ORKA CODE · Changelog
What changed.
Short, useful release notes—what changed, what improved, and what was fixed.
Private browser sign-in, clearer browser controls, and updated Claude Code and Codex support.
Orka Code 0.4.1
- Take over the browser for private manual sign-in, then explicitly return control to your agent. Choose the page to resume when several are open, with Stop and recovery actions available throughout.
- Follow browser work through streamed frames, a named cursor, and clearer question and attention controls. Browser streams recover cleanly when taking control or changing the viewport.
- Read long prompts and subagent descriptions without text clipping in narrow transcript panels.
- Keep Codex peer delegation working through its updated app-server connection, including follow-ups, permission requests, cancellation, and cleanup.
- Keep Codex’s home directory within its Profile and preserve existing WebFetch restrictions when Claude offers Artifact tools.
- Show MCP tool-discovery failures explicitly and refresh available models from each Profile’s live catalog.
- Update the managed harnesses to Claude Code 2.1.270 and Codex 0.154.0 while retaining the runtimes needed by existing conversations.
Password-manager and passkey integrations remain unavailable. Structured Codex asynchronous questions, ordinary-usage availability readouts, and Claude effort-cap settings are planned separately for 0.4.2.
Live model lists from both harnesses, full-file diffs, continue a session on the other harness in a new tab, the standing upgrade path with one-command admission, long-paste pills, Claude Code 2.1.259 and Codex 0.153.0, and the 0.3.1 dogfood fixes.
Orka Code 0.3.2 — live model lists and the standing upgrade path
0.3.2 is the first release admitted under the standing upgrade path: exact pins stay, unknown wire shapes still fail closed, and the hand work leaves.
Models come from the harness, live
- The composer chip, Create, Profile → Models, Assistant, and Atlas pickers offer exactly the models your account is served by the harness at session start: Claude Fable 5.1 shows up the moment Anthropic serves it, and the Codex list follows OpenAI’s current catalog. Only a change in the wire shape fails closed; membership changes never do.
- A session whose model is no longer offered says so and lets you switch; nothing is substituted silently.
- The recorded catalogs stay as offline fallbacks and parser tests. The Global default-model picker still uses the recorded catalog for now.
The upgrade path
npm run harness:admit -- <claude> <codex>performs the mechanical admission steps (currency, Claude recapture, catalog sync, verification) and prints the exact manual commands for the rest; humans read only surfaces whose recorded shape changed.- One standing evidence policy replaces the per-release risk amendments and private-visibility flags.
- Every admission carries a generated changelog delta sorted into four buckets (integrate now, needs adaptation, scrap, settings exposure).
Diffs show the whole file
- Diffs for tracked modifications and renames open with the complete saved file as context by default, hydrated in bounded, snapshot-verified reads; stale, filtered, binary, oversized, untracked, and added/deleted cases fall back to a truthful compact or metadata-only view.
- Diff syntax colors now use the same Timbre roles as the code and Markdown editors, in light and dark.
Continue on the other harness
- Pick a Codex model while in a Claude session (or the reverse) and Orka opens a new tab on that harness, seeded with a concise transcript of the conversation so far, and continues from there. The original tab stays intact.
- A session parked at a usage limit shows Continue with Codex (or Claude) on the limit card for the same hand-off.
- Only your messages and the assistant’s replies cross over; tool output stays with the harness that produced it.
Completed turns, quieter
- The completed-turn footer is a status icon, a compact runtime, and a locale-aware completion time; secondary telemetry sits behind an accessible hover/focus card. Failures and interruptions stay explicit. Legacy history without a recorded completion says so rather than guessing.
Harnesses
- Managed Claude Code 2.1.259 and Codex 0.153.0, admitted in one pass under the standing path. Every wire change between the previous pins was additive.
- Codex 0.153.0 can attach structured questions to a message. Orka has no answer control for them yet, so it shows the message and an explicit “not supported here, answer in the composer” notice carrying every question verbatim instead of dropping them.
- The updater’s retained-runtime declaration now lists every managed runtime the app keeps, so sessions bound to the 0.3.1 runtimes no longer block “Restart & update”.
Composer
- Pasting a long text (≥1,500 characters or ≥30 lines) stages a
pasted_text_….txtpill instead of flooding the composer; the model still receives the full content, and the sent bubble shows the pill. - One-row control rail, thin scrollbars, Enter creates a workspace, compact model picker with digit shortcuts.
Fixes from the 0.3.1 dogfood
- The bundled
orkaMCP works again on Claude Code 2.1.258 (the sidecar’s grant now travels inside the private MCP config). - The root error boundary no longer fires on the first live event of a
session (unbound
queueMicrotask). - “Restart & update” shows why an install was refused instead of doing nothing; the live-catalog probe retries instead of sticking on built-ins.
Dramatically faster session opening, the Pierre file/diff experience, full access by default, and registry-current harnesses including Claude Fable 5.1.
Orka Code 0.3.1 — speed, Pierre, and current harnesses
0.3.1 packs a seven-sprint performance-and-UI arc plus a same-week harness refresh into one private Alpha release.
Much faster where it counts
- Opening older sessions is ~60–90× faster: transcript checkpoint scans that took 29–100ms now resolve in ~0.3–1.1ms, backed by new guarded expression indexes.
- The app re-renders far less under multi-session streaming: session, fleet, and presence state moved into narrow-subscription stores, and the event presentation pipeline was extracted and tightened.
The Pierre file and diff experience
- The Files tab is a Pierre tree: git-status letters (M/A/D/R/U) with folder rollups, the complete colored icon set, compact rows, search, right-click menus, and drag-and-drop file moves with a guarded backend.
- The Changes tab is a folder-grouped changed-files tree; clicking a file opens its diff as a center tab with Split/Stacked views.
- The Assistant’s file surfaces use the same trees. Everything loads lazily — zero Pierre modules at app boot — and follows light/dark theming.
Full access by default
- New sessions on both harnesses launch with full tool access unless you explicitly opt into approvals, choose plan mode, or a session inherits a predecessor’s explicit choice. Historical reviewed Assistant actions replay truthfully with their recorded mode.
Registry-current harnesses
- Claude Code 2.1.258 — including Claude Fable 5.1 with its one-million-token context in the model pickers.
- Codex 0.152.1 — including the refreshed visible model catalog (gpt-5.6-sol and friends); hidden catalog entries remain excluded until proven.
- Both pins admitted under the Harness Fidelity Contract with independent approvals; remaining live-fidelity debt is recorded honestly under the 0.3.1 private evidence policy.
Under the hood
- Two cleanup passes removed dead code and re-verified every protected mechanism; the codebase held up better than expected.
- Release binary and evidence chains are digest-bound end to end.
The Profile Assistant, the Orka Browser, guided Profile folders, and a registry-current harness pair — the biggest private Alpha release yet.
Orka Code 0.3.0 — the Assistant, the Browser, and current harnesses
0.3.0 is a big-bang release for Orka’s private Alpha cohort. It ships two headline capabilities, a clearer home for your work on disk, and returns the managed harness pair to registry-current.
Profile Assistant
- A Profile-native assistant conversation with artifacts, project bootstrap, and reviewed actions: request a worktree Workspace with a founding Session, prepare a new local or remote-backed Project, adjust Profile defaults, or archive a Workspace — each action grant-gated and fenced to the owning Profile.
- Assistant sessions run on native Claude and Codex routes with retained- runtime continuity across app updates and hardened coordination safeguards.
Orka Browser
- An embedded, Profile-isolated browser Workspace with page tabs, a live agent view, and Profile- and Session-fenced browser tools for both Claude and Codex.
- Agent-selected responsive viewports through 8K; temporary human takeover fits to the Orka window and restores the exact agent viewport; QA evidence captures land in the Session workspace.
- Fully optional per Profile: disabling stops owned runtimes, removes tools from new catalogs, and rejects stale calls before vendor execution.
Guided Profile folders
- Each Profile now has one visible working folder with a standard layout (projects, workspaces, assistant files) instead of hidden app-data paths.
- Setting it up is guided: Orka suggests
~/Orka/<Profile>by default, and if a chosen folder would collide with another Profile’s, it explains why and offers a separate subfolder in one click. Profiles stay isolated from each other by construction. - Existing Projects are never moved; they keep working exactly where they are.
Current harnesses
- Managed Claude Code
2.1.246and Codex0.149.1— the registry-current pair, admitted under the Harness Fidelity Contract with exact artifact hashes, refreshed model catalogs, and a full per-surface compatibility audit with independent approval.
Also in this release
- Zero-touch cross-harness Agent CLI provisioning and Finder-safe managed Codex acquisition with an actionable repair path.
- File-tree context actions, a calmer chat send-loading treatment, and a set of composer/transcript fixes.
- A leaner core: roughly 4,000 lines of dead and dormant code removed after a whole-release audit.
A clearer live-work timeline, safer Session continuity, new Claude-native capabilities, and a broad interface-coherence pass for the private Alpha.
Orka Code 0.2.2 — clearer work, stronger continuity
0.2.2 is a catch-up and confidence release for Orka’s selected private Alpha cohort. It packages the product work merged since 0.2.1, keeps the existing exact managed harness pair, and refreshes compatibility review against the final Orka implementation.
Clearer live agent work
- The transcript is now one calmer streaming timeline, with compact reasoning, tool, task, and result rows; clearer in-flight and settled states; improved long-session scrolling; and clickable local-file references.
- Questions, permissions, plans, MCP elicitation, and authentication recovery settle through a composer-anchored request drawer without losing their provider-specific meaning.
- Drafts, send errors, and asynchronous settlements stay attached to the exact Session and Workspace that produced them.
Claude-native additions
- Artifact publishing is explicit and consent-gated: Orka asks before publish or browser open and never silently auto-approves.
- Usage-limit recovery parks the Session truthfully. Automatic continuation is optional, Profile-fenced, bounded, and off by default.
- Todo-tool activity, MCP startup failures, and EndConversation finalization are presented as first-class lifecycle events instead of generic chat text.
- Browser control remains visible but cannot be enabled in 0.2.2 because Orka did not verify a provider-native connection and representative action on the managed Claude Code pin. Existing enabled settings can still be turned off, and the setup guide remains available. Orka does not claim that an extension, account, browser profile, or tab is connected.
Continuity and trust
- Durable Codex Sessions retain the exact managed runtime that founded them across relaunch, resume, native fork, and update preflight.
- Managed-binary downloads expose bounded progress and clean up abandoned scratch data after interruption.
- Failure messages are scoped and actionable, with retained drafts and local incident context instead of cross-Workspace error spill.
- Zero-remote repositories remain first-class for create, start, send, resume, commit, and local merge workflows.
Whole-app coherence
- Shared control, badge, chip, typography, radius, density, elevation, focus, motion, overlay, and toast rules now cover the main product surfaces.
- Command Palette, keyboard shortcuts, and the native macOS menu share one command registry and consistent Escape behavior.
- Observability adapts from the minimum window to ultrawide layouts with one deliberate scroll owner and truthful zero-versus-unavailable values.
- Empty states, truncation, recovery actions, and long labels now preserve the information needed to understand and repair a problem.
Exact managed harnesses
- Claude Code remains on exact managed
2.1.236. - Codex remains on exact managed
0.148.0. - Max approved this exact pair for private 0.2.2 under decision
max-one-time-0.2.2-private-frozen-harnesses-2026-08-21. The release gate still checks and reports registry drift. Registry-current harness admission and upstream feature review move to the dedicated 0.2.3 harness release.
Honest compatibility boundaries
- Both pins retain exact artifact and release-member hashes, synchronized model catalogs, all eleven compatibility surfaces, structured regressions, fail-closed unknown-shape handling, and refreshed implementation bindings. Release remains blocked until the final candidate receives independent fixed-commit approval.
- Missing complete provider-native replay remains explicit
UNVERIFIED-LIVEdebt across both harnesses, including MCP and Skills. This release reuses no 0.2.1 MCP carve-out. - Unsupported semantic controls remain unavailable instead of becoming prompt text or simulated success.
Private Alpha boundary
Install only the signed and notarized DMG supplied through the invited Alpha handout, and do not redistribute it. Commit or back up irreplaceable work before installing or updating.
The frozen-pair and evidence decisions apply only to exact app version 0.2.2 with private visibility. They cannot be reused for 0.2.3, a later release, or a public build.
Faster everyday interactions, roomier chat and Markdown editing, reliable empty states, and safer manual MCP management.
Orka Code 0.2.1 — faster where it matters
0.2.1 makes everyday work feel immediate. It also strengthens manual MCP management without weakening Profile isolation or overstating provider state.
Faster everyday interactions
- Project and Workspace creation now acknowledge immediately and show clear progress during longer local or remote repository operations.
- Context menus, dropdowns, tab closing, Command Palette, note creation, and chat submission respond without the previous visible delay.
- Sessions recover when a completed tool or subagent leaves the activity state stuck on Running, so the next message starts normally instead of disappearing into the previous turn.
- Closing or removing the last open item now shows the correct empty state instead of leaving retired content on screen.
- Chat uses more of the available width on large displays while remaining contained at laptop sizes.
Better notes and Markdown
- New notes are created automatically in the Project’s
notesfolder asnoname.md,noname-2.md, and so on, then open ready for inline renaming. - Notes open in a Write-first editor with rendered headings, emphasis, lists, and tables, plus an explicit Source mode.
- Wide Markdown tables keep readable column sizing and scroll within the table instead of widening the app window.
Clearer navigation
- Command Palette and recent-session results are denser and easier to scan.
- Closing an active file or Session selects the nearest visible item without jumping across the tab strip.
- Transcript spacing, inline code, and completion scrolling are more stable and easier to read.
Atlas on Claude Code or Codex
- Atlas can now start with either Claude Code or Codex, using the models connected to the selected Project Profile.
- Mixed model lists are grouped by provider so the harness choice stays clear.
- An existing Atlas keeps the provider it started with. Choosing a model from the other provider explains that a provider handoff is required instead of pretending the native Session can switch underneath you.
- Codex Atlas stays read-only and network-off, with Profile MCPs, Skills, plugins, subagents, and unexpected approval requests disabled.
Safer manual MCP management
- Custom MCPs using bearer-token or API-key authentication can now be edited, disabled, and removed without getting stuck on “Checking…” or reporting a false cleanup failure.
- Static credentials stay in the selected Profile’s Keychain storage and do not enter Claude or Codex OAuth cleanup.
- OAuth cleanup requires confirmed provider state. If Orka cannot verify that credentials were cleared, it keeps the existing configuration and reports a recoverable failure instead of claiming success.
- MCP failures and recovery actions remain scoped to the Profile where the operation started.
Internal Alpha boundaries
This build is for Orka’s selected internal Alpha cohort. Install only the signed and notarized DMG supplied through the invited Alpha handout, and do not redistribute it. Commit or back up irreplaceable work before installing or updating.
Orka activates only the exact Claude Code and Codex versions admitted for this
private 0.2.1 build. Exact artifacts, catalogs, regressions, and fail-closed
guards passed, but complete provider-native replay on both current pins remains
explicit UNVERIFIED-LIVE debt. Unsupported semantic controls remain unavailable
instead of being presented as working. The one-release risk acceptance expires
after 0.2.1 and cannot be reused for a public build.
A clearer live-work experience, more resilient navigation, Profile-scoped Skills and MCP stores, and a unified ORKA composer.
Orka Code 0.2.0 — a much bigger daily-driver preview
0.2.0 is a closed internal Alpha preview for Orka’s selected cohort. It focuses on making Claude and Codex work easier to follow, launch, configure, and recover without weakening Profile isolation or pretending unsupported provider behavior exists.
Clearer live work
- Live activity now preserves provider identity, scope, ordering, delivery receipts, elapsed time, status, failures, interruptions, and final answers more faithfully across Claude and Codex. Usage remains explicitly unavailable when a harness does not expose it.
- Settled tool work and interim prose fold into one readable disclosure while current activity stays prominent. Skill instructions appear with the relevant run, and Codex collaborators use clearer agent callouts and live status views.
- Shell commands, diffs, JSON, YAML, HTML, CSS, and recognized tool output gain syntax-aware presentation.
- Stable activity identity removes duplicate Codex activity, perpetual “working” ghost turns, Markdown noise in previews, and final replies hidden by late stream events.
- Live and restored Sessions preserve their transcripts when you switch Workspaces or return after a cold start. Legacy transcript rows without a truthful owner now fail visibly instead of appearing under the wrong Session.
- Failed and interrupted work stays visible as a settled outcome. Recoverable transcript and launch errors use calm, dismissible notices without exposing internal error codes in the main interface.
- Ingress queues, transcript projection, and recent destination state are bounded and Profile-fenced. Consequential events cross durable persistence barriers before presentation.
- Navigation is latest-destination-wins, restored transcripts load incrementally, and genuine waits show truthful loading and retry states.
Creation and navigation
- New Workspace creation and live Session chat share the ORKA Code Composer while preserving attachments, Skills, semantic controls, context accounting, interruption, resume behavior, and Profile identity evidence where each surface supports them.
- Enter sends; Shift+Enter inserts a newline.
- New Workspace creation is simpler, and launch presets are removed end to end.
- New Session tabs can launch Claude or Codex within the owning Profile instead of following a Claude-only sibling path.
- The Workspace tab-strip
+opens Quick create:⌘Tstarts a new Session draft, while⌘⇧Tcreates a non-overwriting Workspace-relative Markdown file and opens it in Edit mode. - Session drafts use the compact ORKA composer layout.
- SVG files now preview correctly, and a persistent 10–24 px editor font-size control is shared across file tabs.
Profiles, models, and Project runtime
- One model picker serves Global and Profile settings, New Workspace creation, Session drafts, and live chat. Each Profile shows only the Claude and Codex model catalogs it has connected, stale Profile responses are rejected, and a Profile default can be changed from the composer.
- Generated frontend and Rust model catalogs bind exact recorded fixtures. Release checks fail closed when provider pins, generated catalogs, or compatibility evidence are stale.
- Project Scripts adds Setup, Run, and Archive editors. Named Run targets open and execute in the Session terminal.
- Project variables and Profile passthrough apply to new, resumed, forked, and handed-off Sessions. Restored terminals reconstruct the current matching Profile and Project environment, while protected identity variables remain blocked.
- A restored terminal requires its recorded Profile to still exist and match.
Skills and MCPs
- The Profile-scoped Skills library now has Installed, Explore, and Yours views, with provenance, selected and follow-all policies, explicit updates, offline cache behavior, removed-upstream recovery, transactional rollback, manual Skills, canonical repository identity, and a secure instruction reader.
- A reviewed repository catalog provides an offline floor. Public discovery is best-effort and never borrows ambient Vercel identity.
- The official-only MCP Store includes 22 entries curated from reviewed vendor evidence, with categories, search, setup guidance, provenance, and per-provider compatibility.
- Entries install in one action when no setup is required and open a prefilled setup flow when configuration or secrets need review.
- OAuth continuation, session-free Codex sign-in, Authorize everywhere, provider status, retry and reconnect actions, removal recovery, and Profile-fenced mutation sequencing now work through one lifecycle.
- Installed MCPs,
orka, andorka.peeropen a detail panel with evidence-backed per-provider tool inventories. Unknown or failed tool inventory remains explicitly unavailable.
Integrations, appearance, sound, and onboarding
- Profile Plugins are removed and no longer materialized. Integrations now presents Linear, ORKA Plan, and Plaud as truthfully Coming soon.
- Follow system is authoritative from first paint through live appearance changes while preserving the Profile accent.
- Sounds are enabled by default at 80%, with a keyboard-accessible volume control and updated event routing.
- Onboarding can stop after authenticated Profile setup with Nothing for now, creating no Project or Session.
- Device sign-in exposes native Open and Copy controls, and newly created Profiles appear immediately without restarting Orka.
- Fresh Claude Sessions no longer hit the false ten-second startup timeout seen during dogfooding.
- Sending to a stopped Codex Session now follows the revive path instead of panicking.
Internal Alpha boundaries
This build is for Orka’s selected internal Alpha cohort only. Install only the signed and notarized DMG supplied through the invited Alpha handout, and do not redistribute it. Before installing or updating, commit or back up irreplaceable work and use this preview only with nonessential repositories. Follow the cohort handout’s current Profile-credential restrictions, and report identity or updater anomalies immediately.
This release carries bounded UNVERIFIED-LIVE debt for some exact-pin Claude
and Codex workflows. Automated regressions and fail-closed guards passed, but
not every provider workflow was recaptured live for 0.2.0. The packaged 0.2.0
performance campaign was deferred, so this release makes no measured
performance claim.
Community MCP browsing, connectable Plaud, and post-Send recall remain
unavailable. Provider-native /design, /plan, and /review triggers are also
unavailable in Orka and are never sent as ordinary prompt text.
Updates stay separate
Signed archives live in Cloudflare R2. The small updater manifest and these notes ship with the reviewed website deployment, so a marketing change can never invent an app release.