Skip to main content
New v0.65.0 is out: reaching the human

Every release, in plain language

agentwatch watches your coding sessions and lets you drive them from a browser, a CLI, a phone or a WhatsApp message. It ships continuously, so this is the stream grouped into monthly releases, newest first.

1,423

Commits since January 2026

6

Months with releases

567

Commits in the largest month

v0.65.0

Latest release

Release history

agentwatch tags points in a stream rather than gates, so the work is grouped here by month. Where a month shipped without a git tag, the version number is backfilled and says so.

v0.65.0

Version backfilled, no git tag

Commits
82
Features
38
Fixes
27

Reaching the human

Every rung of an escalation ladder, from a chat message to a real phone call, plus a way for agents to hand work to each other.

  • Hand a task to another repo

    An agent that needs work done in a different repo on the box hands it over with one command and keeps going. agentwatch finds the repo, launches or reuses its session, and introduces the two. Permission modes translate between Codex and Claude instead of being dropped, and a session sitting on a permission dialog is never typed into.

  • WhatsApp, in both directions

    One WhatsApp group per repo. Send a note, ask a question and wait for the answer, or send a one-tap Yes/No poll when a dictated instruction looks wrong. Markdown is converted to WhatsApp markup. Voice notes are transcribed on your own machine, and agentwatch can answer as a real voice note. Photos, screenshots and files travel both ways.

  • Phone calls and SMS

    agentwatch rings you and holds a spoken conversation. Speech to text and text to speech both run on your box, so the carrier only ever hears audio. The agent never learns your number, it passes an index into your list. One live call at a time, six an hour. SMS is the cheaper rung, gated by a capability token, a verified signature and a sender allowlist.

  • A dispatcher that starts itself

    A WhatsApp group named agentwatch starts an on-demand manager session that hands work to other sessions, rescues a stuck one, then terminates itself. Nothing runs until a message arrives.

  • Hand over a secret safely

    Give a session a credential that never enters the transcript, from a Secret button in the viewer or from the CLI, which reads stdin only. It is stored with owner-only permissions and deleted after 24 hours. Only the shape is ever spoken back: the length, the character class, and at most the kind.

  • Real quota, not a screen scrape

    Claude's remaining budget now comes from Anthropic's own rate-limit headers, and Codex quota from the endpoint its status panel reads. The connection dot in the web viewer shows both, and a reading is cached per credential so nothing polls on a timer.

  • Sessions keep their name

    An agentwatch session now follows Claude's session name across resume and rename. The original tmux name stays a working alias for the life of the process, so URLs and CLI commands keep working.

  • Waiting, done properly

    Wait on a pid, a CI run, a PR, a workflow or a URL with one command, plus a stale-task monitor that tells you and never kills anything. Full prompts now really reach Codex: the text is paste-framed and the submit is verified, and agent mail is confirmed by a read receipt rather than a successful write.

v0.64.1

Version backfilled, no git tag

Commits
33
Features
20
Fixes
7

Context and the right device

A short, dense month: agents learned what they were running inside, and notifications learned which device you were actually holding.

  • Agents know they are in agentwatch

    Every Claude session agentwatch launches is given its context on startup, and a hand-typed claude gets the same through a shell wrapper that fails open. Spawned sessions are named after the agentwatch session, so the two namespaces stop drifting apart.

  • Notifications find the right screen

    A push now goes to the single device you most recently had agentwatch open on, desktop or mobile, and only falls back to every device when it has to. A tab already in the foreground silences the push, because you are looking at it.

  • Scrolling that actually scrolls

    Real in-place scrolling in xterm mode. The wheel, trackpad, touch drag and scrollbar all move the terminal viewport with no server round trip, while the live stream keeps running underneath. Direct-keyboard typing is about thirteen times faster, and keystrokes are no longer logged.

  • Files and disk

    Files an agent shares can be downloaded straight to your computer from the inbox. Stale editor workbench trees are pruned, keeping only the one being served, which reclaims roughly 650 MB each.

v0.62.0 to v0.64.0

Tagged in git through v0.63.0

Commits
567
Features
168
Fixes
193

The architecture it still runs on

The largest month in the project's history, and the shape the product has kept ever since: one gateway at the edge, slim per-user daemons on the machine.

  • One gateway, many daemons

    A gateway now owns the tunnel, TLS, login, routing, the API, the web viewer and detection. Slim per-user daemons own tmux, spawning and filesystem access. They meet over a per-user socket with kernel-level trust, so there is no loopback port and no token on the internal hop. The reverse proxy is gone.

  • One install command

    No role flags to choose. macOS installs a gateway and a daemon without sudo, Linux as root installs the gateway, Linux as a user installs a per-user daemon. The gateway runs on macOS as a user-level agent, and you can pick a release channel from the URL.

  • Several people, one browser

    Multiple operating-system users can be logged into one browser session at once, each with their own logout, and the session picker labels every card with its owner.

  • See what the tunnel is doing

    A full tunnel observer with log parsing, verdicts, an edge prober, a CLI status panel, and a web page with cursor-synced historical charts and a per-connection anomaly table. The tunnel now survives a restart, and so do web logins.

  • Open a session in VS Code

    A per-user VS Code Web server, cold-started on first request and reaped when idle, with a deep-linked Open in VS Code button on every session and a way back to the viewer.

  • Push notifications and faster streaming

    Web Push arrived with a per-session bell, mute, a presence gate and a cooldown. Terminal streaming moved to line diffs, sending only the rows that changed, with full frames on connect and resize.

  • Signed releases and a tighter edge

    Release manifests are signed and verified on install and update. A strict content security policy landed, WebSocket, capture and terminate calls are gated on session ownership, and the login lockout moved off usernames so it can no longer be used to lock someone out.

v0.58.0 to v0.61.1

Tagged in git

Commits
152
Features
54
Fixes
45

More than one machine

The month agentwatch stopped being one process on one machine.

  • The gateway appears

    Per-user daemon registration with owner verification, proxy handlers for HTTP and WebSocket, and a gateway mode with a system unit. The first step toward the architecture that landed in July.

  • One control plane, two front doors

    The MCP protocol layer was removed and replaced by dual-auth API endpoints plus a full session CLI that hits exactly the same handlers the browser does.

  • An inbox for every session

    A per-session clipboard and inbox with a viewer history, a toolbar badge, and an arrival popup with one-tap copy. Files of any type can be uploaded from the web viewer straight into the session directory.

  • Self-healing tunnels and updates

    An end-to-end public URL health probe, a supervisor that repairs the tunnel on its own, and channel-based self-updates driven by the heartbeat, with a channel-aware manual update command.

  • Fifteen security fixes

    Owner-only session secrets, auth files, TLS keys and device tokens. Magic links redacted from access logs, a cap on batched WebSocket actions, baseline security headers, brute-force login lockout, and the first phase of a content security policy.

  • Only what you asked it to watch

    The daemon monitors agentwatch-owned tmux sessions and nothing else. Your own hand-started sessions are never captured or exposed.

March to May 2026

No commits landed in these months

No releases

A quiet stretch. No commits landed in these three months.

v0.51.0 to v0.57.3

Tagged in git, 21 releases

Commits
508
Features
88
Fixes
168

The viewer becomes the product

Twenty-one tagged releases in one month. The web viewer stopped being a demo and became the thing people use.

  • Run sessions from the browser

    Create and manage sessions from the web viewer, with deep links, a theme toggle, a profile menu, and clients told the moment a session ends. A progressive web app manifest and home-screen icon arrived alongside.

  • One driver, many passengers

    One viewer holds control and the others watch, with a countdown, a way to request control, and the driver identified to everyone else.

  • A terminal that keeps up

    A high-frame-rate terminal mode with real cursor position and visibility, dynamic font sizing, and scrollback deep links.

  • Type straight into the session

    Real keystroke passthrough on desktop, with word movement and editing shortcuts, Shift+Enter, a rate-limit queue badge, and a floating copy button.

  • Codex detection

    Full Codex program and state detection, with its own patterns and matchers, alongside the existing Claude and shell detectors.

Genesis, before v0.51

No tags yet

Commits
81

Where it started

The project was born as pty-snap, a one-shot tmux pane snapshot tool, and was renamed agent-watch before the month ended.

  • Snapshot a terminal

    Terminal capture with width-safe headers and tmux session auto-detection, in four output formats: a one-line status, plain text, JSON, and a PNG image.

  • The detector framework

    Claude Code, Codex and shell detectors, each reporting a program and a state (Idle, Working, Blocked, Error) with a confidence score. Every state feature since is built on this.

  • Daemon mode and hooks

    Passive monitoring of tmux sessions with a config file, live reload, and hooks that fire on a program change, a state change, or any change, filtered by program and by which state you moved from and to.

  • The first web viewer

    Live terminal streaming in a browser, the ancestor of everything the viewer does now.