): stop agent list overflowing onto the user footer in short windows (#898)
  • fix(release): preserve Bun sidecar in Linux AppImage (#897)
  • fix(release): give vite build 4GB Node heap on low-RAM runners (#896)
  • fix(chat): stop hiding a reply whose text contains an auth code (HOU-734) (#885)
  • fix(migration): skip the empty Reconnect-your-apps step (#893)
  • fix(ui): keep the open chat panel mounted while its card is transiently absent (#891)

Docs

  • docs: add the app node:test suite to the test-commands table
  • docs: KB reflects composer-replacing interaction stepper (HOU-870)
  • docs(kb): drop the resolved sign-in-screen i18n follow-up note
  • docs: record the catalog redesign in the knowledge base and inventory
  • docs(kb): document agentstore-client SDK, store parity features, deep-link install
  • docs(website): point developer docs at the real gateway, centralize the URL (#993)
  • docs(kb): drop retired theagentlibrary note from agent-store KB

CI & infra

  • ci: retrigger
  • ci: raise the web job timeout to 30m — the e2e suite outgrew 20m
  • ci(train): publishing the cloud draft ships the whole train
  • ci(images): publish the served /v1/catalog as an engine-pod-catalog artifact
  • ci(release): cut the cloud release automatically each weekday morning
  • ci(release): build a staging-gateway QA DMG for every cloud release
  • ci(website): pass POSTHOG_KEY to the site build and fail loudly when absent
  • ci(images): build engine-pod/agentstore on tag push, notify prod sepa… (#992)

Changes

  • test: notification body-key cases follow the branded-question model (HOU-885)
  • test: prove the Always-allow circle end-to-end through the dispatch route
  • perf(chat): open chats on the transcript tail + scroll-up lazy-load (HOU-819) (#1051)
  • style(chat): drop the amber triangle chip from the attachment-rejection dialog
  • test(routines): adapt stale e2e specs to the chat-first Routines redesign (#1010)
  • refactor(files): flatten the Files tab onto the canvas (#1007)
  • test(e2e): update catalog specs for the unified catalog redesign
  • test(onboarding): skip-route assertion follows the failure-gated shouldOfferSkip
  • refactor(settings): drop the Connected accounts shortcut row (#947)
  • refactor(integrations): fold Settings > Connected accounts into the Integrations page (#941)
  • test(onboarding): update language-gate e2e to the preselect + Continue contract
  • test(web): approval e2e pins the card without param rows
  • test(onboarding): select required segment in e2e
  • refactor(usage): drop the billing sections' subtitles
  • test(fake-host): serve the pre-agent /setup-runtime/* connect surface
  • test(e2e): align onboarding specs with the segment gate and the welcome-less flow
  • perf(host): parallelize store hydration — cuts managed-pod wake by ~10s (#901)

Before you upgrade

  • Quit Houston before installing. macOS doesn't always replace a running app. If in doubt: rm -rf /Applications/Houston.app and drag the new copy in.

Full changelog: v0.5.6...cloud-v0.5.28


Linear — cloud-v0.5.28

(no project)

  • HOU-819 — Chats hang for a while before opening or accepting input 🐛
  • HOU-883 — Design QA gates: Playwright visual regression suite + token-contract hex cleanup
  • HOU-882 — Design process infrastructure: DESIGN.md, frontend-design + design-review skills, mandatory UI workflow
  • HOU-884 — Landing page rebuild on design tokens (warm editorial direction)
  • HOU-830 — Suggestion: surface the most popular integrations first, full list alphabetical 🐛
  • HOU-829 — Reconnect to Anthropic error after update: Claude sign-in failed (exit 1) on Windows 🐛

AI Models

  • HOU-839 — Anthropic new update that requires typing a code breaks our OAuth
  • HOU-855 — Desktop credential reconcile clobbers the gateway's rotated Anthropic token, revoking the whole family
  • HOU-856 — Gateway cannot refresh GitHub Copilot: cloud Copilot breaks ~25 minutes after connect

Agent Store

  • HOU-864 — I couldn't add any picture to my profile in the agent store
  • HOU-868 — Agent Store profile: only the handle is required, everything else optional
  • HOU-865 — I clicked saved for my profile and it said "You profile could not be saved"

Analytics

  • HOU-755 — Track AI models providers, both usage and when people connect to it. Let's find a way to track if people are creating accounts with them from houston! (like a create account button maybe?)
  • HOU-754 — Feature adoption instrumentation
  • HOU-753 — Slack notification when a new user signs up
  • HOU-752 — Visible warning when the PostHog key is missing on the website

Automations

  • HOU-810 — Every time an user creates an account in Houston, we should be notified via Slack

Backend

  • HOU-800 — Load testing on staging

Chat Experience

  • HOU-849 — Fix autocontinue conversation after reconnect
  • HOU-853 — Show connection card in autopilot mode
  • HOU-846 — Coworker mode it is unusable with integrations
  • HOU-845 — Change the name of the "Cowork" mode to something like Ask permissions or something that is more clear that that's the difference
  • HOU-869 — Integration approvals are permission jargon; replace with a plain confirmation card (Do it / Not now)
  • HOU-870 — Interaction cards: free-text input on every card and replace the chat composer while a card is pending
  • HOU-880 — ask_user questions must offer options by default; optionless card shows wrong placeholder
  • HOU-885 — One card system: integration confirmations are branded ask_user questions; approval gate removed
  • HOU-850 — Only show available models in chat

Files

  • HOU-808 — Being able to upload folders of files - +57 317 8950374 🐛

Global Interfaces & Components

  • HOU-815 — Have persistent login

Integrations

  • HOU-826 — LinkedIn integration can't publish: connector sends a retired API version (426 NONEXISTENT_VERSION) 🐛
  • HOU-823 — Tally integration cannot be connected directly 🐛

Migration

  • HOU-737 — Have a micro game in there

Multiplayer

  • HOU-817 — App unusable: starting a mission fails (error ccd6598049884b2897e97937d6dd1ea3) 🐛
  • HOU-824 — Inviting teammates to a team fails 🐛
  • HOU-871 — The overall multiplayer experience was created, but has never been tried nor tested we should make sure it is working and it makes sense
  • HOU-881 — Space switcher never lists teams: the adapter never fetches the /v1/workspaces bridge
  • HOU-875 — After creating a team you land in an empty space with no pointer to invite people
  • HOU-878 — E2E cannot express team spaces: fake-host spaces arming + coverage for the personal/team gating
  • HOU-876 — Teammate names and avatars are stubbed: initials only across mission attribution and rosters
  • HOU-877 — Gateway org-write store errors panic into opaque 500s (no error code)
  • HOU-874 — Team invites send no email: the invitee never learns they were invited
  • HOU-825 — Creating a new team fails (error f4d2e5e0f8d441d0869f53b3afe06a0d) 🐛

Onboarding

  • HOU-756 — Onboarding is only in english 🐛
  • HOU-757 — Windows login is not working 🐛
  • HOU-758 — Apple login is not working 🐛

WhatsApp draft

🚀 Nueva versión de Houston!
✅ Being able to upload folders of files - +57 317 8950374
✅ App unusable: starting a mission fails (error ccd6598049884b2897e97937d6dd1ea3)
✅ Anthropic new update that requires typing a code breaks our OAuth
✅ Fix autocontinue conversation after reconnect
✅ Show connection card in autopilot mode
✅ Desktop credential reconcile clobbers the gateway's rotated Anthropic token, revoking the whole family
✅ Chats hang for a while before opening or accepting input
✅ I couldn't add any picture to my profile in the agent store
✅ Have a micro game in there
✅ Agent Store profile: only the handle is required, everything else optional
✅ Onboarding is only in english
✅ Windows login is not working
✅ Inviting teammates to a team fails
✅ The overall multiplayer experience was created, but has never been tried nor tested we should make sure it is working and it makes sense
✅ Space switcher never lists teams: the adapter never fetches the /v1/workspaces bridge
✅ After creating a team you land in an empty space with no pointer to invite people
✅ E2E cannot express team spaces: fake-host spaces arming + coverage for the personal/team gating
✅ Teammate names and avatars are stubbed: initials only across mission attribution and rosters
✅ Design QA gates: Playwright visual regression suite + token-contract hex cleanup
✅ Design process infrastructure: DESIGN.md, frontend-design + design-review skills, mandatory UI workflow
✅ Landing page rebuild on design tokens (warm editorial direction)
✅ Coworker mode it is unusable with integrations
✅ Change the name of the "Cowork" mode to something like Ask permissions or something that is more clear that that's the difference
✅ Integration approvals are permission jargon; replace with a plain confirmation card (Do it / Not now)
✅ Interaction cards: free-text input on every card and replace the chat composer while a card is pending
✅ ask_user questions must offer options by default; optionless card shows wrong placeholder
✅ One card system: integration confirmations are branded ask_user questions; approval gate removed
✅ Gateway org-write store errors panic into opaque 500s (no error code)
✅ Team invites send no email: the invitee never learns they were invited
✅ I clicked saved for my profile and it said "You profile could not be saved"
✅ Gateway cannot refresh GitHub Copilot: cloud Copilot breaks ~25 minutes after connect
✅ Only show available models in chat
✅ Suggestion: surface the most popular integrations first, full list alphabetical
✅ Reconnect to Anthropic error after update: Claude sign-in failed (exit 1) on Windows
✅ LinkedIn integration can't publish: connector sends a retired API version (426 NONEXISTENT_VERSION)
✅ Creating a new team fails (error f4d2e5e0f8d441d0869f53b3afe06a0d)
✅ Tally integration cannot be connected directly
✅ Have persistent login
✅ Every time an user creates an account in Houston, we should be notified via Slack
✅ Load testing on staging
✅ Apple login is not working
✅ Track AI models providers, both usage and when people connect to it. Let's find a way to track if people are creating accounts with them from houston! (like a create account button maybe?)
✅ Feature adoption instrumentation
✅ Slack notification when a new user signs up
✅ Visible warning when the PostHog key is missing on the website
Gracias a todos los que reportaron 🙌

Notify reporters (then clear the Notify pending label):

  • HOU-808 → ⚠️ no phone on issue
  • HOU-817 → +32475407080, +573042508033
  • HOU-819 → +573227231739, +573183977808, +573503983550
  • HOU-756 → ⚠️ no phone on issue
  • HOU-757 → ⚠️ no phone on issue
  • HOU-824 → +32475407080, +573042508033
  • HOU-830 → +5216121521166
  • HOU-829 → +573506535829
  • HOU-826 → +5115534105446
  • HOU-825 → +32475407080, +573042508033
  • HOU-823 → +573142934127
  • HOU-758 → ⚠️ no phone on issue