Repository navigation
Releases: passioncode-ai/fabric-switchboard
Release list
v0.6.15
Fabric Switchboard on Linux (x64 and arm64) and on Windows on ARM, beside macOS (Apple silicon and
Intel) and Windows x64. Launching a session now picks its folder with the system picker and an
Isolated session box, a sign-in left waiting in Terminal ends with one Cancel, and the ordinary
Kimi Code sign-in on kimi.ai is read correctly.
Windows: windows_authenticode: NOT_SIGNED. Built natively for x64 and arm64; the installers are
not yet Authenticode-signed (the signing identity validation is in progress), so SmartScreen may warn.
Added
-
Linux, x64 and arm64 (SB-88; operator decision 2026-10-09: every PassionCode.ai product runs
on Apple silicon and Intel Macs, Windows and Linux). A .deb (app andswitchboardonPATH), an
AppImage that updates itself, and the CLI alone. Credentials live in the Secret Service (GNOME
Keyring, KWallet, KeePassXC), never in a plain file; sessions open in your terminal app
($TERMINAL, then the common ones); the session scripts no longer need zsh. Tested in the release
and nightly workflows against a real GNOME Keyring, with the app's smoke check under Xvfb. -
Windows on ARM (arm64): a native installer and CLI beside the x64 ones (SB-88).
-
Launch any account in a folder you pick (operator decision 2026-10-09, SB-86): the row menu's
Launch… replaces Launch isolated… and Launch managed…; an Isolated session box chooses the
mode, ticked and locked when only an isolated session is possible. Every folder Switchboard asks
for — launches, Kimi Code, agents, projects, project rules — is chosen with the system folder
picker, never typed; the picker opens at the last folder chosen, remembered across restarts. -
A provider terms notice (operator decision 2026-10-08, SCN-049): Accounts shows it from the first
start, while the first account is added, until you dismiss it; About shows it always. It says to
use Switchboard in line with the terms of Anthropic and OpenAI, that breaking a provider's terms
can get the account blocked, and that you are responsible for how you use your accounts.
Changed
- Kimi Code accounts use the same compact row as Claude Code and Codex: a small Launch… (or
Sign in) and a ⋯ menu with Sign in again and Remove…; Add Kimi Code account and Refresh
are small buttons (SB-86). - A failed quota check logs the provider's HTTP status as a number (
usage_checkhttp_error
status), so a refusal (403) and an outage (502) are told apart (SB-85).
Fixed
- A CLI or agent request to the running app could fail as "Control request did not complete"
with nothing sent (SB-90): the second request on the control connection went out before the
connection was ready again. Seen on Linux in 12 of 44 requests; macOS's timing mostly hid it. - Cancel ends a sign-in still waiting in Terminal instead of refusing until its window is closed;
a refused Cancel no longer stops the banner from noticing Terminal, nor offers a Retry that
meant finishing. The same for Kimi Code, whose sign-in now notices a closed Terminal (SB-83). - The ordinary Kimi Code sign-in on kimi.ai read as signed out when an older kimi.com login or a
staleregionmarker remained: Switchboard now reads the login slotconfig.tomlnames, as
kimidoes (SB-84).
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc
v0.6.14
Kimi Code accounts, Hermes model settings and a shared OpenRouter key for supported agents.
This release also restores Claude account activation when Claude Code leaves only MCP sign-ins
in its Keychain entry, and explains when a running Switchboard needs a restart after an update.
It includes the changes prepared for 0.6.11, 0.6.12 and 0.6.13, which were superseded before publication.
Windows: windows_authenticode: NOT_SIGNED. Built natively; the installer is not yet
Authenticode-signed, so SmartScreen may warn.
Added
- Kimi Code subscription accounts (SB-81): Accounts → Kimi Code signs an account in with the
officialkimi login(in Terminal), shows its membership tier and 5-hour, 7-day and monthly
usage, launcheskimion it in a folder, and shows the ordinarykimi's sign-in. Each login
stays in its own folder; Switchboard never copies or renews it. CLIswitchboard kimi, MCP
switchboard_kimi_accounts. - Hermes's model and provider on the Agents screen, changed on request through Hermes's own
hermes config set(SB-80). CLIswitchboard agents hermes [set --provider --model], MCP
switchboard_hermes_status/switchboard_hermes_set. - One OpenRouter key for agents, saved once:
switchboard agents openrouter set --key-stdin(the
key is piped on stdin, never an argument) keeps it in the OS vault;statusshows what the key
may still spend, asked of OpenRouter itself;modelchanges the model agents start on;
removedeletes it. Agents read it withswitchboard agents key --service openrouter, and an
agent over MCP sees the status and sets the model (switchboard_openrouter_status,
switchboard_openrouter_model) — never the key. Encrypted backups carry it, so it returns
after a reinstall. First slice of SB-79. - Agents launch on the OpenRouter key (SB-79b):
switchboard agents launch <agent> --openrouter [--model <id>], and in the app Agents → OpenRouter key for agents (add, replace, change the
model, remove; the balance OpenRouter reports) with Launch on OpenRouter in each agent's
setup. Ten agents: Hermes, Kilo, omp, pi, Kimi Code, Aider, OpenCode, Goose, Qwen Code, Crush.
The key reaches the agent only through its environment, read by the session script when it
starts.
Fixes
- Switching to a saved Claude account works when Claude Code has left only shared MCP or
plugin sign-ins in its Keychain entry. Those sign-ins are preserved. An unrecognized or
malformed entry is still refused without changing it. - After an update is installed while an earlier Switchboard still runs, a
switchboardcommand it
does not know (for examplelaunch --in-place) now says to restart Switchboard to finish the
update, instead of “Control request refused”. The running Switchboard names its version to the
command, and every refused control request is logged with its reason. switchboard uninstallalso removes the Kimi Code login folders (kimi).switchboard --data-dir <folder> backup listno longer lists the real backups, and
backup restorethere refuses instead of loading the real accounts into the scratch store
(SB-61).- Every
switchboardcommand and argument explains itself in--help, and
switchboard accounts updatetakes--labelor--enabledalone; the other keeps its value
(SB-68). - A busy machine's
~/.claude.jsonover 1 MiB no longer silently stops Switchboard from
noticing a new Claude Code sign-in, and a file caught half-written is not taken for a changed
sign-in (SB-78). - On Windows, a quit that starts the update installer drains for 5 seconds instead of 8, so the
installer always has time to start (SB-78). - macOS: a failed install at Restart to update says the administrator password was refused
only when one was asked for (SB-78). - Signing in again to an account saved in several pools renews every copy in one step: if a
credential cannot be written, all copies keep the previous sign-in instead of some moving on
(SB-78). - Deleting a project and removing a project rule now ask first, like removing an account; a
rule's Pause stays the one-step choice (SB-69). - The rule dialog no longer offers “Claude Code login” for an account reserved by a project,
which was refused after saving (SB-69). - A failed read of the Projects or Activity screen is titled for that screen, not “Unable to
load accounts” (SB-69).
Build maintenance
- Native config-reader tests create user-owned files on Windows, including elevated CI, while retaining the strict production ownership check.
- The OpenRouter CLI test provides its own synthetic Hermes executable, so a clean Windows build no longer depends on an installed third-party agent.
- Update the build-time
source-map-jsdependency to 1.2.2, fixing GHSA-68fv-2mgg-jv7q.
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc
v0.6.10
Switchboard speaks Russian, updates behave like every PassionCode.ai product, and the fixes of
the 2026-10-07 audit. 0.6.9 was never published — its Windows build failed — so this release also
carries 0.6.9's changes (below). If you run 0.6.1 or later, this version arrives on its own.
Signed by the same team (KJ35UYYL22).
Windows: windows_authenticode: NOT_SIGNED. The installer is built natively but not
Authenticode-signed until the organization's Azure signing account exists; SmartScreen may warn.
Switchboard in Russian
- The whole interface is available in Russian: every screen, dialog, notice, error the window
shows, the first-run tour and the menu-bar (Windows: notification-area) menu. Switchboard follows
the language of the operating system; About → Language overrides it (Same as system, English,
Русский) and reloads the window. Dates and times follow the language. Terms follow the
PassionCode.ai glossary (fabric-workspace knowledge/localization.md, track RM-25). - The journal names its events in the interface language (“Account added · done”) instead of the
recorded codes.
Updates behave like every PassionCode.ai product (LC-16)
- A ready update now starts on its own at an idle moment — window hidden, no managed request
running, no sign-in waiting — instead of only at the next start or Restart to update. Nothing
running in Terminal is stopped. - About → Check for updates checks at once, also with automatic updates off.
- A release marked as needing a manual step is held, with the reason shown.
- The log records downloads (
update_download) and why a copy never checks.
Fixes
- “Turn on for Claude Code” reports the threshold and headroom it actually saved, not always
90 % / 10 points (SB-67). - API-key and setup-token rows say “Not checked automatically · Quota checks need OAuth” instead of
leaving the second line empty (SB-67). - Try again after a sign-in no longer starts a new sign-in when cancelling the old one failed and
left its staging folder behind; the error is shown instead (SB-67). - On Windows the app no longer says “Mac”, “menu-bar icon” or “Keychain”: it names the
notification area and Windows' own key protection (SB-66). - The Windows build compiles its tests again: a test added in 0.6.9 lost its macOS-only mark,
which stopped the 0.6.9 Windows release job. - The automatic hand-over (SB-73) no longer hands work to another saved copy of the same spent
login, never blames the ordinary CLI's limit on a workflow whose executor is an account
Switchboard does not hold or may be a session Switchboard launched, waits five minutes after a
scan that found nothing instead of starting Project Observatory every minute, gives the engine
15 seconds off the monitor's thread, and kills everything the engine started when it hangs. - Windows: turning automatic updates off discards an installer already waiting for the quit, and
an ordinary quit installs nothing while updates are off. - An agent that is not installed ("Aider is not installed. Install it first…") is named in the
error instead of a generic message, in both languages. - A session that could not start in place releases its account at once instead of blocking it for
ten minutes. - A macOS update install that stalls says to reopen Switchboard instead of promising a retry that
would not come. - Russian: reset times, the paused countdown, the native app's start-up timeout and the estimate
check read correctly in Russian. - Interface copy matches the brand pack: “Automatic switching” everywhere (no “rotation”), “Switch”
instead of “Native Claude activation”, “Terminal launch requested” rather than “launched”,
“PassionCode.ai”, and the tour's first two steps describe what the buttons do (SB-66).
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc
v0.6.8
You choose which agents take over a task when an account runs out, and Switchboard follows that
order on its own. Nothing changes until you set a chain. If you run 0.6.1 or later, this version
arrives on its own. Signed by the same team (KJ35UYYL22).
Windows: windows_authenticode: NOT_SIGNED. The installer is built natively but not
Authenticode-signed until the organization's Azure signing account exists; SmartScreen may warn.
Fallback chains
switchboard chainand the MCP toolsswitchboard_chain_get/switchboard_chain_setkeep your
order of agents for continuing work when an account runs out — for the whole machine, a project
or a single task; the narrowest one applies, and none applies until you set one. A ready-made
order: Claude Code → Codex → Kimi Code → Hermes. An agent can be pinned to an account or to a
paid key named in Project Observatory's vault; other agents never get a Claude or ChatGPT
subscription.- When an agent's account runs out and a chain is set, its work moves on by itself. For a task
recorded as a Project Observatory workflow, Switchboard hands it to the next agent of the chain
that has an account with quota — Claude Code or Codex for now — and opens that session in the
task's folder, starting from the last checkpoint. Without a chain nothing happens. Kimi Code and
Hermes in a chain are skipped until paid-key ceilings are in place.
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc
v0.6.7
An agent task that ran out of its limit in Claude Code can now continue in Codex, and back, from
the same point. If you run 0.6.1 or later, this version arrives on its own. Signed by the same
team (KJ35UYYL22).
Windows: windows_authenticode: NOT_SIGNED. The installer is built natively but not
Authenticode-signed until the organization's Azure signing account exists; SmartScreen may warn.
Continuing work on another agent
switchboard continuehands a workflow from Claude Code to Codex, or back, with its context:
the new session starts from the same checkpoint and constraints, told that the work comes from
another agent. Before, it accepted only an account of the same provider. A workflow left by an
agent Switchboard does not run itself (Hermes, Kimi Code) can be taken over the same way.
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc
v0.6.6
Signing in again to an account you already saved no longer renames it or copies it into another
pool. If you run 0.6.1 or later, this version arrives on its own. Signed by the same team
(KJ35UYYL22).
Windows: windows_authenticode: NOT_SIGNED. The installer is built natively but not
Authenticode-signed until the organization's Azure signing account exists; SmartScreen may warn.
Signing in
- Try again in the sign-in banner repeats the same sign-in. Before, it lost the account's name
and pool and started over in the default pool: finishing it renamed a saved account to its email,
or added a second copy of an account saved in another pool — including an account reserved for a
project, which then showed up for switching Claude Code. - Signing in to an account you already saved updates it where it is, from its row, from
+ Add account or from Try again: its name and pool stay, every saved copy gets the new
sign-in, and the notice says it is signed in again. A new account is added only when it is not
saved anywhere yet.
Under the hood
- The local proxy checks an agent's key in constant time, so response timing cannot reveal which
key matched. - The MCP tool descriptions for
switchboard_usageandswitchboard_project_applynow describe
what the tools return.
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc
v0.6.5
The tag v0.6.4 was never published; 0.6.5 carries its changes (below) and this fix. If you run
0.6.1 or 0.6.2, this version arrives on its own. Signed by the same team (KJ35UYYL22).
Windows: windows_authenticode: NOT_SIGNED. The installer is built natively but not
Authenticode-signed until the organization's Azure signing account exists; SmartScreen may warn.
Switching accounts
- Switch works again when Claude Code's sign-in and settings disagree. After an interrupted
switch or a half-finished/login, Claude Code's settings can name one account while it is
signed in to another one you saved in Switchboard. Every switch then stopped with The Claude
Code sign-in does not match the account named in its settings. Now Switchboard asks Anthropic
whose sign-in it is, keeps it under that account and switches. - Switchboard trusts Anthropic's answer over its own saved copies. A copy saved under the wrong
account no longer blocks a switch, and it can no longer overwrite another account's sign-in:
when Anthropic cannot be asked, the switch stops with Switchboard could not confirm which
account Claude Code is signed in to and changes nothing.
Agents and MCP
switchboard mcp --read-onlyno longer asks the provider when an agent setsrefresh: true
onswitchboard_usage: it answers with the stored observation and says so. Before, a
read-only server could still run a quota check, store its answer and renew a sign-in.- The plugin's tool reference now gives the real freshness limit without a rotation policy:
900 seconds, not 300.
Diagnostics
- The log (
~/Library/Logs/Fabric Switchboard/switchboard.log) records why a background quota
check failed, as a short code such asunreachableorrejected. It never records the
provider's reply or a token.
Agent catalog
- Catalog notes for ZCode, Kimi Code, Hermes and OpenClaw were checked against their sources:
ZCode gained a ready config snippet, and OpenClaw can read the key from an environment
variable.
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc
v0.6.2
Switchboard uses far less of your Mac in the background, and an agent that runs out of its limit
mid-task can be picked up by another of your accounts. If you run 0.6.1, this version arrives on
its own. Signed by the same team (KJ35UYYL22).
Windows: windows_authenticode: NOT_SIGNED. The installer is built natively but not
Authenticode-signed until the organization's Azure signing account exists; SmartScreen may warn.
Lighter in the background
- Switchboard watches Claude Code's session logs for limit errors. It used to read the end of
every active log twice a minute; now it reads only what each log added since. On a Mac with
22 active sessions, one background pass went from 66 ms to about 1 ms.
Continue a task on another account
switchboard continue <workflow> --account <id> --dir <checkout>hands a Project Observatory
workflow whose agent hit its limit to another account of the same provider, and opens that
account's session in the checkout. The session takes the work over from the last checkpoint.
Switchboard refuses before changing anything when the workflow cannot be continued here, and
reports Observatory's own reason when it declines. macOS only for now.
CLI.md.
Usage analytics
- Each anonymous usage event also carries the installation id under a second name and whether
the build is a release, so PassionCode's own reports count installs correctly. Nothing new
identifies you. ANALYTICS.md.
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc
v0.6.1
Switchboard now updates itself: from this version on, new releases arrive and install without
you doing anything (turn it off in About). It also works with the popular coding agents beyond
Claude Code and Codex, and a reinstall gets everything back. Install this one by hand; every
later release arrives on its own. Signed by the same team (KJ35UYYL22).
Windows: windows_authenticode: NOT_SIGNED. The installer is built natively but not
Authenticode-signed until the organization's Azure signing account exists; SmartScreen may warn.
Other agents
- Switchboard now works with the popular coding agents beyond Claude Code and Codex — Hermes,
Kilo Code, Cline, Goose, OpenCode, Qwen Code, Aider and 23 more (Agents → Other agents,
switchboard agents). Each gets Switchboard's tools; agents that accept a custom endpoint can
send their requests through Switchboard, which switches accounts for them, and some launch from
Switchboard directly. Subscription sign-ins stay with Claude Code and Codex, as the providers
require; other agents use API-key accounts. The proxy now also speaks Chat Completions for
OpenAI API keys. AGENT-SUPPORT.md.
Backups and reinstall
- Backups now also keep your projects, project rules, which account each pool's managed sessions
use, and the open-at-login and auto-update settings. A change to a project rule triggers a
backup too. - A restore now also gives back the credential of an account that is still listed but lost it
(afterswitchboard uninstall --keep-dataor a removed Keychain item). switchboard uninstallkeeps the Claude Code and Codex history in Switchboard's session
folders and removes only the sign-in files in them;--purgeremoves those folders too.- After a reinstall or
switchboard uninstall, the first start restores the newest backup on its
own and says so; an empty account list with a backup beside it offers Restore from backup.
Automatic updates
- Switchboard now updates itself. About 90 seconds after it starts, and every six hours, it
checks for a new release, downloads it in the background, verifies its signature and installs
it; the new version runs from the next start, or at once with Restart to update in the
menu-bar menu or About. On by default; About → Install updates automatically turns it off. - An update never touches your accounts, settings, connections or backups: on Windows the
installer runs in update mode, which never uninstalls and never deletes the app data. - This version is the first that can update itself; installing it is the last manual download.
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc
v0.6.0
The first stable release. A project can now keep its own accounts: only sessions from its folders
use them, and no other project switches to them. A short tour on first start shows what
Switchboard does and where to press. Signed by the same team (KJ35UYYL22).
Windows: windows_authenticode: NOT_SIGNED. The installer is built natively but not
Authenticode-signed until the organization's Azure signing account exists; SmartScreen may warn.
Projects
- A project is one or more folders — related repositories — with accounts of its own. Create it
under Projects → New project: its accounts serve only sessions launched from its folders,
automatic switching stays inside them, and no other project — nor the ordinary Claude Code,
which every folder shares — switches to them. Inside its folders, sessions use its accounts.
Alsoswitchboard project save|delete.
First start
-
A five-step tour on first start shows what Switchboard does and where to press; About →
Show the tour again. -
Windows: the installer now puts
switchboard.exebeside the desktop app, so the Agents panel
can show its path and the commands that connect Claude Code and Codex to it.
Verify
gpg --verify SHA256SUMS.asc SHA256SUMS # key 63B30DC324BD697487AA31944FAFB8AEC803B6A7
shasum -a 256 -c SHA256SUMS --ignore-missing
gh attestation verify <file> --owner passioncode-ai --signer-repo passioncode-ai/.githubThe organization's public key: https://github.com/passioncode-ai/.github/blob/main/release-signing/passioncode-release-signing.asc