Sharing an enabled personal server now completes its local Team setup while keeping the personal original and credentials on your device.
Repeated GTK launches and Team links reuse the open app. Links for the current Team keep the existing connection.
Server rows distinguish personal and Team entries, and Team actions use compact buttons. Disconnecting the app restores the personal routes it replaced.
Updating a .deb install no longer drops every MCP connection. The update feed only carries an AppImage for Linux, so the in-app updater stopped every gateway and then failed with "invalid updater binary format". Installs from a .deb or .rpm package now link to the release page to download the new package instead. (#961, thanks @JustinKeltner)
---
Full changelog: https://github.com/btsouth/toolport/blob/v1.23.2/CHANGELOG.md
Teams share previews now show the command, arguments, working directory, endpoint and declared credential names before publication in both desktop shells. Credential values stay hidden, personal originals remain saved, and unrelated Team servers stay unchanged.
---
Full changelog: https://github.com/btsouth/toolport/blob/v1.23.1/CHANGELOG.md
Share selected servers with your team. Publish one or more working personal servers without replacing the team's other definitions. Review the changes first, then explicitly choose whether to use the managed version in your profile. Personal originals stay saved, and credential values stay local.
Clearer Teams setup. Connection, local review and setup status make the next step easier to identify. Managed local commands show their arguments, working directory and required credentials before you enable them.
Fixed
Teams keeps working while the window is hidden. Configuration delivery and required status reporting continue while Toolport is running in the tray. Durable reporting retains successful managed-call evidence across interruptions and retries safely.
Managed calls keep their server identity. Reporting uses the shared server's stable identity rather than a normalized tool prefix, so punctuation and similar names do not silently lose attribution.
Joined Teams stay associated with the correct account. The updated Teams connection flow works with named invitations and authenticated membership discovery in the Teams portal.
Modern MCP clients work through the shared gateway. The stdio adapter sends the headers required by modern clients, preserves protocol errors, handles concurrent requests and streaming notifications, and keeps the daemon alive for active clients. Unknown tool names receive a consistent no-route response.
Local server setup preserves individual configuration. Curated launch inputs and team-specif
Download TryOmarchy.exe below, or let your installed launcher update itself. Your guest disk, files and settings carry over.
Drop files straight into apps. Drag a file from File Explorer onto a browser upload area, an editor or an image viewer in Omarchy and that app gets it. The file is also saved to Downloads. Keep the mouse still for a moment after you let go; if it moves, the file just stays in Downloads. Dropping onto a Files folder copies straight into that folder, as before.
Unlock 1Password with Windows Hello. If you've paired Windows Hello for sudo and installed 1Password in Omarchy, run sudo try-omarchy-windows-hello onepassword enable and turn on "Unlock using system authentication" in 1Password. The unlock button then asks for Windows Hello, and canceling falls back to your guest password. 1Password still asks for its account password after it restarts.
Port forwards change without a restart. Adding or removing a local forward under Settings > Advanced takes effect within a couple of seconds. LAN forwards and SSH still change at the next launch.
Older installs catch up on packages. Running Update > Omarchy now installs packages that newer Try Omarchy images depend on, so features like app drops work on installs created by older versions.
Safer Windows Hello sudo. Only this Omarchy's own VM can ask for approval, sudo from an SSH session into Omarchy uses the password, an interrupted request no longer confuses the next one, and after you cancel a prompt that terminal uses the password for 30 seconds. The p
Settings saved as UTF-8 with a byte-order mark, including files written by Windows PowerShell 5.1, now load correctly. Previously, Matteshot fell back to defaults, turning off PrtScn capture and clearing the capture shortcut in the app.
Download TryOmarchy.exe below, or let your installed launcher update itself. Your guest disk, files and settings carry over.
Windows Hello for sudo. Optional. In an Omarchy terminal, run sudo try-omarchy-windows-hello enable, enter your guest password once, and approve the Windows passkey prompt. After that, each sudo asks for Windows Hello instead of your password. The prompt only appears while the Omarchy window is in front, and canceling it falls back to your password. sudo try-omarchy-windows-hello disable turns it off and removes the passkey. Trial accounts don't use a sudo password, so this matters once you've set up your own account.
Theme switches no longer flash. Changing themes used to blank the Omarchy window for a moment and could snap a resized window back to an older size.
Dark title bar. The Omarchy window's title bar now follows your Windows light or dark setting, and changes with it.
Hold Alt to switch windows. Holding Alt and tapping Tab now keeps Alt held inside Omarchy, so window switchers that stay open while Alt is down work the way they do on a normal PC.
More reliable setup downloads. If a download link stops working after the file already finished downloading, setup now uses the finished file instead of failing.
Current Arch packages in the guest image.
Resizing the window still dims the display briefly while Omarchy adjusts. See the compatibility guide for hardware requirements and known limits.
Excel copies are less likely to show a clipboard warning or leave the first paste empty. Cubby now avoids Excel's clipboard publish gap and reads copied data through OLE.
Fast successive copies are kept when a new copy arrives just after a read finishes. Capture also resumes after a clipboard owner stops responding for 30 seconds.
Image recapture no longer overwrites the only remaining original when its destination disappears (SBS-1073).
Image pastes and ignored or duplicate images avoid an unnecessary full thumbnail decode (SBS-1077).
Matteshot is now free and open source under MIT OR Apache-2.0. The source is on GitHub.
The 14-day trial, license keys, activation, device limits and the update term are gone. Nothing in the app checks a license, contacts a license server, or stops working offline.
An install that had an ended trial or a paid license keeps working without doing anything. The old license.json and registry values are left where they were and ignored; settings, History and captures are untouched.
Usage statistics are gone. Matteshot sends no telemetry of any kind, and the consent box on the welcome screen and the checkbox in Settings are removed. A config that still has the old telemetry keys loads normally.
Share is no longer part of the official build, because there is no longer a hosted upload service. It is available to anyone who builds with --features share and runs their own server from share-server/; see docs/self-hosting-share.md.
The tray menu no longer has Buy or license entries, and Settings no longer has Deactivate or the update-term note. Its footer reads "Free and open source".
Updates still arrive automatically and are still verified against the signed release record and the Authenticode signature before they install.
Fixes and hardening since 0.20.0
The picker no longer shows "copied" until the background copy has actually landed.
A recording or an export is no longer deleted when its validation check cannot run or the final rename fails; the partial file is kept for recovery.
Pinch to zoom on a Windows 11 Precision Touchpad. It is on by default in GPU mode with one display, and -disable-pinch turns it off. Existing guests pick up the touchpad rules on their first boot of the new image; a guest whose Hyprland input.lua cannot be updated safely keeps ordinary touchpad input.
Send Ctrl+Alt+Delete to Omarchy with Ctrl+Alt+End while its window is focused. Windows reserves Ctrl+Alt+Delete for its security screen, so it cannot be passed through.
A Hyprland input.lua exported to a real Omarchy install no longer fails on the missing Try Omarchy rules file.
Update the guest to Linux 7.2.7 and systemd 262 with current Arch packages.
Android remains the supported messaging path. BlueFerry history is experimental and phone acceptance remains an explicit release gate for hardware-specific claims.
The dashboard has a new name and a reworked bar panel. Everything from 1.7 is still here. It's just arranged so the numbers you check most often are at the top.
⚡ Live Today count
The panel and dashboard now lead with how many tokens you've processed today, and the number moves while you work.
While the panel or dashboard is open, it checks your local agent histories every 15 seconds and rolls up to the new total. Counts move when an agent records usage, usually right after a response.
It only reads local history. Limits, synced ledgers and Cursor still refresh on the normal schedule.
The dashboard updates in place as new usage comes in. It no longer dims or locks the page on each refresh, so you can keep reading and scrolling while it updates. It only waits on a scan when you change the period, a filter or the source, and a fast one shows no dimming.
🕐 Hourly history
The panel shows the latest six hours. The dashboard opens on Today with hourly bars split by source, and clicking an hour shows its source totals.
Hour labels, reset times and timestamps follow the 12 or 24 hour format of your Omarchy bar clock.
Hermes reports session totals without request timestamps. Those tokens stay in the day total and are labelled separately instead of being guessed into an hour.
📌 Pinned limits
Pin up to three limits from any source and they sit together at the top of the panel and the dashboard, each with its usage and reset time. Below them, "Limits to watch" shows the fullest limit from up to three other sources.
agent-board demo --autoplay now plays the whole story in about 33 seconds, short enough for a post: an agent works and streams its answer, a waiting session gets approved, a reply is typed and answered, and the board collapses to the badge. The manual agent-board demo keeps its normal pace.
agent-board demo --autoplay records itself. Start your screen recorder, run the command, and the board plays the whole story in about a minute:
The board opens as an agent works through its tool steps and streams a reply.
It switches to a session waiting for approval and presses Approve.
It types a reply into the composer and sends it, and the agent answers.
It collapses back to the badge.
Clicks and typing go through the real buttons and composer, so it looks like someone using it. --speed 1.5 makes it shorter. Autoplay only works while a demo is running, so it can never touch real sessions.
agent-board demo puts a fictional board in the overlay so you can record or screenshot Agent Board without showing your real sessions.
An agent works through tool steps and streams a reply with code and a table.
Another session waits for an approval; approve it and that agent picks back up.
Reply to any session and the demo answers. Mentions of a PR, tests, shipping or "why" get matching answers.
New sessions, stop, mark read, settle and archive all work.
``bash agent-board demo # start; Ctrl+C to go back to your real sessions agent-board demo --speed 2 # everything twice as fast agent-board demo --stop # end a demo started in another terminal ``
While the demo runs, the overlay never falls back to your real sessions, even if it restarts. Each run starts the story from the beginning, so every take is the same.
Also fixed: a session you are watching when its reply lands now counts as read.
Right-click any session for a menu: Open, Mark read or Mark unread, Settle (T3 Code) or Archive (Hermes), Stop turn, Copy title and Copy session ID. T3 Code threads can also be archived in T3 Code from the menu, which asks for a second click because archived threads leave the board.
The menu also opens from the keyboard with the Menu key or Shift+F10 on a selected row, and arrow keys, Enter and Escape work inside it.
See the 0.2.0 notes for everything else in this line.
Start World of Warcraft in Windowed or Windowed Fullscreen mode. The badge appears when the game starts; click it or press Super+Alt+C to open the board. Existing installs can run agent-board update.
Notes
Linux with systemd user services is the tested bridge host.
T3 Code support needs Node.js 24 or newer.
Hermes streaming and Stop need the Hermes desktop backend running. Without it, replies still go out through the Hermes CLI.
T3 Code releases text a paragraph at a time by default. Set `"responseStreamingMode": "token"
Agent Board is one native WoW addon and one bridge for T3 Code and Hermes.
This preview combines the tested HermesWoW interaction model with a T3 Code provider adapter. The live desktop overlay is the primary interface; the native addon remains as a reload-based fallback. The T3 adapter attaches to the already-running T3 Code server, so it does not require a second desktop instance or a patched nightly build.
Included
One addon, AgentBoard, opened with /agents or /ag.
One bridge service, agent-board.service.
One provider-neutral action protocol for replies, new T3 sessions, approvals, declines, input answers, stops, mark-read actions, and live overlay hand-off.
Provider-labeled rows from Hermes and T3 Code in the same board.
A persistent live socket with conversation history, direct replies, approvals, input answers, stops, and new T3 sessions without a UI reload.
Game-aware overlay startup and hiding from the existing bridge service.
Guided setup, managed update, rollback, and uninstall for Linux.
An optional desktop overlay that can be focused on a selected session.
Start World of Warcraft in Windowed or Windowed Fullscreen mode. The bridge opens the Agent Board badge when the game starts; click it or press Super+Alt+C to toggle the board. The native addon fallback opens with /agents and updates on Sync.
OpenCode Go usage works again for accounts moved to OpenCode's Console workspace. The taskbar flyout also stays readable when Windows reports a light taskbar color.
Fixed
OpenCode Go usage after the Console migration. Ceiling reads the current Console usage API and uses the legacy workspace page when appropriate. Thanks to @Redbirdma.
Taskbar flyout contrast on light themes. The flyout keeps an opaque dark background with a subtle taskbar tint, so labels and meters remain readable. Fixes #468. Thanks to @jayn2u.
Full Changelog: https://github.com/btsouth/ceiling/compare/v1.5.39...v1.5.41
Toolport now uses one shared host gateway by default for registry-backed MCP clients. Lightweight stdio adapters share server connections while keeping profiles, project roots, subscriptions, approvals, and sensitive-data controls scoped to each session. The legacy setting remains available if a client needs the previous gateway behavior.
Added
Shared HTTP uses the host gateway. The desktop HTTP endpoint runs through a lightweight proxy and releases its service lease when the app closes. (#947, #948)
Gateway savings are measurable. In a local Linux run with three sessions and six configured servers, the gateway tree fell from 18 to 9 processes, direct stdio children from 12 to 4, and private memory from 1,446.1 to 621.1 MiB. Results will vary by setup. (#940, #941, #942)
Fixed
Adapters keep checking the daemon during a slow cold start instead of disconnecting after six seconds.
The in-app updater shuts down idle shared daemons and refuses installation while one is serving active sessions. Close those sessions and retry the update. (#949, #950, #952)
Managed Unix clients move off an old gateway path even if the old binary still exists.
Desktop launches with an explicit data directory leave existing AI client configs and hooks alone. (#958)
On Linux, the server list refreshes authentication status when focused, and the Authenticate action fits narrow windows. (#953)
The main window now recovers from a WebView2 crash the same way the flyout, Settings, and FloatBar already do, and every window reacts the moment its browser process fails instead of on the next open. Secrets stored through the keychain now reach Windows Credential Manager, Antigravity failures finally say what went wrong, and WSL distros with a custom mount root find their Windows-side usage again.
Fixed
The main window rebuilds itself after a WebView2 crash. It was the one window 1.5.38 could not recover, because its open paths run where building a window inline would deadlock. The rebuild now runs off-thread and replays whatever the user clicked once the new window is up. Ceiling also listens for WebView2's ProcessFailed event, so a visible window is rebuilt right away and a hidden one is torn down before it is next opened. Thanks to @diogochaves. Part of #410.
Keychain secrets are stored in Windows Credential Manager. The keyring library was built without its Windows backend, so every entry landed in an in-memory store: keychain API key lookups and the Claude credential entry never found anything, and the StepFun token cache was lost on exit. Entries now go to Credential Manager.
Antigravity failures say what actually failed. Both language server calls dropped their errors, so a signed-out server, a changed response, and a timeout all read "returned no user status and no quota summary". The panel now shows the HTTP status or the shape of the failure, and diagnose -p antigravity carries it too. The reset time a
Switch Windows playback and recording devices while Omarchy runs. Saving audio choices in Settings reroutes the running VM, and Omarchy's own audio picker lists the Windows speakers and microphones so a choice made there is saved back to Windows. Choices carry across guest reboots.
An idle VM no longer holds the Windows speaker open before anything plays.
Update the bundled runtime to the source-built r20c WINQ-EMU build. Turning microphone access on or off still takes effect at the next VM start.
WINQ-EMU r20c runtime component and corresponding source archives for the next signed Try Omarchy app release. This is not a standalone launcher or a new app version.
Built from the source-locked recipe at commit 3ae8213ce5436eb6ec551f764360f08784e19b18 in Runtime run 35931045895. SHA256SUMS covers both archives. r20c adds live SDL audio routes, so Windows playback and recording endpoints can change while the guest runs, and defers the initial playback open so an idle VM does not hold the Windows speaker. The AMD Windows 11 laptop passed a signed candidate with this runtime, including GPU desktop, live routing, reboot persistence and idle release; see the physical record.
The currently published v0.2.0 app still pins r19. The next signed app release will pin r20c.
WINQ-EMU r19 runtime component and corresponding source archives for the next signed Try Omarchy app release. This is not a standalone launcher or a new app version.
Built from the source-locked recipe at commit 751a845359c98f0d31af9d5deee9d3d31ac5497f in Runtime run 35852652612. SHA256SUMS covers both archives. The r19 patch adds WHPX free-page reclamation; the launcher enables balloon reporting only when runtime provenance includes this patch. The AMD Windows 11 laptop passed measured 4 GiB guest memory return and reuse plus a full GPU desktop boot; see the physical record.
The currently published v0.1.0 app still pins r18. A future signed app release will pin r19 after its candidate checks.
The first normal 0.x Try Omarchy for Windows release. Download TryOmarchy.exe below and run it on a 64-bit Windows 10 or 11 PC with hardware virtualization enabled. Existing preview installations retain their guest disk, files, and settings. Older launchers update through the signed v0.0.20-preview bridge before reaching this version.
Open Settings before boot, then choose Launch Omarchy. Start-menu and Desktop shortcuts can optionally launch Omarchy directly, with a separate Settings shortcut. Settings can also launch Omarchy at Windows sign-in and open it fullscreen.
A second installation preserves shortcuts owned by the first and places its own launchers beside the new installation when those Windows shortcut names are already in use.
Choose playback and microphone devices for the next boot. An unavailable saved device falls back to the Windows default.
Use Alt+Tab inside the focused Omarchy window, and Ctrl+Alt+Tab for the Windows task switcher.
Use camera and microphone access controls, the clipboard, folder sharing, file drops, snapshots, backups, recovery, and GPU rendering with automatic CPU fallback.
Hosts that support nested virtualization can run nested Linux workloads. Hosts without it continue to boot Omarchy normally.
Send a diagnostic bundle with a structured bug report when hardware or startup problems arise.
The Precision Touchpad pinch bridge is experimental and disabled by default. Graphics acceleration depends on the Windows driver; automatic CPU rendering is available when the GPU path fails. An
Anthropic started handing out banked usage resets today, the same idea ChatGPT has had for Codex. This release puts them on the Claude card, shows when any banked reset expires, and brings back the provider logos that went missing a few releases ago.
⏳ Claude banked resets
The Claude card now shows how many resets you have banked and when the next one expires, like "1 reset banked · expires Oct 22".
The count comes from the same Anthropic usage endpoint the Claude limits already use. Anthropic only returns it to a current Claude Code CLI, so the refresh sends your installed claude version. It finds the CLI on PATH or where Claude Code's installers put it.
Your token comes from Claude Code's own saved sign-in and only goes to Anthropic's usage endpoint.
Answers are cached for five minutes and rate limits are respected, so opening the panel over and over doesn't hammer the API. If a read fails, the last answer stays up for up to 30 minutes before the count goes to unknown.
The line no longer flickers when the panel opens. Omarchy's own collector briefly rewrites the Claude record without resets during a refresh, and the panel now holds the last count through that.
The reset notifier already watches Claude, so you get a desktop alert when a new reset shows up.
📅 Codex reset expiry
Codex banked resets now show their expiry date too. It comes from the credit endpoint the count already uses, so there's no extra request.
🎨 Provider logos are back
Codex Second, CommandCode, ClinePass, Ollama Cloud, OpenCode Go, Grok and Cur
Play history and local statistics, safer game stopping, durable recording, and new Nintendo DS, PlayStation 3, and PSP sources.
Play history and statistics
Open Stats for recorded play, top games, hourly patterns, streaks, achievements, and backlog habits. Export a local PNG card with the recording period clearly labelled. Imported lifetime totals stay separate. Desktop and Couch Mode are supported.
See running sessions on Home, browse older history, and delete finished sessions with confirmation. Deletion preserves imported playtime and later recorded play.
Stop one game or all attributable games. Previews explain shared Wine/Flatpak scopes; idle installations and documents open in editors are excluded. Recognize Steam Proton games whose process paths use Steam's container drive, and stop their verified prefix processes when no system wineserver is installed. Wait briefly for a forced process to exit before reporting the result.
Record supported file-picker loads on Hyprland. Optionally pause recording when the emulator loses focus, or show the current game through Discord Rich Presence.
Fix imported/recorded playtime overlap, recovery timestamps, stale title matching, Discord reconnects, and partial history deletion on storage failure.
Keep Stats totals and charts consistent across midnight, New Year and DST. Paused historical sessions use labelled timing estimates. Storage errors prevent card export.
Remember the selected Stats period, count linked installations consistently, and fit longer notes inside the exported card. Headles
Toolport 1.20.0 brings slow-start controls and Cursor ask-first approvals into the app, and makes damaged integrity stores visible without taking down unrelated Linux panels. The shared host daemon remains opt-in; this release does not change the default gateway topology.
Added
A Cursor "ask first" rule now prompts in Toolport instead of Cursor. When the guard is enforcing and a native call matches one of your ask-first rules, the question routes to Toolport's approval window (the one destructive calls use) as its own reason, naming the rule that matched, so agent prompts and tool approvals land in one place. A denial, no answer in time, or Toolport not running all refuse the call, each saying which. The Linux-native settings gained the per-agent switch for it.
Servers that need a slow cold start can set their own startup timeout. The server editor's new Startup timeout field applies to initialize for stdio, HTTP, and SSE servers, with a maximum of 24 hours, while the normal request timeout resumes afterward. Server rows also say "Initializing…" after a few seconds, so a slow first start no longer looks like a missing route. (#918)
Arch and Omarchy installs can follow the signed pacman repository. The install and update steps are now documented alongside the other download paths.
Fixed
Damaged integrity stores no longer look like missing identities or an empty quarantine. Cross-profile pin and quarantine views report unreadable, empty, or corrupt stores as unknown, naming the affected profile. A vanished pi
WINQ-EMU r18 support archives for Try Omarchy v1.0.0. These are runtime and corresponding source assets, not a standalone Try Omarchy launcher release.
Built from the source-locked recipe at commit 5b01ecfe6b068a4bc53bde2b9a95a7b9e33b3d18 in Runtime run 35794436367. SHA256SUMS covers both archives. The Windows Precision Touchpad pinch bridge in this runtime remains opt-in.
This release puts CommandCode's extra-credit balance on the card, makes model totals and route attribution add up across Muse and T3 Code, and stops the window from rescanning history every time you change a filter.
💳 CommandCode extra credits
The plan's windows were never the whole story: once its credits run out, work continues against the extra credits you bought. That wallet now shows as money on the CommandCode card and in the bar panel:
What is left comes from the billing response the plan windows are already read from, so no new request and no new key.
What it was funded with is what is left plus what this period has drawn from it, and the card says "estimated" because that part is derived.
A wallet with nothing in it stays off the card, and one left over from a plan that no longer reports windows still shows on its own.
The balance travels on the agent record, so Omarchy's built-in agents panel picks it up too, and it carries CommandCode's own name for the wallet rather than a generic label.
🧮 Totals, routing, and a quieter window
Vendor-prefixed muse-spark-* records now count with the bare Muse model in totals and filters, including the bar panel's all-route model list, while keeping their route attribution.
T3 Code's isolated provider instances are discovered and attributed: CommandCode's Codex and Claude runtimes land on the CommandCode card, FlashX is counted at its published rates, and T3 OpenCode instances for Ollama Cloud and ClinePass reach their own cards.
This is an experimental prerelease for evaluation. Stable v0.1.0 release gates remain open, including the seven-day soak and packaged installation, uninstall, and reboot tests across supported platforms.
Installers may be unsigned. Windows may show an unknown-publisher warning, and macOS builds may lack Developer ID signing and notarization. Do not disable platform security controls to install these builds. Use a source build if your platform rejects an installer. SHA-256 checksum files accompany the artifacts.
Signed automatic updates are not a supported distribution path for this alpha. Build-time updater hooks exist, but published update metadata and end-to-end signature verification remain release gates. See docs/release.md for details.
The Windows MSI uses numeric installer version 0.0.4 for this alpha; the application reports 0.1.0-alpha.4. This keeps the installer version below the eventual stable 0.1.0 upgrade.
Alpha.2 fixes the desktop startup panic when updater configuration is absent. The release workflow now launches the packaged Linux desktop and requires a visible window plus a healthy daemon started through frontend IPC.
On the tested Omarchy/Arch machine with newer NVIDIA drivers, the AppImage also requires the system Wayland client library to avoid a bundled-library/EGL conflict:
This per-launch workaround changes no system files. It was verified locally with the published AppImage; other Linux distributions can use different library
This is an experimental prerelease for evaluation. Stable v0.1.0 release gates remain open, including the seven-day soak and packaged installation, uninstall, and reboot tests across supported platforms.
Installers may be unsigned. Windows may show an unknown-publisher warning, and macOS builds may lack Developer ID signing and notarization. Do not disable platform security controls to install these builds. Use a source build if your platform rejects an installer. SHA-256 checksum files accompany the artifacts.
Signed automatic updates are not a supported distribution path for this alpha. Build-time updater hooks exist, but published update metadata and end-to-end signature verification remain release gates. See docs/release.md for details.
The Windows MSI uses numeric installer version 0.0.3 for this alpha; the application reports 0.1.0-alpha.3. This keeps the installer version below the eventual stable 0.1.0 upgrade.
Alpha.2 fixes the desktop startup panic when updater configuration is absent. The release workflow now launches the packaged Linux desktop and requires a visible window plus a healthy daemon started through frontend IPC.
On the tested Omarchy/Arch machine with newer NVIDIA drivers, the AppImage also requires the system Wayland client library to avoid a bundled-library/EGL conflict:
This per-launch workaround changes no system files. It was verified locally with the published AppImage; other Linux distributions can use different library
This is an experimental prerelease for evaluation. Stable v0.1.0 release gates remain open, including the seven-day soak and packaged installation, uninstall, and reboot tests across supported platforms.
Installers may be unsigned. Windows may show an unknown-publisher warning, and macOS builds may lack Developer ID signing and notarization. Do not disable platform security controls to install these builds. Use a source build if your platform rejects an installer. SHA-256 checksum files accompany the artifacts.
Signed automatic updates are not a supported distribution path for this alpha. Build-time updater hooks exist, but published update metadata and end-to-end signature verification remain release gates. See docs/release.md for details.
The Windows MSI uses numeric installer version 0.0.2 for this alpha; the application reports 0.1.0-alpha.2. This keeps the installer version below the eventual stable 0.1.0 upgrade.
Alpha.2 fixes the updater initialization crash in unsigned desktop builds. Packaged desktop startup passed on Ubuntu CI.
On the tested Omarchy/Arch machine with newer NVIDIA drivers, use the system Wayland client library to avoid the bundled-library/EGL conflict (verified locally):
> Desktop startup issue: This version can panic while initializing the updater. Use v0.1.0-alpha.2, which fixes that bug and adds a packaged desktop startup check.
This is an experimental prerelease for evaluation. Stable v0.1.0 release gates remain open, including the seven-day soak and packaged installation, uninstall, and reboot tests across supported platforms.
Installers may be unsigned. Windows may show an unknown-publisher warning, and macOS builds may lack Developer ID signing and notarization. Do not disable platform security controls to install these builds. Use a source build if your platform rejects an installer. SHA-256 checksum files accompany the artifacts.
Signed automatic updates are not a supported distribution path for this alpha. Build-time updater hooks exist, but published update metadata and end-to-end signature verification remain release gates. See docs/release.md for details.
The Windows MSI uses numeric installer version 0.0.1 for this alpha; the application reports 0.1.0-alpha.1. This keeps the installer version below the eventual stable 0.1.0 upgrade.
One core for both clients, and an account you can keep your practice in.
The desktop app and the browser now run the same typing, content and history code, generated from one source. A score means the same thing in both, and a history backup moves between them.
Keep practice history on your profile: opt-in from the History page, one press, scores only. No prompts, no keystrokes, and your device keeps all of its runs while the account keeps the newest 500.
History is one page with three labelled sources: this device, your account, and your challenge results.
The site installs like an app and works offline, and a completed run is saved locally with no network.
Small text is legible again. The game was drawing its labels at 4.40:1 against its own background, and now goes through the same contrast correction the result card always used. Three of the six themes were affected.
A run can be chosen, set up, played and finished with the keyboard alone.
Under the surface: history paging no longer repeats a row at a page boundary, every internal link resolves, and the public routes and share pages are audited for contrast, control names and heading order on every change.
A launcher's Exec line is read as an argument list, so the three forms Omarchy has written parse: a bare URL, a bare URL followed by browser flags, and the quoted URL the current installer writes. A quoted launcher, and one carrying a Chromium profile flag, used to be captured and then refused on the machine that needed them — and the launchers Omarchy ships were captured in their place, so the category travelled the wrong set in both directions.
A launcher byte-identical to one in /usr/share/omarchy/applications is not captured: it is not this machine's state, and a fresh install has it already.
Browser flags and the omarchy-launch-or-focus-webapp form travel through the installer's custom-exec argument, assembled from validated pieces rather than copied out of the vault. A launcher whose second word is a command is refused.
An Exec line longer than a launcher could need (1024 bytes) is refused unread, so a fetched vault cannot buy a stall with one.
A launcher a restore cannot rebuild is named at capture, listed as refused by ress verify, and left out of a shared loadout rather than published.
Status
ress status --json no longer exits 2 with no output when a setting holds a value it does not expect (INCLUDE_OMARCHY=, AUTO_INTERVAL_HOURS=24h), when the last-backup stamp is not a number, or when a vault's manifest is not JSON. The panel reads nothing but this command, so a blank panel was the visible symptom.
Plugins and themes
A remote a restore will not clone — a file:// URL, a bare local
Version 1.5 brings practice and challenge results together in one History page, and makes local history harder to lose.
One History page for practice and challenge results, with progress, practice time, and frequent mistypes shown without digging through settings.
Reopen saved passages and review a challenge result privately before sharing it.
Keep older runs: history paginates, and the browser keeps its original archive until you clear it, so a migration can be undone.
Import a backup without duplicates, and get your original data back when an import fails.
Sharper result flow: the practice editor opens when you start a new custom practice, controls wait for the game to be interactive before they accept clicks, and the duration buttons fit again.
The desktop app cannot lose history on upgrade: installing keeps a snapshot of everything it touches and restores it if anything fails.
ds-router keeps Hermes pointed at a provider with quota. It reads four providers' usage APIs, updates Hermes' default provider, and can spread existing sessions across providers with declared concurrency caps.
Runs locally. No proxy or per-request routing.
This first tagged release includes credential-safe HTTP handling, serialized config changes, safer session placement, and reversible installation scripts.
Validation: 242 tests across 10 suites, plus Ubuntu/macOS CI on Python 3.10 and 3.12. Live macOS launchd execution remains unverified. See release validation for the exact limits.
Start with the README. Linux installation enables the timer; use --no-service for manual routing.
This release adds Cursor — cloud usage events and a billing-cycle quota meter — and fixes the installer's built-in-widget check, which could only pass on the machine it was written on.
🟣 Cursor
Cursor is the first source here that cannot be rebuilt from local files, so it is read from Cursor's own usage events, per model:
Token history — every event's input, output, and cache-read tokens, priced at list price
A billing-cycle quota meter with its reset date, read through the session the Cursor desktop app already stores locally
Free events still count — an event that carries no tokens is kept as a turn rather than dropped as empty
The session token is read from Cursor's local store and is never copied, logged, or sent anywhere but Cursor. The endpoint is undocumented and can move without notice; when a call fails, the previous snapshot stays in place with its error and nothing else in the dashboard is affected.
Event costs are list prices and plan discounts are not applied per event, so the quota card's billed total is the figure to trust where the two disagree.
Cursor support arrived as a community pull request from @hilather — the collector, the paginated walk with resume, the quota mapping, the pricing, and the tests are his work. Thank you.
🛠 Also in this release
The installer's built-in-widget check read /usr/share/omarchy directly — a path that exists on a development machine and nowhere else — so it passed locally and went red the moment it ran anywhere else. It now follows the OMARCHY_PATH conve
One-command setup for the Hermes WoW bridge on Linux.
Finds your game and Hermes installation, installs the addon, and verifies the first snapshot.
Starts the bridge automatically at login, with no terminal left open.
Adds status, update and uninstall commands. Failed updates restore the previous installation.
Improves first-run instructions and snapshot recovery guidance.
Requires an existing Hermes installation and Linux with a systemd user session, Python 3.10+, Git and curl. The addon ZIP alone does not provide the bridge.
Live setup, uninstall and reinstall passed on Linux. Offline gates cover update rollback and duplicate watchers. This remains a Classic beta preview for interface 16001; in-game controls and other clients are unverified.
Hermes agents in Azeroth: see what needs you, reply, and manage sessions from a native WoW board.
Clickable sync toasts for new attention and completed work.
First-run setup card and a visible Sync button.
Mark read without changing Hermes's database. New activity resurfaces the session.
Clickable session links in chat.
Stop a local desktop-backend turn at sync. It targets the turn active when delivered and clears queued prompts and approvals.
Fixes for late CLI failures, corrupt dispatch state, notifications, and panel layout.
Requires a local Hermes installation and the Python bridge. The addon zip alone is not enough. Update both halves together for payload schema 3.
This is a preview release for the tested Classic beta client, interface 16001. Offline gates and rendered previews pass; the new controls still need an in-game check. Other client builds and bridge operating systems are unverified.
This release makes the packaged widget the only widget — and the complete one — adds reset notifications, and counts work done through the Command Code CLI.
🔀 The widget merge
The widget that ships with the dashboard now includes everything a private, customized clone held — rebuilt as settings anyone can set from the widget's bar.layout entry in shell.json:
providerOrder — walk the bar and panel in your order. Unlisted providers follow alphabetically, so a new provider never drops off the end.
launchCommands — right-click a provider to launch its own CLI in a terminal; unmapped providers fall back to Omarchy's agent picker.
extraProviders — write an upstream-format record into the usage directory and the widget shows it. Bring your own collector; the record is the whole contract.
alwaysShow — keep a provider on the bar before it has numbers.
Fireworks is back (off by default; enable it in Settings).
The installer now names any other installed model-usage widget it finds — including Omarchy's built-in Agents widget — so a second AI icon never appears by surprise.
🔔 Reset notifications
A desktop notification when a weekly or monthly limit resets, or when banked reset credits arrive (the way Codex delivers dropped resets) — with the provider's own mark on the popup.
Short (session) windows never notify
Codex and Claude are watched by default; more via --provider, never by silent opt-in
Overlapping refreshes serialize on a lock file, so a reset notifies exactly once
Camera, microphone and file-drop improvements for Windows x64.
Use the Windows camera and microphone in guest apps. Camera capture starts on demand and stops when the app closes it.
Drop Windows files into an open local Files folder without a transfer window taking over. Other destinations use Downloads with a notification. Duplicate names keep both files.
Existing guests receive matching camera and TUN modules automatically. Interrupted module delivery retries on the next boot.
Recover from orphaned package-manager locks after interrupted updates, without removing locks owned by a running transaction.
Pause the guest during Windows sleep and resume it on wake with clock synchronization.
Existing installations keep their disk, files and settings. Use Update > Omarchy inside the guest for the full system package update.
This remains a preview. Windows sleep/wake recovery has not been verified on physical hardware. Direct drops into arbitrary applications, portable-drive lifecycle, native migration and broader Windows/GPU coverage remain unfinished. Accelerated RAM resume and Windows ARM64 are not supported.
Thanks to everyone testing and reporting issues, and to the Omarchy, WINQ-EMU, QEMU and Mesa communities.
CommandCode usage: plan windows read from an API key you supply, with the resets it publishes. Its allowance is measured in credit value rather than tokens (the $10 GOAT plan allows $14 in any 5 hours, $35 in any 7 days, and $70 a month), and each window reports its own spend, cap, and reset time, so these meters carry a countdown where the other providers cannot. Add the key under Settings, or export COMMANDCODE_API_KEY, or drop it in ~/.config/omarchy/ai-usage/commandcode.key. The key is never written back, never leaves the request it authenticates, and never appears in anything the dashboard renders.
Count CommandCode token history through the same agent ledger as OpenCode Go and Ollama Cloud. Its two profiles for one account, one OpenAI-shaped and one Anthropic-shaped, collapse onto one card, with the raw route kept in the Routes breakdown so nothing is double counted.
CommandCode model rates, transcribed from the rates it publishes rather than the labs' list prices, since it bills against its own resale table. Includes its peak window that doubles the DeepSeek rates on weekday early mornings. Models that are free while capacity lasts price at zero instead of reading as unpriced.
Keep the provider tabs on one row: the chips now share the width evenly and keep their own text width, so four or five providers sit on one line instead of wrapping, with more room on both sides.
Ollama Cloud usage: local token history alongside the plan's usage limits, read from an API key you supply. Add it under Settings, or export OLLAMA_API_KEY, or drop a key in ~/.config/omarchy/ai-usage/ollama.key. The key is never written back, never leaves the request it authenticates, and never appears in anything the dashboard renders.
Ollama Cloud model rates, including the published peak window that doubles the DeepSeek rates on weekday afternoons.
Count your agent's own OpenCode Go and Ollama Cloud spending. Running those routes through Hermes used to hide that usage; both are now included, and they reconcile to the agent's own ledger exactly.
Split agent-sourced usage by what it was for: typed prompts, title generation, context compression, vision, approvals, and background review.
Treat a Hermes home as an account source folder, so it can be labelled per account or imported from another machine.
Show up to four model rows on each overview card, from local token totals. Providers whose usage endpoint reports one aggregate number cannot supply per-model shares, so the local figures are the honest view there.
Fix the bar widget's scrollbar so it no longer draws over the text, and give the provider chips room to fit their labels.
Xenia (Xbox 360) support and a TV setup for the couch.
Xbox 360 games from Xenia Canary: discovery from Xenia's recent-games list and storage root, save backup, playtime recording, and launching through the xenia_canary binary. Thanks to @Salt-555 for the Xenia source work.
Xbox 360 titles identified with IGDB and shown under their own console card, including names Xenia writes with trademark marks.
Xenia pinned to X11 on Wayland, where its window otherwise stayed grey while audio kept playing.
An optional TV gaming agent skill with a Gamescope launcher that checks the TV output, workspace, and audio sink before starting a game. It stays inert unless you install it. Thanks to @LucasOl1337 for the guide and helper.
Notification sources setting: comma-separated app names or Android packages, defaulting to messaging and authenticator apps, matched anywhere in either; clear it to allow everything.
Notification popups setting: keep matching notifications listed in the panel without desktop popups.
Media controls setting: hide the phone's now-playing section entirely.
Skip notifications the phone re-sends flagged silent after a reconnect, so old messages do not pop up again.
Ask the phone for its thread list on every listing so messages sent on the phone appear without waiting for a push.
Reap orphaned dbus-monitor watchers left behind by a killed watcher.
Now-playing media controls in the panel: track, artist, album art, play/pause, previous/next, seek, and volume.
Toolport 1.19.0 lets one shared gateway serve clients with different discovery modes at the same time, stops an over-long routine name from breaking every request from a prefixing client, and fixes a placeholder guard that refused real HTML and template values. It also carries cross-process rate-limit backoff for busy hosts and two dependency security updates.
Added
The shared HTTP gateway can pick a discovery mode per client. One bridge process previously resolved a single mode at startup and applied it to every client, so it could serve a native-tool-search client the full catalog or a local model the compact meta-tools, but not both. It now honors clientDiscovery[<http-client-id>] for the client its bearer token resolves to: set full for Claude Code or Codex and lazy for Open WebUI in the same process. Only full and lazy are per-client; grouped stays process-wide, and a client without an entry inherits the process mode. (#868)
Fixed
Two server ids that differ only by - and _ could become one server. The gateway rewrites ids to the tool-name charset for exposed names, and that rewrite also keyed client scope, PII pseudonym origins, injection block exemptions and result budgets, so a local server named "Team Acme CRM" and a synced team server team_acme-crm, or a hand-edited gh_api beside a new gh-api, shared scope and exemptions. New ids, local or team-synced, are now kept distinct under that rewrite the same way an exact duplicate is renamed.
**The OpenAPI endpoint answered failed tool calls with H
Synced machine ledgers: point every machine at one shared folder and each imports the others' snapshots, so totals, charts, and model breakdowns cover all of them.
Show synced machines in the data coverage card, and warn once per broken snapshot instead of every scan.
Fix release pinning in the one-line installer: tags download correctly, not only branches.
First public release of the AI Usage Dashboard for Omarchy.
Named history accounts with multiple folders, account comparisons, and filters.
Deduplicate mirrored history and flag conflicting account assignments.
API-value shares and tokens/value per recorded session.
Grok Build history, recorded API value, model calls, and weekly quota.
Gemini CLI, general OpenCode, Pi, and Oh My Pi history, with source-route breakdowns.
Detect active sources on first use and adapt layouts to the enabled providers.
Refresh Grok quota after login and request fresh limits on manual Refresh.
Reopen unmapped dashboard windows and focus the correct instance across workspaces.
Keep provider colors readable on light and dark backgrounds.
Wrap bar-widget provider chips when many sources are enabled.
One overview card per account, with optional monthly prices per provider or labelled account.
Daily and hourly charts split into one series per account when a provider has more than one, each in its own shade of the provider color, largest solid and the others dashed.
Labelled accounts read their own agent usage record by matching id or name, so a second Codex account shows its quota beside the current login.
OpenCode Go prices the full documented model table, doubles DeepSeek rates during peak hours, and falls back to OpenCode's recorded cost for unlisted models.
The Go card shows value used against each model's monthly allowance, including the DeepSeek V4.1 Flash 4x promo through Sep 20.
Price Codex gpt-5.3-codex-spark and mark codex-auto-review internal, clearing t
A reliability preview. Download TryOmarchy.exe below and run it on Windows x64. Existing installations keep their guest disk, files, and settings. The launcher updates its guest integration automatically; use Update > Omarchy inside the guest for the full system package update.
What's new
Lighter portable copies. Creating a portable copy, or copying an existing portable installation, now writes an independently verified QCOW2 disk directly instead of staging a full backup and raw restore. Moves and snapshots also retry transient Windows file locks.
Clean guest package ownership. The guest runtime package no longer claims the two Neovim helper commands owned by the editor package. Existing guests keep both helpers, including administrator edits, and the package database reports no duplicate ownership.
Restored Neovim theming. New accounts get the packaged Neovim theme link again, and existing guests receive it when the launcher integration updates. Neovim follows the active Omarchy theme, and omarchy-nvim reports no missing files.
Validation and remaining preview limitations
Automated launcher, guest, and factory-image checks pass on the pinned candidate. The guest update path was exercised end to end on the checksum-verified v0.0.18-preview image, including the five-boot preservation run and the new compatibility-revision delivery, and the physical Windows draft test verifies preserved data, the new kernel boot, reboot and poweroff, rollback, and the one-time compatibility repair before publication.
Codex usage keeps reading correctly through OpenAI's latest response changes, and the Antigravity CLI is recognized when Windows cannot read its process command line. A Windows rendering failure also gets a recovery path: the flyout, Settings, and FloatBar windows rebuild themselves after their WebView2 process exits instead of staying blank, and the taskbar flyout no longer leaves a strip of desktop showing under its last row.
Fixed
The flyout, Settings, and FloatBar rebuild themselves after a WebView2 crash. Windows keeps a Tauri window's frame after the WebView2 browser and render processes exit, but the client area then paints nothing, and because these windows are hidden rather than closed the dead frame was reused on every open. Each window now checks for a live render host before opening and destroys the dead frame so a fresh one is built. Fixes the blank frame for those windows in #410; the main window needs an async rebuild path and remains open.
Codex usage keeps reading through OpenAI's latest response changes. The usage endpoint renamed and moved several fields, and the old parser silently dropped them: a quoted credit balance never rendered, the spend limit under spend_control.individual_limit and the top-level code-review meter were ignored, and Spark's weekly window was discarded. Those are read again, Spark is matched by its new codex_bengalfox meter, and numeric fields that arrive as strings still parse. Fixes #441.
The Antigravity CLI is detected even when Windows cannot read its command line. Th
Lossless rotate and flip. A JPEG rotated or flipped with no crop or resize is written without recompressing the pixels (through jpegtran where available), so a turn no longer costs quality; every other correction recompresses as before. An image with an EXIF orientation tag still takes the recompressing path, which bakes the tag in.
Crop aspect presets. The correction editor holds the crop to Free, Original, 1:1, 4:3, 3:2 or 16:9 while the frame is dragged, snapping to the largest centred rectangle of that ratio when the preset is chosen.
Straighten. A fine ±15° level control in the correction editor, scaled to fill the frame so no empty corners show, applied before the crop.
Correct a selection. Rotate, flip or resize several selected pictures at once (B), each written as its own copy with the existing collision handling.
PDF continuous scroll. Pages scroll at the window width by default, with a Fit page mode for reading a whole page with zoom and pan.
Print. A Print action for pictures and PDFs hands the file to the system print path (CUPS), and is greyed out with an install hint when it is absent.
Undo organization marks. Ctrl+Z steps back through favourites, hidden flags, ratings and captions, one action at a time.
Subtitle timing. Sidecar subtitles can be nudged earlier or later by half a second to fix a track that is out of sync.
Slideshow options. The slideshow interval is configurable (2 to 20 seconds) and a shuffle mode picks a random picture instead of the next in order.
Crop, rotate, flip and resize a picture as a copy. The viewer's action list gains Crop, rotate, resize (Q): a live preview with a draggable crop frame, quarter turns and flips, and an optional output size. The original is never modified; the copy is written beside it as <name>-edited.<ext>, numbered on repeat. EXIF orientation is baked in, the ICC profile is kept, and collision or write failures leave the original untouched.
Rename an album or a tag without losing its membership. Renaming a tag also renames every tag nested under it (Travel/Japan follows Travel). A name that clashes with an existing collection is refused.
Compare pictures side by side with synchronized zoom and pan (K). It uses the checked selection, or the open picture's exact duplicates and then its visually similar set, and shows each file's name.
Remember video playback. Volume and mute are kept across files and sessions, and a video reopened part-way through offers Resume or Start over instead of always starting from the beginning. Watching to the end clears the spot.
External subtitles. A .srt or .vtt beside a video is offered alongside any embedded tracks, labelled by its language tag (movie.en.srt shows as English), and drawn over the video as playback reaches each cue.
Find text in a PDF. The viewer's PDF controls gain a search box; each match is a page you can step through, with a count, and the page turns as you move between matches.
Copy a PDF page's text to the clipboard, and jump straight to a page by typing its number in the PDF c
Add an optional ProtonDB tier badge on library cards, off by default. Turn on both community reports and card badges in Settings to see the tier beside playtime and rating. Fixes #39.
A larger Windows preview with better file sharing, recovery tools, and graphics reliability. This is the recommended upgrade from v0.0.14-preview, the previous public release; it includes the changes developed in the unpublished v0.0.15�17 candidates.
Download TryOmarchy.exe below and run it on Windows x64. Existing installations keep their guest disk, files, and settings. The launcher updates its guest integration automatically; use Update > Omarchy inside the guest for the full system package update.
What's new
Copy files and folders between Windows and Omarchy. Clipboard transfers preserve originals, and dedicated transfer windows support native Windows drag and drop and larger transfers.
Snapshots and recovery. Create snapshots, restore a separate copy, or roll back an installation with disk verification and recovery data retained if something interrupts the operation.
Move your installation from Settings. Verified copying, cancellation, interrupted-move recovery, and shortcuts that follow the new location make moving to another drive easier.
More accessible Settings. Adjust guest resources, disk capacity, rendering, displays, and sharing. Settings remain usable on smaller screens, and disk reclaim now has tray access and progress reporting.
Better configuration migration. Native monitor settings and the Omarchy runtime location survive restoration. Incomplete package or theme restoration is reported, and repeated restores retain separate backups.
This patch fixes RomM catalog refresh for large libraries.
Ask RomM to omit the result-set index and filter data it repeats on every page by default, which is what pushed large catalogs past the response limit.
Raise the whole-refresh total while keeping each page bounded in memory, so libraries with tens of thousands of entries finish loading. A failed refresh still keeps the existing offline catalog.
Omakade 1.9 adds RomM libraries, per-game launch setup, emulator save protection, and tools for fixing your library.
New features
RomM libraries: connect your server, launch locally mounted games, and browse the cached catalog offline. Credentials are stored securely; Omakade does not modify your server.
Launch setup: choose an emulator or core for each installation, inspect launch diagnostics, and repair missing paths.
Save protection: back up supported emulator saves before launch, restore or undo changes, and manage custom layouts, retention, and cleanup. Shared memory cards include warnings before restoring.
Library repair: work through missing artwork, identification problems, and unavailable installations with saved filters, selected retries, and separate identity and artwork undo.
Game details: view play history and optional ProtonDB community reports. Library cards keep their compact two-line layout.
Fixes
Improve ROM identification and artwork recovery while preserving manual choices and editions.
Fix cached cover loading loops and refresh backup lists after automatic capture.
Keep archive launches on compatible RetroArch setups and explain missing archives, cores, or runtimes.
Skip GOG DLC-only manifests so they do not block game discovery.
Recognize Cemu .wua games in session recording.
Thanks
Thanks to @gotar for reporting the GOG DLC scanning bug and @ksavery for suggesting ProtonDB integration. Thanks to everyone contributing reports, ideas, and testing.
Omakade 1.8 adds a Home screen, an Up Next queue, and more ways to browse your library.
Find games by genre, decade, or platform, with richer descriptions, credits, and regional release dates.
Choose identities and artwork in one panel, with better protection for existing covers.
Get smoother controller navigation, clearer launch feedback, and reliable focus when returning from details.
Optionally record emulator sessions and see imported and recorded playtime separately.
Include game identity choices, play history, and preferences in personal backups.
Keep ROM Folders visible on the Sources overview.
Session recording requires a recognizable game path in the emulator command line. Paused emulator time counts; internal game changes and some wrappers are not covered. Personal backups do not include emulator saves.
Packages are available for x86_64 and ARM64. Both passed automated build, test, and package lifecycle checks. ARM64 has not been tested on physical hardware.
Omakade 1.7 brings console libraries, more ways to organize your games, and a reworked controller keyboard.
Console libraries
Discover Dolphin, Cemu, and shadPS4 games alongside existing sources. Launch Dreamcast games through Flycast and scan ROM folders and EmuDeck layouts.
Browse console cards or individual games, pin games outside their console card, and choose a layout for each system.
Read titles and icons from supported Switch dumps using locally installed keys, and artwork from Wii U archives. Filter out Switch updates and DLC.
Artwork and settings
Identify games with IGDB, display ratings, and sort by rating or popularity. Matching handles common region, revision, and translation tags in ROM names.
Add optional SteamGridDB portrait covers, or choose your own cover, hero, and logo images. Each artwork slot can be reset separately.
Browse settings by Sources, Library, Connections, Controls & streaming, and About & storage. Adjust desktop and couch cover sizes independently.
Organization and backups
Add native games and desktop entries with custom arguments and a working directory. Removing an entry leaves its game files alone.
Choose a preferred installation for linked games and add extra GOG folders.
Bulk-edit games, save named filters, and pick a random game from your results.
Export personal library settings and artwork to a local backup. Preview, merge, or replace data, with recovery and undo for interrupted restores.
Preserve console pins and favorite/hidden choices for the new emulator sources in backups
v0.0.14-preview follows v0.0.13-preview from earlier today. It ships a rebuilt guest image (integration revision 12) and a launcher fix worth not waiting for.
Fixed
Choosing Suspend inside Omarchy no longer freezes the VM window. The guest can no longer enter the S3 or S4 sleep states, and new guests have Omarchy's suspend-off toggle on so the system menu does not offer it.
A runtime archive that is unchanged between releases is kept instead of being downloaded and unpacked again.
New
The guest follows the Windows display language, alongside the time zone and keyboard layout it already follows. The locale is generated inside Omarchy and takes effect at the next login. -locale overrides it.
Existing guests catch up with the image defaults on the first boot after an image update, without touching anything you changed: an untouched monitors.lua gets the current profile, the toggles an older image switched on by mistake are removed, and Suspend leaves the system menu.
New guest images include the Noto CJK fonts.
File drag and drop and file clipboard transfers are not included yet. Use Omarchy Shared for files.
Star ratings. Rate a file from the viewer or with Alt+1 to Alt+5, sort by Top rated, and narrow any view to a minimum rating from Browse. Saved views keep the choice.
Captions. Add a short caption in the viewer; it shows on the tile and is searched with filenames and picture text.
Nested tags. A tag named Travel/Japan sits under Travel in Browse, and choosing the parent shows everything beneath it.
Browse a photo library by camera and lens. The metadata pass that reads capture dates now records the camera and lens too, and saved views keep the choice. Libraries without camera photos do not show the section.
Tab and Shift+Tab step through the sections, wrapping at either end.
Changed
A video that plays to its end rewinds to its first frame and pauses there instead of leaving a blank stage.
Launch, manage, and install Steam games through the Steam client itself, native first and then Flatpak, and only fall back to the desktop steam:// URL handler when neither is available. Steam packages that register no handler sent Play to the web browser. Thanks @radiohost-cloud for the report and the Apple Silicon test.
Stop matching the Omakade desktop entry when searching for "Steam" or "RetroArch" in the app launcher. Thanks @gmickel for the report.
Remember the library sort order between launches.
Show every game's cover at the same compact size on the details screen instead of letting portrait covers render larger than landscape ones.
Share QML role-name definitions across nine game models without changing their role IDs, names, or behavior.
v0.0.13-preview follows v0.0.12-preview. It ships a rebuilt guest image (integration revision 9) and a launcher that adapts to the machine it runs on. Existing guest disks keep their data and gain the new guest services on the next launch.
New
Images cross the clipboard in both directions: a screenshot copied in Windows pastes into Omarchy, and an image copied in Omarchy pastes into Windows apps. Text keeps working as before.
The guest follows the Windows time zone and default keyboard layout, and a small guest agent keeps the Omarchy clock in step with Windows, including after sleep. A layout or zone chosen inside Omarchy stays until Windows changes.
Automatic rendering remembers when this PC cannot run the GPU path and goes straight to CPU rendering on later launches, retrying daily or after a runtime or driver change. A new Rendering setting (Automatic, GPU, CPU) overrides it. New guests on CPU rendering start with animations off; existing guests keep their current setting.
Guest CPUs are sized to the machine (all logical processors but two, between two and eight) with a Guest CPUs setting and -cpus. CPU rendering also gets a larger automatic RAM ceiling; GPU rendering keeps its 6 GiB.
The VM window remembers its size and position between launches.
Try Omarchy registers under Windows Apps & features and can be removed from there, from Remove Try Omarchy in Settings, or with -uninstall, with a full backup offered first.
TryOmarchy.exe -reclaim gives the space of deleted Omarchy files back to Windows after the next shutdown, within a budget th
Open multiple selected files in order, including across folders and in an already-running window. Explicitly selected hidden files open without scanning their surrounding folders.
Opt-in startup readiness tracing and a reproducible startup benchmark.
Changed
Video setup is deferred until a video is opened, reducing startup work for images and the library.
Numbered filenames sort naturally, so image2 appears before image10.
Copying extracted text is confirmed visually and through accessibility announcements.
Real video rendering checks run under Mesa OpenGL in CI and release validation, and automated playback stays off physical audio devices, including native PipeWire.
Fixed
Thumbnail, PDF and matte image responses no longer risk a crash when a request is cancelled or finishes during fast scrolling or a tile size change.
Tiles no longer keep a previous file's thumbnail after the window or tile size changes, which could open a different file than the one shown.
v0.0.12-preview replaces v0.0.11-preview. It ships a rebuilt guest payload with Linux 7.2.3 and current Arch packages. Existing guest disks keep their data and receive the updated clipboard bridge on the next launch.
New
Backup, restore, and reset controls in Settings for stopped standard installs, plus -backup and -restore on the command line. Backups cover the guest disk, boot files, bundled runtime, and settings, and every file is checksum-verified on restore. Restore creates a separate installation with its own shortcuts and never replaces an existing one.
Reset offers a full backup first, prepares the new disk before moving the old one, and keeps the previous disk in a recovery folder
Disk capacity setting for standard installs with in-place growth and Windows free-space information. Lowering the setting never shrinks an existing disk.
First-run choice between Local AppData and another local drive or folder, remembered across launches and shortcuts
Windows folder pickers for install locations and shared folders, and an optional repair when preferences are unreadable
Stable-release update support with a bridge for older preview launchers
Official Omarchy mark in the app icon, setup splash, and VM window
Fixed
Clipboard sharing after reconnects and when copying an earlier value again; trailing newlines are kept, failed sends retry, and overlapping transfers no longer suppress a later copy
Interrupted setup reuses a completed download after a server outage or an ignored resume request, verified before use
Create a challenge, send a friend the link, and race. Typearchy 1.4 makes sharing easier and gives you more control over your account and practice history.
Share challenges right away. Friends can race your custom passages before they appear in the public library, with shared results and standings.
Connect your browser from the app. Link a browser without entering your recovery code, or replace a lost code without disconnecting your devices.
Keep your practice history. Export and import runs from the app without creating duplicates.
Make sense of your results. Clearer labels show which runs are saved locally, shared, or paused, and explain how your personal bests compare.
Get clearer feedback. Better messages explain connection problems, unsuccessful submissions, available updates, and when guest results expire.
Challenges now show unfinished progress accurately, with visible Enter markers and incorrect spaces. You can erase back to the first mistake without restarting.
Tab keeps your typing focus; Escape releases it in the browser. The finish timer stays frozen, and restarting an unsaved result asks before discarding it.
Verified with a full Rails challenge using real browser keyboard input and server validation.
Challenge search and language filters now apply automatically. The extra button is gone, and the language selector is aligned and centered.
Browse, search, organize, and launch games with a controller in the new Detail and Grid views. Switch with F11 or controller Start, or launch with omakade --couch.
On-screen keyboard, controller-friendly settings, and clearer selection.
Selection stays put when switching views.
Launched games keep controller focus. The cursor hides during controller use and returns when you move the mouse.
GOG and Battle.net
Direct GOG discovery and launching: native Linux games run directly; Windows game builds run on Linux through UMU. Heroic-managed games keep their existing launch settings.
GOG rescans remove uninstalled games and keep cached entries when Heroic’s inventory cannot be read.
Fixed Omarchy Battle.net prefixes being detected as Wine instead of Proton. Rescan your library after upgrading to correct cached entries. Thanks @TheAirick for the report.
Downloads
Packages are available for x86_64 and aarch64, with checksums, SBOMs, and provenance.
Both architectures passed automated build, package, launch, and lifecycle tests. ARM64 still needs testing on an Omarchy device; additional real-library compatibility reports are welcome.
Image previews now include actual-size viewing, horizontal and vertical flips, a checkerboard behind transparency, zoom up to 64 times the fitted size, and Space to pause animated GIF and WebP files.
Video playback now includes standard Space, mute, volume, seek, speed, audio track, and subtitle controls. Double-clicking the video toggles fullscreen.
SVG, icons, JPEG 2000, JXL, QOI, PSD, DDS, EXR, and TGA images can be scanned and opened directly when the packaged image plugins are installed.
Changed
Videos start with sound, play once, and preserve an intentional pause when the window is minimized and restored.
Fixed
Browse stays fully visible at the minimum window width.
Closed matte previews no longer reload their previous file when the window changes size.
Opening a PDF directly from a file manager no longer rejects it as an unsupported media file.
Space in a video preview now pauses or resumes playback instead of launching the configured video action.
Added optional RetroAchievements support for RetroArch games, including compatible ROM hashing, achievement progress, unlock details, rarity, and account-aware caching.
Kept network, hashing, and database work off the interface thread and handled sign-out, stale data, unsupported systems, and malformed responses safely.
Battle.net
Added Battle.net as a library source. Omakade finds the Windows Battle.net client in Wine, Proton, and Bottles prefixes, imports installed games from product.db, and launches them through Battle.net.
Downloads missing Battle.net covers and banners from Lutris's public artwork hosts, including Heroes of the Storm.
PCSX2 and Ryujinx
Added PCSX2 as a game source: imports disc-based games from the current gamelist cache (v34) for native and Flatpak installs, with cover art, playtime, last-played, and region metadata, and delegated launching through the owning PCSX2 install. Sources are discovered automatically and appear once the emulator is detected.
Added Ryujinx as a game source: discovers XCI, NSP, and NRO games from the configured game directories for native and Flatpak installs, with custom titles, playtime, and last-played metadata, and delegated launching.
Added per-source filter chips, status rows, and rescan controls for both emulators in Settings.
Steam
Imported non-Steam shortcuts from shortcuts.vdf, including Wine/Proton games added to Steam, and launched them with the 64-bit shortcut ID Steam expects.
v0.0.11-preview replaces v0.0.9-preview and the withdrawn v0.0.10-preview. It includes all changes since v0.0.8-preview.
New
Recommended Omarchy Shared folder for moving files between Windows and Omarchy. It opens once when first attached, stays pinned in Files, and is available from the tray.
Tray menu for reopening Omarchy, opening the shared folder, Settings, diagnostics, and clean shutdown
Settings for fullscreen, memory, folder sharing, port forwarding, and SSH keys, plus a Start menu Settings shortcut
Offline portable USB mode with persistent guest data
Loopback-only SSH and port forwarding
Redacted diagnostics bundles and try-omarchy-export
Omarchy 4.0.2 for new and reset guests
yay, base-devel, clang, Omarchy's Neovim configuration, screen recording, and missing menu and keybinding tools
Fixed
Upgraded v0.8 through v0.10 guest disks now receive the current launcher integration without replacing the guest or user data
Updates are verified before switching versions, and a failed first boot restores the previous guest and runtime
Folder sharing works with CPU rendering through the bundled runtime
Unsafe or unavailable shared folders no longer prevent startup
Startup no longer fails solely because nested virtualization is unavailable
Reduced idle CPU use from excessive QEMU redraw polling
Reduced QEMU HDA audio underruns
Fixed notification close behavior and kept notifications private on the lock screen
Fixed Settings opening behind the Omarchy window
File drag and drop and file clipboard transfers are not included yet.
Extracted image text now opens in a selectable review sheet with preserved line breaks, Copy selection, Copy all, retry, and temporary corrections.
The viewer action list supports Tab, arrow keys, Enter, Space, and accessibility activation. Shortcut tooltips now use the live bindings.
QR actions appear only after a QR code is detected in the open image.
OCR search results show the matching text when the filename did not match.
Changed
Copy to clipboard is now Copy image.
Browse is now a bounded, searchable library panel with direct source, folder, album, duplicate, and add-folder controls. Folder labels are concise while the parent path and recursive item count remain visible as context. Search filters the choice model before rows are created, and reopening Browse returns to the active folder or album.
Extract Text retries sparse screenshots once when the normal OCR pass finds almost no text. Results still share the same private cache.
Extract Text takes priority over background OCR and stops its current pass when the review closes.
Viewer actions keep keyboard focus when moving between files or closing a nested sheet. Extracted text receives focus as soon as it is ready.
Large libraries use indexed path lookups and bounded image metadata batches. OCR queues start and stop without hashing every path.
Libraries with more directories than the inotify safety cap get a periodic worker rescan, while ordinary watcher updates only change affected paths.
Fixed
First-run media date indexing publishes one settle
Clear folder sources in Settings. Omaroll lists the Omarchy and XDG folders it detects automatically, combines roles that resolve to the same path, and marks unavailable paths. Added folders stay saved so removable storage can return later.
Original media dates. General photos use EXIF DateTimeOriginal or DateTimeDigitized, and videos use their embedded creation time, so files copied into a watched folder still land on the day they were made. Omaroll reads one file at a time after discovery, caches both found and missing dates by file identity, and never overrides a timestamped capture filename.
Find exact duplicates. Browse opens a read-only review that compares only same-size candidates, hashes them off the interface thread, keeps matching sets together, and updates when files change. It never removes anything.
Save the current video frame. The viewer hands its exact playback position to ffmpeg, writes a timestamped PNG beside the recording, and tracks the result without changing the video.
Rename in place. The sheet keeps the media extension fixed, refuses an existing filename, and carries favourites, hidden state, and album membership to the new path.
Search inside pictures. Filename results appear immediately, then local Tesseract indexing adds screenshots and photos containing every search term. It starts only while search is active, runs one file at a time, pauses after the current file when search clears, and reuses a private, identity-checked cache pruned to 64 MB at startup. Progress is visible, and Settin
Transcode actions always show a result. A running transcode pins a "Making ..." line in the footer and selects the finished file in the grid, and pressing an action whose output already exists opens the viewer on it.
Existing outputs are verified with ffprobe before being trusted, so an empty or truncated file left by an interrupted run is cleared and remade instead of blocking every retry as "already done".
A -720p.gif, -1080p.mp4 or -4k.mp4 renders its thumbnail from the source video beside it, so a recording and its conversions show identical tiles instead of three different frames of the same content.
A recording's tile returns to its resting frame when a hover scrub ends, instead of parking on whatever frame the hover left it at.
An animated GIF with no source beside it thumbnails at the same percent-in moment as a video, rather than always its first frame.
The thumbnail cache regenerates lazily on first view after upgrading.
Clip to GIF, Resize to 1080p and Convert to JPEG used to be fire-and-forget: the new file blended into the library with no word about where it went, a transcode's output sat in the grid as a broken zero-byte tile while ffmpeg worked, and if the run died the tile stayed broken forever with no explanation. Transcodes are now followed to the end.
Fixed
You can see where the file went. When a transcode finishes, the library rescans, the status line says the new file was saved beside the original, and the grid selects and scrolls to it. If the current filter would hide it, the view clears to show it, the same way "Open with Omaroll" does; otherwise your filters are left alone.
No more broken tiles mid-transcode. The output file is held out of the library until the tool finishes, so the zero-byte in-progress file never appears as a broken entry, and its thumbnail is only made once the file is complete.
Failures are cleaned up and explained. A transcode that dies leaves no partial file behind, and the tool's own last error line is quoted in the status message instead of silence.
No more false "already done". Running the same transcode again while one is in flight says "Still working on ..." instead of mistaking the half-written file for a finished one.
Stale entries fix themselves. Finished transcodes are rescanned even though writing into an existing file fires no directory event, which was why a thumbnail made from a half-written file used to stay broken until restart.
Omaroll now resolves theme colors the way Omarchy itself does. Before this release, only themes with a fully semantic colors.toml followed your theme; anything else quietly fell back to Omaroll's built-in green look.
Fixed
Compact terminal palettes follow the theme. A colors.toml that defines only background, foreground and color0..color15 (the format many third-party and Ghostty-derived themes use) now resolves through the same alias cascade as omarchy-theme-color: ANSI names map to semantic names, muted, selection and the foreground variants follow the same fallback chains, missing dark and darker background shades are derived with the same 25% and 50% black mixes, and light or dark mode is detected with the same precedence and luminance threshold.
Accent falls back to the terminal blue. When a theme defines no accent, Omaroll takes color4, exactly like the Omarchy shell, instead of showing the built-in green accent.
Legacy names and the Omarchy 3 layout work again. Themes using the old short names (bg, fg, dark_bg, ...) resolve correctly, and a theme installed under ~/.config/omarchy/current is found when the Omarchy 4 state root has none.
The state root matches Omarchy. Omaroll reads the fixed ~/.local/state/omarchy/current path that Omarchy's own scripts use, rather than honouring XDG_STATE_HOME when Omarchy does not.
Machine-level launcher overrides apply. A [launcher]background or background-alpha in ~/.config/omarchy/shell.toml overrides the theme's values,
Omaroll is a fast image and video viewer that turns your media folders into a library. Built for Omarchy, as an independent community project.
Omarchy ships a very good capture stack and then saves everything to folders. Omaroll is the part that comes after: finding the thing again, and doing the obvious next thing with it.
Highlights
One library for everything you capture. Screenshots, recordings, pictures, videos and downloads, grouped by day, newest first. Add any other folder from Settings and switch between folders from the library bar.
Knows what each file is. Omarchy stamps its captures with a predictable name, so a screenshot is a Screenshot even when it lives next to every other image in ~/Pictures.
A viewer with every action beside the picture. Enter opens a capture large. Images zoom, pan, rotate and animate. Recordings preview muted with a scrub bar and a sound toggle. F11 for fullscreen, F5 for a slideshow of any folder, album, search or filtered view.
The tools you already have, one key from the file. T sends a recording to omacut, A sends a screenshot to tensaku or $OMARCHY_SCREENSHOT_EDITOR, and the action list runs omarchy-transcode, mpv, tesseract, zbarimg, Pinta, imv, LocalSend and Nautilus. A tool that is not installed is shown greyed with the package to install, not hidden.
Make it postable. The one thing Omaroll does natively: six finished backgrounds derived from the screenshot's own dominant colour, the same six every time for the same file. Pick one and it is on your clipboard and sa
Added optional owned Steam library sync, installed and ready-to-install filters, and Steam installation handoff.
Loads owned-game covers as they enter the visible library instead of fetching an entire account at once.
Kept the Steam library when a configured library path is missing or a manifest is unreadable instead of showing an empty or frozen library.
Skipped unusable entries and Steam tools during owned-library sync instead of failing the whole sync.
Remembered games without Steam achievements instead of re-requesting them on every visit, and reported that state plainly.
Required a 17-digit Steam ID, reported when Steam is still busy, and stopped re-requesting covers Steam does not have.
Heroic, RetroArch, and Lutris
Added games sideloaded into Heroic, plus Heroic playtime and last-played activity.
Resolved the RetroArch Flatpak's sandbox paths so its playlists, thumbnails, and playtime logs are found, and matched playtime logs by the core's short name and archived content name.
Ignored a leftover Lutris database whose native or Flatpak launcher is no longer installed, and checked Flatpak launchers without blocking the interface.
Navigation and library
Added controller navigation across library modes, source filters, organization controls, Settings, and game details.
Moved keyboard and controller Up from the top row of games into the filters and toolbar, with arrow keys between those controls and Down back into the grid.
Kept detail-page controller movement in content order below collections.
Fixed the launcher quitting on its own after about half an hour. Omarchy kept running, but the Windows key and every Windows shortcut went back to Windows, and the window could no longer be closed normally.
Fixed setup blaming your connection when the real problem was a full disk.
Removed a stall of about a minute when the bundled runtime rolled back to its previous version.
Added resumable downloads so an interrupted setup continues where it stopped instead of fetching the payload again, with bounded retries when antivirus or indexing briefly locks a finished file.
Added version details to the launcher, so Explorer, Task Manager and the Windows permission prompt now show Try Omarchy instead of a blank entry.
Added a source-locked CI build for the patched Windows QEMU runtime, including matching source, licenses, package inventory, provenance, and per-file hashes.
Added isolated signed test launchers so runtime candidates can be exercised without changing the production payload.
Hardened runtime packaging and validated clean setup, CPU fallback, scoped Windows-key handling, clipboard sharing, shutdown, relaunch, and persistent guest data in a nested Windows VM.
Made text clipboard sharing survive late guest startup, Wayland reconnects, early Windows copies, and temporary Windows clipboard contention.
Updated the guest image to nautilus 50.3 and fd 10.5.
Known limitation: Win+L still locks Windows instead of reaching Omarchy. Windows reserves that shortcut and no application can intercept it, so rebind the Omarchy action if you need it.
Toolport 1.18.0 adds a native GTK shell for Arch and other current-GTK Linux distributions, makes the destructive-tool setting hide what it refuses, and fixes catalog entries for servers you host yourself. The .deb and AppImage builds are unchanged and remain the Linux download everywhere else.
Added
A native GTK shell for Arch, Omarchy, and other current-GTK distributions. Not a rewrite of the Linux app for every distribution: this is a second Linux build, packaged for Arch as toolport, and it needs GTK 4.10 or newer and libadwaita 1.4 or newer. That rules out Ubuntu 22.04 and Debian 12, which keep the existing .deb and AppImage, as does anywhere the native package is not available. Where it does run it is GTK4/libadwaita rather than a web view: it follows the active Omarchy palette, behaves as a regular Wayland window under Hyprland, and leaves tiling and geometry to the compositor. Everything the cross-platform app does is here - servers, profiles and secrets, client detection and connection, pending approvals with desktop notifications, Activity, Catalog and starter stacks, Playground, Rules and project rules, Teams, agent permissions and the activity recorder, the shared HTTP endpoint, diagnostics, and first-run setup. Updates come from pacman or the Omarchy update flow; there is no self-updater in this build.
Only one Toolport should run at a time. Both builds read the same ~/.config/Toolport, and only one process can hold the approval broker's endpoint, so the second to start shows an empty approval queue while promp
Sticky notes that live on the edge of your screen, for Hyprland.
The dash on the edge *is* the note: reach for the strip and it fans out its labels, land on one and that same rectangle grows into the editable note. Nothing slides out from behind anything else, and everything else on the surface is click-through.
Edge strip with hover peek, drag reorder, and scrolling past ten notes
Markdown styled in place, with no edit/preview mode
Pop a note out into a real window: move it, resize it, drag it between monitors
All Notes: search, archived notes, trash with restore, and export
Reminders, checklists, and pasted images
Follows the active Omarchy theme, with note colours generated per theme
Notes are plain markdown files. Everything has a CLI and an IPC call
Install
The AUR is closed to new submissions at the moment, so either build it:
``bash git clone https://github.com/tsouth89/ledge cd ledge && makepkg -si ``
or install the package attached below, which is built from this tag and contains no compiled code:
Then systemctl --user enable --now ledge, or exec-once = ledge start in your Hyprland config.
Requires quickshell. Developed on Hyprland; other wlroots compositors should run the strip, but popped-out notes rely on Hyprland window rules for placement.
Added CI for launcher builds, release-pin validation, and guest patch contracts.
Added a two-phase release workflow that rebuilds and smoke-tests the guest, signs the optimized launcher through Azure OIDC, and verifies public downloads before marking a release Latest.
Added authenticated automatic updates for the launcher, bundled runtime, and factory guest image, with staged installs and automatic rollback after a failed first boot.
Added bounded retries for temporary DNS, connection, rate-limit, and server failures during setup downloads.
Made instant-mode credentials explicit in the account choice, setup splash, and a one-time first-desktop notification.
Removed the duplicate Windows pointer over the guest-rendered cursor, with -host-cursor retained as a diagnostic fallback.
Thanks to everyone testing Try Omarchy on real hardware and over remote sessions.
Try Omarchy can now take you straight to the desktop with a ready-to-use trial account. This release also adds branded Start-menu and Desktop shortcut choices, plus a compatibility guide for common Linux apps and packages.
Thanks to Marx-Bray for suggesting the launcher shortcuts in issue #1, and to everyone testing Try Omarchy across different Windows setups.
This preview polishes the first-run experience and fixes the rough edges found during launch-day testing.
Reworked the setup splash with a clear SUPER-key explanation and starter shortcuts
Added safe cancellation that stops downloads, removes partial setup data, and keeps the launcher
Authenticated the release manifest before downloading payloads and added recovery for incomplete installs
Prevented QEMU from trapping the Windows cursor in RDP sessions
Added essential keys, uninstall instructions, compatibility notes, and a FAQ
Thanks to Tom Ballard for the manifest hardening and incomplete-install recovery in PR #2. Thanks also to everyone who tested the early previews and reported the problems that shaped this release.
The EXE is signed with Azure Trusted Signing. It uses the unchanged Omarchy image and WINQ-EMU payload from v0.0.3-preview.
Download: TryOmarchy.exe (8 MB, signed). Open it - first run switches on Windows' virtualization if needed (one permission prompt, one restart; machines with Memory Integrity on skip this entirely), downloads the GPU runtime and the Omarchy image, and boots you into setup. Checksum in TryOmarchy.exe.sha256.
---
Same Omarchy 4.0.1 image as v0.0.2 plus two guest-side fixes for the native app shell: a reboot-notify unit (reports reboot intent on lifecycle port 4450, so TryOmarchy.exe relaunches instead of exiting even when stock WHPX QEMU wedges during guest reset) and a silenced clipboard-bridge push when no host listener is up.
Hardware-validated on a Ryzen 5 5625U laptop: regression, runtime download, signed-binary smoke, close guard, clipboard, folder sharing, reboot lifecycle. The exe is signed with Azure Trusted Signing (publisher: Brandon South).
Second preview image. Omarchy 4.0.1 (was 4.0.0.alpha), all 22 upstream themes, screensavers working out of the box (ttfx + hypridle), Venus ICD (vulkan-virtio) preinstalled, permanent SDDM autologin written by first-boot provisioning (no greeter, ever), baked-in two-way clipboard bridge, /mnt/host automount for the launcher's -Share folder, and a visible cursor under SDL.
Validated end to end under KVM before publishing: setup form to desktop, reboot straight back into the desktop, 3.45s to graphical.target on the test box. Use scripts/bootstrap.ps1 from the repo to install; rerun with a deleted %LOCALAPPDATA%\TryOmarchy\guest to upgrade from v0.0.1, and launch with -Fresh.
Guest image built from jorge-huxley/try-omarchy-win (win branch) plus the patches in guest-build/.
First public release of Typearchy, a local-first typing game for Omarchy. Includes the native plugin, full browser client, Daily challenges, adaptive Drill mode, code and shell practice, local history, ghosts, themes, and shareable result pages.
First developer preview: Omarchy boots to a rendered Hyprland desktop under QEMU/WHPX on Windows. CPU rendering only (llvmpipe, SSE4.2-tier flags — see docs/FINDINGS.md for the WHPX XSAVE cliff). Validated in a nested dev environment; bare-metal validation in progress. Use scripts/bootstrap.ps1 from the repo. Guest image built from the pinned Omarchy revision via jorge-huxley/try-omarchy-win's x86_64 builder.
An abandoned backup or Ditto file-dialog pick is no longer writable for the rest of the process: the grant expires after 60 seconds or when Settings closes (SBS-1015)
Edited clips now store the same 200-character text_preview as capture, so flyout and History search no longer ship 500 characters of an edited body (SBS-994)
Content-hash dedup no longer deletes a file named by clip_images.file_path unless it sits in the managed image directory, matching the other delete paths (SBS-987)
Backup import refuses a file larger than 256 MiB before reading it into memory or checking the AEAD tag, so a huge unauthenticated bundle cannot abort the process (SBS-981)
Encrypted backup now overwrites the passphrase, the key derived from it, and the in-memory JSON history when export or import returns, instead of leaving them in freed heap (SBS-983)
Search no longer ships full decrypted clip bodies on every keystroke; flyout and History search rows use the same preview-only contract as the list (SBS-912)
The opener release gate now models glob the way tauri-plugin-opener does (star and question-mark match slash) and refuses a host pattern that contains a wildcard, so a dropped-slash glob fails the release check instead of shipping (SBS-997)
Paste and copy no longer emit the full decrypted clip body to the WebView when no clipboard-write listener is present (SBS-1042)
Revealed plaintext is cleared when a clip is deleted, the flyout hides, or History loses focus (SBS-1005)
Clipboard items carrying supported do-not-retain markers are no longer stored, and
Toolport 1.17.0 brings one permission policy to Claude Code and Cursor, makes agent rules project-aware and safe around hand edits, hardens approval and Teams trust boundaries, and fixes fresh Codex gateway startup on Omarchy.
Security
A process that bound the approval broker's endpoint after the app had gone could approve gated calls in its place, and be handed the arguments first. The gateway dialed whatever approval-endpoint.json named and believed whatever came back. The descriptor survives a crash or a force-kill, and nothing authenticated the peer that answered: the literal bytes "approved" were a complete decision. Because the request is written before the reply is read, such a peer also received the call's real arguments, including the rehydrated values behind a PII release. The gateway now opens every dial with a random challenge that the broker must answer with an HMAC-SHA256 proof of the shared token, and sends nothing until the proof checks out; a peer that cannot read the owner-only descriptor cannot produce it, so it sees no request and its answer is never read. The failure is reported as unreachable, so a restarted app is still found on the re-read, and it is still fail-closed. On Unix the broker also listens on a socket file in a 0700 directory under the data dir, which a current gateway prefers, so such a peer cannot even connect on that path; the loopback listener stays (and is all there is on Windows), and the challenge protects both the same way. A gateway from before this change still reads only the loop
Charts stops showing numbers it cannot stand behind. A month whose models have no published prices painted as an empty one, the busiest day on the activity heatmap could share a shade with the quietest, and a Codex session carried whatever calendar day it was first parsed on, so a DST change or a trip moved usage onto the wrong day. Two cards scanning at once could overwrite each other's index, and a price refresh landing mid-scan stamped old dollars as current for every card already in the file.
The rest is state a surface reported but could not actually reach. A settings or credentials write could run unserialized on a filesystem that cannot flock, Install and Restart could check a staged installer against a different release's digest, and dismissing an update mid-download un-dismissed itself on the next progress chunk. A machine reporting no home directory no longer reads Gemini credentials from — or writes refreshed Google tokens into — whatever directory it happened to start in.
Ceiling also asks for a GitHub star now. At most twice, ever, and only after a provider has actually reported a reading.
Added
Ceiling asks for a GitHub star, at most twice ever. A card in the bottom-right of the dashboard, and the only thing Ceiling has ever asked of anyone using it. The first ask waits until a provider has actually reported a reading and that reading has been on screen for twenty seconds, so it lands after the app has done something useful rather than during setup, when it would be asking to be paid before the work. The second,
Toolport's AppImage opened a grey, empty window on Arch, Omarchy, Manjaro and other rolling distros — but only on Mesa, which is to say AMD and Intel graphics. NVIDIA machines were fine. That split made it look like an AMD bug, and 1.15.0 shipped advice to install a native package instead and pick your download by driver.
It was never about the GPU. 1.16.0 fixes it at the source: one AppImage, running on Omarchy, Arch, Manjaro and EndeavourOS across AMD, Intel and NVIDIA alike. No native package required, no driver-specific advice, nothing to choose.
scripts/install.sh follows suit — Arch just gets the AppImage now. toolport-bin is still published for anyone who would rather have a real package that upgrades through pacman; it's a preference now, not a workaround.
---
What was actually wrong
The AppImage bundled wayland 1.20. AppRun puts the bundle on LD_LIBRARY_PATH, and the dynamic loader applies that to everything the process opens afterwards — including the host's GPU drivers, which are deliberately not bundled. So the host's own Mesa was resolved against a four-year-old wayland:
wl_fixes_interface arrived in wayland 1.23. libEGL_mesa therefore never loaded at all, eglGetDisplay returned nothing, and WebKitWebProcess aborted on startup with EGL_BAD_PARAMETER — a window that opens and never paints. NVIDIA's proprietary EGL doesn't link libwayland-client, which is the only reason it escaped.
Security hardening requested during marketplace review: remote Sentry data is bounded and rendered only as plain text, authenticated API responses have strict size limits, and plugin-owned config/cache state rejects symbolic links and uses atomic writes.
Release job no longer inherits Azure Trusted Signing credentials during frontend install. They are now step-scoped to the Windows tauri build, matching TAURI and APPLE. (SBS-925)
Downstream stderr drain no longer grows without bound on a newline-less write. Stdout was already capped at 16 MiB per line; stderr still used unbounded read_line and only trimmed the kept tail afterwards. A hostile or buggy stdio server that wrote a multi-GB chunk with no newline could OOM the gateway and take every HTTP-bridge client with it. The drain now uses the same take(MAX_RESPONSE_BYTES) bound as stdout and stops on an unterminated full-cap line. (SBS-930)
Added
Arch Linux package: toolport-bin (paru -S toolport-bin, or omarchy pkg aur add toolport-bin, once AUR account registration reopens upstream; until then `scripts/render-aur.sh <version> ./aur && cd aur &&
makepkg -si builds the identical package with no AUR account). The AppImage bundles Ubuntu 22.04's libwebkit2gtk-4.1, which has no WebKitGPUProcess and cannot initialise EGL against a current Mesa, so on a rolling release the window opens grey and empty while WebKitWebProcess aborts every launch. No WEBKIT_* variable avoids it. The AUR package repackages the official .deb payload against the host WebKitGTK, the same thing the .deb already does on Debian/Ubuntu. Published by a new aur.yml workflow that build-tests the PKGBUILD in an Arch container before pushing. scripts/install.sh` now routes Arch users there. The fat AppImage is
Charts opens in about two seconds instead of about thirty. Each local transcript is now parsed once into a small index beside your settings rather than re-read from the top by every card, every time, and the cards keep their last result so a restart is not a cold start. The numbers are unchanged: an indexed scan is checked against a full re-parse, and the index is discarded outright whenever model prices move.
The rest of this release is about surfaces reporting a state they could not actually reach. Signing out of StepFun could leave a live token behind if a refresh was in flight, Gemini treated a token endpoint it could not reach as a signed-out account, a countdown could read "0m" while a window still had a minute in it, and About labelled a failed download as a failed update check and said it in half-translated English.
Fixed
Charts opens in a couple of seconds instead of half a minute. On a machine holding gigabytes of Codex and Claude transcripts, opening Charts started three separate walks of the same logs at once, and each one read every file from the top: Estimated API value scanned ninety days when the furthest period it shows reaches back sixty, the activity heatmap scanned thirty, and the provider charts scanned again on top. Nothing was kept, so switching tabs paid for all of it again, and clicking Yesterday or 30 days re-ran a full scan for numbers the card already had in hand. Each transcript is now parsed once and its records are kept in a small index beside your settings; a file that grew since is resumed from w
The Win+V helper no longer opens the flyout on a bare localhost UDP activate datagram; the channel now requires a per-session token, a loopback source, and a rate limit (SBS-809)
History list requests no longer ship full decrypted clip text to a window that asked only for previews (SBS-829)
Release builds no longer stream Rust logs into the WebView, which had been putting process names, clip identifiers, and filter values in renderer memory (SBS-837)
Backup export, backup import, and Ditto import now only write or read a path chosen in the file dialog, so a compromised Settings page cannot send history to an arbitrary location (SBS-808)
History source-app filter values are no longer written to the persistent Info log (SBS-773)
A signed Microsoft Store installer that packs an unsigned cubby.exe is now rejected instead of published (SBS-777)
Pin third-party GitHub Actions in privileged release and Store workflows to immutable commit SHAs, and reject new mutable pins in CI (SBS-778)
Changed
Portable mode keeps its promises: logs stay in the folder you carry instead of %LOCALAPPDATA%, the installed-channel updater stays out of portable builds, and a storage.key this Windows account cannot read is explained at startup instead of failing silently (SBS-774, SBS-775, SBS-776)
Startup now records what its storage migrations changed, so a run that edited history says so
Pre-merge CI now cargo-checks x64 and ARM64 default and Microsoft Store feature builds, so those configurations fail on the pull request instead of at release (SBS-779)
Adds an activity heatmap to Charts and an opt-in spend warning that needs no budget set, and lets the floating bar follow whichever app you are working in. Mostly, though, this release stops surfaces reporting a state they could not actually read: a provider outage is now told apart from an empty quota, a missing Cursor plan reads as unavailable rather than 0% used, SuperGrok's weekly figure is decoded rather than guessed at, the taskbar strip stops cutting the last character off a reset, and prices, chart caches, and CLI logs stop losing or hoarding data on disk. Release builds also drop the loopback exception their content policy was carrying from the dev server.
Supersedes 1.5.32. That version was tagged, signed, and drafted on 2026-08-16, and its installers were uploaded to the versioned download path, but the GitHub release was never published and no one received it. The v1.5.32 tag stays as a marker. Everything from it is included here, plus the taskbar reset fix that was found in its build.
Added
Providers having a public outage get a badge on their card. A "0 tokens left" reading and a provider outage looked identical, so the second was read as the first. The provider card now carries the status page's own wording, plus a control that opens that page. Off by default and opt-in under Notifications, because it is the only outbound request Ceiling makes that is not to a provider you already signed in to. Nothing about you is sent. Only enabled providers whose status page can actually be read are polled, at most once every
Agents can now keep what worked. A proven multi-tool orchestration can become a saved routine that survives sessions and clients, with a human approving the exact definition every time one is persisted.
The rest of the release is mostly a security pass, and the credential one is the reason to upgrade rather than wait: the redaction gate in front of the public share link, the diagnostics bundle and the team config push missed several of the most ordinary ways a key is spelled, so live tokens could ride out to a public URL. Two more findings in the same family are closed here, along with a set of local-file permissions that were wider than intended and an installer that never checked who signed the build it was about to install.
A run of hardening across the app, on one theme: a check that could not finish used to look exactly like a check that passed. A reload signal, a vault read, a restart check, a backup stat each had a failure path that came back looking like good news. They now report the failure, so what the app shows you is what it actually knows.
Added
Persistent agent routines. A proven multi-tool Code Mode orchestration can be promoted into a saved, parameterized routine that outlives the session and works from any client. Promotion is the only way in: toolport_run_script gains an immutable input mode (inputs schema-validated, deep-frozen in the VM, dropped after assessment), only immutable runs are promotion-eligible, and toolport_save_routine takes a runId rather than source, so free-typed source can never be persisted. Every save
Hardens updates, credentials, and the local serve API, and ships the unpublished 1.5.30 work: a second tray click hides the dashboard, Grok banked resets show, and the taskbar strip finds a second lane when the usual gap is gone.
Supersedes 1.5.30. The GitHub release was tagged and drafted on 2026-08-13 but never published; the v1.5.30 tag stays as a marker. A Microsoft Store submission was created from that tag. Everything from it is included here.
Security
Ceiling checks who signed an update before it runs it. An automatic update was trusted on the strength of the SHA256 that GitHub's release metadata reported, so that metadata was the only thing standing between Ceiling and launching an attacker's installer with the user's privileges. Every downloaded installer is now independently checked against Windows Authenticode and pinned to Ceiling's publisher identity, once when the download completes and again immediately before launch. An installer that fails either check is deleted instead of being left on disk to be retried. The publisher identity is pinned rather than the signing key, because Azure Trusted Signing issues a fresh short-lived leaf certificate for every release and a key pin would reject the next legitimate one.
codexbar serve now requires a per-user bearer token. The local HTTP API bound to loopback with only a Host check, so any process on the machine could read usage, email, organization, and raw provider errors. /usage and /cost now need Authorization: Bearer unless you pass `--allow-unauthentic
Toolport installs two new ways: as an agent plugin any conformant client can pick up, and on Windows through a one-line command instead of a trip to the Releases page. Pseudonymization gains the piece it was missing, a way for a human to release one value to one server, so the workflow it used to dead-end now has an answer.
Most of the rest of this release is one defect wearing different faces: code that read a failed probe as good news. A failed audit baseline, health check, security read, or integrity load could each come back looking like "all clear" and let the app act on it. Each one now fails closed.
Added
Agent plugin. Toolport now ships as an Agent Plugins 1.0 package (toolport-agent-plugin.zip on each release): one install connects VS Code, GitHub Copilot CLI, the Copilot app, and other conformant clients (plus Claude Code, via the bundled dual layout) to the local gateway, with a skill teaching the agent the search → call workflow. The plugin launches the gateway the desktop app already installed, so plugin installs share your existing servers, credentials, and profiles. If the app already manages that client, disconnect it there first or the gateway connects twice.
Windows one-line install.irm https://raw.githubusercontent.com/tsouth89/toolport/main/scripts/install.ps1 | iex, matching the macOS and Linux one-liners. It resolves the release through the GitHub API, picks the NSIS asset for the machine's architecture, and refuses to install anything it cannot verify against the per-asset dige
Finishes what 1.5.27 started: Cursor's on-demand spend now reads as money on every surface that shows it, not only the Overview card. Also lets a monthly quota raise a pace warning, and gives every settings control a name a screen reader can reach.
Supersedes 1.5.28, which was tagged but whose build was cancelled before it signed or published anything; everything from it is included here. The v1.5.28 tag stays as a marker.
Fixed
Cursor's on-demand spend reads as money on the taskbar, not just on the Overview. 1.5.27 taught the Overview card to show dollars, but the surfaces you actually glance at were left behind. The taskbar tile picked the on-demand lane correctly and then drew "62%" � the fraction of a spend cap, which says nothing about the $1,112.92 behind it, and which inverts to a cheerful "38%" if you display remaining rather than used. The flyout was worse: it discarded any lane whose name contained "on-demand" before building its rows, so the tile named a lane that the panel beneath it refused to show, and because the same filter ran before the "+N more limits" count, nothing hinted that a row had been dropped. The free-floating bar carried the identical percentage-only defect. Activity had the same habit from the other direction: it listed the On-demand row faithfully and then headlined it "56% used", describing the shape of the bar instead of the bill. A lane billed in currency now leads with the amount on every surface that shows it � taskbar tile, hover flyout, floating bar, and the Activity schedule � the flyout
Makes Cursor's on-demand spend readable at a glance, corrects two numbers Ceiling was reporting wrong, and replaces browser cookie import with a manual setup you can see.
Supersedes 1.5.26, which was built but never published; everything from it is included here.
Changed
Browser cookie import is gone, replaced by a manual copy-and-paste setup. Ceiling could read cookies out of the browser's own database to authenticate a provider, and provider fallbacks could reach for that database without being asked. Handing an app your browser's cookie store is a large amount of trust for a usage meter, and it happened where you could not watch it. Providers that need a cookie now ask for one, with a guide for copying it out of the browser's developer tools, and the value goes to the same secure store as every other credential. If a provider was authenticated by browser import, it will ask you to set it up again. Everything else is untouched: CLI credentials, IDE credentials, OAuth sign-in, and Claude Desktop sessions are all still detected automatically, and providers on those paths need no attention.
Added
Tab strips can be driven from the keyboard. Settings, the Charts provider selector, the account switcher, and the chart-type tabs all announced themselves as tab strips to assistive technology while ignoring arrow keys entirely, and each one spent a Tab stop per tab. Left and Right move between tabs, Home and End jump to the ends, focus wraps, and a strip is now a single Tab stop. Each panel names the tab that opened it, a
A dedicated History window, separate from the Win+V flyout, with a larger image preview you can read and select text from
Multi-select in the History window, with copy, paste, delete, and move applied to everything selected
Filter history by source application and by date range, with per-app counts and quick date presets
Edit the text of a stored clip in place
Notes on a clip, searchable alongside its content and its recognized text
On-demand Scan Text on an image clip, with an editable box for correcting the recognized text before you use it
Encrypted local backup export and import, protected by a passphrase so a bundle can be restored on another machine
A per-clip visibility toggle for keeping sensitive content hidden in the list
Fixed
Stop a failed duplicate check from storing a second copy of a clip. The database now enforces uniqueness itself, and duplicates already in your history are merged on first launch, keeping pins, folders, notes, and hidden state
Keep history ordering total, so scrolling can no longer repeat or skip a clip
Four capture and paste failure paths, alongside signing the shipped binaries so Windows stops flagging them
Accessibility problems found by a static audit, including missing names for icon-only buttons
Changed
Search uses roughly a fifth of the memory it used to per clip, and returns results faster on a large history
Refreshed the interface icon set. The filter, settings, shield, play, pause, file, and flask icons are redrawn with the same meanings and slightly different shapes
Two features ship for the first time. PII pseudonymization replaces personal data in tool results with tokens before the model sees them, restoring the real values only for the server that provided them. OAuth client credentials let a headless server — one nobody can click a browser sign-in for — get a real token. Both are off or opt-in by default.
Several things that were only safe within one process are now safe across processes: rate-limit counters, OAuth token refresh, and the pseudonym map. Each client spawns its own gateway, so one process was never the real shape.
Upgrading a Teams deployment: the instructions receipt hash changes once in this release. See Changed below before rolling it out.
Added
PII pseudonymization. Emails, phone numbers, card numbers, IBANs, IP addresses and provider-shaped API keys become stable tokens (⟦EMAIL_1⟧) before the model sees them, and are restored on the way out. The mapping stays in memory. Off by default, and a reduction rather than a guarantee: a value no detector recognizes passes through, as does everything once the per-session cap is reached. (SBS-346)
OAuth client credentials for headless servers. Discovers the endpoint, negotiates the auth method, and reacquires before expiry. Never falls back to a browser flow, which would be unusable where this is needed. (SBS-524)
Old gateway binaries are cleaned up instead of accumulating (~18 MB a release). Keeps anything running, named by a client config, known to be relaunching, or recent enough to still be cached. (SOU-484)
Claude's taskbar tile now shows the capacity that governs your account
Claude's model-specific limits, such as "Fable only," could take over the single taskbar lane when they reached 100%. That hid Session and Weekly capacity even though switching models still let you work. The native taskbar tile and floating bar now reserve that lane for the real account pools; model limits remain visible everywhere that lists all windows.
Credential and settings updates no longer risk unrelated data
An unreadable API-key or manual-cookie store is left untouched instead of being treated as empty and overwritten.
Unknown provider settings and token accounts survive saves and downgrades instead of resetting preferences or disappearing.
Removing one token account preserves the account you actually selected.
Custom Codex endpoints are checked by their real host
Plaintext custom Codex URLs are restricted to genuine loopback hosts. URL shapes that merely contain localhost while pointing at a remote host are rejected, preventing the Codex access token from being sent there. Legitimate local proxies continue to work.
Also fixed
Countdown formatting no longer loses nearly an hour around hour boundaries.
Relative reset timers hold at one minute instead of displaying "Resets in 0m."
Installers
Ceiling-1.5.25-Setup.exe - standard installer
Ceiling-1.5.25-portable.exe - portable
Ceiling-1.5.25-Store-Setup.exe - Microsoft Store package (WebView2 bundled)
Portable builds show alerts as banners but do not keep them in the notificat