Minor Changes
- 9de88f7: Split self-modification into separate
eve/self-modification/localandeve/self-modification/remotemounts, soeve devno longer loads deployed sandbox dependencies.eve/self-modificationremains an alias for the local mount and now rejects thedeployedoption; move that configuration to its own mount, for exampleagent/extensions/self-modification-remote/extension.ts, with the formerdeployedfields at the top level.
Patch Changes
-
a549cb6: Enable Workflow stream-writer WebSockets for eve's Vercel world. The upgraded SDK disposes released and aborted writer sessions, and falls back to HTTP when the server declines a WebSocket upgrade.
-
83b97e6: Chat SDK channels now send a sign-in started in a shared thread to the person signing in, as an ephemeral message or a direct message, and show a link-free status in the thread. Adapters that support neither still post the existing "continue in a direct message" notice.
-
7c60065: Discord button presses, selects, and modal submissions now answer as the Discord user who made them instead of anonymously, so requester-only and other approval response policies work on Discord. The new
onInputResponseoption ondiscordChannelchooses an answer's auth or drops it, and its context carries the presser'sdefaultAuth. Apps with a customonCommandmust also setonInputResponse; until they do, eve drops presses and logs a warning. -
90972b6: Start the first model call without waiting for session-title metadata persistence, while still completing the title write before the durable turn step finishes.
-
933996c:
invokeToolnow accepts akey: calls from the same caller with the same key share one session id and keep their sandbox between calls, on Vercel Sandbox and just-bash.mcpChannel({ tools: true })advertises thedev.eve/tool-sessionsextension, so MCP clients that declare it can join a tool session with_meta["dev.eve/tool-session"]. A forwarded caller's session also covers the verified forwarder, passed asinvokeTool'sforwardedBy(mcpChannelpasses the router itsauthverified), so one user reached through two routers gets two sessions. Tool sessions need an authenticated caller: a keyed call from the anonymous principalnone()gives is denied. On Vercel Sandbox, a tool session's saved filesystem expires a day after its last use, so the next call with the key starts a fresh sandbox; a deploy that changes the agent's sandbox definition also starts a fresh sandbox for each key. -
279e2b6:
mcpChannel({ skills: true })serves the agent's skills as SEP-2640 skills underskill://, with each file's size and SHA-256 digest. Files are served byte for byte, except that aSKILL.mdwithout conformingnameanddescriptionfrontmatter is served with generated frontmatter. Channel routes also getlistSkillFiles(skill), which lists a skill's files with their sizes, andreadSkill(skill, path?), which returns one skill file's bytes;describe()lists each skill's name and description.Production builds now ship skill files as eve-owned server assets and drop Nitro's default
serverasset entry, which bundled the app'sassets/directory. An app that readassets:serverstorage in production finds it empty; eve reads only its own asset bases. -
866cb41: Tools published with
mcpChannel({ tools: true })can now run as the user a trusted caller forwards. SettrustedForwarderson the channel to accept theeve-forwarded-principalheader, andforwardPrincipal: trueon adefineMcpClientConnectionto send the turn's user to another eve agent. A channel withouttrustedForwardersrefuses requests carrying the header with403.invokeToolalso accepts aninitiatoroption. -
282802a: Reduce new-session startup latency by overlapping session creation with timeout startup and first-turn cancellation and steering hook registration after inbox ownership is ready.
-
64301d1: Remote evals now resolve Vercel deployments using the owner and project from the environment or local project link, allowing protected deployments owned by a different team than the CLI's current team. Ambient credentials are withheld when the deployment does not match the expected project.
-
f8bf204: Add the Sanity MCP integration to the registry. Use
eve add connection/sanityto connect an existing Sanity account through Vercel Connect OAuth. -
0d6e2e2:
eve addandeve registrynow use@shadcn/registryinstead of the fullshadcnCLI package. The vendored registry bundle shrinks from 9.7 MB to 3.8 MB, and registry items install the same files, env vars, and dependencies as before. -
3c8919a: Slack
onInteractionactions now includetriggerId, so a button on a message can open a modal withviews.open. -
17d5b11: When a turn waits on several questions or approvals, a typed reply now answers the first open one instead of none, so people can answer them one message at a time. Twilio, GitHub, Linear, and Chat SDK channels (including Linq and Photon) show one prompt at a time and post the next once it is answered. An approval raised alongside a workflow tool call such as
ask_questionis now requested after that call finishes, since it can't take effect before then.On Twilio, GitHub, and Linear, the built-in prompt queue spans the
input.requested,input.resolved, andapproval.settledhandlers. If you override any one of them, override all three, or the built-in handlers will post prompts twice or stop posting later ones. If you render prompts yourself frominput.requested, makeinput.resolvedandapproval.settledno-ops. -
7f559ac: The TUI now prints a connection sign-in URL on its own line and makes every wrapped row an OSC 8 hyperlink to the full URL, so Cmd-clicking the link opens the whole URL in a narrow terminal.
-
17d5b11: Typing
approveorcancelnow answers a tool approval that has anapproval.responsepolicy. The policy checks the person who typed the reply, just as it checks someone who presses a button. Before, the reply reached the model as an ordinary message and the approval stayed pending.