Releases: talayolabs/sessionboxer
Release list
Sessionboxer 1.4.1
Install: npx sessionboxer@1.4.1 serve, brew install talayolabs/tap/sessionboxer, the installers on the
release, docker compose up, or curl -fsSL https://sessionboxer.talayolabs.com/install.sh | sh. The Sandbox
image did not change.
- New defaults: verification off, automatic snapshots off, Agent tools on All Sessions; saved values are kept. (716fe44)
- Advanced, Session and Global settings share one layout — Environment, Agent, MCP & connectors, Auto QA, Debug — with the explanations behind
?popovers; the Verification pane is now Auto QA. (8955281) - Attach files and dictate on the New session screen, sent with the first prompt. (ab389d7)
- MCP tools reference: every tool of the built-in
desktopandsessionboxerservers. (af8f1c6)
Images: ghcr.io/talayolabs/sessionboxer-sandbox:1.4.1, ghcr.io/talayolabs/sessionboxer:1.4.1 (linux/amd64, linux/arm64).
npm: npx sessionboxer@1.4.1 serve, or npm i -g sessionboxer@1.4.1 then sessionboxer serve. Full instructions: https://github.com/talayolabs/sessionboxer#install
Desktop app (needs Docker, not Node): the Sessionboxer-1.4.1-* files below — Linux AppImage/deb (x64, arm64), macOS dmg/zip (mac-arm64 for Apple silicon, mac-x64 for Intel), Windows installer/zip (x64); SHA256SUMS alongside.
The builds are not code-signed yet, so macOS says the dmg is damaged and can't be opened. Before opening it, clear the quarantine flag on the download: xattr -d com.apple.quarantine ~/Downloads/Sessionboxer-1.4.1-mac-*.dmg, then open the dmg and drag Sessionboxer to Applications. If the app itself is still refused, xattr -dr com.apple.quarantine /Applications/Sessionboxer.app or right-click → Open. On Windows choose More info → Run anyway in SmartScreen.
Sessionboxer 1.4.0
Install: npx sessionboxer@1.4.0 serve, brew install talayolabs/tap/sessionboxer, the installers on the
release, docker compose up, or curl -fsSL https://sessionboxer.talayolabs.com/install.sh | sh. The Sandbox
image changed: Stop → Resume existing sessions.
- The agent knows it runs inside Sessionboxer: a
sessionboxerMCP in every box (whoami,docs, PRs, snapshot, queue, title,verify,notify, terminals,ui_open),.sessionboxer/session.json, a marker in the chat for every action; policy off / this Session / all Sessions in Settings → Agent tools. (cb1a172) - Agents work across Sessions: list, create (you Allow or Deny in the chat), fork with their own handoff, message another Session (marked from Session X on both sides), wait, stop own children, schedules; children show child of … in the sidebar. (5f94bcf)
- The
sessionboxerMCP in Windows and macOS Sessions too; the guide's The agent and Sessionboxer itself section (ADR-0062); Windows/macOS VMs no longer refuse to boot on a false low-RAM check. (834f2ff) - Windows Sessions run the agent inside the VM: agent, MCP servers, git and the Terminal (PowerShell) are Windows-native, repositories in
C:\workspace; reinstall the Windows base once. (cc50730) - macOS Sessions run the agent inside the VM the same way (zsh Terminal,
/Users/agent/workspace); an existing base is reprovisioned from Global settings → macOS VMs. (d38f65e) - Environment per session: Docker · Linux, QEMU · Windows (a Windows VM next to the box, its desktop over RDP; Linux hosts with KVM, base installed once from Global settings). (8a6350b)
- QEMU · macOS as a third environment: a macOS VM (dockur/macos, OpenCore) next to the box, its desktop over VNC; Linux hosts with KVM and AVX2, Apple's licence terms apply. (4078b03)
- New session toolbar: Environment, Agent and Model dropdowns with logos; every native
<select>replaced by the themed list; a Runtime item first in the set-up checklist. (4d4a065) - New session: picking an unconnected Agent opens Connect a Provider, picking an environment that is not installed opens its install dialog. (f4f9eb3)
- Sign in with Claude Code, Codex, Cursor or Devin from Settings in your own browser; a login already on the server's machine is copied with one click. (7cbe0c3)
- One USB device of the host per Session (Connect USB device… menu; WSL2 via usbipd). (52ce83a)
- Global settings as a split view with
#/settings/<section>deep links and one Save. (f6126ef) - An in-repo design system: Radix Primitives for menus, dialogs and tooltips;
--vscode-*aliases from the same palette as the VS Code theme. (8d4505f) - Long conversations no longer lose messages on reload (the 5,000-event cap is gone); the Code pane keeps each Session's own tabs and layout. (7a12588)
- No more messages missing after the tab was in the background: a dead push socket is detected and the transcript refetched. (054616a)
Images: ghcr.io/talayolabs/sessionboxer-sandbox:1.4.0, ghcr.io/talayolabs/sessionboxer:1.4.0 (linux/amd64, linux/arm64).
npm: npx sessionboxer@1.4.0 serve, or npm i -g sessionboxer@1.4.0 then sessionboxer serve. Full instructions: https://github.com/talayolabs/sessionboxer#install
Desktop app (needs Docker, not Node): the Sessionboxer-1.4.0-* files below — Linux AppImage/deb (x64, arm64), macOS dmg/zip (mac-arm64 for Apple silicon, mac-x64 for Intel), Windows installer/zip (x64); SHA256SUMS alongside.
The builds are not code-signed yet, so macOS says the dmg is damaged and can't be opened. Before opening it, clear the quarantine flag on the download: xattr -d com.apple.quarantine ~/Downloads/Sessionboxer-1.4.0-mac-*.dmg, then open the dmg and drag Sessionboxer to Applications. If the app itself is still refused, xattr -dr com.apple.quarantine /Applications/Sessionboxer.app or right-click → Open. On Windows choose More info → Run anyway in SmartScreen.
Sessionboxer 1.3.0
Install: npx sessionboxer@1.3.0 serve, brew install talayolabs/tap/sessionboxer, the installers on the
release, docker compose up, or curl -fsSL https://sessionboxer.talayolabs.com/install.sh | sh.
- New first screen: a prompt box with the Provider, repositories and Start under it; the four Provider logos above it until one is connected. (ccb681b)
- Connect a Provider from the app: per-Provider dialog with the install, log-in and paste steps for your OS (macOS, Windows, Linux). (ccb681b)
- Session settings behind "Advanced…", sections on the left, controls on the right. (ccb681b)
- "To set up" checklist in the sidebar: Provider and Git account, each a two-click wizard; Git offers GitHub or Bitbucket. (b0bd4cd)
- Settings → Git accounts: GitHub with a personal access token (direct create link, exact permissions) next to the CLI and OAuth App logins. (bf5c407)
- Login page: "Where do I find the token?" per install method, for
docker compose up -dand friends. (bf5c407) - Pull request rows open the PR detail; the GitHub link stays a separate button. (bf5c407)
sessionboxer servewithout Docker: one readable message and exit instead of a stack trace; a banner with Retry when the Sandbox image cannot be pulled. (5fee507)- Install: Homebrew tap,
sessionboxeron npm, the desktop app's Get Docker link per OS. (085c511)
Images: ghcr.io/talayolabs/sessionboxer-sandbox:1.3.0, ghcr.io/talayolabs/sessionboxer:1.3.0 (linux/amd64, linux/arm64).
npm: this version is not on the npm registry; install the tarball below instead: npm i -g https://github.com/talayolabs/sessionboxer/releases/download/v1.3.0/sessionboxer-1.3.0.tgz then sessionboxer serve (Node 22+ and Docker). Full instructions: https://github.com/talayolabs/sessionboxer#install
Desktop app (needs Docker, not Node): the Sessionboxer-1.3.0-* files below — Linux AppImage/deb (x64, arm64), macOS dmg/zip (mac-arm64 for Apple silicon, mac-x64 for Intel), Windows installer/zip (x64); SHA256SUMS alongside.
The builds are not code-signed yet, so macOS says the dmg is damaged and can't be opened. Before opening it, clear the quarantine flag on the download: xattr -d com.apple.quarantine ~/Downloads/Sessionboxer-1.3.0-mac-*.dmg, then open the dmg and drag Sessionboxer to Applications. If the app itself is still refused, xattr -dr com.apple.quarantine /Applications/Sessionboxer.app or right-click → Open. On Windows choose More info → Run anyway in SmartScreen.
Sessionboxer 1.2.0
Install: npx sessionboxer@1.2.0 serve, the installers on the release, docker compose up, or
curl -fsSL https://sessionboxer.talayolabs.com/install.sh | sh. The Sandbox image changed:
Stop → Resume existing sessions.
- Cursor as a fourth agent, on your Cursor subscription (
agent loginfile or API key). (164c955)
Images: ghcr.io/talayolabs/sessionboxer-sandbox:1.2.0, ghcr.io/talayolabs/sessionboxer:1.2.0 (linux/amd64, linux/arm64).
npm: npx sessionboxer@1.2.0 serve. Full instructions: https://github.com/talayolabs/sessionboxer#install
Desktop app (needs Docker, not Node): the Sessionboxer-1.2.0-* files below — Linux AppImage/deb (x64, arm64), macOS dmg/zip (arm64 Apple silicon, x64 Intel), Windows installer/zip (x64); SHA256SUMS alongside. While the builds are unsigned (no signing certificate configured): on macOS run xattr -dr com.apple.quarantine /Applications/Sessionboxer.app after dragging it to Applications, on Windows choose More info → Run anyway in SmartScreen.
Sessionboxer 1.1.0
Install: npx sessionboxer@1.1.0 serve, the desktop installers below, docker compose up with
this release's docker-compose.yml, or curl -fsSL https://sessionboxer.talayolabs.com/install.sh | sh.
Upgrading from 1.0.0: the Sandbox image changed (ghcr.io/talayolabs/sessionboxer-sandbox:1.1.0
is pulled on first use; npm run build:image for source installs); Stop → Resume existing sessions
to get the new image. Highlights: Codex as a third agent, scheduled tasks, color themes shared
with VS Code, verification of each turn with a video, PR checks (GitHub and Bitbucket Data Center)
fixed from the PR pane, forks with another agent and handoffs, usage limits with Continue /
Auto-continue, and a chat that folds the agent's messages of a turn.
- Desktop MCP: the cursor glides to its target instead of jumping —
mouse_move, the clicks,scrollandleft_click_dragwith a coordinate move through an eased path (ease-in-out cubic, ~100 ms for a short hop to 300 ms across the screen, a position every 8 ms) sent to xdotool as one command chain, so it costs one process and shows in the Desktop pane and in recordings; the program under the cursor receives the intermediate motion events (hover,dragover) a hand-moved mouse produces. A move to the point the cursor already stands on returns at once (it used to hang 15 s in xdotool's--sync).SESSIONBOXER_MOUSE_GLIDE=0restores the jump. Needs an image rebuild. - Usage limits: a turn the Provider refuses for lack of credit (Claude's You've hit your session limit · resets 2pm (UTC), weekly/monthly/Opus/Sonnet/fast-mode limits and usage credit limit reached; Codex's usage limit /
quota_exceeded; Devin's Quota exhausted /resource_exhausted) no longer looks like an answer or an error: the Session stays idle withSession.usage.limit, a red bar with a no-entry sign above the composer counts down the time left to the reset asdays hh:mm:ss(hover: the reset date and what the Provider said), the session list shows the sign in place of the status dot, Continue sends the interrupted prompt again (attachments included; Continue where you left off. when the Agent had already run tools) and Auto-continue polls the Provider every 10 s once the reset is due — a one-line question in a throwaway ACP session — and continues by itself as soon as it answers; the queue holds while a limit stands and plays on afterwards. Claude's refusal is also recognised from the API'santhropic-ratelimit-unified-status: rejectedheader, whatever the wording. Three usage bars above the context gauge show the Provider's metered windows, green→red without figures, the percentage and reset on hover: Claude's session / week / Fable-or-Opus windows from theanthropic-ratelimit-unified-*headers the LLM recorder sees (Inspect LLM on; only those headers leave the recorder), Codex's 5-hour and weekly limits from/statusafter each turn; Devin reports none and the bars say so. A scheduled run cut by a limit is marked failed with that reason.sessions.usagecolumn,POST /api/sessions/:id/usage/continue,POST /api/sessions/:id/usage/auto-continue,agent_error.limit,DaemonStatus.usage(ADR-0053). npm run build:imageafter a Sessionboxer change reuses the expensive layers: the Sandbox Dockerfile is ordered from rarely to often changed — apt, agents, VS Code, TTS model,bb, the agent user and the Devin CLI first; then Sessionboxer's own runtime dependencies installed frompackage.jsonalone; then configuration, briefing and skills; the compiled Daemon / MCP / protocol last — and each version pin is declared right before the layer that uses it (anARGis part of the cache key of every laterRUN). The build context is the three compiled packages andimages/sandboxonly (.dockerignore). A Daemon code change now rebuilds in seconds instead of re-running the npm installs, thebbbundle and the Devin download; same image size.- Fork: an Agent pick — the fork can run another agent (Claude Code → Devin, …) on the same snapshot — and a third Conversation choice, Hand off: the origin's agent writes a handoff document in a hidden turn (goal, state of the work, decisions, open items, files and places, how to run and test, gotchas; no secret values) and the fork starts a new conversation with it as its first message — towards another agent or a fresh session of the same one. Continue it stays for the origin's agent only (its memory cannot be loaded into another; the dialog greys it out and the API answers 400). The origin's chat shows Writing a handoff for a fork…, the fork's shows the document folded under Handoff from the origin's Agent; a fork with another agent starts from that agent's default model and options and its token must be configured.
ForkSessionRequest.provider,conversation: "handoff",user_prompt.origin: "handoff_request" | "handoff",forked.fromProvider(ADR-0052). - Chat: every message carries its time at the bubble's bottom-right, as people say it (just now, 12 min ago, today 14:32, yesterday 14:32, Mon 14:32, 12 Sep 14:32), with the exact RFC 5322 date (
Tue, 22 Sep 2026 10:47:12 +0200, browser time zone) on hover; the turn divider's tooltip uses the same form. The folded Agent group shows how long the turn is taking — a live m:ss while it works, then the time it took (Show all 10 messages · 0:26). - Instructions for the agent: the shipped default no longer asks the Agent to test each change end to end and record a video — Verify each turn end to end does that as its own step. The default is now the git-identity rule alone; a
config.jsonstill holding the old default verbatim moves to the new text (an edited one is left alone). - PRs: a PR opens inside the PRs pane instead of as its own header tab — the list shows one row per PR, a row opens the PR, and a breadcrumb at the top (Pull requests › owner/repo#123) leads back; the PRs tab stays lit while a PR is open. Comment bodies render the HTML GitHub allows in them (coverage-report tables,
<details>, images) instead of showing the tags as text: the same Markdown renderer as the chat withrehype-raw+rehype-sanitizeon GitHub's allowlist — no script/style/iframe/form/svg, noon*handlers,http(s)/mailtolinks only, ids prefixed. Chat messages are unchanged (HTML still not interpreted). - Fix: PR checks — GitHub's rollup lists every run on the head commit, so a workflow that ran twice (branch renamed, a re-run, push + pull_request events) showed each job twice or thrice and auto-merge waited on stale failed runs (22/25 checks, waiting: 2 failed). Only the newest run of each check (workflow / app + name) counts now, in the Checks list and for auto-merge, as in GitHub's merge box; a check is followed by workflow + name (
PrCheckItem.idchanges, so a failure standing at upgrade is announced once more). Auto-merge's line also says what else it waits for besides checks: an approval from a reviewer / changes were requested by a reviewer. - PRs: pull requests on a Bitbucket Data Center are watched too — attach one by URL (
https://host/projects/KEY/repos/slug/pull-requests/12, pasted or found in the chat;KEY/slug#12/#12shorthands for Workspace repositories) and the Control Plane polls it with the session's Bitbucket entry for that host, box running or not: comments with their replies, inline comments withpath:line, tasks, resolved threads, approvals and needs work as items; the head commit's build statuses as Checks (running / passed / failed / cancelled, parent build as source, required-build merge checks as required, link to the build), announced and fixed like GitHub's — the fix prompts speakbb(bb pr checks,bb pr comment --reply-to) instead ofgh. The PR pane names the provider and host; Auto-merge stays GitHub-only and is hidden for Bitbucket PRs.PullRequest.provider/.host(defaultsgithub/github.comfor existing rows),PrCheckItem.kind: "build",parsePrUrl/prUrlprovider-aware. Not covered: Bitbucket Cloud, a Data Center under a context path (ADR-0051). - PRs: the checks on a watched PR's head commit (GitHub Actions and other check runs, commit statuses) are watched with the comments — the PRs row counts failed / running / passed, a failure is announced once like a comment (toast, browser and push notification a check failed; again on a new push or a re-run that fails again), and the PR's tab has a Checks list where one or several failed checks go to the Agent with To prompt, Fix or Fix & push (name, conclusion, log link and summary; alone or together with ticked comments).
GET /api/sessions/:id/prs/:prId/checks,pr_checksbroadcast,PrActionRequest.checkIds(ADR-0050). - Fix: a PR poll cut short by stopping the Session showed error: daemon connection closed instead of watching paused — Sandbox stopped.
- Fork: a Conversation choice — Continue it (as before: the chat up to the snapshot is copied and the Agent remembers it) or Start a new one (empty chat; the Agent starts a fresh session on the same files and tools).
ForkSessionRequest.conversation: "continue" | "new"; the Daemon ignores the origin's persisted Agent session on the fork's first boot (SESSIONBOXER_NEW_CONVERSATION). - Composer: typing no longer lags — the draft lives outside the Session view's React state, so a keystroke re-renders only the composer instead of the whole Session (header, transcript, panes); Markdown messages are memoised too, so a streaming message no longer re-parses its neighbours.
- Chat: the Agent's consecutive messages of a turn (text, thoughts, tool calls, plans) fold behind one GitHub-style squiggly rule — a spinner and Working… n messages so far while it works, then only its last message (the summary) with Show all n messages; open to see every message as before, and fold them again from either end.
- Veri...
Sessionboxer 1.0.0
Install: npx sessionboxer@1.0.0 serve, the desktop installers below, docker compose up with
this release's docker-compose.yml, or curl -fsSL https://sessionboxer.talayolabs.com/install.sh | sh.
Upgrading from 0.1.0: the Sandbox image changed (ghcr.io/talayolabs/sessionboxer-sandbox:1.0.0
is pulled on first use; npm run build:image for source installs).
sessionboxer service install|…: run the Control Plane as a background service of your user account (launchd on macOS, systemd user unit on Linux), started at login.- Desktop app, first cut: an Electron tray shell that runs the Control Plane and shows the web UI in a window; no Node install needed, Docker still is (ADR-0043). Installers for Linux, macOS and Windows are built by the release workflow and attached to each GitHub Release (unsigned for now).
better-sqlite313: Node-API prebuilds, so one binary serves every Node ≥ 22 and Electron without a rebuild.- Dictation: a 🎤 button in the prompt box records your voice and appends the transcript to the draft; whisper.cpp runs offline on your machine, model and language in Settings (ADR-0042).
- Draggable splitters between the session list, the chat and the right pane; hiding the session list no longer blanks the window.
- One GitHub account per repository (Account dropdown,
--as <login>); clone, push andghin that repository act as it. Needs an image rebuild (ADR-0041). - Several repositories per session, each under
/workspace/<name>; add and remove them live (ADR-0037). - Auto-merge for attached pull requests: merged as soon as GitHub allows it, polled every 10 s (ADR-0040).
- Bitbucket (Data Center / Server) connector with the
bbCLI in the Sandbox (ADR-0038). - Control Plane: logging no longer loops on a closed stderr.
Images: ghcr.io/talayolabs/sessionboxer-sandbox:1.0.0, ghcr.io/talayolabs/sessionboxer:1.0.0 (linux/amd64, linux/arm64).
npm: npx sessionboxer@1.0.0 serve. Full instructions: https://github.com/talayolabs/sessionboxer#install
Desktop app (needs Docker, not Node): the Sessionboxer-1.0.0-* files below — Linux AppImage/deb (x64, arm64), macOS dmg/zip (arm64 Apple silicon, x64 Intel), Windows installer/zip (x64); SHA256SUMS alongside. While the builds are unsigned (no signing certificate configured): on macOS run xattr -dr com.apple.quarantine /Applications/Sessionboxer.app after dragging it to Applications, on Windows choose More info → Run anyway in SmartScreen.
whisper.cpp 1.9.4 binaries
Static whisper-cli builds of whisper.cpp v1.9.4 (MIT) for Sessionboxer's speech-to-text; the Control Plane downloads the one for its platform on first use. Not a Sessionboxer release.
Sessionboxer 0.1.0
First release. Sessionboxer runs coding agents (Claude Code, Devin) in one Docker Sandbox per
session, each with its own desktop, terminal, editor and browser, managed from a web UI that
also works on a phone.
Install: npx sessionboxer@0.1.0 serve, or docker compose up with the docker-compose.yml
from this release, or curl -fsSL https://sessionboxer.talayolabs.com/install.sh | sh. The
Sandbox image ghcr.io/talayolabs/sessionboxer-sandbox:0.1.0 (linux/amd64, linux/arm64) is
pulled on first use.
Sessions and Sandboxes
- One Docker Sandbox per session (Ubuntu 24.04 desktop: Xvfb, XFCE, Firefox, noVNC), agent runs
inside it; workspaces from a git URL, a copied host folder, or empty; CPU/memory limits. - Claude Code (subscription via OAuth token or API key/base URL) and Devin CLI, both over ACP;
model and agent-option pickers; per-session instructions. - Snapshots after each turn and on demand; fork a session from any snapshot; branches with
revert/switch; stop/resume with the conversation replayed. - Docker inside the Sandbox (Sysbox when available, privileged fallback, or off).
- Saved messages and a send queue; attachments (images, files) in prompts.
Panes
- Chat with inline screenshots, tool calls, videos/images/PDFs the agent produced, clickable
file paths that open in the Code pane. - Desktop (noVNC), Terminal (xterm.js), Code (VS Code in the browser), Context (usage gauge,
compactions, exact LLM requests/responses when inspection is on), PRs (comments and reviews
of attached pull requests, with "address and reply" actions). - Recordings with captions and narration from the agent's
start_recording/annotate_recording.
Integrations
- MCP server registry with per-session activation and secret injection; GitHub login (device
flow or existinggh) forwarded into the Sandbox asgh/git credentials; git identity. - Pull request polling and notifications.
Remote access
- Access token + per-device cookies in front of everything; QR pairing for phones.
- Pair another device over: the local network, an embedded Cloudflare quick tunnel, the
Sessionboxer tunnel (frp at tunnel-sessionboxer.talayolabs.com, stable subdomain, verified
TLS), or your own server over SSH. - Phone layout, installable PWA, Web Push for "turn ended" and PR feedback.
- Trusts this machine's CA certificates (Cloudflare WARP, corporate proxies) for its own
downloads and inside Sandboxes.
Distribution
sessionboxeron npm (Control Plane, web UI and CLI in one package).ghcr.io/talayolabs/sessionboxer(Control Plane) andghcr.io/talayolabs/sessionboxer-sandbox
images for linux/amd64 and linux/arm64;docker-compose.yml.npm run build:imagestill builds the Sandbox image locally for development.
Images: ghcr.io/talayolabs/sessionboxer-sandbox:0.1.0, ghcr.io/talayolabs/sessionboxer:0.1.0 (linux/amd64, linux/arm64).
npm: npx sessionboxer@0.1.0 serve. Full instructions: https://github.com/talayolabs/sessionboxer#install