github vercel/eve eve@0.73.0

4 hours ago

Minor Changes

  • 9de88f7: Split self-modification into separate eve/self-modification/local and eve/self-modification/remote mounts, so eve dev no longer loads deployed sandbox dependencies. eve/self-modification remains an alias for the local mount and now rejects the deployed option; move that configuration to its own mount, for example agent/extensions/self-modification-remote/extension.ts, with the former deployed fields at the top level.

Patch Changes

  • a549cb6: Enable Workflow stream-writer WebSockets for eve's Vercel world. The upgraded SDK disposes released and aborted writer sessions, and falls back to HTTP when the server declines a WebSocket upgrade.

  • 83b97e6: Chat SDK channels now send a sign-in started in a shared thread to the person signing in, as an ephemeral message or a direct message, and show a link-free status in the thread. Adapters that support neither still post the existing "continue in a direct message" notice.

  • 7c60065: Discord button presses, selects, and modal submissions now answer as the Discord user who made them instead of anonymously, so requester-only and other approval response policies work on Discord. The new onInputResponse option on discordChannel chooses an answer's auth or drops it, and its context carries the presser's defaultAuth. Apps with a custom onCommand must also set onInputResponse; until they do, eve drops presses and logs a warning.

  • 90972b6: Start the first model call without waiting for session-title metadata persistence, while still completing the title write before the durable turn step finishes.

  • 933996c: invokeTool now accepts a key: calls from the same caller with the same key share one session id and keep their sandbox between calls, on Vercel Sandbox and just-bash. mcpChannel({ tools: true }) advertises the dev.eve/tool-sessions extension, so MCP clients that declare it can join a tool session with _meta["dev.eve/tool-session"]. A forwarded caller's session also covers the verified forwarder, passed as invokeTool's forwardedBy (mcpChannel passes the router its auth verified), so one user reached through two routers gets two sessions. Tool sessions need an authenticated caller: a keyed call from the anonymous principal none() gives is denied. On Vercel Sandbox, a tool session's saved filesystem expires a day after its last use, so the next call with the key starts a fresh sandbox; a deploy that changes the agent's sandbox definition also starts a fresh sandbox for each key.

  • 279e2b6: mcpChannel({ skills: true }) serves the agent's skills as SEP-2640 skills under skill://, with each file's size and SHA-256 digest. Files are served byte for byte, except that a SKILL.md without conforming name and description frontmatter is served with generated frontmatter. Channel routes also get listSkillFiles(skill), which lists a skill's files with their sizes, and readSkill(skill, path?), which returns one skill file's bytes; describe() lists each skill's name and description.

    Production builds now ship skill files as eve-owned server assets and drop Nitro's default server asset entry, which bundled the app's assets/ directory. An app that read assets:server storage in production finds it empty; eve reads only its own asset bases.

  • 866cb41: Tools published with mcpChannel({ tools: true }) can now run as the user a trusted caller forwards. Set trustedForwarders on the channel to accept the eve-forwarded-principal header, and forwardPrincipal: true on a defineMcpClientConnection to send the turn's user to another eve agent. A channel without trustedForwarders refuses requests carrying the header with 403. invokeTool also accepts an initiator option.

  • 282802a: Reduce new-session startup latency by overlapping session creation with timeout startup and first-turn cancellation and steering hook registration after inbox ownership is ready.

  • 64301d1: Remote evals now resolve Vercel deployments using the owner and project from the environment or local project link, allowing protected deployments owned by a different team than the CLI's current team. Ambient credentials are withheld when the deployment does not match the expected project.

  • f8bf204: Add the Sanity MCP integration to the registry. Use eve add connection/sanity to connect an existing Sanity account through Vercel Connect OAuth.

  • 0d6e2e2: eve add and eve registry now use @shadcn/registry instead of the full shadcn CLI package. The vendored registry bundle shrinks from 9.7 MB to 3.8 MB, and registry items install the same files, env vars, and dependencies as before.

  • 3c8919a: Slack onInteraction actions now include triggerId, so a button on a message can open a modal with views.open.

  • 17d5b11: When a turn waits on several questions or approvals, a typed reply now answers the first open one instead of none, so people can answer them one message at a time. Twilio, GitHub, Linear, and Chat SDK channels (including Linq and Photon) show one prompt at a time and post the next once it is answered. An approval raised alongside a workflow tool call such as ask_question is now requested after that call finishes, since it can't take effect before then.

    On Twilio, GitHub, and Linear, the built-in prompt queue spans the input.requested, input.resolved, and approval.settled handlers. If you override any one of them, override all three, or the built-in handlers will post prompts twice or stop posting later ones. If you render prompts yourself from input.requested, make input.resolved and approval.settled no-ops.

  • 7f559ac: The TUI now prints a connection sign-in URL on its own line and makes every wrapped row an OSC 8 hyperlink to the full URL, so Cmd-clicking the link opens the whole URL in a narrow terminal.

  • 17d5b11: Typing approve or cancel now answers a tool approval that has an approval.response policy. The policy checks the person who typed the reply, just as it checks someone who presses a button. Before, the reply reached the model as an ordinary message and the approval stayed pending.

Don't miss a new eve release

NewReleases is sending notifications on new releases.