<!-- Generated from changelog.html. Do not edit by hand. -->

> Markdown twin of https://conduitllm.com/changelog.html
> What changed in Conduit, release by release: a side rail and inspector, live-data pages, documents in chat, image generation — with the limits stated.

---
Release notes

# What changed in Conduit

A summary of each release, written in plain language rather than commit titles. The full list lives in the repository, and every binary is on the [GitHub releases page](https://github.com/runningpixels/conduit/releases). Conduit is in release-candidate stage for 1.0: installers are not OS code-signed, so Windows SmartScreen and macOS Gatekeeper warn on first launch.

## 1.0.0-rc.7 — 5 October 2026

**Writing: long pieces, outline first.** A new area on the rail for blog posts, technical docs, reports and newsletters. Describe what you're writing and the assistant proposes an outline, with the sections, what each must say and a target length, that you edit and approve. Then it writes the draft section by section into an editor beside the chat. It can draw on the web (off by default), your document collections or a finished Research report, linking each fact to its source and marking anything it can't source as a TODO instead of making it up. Ask for a change and only that part is rewritten, or select text to make it shorter or clearer. Text you write yourself stays word for word, History keeps every version, and a draft exports as Markdown or HTML.

**Costs for every current model.** Prices now come from a snapshot of the open models.dev catalog bundled with each release, about 790 models, instead of a short hand-kept table; OpenRouter models use the price OpenRouter lists. You can set the price of any model yourself, and a model with no known price says so instead of showing $0. Costs were also shown 100 times too small, and cached input was counted twice on several providers; both are fixed, and past usage is re-priced.

**Fixes.** DeepSeek chats no longer fail after the first reply. Time spent on a tool approval no longer counts toward a turn's time limit. Asking to fix a page updates that page instead of writing a new one. Hosted web search can now read the pages it finds, and a later reply no longer mistakes earlier search results for made-up ones. The inspector's Sources tab lists a Research run's sources, and Home's Start a deck chip starts a deck from what you typed.

## 1.0.0-rc.6 — 3 October 2026

**Research: a report whose every finding is checked against its source.** Turn on Research in the composer's + menu (or pick it on Home) for a question that needs more than a quick search. It proposes a brief, with the sub-questions it will answer, a scope and a depth (Quick, Standard or Deep), and nothing runs until you approve it. Then it searches, reads the pages in full and pulls out facts, each with the exact words from the page behind it. A fact counts only if those words are really on the page, and the app checks that, not the model. The result is a report in your chat's documents: a summary, findings per sub-question, open questions and numbered sources, with every finding cited. Stop keeps what was found so far. Research needs web search turned on and isn't available in local-only mode. Page text only reaches a model call that has no tools, so a page that tries to give instructions can't make it search, fetch or save anything.

**PDFs on the web are read.** Research, a workflow's Fetch page step and the model's page fetch now read PDFs up to 20 MB, parsed on your device the way Documents imports one. A scanned PDF with no text counts as a page with nothing to read.

**Security: connector tools ask unless they're marked read-only.** A tool from an MCP connector now runs without asking only when its server marks it read-only (the standard `readOnlyHint`, or Conduit's own field); every other tool asks first. Before this, tools on most third-party servers ran without asking, because only a field that Conduit alone reads could make one ask. Connectors you already use may now ask for tools that ran silently before, and "Always" on the prompt remembers your answer, as before.

**Security: the model's page fetch can't reach your own network.** It could previously be pointed at `localhost` or a private address. It now fetches public https sites only, re-checks every redirect, and returns the page's readable text instead of raw HTML.

**A search-heavy answer no longer stops silently.** Past a turn's search limit, a chat used to end on whatever the model had said so far, with no answer and no error. Now the model is told to answer with what it has. With Exa, Tavily, Brave or SearXNG a turn can search up to 8 times (DuckDuckGo stays at 3), and those results now show as sources in Activity and Sources.

## 1.0.0-rc.5 — 3 October 2026

**Web search on every model, with no setup.** Search now works out of the box on any model. OpenRouter uses its own built-in search, billed to the same key, like OpenAI, Gemini and Anthropic already did. Every other model — Groq, DeepSeek, a local Ollama model — searches through Exa by default, which returns real web results with no key (free and rate-limited; queries go to Exa under its terms). DuckDuckGo's instant answers, the old default, rarely found anything; if you chose it, it stays selected, and Settings → Web search offers a one-click switch.

**Get a search key in one click.** Settings → Web search links to the key pages for Exa, Tavily and Brave, and to SearXNG's setup guide, each opening in your browser.

**Personal apps.** Saved apps are now called personal apps on the Apps page and on Home; the rail still says Apps.

## 1.0.0-rc.4 — 2 October 2026

**Home.** Conduit now opens on a Home page. One box starts anything: ask for a deck and Slides opens with a storyline, ask anything else and a chat starts. Below it, Home shows what is waiting on you (workflow approvals and questions, memory suggestions), your latest chats, decks and apps to pick up, and every part of the app as a tile with a live count. A part you haven't used yet shows an example to try instead.

**Go anywhere from the keyboard.** `Ctrl+1` to `Ctrl+9` (`⌘` on macOS) open Home, Chats, Apps, Slides, Documents, Library, Workflows, Connectors and Memory, and the command palette has a “Go to” entry for each.

**Fixes.** Remote connectors on the 2025 protocol, such as DeepWiki, connect again instead of showing as down. A chat opened from Home starts at its latest message. The Pitch deck idea now opens in Slides. A connector search that hits a network hiccup tries once more before it gives up.

## 1.0.0-rc.3 — 2 October 2026

**Slides.** A new Slides section for presentations you build by asking. Describe the story, or ask for a deck in any chat, and the assistant drafts a storyline you edit and approve before it builds the slides. Everything happens in one live deck, so a change edits the slide it's about instead of producing a new copy of the file.

**Edit it your way.** Ask for a change and the assistant edits one slide at a time, or swaps a word across the whole deck. Script shows every word of the deck as one document you can type in, and you can double-click text on a slide to change it. Text you write stays as you wrote it when the assistant reworks a slide, unless you ask it to change that text. History keeps a version for every change, named after your request.

**Present and share.** Present full screen, with a separate presenter view (current and next slide, speaker notes and a timer) you can keep to yourself while sharing the slides. Export a deck as a single HTML file that presents itself in any browser, or as a PDF on Windows.

**Fixes.** The Documents page, the indexing consent dialog and the usage table show provider names (“OpenRouter”) instead of internal ids.

**Before you upgrade.** This version adds to your local database. If you later go back to rc.2 or earlier, that version starts with an empty database (the old file is kept as a backup).

## 1.0.0-rc.2 — 1 October 2026

**App settings.** Every saved app has a Settings page: choose which model answers its main and quick requests (or follow your active model), see its token use for the last week and set a daily limit for cloud models (models on your computer are never limited), browse, export or clear the data it keeps, revoke the sites and model providers it may use, and read a week of its activity. Prompts, replies and saved values are never recorded.

**Starter apps in your language.** The eight starter apps show their text in the interface language, with numbers, dates and currencies formatted to match.

**Fixes.** White-label branding works with the new design again: the Branding form starts from the current colours, a brand's colour reaches every accent, and turning branding on or off takes effect properly. Word documents keep characters like “&” and “é” when added to Documents.

**Security.** On Linux, pages can no longer open WebRTC connections: the webview starts with WebRTC off. It remains a known issue on macOS, which has no webview setting for it.

## 1.0.0-rc.1 — 30 September 2026

**A new look.** One design, dark or light (or following your system), replaces the theme gallery and theme files. The rail is labeled and carries the name and mark, and you can still pick the main colour for each mode. Ideas moved from the rail to the new-chat screen, under the message box, where picking one fills in the prompt.

**Apps.** Save a page the assistant built as an app and open it from the rail or from *Your apps* on the new-chat screen; it keeps working after you delete the chat. Eight starter apps come built in. Apps — and pages in a chat — can keep a little data between launches, take a few settings you fill in, and, only after you allow it, ask your AI model: the prompt names the provider and says when text would leave your device, and the page gets text in and text out — no tools, chat history, memory, or documents.

**Workflows.** Routines that fetch pages, search the web, have the model summarize, and save the result as a document — run now or on a schedule. Turning a schedule on shows everything the workflow may do on its own for you to approve, and a run that needs more pauses and asks.

**Known issue:** on macOS and Linux, a page's script can still open a WebRTC connection, which a page's content security policy doesn't cover. Windows blocks it in the webview itself; the macOS and Linux fixes haven't been built and verified yet.

## 0.1.0-rc.8 — 27 September 2026

Every page on the rail now shares one layout: a title, one line on what the page is for, the main action on the right, and a folded *How this works* for the longer explanation. Documents, Library, and Connectors are a list beside the selected item's full detail, Memory puts pending suggestions first, and Ideas uses the full width for its grid. The new layout is translated into all eight interface languages.

A page that needs data from many sites — a news reader, say — can now be allowed to **reach any public site**, for this session or always, instead of one site at a time. Every other rule still applies: https only, no local or private addresses, no cookies or credentials, the same limits, and nothing at all in local-only mode. And when an allowed site redirects to a different one, Conduit now asks about the new site instead of leaving the page with no data.

## 0.1.0-rc.7 — 26 September 2026

A new **side rail** holds Chats, Ideas, Documents, Library, Connectors, Memory, and Settings, and each opens as a full page instead of a pop-up — a reply keeps running while you're on another one. Settings is smaller as a result: providers, chat, web search, workspace, appearance, branding, privacy, and about. The panel beside the chat became an **inspector** with Page, Activity, and Sources tabs, so a finished reply shows one line — "2 steps · 1 site" — rather than a card per tool call, and the detail is one click away. The composer's row of icons became a single **+** menu, with whatever is switched on shown as chips, and a chat you've left shows "Running" or "Needs you" in the list.

**Ideas** is a page of twenty-one tested starting points — a pomodoro timer, a budget tracker, flashcards, Snake — that fill in a prompt you can edit before sending. An idea that needs something you haven't set up says so, and which ones you've tried is remembered on your device only.

**HTML pages can fetch live data, from sites you allow.** The page still has no network connection of its own: its requests go to Conduit, which asks you about each new site — once, always for this page, or not at all — and then makes the request itself, over https, without cookies or credentials. The globe button on a page lists every site it asked for and every request it made. Local-only mode refuses all of it, and one setting turns it off. Forms in HTML pages also work now; before, pressing a submit button did nothing.

Fixed: **local-only mode now refuses cloud providers everywhere.** Before, a chat that used tools — most chats, since the built-in tools are on by default — could still reach a cloud provider with local-only mode on. Plain chat, tool-using turns, image generation, and context compaction are all checked now.

## 0.1.0-rc.6 — 22 September 2026

Conduit can now chat with your own files. A new **Documents** collection in the sidebar takes plain text, Markdown, CSV, Word documents, and PDFs — drop them anywhere on the window, or attach a collection from the composer, and the assistant searches it while answering. A reply names the passages it drew on, and clicking one shows the exact text. Search combines meaning-based matching with exact keyword search, because each catches what the other misses. PDFs are parsed on your own machine; a scanned PDF with no text layer yields nothing, and the app says so rather than guessing. **Indexing sends a document's full text to whichever provider embeds the collection — OpenAI, Gemini, or OpenRouter — unless that provider is Ollama, which stays local.** Consent is asked per provider before the first document, remembered, and can be withdrawn from Documents at any time; with local-only mode on, a collection needs a local provider. Until you create a collection, chat is unchanged.

Ask for a picture and, on **OpenAI, Gemini, or OpenRouter**, Conduit generates one and saves it locally with the conversation rather than linking to a provider URL that can expire. Each image is billed by the provider, so Conduit asks once before the first one; asking *about* image generation doesn't trigger the prompt. Providers without an image endpoint are unchanged.

The prompts and resources a connected MCP server offers are now reachable from the composer, not just its tools: a prompt picker fills in the arguments a prompt declares and drops the result into the composer to edit before sending, and a resource picker attaches a document to the next message only, redacted and checked before the model sees it. A saved prompt with `{{variables}}` now asks you to fill them in when you insert it, instead of leaving the braces in the composer for you to find.

## 0.1.0-rc.5 — 15 September 2026

Six more providers shipped — **xAI, Z.ai, Moonshot AI, Qwen, Together AI, and Fireworks AI** — bringing the built-in total to **17**. Anthropic and OpenAI gained a base URL field too, so either can point at a compatible endpoint such as a LiteLLM proxy, and hosted web search stays limited to the official endpoints.

Themes go beyond colour now: a theme sets type, corner radii, borders, elevation, and motion as well as the palette, and **nine built-in themes** are available from Settings → Appearance — Orange Charcoal (default), Orange-Dark, Terra, Amber Terminal, Green Phosphor, Amber Paper, Graphite, Editorial, and a High Contrast option built to AAA. A `.theme.md` file extends a built-in theme with your own colours — no CSS, no URLs. A separate Reading font setting picks the face for assistant replies.

**Automatic updates are now optional.** Settings → About offers only-when-you-check (the default, unchanged), notify-when-available, or install-on-quit; turning checks off still means no network request at all, and automatic install isn't offered for the Linux `.deb`. The sidebar can now be resized or reset with a double-click, a settings button in the title strip jumps to any section, typing in Settings search narrows the section list, and a keyboard shortcuts sheet (`Ctrl+/`, `⌘/` on macOS) lists everything. The artifact panel can be expanded (`Ctrl+Shift+E`), and while the assistant writes a document you can watch its line count and size grow, with a button to pick up where it stopped if a long one runs out of time mid-turn.

Fixed: a cloud provider chosen before the provider list finished loading could leave local-only mode on and the first message failing with an error about a setting nobody had seen; the model menu no longer mislabels priced cloud models as self-hosted; a narrow window's sidebar and artifact panel now open as overlays instead of becoming unreachable; and Ollama now receives tool definitions, so it can use tools at all.

## 0.1.0-rc.4 — 12 September 2026

First-run setup now opens by asking for your language, theme, palette, and text size, so the rest of it is readable before it explains anything, and ends on a review of what was actually configured. **The interface is available in German, Spanish, French, Japanese, Korean, Brazilian Portuguese, and Simplified Chinese**, alongside English, from Settings → Appearance, or by leaving it on System to follow the OS. Japanese, Chinese, and Korean text is drawn with the platform's own font for that language, and dates, times, number grouping, file sizes, and sorting follow the language you picked rather than the machine's region.

Fixed: choosing a cloud provider while local-only mode was on used to fail the first message with an error naming a setting nobody had seen — it now turns local-only off and says so. The first-run screen could render above the top of the window with no way to scroll to it; errors during setup were silent; the allowed- and blocked-domain placeholders showed a literal `&#10;` in German, Spanish, and French instead of a line break; truncated text now shows its full value on hover; and the connector consent dialog's description of a tool's permission level is built from the permission and the tool's own description now, instead of a fixed backend sentence, so it can be translated.

## 0.1.0-rc.3 — 6 September 2026

The agent release. A turn can now be steered while it runs: follow-up messages queue while a turn is in flight, a run can be interrupted mid-loop to redirect it, and tool approvals can be remembered for one conversation or permanently — **except sensitive tools, which are never remembered and always ask**. The model can also render a native form to ask a question instead of guessing.

Three larger pieces landed alongside it. **Remote MCP** over streamable HTTP, including OAuth 2.1 with dynamic client registration and tokens held in the OS keychain, plus read-only search of the official MCP registry with one-click install; SSE-only servers are refused with a reason rather than failing later. **Agent Skills** as `SKILL.md` packages enabled per conversation, with metadata read first and the instruction body only on enable — **Conduit does not execute a skill's `scripts/`**, they are listed as documentation. And **persistent memory**, where the model proposes a fact through a tool but it is stored as pending and **never injected into a later prompt until you save it**; everything stored is listed, editable, and deletable in Settings, and encrypted at rest only when encryption at rest is switched on, which is off by default.

A context gauge now measures the fill of the next request being built rather than summed turn usage, and compaction journals older turns into a summary as a conversation nears the model window — **raw messages are never deleted**; compaction applies when the request is assembled. Conversations gained pinning, archiving, and one level of folders, and a segment timeline renders thinking, tool calls, and answers in the order they actually happened. Always-show-reasoning is on by default.

## 0.1.0-rc.2 — 2 September 2026

Web search became pluggable: a local backend with a DuckDuckGo default plus Tavily, Brave, and SearXNG, alongside Anthropic hosted search, selected under a dedicated Auto / Hosted / Local setting. Image attachments are now sent to models that accept them, and conversations can be exported as Markdown or JSON.

Chat markdown gained Mermaid diagrams and KaTeX maths. Messages can be edited and resent, including forking mid-thread, and each conversation can carry its own generation controls and custom instructions. Workspace folder tools are opt-in, with a chip in the chat showing when a folder is bound. This is also the release where white-label branding arrived in both forms — runtime branding from Settings, and build-time branding for a build made from source.

## 0.1.0-rc.1 — 22 August 2026

The first packaged release candidate: unsigned installers for Windows, macOS on both Apple silicon and Intel, and Linux as `.deb` and AppImage, with update payloads signed by an Ed25519 key. It carried the initial public licensing under AGPL-3.0, contributor documentation, and third-party attribution.

[Download the current release](https://github.com/runningpixels/conduit/releases)

New here? Start with the [documentation](https://conduitllm.com/docs.html), see [what stays on your machine](https://conduitllm.com/privacy.html), or read [how to demo an MCP server to a customer](https://conduitllm.com/mcp-distribution.html).
