# Locale release notes

Machine-readable source: /release-notes.json

## 2026-09-07: Staging and account security

Version: 0.1.0 | Status: unreleased | ID: 2026-09-07-staging-account-security

### Added

- Single-use email verification and password reset links with encrypted delivery queues.

### Changed

- Administration requires the configured owner email and assigned administrator role.
- HTTPS sessions use host-only cookie prefixes; existing browsers must sign in again.

### Limitations

- Staging rollout and email delivery verification are in progress.

## 2026-09-06: Stripe test billing and hosting preparation

Version: 0.1.0 | Status: unreleased | ID: 2026-09-06-stripe-test-hosting

### Added

- Stripe test checkout with approved server-owned monthly prices and signed, idempotent payment reconciliation.
- Test subscription status in account pages and Locale settings, with a restricted subscription management portal.
- Encrypted administrator service credentials, test payment and refund monitoring, and audited billing review holds.
- A dedicated Linux website release with restricted service configuration and server-console administrator setup.

### Changed

- Test payments are reported separately from pending mock checkout and real revenue.

### Fixed

- The dedicated website server serves the Locale workspace at /app and permits its same-origin preview frame.
- Stripe test checkout works when Managed Payments is enabled by default on the Stripe account.
- Service credential fields use independent labels and responsive administration layout.

### Limitations

- Live Stripe keys and events are rejected. Test payment verification does not authorize real cloud spending.
- Inference, storage, synchronization, sites and Box adapters remain unconnected.
- OAuth configuration, recovery email, automated database backups and independent outage alerts remain pending.
- Subscription upgrades and portal plan switching are not enabled.

### Validation

- Initial billing implementation passed TypeScript and the 1008-test baseline.
- Approved prices, restricted portal and HTTPS webhook were created in Stripe test mode.
- Dedicated cloud server and administrator bundles built successfully.
- TypeScript and 39 affected behavior tests passed after the checkout compatibility fix.
- Public HTTPS, registration, secure cookies, origin rejection and unauthorized administration checks passed.
- A synthetic Stripe sandbox payment completed through hosted checkout and its signed webhook marked the account paid while real cloud entitlements stayed disabled.
- The authenticated Stripe test portal endpoint and the www HTTPS redirect passed.

## 2026-09-06: Locale workspace accounts and interface cleanup

Version: 0.1.0 | Status: unreleased | ID: 2026-09-06-workspace-account-cleanup

### Added

- Registration, sign-in and sign-out within hosted Locale account settings.
- Account plan, promotion and credit usage details with session refresh on focus.
- Google and GitHub sign-in can return to the originating Locale workspace.

### Changed

- Website account identity appears in the workspace sidebar, separate from the local profile.
- Consolidated settings, profile, chat and workspace styles and restored shared search-field styling.
- Corrected tools copy to reflect Sync and Cloud account inference credits at launch.

### Fixed

- Account requests bind browser fetch correctly and ignore stale responses after sign-out.
- Shared radio inputs are anchored to their visible option for keyboard focus and scrolling.

### Limitations

- Cloud inference, storage, billing and synchronization remain unconnected. Signing in does not upload chats or activate a pending subscription.
- Standalone Agent hosts require a future device authorization flow for cloud accounts. Hosted Locale supports the website session now.
- Google and GitHub require configured OAuth apps. Password recovery is not yet available.

### Validation

- TypeScript and the initial 998-test baseline passed; affected account and OAuth behavior tests passed after implementation.
- Verified the existing website session within Locale and account layout in both themes at desktop and mobile widths; checked all five accent choices.
- Isolated browser registration, repeat sign-in, session persistence, sign-out and keyboard mode selection passed. No browser console errors were reported.

## 2026-09-06: Approved plans, account sign-in, and service operations

Version: 0.1.0 | Status: released | ID: 2026-09-06-approved-plans-account-operations

### Added

- Google and GitHub OAuth sign-in and explicit provider linking, pending provider configuration.
- Mock checkout receipts without payment or cloud activation.
- Public service status and administrator incident updates.
- Confirmed grants to all current accounts with a one-minute undo window.
- Authenticated encryption for server vault records and OAuth verifiers.
- An editable model catalog with tier access, timed percentage discounts, free-model cost confirmation, and Locale-funded sale budgets.
- Authenticated account usage, credit, model catalog and quote APIs, plus internal credit reservation and settlement.
- An account promotion countdown and weekly site request windows.

### Changed

- Approved Keep $5, Sync $10, Cloud $25, and owner-enabled Access $3 monthly offers.
- Personal site wording, excluded features, and planned site database, account, and credit allowances.
- Storage allowances are Keep 10 GB, Sync 50 GB, Cloud 256 GB and Access 2.5 GB. Site files and databases use the same storage allowance.
- Costs reflect revised storage, site backend budgets and optional model-sale funding.

### Fixed

- Website builds use an explicit source root so HTML entries remain at their expected output paths.

### Limitations

- Billing, inference, storage, site hosting, site account services, sync, and Box provisioning remain unconnected.
- OAuth requires configured provider apps. Independent outage alerts require an external monitor.
- Browser-local chats are not encrypted by the server vault.
- Usage APIs report unconnected services as unavailable. Metering is implemented internally but is not connected to live inference or provider invoices.

### Validation

- TypeScript and affected behavior tests passed for accounts, OAuth, secure proxy origin handling, mock checkout, catalog controls, discounted metering, credit reservations, grants and undo, promotion expiry, status, vault isolation, and cost projections.
- A dedicated production-mode host passed isolated page and asset checks, trusted HTTPS proxy handling, Secure session cookies, registration, mock checkout, account APIs, and disabled local administration.
- The website build passed after fixing the HTML output root.
- Portable Windows Agent compilation and packaging passed. Published portable copies match.
- The local preview, account and admin pages, status page and health probes responded successfully.

## 2026-09-06: Account administration and pricing review

Version: 0.1.0 | Status: released | ID: 2026-09-06-pricing-review

### Added

- A local admin dashboard with persistent account controls, roles, suspension, session revocation, password replacement, draft profiles, and audit history.
- Expiring, revocable promotional credit grants funded by Locale, with no customer charge and idempotent retries.
- Saved startup funding and cash-flow projections, including model funding, Box commitments, hosting, and promotional credit liability.
- Proposed static hosting on Keep, Sync, and Cloud, account inference on Sync and Cloud, and a Box worker on Cloud.

### Changed

- Landing pricing previews Keep at $5, Sync at $10, Cloud at $25, and an owner-enabled Access offer at $3, pending approval.
- The Agent section appears directly below Features, explains browser and paired phone use, and the top-right Download Agent link is removed.

### Fixed

- Admin account search treats wildcard characters literally.

### Limitations

- Prices and allowances remain proposals. Existing account offers and pending checkout selections are unchanged.
- Cloud inference, storage, site publishing, device sync, worker provisioning, credit spending, and billing remain unconnected. Saved grants do not run models.
- Account-based admin access requires an assigned role and explicit HTTPS server configuration. Local bypass is disabled in production.
- Provider spending is not connected. Forecasts use assumptions and exclude unentered labor, tax, payout delays, and provider capacity changes.

### Validation

- TypeScript and affected behavior tests passed for admin access restrictions, account persistence, session and password controls, promotional grants, expiry, audit, and price isolation.
- Cost tests passed for full-allowance expenses, Box minimum accounting, storage egress, prepaid inference, growth, churn, and promotional credit costs.
- The local website, admin page and APIs, account page, and browser workspace returned successful responses.
- Website build and portable Windows Agent packaging passed.

## 2026-09-06: Get Started with a recorded introduction

Version: 0.1.0 | Status: released | ID: 2026-09-06-browser-get-started

### Added

- The browser app opens a normal introductory chat with a genuine Muse Spark 1.3 response generated through OpenCode. Recorded playback makes no model request.
- The introduction includes browser tools, optional Agent features, limits, and three starter projects, with visible recorded-response attribution.
- A first-use confirmation is required before Nano sessions can download or run the on-device model.

### Changed

- Renamed browser entry buttons Get Started and placed Sign in before the header button.
- Moved Pricing into the main navigation and View pricing below the hero buttons.
- Removed the hero account requirement line and simplified the local-compute description.
- The browser app now uses /web. Existing /try links redirect to the new route.
- Account pages hide the header Get Started and Download Agent actions.
- The dismissible Back banner appears only for Get Started navigation; direct and account local access open without it.

### Limitations

- Live browser replies require a supported Chrome Prompt API and device. The recorded introduction can be read without Nano.
- Playback timing is simulated. The recording is attributed to Muse Spark 1.3, not Nano.
- Browser storage must persist to remember introduction completion and on-device consent across visits.

### Validation

- TypeScript and affected behavior checks passed, including recorded playback, history preservation, repeat visits, Nano consent, cancellation, and browser navigation.
- Generated the final introduction through the configured OpenCode connection using Muse Spark 1.3.
- The local preview and dedicated website server served /web and account routes successfully; old /try links redirected to /web.
- Website build and portable Windows Agent packaging passed.

## 2026-09-06: A local harness for first steps and long-term projects

Version: 0.1.0 | Status: released | ID: 2026-09-06-local-harness-positioning

### Changed

- The landing page presents Locale as a local AI harness for small workloads and large, long-term projects.
- Browser and Agent descriptions distinguish free introductory agentic coding with Gemini Nano from multi-model orchestration for power users.

### Limitations

- Model groups, task delegation, local Ollama models, and device tools require an open Agent.

### Validation

- TypeScript and four affected behavior tests passed.
- Website build and portable Windows Agent packaging passed.
- The local website preview, release feed, and website guidance routes returned successful responses.

## 2026-09-06: Accounts, cloud plans, and updated website

Version: 0.1.0 | Status: released | ID: 2026-09-06-cloud-accounts-website

### Added

- Working account registration, sign-in, sign-out, and a dashboard for saving a plan selection before checkout.
- Sample models grouped by Chrome, Ollama, OpenCode, and Grok.
- A dark illustrative workspace matching the current interface, using sample content.

### Changed

- Renamed the plans Keep, Sync, and Cloud, preserving existing selections. Keep emphasizes $5 for the first month, then $10/month.
- Cloud includes monthly inference credits through a third-party provider and a Box VM under one subscription. Final allowances remain to be announced.
- The browser action is now Use It. Header actions include Download Agent, View Pricing, and Sign in.
- Removed the harness suffix beside the Locale wordmark, added the no-account requirement checkmark, and described local compute and Kickbacks.ai earnings.
- Codex is hidden behind a disabled marketing flag. Machine-readable documentation remains discoverable outside visitor navigation.

### Limitations

- Checkout is a placeholder. No charges, inference credits, cloud storage, device sync, or VMs are activated by registration or plan selection.
- Email verification, password recovery, and public account hosting are not yet available.
- Cloud model, credit, and VM allocations are not finalized. Research estimates are proposals, not included allowances.

### Validation

- TypeScript and 12 affected behavior tests passed. Focused account tests covered persistent sign-in, hashed credentials, session rotation/expiry, isolation, pricing, request validation, and throttling.
- Two focused account tool contract tests passed. A supported live WebMCP browser context was not available; live registration of that optional browser tool was not verified.
- Website build and portable Windows Agent packaging passed. Local preview and documentation routes responded successfully.
- An isolated dedicated website server passed HTTP registration, session, pending-plan, and logout checks, and rejected Agent API routes.

## 2026-09-06: One source for interface colours

Version: 0.1.0 | Status: released | ID: 2026-09-06-design-token-consolidation

### Changed

- Every interface colour token is now defined in one stylesheet instead of two, so a theme or accent value has a single place to read and change.
- Buttons take their fill and hover colours from the accent tokens, so the selected accent applies to them instead of always showing violet.

### Fixed

- Restored hover and panel backgrounds that rendered as transparent because they referred to colour tokens that were never defined.
- Raised the contrast of text on filled accent backgrounds, which fell below the accessibility minimum in dark mode and on the amber accent.

### Limitations

- This is an internal styling change. Layout, wording, and behaviour are unchanged.

### Validation

- TypeScript and the full test suite passed with 947 tests.
- Checked in Chrome that all 33 referenced colour tokens resolve, across both themes, all five accents, and at 1440 and 420 pixels wide.
- Website build and standalone Windows Agent packaging passed.

## 2026-09-06: Models included with Ensemble

Version: 0.1.0 | Status: released | ID: 2026-09-06-ensemble-model-access

### Changed

- Ensemble includes models alongside its cloud-hosted harness, 1 TB of storage, and device sync for $60/month.
- Keep and Locale Cloud continue to require Chrome’s foundation model or an Agent connection and do not include model access.

### Fixed

- Corrected the previous plan description that excluded models from Ensemble, including pricing, FAQs, model-readable documentation, and repository guidance.

### Limitations

- Subscriptions and cloud services remain in development. Ensemble’s model selection and usage limits are not yet published.

### Validation

- TypeScript and four affected release-feed and subscription behavior tests passed.
- Website build and standalone Windows Agent packaging passed. Preview, trial, and model-readable documentation routes returned successful responses.

## 2026-09-06: Quieter sponsored turns and clearer model pickers

Version: 0.1.0 | Status: released | ID: 2026-09-06-picker-and-sponsor-polish

### Changed

- Primary and consultation pickers share search, clear, and header controls using existing UI primitives. Clearing a search preserves model selections.
- Ship It and Deep use matching option rows below Consultation inside the model-selection popup. Consultation includes an adjacent arrow to choose advisors without a separate models row.
- Model favorites and Deep controls use keyboard-accessible Locale tooltips. Provider variants are distinguished from native thinking controls.

### Fixed

- Narrow chat headers keep their title and actions separate, including zoomed viewports.
- Empty model searches no longer imply that a provider is disconnected.
- Kickbacks.ai inventory retries stop after three attempts per user turn, with increasing backoff. Thinking phases and focus changes cannot reset the budget or rotate a served creative.

### Limitations

- Company accents use supplied brand colors or readable icon pixels, with a neutral fallback. Inventory and settled earnings remain vendor-dependent.
- No paid ad metrics or full live model matrix were tested for this update.

### Validation

- Type checking and affected behavior tests passed, including bounded inventory retries and stale-turn protection.
- Chrome verified favorite persistence, independent Ship It and Deep toggles after reload, search clearing without selection changes, and popup controls at a zoomed phone-width breakpoint.
- The final consultation arrow opened and closed its paired model chooser without changing preferences. Consultation, Ship It, Deep and native thinking share the same option-row controls.
- Synthetic Chrome no-fill testing stopped at three inventory requests and did not restart after focus or thinking-phase changes. No real ad metrics were sent.
- The sponsored composer retained one loaded company icon and matching accent across twelve thinking phases. Lease expiry, loop mode, quick turns, and broken-icon fallback behaved as expected.
- Production website build and portable Windows Agent packaging passed. Local app and trial previews responded successfully.
- The automatically triggered 937-test repository baseline passed after resolving account-page build errors. Subsequent TypeScript and affected checks passed after the final option-row refinement, followed by successful website and portable Agent builds.

## 2026-09-06: Updated plans, tool descriptions, and provider branding

Version: 0.1.0 | Status: released | ID: 2026-09-06-plans-tools-branding

### Added

- Descriptions of file tools, previews, browser history, command execution, model consultation, task tracking, and model management, with runtime requirements.
- Original provider logos served locally, including the Kickbacks.ai brand.

### Changed

- Removed the public benchmark section and downloads. Historical research remains in the repository.
- The browser trial return link is now Home.
- Keep is $5 for the first month, then $10/month for 50 GB without sync. Locale Cloud replaces Reach at $15/month for 100 GB with sync. Ensemble is $60/month for 1 TB with sync and a fully cloud-hosted harness.
- Keep and Locale Cloud require the Chrome foundation model or an Agent connection. Ensemble adds cloud hosting. The initial Ensemble model exclusion was corrected in release 2026-09-06-ensemble-model-access.

### Limitations

- Cloud checkout, storage, device sync, and Ensemble hosting are planned and not yet available.
- Files and models on your own computer still require an open Agent.
- Codex integration is planned. The OpenAI mark identifies this connection.

### Validation

- Type checking and 12 affected behavior tests passed. Nine focused release-feed, subscription-pricing, and Kickbacks.ai protocol tests passed.
- Local website, browser trial, release feeds, and all six provider logo routes returned successful responses. Removed benchmark routes return 404.
- Production website build passed, local asset references resolved, and benchmark downloads were removed from the build.
- Standalone Windows Agent core compilation and portable packaging passed.

## 2026-09-06: Context Broker and bounded task completion

Version: 0.1.0 | Status: released | ID: 2026-09-06-context-broker-turn-controls

### Added

- Opt-in Locale Context Broker with an independently selected worker, local-only routing by default, and exact source excerpts with hashes and locations.
- Browser candidate files with isolated generation, focused diff review, validation, and revision-checked promotion that preserves concurrent user changes.
- Ship It mode with bounded completion checks and repeated-action protection.

### Changed

- File tools return concise write receipts, bounded reads and search results, and focused paginated diffs.
- Tool cards expose source evidence and file changes without requiring raw JSON. Thinking status stays after the latest chat activity.
- Consultation selection stays beside the primary model popup and remains open until dismissed. Busy shared models link to the chat using them.

### Fixed

- Kickbacks.ai uses a single sponsored placement per user turn instead of refreshing with each thinking phase, and is disabled during loop execution.
- Kickbacks.ai v2 readiness and native inventory handling, with honest Locale client identification.
- Sponsored composer uses the vendor company icon and its supplied brand color or a color sampled from that icon. Missing assets use a stable fallback. Short turns do not flash an ad, and focus changes cannot bypass retry backoff.
- Nano recovery validates observed preview references and candidate handles instead of accepting invented IDs.

### Limitations

- Context Broker is off by default. Device candidate staging, a complete cross-provider billing ledger, adaptive routing, and measured end-to-end savings are not included.
- No Portal service, adapter, or dependency is integrated.
- Nano completed source inspection and candidate generation/review, but stalled before end-to-end candidate validation and promotion. Model reliability is not guaranteed.
- Kickbacks.ai inventory and settled earnings are vendor-dependent. Paid impression settlement was not tested.

### Validation

- Focused behavior tests passed for source ownership and freshness, bounded worker calls, dirty-tree preservation, validation failures, full diff review, and atomic promotion.
- Chrome-controlled Nano checks completed a real broker inspection and a counter preview test with observed Add and Reset results.
- Nine deterministic Chrome browser checks passed for isolated candidates, real offline preview interactions, atomic promotion, dirty-file preservation, and rejection of failed validation.
- Chrome composer checks with synthetic advertisers verified loaded icons and matching accents in both themes, one inventory request across twelve thinking-phase changes, a fresh creative only on a new turn, and no ads for short turns or loop execution. No real ad metrics were sent.
- TypeScript and affected behavior tests passed, including 25 focused Kickbacks.ai tests and subsequent Agent turn-budget checks. Website and portable Windows Agent builds passed. No full test suite or paid model matrix was rerun.

## 2026-09-06: Website, browser trial, and public release notes

Version: 0.1.0 | Status: released | ID: 2026-09-06-website

### Added

- Product website with features, local and connected model options, published benchmark results, and Agent downloads.
- Dedicated browser-only trial using Chrome's foundation model with Agent connections and backend sync disabled.
- Subscription offers: Locale Keep at $5/month for 50 GB without device sync; Locale Reach at $10/month for 100 GB with device sync; Locale Ensemble at $100/month for 1 TB with device sync and exclusive discounted inference/model access.
- Release notes available as HTML, JSON, and Markdown from a shared source.

### Changed

- The standalone website opens the product page. Locale Agent continues to open the full workspace.
- Repository instructions require user-facing changes to be recorded in the release notes.

### Limitations

- Cloud checkout, storage, subscription entitlements, remote internet sync, and discounted inference are not yet implemented. No subscriptions are sold by this release.
- Codex sign-in integration is planned. Existing OpenAI-compatible API support is separate.
- Chrome's foundation model requires a supported desktop browser, available Prompt API, suitable hardware, and an initial model download.
- Published model benchmarks are historical internal trials with simulated file/tool effects, not general model rankings or performance guarantees.

### Validation

- TypeScript and 515 affected tests passed across 80 files; no full suite or live model smoke tests were rerun.
- Focused browser-only capability and release-note tests passed: 12 tests, 72 assertions.
- Development HTTP checks passed for the product page, browser trial, release notes, machine-readable feeds, and benchmark downloads.
- Final affected check passed TypeScript and 14 tests across 3 files after the content refinements.
- Website and portable Windows Agent builds passed. Required Electron dependency download succeeded on retry.
- Built-page link and asset checks passed, including static route aliases and matching JSON/Markdown release feeds.

## 2026-09-06: Model groups and browser workspaces

Version: 0.1.0 | Status: released | ID: 2026-09-06-model-workspaces

### Added

- Reusable Agent Groups with a primary model, consultants, instructions, and bounded background delegation.
- Per-chat model consultation, model favorites, throughput observations, and context usage.
- Sandbox project files, previews, task tracking, and browser-local snapshot history.

### Changed

- Browser-only settings show capabilities available without Locale Agent.
- Agent Group edits synchronize linked chats while preserving their histories.

### Fixed

- Recovery of legacy project-child Scratch files into their project workspace while preserving conflicts and original records.
- Kickbacks.ai consent renewal handling and separate notices for empty, incompatible, or expired ad inventory.

### Limitations

- Snapshot history in Sandbox is separate from real Git repositories on Device workspaces.
- Kickbacks.ai requires explicit consent and eligible vendor inventory. Earnings and ad availability are not guaranteed.
- Multi-provider concurrent live delegation has not been exhaustively tested.

### Validation

- Historical affected tests and TypeScript checks passed in the corresponding feature reports.
- Recorded Chrome browser-only test: Nano wrote and previewed a page in two tool calls in 12 seconds. This is one task observation.
