New features
- audit record every LLM request on every surface in the audit trail #1448 · a4a6fac
- cache explicit Gemini cache resources, storage pricing and auto TTL #1451 · b719cfa
- cache rolling conversation breakpoint, extended TTL and cache telemetry across providers #1442 · 4ec16b3
- compaction session threshold, dedicated summarizer, tool-catalog reserve and repeated-read dedup #1445 · 144e02c
- config organization-managed defaults and locked policies #1456 · e360582
- context compaction hooks, verbatim-safe levels, summarizer accounting, 1h cache TTL on Bedrock/OpenRouter #1460 · d1e77cc
- context incremental re-index with file stamps, /context refresh and /context watch #1455 · c969c28
- context live context inspector and learned chars-per-token calibration #1443 · fa0dfb2
- context persist the token calibrator per state root and route every estimate through it #1462 · 6c22c4b
- context prefix budget allocator, projected ctx%, /clear conversation semantics #1453 · 445263d
- gateway per-principal store sets under hub isolation #1450 · 6b46d74
- gateway tenant-scoped park and task-graph roots and a per-tenant daily budget #1467 · 7ead7fc
- knowledge opt-in lexical normalization, fact IDF, local embeddings with cost, retrieval budget and citations #1465 · 2a40a7b
- memory export/import, multi-process merge for profile/topics/projects, recall reasons and project labels #1464 · a2b9b95
- memory pluggable memory provider and context engine through MCP #1457 · 8adc9c5
- memory vector-aware auto-recall with a relevance floor and session-persisted context attachments #1447 · 311cf1a
- retention expire park and cost snapshots on the session TTL and show every store’s policy #1449 · 09a4a6a
- retrieval rerank stage, corpus weights, structure-aware passages and evidence-based recall #1452 · 41b267b
- security encryption at rest for memory, contexts, CCR and costs, key rotation and a hash-chained audit trail #1466 · 442b2e6
- session append-only transcript journal and memory flush before compaction #1446 · 0c34ce0
- session undo compaction, persisted rewind checkpoints and transcript export/search #1461 · 909f050
- telemetry OpenTelemetry metrics export over OTLP/HTTP and a provider-side context engine #1468 · 6a0e12b
- tokens provider token counting on every surface, exact calibration and budgeted summaries #1454 · 19d57ac
- workspace nested AGENTS.md hierarchy with imports, nested watch dirs and legacy source paths #1463 · 607a41c
Fixes
- agent follow the @model route in delegation and never report an empty worker as success #1440 · c965332
- agents workers share the orchestrator’s compactor, overflow recovery and journal #1490 · ef08a6b
- cache provider cache parity — Bedrock system marker TTL, GPT-5.5 retention, cache key on OpenAI-compatible upstreams, OpenRouter marker cap #1479 · 1545c42
- claudeai surface SSE error events and decode br/zstd responses #1458 · edc1148
- config registry, reload and surface truth — missing defaults, reloadable variables, /config memory rows, /help lines, completer entries, sections hint from the router, dead code #1494 · 64a50d5
- context byte-stable system prompt with per-turn context as a flagged user message, stable cache key, frozen prefix ratio #1470 · 136526d
- context cache-stable prompt prefix, reversible guided compact and fsync durability #1438 · 339cd79
- context close the P0 gaps of the second context audit #1459 · a026988
- context mirror provider context edits locally — stub cleared tool results, skip calibration, note the rebuild, surface freed tokens #1483 · cd30482
- context recover from context overflow on chat, RPC, one-shot and MoA; classify every provider’s overflow body; per-session recovery budgets #1477 · fd84ffe
- context single context estimate and window-scaled retrieval budget #1485 · 0d00f9c
- context verbatim results survive pairing, verbatim cap for convergence, skipped-compaction bookkeeping, shared restore helper #1472 · 821638c
- cost attribute usage to the call that produced it — summarizer, memory worker, streaming, Gemini thinking, provider resets #1473 · fc96fa9
- cost cache telemetry truth — subset-schema total misses, per-provider first and hit ratio, expected rebuilds on every prefix change, Bedrock TTL as sent #1481 · a11449d
- cost long-context tiers per call, Amazon Nova rows, Copilot as a subscription #1491 · ca39638
- cost reset clears every aggregate, daily-aware budget notices, summarizer cache keyed by env, locked audit path fails closed #1488 · c4e8103
- cost telemetry semconv and opt-in session series, embedding and daily-budget metrics, CSV export, spend finalized on every surface, park on hard stop #1496 · 78106ac
- gateway swap every per-conversation state with the tenant, guard the base memory worker, tag external memory calls, keep the workspace on queued segments #1474 · 42695ff
- knowledge batched, single-flight embedding with skip-and-continue; binary/minified skip; passage hard cap; partial upsert persistence; rune-safe cuts #1478 · c5946f2
- knowledge hybrid retrieval as a vector-BM25 union fused by RRF, query embedded once per turn, system-only tagged reranker #1486 · 381bfdd
- memory cross-process lock around every merge-and-write of the shared stores #1489 · 0b3ae15
- memory drain the queued backlog at boot and on every tick, bounded shutdown wait, exit-tail queueing, race-free watermark #1480 · b156159
- memory fence recalled and retrieved text as data, keep injected blocks out of extraction and search, sanitize and validate stored facts #1482 · a95c760
- memory hygiene batch — rune-safe cuts, test-only helpers out of production, CCR skip surfaced, coder read line cap, transcript cap and plaintext notice, isolation refusal, external-only memory provider, worktree-aware projects #1495 · 75b8f98
- memory lock sealed stores read-only when the key is missing, keep daily notes plain, seal and redact the pending queue #1469 · 8065549
- security at-rest v2 — payloads bound to their store and tenant, passphrases stretched, fsync on reseal, 16-byte tenant digest, 0700 dirs #1493 · 47a3f50
- security encrypt session stores at rest and redact secrets on the LLM path #1441 · a90e35b
- security never hand ChatCLI’s own secrets to MCP servers and executable plugins #1475 · 495a713
- security persisted-data hygiene — strict-policy redaction on every store, sealed REPL history, missing secret shapes, periodic tenant retention #1484 · ab1f286
- security share one locked, rotating, sealable audit chain across the REPL, gateway and gRPC server #1476 · 39c469d
- session exact schema gate, fork on its own journal with attachments, cost and CCR references, atomic state writes #1487 · b3a5110
- session journal integrity — full-prefix hash scan, tool-call-aware hashes, torn-line tolerance, no tail dedup #1471 · d52634f
- ui footer shows used context apart from the answer reserve #1497 · 14df167
- workspace instruction-file parity — import boundary and per-file cap, global always merged, local and override files, .claude/rules, watched-dir cap with .gitignore #1492 · f75aaf1
Newer release: v1.196.1
a reload keeps what the client provided and reaches the servers; environment file discovery for editor-spawned servers and Bedrock profile parity
Previous release: v1.195.0
list the models the account can invoke via the Devin CLI