Skip to content

KyoubeAI 1.8.0

Latest

Choose a tag to compare

@jknigel jknigel released this 10 Oct 02:36
· 17 commits to main since this release

Kyoube apps and agents can now work with the other services your company uses, such as payments, CRMs, shipping and weather, through connections an admin sets up. API keys never reach the browser.

What's in 1.8.0

Connections. An instance admin adds a connection under Settings → Plugins → Kyoube Data & Apps, with the company selected: a name, the service's https address, how it signs in (a Bearer token, an API-key header, or Basic) and a company secret holding the key. Each connection is read-only or read-write. Company Settings → Data access shows whether each one is ready, which apps use it, and which agents may call it.

Apps that call out. An app names the connections it uses and calls them with kyoube.connections.call. It works as the person using it: groups decide who can open the app, and changes at the other end need that person's write access. When a new app version adds a connection, or turns a read-only one read-write, a person publishes it after seeing exactly which services it can reach. An agent can't.

Agents that call out. An owner or admin can let an agent use a connection, read-only or read-write. With the guardrail on, an agent's write waits for a person's OK. The Kyoube Apps skill teaches agents how to find connections, use them, and what to ask you to set up.

Kept where you pointed it. A call can only reach addresses under the connection's base address. Tricks that try to step outside it are refused, and every call is recorded without its contents.

Update

From 1.7, run ./update.sh. It backs up first, and ./update.sh --rollback returns to 1.7. The update adds one empty table and changes nothing until an admin adds a connection.

How connections work, and what they don't cover, is in docs/connections.md. The full list of changes is in CHANGELOG.md.