Houston Cloud v0.5.28
Pre-release
Pre-release
·
257 commits
to main
since this release
Houston v0.5.28
Features
- feat(ci): sign Windows MSI via Azure Artifact Signing to clear SmartScreen (#1082)
- feat: rebuild landing page — Night Launch design on a single token layer
- feat: one card system — branded ask_user replaces the approval gate (HOU-885)
- feat(teams): teammate names and avatars from the gateway profile source
- feat: agent design process — DESIGN.md + frontend-design/design-review skills
- feat: visual regression suite + design-token hex cleanup
- feat: ask_user defaults to options; honest optionless placeholder (HOU-880)
- feat: forward composerOverrideMode through the board panel (HOU-870)
- feat: interaction cards replace the composer, free-text escape on every step (HOU-870)
- feat: integration approvals become a plain confirmation card (HOU-869)
- feat: make display name optional in the creator profile forms (#1064)
- feat(migration): emoji space-invaders + progress screen polish (#1063)
- feat: rename Coworker mode to Ask first
- feat: run read-only integration actions without the approval card
- feat(chat): upload whole folders as chat attachments (HOU-808) (#1045)
- feat: label Linear issues at the cut, not just at publish (#1049)
- feat: presence-style status dot on catalog rows (#1040)
- feat: sign-in referral panel reads Coming soon; localize panel strings (#1039)
- feat: Linear release stamp on cloud train publish (#1038)
- feat(store): starter-agent publish pipeline, admin grant UI, docs and i18n cleanup
- feat(integrations): turn the catalog spotlight into a "Most used" section
- feat(analytics): stamp the display name as a person property on sign-in
- feat(analytics): emit user_signed_up on first sign-in of a new GCIP account
- feat(providers): 2026-07 catalog QA sweep + Gemini 3.6 Flash / 3.5 Flash-Lite
- feat(analytics): emit $ai_generation per model turn to light up the AI Usage dashboard
- feat(routines): chat-first redesign of the Routines tab
- feat(catalog): add Kimi K3 (kimi-coding) by backporting the pi-ai 0.80.9 entry
- feat(store): creator profiles - in-app editor, @handle pages, analytics, verified badges
- feat(app): unified catalog search across integrations, AI hub, and skills
- feat(ui): two-section catalog shell with unified search grammar
- feat(providers): hide regional duplicate deployments from the catalog
- feat(store): one-click Open in Houston install from the website
- feat(analytics): instrument usage, permissions, org, AI hub, skills, cloud migration
- feat(analytics): instrument feature-adoption gaps + model/provider on sends
- feat(sentry): tag client events with their deployment (#991)
- feat(dev): add
pnpm dev:stagingto run the desktop against remote staging (#994) - feat(app): send app-version header to the gateway + blocking required-update screen (#985)
- feat(host): build identity on /v1/version + pod-level /activity busy probe (#984)
- feat(chat): apply AI Mode changes to the running turn, like Claude Code's shift+tab
- feat(files): transparent files panel + move-conflict dialog (#966)
- feat(store): app parity wave - categories, integration filter, reporting, owner dashboard
- feat(store): extract @houston/agentstore-client SDK and migrate both frontends
- feat(teams): agent-centric Permissions, on-agent mount, and permission-aware agents (#954)
- feat(teams): admin Permissions hub — People access lens + blocked-state deep links (#948)
- feat(usage): split the Usage page into Compute usage / Model usage panes
- feat(integrations): review and revoke always-allowed actions per agent (#942)
- feat(integrations): surface connected-but-ungranted apps on the agent tab (#939)
- feat(files): redesign the Files tab as a Drive-style card grid (#960)
- feat(analytics): enable session recordings + heatmaps (masked)
- feat(chat): add conversation map
- feat(onboarding): email steps - floating brand marks, one clear final action
- feat(onboarding): preselect the OS locale on the language gate
- feat(chat): toast when a mode change lands on the next message
- feat(usage): show time worked instead of engine up-time + chart legibility (#936)
- feat(usage): split accounts into AI subscriptions and AI per token sections
- feat(sentry): debuggable engine events — synthetic stacks, version tag, severity correctness (#937)
- feat(ios): move auth to GCIP with Apple, Google, Microsoft, and email-code sign-in (#938)
- feat(secrets): use gateway custody for managed agents (#899)
- feat(usage): show how long agents ran (compute usage, hosted cloud) (#925)
- feat(models): curate provider model lists via one shared visibility table (#928)
- feat(create-agent): model picker in the Create-with-AI step (#927)
- feat(usage): meter token spend locally for API-key providers with no usage API
- feat(chat): preview + download files the agent created from chat (#923)
- feat(onboarding): larger Gmail/Outlook rows on the connect-email step
- feat(onboarding): centered pill-grid segment screen with skip + PostHog person property
- feat(analytics): enable rage + dead click capture, fully masked
- feat(engine): Sentry crash reporting for the TS engine (pods + desktop sidecar) (#907)
- feat(onboarding): add reset segment setting
- feat(onboarding): add segmentation screen
- feat(website): unlisted bootcamp landing page at /bootcamp/ (#906)
- feat: Admin > Agents drill-in to manage one agent's access in place
- feat: visible workspace policy everywhere and a settings-style Admin page
- feat: move org allowlists to an Admin page, keep Integrations personal
- feat(dev): one pnpm dev — full local stack, multiplayer included (#900)
- feat(migration): reconnect checklist from the legacy Composio consumer account (#895)
- feat(local-model): share a tunnelled local model with your team (#860)
- feat(auth): provider pill row + six-box pin input on the login screen
- feat(design): visible sidebar selected state via sidebar-active token
- feat(board): say Archive/Archived instead of Complete/Completed
- feat: per-account provider usage page (top-level Usage view) (#890)
Fixes
- fix(release): stamp the whole train in Linear; clean up superseded drafts (#1074)
- fix(teams): bridge team spaces into the switcher; invite follow-through; spaces e2e
- fix(teams): personal space never offers a broken invite flow
- fix(auth): register the houston:// scheme at runtime on Windows
- fix: surface the real cause when a creator profile save or photo upload fails (#1062)
- fix(i18n): translate the pre-auth sign-in screen (es/pt)
- fix(analytics): let session replay start by not disabling flags
- fix(providers): report a provider connected only when it can actually serve a turn (#1054)
- fix(credentials): make the desktop reconcile a fill-only push so it cannot revoke the token family (HOU-855) (#1056)
- fix(runtime): show the connect card in Autopilot mode (HOU-853) (#1055)
- fix(chat): flush a stranded reconnect auto-continue with a history-probe watchdog (HOU-849) (#1052)
- fix(integrations): serve the secure credential card through the per-agent surface so managed-cloud saves stop 404ing (HOU-823) (#1053)
- fix(app): accept the Claude sign-in code when the browser hand-off is blocked (HOU-839) (#1043)
- fix: keep the open chat when clicking outside the board panel (#1048)
- fix(teams): resume abandoned agent moves so a wedged move can't brick the agent (HOU-817) (#1044)
- fix(ci): green-main guard must ignore the cut's own failed runs
- fix(host): stop exhausting the Linux inotify watch budget (HOU-841) (#1042)
- fix(ci): surface GitHub's rejection message in the cut token probe
- fix(ci): tokenless checkout + API-validated PAT for the daily cut
- fix: show the full email on the sign-in continue button (#1041)
- fix: never sign users out on secure-storage read faults (#1037)
- fix(integrations): platform-correct custom-secret file permissions
- fix(integrations): never dead-end the secure credential save on schemeless specs
- fix(host): quiesce of an absent runtime is a no-op, not a launcher sleep error
- fix(analytics): identify the person before emitting user_signed_up
- fix(providers): route Copilot Business connects through github.com
- fix(providers): drop the two Cloudflare providers from the catalog
- fix(runtime): classify no-credit provider errors as quota_exhausted
- fix(host): quiesce the agent runtime before a rename so the old name cannot resurrect
- fix(host): serve the Rust-era agent color so migrated agents keep their colors
- fix(integrations): pin Composio tool version to latest on search + execute
- fix(chat): block image attachments when the active model has no vision
- fix(host): no-auth Composio toolkits are not connectable apps (#1012)
- fix(chat): render URL-labeled links inline instead of a clipped black pill
- fix(app): repair Linux AppImage sign-in end to end (#1019)
- fix(providers): friendly toast for a GitHub account without Copilot access (#1017)
- fix(providers): verify Google keys against the models list and surface typed connect errors (#1016)
- fix(providers): repair the Windows shell env for Claude sign-in and turns (#1014)
- fix(app): guard agent-JSON reads against wrong top-level container shape (#1013)
- fix(website): download buttons serve the newest cloud prerelease (#1009)
- fix(routines): adapt intake connect card to per-slug connect-flow states
- fix(onboarding): migration-flow polish, durable onboarding-completed signal, deleted-account sign-out (#999)
- fix(store-sync): skip an over-cap file instead of letting it block every sync pass (#989)
- fix(runtime): size Claude context fill from per-request usage, not the turn aggregate (#988)
- fix(sentry): stop expected operational failures from spamming error events (#986)
- fix(runtime-client): retry transient object-store failures instead of failing hydrate/sync (#987)
- fix(runtime-client): tolerate files vanishing mid-walk in syncBack (#983)
- fix(host): cover all delivery paths of the recursive-watcher ENOENT race (#981)
- fix(app): reconnect card for a disconnected local model + unknown-state polish (#980)
- fix(local-model): connect directly when the deployment has no tunnel relay (#978)
- fix(chat): unwedge the reconnect auto-continue from the send queue (#979)
- fix(host): disconnect a terminally-rejected credential instead of retrying its dead refresh token forever (#977)
- fix(skills): require a description before creating a skill from scratch (#976)
- fix(app): keep the Codex sign-in relay off for a loopback hosted gateway (#955)
- fix(website): unblock download gate and de-jank modal open (#975)
- fix(providers): report unknown, not signed-out, when the engine is unreachable (#973)
- fix(host): demote the Linux recursive-watcher ENOENT race to a warning (#970)
- fix: stop a double-fired first send from losing a mission (#969)
- fix(usage): only show the user's own agents, count messages not tasks (#967)
- fix(onboarding): skip only on failure; the sent payoff says check your inbox
- fix(onboarding): email mission runs in Autopilot; skip waits for the agent's reply
- fix(providers): fail Codex sign-in port conflicts fast, loud, and localized (#945)
- fix(e2e): conversation map spec earns its 3-moment minimum on the fake host
- fix(agentstore): pin folder-entry timestamps — reproducible skill zips (#961)
- fix(sentry): count orgs as users-affected, trim the runtime capture frame (#957)
- fix(usage): hide system/ghost agents from the Time worked list (#956)
- fix(analytics): admit detected_locale through the branch cleanProps filter
- fix(chat): conversation map floats over the transcript + clean marker previews
- fix(onboarding): ask the work-segment question at most once per user
- fix(web): provider connect no longer reports success it did not earn
- fix(auth): desktop Apple sign-in returns via gateway bridge + houston:// deep link
- fix(app): paint cached mission cards on cold open while the pod wakes (#950)
- fix(sentry): attach the synthetic stack as a thread, keep the message as the issue title (#949)
- fix(design): floating surfaces are solid everywhere, no glass modals
- fix(chat): approval card drops the technical param rows
- fix(host): satisfy noUncheckedIndexedAccess in the provider-usage route test
- fix(usage): Copilot usage no longer reads "sign in again" on a healthy connection
- fix(onboarding): require initial email action
- fix(chat): pin the agent's configured model on setup-chat kickoffs
- fix(runtime): expire abandoned OAuth logins so they release the callback port (#932)
- fix(settings): remove onboarding segment reset from production settings
- fix(design): solid dialog + create-agent cards, no see-through surfaces
- fix(e2e): scope usage-compute agent rows to the Running time section
- fix(design): opaque floating surfaces on desktop (WebView2 backdrop-filter)
- fix(chat): make pasted links readable inside the user message bubble
- fix(usage): honest OpenRouter balance + "not metered yet" copy
- fix(routines): stop cron routines vanishing after an edit (#924)
- fix(fake-host): split the setup-runtime connect surface into gate + first-run slots
- fix(e2e): onboarding connect spec survives the connected setup-runtime
- fix(providers): live-verify a pasted API key before storing it
- fix(web): make the engine gate reachability-only; onboarding owns connect
- fix(chat): make the in-chat integration approval card work on hosted cloud + stop the footer overflowing (#919)
- fix(fake-host): serve the /setup-runtime connect surface the WebApp gate probes
- fix(web): point the standalone connect gate at /setup-runtime
- fix(e2e): teach the fake host the /setup-runtime connect surface
- fix(web): probe the host's /setup-runtime connect surface, not a flat /auth/status
- fix(web): point the connect gate at the host's /setup-runtime surface
- fix(providers): curate key-dashboard URLs for the remaining api-key providers
- fix(providers): connect any pi api-key provider from the UI
- fix(integrations): never mint a bare custom OAuth auth config (Meta Ads)
- fix(onboarding): email test-send card shows only the option; Omitir actually skips
- fix(app): paint sidebar needs-you badges through a pod cold start (#914)
- fix(onboarding): drop the "Another provider" row from the connect-email step
- fix: cloud-migration wizard recovery — keep the Settings retry after partial runs, escape hatch on errors (#908)
- fix(anthropic): repair OAuth connect + credential lifecycle end to end (#910)
- fix(app): keep cached mission cards painted while an asleep pod wakes (#911)
- fix(ai-hub): stop curating OAuth providers' model lists — hub now matches the chat picker (#909)
- fix(onboarding): adapt segmentation screen to current main after rebase
- fix: cloud-migration backup fails on Windows with 'Acceso denegado (os error 5)' (#905)
- fix(sidebar): stop agent list overflowing onto the user footer in short windows (#898)
- fix(release): preserve Bun sidecar in Linux AppImage (#897)
- fix(release): give vite build 4GB Node heap on low-RAM runners (#896)
- fix(chat): stop hiding a reply whose text contains an auth code (HOU-734) (#885)
- fix(migration): skip the empty Reconnect-your-apps step (#893)
- fix(ui): keep the open chat panel mounted while its card is transiently absent (#891)
Docs
- docs: add the app node:test suite to the test-commands table
- docs: KB reflects composer-replacing interaction stepper (HOU-870)
- docs(kb): drop the resolved sign-in-screen i18n follow-up note
- docs: record the catalog redesign in the knowledge base and inventory
- docs(kb): document agentstore-client SDK, store parity features, deep-link install
- docs(website): point developer docs at the real gateway, centralize the URL (#993)
- docs(kb): drop retired theagentlibrary note from agent-store KB
CI & infra
- ci: retrigger
- ci: raise the web job timeout to 30m — the e2e suite outgrew 20m
- ci(train): publishing the cloud draft ships the whole train
- ci(images): publish the served /v1/catalog as an engine-pod-catalog artifact
- ci(release): cut the cloud release automatically each weekday morning
- ci(release): build a staging-gateway QA DMG for every cloud release
- ci(website): pass POSTHOG_KEY to the site build and fail loudly when absent
- ci(images): build engine-pod/agentstore on tag push, notify prod sepa… (#992)
Changes
- test: notification body-key cases follow the branded-question model (HOU-885)
- test: prove the Always-allow circle end-to-end through the dispatch route
- perf(chat): open chats on the transcript tail + scroll-up lazy-load (HOU-819) (#1051)
- style(chat): drop the amber triangle chip from the attachment-rejection dialog
- test(routines): adapt stale e2e specs to the chat-first Routines redesign (#1010)
- refactor(files): flatten the Files tab onto the canvas (#1007)
- test(e2e): update catalog specs for the unified catalog redesign
- test(onboarding): skip-route assertion follows the failure-gated shouldOfferSkip
- refactor(settings): drop the Connected accounts shortcut row (#947)
- refactor(integrations): fold Settings > Connected accounts into the Integrations page (#941)
- test(onboarding): update language-gate e2e to the preselect + Continue contract
- test(web): approval e2e pins the card without param rows
- test(onboarding): select required segment in e2e
- refactor(usage): drop the billing sections' subtitles
- test(fake-host): serve the pre-agent /setup-runtime/* connect surface
- test(e2e): align onboarding specs with the segment gate and the welcome-less flow
- perf(host): parallelize store hydration — cuts managed-pod wake by ~10s (#901)
Before you upgrade
- Quit Houston before installing. macOS doesn't always replace a running app. If in doubt:
rm -rf /Applications/Houston.appand drag the new copy in.
Full changelog: v0.5.6...cloud-v0.5.28
Linear — cloud-v0.5.28
(no project)
- HOU-819 — Chats hang for a while before opening or accepting input 🐛
- HOU-883 — Design QA gates: Playwright visual regression suite + token-contract hex cleanup
- HOU-882 — Design process infrastructure: DESIGN.md, frontend-design + design-review skills, mandatory UI workflow
- HOU-884 — Landing page rebuild on design tokens (warm editorial direction)
- HOU-830 — Suggestion: surface the most popular integrations first, full list alphabetical 🐛
- HOU-829 — Reconnect to Anthropic error after update: Claude sign-in failed (exit 1) on Windows 🐛
AI Models
- HOU-839 — Anthropic new update that requires typing a code breaks our OAuth
- HOU-855 — Desktop credential reconcile clobbers the gateway's rotated Anthropic token, revoking the whole family
- HOU-856 — Gateway cannot refresh GitHub Copilot: cloud Copilot breaks ~25 minutes after connect
Agent Store
- HOU-864 — I couldn't add any picture to my profile in the agent store
- HOU-868 — Agent Store profile: only the handle is required, everything else optional
- HOU-865 — I clicked saved for my profile and it said "You profile could not be saved"
Analytics
- HOU-755 — Track AI models providers, both usage and when people connect to it. Let's find a way to track if people are creating accounts with them from houston! (like a create account button maybe?)
- HOU-754 — Feature adoption instrumentation
- HOU-753 — Slack notification when a new user signs up
- HOU-752 — Visible warning when the PostHog key is missing on the website
Automations
- HOU-810 — Every time an user creates an account in Houston, we should be notified via Slack
Backend
- HOU-800 — Load testing on staging
Chat Experience
- HOU-849 — Fix autocontinue conversation after reconnect
- HOU-853 — Show connection card in autopilot mode
- HOU-846 — Coworker mode it is unusable with integrations
- HOU-845 — Change the name of the "Cowork" mode to something like Ask permissions or something that is more clear that that's the difference
- HOU-869 — Integration approvals are permission jargon; replace with a plain confirmation card (Do it / Not now)
- HOU-870 — Interaction cards: free-text input on every card and replace the chat composer while a card is pending
- HOU-880 — ask_user questions must offer options by default; optionless card shows wrong placeholder
- HOU-885 — One card system: integration confirmations are branded ask_user questions; approval gate removed
- HOU-850 — Only show available models in chat
Files
- HOU-808 — Being able to upload folders of files - +57 317 8950374 🐛
Global Interfaces & Components
- HOU-815 — Have persistent login
Integrations
- HOU-826 — LinkedIn integration can't publish: connector sends a retired API version (426 NONEXISTENT_VERSION) 🐛
- HOU-823 — Tally integration cannot be connected directly 🐛
Migration
- HOU-737 — Have a micro game in there
Multiplayer
- HOU-817 — App unusable: starting a mission fails (error ccd6598049884b2897e97937d6dd1ea3) 🐛
- HOU-824 — Inviting teammates to a team fails 🐛
- HOU-871 — The overall multiplayer experience was created, but has never been tried nor tested we should make sure it is working and it makes sense
- HOU-881 — Space switcher never lists teams: the adapter never fetches the /v1/workspaces bridge
- HOU-875 — After creating a team you land in an empty space with no pointer to invite people
- HOU-878 — E2E cannot express team spaces: fake-host spaces arming + coverage for the personal/team gating
- HOU-876 — Teammate names and avatars are stubbed: initials only across mission attribution and rosters
- HOU-877 — Gateway org-write store errors panic into opaque 500s (no error code)
- HOU-874 — Team invites send no email: the invitee never learns they were invited
- HOU-825 — Creating a new team fails (error f4d2e5e0f8d441d0869f53b3afe06a0d) 🐛
Onboarding
- HOU-756 — Onboarding is only in english 🐛
- HOU-757 — Windows login is not working 🐛
- HOU-758 — Apple login is not working 🐛
WhatsApp draft
🚀 Nueva versión de Houston!
✅ Being able to upload folders of files - +57 317 8950374
✅ App unusable: starting a mission fails (error ccd6598049884b2897e97937d6dd1ea3)
✅ Anthropic new update that requires typing a code breaks our OAuth
✅ Fix autocontinue conversation after reconnect
✅ Show connection card in autopilot mode
✅ Desktop credential reconcile clobbers the gateway's rotated Anthropic token, revoking the whole family
✅ Chats hang for a while before opening or accepting input
✅ I couldn't add any picture to my profile in the agent store
✅ Have a micro game in there
✅ Agent Store profile: only the handle is required, everything else optional
✅ Onboarding is only in english
✅ Windows login is not working
✅ Inviting teammates to a team fails
✅ The overall multiplayer experience was created, but has never been tried nor tested we should make sure it is working and it makes sense
✅ Space switcher never lists teams: the adapter never fetches the /v1/workspaces bridge
✅ After creating a team you land in an empty space with no pointer to invite people
✅ E2E cannot express team spaces: fake-host spaces arming + coverage for the personal/team gating
✅ Teammate names and avatars are stubbed: initials only across mission attribution and rosters
✅ Design QA gates: Playwright visual regression suite + token-contract hex cleanup
✅ Design process infrastructure: DESIGN.md, frontend-design + design-review skills, mandatory UI workflow
✅ Landing page rebuild on design tokens (warm editorial direction)
✅ Coworker mode it is unusable with integrations
✅ Change the name of the "Cowork" mode to something like Ask permissions or something that is more clear that that's the difference
✅ Integration approvals are permission jargon; replace with a plain confirmation card (Do it / Not now)
✅ Interaction cards: free-text input on every card and replace the chat composer while a card is pending
✅ ask_user questions must offer options by default; optionless card shows wrong placeholder
✅ One card system: integration confirmations are branded ask_user questions; approval gate removed
✅ Gateway org-write store errors panic into opaque 500s (no error code)
✅ Team invites send no email: the invitee never learns they were invited
✅ I clicked saved for my profile and it said "You profile could not be saved"
✅ Gateway cannot refresh GitHub Copilot: cloud Copilot breaks ~25 minutes after connect
✅ Only show available models in chat
✅ Suggestion: surface the most popular integrations first, full list alphabetical
✅ Reconnect to Anthropic error after update: Claude sign-in failed (exit 1) on Windows
✅ LinkedIn integration can't publish: connector sends a retired API version (426 NONEXISTENT_VERSION)
✅ Creating a new team fails (error f4d2e5e0f8d441d0869f53b3afe06a0d)
✅ Tally integration cannot be connected directly
✅ Have persistent login
✅ Every time an user creates an account in Houston, we should be notified via Slack
✅ Load testing on staging
✅ Apple login is not working
✅ Track AI models providers, both usage and when people connect to it. Let's find a way to track if people are creating accounts with them from houston! (like a create account button maybe?)
✅ Feature adoption instrumentation
✅ Slack notification when a new user signs up
✅ Visible warning when the PostHog key is missing on the website
Gracias a todos los que reportaron 🙌
Notify reporters (then clear the Notify pending label):
- HOU-808 →
⚠️ no phone on issue - HOU-817 → +32475407080, +573042508033
- HOU-819 → +573227231739, +573183977808, +573503983550
- HOU-756 →
⚠️ no phone on issue - HOU-757 →
⚠️ no phone on issue - HOU-824 → +32475407080, +573042508033
- HOU-830 → +5216121521166
- HOU-829 → +573506535829
- HOU-826 → +5115534105446
- HOU-825 → +32475407080, +573042508033
- HOU-823 → +573142934127
- HOU-758 →
⚠️ no phone on issue