Skip to content

Releases: usehivy/hivy

v8.4.3

Choose a tag to compare

@bahdcoder bahdcoder released this 26 Jul 03:07

What changed

Hivy v8.4.3 keeps email replies attached to the session that sent them, lets agents publish complete skill bundles from their workspace, and improves the empty states around agent inboxes, Apps, Sheets, and Skills.

Email replies return to the right session

  • Outbound email threads now retain their originating Hivy session. Once Resend accepts a message, Hivy retrieves and stores the provider-assigned RFC Message-ID.
  • Incoming replies are matched through In-Reply-To and References. Matching is scoped to the organization and agent, checks outbound messages only, and confirms that the sender appeared in the original To or CC list.
  • A reply to an active session is delivered into that same conversation. If the original session is no longer active, the normal email automation path can create or reuse an email session.
  • Agents send and receive through their permanent inbox address; the old reply-* routing-address mechanism is no longer used.
  • Email persistence now performs the message and thread updates in transactions, checks affected rows on scoped writes, and handles duplicate webhook deliveries without creating another message or session.

Agents can publish workspace skill bundles

  • The create_skill and update_skill tools now accept a complete SKILL.md plus supporting files read from the agent's sandbox workspace.
  • Hivy parses the SKILL.md frontmatter for the skill name, descriptions, category, tags, and required environment variables. New skills are published to the calling agent's team and attributed to the actor who requested the change.
  • The sandbox runtime converts workspace paths into the MCP payload expected by the Skills service. Supporting files must sit beneath the skill directory in references/, templates/, scripts/, or assets/.
  • Bundle reads reject symbolic links, path traversal, duplicate paths, invalid UTF-8, and files outside the declared skill directory. Limits are now 256 files including SKILL.md, 4 MiB per file, and 16 MiB for the complete bundle.
  • Browser-side skill creation has been removed. Add skill now opens a new chat, where an agent can build and publish the bundle; existing skills can still be edited or archived from Settings.

Agent inbox setup has clearer states

  • The agent details page now explains that email starts a session, shows whether an inbox is active, and provides a full Copy address action.
  • Message counts use readable text, including a dedicated zero-message state. Provisioning, loading, and failure states now use the same compact layout as the rest of the agent details page.

Apps and Sheets no longer end in a blank screen

  • Apps and Sheets load collection data across all available teams before deciding which state to show.
  • Each page now distinguishes loading failures, no teams, an empty collection, and a search with no matches.
  • Empty collections link directly to a new chat so an agent can create the first app or sheet. Failed loads can be retried, and an empty search result offers a one-click reset.
  • The shared empty-state presentation has no surrounding card or icon container, keeping it visually consistent with the collection pages.

Deployment notes

  • Database migration 000011_agent_email_rfc_threading.sql supplies a temporary database default for the legacy reply_token column so old and new application pods can overlap during a rolling deployment.
  • No new environment variables or customer-side configuration are required.
  • CI, CodeQL, and the main image-publishing workflow passed for the release commit.

Commits

  • f0d078a46 Reconcile agent email replies by RFC message ID.
  • f507c2105 Create and update skills from workspace bundles.
  • 997ed8ce8 Redesign agent inbox setup and status.
  • 003b70372 Add Apps, Sheets, and Skills empty-state behavior.
  • 5e95c9f61 Remove the surrounding collection-state cards.

Full changelog: v8.4.2...v8.4.3

v8.4.2

Choose a tag to compare

@bahdcoder bahdcoder released this 25 Jul 11:58

Full Changelog: v8.4.1...v8.4.2

v8.4.1

Choose a tag to compare

@bahdcoder bahdcoder released this 24 Jul 23:56

What's Changed

  • feat(skills): add platform-status-check skill by @usehivy[bot] in #224

Full Changelog: v8.4.0...v8.4.1

Hivy v8.4.0

Choose a tag to compare

@bahdcoder bahdcoder released this 24 Jul 10:25

Highlights

Hivy v8.4.0 adds end-to-end session observability, a substantially expanded model catalog and routing layer, a dedicated credit-purchase flow, and a new static product and model-catalog experience.

End-to-end session and infrastructure observability

  • Added session correlation across API requests, provisioning phases, sandbox lifecycle events, runner activity, tool calls, model generations, and failures.
  • Added searchable session-forensics and runner/sandbox dashboards so support can investigate a session ID from provisioning through execution.
  • Added private Prometheus metrics for API RED signals, Asynq queues, LLM latency/tokens/cost, workflow phases, runner capacity, sandbox state, PostgreSQL, Redis, Qdrant, and synthetic journeys.
  • Added 18 validated Hivy Grafana dashboards covering customer support, API reliability, LLM/tool behavior, queues, sandboxes, automations, RAG, data services, billing/security, deployments, backups, product journeys, and telemetry health.
  • Added nine sanitized PostgreSQL support views and least-privilege hivy_observability database roles for staging and production.
  • Added scalable runner telemetry through Ansible-managed VMAgent, VLAgent, node exporter, runner API scraping, sandbox log ingestion, and disk-backed delivery queues.
  • Added recording rules and alerts for HTTP latency/errors, queue health, runner heartbeat/capacity, database collectors, application scrape health, and public journey failures.
  • Added Redis exporter and blackbox synthetic probes with pinned, non-root images.

Models and routing

  • Added Atlas, Novita, Together AI, Engy, TheGrid, and Thesean provider/model catalogs.
  • Expanded provider and model failover behavior and made routing prefer the lowest-cost eligible provider.
  • Removed OpenRouter from text-model routing while retaining supported image-only behavior.
  • Added usage and billing support for Atlas and Novita routes.
  • Added a public model-catalog API and UI, provider branding, model “new” badges, and broader model-selection coverage.

Billing and product experience

  • Added a dedicated credit-purchase checkout and refreshed billing purchase flows.
  • Added statically generated marketing and model-catalog pages.
  • Added the themed Hivy wordmark and updated navigation/model presentation across public and authenticated surfaces.

Reliability and maintainability

  • Split oversized Go observability/runtime modules to restore the repository’s 300-line quality gate.
  • Restored main CI deployment checks and added validation for coherent backend/runtime/app image tuples.
  • Added tests for correlation metadata, generation cost accounting, provider routing/failover, model catalogs, runner log ingestion, and the new billing experience.

Deployment notes

  • Database migration 9 creates the sanitized observability support views.
  • API metrics are exposed only on the private port 9090; worker metrics remain on the private health port.
  • New Kubernetes nodes are discovered automatically by VictoriaMetrics.
  • New runner nodes inherit the complete telemetry configuration when added to Ansible inventory and reconciled with the standard runner playbooks.
  • This release does not require customer-side configuration changes.

Changes

  • 58b0f4bc4 Run the blackbox exporter with an explicit non-root identity.
  • 9c9581326 Add the full application/infra observability dashboard and metrics suite.
  • 71aaf2597 Restore main CI checks.
  • 3176e5ef9 Split oversized observability files.
  • 9dcf7fcd4 Add end-to-end session observability.
  • 497b9c074 Split oversized Go files.
  • 501374d49 Pin sandbox observability images.
  • 3b591e4ba Centralize runner and sandbox observability.
  • c7199ea9a Add the themed Hivy wordmark.
  • 579a7125f Expand the model catalog and static marketing pages.
  • e113f4f17 Mark GPT-5.6 models as new.
  • 66539a143 Expose the model catalog and new-model badges.
  • 933c9a4e3 Satisfy repository quality gates.
  • caa837d29 Prioritize the cheapest model providers.
  • 3de5bd519 Remove OpenRouter text routing.
  • c4f43b27a Add the Together AI provider catalog.
  • e78f4b757 Add the Engy model provider.
  • 37f78a2a5 Derive email tools from agent inboxes.
  • 3a552feaa Add Novita routing and usage billing.
  • bf3569d0b Expand provider and model failover.
  • 1ac484ed9 Add dedicated credit-purchase checkout.
  • 4c24b1579 Add Atlas routing and usage billing.

Full changelog: v8.3.1...v8.4.0

Hivy v8.3.1

Choose a tag to compare

@bahdcoder bahdcoder released this 23 Jul 19:11

Redis Cluster reliability

  • Fixes production session-event persistence failures caused by the runtime append Lua script addressing keys in different Redis Cluster hash slots.
  • Uses shard-scoped hash tags for runtime streams, sequence checkpoints, event indexes, projector checkpoints, and leases while preserving existing standalone Redis key names.
  • Makes multi-key deletion and prefix scanning topology-aware, including scanning every Redis Cluster master.
  • Detects standalone versus clustered Redis for user database integrations and inspects keys across the complete configured topology.

Production-shaped local development

  • Replaces the standalone Docker Compose Redis service with a real three-master Redis Cluster covering all 16,384 slots.
  • Adds idempotent Linux-compatible cluster initialization, bounded readiness diagnostics, and topology-aware test clients.
  • Adds integration coverage for runtime ingress, Lua appends, streams, pub/sub, cluster-wide scans, cache invalidation, counters, external Redis access, and Asynq.
  • Keeps the existing CI matrix on standalone Redis and adds a dedicated Redis Cluster job so both supported modes remain continuously tested.

Validation

Hivy v8.3.0

Choose a tag to compare

@bahdcoder bahdcoder released this 23 Jul 16:07

Agent inboxes

  • Adds stable, dedicated email inboxes for agents so incoming email can start a new agent session.
  • Adds tenant-scoped inbox provisioning and lookup APIs with idempotent address creation and inbound message counts.
  • Adds inbox management to the agent page, including provisioning, retry states, address copying, and message totals.

Agent runtime tools and skills

  • Makes every native runtime tool directly available without progressive discovery.
  • Replaces search_tools and get_tool_details with one native load_tools call that loads an exact batch of MCP tools for the current turn.
  • Prepends a cacheable <system-tool-usage> catalog containing every effective native tool and permitted MCP tool name to each turn.
  • Scopes MCP schemas and skill contents to a turn, reloads skills when a later turn needs them, and prunes stale tool-loading transcripts from model-visible history.
  • Preserves loaded MCP schemas throughout one turn while preventing them from leaking into later turns or other sessions.
  • Hardens turn identifiers, queued follow-ups, MCP catalog reload readiness, and config publication against lifecycle races.

Grafana integration

  • Adds first-class Grafana MCP support for listing data sources, searching dashboards, loading dashboard definitions, and querying data sources.
  • Adds Grafana catalog metadata, generated actions, OAuth proxy handling, connection UI support, and integration coverage.

Infrastructure reliability

  • Hardens Redis backups with structural validation, disposable restore checks, production cluster topology verification, remote object-size validation, and restore manifests.
  • Adds Redis backup failure and stale-recovery-point alerts.
  • Gives K3s nodes an explicit Ansible-managed resolver configuration to avoid kubelet DNS truncation.
  • Adds deployment and manifest regression coverage for the infrastructure changes.

Validation

Hivy v8.2.1

Choose a tag to compare

@bahdcoder bahdcoder released this 23 Jul 11:23

Deployment reliability

  • Restores automatic Kubernetes delivery: pushes to main deploy staging, while stable releases deploy production. Daytona image and snapshot publication remains removed.
  • Deploys the backend, web, sandbox runtime, developers runtime, and sandbox app as one versioned tuple so API and worker Pods cannot start with stale sandbox image configuration.
  • Builds commit-specific sandbox images for staging and release-specific images for production, and makes those image builds hard prerequisites for deployment.
  • Freezes Deployment reconciliation while preparing the tuple without stopping live Pods, then performs the existing zero-unavailable rolling update.
  • Verifies the completed tuple and automatically restores the exact previous pod templates if patching or rollout fails.
  • Prevents newer main pushes from cancelling a deployment or rollback already in progress.

Release pipeline

  • Restores the main and release image workflows, immutable application-digest deployment, release manifests, and Kubernetes environment rollout jobs.
  • Keeps Microsandbox control-plane and preview-gateway images published but operator-managed rather than automatically deploying them.
  • Improves portable sandbox app build-context generation and records the sandbox app image in release metadata.

Validation

Hivy v8.2.0

Choose a tag to compare

@bahdcoder bahdcoder released this 23 Jul 09:54

Workspace and settings

  • General, billing, teams, skills, and knowledge now live inside the main workspace layout. Admin-only pages still use the existing role gates, and knowledge document management has its own frontend admin check.
  • The old settings shell and its retired appearance, archived sessions, environment, and MCP pages are gone.
  • Settings starts collapsed in the sidebar. The theme control now sits with the page navigation controls.
  • The account menu is now a full-width workspace switcher with the signed-in user's avatar and identity, workspace creation, and workspace switching.
  • Switching workspaces cancels active requests, clears organization-scoped cache data, reloads the new workspace, and reconnects running agent sessions from their last stream cursor. Switching back can resume work without replaying stale data from another workspace.

Teams, agents, and Slack routing

  • Team management now uses dedicated Overview, Connections, Skills, Knowledge, Env, and Routing tabs.
  • Slack routing is limited to Slack connections and loads the channels available from the selected workspace. The new modal walks through workspace, channel, and agent selection with searchable card lists, persistent navigation controls, a route summary, and a confirmation dialog for deletion.
  • Existing Slack routes can be reassigned through the shared agent popover. Team and chat selectors now use the same agent and team selection patterns.
  • Agent configuration now includes environment access and connection-resource controls.
  • Skills administrators can see organization-wide and team-specific skills together, with loading and empty states matching the team views.

Billing

  • Credit purchases now accept custom deposit amounts alongside the preset packs.

Fixes

  • Skill calls keep user context through the proxy path, fixing the intermittent 401 missing user context response.
  • The current-organization endpoint survives middleware and proxy path normalization instead of falling through to Envoy's plain-text 404.
  • Session panel animation no longer resizes a panel group after that group has unmounted.
  • Workspace, team, knowledge, and billing documentation now points to the new routes.

Build and delivery

  • Daytona-targeted image and snapshot publication has been removed. Application images still publish and deploy automatically to staging from main and to production for stable releases.
  • Frontend dead code and unused exports were removed, large components were split below the repository limits, and ESLint plus Knip now run clean.
  • The web CI target no longer starts the deleted plans API helper before a production build.

Full diff: v8.1.1...v8.2.0

Hivy v8.1.1

Choose a tag to compare

@bahdcoder bahdcoder released this 23 Jul 04:42

Highlights

Choose USD or NGN for every Paystack deposit

Credit purchases are no longer tied to a permanent organization billing currency. Customers can choose USD or NGN for each deposit, while credits remain currency-neutral after payment.

  • Adds USD and NGN selection directly to the deposit flow.
  • Adds a new $5 credit pack and its ₦7,250 equivalent.
  • Keeps Paystack currencies intentionally limited to USD and NGN.
  • Uses a fixed conversion snapshot of ₦1,450 per USD so matching packs grant the same credits.

Currency-safe saved cards

Saved Paystack cards now retain the currency in which their authorization was created.

  • Only cards matching the selected purchase currency are offered at checkout.
  • The API rejects attempts to charge a saved card in a different currency.
  • The same physical card can be saved independently for USD and NGN.
  • Existing saved cards are backfilled with their previous organization billing currency during migration.

Clearer Paystack failures

Paystack currency-availability rejections now produce an actionable conflict response instead of appearing as an opaque server error. The underlying provider error remains available in operational logs without being exposed to customers.

API and data changes

  • POST /v1/billing/purchases now requires a currency value of USD or NGN.
  • Billing account responses expose both USD and NGN pack catalogs.
  • Payment method responses now include their saved currency.
  • Removes the organization-level billing_currency field and the legacy /v1/billing/account/currency endpoint.
  • Adds database migration 7 for payment-method currency backfill, currency-aware uniqueness, and removal of the obsolete organization currency column.
  • Regenerates the OpenAPI contract and frontend client for the updated billing API.

Validation

  • Added Paystack initialization and structured-rejection contract coverage.
  • Added migration-backed purchase tests for cross-currency saved-card protection.
  • Added handler error-mapping and frontend currency-filtering coverage.
  • Passed backend build, vet, lint, billing tests, frontend tests, TypeScript checks, repository CI, CodeQL, image publication, and staging rollout.

Upgrade notes

  • The database migration runs automatically with the normal application migration flow.
  • Existing integrations creating purchases must provide currency.
  • No new Paystack environment variable is required.

Full changelog: v8.1.0...v8.1.1

Hivy v8.1.0

Choose a tag to compare

@bahdcoder bahdcoder released this 22 Jul 20:16

Highlights

Read-only platform engineering investigations

This release adds a complete workflow for agents to investigate Kubernetes health from an isolated sandbox without receiving write access to the cluster.

  • Adds the platform-engineering-agent service account, cluster roles, and bindings for deep, cluster-wide observation across workloads, nodes, events, logs, metrics, RBAC, networking, configuration, and installed operators.
  • Keeps sensitive and mutating surfaces out of scope: Kubernetes Secrets, node proxy access, and all write verbs remain unavailable.
  • Adds checksum-verified kubectl setup, an SSH tunnel on 127.0.0.1:16443, connectivity checks, cleanup, and tunnel teardown scripts.
  • Adds a reusable Platform Engineering Agent skill that records exact UTC start/end times and writes its investigation to /workspace/investigations/report.md.

Markdown-first agent email reports

Agents can now prepare reports as workspace Markdown files and pass the file path to send_email.

  • Adds generic workspace_text_file tool-input bindings that securely load a declared workspace file and inject its contents into an MCP tool call.
  • Enforces workspace containment, rejects symlink and traversal escapes, validates UTF-8 and allowed extensions, and supports reports up to 1 MiB.
  • Updates send_email to accept Markdown, render GitHub-flavored Markdown, sanitize the generated HTML, and retain the original Markdown as the plain-text fallback.
  • Preserves compatibility with existing text and HTML email inputs.

More runtime headroom

Model profiles now have four times the previous operational capacity for long-running investigations and tool-heavy work:

  • 400–800 tool calls per turn, depending on profile.
  • 40 consecutive tool-error tolerance.
  • 200-turn compiled sessions.
  • 720k input-token and 32k output-token budgets.
  • 240-second turn timeout.

Provider, protocol, and security limits remain unchanged.

A clearer Hivy product experience

  • Adds a public blog with an index, article pages, and ten launch articles.
  • Refreshes the home, pricing, Sheets, Slack, access control, agents, automations, Drive, knowledge, and model-choice experiences.
  • Expands product documentation with dedicated guides for workspace setup and settings, agent memories, Agent Drive, MCP servers, and skills.
  • Reworks agent context so environment variable values remain opaque while agents can still understand available variable names and descriptions.
  • Improves knowledge-source guidance so agents search the connected knowledge base before concluding information is unavailable.

Reliability and security

  • Kubernetes credentials remain outside version control; only non-secret configuration and generation tooling are included.
  • Workspace file bindings are covered by tests for path traversal, symlink escape, extension, size, encoding, and missing-file failures.
  • Markdown email rendering is sanitized before delivery.
  • Sheets marketing previews are split into focused modules, with unreachable preview code and unused exports removed so repository quality gates remain enforceable.
  • The release includes expanded runtime, backend, frontend, Kubernetes, and Ansible validation coverage.

Upgrade notes

  • No database migration is required.
  • Platform operators who want agent-led Kubernetes investigations should generate the ignored access bundle and configure the documented sandbox environment variables.
  • Existing send_email callers using text or HTML continue to work; new agent workflows should prefer markdown_file_path.

Full changelog: v8.0.3...v8.1.0