What's New

Release notes for K2. Updates are published to GitHub.

v0.45.0

Latest
October 8, 2026

0.45.0 — See your agents work

-Thread shows the agent working. While an agent works, Thread shows a live strip under your message: the time since you asked, the current step ("Running a command", "Thinking… 8s"), any subagents, and a Stop button. It stays up after the reply while subagents or background tasks are still running, and says plainly when the agent is stuck on a permission prompt or a question.
-Activity you can trust. The server, not each window, now decides whether an agent is working. Every window, the web app, My Home and Zen show the same state, and it no longer gets stuck on "working". Older servers keep showing their dots in the new app.
-LLM tokens. Settings → LLMs → Tokens holds several subscriptions and API tokens for Claude, Codex and Grok (API tokens for Gemini too). Each tool has one server default. Use next token switches when one runs out, and running chats pick up the change. Any chat tab or workspace can use its own token: open the Token menu in the chat header, or right-click the tab. K2 keeps your saved logins fresh. Logins stay on this server and never travel in a clone. From the CLI: k2 llm tokens.
-Hosted mail: calendars groundwork and steadier certificates. Servers get ready for calendars and contacts. There's an Apple setup profile (k2 hostmail profile) and an explicit Stalwart upgrade to 0.16.20. Certificates K2 issues now renew themselves before they expire.
-Mail you stay in control of. k2 mail send --bcc, and an owner "always BCC" setting per workspace that the agent can't remove. Agents send only through K2, so your rules always apply. An agent allowed to manage mail can now do what you can for other mailboxes, except loosen the rules on its own mail.
-k2 sidecar. Agents can start, list and stop side chats for Claude, Codex, Grok, Gemini, Cursor, Pi and Hermes. Each can be resumed later. Turn it on per workspace with k2 sidecar access on.
-Rename agents from the sidebar: right-click → Rename agent. The handle stays the same, so messages keep working.

Fixes

-Codex: each chat runs its own background server, so Thread replies and k2 commands act as that chat. Messages you send before Codex's first reply no longer disappear. If Codex was already open, restart it once after updating.
-A Thread message to a chat opened from history now goes to that workspace's agent, never another workspace's.
-Terminals no longer hang or print (eval) errors when the login shell prints extra output at startup.
-Published apps on localhost load even when the server lists IPv6 first. An app that isn't running shows "Service not reachable" (502) instead of a 404.
-My Home remembers the view (terminal, chat, split) for agents on other servers.
-The LLM launch bar starts hidden; turn it on in Settings → LLMs.
-The Zen permission banner just states that the agent is stuck, with no button. Zen widgets get the full set of agent states (working, monitoring, needs you, no update, idle).

Server owners: to use the calendar features, re-run the mail helper installer once with --version 0.45.0 (sudo bash install-mail-helper.sh --version 0.45.0). New servers we set up get it automatically.

v0.44.4

October 7, 2026

0.44.4 — Security update

-Important security fixes. K2 now checks where every browser request comes from before it acts on it, for the web client, apps and live connections. Please update the app and your servers.
-Actions use the right method. Every action that changes something now needs a POST request. Reading still works as before. Update the desktop app along with your servers: an older app connected to a 0.44.4 server can read but can't make changes until it's updated.
-Apps. An app's guest sign-in now expires after 7 days, and app requests from other sites are refused. Apps calling their own address keep working as before.
-Agent switches. Only Admins and Owners can turn agent permissions on or off (DNS, connections, mail sending, database access). An agent can't grant itself database access.

v0.44.3

October 7, 2026

0.44.3 — Gardens your way

-Put the controls anywhere. A Garden file can now place the Garden switcher, the Zen toggle, usage and the theme picker wherever you like: the top band, a new bottom band, the top or bottom edge of a column, or inside a menu. Leave one out (usage, for example) and it's hidden. A Garden can drop the top band entirely; a thin strip stays so you can still drag the window.
-Menus. A menu button can hold the switcher, the Zen toggle, the theme picker and usage. It works with the keyboard: arrows to move, Enter to pick, Esc to close.
-The nav rail in the top band. slot = "top" puts My Home, Agents, Projects and Tickets as a row of icons next to the Garden switcher.
-Always a way out. The Garden switcher and the Zen toggle must each be on screen or one click away in a visible menu, or the Garden won't validate. A closed menu never trips safe mode. On a narrow window, usage and theme hide before anything you need. ⌃⌘Z, View → Exit Zen Mode and Shift-for-safe-mode work in every layout.
-k2 zen guide. A user guide in the CLI with 10 topics and copy-paste examples (bottom bar, both buttons in a menu, the rail on top…). It works even when K2 isn't running. k2 study zen points to it, and validate errors name the page to read.
-Older K2 apps ignore the new layout and keep today's top band.

v0.44.2

October 6, 2026

0.44.2 — IMAP repair works without the mail helper

-IMAP check on startup, fixed. In 0.44.1 the startup check for the IMAP listeners (143 and 993) skipped itself whenever the mail helper wasn't installed yet. Now it reads the listeners first. If both are there, it does nothing. If one is missing, it adds it, then restarts the mail server through the helper or the server's existing permission to restart it. If neither is available, it keeps the new listener and logs the one command to run.

v0.44.1

October 6, 2026

0.44.1 — Hosted mail installs again, and air-gap fixes

-IMAP on older mail servers. A server that turned on hosted email before 0.40.147 never got IMAP on ports 143 (STARTTLS) and 993 (TLS). On startup, the daemon now adds whichever of those two is missing and restarts the mail server once. If both are already there, it does nothing. Nothing else in the mail setup changes.
-Air-gap stops the usage check. With air-gap on, K2 no longer checks your Claude, Codex or Grok usage, so nothing goes out to those services in the background. The usage chip reads "Off (air-gap)".
-Mail helper ships with the release. Turning on hosted email needs a small root helper on the server. It now comes with every release, along with a one-line installer that someone with root runs once per server. If the helper is missing, k2 hostmail enable stops before downloading anything and prints that exact command instead of "Permission denied". k2 hostmail status shows helper: installed, missing, or not allowed by sudoers.
-Reverse DNS reads right. k2 hostmail ptr set judges "aligned" by what k2.dev actually published. If this machine's DNS cache still has the old name, you get a note saying it clears on its own, instead of "not aligned".

v0.44.0

October 5, 2026

0.44.0 — Zen Gardens

-Zen Mode. The ensō at the top right of the top bar turns a window into Zen: a calm, personal page instead of the admin panel. ⌃⌘Z leaves Zen from anywhere (Ctrl+Alt+Z on Linux). Hold Shift when turning it on for safe mode. Zen is per window, and it's on the Mac and Linux desktop app only.
-Gardens. Inside Zen you see your Gardens. They're personal pages kept on this computer, and nobody else on the server sees them. Garden 1 has a thin rail (My Home, Agents, Projects, Tickets) beside your agents and a conversation. Garden 2 starts empty: ask your agents to build it, or click Start with the default. ⌘⌥1–9 switches Gardens. + New Garden asks whether to start with the default or empty.
-Inside Garden 1. My Home shows your Homes' agents. Agents shows this server's agents, with a GROUP: picker when focus groups are on. Tickets shows the Tickets board in glass, with chat only. Projects is coming soon. Picking an agent, or coming back to it, puts the cursor in its message box. Agents' pictures show where they have one.
-Themes. Basic (K2 blue), Midnight and Paper. ⌃⌘. cycles them, and each Garden can have its own. The usage chip and the theme control sit at the top right, and every tile has the same soft glass edge.
-Agents can build it. k2 zen garden list|new|rename|reorder|delete|template and the k2-zen skill let your agents arrange and restyle Gardens for you. Settings → Gardens manages them too.
-My Home. The Home tab is now called My Home, and its tooltip says it's your own page on this computer.
-Thread stays in sync. A message sent from a Garden, the Agents page, Home, another window, another person, or an agent now shows up live in every view of that Thread. A view that loses its connection reconnects and catches up by itself.
-Fixes. Typing no longer hides the working dots, and a growing message box keeps the newest message in view while you're at the bottom. Dropdowns in cards are no longer cut off.

v0.43.3

October 4, 2026

0.43.3 — Tickets go live for apps

-Live tickets in apps. An app with ticket access now hears ticket changes the moment they happen, on the same activity socket it already uses: new tickets, comments, answers, status changes, assignments, and resolves or dismisses. Each person only hears about tickets in rooms where they're allowed to read them. Briefs are never sent over the socket. Apps fetch them on demand.
-Apps catch up with the new tickets. Apps that can post to tickets can assign a person, with the same warning for names that aren't on the server. Answering with a suggested option or a typed message, changing the status, and reading a brief are all covered.
-Privacy. Ticket reads for app guests no longer include file paths on the server or internal session IDs.
-For app developers. k2 study app-tickets documents the events and the ticket calls.

v0.43.2

October 4, 2026

0.43.2 — Agents from other servers open right on Home, and tickets you can read

-Other servers open in place. On macOS and Linux, picking an agent from another server on Home opens it right there, and your window stays put. If you turned this off before, it stays off. The setting is Settings → General → Experimental → Open agents from other servers here. Windows keeps the old behavior for now. Servers older than 0.41.0 still switch the window, and 0.41 and 0.42 servers open view only.
-Switching servers keeps your rooms. Changing servers in the top bar no longer reconnects the agents open on Home.
-The top bar follows the agent you're looking at. For an agent from another server, the server name, people, usage (for example "akzm | 42%") and Keep awake show that server. The timer and the Tickets badge stay on your window's server.
-Home shortcuts. Rows on Home show their number. ⌘1–9 opens a row, and ⌘⌥1–9 switches between your Homes.
-Tickets, redesigned. A narrow list sits on the left, with short cards showing status, who it's assigned to, age, and an HTML mark. The agent's write-up fills the middle. The chat sits on the right, with Thread and Agent tabs, and a message box that has the agent's suggested answers above it. Change the status or the assignee from the ticket's header. Filter by Mine, Waiting on me, or All. Collapse the list to agent pictures. Open a ticket in its own window.
-Answers and discussions. Picking one of the agent's suggested answers marks the ticket answered. Writing your own message moves it to Needs discussion until the agent settles it.
-Agents write their requests up. An agent asking you for help can attach an HTML brief covering the problem, what it tried, what it needs from you, and the options. It opens in a locked frame with no scripts, and its links open in your browser. Agents should also assign every ticket to a person on this server. For now a missing brief or assignee is only a warning.
-Keep awake without the password prompt. Choosing a mode no longer asks for your Mac's admin password. "Also with the lid closed" is its own switch, and its one-time setup runs only when an Admin or Owner clicks Set up on that Mac. Only Admins and Owners can change Keep awake. Members see it read-only.
-Live status everywhere. Working dots update live for agents from other servers too. Email settings refresh on their own. The usage figures in the top bar update within a minute of each check.
-Mac touches. The daemon shows up as K2 Daemon with the K2 icon in Activity Monitor. The window buttons stay centered when you zoom with ⌘- and ⌘=. The Tickets page has no leftover close button.
-Fixes. An agent can no longer open or change the inbox of a workspace it isn't connected to. Codex host sessions start again with codex 0.154.

v0.43.1

October 3, 2026

0.43.1 — No more "Something went wrong" after 0.43.0

-The 0.43.0 crash. On 0.43.0, the window could fall into "Something went wrong" soon after opening, on your own server or another one. After the Keep awake button checked its status, other requests on the same connection could get that status back instead of their own reply. Every reply now matches its request.
-Crash guards. A list that comes back in the wrong shape no longer takes down the window. This covers the usage chip, presets, the chat list, Heartbeats, token usage, Projects, saved split layouts, and ten more places.
-Crash panel. "Something went wrong" has a Details section with Copy details, so a report names the part of the app that broke.
-Grok usage. At 0% used, the menu shows Weekly 0% with its reset time instead of "No usage window".
-Thread. An empty Thread says "No Thread messages yet" in the middle of the pane and names the agent you can message.
-HTML safety. HTML files, dashboard HTML, and HTML email can no longer reach the local K2 server or plain-http sites. Scripts and styles still work where they did.
-Keep awake. The menu uses square controls like the rest of Settings, and the mug is redrawn at full size. It fills up to show the mode.
-Settings. The last round checkboxes are now square.

v0.43.0

October 1, 2026

0.43.0 — Home, heartbeats that fire on their own, and apps

-Home (Beta). A Home tab sits between the gear and Agents. It looks like Agents, but the list is yours: agents from any server you have saved, in named Homes, and switching servers doesn't change it. Add Agent offers This server or From a server. Rows show live, offline, or Sign in, and the initials of whoever else is on that agent.
-Remote rooms (preview). Turn on Settings → General → Experimental → Remote rooms, and an agent from another server opens right on Home without switching your window. You get its tabs, drawers, chat history, and presence. You can type, open and close tabs, and split, and it all saves on that server. A server that's too old opens view only and says why.
-Heartbeats fire on their own. The daemon now runs the schedule itself every minute, on Mac, Linux, and Windows, even with no window open. A heartbeat missed while the computer slept fires once when it wakes, if it's less than 12 hours late. Turning one on or editing it waits for its next slot.
-Wake this computer for heartbeats. One switch in Settings. On a Mac it asks for your admin password once. "Also on battery" stops below 20%.
-Keep awake. A new control next to the timer in the top bar: Off, While agents are working, or Always. It says what it can actually hold, for example "lid closed will still sleep". Keeping a Mac awake with the lid closed uses the same one-time admin approval.
-Heartbeat drawer. It shows the real next fire, or the reason it's waiting, such as "needs instructions", "invalid schedule", or "retry in 2m". It never shows a stuck "now". New heartbeats need instructions. History shows who made each change. Only the Owner can delete a heartbeat for good; everyone else archives.
-Apps and heartbeats. An app can list, add, edit, turn on and off, fire, and archive the heartbeats in its room with heartbeats:read and heartbeats:write. App developers can read k2 study app-heartbeats. Apps can hear "agent working" again.
-Split view. Two windows on the same workspace share columns. A tab closed in one window stays closed in the other. A Browser tab no longer follows the other window's navigation or flickers.
-Tickets badge. The badge counts only tickets you can see. Tickets left from a removed workspace show under Unlinked workspace with Resolve and Dismiss. A badge that can't refresh dims instead of showing a wrong number.
-Roles. The Viewer role is gone. Logins are Owner, Admin, or Member. Use apps to give someone limited access. A Viewer account is turned off on update, and Settings lets you turn it back on as a Member.
-Stability. A rare error inside a window event no longer quits the app; it's logged to ~/.k2/client-event-faults.log. Mac stoplights stay centered after moving between displays, waking, or switching light and dark.
-Claude usage. The top-bar chip shows the greater of the 5-hour and weekly limits.

v0.41.6

September 30, 2026

0.41.6 — Notes you can page, and a lock you can clear

-Read what's new. Settings → General opens on the newest note. The arrows walk back through 0.41.0 and every later note in this series, and they stop before 0.40. Closing the popup still marks this version seen. The button still opens after this version was already dismissed.
-Login lock. k2 app user unlock clears an app guest's lock and leaves the password alone. k2 users unlock does the same for a box login. A name with no lock still succeeds. Changing an app user's password leaves the lock in place. Changing a box user's password still clears that lock.
-Thread. A message sent as the room shows the room's name. You is a message typed in the compose bar.
-Apps. An app with a room can add a file to that room's resource list, rename one file in the room, and hear when an agent there is working. Settings → Apps lists activity:read on its own. files:read and files:write do not include it. A new file name is one name, not a path.
-Database grant. k2 db grant can name the tables or views another workspace may use. Repeating --relation replaces that list. Leaving --relation off restores the whole public schema. A later migrate keeps the same list.
-Guest query. On the Linux database, an app session can send one SQL statement. K2 fills in the signed-in person, and the statement cannot choose someone else. A read uses store read. A change uses store write.

v0.41.5

September 29, 2026

0.41.5 — Nested workspaces, and menus that stay put

-Nested workspace. A workspace that lives inside another workspace keeps its own terminal. The outer workspace's session list no longer shows the inner one. Opening a saved pane leaves the other workspace's live terminal alone.
-Menus. A dropdown opened from Settings, or from a dialog, paints solid and sits above the layer that opened it. A list that used to clip inside the page now opens on the page.
-Read what's new. Settings → General opens the latest notes. It does not replay the older pages in this version series.

v0.41.4

September 29, 2026

0.41.4 — User access, apps, and shortcuts in the front window

-User Access. K2 Server lists Admin Access, User Access, User Templates, Custom Domains, Tunnel, Connected Servers, API Keys, and K2 Companion. User Access, User Templates, and Apps are marked Beta. You add a person on User Access. Each app lists its users, and adding one gives that person a role on the app.
-Apps. Pick an app on the left and its users and roles are on the right. Platform tokens and the sign-in issuer stay on Host. The old Caddy group is no longer on this page.
-Connected agents. The mark next to a connected agent is a square.
-CLI on Linux. Settings → General shows the k2 command that is already on the machine, including an Arch install. It no longer offers a Mac-only install button when that command is missing from the Mac path.
-Front window. Command-K, Command-J, and Command-Shift-L open in the window you are using. Other K2 windows stay put.
-Wording. User Access says app users.

v0.41.3

September 28, 2026

0.41.3 — Window chrome, and a crash after a long run

-Top bar. The K2 icon is the menu on Linux and Windows. Projects, Tickets, Settings, and Wiki use the same logo and the same right-hand cluster as Agents. New Window is Ctrl+Shift+N on Linux and Windows, and still Command+Shift+N on Mac.
-Linux window buttons. GNOME shows close, minimize, and maximize. Other Linux desktops, including Hyprland on Arch, show close only. The squares sit 1px lower in the bar. A divider next to the drawer buttons hides when those buttons are not on the page.
-Long run. After the app had been open for many hours, a missing method name inside a window event quit the process. That event is skipped. The app stays up.
-Email Link. The Primary workspace menu on Connect an inbox stays readable and can be clicked. It no longer opens as a see-through list inside the page.
-Mac and Windows. Mac keeps the system stoplights. Windows keeps minimize, maximize, and close on the right.

v0.41.2

September 27, 2026

0.41.2 — Arch download, and quieter stoplights

-Arch updates. On an Arch package, Settings → General no longer asks the Mac updater list for a Linux entry. A newer release offers the pacman package (k2--x86_64.pkg.tar.zst). The app does not install it. The same version stays quiet.
-Stoplights. When the window is not selected, the square stoplights stay the same grey and become 80% translucent.

v0.41.1

September 27, 2026

0.41.1 — Server switch no longer quits the app

-Square close button. Switching to another server changes the window title. On the Square style that update asked the close button for theme-button calls it did not have (setEditedFlag:, setTemporarilyDisabled:), and the app quit. Those calls now go to the system button. The square paint stays.

v0.41.0

September 27, 2026

0.41.0 — Usage, chat continuation, and a desktop that stays put

Everything since 0.40.150. The window, the browser, usage, and how a chat continues.

-Subscription usage. Signed-in Claude, Codex, and Grok show a chip on the top bar with the harness icon and the percent used. A harness you are signed out of stays hidden. The menu has the allowance bar, recent turns, and Refresh. Settings → Token Usage (under Context Catalog) charts daily tokens and can filter by workspace and model. The host ledger records Claude, Codex, and Grok. Gemini’s subscription meter is not in this build.
-Continue in a new chat. From history or from pinned Chat, continue in another harness. The menu shows that harness’s icon and where the chat came from. Claude, Codex, Grok, and Gemini can also show the session itself as chat.
-Plus menu. The tab bar has a plus menu. Hold Option and the preset you clicked opens in a sandbox. Launching an agent installs that one CLI if it is missing.
-View menu. One View menu replaces the old strip. Terminal is listed, then Chat. The button is named for the mode you are in. A plain shell tab uses a window icon and does not wear agent chrome. Inbox and pinned Chat stay on screen while the rest of the strip scrolls.
-Tab icons. File tabs use the same icons as the files drawer. A browser tab shows the site’s name and icon.
-Images and notices. Drop an image on Thread or on chat compose. Pane notifications sit at the top right.
-Square window. On the Square style, the stoplights and the window corners are square. Status marks are square. Radios and checkboxes are square. The window title is K2 and the server name. The logo opens the K2 dashboard. The Running Agents button is gone from the top bar. The nav collapse button sits at the bottom of the sidebar. The collapsed rail uses the same Active list as the open sidebar, without the old corner dots.
-Menu bar. On a Mac, a helper stays in the menu bar after you close the window and says whether this Mac’s daemon is running. Clicking it opens that menu.
-Browser. Back and forward live on the browser tab. The address field is square, and devtools is a cog. The page stays up when another app is in front, and still steps aside for other K2 tabs, Settings, and open menus. ⌘L selects the address on a browser tab, and opens the server switcher otherwise. ⇧⌘L is still the workspace assistant. A new browser tab starts with the address selected. Dragging a file in from Finder works. The Mac pane names the WebKit it is actually running, so sites serve the normal page. The embedded browser is on the current system webview.
-Server switcher. A click no longer dies because Settings, or another page, left a hidden copy of the switcher open.
-Sidecar refresh. Refresh resumes the same conversation and keeps the same tab. The terminal inside redraws. Closing the session still removes the tab.
-Sidecar Thread. Send waits until that extra chat has an address. Your draft stays if it is not ready yet.
-Heartbeats. Clicking a heartbeat opens the session that is already running. After the first fire, Own session points at the session it opened.
-Files. Long names in the drawer keep the end of the name visible.
-k2 workspace resources. list, add, and remove for a workspace’s resource files.
-Arch package. The release-tag build of the Arch/Omarchy package runs again.

Not in this build: Gemini’s subscription meter, and Home.

v0.40.150

September 23, 2026

0.40.150 — People, grants, and mail an agent can stand up

A skin user can have a full name, and Settings shows that list as People. Who may open an app is a grant. An agent on the box can bring hosted mail up with the CLI.

-People. Optional full name on the skin user (64 characters). Settings → People is that list. It is not Server Access. k2 app user full-name sets or clears it.
-Grants. A role is the rooms and caps for one app. A grant says who has that role. The subject is a skin user or a workspace. k2 app grant list|add|rm is owner-only. There is no separate people table.
-Host login. The first boot copies every existing guest onto a host grant and keeps an assigned role. A new guest gets a host grant. A missing host grant fails login the same way a bad password does. Deleting that grant stays deleted.
-k2 app. The human-facing command is k2 app. k2 skin still runs and points at it.
-Mail from the box. User k2 can run k2 hostmail enable from zero. A root helper does the system steps, so enable does not need a second admin at the keyboard. A partial enable resumes instead of stopping because this box is already listening on port 25.
-Arch and Omarchy. A release tag builds k2--x86_64.pkg.tar.zst on the Arch runner and attaches it to the GitHub release. One package for both. pacman -R k2 leaves ~/.k2 in place.

Not in this build: a Windows runner, a grant required per app address, mailbox and database grants applied to mail or Postgres.

v0.40.150a

September 23, 2026

Arch and Omarchy package for 0.40.150. The Mac release is v0.40.150. The package file is k2-0.40.150-x86_64.pkg.tar.zst.

v0.40.149

September 19, 2026

0.40.149 — Agents can attach hostnames; doctor refreshes; certs over CNAME

Mail-manage / DNS-manage agents can add mail. themselves once the apex is on the box. Thread posts from k2 thread remind agents the overlay paints markdown.

-Hostname add/remove is dns_manage. k2 domain name add [--role mail|publish|direct|other] and name remove use the same grant as k2 dns / k2 cert issue. Apex k2 domain add|remove stays owner (exit 3). e2e on lztek: idempotent add of mail.discover-nocode.com, scratch add+remove, apex still owner_only.
-Thread markdown nudge. After a successful k2 thread write (not --json), a stderr hint on the first post and every 10th: Thread renders markdown (bold, lists, code, fences, links). Help and AGENTS.md Tooling say the same.
-Doctor refreshes. k2 hostmail doctor POSTs /cli/mail/doctor (runs probes now). It no longer GETs the last stored run, which stayed stale after PTR/DNS already moved.
-Cert issue vs CNAME. If the apex is dns_write, k2 cert issue uses DNS-01 on _acme-challenge. (not the mail CNAME). It waits until ns1 and ns2 both have the TXT, then 8.8.8.8 and 1.1.1.1, before telling Let's Encrypt (querying public DNS too early caches NXDOMAIN from a lagging NS). Finalize accepts an already-Valid order. Issue JSON reports inventory PEM SANs, not live TLS through a CNAME. e2e: scratch-le4.discover-nocode.com issued YE2. If the hostname is a CNAME and the zone is not dns_write, it fails loud instead of HTTP-01 following the CNAME onto a closed :80.

Not in this build: People hub, hide XOAUTH2 when no IdP, Omarchy pacman package.

v0.40.148

September 19, 2026

0.40.148 — Hosted-mail PTR and bans, skin files, server switcher hotkey

Hosted-mail operators can set this box’s SMTP reverse DNS and unban Mail.app users after a migration. Skin guests can move PDFs and images without an owner token. ⌘L opens the server switcher.

-PTR / HELO. k2 hostmail ptr show|set writes the SMTP banner name and asks k2.dev to set the OVH reverse for this box’s origin IP. Doctor PTR/FCrDNS now queries 8.8.8.8 and 1.1.1.1, not the box’s own stub cache. One IPv4, one PTR — not one per hosted domain.
-Mint quota and autoconfig. New mailboxes default to unlimited quota (0 = unlimited). Mail-manage still sets a cap per inbox. Autoconfig DNS uses the attached mail. hostname (mail.lztek.io), not mail..k2.dev.
-Auth bans. k2 hostmail bans list|clear|migrate and k2 hostmail allowlist list|add|remove. Default bans list shows reason counts and real-user (authFailure) rows first; scanner IPs are a summary (full list: --json).
-Skin guest files. Guest k2skn_ can read-binary / upload-binary / create / copy / move in rooms with files:read / files:write. Pin lookup is find-only (200 if Chat is live, 404 if not — it does not start the agent). Thread posts still wake a sleeping Chat the same way k2 msg does. Admin Skin Access stays owner.
-⌘L / ⇧⌘L. ⌘L opens the server switcher (search focused). ⇧⌘L is the local LLM helper (was ⌘L).
-Hire color and focus group. k2 agent hire --focus-group Ops --color "#22c55e" (also rgb(r,g,b)). Settings → workspace → Agent tab has a hex/rgb field next to the swatches.

Not in this build: People hub, hide XOAUTH2 when no IdP, k2 hostmail reload, guest spawn of a pinned Chat, Omarchy pacman package (release.sh still does not build one).

v0.40.147

September 18, 2026

0.40.147 — Custom domains, IMAP 993, and hosted-mail operator tools

Attach a real domain to this server — Settings → K2 Server → Domains, or k2 domain add then k2 domain name add mail.example.com --role mail. That does not move nameservers and is not a K2 edge. Hostnames on this box get a Let's Encrypt certificate here (k2 cert issue / renew); cert.k2.dev still only covers *.k2.dev. After issue, the mail server reloads the new PEM (no hostmail disable).

Hosted mail now listens for IMAP on 143 (STARTTLS) and 993 (IMAPS) as well as the existing submission ports. Mail.app can use 993; 443 ALPN is no longer the only IMAP door.

Mail-manage operators get the rest of the hosted-mail CLI (e2e'd on lztek.io). k2 mail … for these verbs still exits 2 and points at k2 hostmail.

-Catch-all, alias, forward. k2 hostmail catchall|alias|forward. An alias is an extra address on an existing mailbox, not a new mint. Plus-tags (user+tag@) already work and are not aliases. Forward dest must be minted on this host; --keep leaves a local copy. Out of office and forward share one Sieve script — unset one leaves the other.
-Out of office and company footer. k2 hostmail ooo (vacation auto-reply on that mailbox) and k2 hostmail footer (one host-wide outbound plain-text footer). --domain on footer is reserved.
-Lists, spam, queue, ACL, autoconfig. k2 hostmail list (mailing lists — not k2 mail list), spam (train Junk, allow/block sender, quarantine), queue (outbound only), acl (IMAP/JMAP share between minted users — not k2 mail access grant), autoconfig show|apply (print or plant client-config DNS).
-App passwords. k2 hostmail app-password add|list|revoke — extra labeled secrets. Shown once. Rotating the mailbox IMAP/SMTP password does not kill them.
-DKIM / DMARC. k2 hostmail dkim show|rotate|retire and dmarc show|report-to. Rotate keeps the previous selector until you retire it. report-to sets Stalwart's report URI on a minted inbox and prints rua= to plant; it does not rewrite _dmarc.

Not in this build: People hub, hide compose unless an LLM pane, skin self-serve password reset, Omarchy pacman package (release.sh still does not build one), autoconfig apply rewriting names off *.k2.dev, swapping live MX off cPanel.

v0.40.146

September 17, 2026

0.40.146 — Hosted mail cutover tools, and the extra-window crash

Hosted mail is ready to hold mailboxes before you point DNS at the box. Mail-manage agents can mint on a pending receive-only domain, import cPanel Maildirs (including Sent/Archive folders, not only Inbox), raise per-inbox quota, and rotate the one IMAP+SMTP password (k2 hostmail password rotate, and Settings → Email Hosting → Rotate next to Retire). Import waits up to two hours so large inboxes do not look failed at 30 seconds. Doctor no longer returns a fake empty success. Cert status stops lying about self-signed certificates. k2 hostmail cert renew retries ACME without a second enable. Extra LLM-tab / named-chat typecheck leftovers from 145 ship here if your 145 build missed them.

Typing in Message-the-agent on a second window should no longer abort the Mac app (nil WebKit URL on IPC). Same crash as viewing several windows.

CLI honesty: k2 workspace open/create no longer crash on empty extra args; k2 terminal spawn does not print success on an error; k2 workspace triage rejects extra args and the help says it is this workspace’s inbox list.

Not in this build: hide compose unless an LLM pane, listen on IMAP 993 (use 443 ALPN), mail aliases, skin self-serve password reset, Omarchy pacman package (release.sh still does not build one).

v0.40.145

September 16, 2026

0.40.145 — Login history, 5/5 password delay, tabs that resume

Password guessing is capped at five tries per IP per five minutes — a delay, not an account lock (there is still no forgot-password on Connect). The Worker already does this on https://.app.k2.dev. This build puts the same cap on the daemon login POST (dashboard, LAN, a raw IP) and on skin guest login. Sitting at the machine (loopback) is not capped. Unsigned tunnel login is still 404 from 0.40.144.

Settings → Logs → Access Audit shows this host’s sign-in log (k2 users audit): who got in, from which IP, when. Owner-only.

After an update, extra LLM tabs in the strip come back as that agent (claude --resume), not a login shell. Pinned Chat already did. Named chats keep the name you saved on the tab (not “grok” / “claude”).

New workspaces skip “Do you trust this folder?” for Claude, Codex, Grok, and Gemini — K2 writes the same grants those tools already use, and re-asserts them on spawn and after a daemon restart. Never your home directory. Cursor may still ask.

Adding a folder that is already a workspace says workspace already exists \ instead of a generic fail.

Hosted mail. Mail-manage agents get the rest of k2 hostmail (grant, doctor, approvals, import, IMAP once-password, leaf --help). k2 hostmail status matches systemd. This is the cut for lztek / it-email / Mara once this daemon is on the box.

Thread, Chatter, Project, and Feedback use Meslo. Long words wrap. Shift+Enter is a real line break. In split view, Message-the-agent under Thread gets the caret and is the default when that setting is on. Selecting Thread text should not shrink the terminal by a pixel.

Companion 3.1.1 is enough; no 3.1.2. Skin guests no longer see Chatter frames on the overlay socket.

Not in this build: dark-tunnel (the API hostname still 302s / to app.k2.dev), local workspace duplicate.

v0.40.144

September 14, 2026

0.40.144 — Password sign-in moves behind the K2 edge

Your server's tunnel address (https://.k2.dev) no longer serves a login page, and no longer accepts a username and password from just anyone on the internet. Those were being scanned. Password sign-in now goes through https://.app.k2.dev, which is fronted by Cloudflare and signs each login for your server; the K2 app does this for you when you connect to a .k2.dev server, and the hosted web client already lives there. Everything that carries a token — your existing desktop sessions, the CLI, terminals — is unchanged. Self-hosters without the K2 edge can set Password sign-in over the tunnel to *Any client* in Settings → K2 Connect → Policies, or turn it off entirely.

If an admin created your account with a temporary password, the K2 app and the web client now walk you through choosing a new one on first sign-in, wherever you signed in from: the server switcher, Settings → Connections, or a sign-in prompt. Opening the tunnel address in a browser now sends you to your server's app.k2.dev address instead of an account page; on the server itself the local account page still answers.

Every sign-in attempt is now recorded with time, user, outcome, and where it came from: k2 users audit. Sessions last 7 days instead of 30; the app signs you back in from your saved password. Server owners can reset a user's password from the dashboard and force a change on next sign-in.

Hosted mail. k2 hostmail status now asks systemd whether the mail server is actually running instead of trusting what K2 last recorded, and tells you plainly when the two disagree. Re-enabling after a disable really restarts the server, and a new mail hostname sticks. Owners and admins can let a specific workspace's agent turn hosted mail on and off and manage domains for that workspace; minting addresses, sign-in setup, and removal stay owner-only.

HTML file tabs, dashboard HTML panes, and HTML mail in the Inbox no longer render blank.

v0.40.143

September 10, 2026

0.40.143 — Highlight and copy in Thread

Click-drag to highlight Thread posts and copy them. Double-click already selected a word; a background poll was focusing the terminal mid-drag and killing the range. Growing the Message box and staying on the latest post after you leave and come back shipped in 0.40.142.

v0.40.142

September 10, 2026

0.40.142 — Inbox you can read, and WebGL terminals

The pinned Inbox tab is a reader, not a kanban. Left: K2 Inbox (packages from k2 inbox / k2 msg) plus any hosted or linked mail for that workspace. Middle: the list. Right: the body — markdown for K2 Inbox, text or sandboxed HTML for mail. Open a message and Chat about this sends a note into that workspace’s pinned Chat with an id the agent can k2 inbox read or k2 mail read. Stay on Inbox; it is not a mail reply. Inbox / Active / Done are no longer statuses.

Workspace Published rows show live status and PID. Details (the blue chip on the second line) opens a view-only sheet: launch command or official skin gateway, cwd, port, host. A hostname from k2 publish subdomain create in this workspace still lists here even if the tunnel map is empty (label, target if known, Details — no fake PID). Create/point/rm now fail if they cannot stamp that workspace. Unowned account hostnames stay in Settings → K2 Connect. The Workspace drawer scrolls when it overflows.

Terminals paint with WebGL by default. Anyone still on the DOM painter is moved to WebGL; DOM remains an opt-out in Settings → Terminal, and a pane still falls back if WebGL2 is missing. Reopen a terminal (or reload) so it remounts. Thread, compose, tickets, and the code editor default to 13pt (terminal was already 13). A size you already saved is unchanged.

Focus Window actually opens (⌘⇧F). Each extra window keeps its own drawers and rail. Project chips on Agents come back after you switch hosts. Right-click menus follow the cursor after Cmd+= / Cmd+−. Agent tiles no longer jump when the working spinner appears.

After an update, the Chat you had selected comes back as that agent conversation — not a plain terminal. Thread (and split: terminal + thread) stays on the latest message when you return; growing the Message box pushes the list up so the latest post stays in view.

The server switcher highlights the top match as you type; arrows and Enter pick a host. Connected Agents in the workspace drawer uses a robot-head icon.

v0.40.141

September 8, 2026

0.40.141 — Local sites in Browser, and k2 db for BYO skins

Opening http://127.0.0.1 (a local preview, k2 publish, a markdown link) no longer replaces the K2 window or crashes it. Those links open in an in-app Browser tab. The Browser tab can still load local sites on this Mac. If you are connected to a remote host, loopback in that pane is this Mac — not the server — and K2 refuses it.

k2 db migrate now grants the workspace agent on new schemas and identity sequences, not only public tables. SQL comments are not mistaken for FORCE RLS. Migrations that try to CREATE ROLE are refused (roles are cluster-wide). k2 db --test mints a disposable database that does not count against the cap. SQL helpers k2.set_principal / k2.clear_principal / k2.principal_hygiene SET LOCAL on a checkout so a BYO pool starts empty.

---

v0.40.140

September 2, 2026

0.40.140 — Project pane shortcuts follow Message agent

On a project board, ⌘1–⌘9 now follow When moving between workspaces, auto-select. If that’s Message agent, the shortcut lands in that pane’s message box — not the terminal. Terminal still focuses the grid when that’s the setting.

---

v0.40.139

September 2, 2026

0.40.139 — Skin guests can have an email for password reset

Skin Access guests have an optional email. Username is still required. Forgot-password only mints a reset when that guest has both a password and an email — then the site (not the browser) gets the address to send mail. Guests can type the username or the email on login and forgot. K2 still does not email guests. Official --skin still cannot mint or send. Grid and the terminal stay off.

Owner sets email in Skin Access or k2 skin user add --email / k2 skin user email. Empty email clears it. Guests with a password but no email cannot use forgot until the owner fills the address.

---