Minor Changes
-
efa0869:
ctx.agent(name)in a workflow tool now returns a session with that agent:send(message, { outputSchema, signal })returns a response whoseresult()resolves the turn's{ data, message, status }, and the parent stream announces each session withagent.started, carrying the opening call'scallIdandturnId, whichsession.agent(started).stream()follows.ctx.agent(name, { message, agentId })is removed, sessions end when the workflow run finishes, and remote agents now check a protocol version, so upgrade both deployments together. -
c8d38a8: Every agent tool is now a
serve(receive, ctx)tool built onctx.agent, so every subagent call is a resumable task: the call returns a receipt, the agent's reply arrives as a task result, and the model continues the same agent by passingtaskId(replacingagentId) or stops its current turn withtask_cancel. Thesubagent.called,subagent.started,subagent.event, andsubagent.completedevents, their hooks, the[Agents]note, and theAGENT_*errors are removed; clients, hooks, and evals readtask.started,task.settled, andagent.startedinstead, andsession.agent(started).stream()follows a child from itsagent.startedevent.task.startedcarrieskind: "agent"for an agent tool's call and"tool"otherwise, sot.calledSubagentalso sees an agent call that failed before its session opened. The default message reducer behinduseEveAgent()settles a task call's tool part fromtask.settled(output, error, or cancellation). -
7869f50: The Chat SDK bridge's
sendnow takes a message plus channel send options, and a newrespond(inputResponses, { thread })answers pending input requests. To migrate, replacesend({ message, context }, { thread })withsend(message, { context, thread }), and replacesend({ inputResponses }, { thread })withrespond(inputResponses, { thread }). Channel send options also acceptoutputSchema, asSession.send()does.Telegram and Chat SDK inbound messages now go through the public channel
send(), so route wrappers see them. A Telegram reply to a bot message that no session owns now starts a session instead of failing delivery. -
c8d38a8:
session.streamSubagent(started)is nowsession.agent(started).stream().session.agent()takes anagent.startedevent and returns aClientAgentSessionhandle with the child'sname,sessionId, andtaskId; eval sessions get the samesession.agent(started).stream(). -
cc14b3d: Connection tools no longer break the prompt cache. The model finds them with
connection_searchand calls them with the newconnection_executetool, so discovered tools are no longer added to the model's tool list. Connection names now arrive in append-only context messages instead of the system prompt.connection_executereturns MCPstructuredContentor text instead of the raw MCP envelope, and stream events report each call as a nested<connection>__<tool>action with a newparentCallId. Theeve/tools/connection_searchexport is removed, and both tools are reserved names that cannot be replaced or disabled. -
c8d38a8: When eve holds a turn because its tasks are still working, the stream now emits
turn.waitingfor that turn in every session, andsession.waitingcomes only after the turn really ends. In a root session, the model's text before the wait now completes as an ordinary"stop"message, so a person sees it right away. Child and schedule turns still report it as"tool-calls", so they post once.send().result()and MCPagent_getreturn the final reply, not the text written before the wait. -
1a5bc56: Approval response policies now run for Cancel as well as Approve (
response.decisionis"approve" | "cancel"), so a responder the policy rejects can no longer cancel someone else's request; a policy that only restricts approval should return{ status: "allowed" }forcancel. The responder moved fromrespondertoresponse.principal, alongsiderequest.principal. -
b34bab8: Extension configuration and durable state now belong to each logical mount, so duplicate mounts can use independent config and state. Session handoffs across this upgrade boundary are rejected in both directions, including for agents without extensions; keep each session's owning deployment available until it finishes, or start a new session on the deployment you want to use.
-
efa0869: Remove background tasks: workflow tools and subagent calls now always block the turn until they settle,
defineWorkflowToolrejectsexecution, andtaskDeliveryPolicy, thetask_canceltool,session.cancel({ tasks }), task receipts and notifications, and<eve-empty-delivery/>are gone. Extensions built against earlier capability epochs must be rebuilt. -
c8d38a8: Workflow tools can define
serve(receive, ctx)to run a resumable task:receive()resolves the call that started the task, then each later call the model makes with the task'staskId, andctx.reply(output)delivers a result while the task stays available. eve adds an optionaltaskIdto aservetool's model input (the build fails ifinputSchemadeclares its own), idle tasks don't hold the turn and are listed in the[Tasks]note, andtask_cancelaborts the current work'sabortSignalwhile the task stays available for its next call, as long as the body returns toreceive()within 30 seconds. While the task serves a later call,ctx.sessiondescribes that call, with its turn and the auth it was admitted with, andctx.agentslists the agents that call may open. A session opened withctx.agentis the child in lineage and trace of the call served when it opens, and each message sent to it carries the auth of the call served when it's sent. The events a call causes, includingtask.settled,agent.started, and questions, carry itscallIdandturnId. -
9c36b7c: Slack now shows each turn's tasks in a live task card: one message, updated in place, with a row per task that shows whether it is working or waiting on a person, and how it ended. Slack also acknowledges a mention or DM with
Thinking...right away, even with a customonAppMentionoronDirectMessage, and clears it if the hook drops the message. While a turn waits on its tasks, the status names them. Outside DMs and private channels, the card shows a failed task asFailedwithout its error text, and a blocked task without the request's prompt. Channels can now handleinput.resolvedto learn when each question or approval ends, however it ended.slackChannel({ events })is replaced byrenderers, which wrap eve's default rendering instead of replacing it; withoutrenderers, eve renders with its default. Moveevents: { … }torenderers: [{ events: { … } }]and handlers behave as before; call the newnextargument to keep eve's default;nextalso replacesinput.requested'sdefaultDeliver. A renderer can also shape the task card withtaskCard(view, next), whose view includes the turn's other tool calls and their input, so your own tools, such as a checklist, can appear on the card. The experimentalactivityoption, theexperimental_slackActivity*renderers, and the activity collector behind them are removed, along with theactivityObserverfield on delegated and remote-agent sessions; remote agents ignore it when an older caller still sends it. -
c09c0d6: Slack task cards and typing indicators name work more clearly. A task the agent hands to its own copy shows its brief instead of
agent: …. Row titles and results use the first sentence, and results are cut to about 100 characters at a word boundary. The typing indicator shows the same labels as the card and saysWaiting on 3 tasks...instead of naming one task and counting the rest. ThedescribeActionRequestanddescribeActionRequestsexports fromeve/channels/slackare removed. A renderer can callnext()for eve's default status, or readpresentationfromactions.requested. -
efa0869: A steering message now aborts the
ctx.abortSignalof eachexecuteworkflow tool call the turn waits on, so a waited call stops early and settles with what its body returns, or{ interrupted: true }if the body rejects.ctx.ask(request, { signal })withdraws the question when the call'sabortSignalorsignalaborts, resolving ascancelledwith aninput.resolvedoutcome of"cancelled".sleepandask_questionnow stop early for a new message, anddismissibleand thedismissedstatus are removed: a question in anexecutecall lapses when the conversation moves on, and a question asked from ataskstays open. -
c8d38a8: A workflow tool now defines exactly one of
execute(input, ctx)ortask(input, ctx). Atasktool runs each call as a task: the model gets a receipt at once, the result arrives later in atask.resultmessage, the model waits withtask_waitor stops a task withtask_cancel, and a turn can't end while its tasks work.agentRouter()and theworkflowtool now run as tasks. The stream reportstask.startedandtask.settledwith each call'sturnId,turn.waitingwhiletask_waitwaits, and thetaskIdonagent.startedfor a session a task opens; task results are not published asmessage.received.session.cancel()also stops working tasks, andexecutionnow fails with a pointer totask(). Authored tools can no longer be namedtask_waitortask_cancel. Consecutive queued messages from one principal now share a turn even when their auth claims changed, and the turn runs with the latest claims. -
315b353:
eve dev --subagentsnow acceptsfull,collapsed, orhidden, and defaults tocollapsed.auto-collapsedwas removed because it rendered the same ascollapsed; passcollapsedinstead. -
efa0869: A question or sign-in from inside a running call, such as a workflow tool's
ctx.ask(),ask_question, or a subagent's question or connection sign-in, no longer ends the turn: the stream emitsinput.requestedorauthorization.required, then the newturn.waitingevent, and the turn resumes under the sameturnId. The session you answer on now emitsinput.resolvedfor every subagent or workflow tool question it routes an answer to, andsend().result()stops atturn.waitingonly while a question is pending. The message stream version is now 26, which older eve clients reject, so upgrade them with the server.
Patch Changes
-
0ec0381: Channel activity, such as Slack, now shows each agent task or
ctx.agentsession as its own row under the call that opened it. The row settles as completed, failed, or cancelled when the agent's first turn ends, and a turn cancelled while it waits for an answer, including the caller's own, now settles as cancelled unless its own approval or sign-in can still be answered. Before, a local agent's activity merged into the caller's row and marked it done early, a remote agent's row stayed running until the caller's turn ended, and a later message to a remote agent, such as continuing its task bytaskId, failed while activity was on. Later turns of the same session, such as a secondsendor a task continued bytaskId, still appear under its first row. -
c8d38a8: A message sent to an agent task by
taskIdjust as the agent's turn ends now reaches the agent and gets the reply of the turn that read it. Before, the message could be settled with the earlier turn's reply without the agent ever seeing it, and a message sent just after atask_cancelcould be left unanswered. -
c8d38a8: Correcting an agent by
taskIdwhile it works now gets the agent's corrected reply, and a correction sent during the agent's first turn joins that turn instead of waiting for it to end. Before, a message the agent read only after its turn ended was answered with the earlier turn's reply, and the corrected reply was lost, which could leave the caller's turn waiting forever. The same applies toctx.agent(name).send(): a response resolves with the result of the turn that read its message. -
bbbf9fc:
agent.startedhooks keep the session state and sandbox changes they make. A child session that opens while the parent's model is generating appears on the parent stream when that model step ends. -
c8d38a8: A
ctx.agentturn that fails now reports why:result()returnserror.messagealongsidestatus: "failed". Agent tasks andworkflowprogram calls include that reason in their failure, so the parent sees the agent's error instead of "The agent's session ended." -
66f295e: Approved tools now execute correctly when memory recall and dynamic user instructions run during approval resume.
-
efa0869: A
ctx.ask()question now resolves the way the session decided it: an answer that reached the session before its withdrawal resolves the ask asanswered, even after the signal aborted, soask_questionand the channel never disagree. Cancelling atask()also reports its pending questionscancelled, and questionrequestIds are now<runId>-ask-<n>instead of an internal hook token. -
a402836:
authorization.requiredandauthorization.completedevents now includeprincipalId, the session principal who started the sign-in, using the same value asresponderPrincipalIdon approval events. Candidate sign-in events also now include theirattemptId. -
e9dd418: Add an optional
fallbackmodel toautomodel routing. When the evaluation model fails, eve now uses the configured fallback for the rest of the turn while preserving cancellation behavior. -
c8d38a8: Cancelling a turn no longer erases the tool calls it was waiting on from the model's history. Each one stays, answered as cancelled, so in the next turn the model sees that the work was started and stopped instead of redoing a request that looks unanswered.
-
ce14b1e:
defineChannelevent handlers can now subscribe tostep.completed, the same event hooks receive when a model step finishes. -
cd3f263: Include channel kind and origin on agent step spans so traces can be classified while a turn is still running or waiting for input.
-
aa73bcb: Trace viewers now use the GenAI system-instructions attribute instead of recording a duplicate system prompt attribute.
-
4902e93: The
eveCLI now finishes writing stdout and stderr before it exits. A parent process that reads large output through a pipe, such aseve info --jsonfor an agent with many tool schemas, now receives the complete output instead of output cut off partway through. -
f0a9ee1: The Datadog reporter now records eval content by default and reuses one dataset across runs, so experiments can be compared in Datadog.
-
47c2844: eve now defaults to
openai/gpt-6-luna-fastwith high reasoning when no model is configured, including newly initialized agents; explicit model and reasoning selections remain unchanged. The terminal UI shows compact model labels with dot-separated reasoning and a⚡︎speed marker in place of a trailing-fastsuffix. -
a9da46c: Delegated agents again share and count against the parent's session token and cost budgets: agent tasks started in the same model step split the parent's remaining quota, and delegated usage, including remote agents and nested subagents, counts toward the parent's
maxInputTokensPerSession,maxOutputTokensPerSession, andmaxTokenCostUsdPerSessionand the usage the parent reports. An agent task's usage counts with each reply and when a cancelled turn ends; other workflow tools'ctx.agentusage counts when the tool replies or finishes. -
8149c72: The Braintrust and Datadog reporters now report one score per assertion name, the lowest, instead of numbering repeats like
judge_boolean_2. -
4b195e9: Add
eve/server, whosesessions.attach(sessionId).stream({ startIndex, follow, signal })reads a session's durable event stream in process from hooks, tools, schedules, and channel routes, with the same shape as the client and no HTTP round trip. -
21e11d0:
eve devnow reaches a ready server about 40% sooner. The bundled self-modification extension no longer re-bundles eve's internals for each module it loads, and dev builds no longer re-parse large output chunks. Installing eve also no longer reportsnpm auditadvisories forundici, which is now 8.10.2. -
e0dd11e: Fix imports of
eve/extensions/code/sandboxfrom ES module consumers when bundled Connect dependencies include CommonJS code. -
0afae69: Restore completed-turn memory capture by providing memory providers with the settled conversation history.
-
f9c785f: When a target deployment cannot read the session checkpoint version, validation returns incompatibility instead of throwing so Workflow no longer retries the step. The turn is processed on the current owner immediately.
Owners running this eve build remember every deployment that reported incompatibility and skip handoff to those targets for later turns in the same run. Sessions whose owner workflow started on an older build still attempt handoff each turn, but each attempt no longer triggers validation retries on the target.
-
5181b14: Approval response policies now receive
request.principal, the person whose turn requested the call, so a policy can let only that person approve it in a shared conversation. It isnullwhen the caller was unauthenticated or anonymous. -
7869f50: Inbound Slack messages now go through the public
from(address).send(), so a route wrapper that replacessendsees every inbound message and receives delivery failures as errors. Channelsend()also forwards itsstateoption to thedeliverhook aspayload.stateon every delivery, asrespond()already did. -
7869f50:
eve info --jsonnow includestoolInputSchemas: each static tool's input schema, for the root agent and each declared subagent, in the form eve sends to the model. Subagent entries are keyed by their path from the root agent, such asforecaster/reviewer, so nested subagents that share a name each get their own entry.eve/toolsalso exportsserializeModelInputSchema(schema), which returns that JSON Schema for any tool input schema, so checks no longer need to read.eve/build output. -
7869f50:
eve/schedulesnow exportsisScheduleAuth(auth), which returnstruefor the app principal that schedules pass asappAuth. Use it to tell the agent's own scheduled work from a user's turn without copying eve's internal principal values. -
e6c90d0: Keep slash-command suggestions visible after a command name is fully typed, so the matching command and its description remain visible alongside any inline argument hint.
-
7a33f37: Isolate extension module instances and configuration per logical mount, including directory overrides and their subagents, while preserving asset imports and extension-owned dependencies. Durable extension state still uses package-scoped keys.
-
0e0fa1b: Record canonical logical mount identities in compiled extension metadata and contribution ownership. Flat and directory mounts share an identity, while mounts in different subagents retain distinct paths; this does not yet change extension configuration or state isolation.
-
c8d38a8: A
servetask'sctx.reply()that answers several calls, such as an agent's reply to a message and its correction, now settles them together:task_waitno longer reports the task as both done and still working, and the model receives the reply once instead of once per call. Each call still gets its owntask.settledevent. -
c8d38a8: A model response that mixes AI Gateway
web_searchresults with local tool calls such asweb_fetchno longer breaks the next model call. eve kept a local call ahead of a later search result, so Anthropic rejected the history with "tool_useids were found withouttool_resultblocks" and the turn failed. -
e0ad9a0: Agents using AI Gateway web search no longer claim on the next turn that they answered before searching. When a reply continues after a search result in the same model call, eve now stores that text as its own assistant message, so AI Gateway replays it after the result instead of before the search.
-
cd13d12: The initial
eve devcomposer now suggests concrete changes you can ask your agent to make, based on its instructions and capabilities. Fresheve initagents get the customization hint even when scaffolded channels expose workflow webhook routes; agents with an added channel keep the minimal “Send a message…” placeholder. -
631122f: The
eve devterminal UI now hides Workflow SDK output such as[workflow-sdk]lines unless/loglevel allis on; the diagnostic log still records every line. eve also no longer warns with "Step execution already in flight in this process" when a queued step delivery loses a normal race with a new inline step. -
23dc0da: A remote agent on this release now serves callers on eve 0.66 through 0.68 instead of rejecting them with
REMOTE_AGENT_PROTOCOL_MISMATCH, so you can upgrade remote agents before the deployments that call them. Those callers' turns, results, follow-ups, and resets work as before, and the remote agent's tool approvals and sign-in requests still reach the caller and accept its answers. -
b0b975b: Remote subagents inherit the parent's human-input capability and forward questions and authorization requests through the parent channel, including concurrent workflow questions. Trusted remote receivers can read the replay-stable invocation operation ID in
onMessage. -
e005932: Traces no longer give each
ctx.agent()call in a workflow tool its ownagent.actioncaller span, and a workflow tool that calls agents stays anagent.actionspan instead of becominginvoke_workflow <tool>withgen_ai.workflow.name. Sessions opened withctx.agent()now link to the calling tool'sagent.actionspan, and their usage no longer appears on a separate caller span; it still counts toward the parent session's usage. -
ba96305: Include provider-reported
costUsdalongside token counts on terminal subagent action instrumentation events and spans. -
7e4ceb8: The self-modification
registry_addtool no longer pauses for approval before installing an official registry item. It now refuses items that would replace the self-modification subagent's own mount, andsearch_registryhides them. -
cd8fb87: The self-modification subagent no longer tries to install
eve/self-modificationwhen asked to change the agent's own instructions. To change the subagent's own model or reasoning, it now creates or editsagent/extensions/self-modification/extension.tsdirectly. -
e167dd3:
ctx.reply()in aserveworkflow tool now withdraws thectx.ask()questions still pending for the calls it settles, so they resolve ascancelledand channels stop offering them. Before, such a question stayed pending after its call had a result: it kept steering from interrupting a model step and could take the person's next plain message as its answer. -
99b4166: Session workflow steps now return only the session state they changed, and the workflow applies that change to the state it passed in. Each step used to return a full copy of the session, so stored step output and the data a workflow replay reads grew with conversation length on every step; they now grow only with what each step changes.
-
138e3b1: The Shopify integration setup now scaffolds a UCP agent profile for protocol version
2026-08-25, withspecandschemadeclared on every capability. -
8d6cd3e: Slack now sends sign-in challenges and approval feedback privately to the Slack user behind the event's principal, not to whoever spoke last in the thread. Channel state replaces
approvalResponderUsersandpendingApprovalCandidateUserswith a singleslackUsersByPrincipalmap. -
7869f50:
eve/channels/slacknow exportsrenderInputRequestBlocks,deriveHitlResponse, andHITL_ACTION_PREFIX, with theSlackHitlAction,DerivedHitlResponse, andSlackHitlRoutetypes. Apps can render eve's HITL Block Kit controls and decode clicks on them without importing from eve's build output. -
79fa2aa:
task.settledfor a cancelled call now carriescancel.reason:"task_cancel"when the model calledtask_cancel,"turn_cancelled"when someone cancelled the turn, or"turn_ended"when the turn ended while the task still worked. The Slack task card uses it: a task the model cancelled now shows a success check andStopped early since it was no longer needed, and other stopped tasks say why, such asStopped by requestorStopped when the turn ended. -
ce19751: The Slack task card now shows how long each task took, as in
Done in 1m 14s: Found three incidents.orFailed after 3m, and the finished plan title includes the turn's total time. A plan whose tasks are all subagent or remote agent calls names them, as inAsking researcher and reviewerorWaiting on reviewer · 1 of 2 tasks done. The card also keeps oneblock_idfor the whole turn, so rows a reader expanded can stay open as the card updates. When a turn you keep messaging starts new tasks after its earlier ones settled, eve marks the earlier card finished and posts a new card instead of updating the old one further up the thread. -
47c2844: Clarify that
task_waitshould be called sparingly, only to deliberately withhold a user-facing reply while waiting for a task result. Tasks keep running and their results reach the model without an explicit wait. -
7869f50: Spreading a channel into a new object with replaced routes, such as
{ ...slackChannel(), routes }, now keeps its build metadata, so the Slack app manifest and Vercel Connect credentials still reach the build. The custom channels docs now describe wrapping an existing channel's routes as supported. -
e5d45dd: A message that steers a turn right after a tool call, such as a question sent while a task works, now gets answered on Anthropic models. Before, the message reached the model in the same turn as the tool results, and Claude often treated it as tool output and kept waiting on its tasks without replying.
-
e0ad9a0: A message that interrupts a waiting tool call, such as a
sleeportask_wait, no longer also interrupts the step that reads it. The stream no longer emits a straystep.startedwith no model call before the step that answers the message. -
c8d38a8: Channel activity, such as Slack's activity message, now shows a call to a task as running from its receipt until the task settles, then marks it completed, failed, or cancelled. Before, the receipt marked the call done as soon as the task started.
-
c8d38a8: The task system prompt now tells the model it can reply before a task's result when it doesn't need the result yet. Its turn stays open and it gets the result when the task finishes, so a person who says there's no rush gets a reply right away. A question asked while tasks work is now answered before the model waits again.
-
67ae5b5: A question or approval that a task run or workflow tool call relays, from its own
ctx.ask()or from a session it opened withctx.agent, now emitsinput.resolvedwithoutcome: "cancelled"when that run finishes before anyone answers. Every question or approval a session relays does the same when the turn is cancelled. Previously these requests were dropped silently or left in place, so channels anduseEveAgentUIs kept offering them even though no answer could reach anyone. -
7869f50:
task.settledevents now carry the task's toolnameandkind, the same values as on the call'stask.started, so clients and hooks can label a settled task without tracking its start. Events recorded by earlier versions omit both fields. -
ce14b1e: Models now get clearer task guidance: call
task_waitwhen there's nothing to say until a result arrives, reply when the person should hear something first, and in child and schedule sessions wait instead of replying.task_waittakestimeoutSecondsinstead oftimeoutin milliseconds,task_cancelanswers in plain text, and receipts and failed agent results tell the model what happens next. -
50afc41: Allow
eve remote infoto inspect deployments that report retired kernel-effect options, marking those options as unrecognized instead of rejecting the agent-info response. -
ed2c04b:
ToolContextnow exposesmessages, the model input for the step that requested the call, so tools can evaluate the conversation that led to them without recording it separately. It matches thectx.messagesdynamic resolvers receive atstep.started. -
5a5561a: Tools can now end a turn without a reply. Set
endsTurn: trueon adefineTooltool whose action is the whole answer, such as a reaction: once every call in the model's step succeeds, the turn completes with no final message, so channels and schedule sends post nothing. Withtrue, eve appends a sentence to the tool's model-facing description saying the call ends the turn; pass a function instead to decide from theexecuteoutput. The new opt-inno_replytool (eve add tool/no_reply, ornoReply()fromeve/tools/no_reply) uses it to let the agent stay quiet, for example when a scheduled check finds nothing to report. Slack now clears its thread status when a turn completes. -
f442363: System instructions now remain available in traces when JSON encoding would otherwise push them over the span attribute size limit.
-
d09e381: The
eve devTUI now labels the self-modification subagent asagent editorinstead of its raw tool name,self-modification__agent, and the turn bar reads "Modifying your agent" while it works. -
315b353: The
eve devterminal UI now shows each task, such as a subagent call, as one line when it starts and one when it finishes, fails, or is stopped, with a panel above the prompt showing what every working task is doing. The transcript no longer jumps or rewrites while tasks work, the model's owntask_waitandtask_cancelcalls no longer appear in the terminal UI or Slack typing indicators, and tools with alabelshow it instead of their raw arguments. -
e0ad9a0: The
eve devterminal UI now shows text the model writes after a provider-executed tool such as web search in the same model call. Before, the answer after a search was dropped from the transcript even though the agent sent it. -
bb70743: Workflow tools now wait for approval before starting, and calls denied by a person or policy never run. An approved workflow starts when it is approved.
-
efa0869: A workflow tool's
action.partialupdates now reach the channel adapter, stream-event hooks, and instrumentation, like the events a turn publishes, and theinput.resolveda session emits when a question raised inside a call is answered or withdrawn now reaches the channel adapter and stream-event hooks. Both were previously written only to the session stream.