What's new in Codelit.io
Plans, architectures, and Agent Teams now open inside the Thread
Select a generated artifact to inspect it, edit it with the full visual workbench, save a new version, or return to the conversation without navigating to another builder.
Agent Team proof stays attached to the design
Safe runs, progress, approvals, terminal and browser evidence, failures, and the final receipt appear chronologically in the same Thread while the focused Agent Team view remains available on demand.
Artifact state stays with its exact Thread and route
Local and cloud versions now require matching Thread ownership, and Product Plan, Architecture, and Agent Team links clear stale editor state before loading another shared artifact.
Specialists start real work from the homepage
Claude Code, Browser QA, Hermes, and OpenClaw now open their proven Agent Teams directly from the composer without spending a model call to rediscover the workflow.
One composer reveals specialists and actions
Type @ to choose a specialist or / to choose Product Plan, Architecture, Agent Team, browser, proof, schedule, or Plan & Ship. Codelit previews the selected path and its safety boundary before the Thread starts.
Completed work suggests the useful next move
Thread results now offer a few contextual continuations such as mapping architecture, adding Browser QA, running a safe proof, or preparing Plan & Ship while keeping the full composer available.
The homepage starts as a focused conversation
A larger centered composer keeps Product Plan, Architecture, and Agent Team suggestions close at hand. The suggestions disappear as soon as someone types and return when the message is cleared.
The composer moves with the conversation
The input begins in the middle of an empty desktop or phone workspace, then settles at the bottom while a new Thread starts. The rounded composer remains solid while the surrounding workspace stays clear.
Every new request receives its own Thread
Submitting from the lightweight homepage opens a dedicated Thread URL without putting the prompt in the address. Generated plans, diagrams, Agent Teams, follow-up messages, and saved Project placement continue there.
The heavy builders stay out of the homepage
Product, Architecture, and Agent Team engines now load inside the Thread that needs them. The homepage ships about 252 KiB of initial JavaScript with no Firestore or animation runtime, protected by a tighter bundle budget.
Three starting paths stay in focus
Product Plan, Architecture, and Agent Team are the only links beneath the composer. Claude Code, Browser QA, Hermes, OpenClaw, and advanced actions remain available through chat, @, and / without crowding the empty workspace.
Signed-out navigation stays useful and unobtrusive
Plans and pricing, Settings, and Help stay at the bottom of the sidebar. Terms and Privacy sit quietly below the launcher, while optional analytics consent now appears at the bottom instead of competing with the headline.
The homepage starts with one outcome
Codelit now routes one message to the right Product Plan, Architecture, Agent Team, or Plan & Ship path without asking people to choose a builder first.
Projects and Threads stay beside the conversation
The desktop sidebar opens by default without covering or disabling chat, remains independently collapsible, and keeps local drafts and saved Project work in one compact hierarchy.
Specialist edits return to the exact Thread
Every generated artifact keeps versioned history. Product Plan, Architecture, Agent Team, and Plan & Ship editors return direct changes and runs to the originating conversation without duplicating canonical work.
Safe proof stays inside the conversation
Agent Teams can complete a zero-write proof, pause for an inline approval, and preserve a redacted receipt without navigating away or hiding earlier work.
Conversion is measurable without storing prompts
Codelit's first-party analytics now distinguishes routing, correction, artifact creation, editor engagement, proof, own-data connection, managed intent, and Stripe-confirmed subscription using bounded fields and private internal references.
The simpler homepage ships less JavaScript
Retiring the old mode selector, prompt catalogs, promotional shell, and animation runtime reduced initial homepage JavaScript by more than 20% while keeping every specialist editor available on demand.
Use my repository discovers open issues
The first personal proof and an ordinary Live Run now share one GitHub issue picker. Codelit lists current open issues from the selected repository instead of asking for a raw issue number.
Empty repositories have an exact next step
When a repository has no open issues, the proof stays stopped and explains how to choose another repository, create an issue in GitHub, or refresh the current list. A stale issue selection cannot continue silently.
Mobile workspaces keep navigation and chat in place
Agent Teams, Product Plans, and Architecture boards now keep the top navigation and bottom composer fixed to the phone viewport while the work between them scrolls independently.
Run proof stays readable on narrow screens
Compact run summaries keep status and time visible without wrapping details over themselves. The complete duration, approval, and cost record remains available to assistive technology and wider layouts.
Trial status never exposes an empty countdown
A missing or delayed trial end date now falls back to a clear active-trial state and a Manage trial action instead of displaying a null day count.
Release proof is easier to scan
The Showcase now presents planning, approval, and verification as one restrained proof sequence that stays clear on desktop and phone.
Slack setup proves notification access
New connections retain the exact scopes Slack granted. Older connected workspaces verify those scopes on the next setup check, so an approved channel delivery becomes ready only when chat access is genuinely available.
Proof setup reuses the resource you selected
Choosing a GitHub repository, Slack channel, Vercel project, or another connected scope now fills the matching run input and removes the duplicate question. Remaining case details stay visible and editable.
Browser capacity failures keep the task ready
Brief secure-browser capacity windows retry once automatically with the exact saved task. Longer outages preserve the provider boundary, confirm that no browser change or usage settled, and offer a safe retry without sending users into unrelated tool setup.
Live setup and provider capacity stay distinct
Agent Teams now say Live configured when tools and run setup are complete. The launch review labels browser time as a Codelit plan allowance and explains that secure-browser capacity is reserved at start, so a temporary provider refusal cannot look like spent or missing plan time.
Safety decisions stay held, not failed
Denying or editing a reviewed action now records the run as Held in Activity, preserves completed proof, and stays out of reliability-failure reporting. Provider and model failures remain clearly separate and retryable only when safe.
Finished sample runs stay finished after reload
Sample links still start the first proof automatically, then consume the one-time launch request. Reloading after Hold or Deny no longer starts a new run that looks like the reviewed decision was undone.
Ask Codelit explains the whole active run
A question about what happened, what remains, and what approval will do now returns one concise status naming completed work, the exact held step, later work, and the approval boundary.
Compound Team edits reuse connected tools
A request such as adding an approval before Browser QA and delivering the final result to Slack produces one reviewable plan. Existing Slack delivery is reused and protected instead of duplicated.
Stop owns planning from the first click
The composer becomes busy immediately while setup and Team changes are checked. Stop cancels that shared planning lifecycle before a late result can replace the current Flow.
Advanced repair code waits for intent
Preset catalogs and launch-readiness repairs now load only when opened, leaving more bundle headroom while preserving every advanced control.
Upgrade returns to the exact pending run
Codelit keeps the account-bound Agent Team, Project, Team, Thread, and managed-run intent through subscription or Execution Pack checkout. A successful return resumes that work once without putting private source details in the URL.
Paid completion comes from Stripe
Subscription payment and Execution Pack completion are recorded on the server with one stable purchase identity. Browser refreshes, webhook retries, and out-of-order events cannot create duplicate paid outcomes.
Billing changes preserve current truth
Trial conversion, plan downgrade, cancellation, failed payment, and recovery now recheck Stripe before changing access. A delayed old checkout cannot replace a newer active subscription, and managed-run capacity remains visible before purchase.
Agent Teams can roll back without a deploy
An admin can restore compatibility discovery from one revision-checked control. The page cannot flash the wrong variant while it loads, Plan & Ship remains available, and saved Teams, runs, connections, approvals, receipts, and runtime permissions remain untouched.
Stopped runs return to the exact Team card
The stopped-run rail stays transparent around its solid rounded status and chat cards. Fix now opens the held step and its inline controls, while Retry remains a separate fresh-run choice.
Agent Team controls work across keyboards and mobile browsers
Team cards now open their complete action menu with Shift+F10. Reduced-motion preferences stop nonessential workspace animation, while touch, reflow, refresh, reconnect, and slow-loading journeys stay usable in Chromium and mobile WebKit.
Agent Team outcomes are measurable without storing the work
Codelit now measures command completion, chat coverage, blocked-run recovery, repeat use, and paid managed intent from fixed status fields. Prompts, URLs, provider payloads, resource names, and credentials stay out of product analytics.
Adding Team parts follows the same command history
Advanced presets, saved Library Skills, triggers, model routes, rules, evaluations, and harnesses now use validated Team commands. The selected item opens for review and the accepted change remains visible in Activity.
Removing an item cleans up its Flow references
A reviewed removal uses the item's stable identity, clears related tool access and step handoffs, and stays removed after reload. The last teammate remains protected so a Team cannot become unrunnable by accident.
Tool settings save through one auditable path
Browser Operator, connected-app, provider, custom-action, and GitHub Actions settings now use the same validated Team command as chat. One edit creates one Activity record and restores the exact configuration after reload.
Run messages no longer add a page-wide panel
Approval and stopped-run messages now sit in their own rounded surfaces above the Team Flow. The page shell, Flow, and composer dock remain transparent, so the workspace stays visible and usable around them.
Every page has one dependable content landmark
Codelit's skip link now focuses one shared main region, while public pages and product workspaces avoid duplicate main landmarks that could make screen-reader navigation ambiguous.
Expired app access recovers in place
A revoked or expired connected app now fails readiness closed and shows one provider-specific reconnect action inside the Agent Team. OAuth returns to the same Team context, verifies the connection, and leaves completed evidence and pending run work intact.
Advanced edits follow the same command history
Committed workflow, teammate, app, Skill, MCP, model, guardrail, evaluation, and test-harness fields now use the same validated command path as chat edits. Typing remains immediate, unchanged values create no duplicate work, and every accepted change stays available to undo and audit.
Useful context can follow the right Team
Save private, Project, workspace, or selected-Team knowledge in the Agent Library, with clear scope, source, sensitivity, and retention controls.
Every run shows what it will remember
Before execution, Codelit explains the selected memories and lets you remove any item for that run. Archived, expired, changed, restricted, or no-longer-shared context stays out.
Successful work becomes a reviewed draft
After a safe run, Codelit can propose a reusable memory. Nothing becomes active until a person reviews and confirms it, and raw browser or tool output cannot silently teach the Team.
Project Knowledge and receipts keep the trail clear
Projects now have one Knowledge view, while private run receipts preserve the exact context references needed to understand what shaped an outcome.
Managed Browser Operator works from request to evidence
A Live run can open an approved public site, perform one bounded task, capture current DOM and screenshot evidence, hand that evidence to a verifier, and retain the result in the Run Receipt.
Connected updates come from current browser proof
The Autonomous Release Team now finalizes its channel update after Browser QA. An approved Slack action receives that browser-grounded result, and both the browser proof and delivery proof remain attached to the run.
A human card is a real runtime gate
Human approval steps now pause for the person's decision, preserve the reviewed handoff, cost no model tokens, and never ask a model to impersonate the approver in Codelit or an exported Agent Team.
The Showcase demonstrates the complete proof path
A one-click, zero-call Sample shows browser evidence, approval, Slack delivery, and the Run Receipt. Its dedicated phone layout keeps every stage readable without shrinking a desktop diagram.
The Showcase names the action and outcome clearly
Paid and organic visitors now see the exact Agent Team job, a 60-second Sample action, its approval boundary, and the Run Receipt they will receive before choosing to build their own Team.
Sample navigation warms only after real intent
The flagship Agent Team route prefetches on hover, focus, or touch instead of during every Showcase view, then gives immediate opening feedback while the one-click Sample starts.
Google Ads can learn from completed proof
A completed Sample proof is now the primary activation conversion for campaign reporting and future optimization. The $5 daily budget and click-based bidding remain unchanged while the cohort grows.
Search and answer engines see the same product promise
The Showcase title, summary, social preview, and first heading now lead with building and running AI Agent Teams instead of an abstract product label.
Six useful repositories start from working code
The public Codelit organization now includes a runnable Agent Team starter, reviewed workflow examples, guarded browser QA, bounded repository maintenance, architecture blueprints, and a zero-dependency workflow check.
Every public artifact ships with proof and guardrails
Clean clones pass strict installs and their full verification suites. Releases, CI, private vulnerability reporting, secret scanning, push protection, and automatic security updates are enabled across the active repositories.
The product and repositories form one discovery path
A responsive Open Source hub, documentation links, feature links, sitemap coverage, structured data, and privacy-safe outbound attribution connect inspectable code to the matching visual Codelit workflow.
Articles link to useful next reading with clear disclosure
Related guides now form a contextual internal link graph. Selected resource sections can include the founder's books alongside relevant third-party reading with an explicit affiliate disclosure.
The Showcase starts a complete Sample in one click
Visitors can open the Repo Maintenance Agent Team directly, with no signup or API key, and continue through its approval gate to a visible proof.
Paid journeys stay measurable through subscription
The protected admin view joins privacy-safe Google campaign attribution across Showcase visits, Sample activity, account creation, checkout, and Stripe-confirmed payment without storing raw click identifiers.
Google account creation records the right outcome
A first-time Continue with Google flow now records account creation instead of returning-user sign-in, keeping product reporting and the existing signup conversion aligned.
Live outcomes require native execution proof
A connected or browser action can report completion only when its Codelit executor returns real provider evidence. Read-only personalized proofs stop before the first write, and public receipts hide provider identifiers by default.
Paid campaigns keep attribution without leaking prompts
Google click and campaign parameters survive the landing-page view while arbitrary query text stays excluded. Codelit's own funnel stores sanitized campaign dimensions and never stores raw Google click ids.
Showcase media yields the first paint to the product
The hero now loads an optimized responsive poster before starting video after page load. Below-the-fold reels wait until they approach the viewport.
Browser and free proofs start with the right boundaries
Browser QA collects one website, approved domain, goal, and visible success criteria before managed execution. Refund limits accept normal USD input, and the free relay has a shared daily cap, an emergency pause, and capacity warnings.
Try an Agent Team from any article
Only 19 of 507 guides offered a route into Codelit; the rest ended without one. Every article now carries a persistent link to the Agent Team launcher, alongside the existing sample paths on mapped guides.
Titles now match what people actually search for
Nine widely-seen guides had titles written as broad surveys while readers were searching for specific comparisons. The titles and summaries now say what each guide answers. Article content is unchanged.
Search engines and answer engines can read the home page
The Design, Run, Ship and Automate loop, the connector row, and the product-loop section now render in the served HTML instead of only after the page becomes interactive. The visible page is unchanged.
Dependency audit is back to zero known vulnerabilities
A newly published PostCSS source-map advisory affected the shared build toolchain. The pinned floor moved to a patched release with no product behavior change.
Pro is $5 and Team is $15
The primary paid choice is a solo Pro plan with BYOK, local and in-tab runs, a small managed allowance, and one hosted automation. Team adds three seats, shared approvals and connections, and the former Pro-level managed capacity.
Every existing subscriber keeps their contract
Legacy $5 and $15 subscriptions plus v2 $9 and $29 subscriptions retain their original price, seats, automations, model allowance, and browser minutes. New checkout uses a separate immutable Stripe offer version.
The pricing funnel now reaches paid conversion
Codelit records the v3 offer from pricing click through checkout, trial, and paid subscription with retry-safe Stripe events. The 14-day read excludes internal and automated traffic and evaluates paid outcomes instead of clicks alone.
The visual Team Flow opens without inactive run machinery
Codelit now waits for the first run before loading the terminal and browser-dock workspace, while the editable Team Ladder remains the immediate first screen.
Starting a run keeps every mode and proof surface intact
Sample, Dry, local, BYOK, and managed runs keep the same terminal, approvals, browser controls, receipts, and recovery paths behind a small first-intent load.
Completed runs no longer make Team cards flash away
Cards keep one stable identity while returning from read-only run status to editing, and the retired React Flow canvas is no longer downloaded by production Team Flows.
Opening more model menus creates no duplicate sweep
The composer, Team cards, and advanced controls now share one in-flight and recently refreshed catalog instead of asking every provider again for each mounted picker.
Each BYOK provider keeps its own freshness
Saving an OpenAI, Anthropic, Gemini, or compatible provider key refreshes that provider once. One successful key can no longer make an unrelated stale catalog look current.
Discovery failures stay bounded and usable
Live catalogs reuse a five-minute server cache, keep the built-in safe models when a provider is unavailable, and back off brief failures while manual Refresh remains available.
Curated articles open a matching Agent Team Sample
Nineteen proven system-design topics now offer a restrained path to a runnable Team with sample data, human approval, and no account setup. Other articles stay focused on their editorial job.
Article context stays attached through the Team handoff
The article, placement, and matching Team remain attributed when the workspace opens, so Codelit can distinguish a real discovery journey from an unrelated template visit.
Discovery reporting counts only ordered, privacy-safe journeys
Admin counts unique visitors who move through the same article path in strict timestamp order. Retries, ties, internal accounts, automated browsers, unstable ids, and truncated article rankings fail closed.
Automated browsers leave the complete journey
Explicit test runners, conflicting browser requests, and high-speed page-only sweeps are removed as one browser journey from both general reporting and the protected Agent Team cohort.
Core Web Vitals have one private home
Admin now collects identifier-free LCP, INP, and CLS from a bounded 20% per-tab sample. Performance records contain no account, visitor, referrer, raw user agent, query string, or page content.
Public discovery starts filling Codelit's Vercel Analytics
The already-enabled Web Analytics project now receives masked public-page views. Private workspaces do not load the script, and dynamic identifiers plus query strings are removed before delivery.
Large public collections load only after intent
Documentation sidebars, searchable guide lists, and template galleries no longer prefetch every visible destination. Primary actions remain instant while one page view creates far fewer background requests.
Connected apps wake only where they are useful
Anonymous visitors can read public discovery pages without refreshing secure integration sessions. OAuth returns, remembered connections, and Agent Team workspaces keep the same automatic hydration.
Distributed browser sweeps meet a targeted safety boundary
A production firewall limit now groups repeated Alibaba Cloud traffic by browser fingerprint and challenges only unusually large bursts, leaving ordinary visitors and isolated requests alone.
Browser-held Agent Team state leaves with the account
After the server confirms deletion, Codelit clears available Outcome Save-State, drafts, session state, the local-agent database, and origin caches before returning home.
A browser cleanup error no longer becomes a false account error
If a browser refuses an IndexedDB or Cache API operation after server deletion, Codelit still completes sign-out and returns home instead of incorrectly saying the account deletion failed.
Every Architecture template grows around its content
Template titles, descriptions, counts, and component labels now use an explicit shrinkable content column, wrap inside the card boundary, and expand vertically across phone, desktop, and enlarged-text layouts.
Every run mode follows one clear lifecycle
Sample, Dry run, Run with my key, local, and managed Live runs now coordinate setup, progress, Stop, approvals, and receipts through the same workspace without overlapping preparation states.
Offline Sample runs stay clean
A loaded Agent Team can still run its deterministic Sample while offline. Background connection refreshes are contained, and the social sign-in helper now waits for sign-in intent instead of creating a hidden Safari error when the network disappears.
Every existing safety boundary remains in place
Read-only source limits, model-key checks, managed funding, explicit consent, Browser Operator controls, and approval gates still run before the matching execution mode can start.
A later funnel step must have a later timestamp
Activation, improvement, repeat, delivery, blocker, and failure stages no longer inherit Firestore's arbitrary order when two dependent events share the same millisecond.
Unproven ties stay out of every decision count
The first observed stage remains eligible, but Codelit excludes any tied dependent stage instead of manufacturing or suppressing a journey based on document order.
The frozen cohort and evidence gate remain unchanged
The repair adds no identifier, resets no collection window, and publishes no rate. Seven clean days, 200 qualified visitors, complete coverage, and aligned cohorts are still required before M3.
The M3 decision stays locked with the evidence
No next experiment can appear while time, traffic, sample coverage, or shared-cohort alignment is incomplete. Codelit cannot turn an early count into a product claim.
Verified final outcomes determine the narrow follow-on
An eligible path needs at least three final-outcome visitors and is ranked against the same qualified launcher cohort. Deployment must also name one privacy-qualified channel.
Weak evidence rejects the experiment instead of inventing a winner
If no path reaches the support floor, the protected dashboard records no M3 choice. Positive ties use a pre-registered lower-infrastructure order, and every result remains an observed demand signal rather than causal proof.
The current outcome cohort no longer inherits older event volume
Codelit's protected decision surface now reads the July outcome loop from its own release boundary. Earlier Agent Team comparison history cannot exhaust that sample and falsely report incomplete coverage.
Each measurement still fails closed independently
Older activation comparisons retain their historical window and coverage guard. The outcome cohort keeps the same internal-browser, automated-traffic, stable-visitor, and aggregate-only protections.
The product decision remains evidence-gated
The protected dashboard shows the dedicated outcome sample, but rates and the next experiment remain locked until seven clean days, 200 qualified visitors, aligned cohorts, and complete coverage are all proven.
Internal journeys stay out before and after sign-in
When an internal account signs in, Codelit removes that browser's earlier signed-out activity from product reporting instead of leaving a false qualified visitor behind.
Shared internal identities fail closed
If an internal account appears on a browser identity, the complete browser journey is excluded. The protected dashboard still returns only aggregate counts and never exposes visitor identities.
The evidence gate does not move
This cleanup applies to the existing frozen cohort. Rates and the next product choice remain locked until seven clean days, 200 qualified visitors, and an untruncated aligned sample are all proven.
Typed receipt proof chooses one bounded next step
A completed receipt can now preselect an approval gate when it proves an ungated risky tool or external action, or an outcome check when it proves none is declared.
Outputs and prompts cannot influence the recommendation
The rule reads only normalized approval state, tool risk, action proof, and declared evaluations. Free text, private output, receipt identity, and model inference stay outside the decision.
The existing comparison remains the decision point
The suggestion opens the same cost, latency, permissions, replay, evidence, promotion, and rollback checks. It never changes the Team until the user explicitly chooses Use this version.
The successful version is the version Codelit keeps
After a promoted improvement completes a real run, Keep as my default verifies and pins that run's exact workflow snapshot instead of merely re-saving the current editor state.
Keeping the winner preserves one-step rollback
Codelit verifies both the promoted candidate and its original receipt baseline before changing the local default. A stale, tampered, or cross-owner save-state stops with a clear History recovery message.
Outcome feedback contains no outcome content
Useful and Needs work record only the fixed rating, run mode, and bounded improvement type. Receipt IDs, results, private inputs, evidence, workflow hashes, and secrets remain excluded.
Usefulness rates remain evidence-gated
Admin can collect ordered unique closeout counts, but the usefulness percentage stays hidden until the existing seven-day, 200-qualified-visitor, untruncated-sample gate closes.
Older proof stays compatible without becoming less trustworthy
Supported version-one Run Receipts receive only safe additive defaults. Unsupported, malformed, incomplete, out-of-order, or execution-truncated claims stop before Codelit creates a candidate.
Every comparison belongs to its selected receipt
Codelit rebuilds the immutable baseline from the exact selected proof and rejects an unrelated baseline, even when that other receipt is otherwise valid.
Missing proof has a useful way forward
A removed, revoked, or unverifiable receipt now explains that no comparison or promotion occurred and points to proven outcomes or Agent Teams. An ineligible proof offers Remix and review without recording a misleading improvement open.
Architecture template cards contain their content
Titles, descriptions, node counts, and component labels now wrap together at the card's natural width on phone, desktop, and enlarged text instead of squeezing or extending past the card boundary.
Every next-product bet now uses the same qualified cohort
Proof-to-Remix, key-funded delivery, and deployment count only visitors who entered through the measured Agent Team launcher. Each final outcome uses that shared frozen denominator, while a mismatch locks every rate instead of producing a misleading comparison.
Admin follows both paths after a proven outcome
The protected outcome loop now counts ordered unique visitors who improve a Run Receipt or repeat a locally saved successful job. Duplicate clicks and out-of-order events cannot inflate a stage.
Every percentage stays locked until the evidence gate closes
Raw counts can accumulate immediately, but the Activation Lab and outcome-loop conversion percentages remain hidden until the existing seven-day and 200-qualified-visitor gate is complete and the analytics sample is untruncated.
Diagnostics stay aggregate and privacy-safe
The dashboard returns no visitor, workflow, run, or receipt identifiers. A repeat-blocker category appears only after at least three distinct visitors encounter it.
The next three product bets stay measurable and distinct
Proof-to-Remix, key-funded follow-on delivery, and deployment channels now keep separate ordered visitor paths. Low-volume channel details stay hidden, and Codelit makes no choice before the frozen evidence gate closes.
The application framework is on the patched security release
Codelit now runs the repaired Next.js framework line that closes the newly disclosed authorization-bypass and excessive-request-processing vulnerabilities.
Completed work gets one clear next action
Run with my key, local, and managed completions now offer Do this job again. The same run mode opens with fresh inputs and creates a new receipt linked to the completed proof.
Every repeat rechecks the safety boundary
Codelit verifies the current runtime, tools, destination, approvals, model estimate, and browser allowance before anything starts. A changed boundary stops with a specific review message.
The reusable state stays private and local
The browser keeps only a versioned workflow reference, input shape, caps, approval policy, and bounded receipt reference. Keys, prior input values, outputs, and raw evidence are not copied into the repeat state.
One bounded change starts from the receipt
A public Run Receipt can now propose one predefined approval or outcome-check change without altering the Team's tools, models, permissions, or step count.
The comparison says what is still unknown
Codelit compares outcome checks, replay evidence, estimated cost, observed latency, permissions, and evidence quality while clearly marking candidate results that require a fresh run.
Promotion and rollback stay in your hands
Use this version opens the candidate in Team Flow with its exact receipt provenance. Undo improvement restores the verified receipt version in one step unless newer edits must be protected.
Persisted improvement drafts leave the receipt identity behind
The open session can still link back to its public Run Receipt. After reload, the browser draft retains only the sanitized rollback workflow and version hashes, while a migration removes receipt IDs and URLs from older improvement drafts.
The Team Ladder shows where a remix came from
A remixed Agent Team keeps a visible link to its public Run Receipt in the same summary row as readiness and run proof, including on mobile.
Sample and personal proof stay one journey
The sanitized workflow, local draft, and anonymous visitor continue through Remix, Sample, the sign-in checkpoint, and the first read-only personalized proof instead of becoming disconnected steps.
Attribution stays bounded and private
Codelit records only the public receipt source and placement needed to measure the journey. Receipt IDs, credentials, private inputs, and proof payloads stay out of analytics.
Next cannot reuse the previous step's position
Agent Flow, Architecture, and Product Plan now attach every spotlight rectangle to the step that measured it. A fast Next or Back transition cannot briefly point at the control from the prior tooltip.
Moving controls remain aligned
The guide follows the exact resolved card, canvas node, toolbar control, or menu action for the entire tour, including responsive reflow, canvas motion, CSS transforms, and menu animation on desktop and mobile.
Agent Team changes keep one lifecycle
Plain-language workflow updates now share one owner for input, progress, retry, and Stop behavior while preserving the same preview, Undo, focus, and workflow safety boundaries.
Workflow downloads keep one dependable path
Download JSON and Repo pack remain available from the same Agent Team toolbar on desktop and mobile. Free blueprints and Pro runnable packs keep their existing contents and plan boundary.
Sharing recovers clearly when sign-in is needed
Sharing a launch review still opens the focused Share sign-in step for anonymous users, then preserves the same owner-bound review link and copied-link feedback.
GitHub export keeps its verification gates
Push to GitHub still requires both a connected account and signed-in Codelit owner, verifies the required repository files, and reports a clear stopped or failed state without changing the workflow.
Every guide highlights and focuses the same action
Agent Flow, Architecture, and Product Plan now move focus to the exact Run or More action described by the tooltip. Nearby menu commands can no longer look selected while the guide points somewhere else.
Workflow fields behave consistently
Advanced, Flow card editors, and Add Tool now share the same labeled text, multiline, and searchable choice controls while preserving every existing workflow setting and update.
Searchable choices stay inside their dialog
Tool and workflow searches keep keyboard focus within the modal that opened them, retain entered values, and close cleanly after selection on desktop and mobile.
Flow, Run, and History keep one clear place
Starting a run, approving a held step, opening retained proof, returning to Flow, and reviewing workflow details now share one focused workspace owner without changing the Team Ladder or its actions.
Browser and terminal evidence stay together
The Browser Operator dock, expandable terminal, empty-flow recovery, remixed-run context, and desktop inspector keep their existing controls and containment while the route shell remains focused on workflow and run decisions.
The Agent Team starts with less JavaScript
The initial Agent Workflow download and its largest chunk are both smaller, while History remains deferred until it is opened and every desktop and mobile release check stays green.
Next and Back cannot jump to the previous control
Agent Flow, Architecture, and Product Plan keep the tooltip, pointer, and spotlight attached to the requested step while the board scrolls or resizes. Every transition is checked continuously instead of only after the page settles.
Flow and History wait until they can answer
Section controls remain visibly in place but inactive during the brief hydration window. A fast click after reloading can no longer disappear before the Agent Team is ready.
Readiness and run cost keep one focused owner
Launch checks, the next recommended setup action, and the per-run cost breakdown now share one compact status surface while preserving the same fixes, pricing details, and mobile containment.
The change bar has one clear job
Writing a Team Flow change, adding a new line, attaching context, choosing a model, and stopping an update now share one focused interface owner while workflow decisions remain safely in the Agent Team controller.
Keyboard and context actions stay predictable
Enter previews a change, Shift+Enter adds a line, and Add context loads its source menu only when requested. The menu opens and closes cleanly without moving the composer offscreen on desktop or mobile.
Compact context labels stay readable
Local workspace and spec-import details now keep sufficient contrast in the light theme while preserving the same calmer secondary emphasis in dark mode.
Setup changes still undo as one action
Adding an agent, tool, trigger, model route, guardrail, evaluation, or test harness keeps the same single-step Undo behavior. Removing a tool also clears its agent assignments together instead of leaving stale setup behind.
Readiness fixes update the complete requirement
When Codelit repairs a launch-readiness gap, the related safety and test setup stays in one coherent workflow update. A partial fix cannot leave the Team in a misleading ready state.
The simpler editor keeps every board guide intact
Agent, Architecture, and Product Plan tours still point to the exact visible control on desktop and mobile, while Flow keeps role, tool, and readiness actions in the same focused workspace.
Agent setup panels stay focused and readable
Team settings, private proof, run inputs, Launch Review, Trigger Hub, receipts, and publishing still open only when requested and close cleanly. Their fields remain named, readable, and contained on phone and desktop.
The Team Ladder retires the legacy setup workspace
The former six-section setup workspace is removed. Common role, model, tool, input, output, trigger, and approval changes live directly on Flow cards; deeper policy remains available in Advanced.
Every existing setup action stays available
Agent roles, model choices, tool presets, approval rules, triggers, run setup, and Plan & Ship keep their existing workflow updates and handoffs inside one focused workspace on desktop and mobile.
Add Tool stays contained on small screens
The custom tool dialog now keeps its search, categories, fields, and actions inside the mobile viewport without adding an outer horizontal scrollbar.
Each tooltip has a visible pointer
Agent Flow, Architecture, and Product Plan now place every guide beside the exact title, field, card, tab, or menu action it explains. A clear pointer keeps the relationship obvious as you move through the tour.
The guide moves around the control instead of covering it
Each coach mark chooses the clearest available side and keeps both itself and its target inside the viewport. Compact screens scroll toward the target without placing the instructions over it.
Agent and Architecture steps teach real actions
Agent setup now points to the exact Team title and editable Agent name. Architecture handoff reveals and points to the real Export action, while controls that do not exist stay out of the tour.
The complete Agent toolbar keeps one responsive row
Run, share, notifications, guide, import, export, and Advanced actions now share one focused toolbar surface. Every command remains reachable without crowding or wrapping the board on desktop and mobile.
The Team Flow stays focused on the work
Runtime, Models, Safety, Skills + MCP, Harness, and the editable graph now load only after you open Advanced. The visual Team Ladder remains the fast, uncluttered first screen.
Every Advanced section remains one clear click away
The complete controls keep their existing workflow data and actions inside one named section group. Graph edits still open the exact step inspector, and every panel remains contained on desktop and mobile.
Inactive setup code leaves the first download
The initial Agent Workflow carries less JavaScript while the full Advanced workspace stays in its own on-demand chunk. Permanent source, bundle, and browser checks prevent those controls from drifting back into first load.
Connected setup returns to the exact card
Agent App and connected-account setup now restore only the Team, card, capability, and guided proof that started the handoff. A stale or unrelated return safely opens the Team instead of changing the wrong step.
Local context stays with its account
Saved workspace context and scheduled runs are loaded only for the current account and Team. Switching accounts or clearing context cannot be undone by a slower background restore.
Add context waits until it can answer
The context control stays unavailable for the brief moment before its deferred menu is interactive, then works consistently by keyboard or pointer while keeping the larger integrations menu out of the first download.
Next has one exact target
Agent Flow, Architecture, and Product Plan now clear the previous highlight and attach each guide step to exactly one visible control inside the board that opened it. Run and More menu actions keep their intentional portaled targets.
Canvas startup cannot shorten the tour
The Help control waits until it is interactive, then waits for the board's stable canvas anchor before opening. A slower Architecture canvas no longer drops Inspect or Chaos and starts halfway through the guide.
First-visit consent cannot cover the guide
Automatic tours wait for the optional analytics decision to close before opening, so the consent banner cannot block Help, Next, or Done on desktop or mobile.
Connected apps return to the exact capability
After GitHub, Slack, or another connected-app authorization, Codelit restores the Agent card and tool that started setup. A slower mobile return no longer lets the general Settings screen cover that destination.
Proof recovery stays scoped to you and this Team
Private proof restoration is keyed to the current account and workflow. A published Agent App is recovered only when its proof matches the exact workflow version currently open.
Use your own key stays in the guided proof
Source discovery, model-key setup, read-only launch, progress checkpoints, and the next Live action now share one focused lifecycle while keeping the existing permission, approval, and redaction boundaries.
Next stays attached to the same control
Agent Flow, Architecture, and Product Plan now hold the exact card, field, tab, or menu action selected for each guide step while the board scrolls or animates.
Responsive Product Plans open one guide
Desktop and compact Product Plan shells can coexist for responsive layout, but only the visible board may auto-start its tour. One tooltip, one spotlight, and one Next action remain active at a time.
Advanced controls load only when you open them
The detailed workflow inspector stays out of the initial Agent Team download, then opens with the same agents, tools, models, rules, handoffs, provider setup, and browser controls when you choose Advanced or inspect the execution graph.
Custom tool setup is still one action
Custom tool search and creation now load after Custom tool is selected. Slack, GitHub, Jira, browser, database, runtime, and custom presets keep the same saved workflow shape, validation, close, reopen, and creation behavior.
The first Agent Team screen carries less editor code
The guarded Agent Workflow payload is about 3 KB smaller gzip, and its largest initial chunk is about 3 KB smaller. Permanent source and bundle limits keep these interaction-only editors from quietly returning to first load.
Small controls remain clear on mobile
Advanced field labels, handoff choices, execution tools, and the selected-step summary now meet the contrast floor in light and dark themes while the full-screen mobile editor remains contained at 390 pixels.
Next points to the exact thing it explains
Agent Flow, Architecture, and Product Plan now clear the previous highlight before advancing, then attach the guide to the named card, field, board tab, or action instead of a nearby container.
Run and More actions reveal themselves
When a guide step explains Dry run, Automate, Repo pack, GitHub, Review, Copy PRD, or Import, Codelit opens that nested action and keeps the spotlight aligned while the menu appears.
The compact Product Plan has a real mobile tour
Phone-sized Product Plans now guide people through an inspectable card and the Architecture switcher, while controls that do not exist in the compact layout stay out of the tour.
The live run workspace stays together
Browser control, the expandable terminal, connected-data consent, and human approvals now share one focused presentation surface while each Sample, local, key-funded, and managed run keeps its existing isolated controller.
Approval details remain readable in every theme
The compact Scope, Approve, and Hold summary now keeps sufficient foreground contrast in light mode. Approval actions remain contained above the terminal on narrow mobile screens without hiding run evidence.
Heavy runtimes still wait for intent
Browser Operator panels and managed execution remain deferred until the workflow actually needs them. A permanent source-size guard keeps the main Agent Workflow shell below 5,400 lines as the broader extraction continues.
The homepage heading collapses and expands again
Each short Agent Team promise now closes naturally into the prompt, changes, and opens back out instead of simply fading. The reserved heading frame stays fixed, narrow screens remain contained, and reduced-motion visitors keep a stable headline.
Google sign-in stays readable on hover
Continue with Google now uses the same theme-aware foreground and background tokens in the sign-in dialog and Settings. Its label keeps full contrast in light and dark themes before, during, and after hover.
Every board tour points to the control it explains
Agent Flow, Architecture, and Product Plan now move each guide spotlight to a real visible card or control. Unavailable steps stay out of the tour, offscreen targets move into view, and every coach mark keeps Back and Next inside the viewport.
Setup status colors meet the light-theme contrast floor
Agent Team settings sheets now use an opaque surface with darker warning and success accents, keeping provider setup instructions and status labels readable without changing their meaning.
Live Run checks stay in one order
Funding, connected-source discovery, explicit read consent, stale-scope reconciliation, and approval gates now share one focused controller. The same fail-closed checks still happen before any model or connected tool can run.
Stop cleans up the whole run
Canceling a managed run now keeps its task, pending approval, consent scope, browser activity, and terminal state under one owner. Starting a local or key-funded run stops that managed work cleanly instead of leaving hidden state behind.
The workflow shell keeps getting easier to maintain
Managed preflight and launch ownership moved out of the Agent Workflow page while the execution engine remains deferred until a user starts Live Run. A permanent source ratchet keeps the main shell below 5,700 lines.
Connected tools update the same Team Flow
Slack, GitHub, custom integrations, provider accounts, and saved browser sessions now share one readiness owner. Connecting or refreshing a tool updates every matching Team card without changing the flow or losing keyboard focus.
Provider scopes fail closed
Codelit marks only ready accounts, approved provider operations, and normalized website domains as executable. Signing out or losing Pro access immediately clears that readiness instead of exposing stale Live setup.
The workflow shell keeps getting smaller
Connection discovery, refresh events, provider-template binding, and browser-domain checks now live in one focused controller. The main Agent Workflow component is permanently held below 6,000 lines while its deferred Live runtime remains unchanged.
Every managed approval stays tied to its run
Browser writes, GitHub Actions, connected apps, custom integrations, and provider operations now share one bounded approval controller. Approve, Hold, Stop, and cleanup keep the same reviewed payload and fail-closed boundary.
Browser control returns to the same checkpoint
Browser Operator approval, private takeover, control return, stop, and recipe saving keep one continuity owner, so a paused agent cannot silently resolve a newer run or skip the reviewed action.
The first mobile action is ready when it looks ready
Pro, Max, and one-time execution choices now wrap cleanly on narrow screens. The More menu also remains disabled until the editor can answer, preventing an early tap from disappearing during hydration.
Image processing uses patched native libraries
Codelit's Next image pipeline now runs Sharp 0.35.3 with libvips 8.18.3, closing the current upstream image-decoding advisories while preserving optimized image delivery.
Build-time URI validation is patched
The development toolchain now pins fast-uri 3.1.4, which closes its host-confusion advisory without changing Codelit's public routes or runtime behavior.
The first run click cannot disappear
Agent Teams reserve a clear Loading control until the editor owns the page, prepare the small Sample runner in the background, and expose Try agent only when that runner can open the terminal immediately.
A failed preparation has an honest retry
If the Sample runner cannot load, the toolbar changes to Retry run instead of leaving a dead control. Once prepared, the same Team can still start after the tab goes offline.
Remixed Teams keep their real tools
A remixed Agent Team now resolves each fresh tool id through its canonical fixture identity, so Sample evidence and approvals continue to show the Slack, GitHub, Jira, browser, and other tools the Team actually uses.
The real Team Flow arrives immediately
Known Agent Team links now resolve on Codelit's server and stream the actual Ladder before the full editor starts. On a controlled mobile Fast 3G profile, median Ladder visibility falls from 8.78 seconds to 0.53 seconds and LCP falls from 9.06 seconds to 1.46 seconds.
Every visible choice says what it contains
Trigger text, Agents, tools, models, inputs, outputs, approval rules, retries, and handoffs now include their displayed value in the control's accessible name. Run options also move focus cleanly into the next activation dialog on desktop and mobile.
A saved draft cannot replace the Team you opened
Codelit restores a browser draft only when it belongs to the current Agent Team route. Shared and unknown Team links keep their existing private cloud lookup, while unrelated local work stays out of the way.
Your selected key wins
Run with my key now pins the model provider you selected and funded, even when the Agent Team uses a different managed routing policy. One saved key starts the run without asking you to configure an unrelated provider.
Stop or reload leaves an honest checkpoint
Key-funded runs keep owner-scoped progress in this browser. Stop records an Interrupted History entry, Retry continues from the first unfinished routed step, and a reload repairs the same account and workflow without replaying completed work.
Browser-owned work cannot fan out globally
Run status stays local to the tab and account. A key-funded run cannot call Codelit's managed model or browser, send a global task notification, or post to Slack unless the workflow later enters an explicitly approved managed action path.
Run locally owns its full Worker lifecycle
Starting, approving, pausing, resuming, completing, and restoring a Local Lite run now stay behind one browser controller. A resumed run starts at its durable checkpoint instead of replaying completed Agent steps.
Reviewed files and task status stay local
Local runs still send selected evidence only to the provider paid by your key. They cannot call Codelit's managed model, allocate a managed browser, or inherit the global task-notification endpoint.
Closing the tab leaves honest proof
If the page closes during a run, Codelit interrupts the owned Worker, releases its reservation, and restores an Interrupted History entry for the same account and workflow. Resume requires the same workspace, provider, and model.
Approve, hold, and stop have one run owner
Sample and Dry runs now keep progress, approval, cancellation, evidence, and the final receipt in one bounded controller. Approving continues the committed path, Hold prevents later artifacts, and Stop records an interrupted run instead of leaving hidden work behind.
Dry runs keep their no-invention boundary
Read-only tool calls remain visible in the terminal without manufacturing approval gates, while write decisions still stop for the person named on the Team card. Live, Local Lite, and key-funded executors keep their existing isolated approval boundaries.
Run decisions are clearer in every theme
Approval actions, setup labels, and hold controls now meet contrast requirements in light and dark themes. The terminal log and detail panel are keyboard reachable, and the mobile approval panel stays clear of the resizable terminal.
History, receipts, and archives stay synchronized
Starting, pausing, completing, retrying, settling, and archiving a run now pass through one owner-scoped ledger. Completed proof remains after reload, and an archived run stays out of Recent runs instead of returning later.
Tabs and accounts cannot claim each other's local runs
Every browser tab keeps one session identity across Sample, Dry, Local Lite, key-funded, and managed runs. Stale local work is repaired only for the matching account, workflow, and resume id, while unload interruption leaves another tab's work untouched.
The Agent Workflow shell keeps getting smaller
Run-history state, storage, receipt selection, lifecycle cleanup, and managed-usage settlement now live in a focused module below 300 lines. The main workflow component is permanently held below 7,500 lines with no new interaction request or run-policy change.
Natural-language edits open a review instead of rewriting the Team
Describe a card, handoff, tool, approval, or structure change and Codelit shows the exact proposed differences first. Suggestions, critique fixes, and re-running the last edit follow that same review path in Team Flow.
Clear edits stay instant and model-free
Common add, remove, rename, connect, approval, and resource-targeting requests are planned locally. Connector resources come only from the accounts and scopes Codelit can currently discover; ambiguous requests use one bounded planner call.
Nothing changes until you accept
Reject leaves the workflow untouched, missing targets explain what to select or name, Stop cancels model planning, and accepting reviewed changes creates one exact Undo point across desktop and mobile.
Every card and handoff edit uses the same reversible path
Inline fields, the full settings sheet, Add actions, copy and paste, approval gates, rerouting, and deletion now share one Team Flow editor transaction instead of being coordinated by the page shell.
Undo keeps exact snapshots and keyboard behavior
Rapid typing still becomes one undo point, structural changes remain separate, history stays capped, and Command-Z or Control-Z restores the exact prior Team while clearing a focus target only when that object no longer exists.
The Agent Workflow shell is another 661 lines smaller
Synchronous editor ownership moves into a focused module below 900 lines, and the main workflow component is permanently held below 7,650 lines. AI change previews stay separate until their own measured extraction.
Tools, skills, and runtime choices have one source of truth
Codelit's 39 built-in tool presets, skill and MCP conversions, risk choices, trigger presets, and setup labels now live in focused Agent Workflow modules. Their stable ids, order, defaults, and saved workflow shape remain unchanged.
The workflow shell gets smaller without adding download cost
Another 754 lines leave the main Agent Workflow component while its complete initial payload remains below the tightened 425 KB gzip budget. Static setup vocabulary stays in the same compiled boundary instead of becoming another network request.
Provider and browser setup are tested through the Team Ladder
Slack, Linear, trigger, unavailable-resource, Browser Operator, and live-data consent checks now use each Ladder card's current settings path on desktop and mobile. Retired graph-canvas and Simple Build test contracts no longer obscure the experience users actually receive.
Launch review and Trigger Hub no longer slow the Flow
Codelit keeps both interaction-only surfaces out of the initial Agent Team download, then loads exactly the dialog you request from Run options. The other dialog stays unloaded until you choose it.
The Agent Workflow core is smaller
The complete initial Agent Workflow payload falls from 427 KB to 420 KB gzip, and its largest chunk falls from 163 KB to 156 KB. Lower enforced budgets prevent either dialog from quietly returning to the first load.
Close, reopen, and continue on any screen
Launch review and automation settings keep their current behavior after extraction, including dry-run handoff, the Pro publishing boundary, open-tab schedule creation, keyboard focus, and responsive layouts on desktop and mobile.
Unused integration artwork stays off the first screen
Agent Teams keep GitHub, Slack, and OpenAI marks ready for common flows, then fetch narrow AI, business, collaboration, or developer logo sets only when the visible Team actually uses one.
The Agent Teams library is another 7.5% smaller
Initial JavaScript on the public Agent Teams route falls from 325 KB to 301 KB gzip. The measured budget is lower too, so a future change cannot quietly restore the previous payload.
Provider labels keep their space while artwork arrives
Every deferred logo has a stable reserved frame, remains decorative for assistive technology, and keeps Team cards aligned without horizontal overflow on desktop or mobile.
Add context stays one click without slowing the Flow
Codelit keeps repository, file, and local-workspace tooling out of the initial page, preloads it on pointer or keyboard intent, and opens the complete source menu on the same first click.
Agent Teams and public pages carry less idle animation code
The Agent Team shell, shared route transition, connection banner, back-to-top control, source menu, and feature icons now use lightweight CSS motion with the same reduced-motion behavior. Features, Agent Teams, Pricing, and Showcase no longer load Motion directly or speculatively fetch linked animation runtimes.
The measured payload drops again
Compared with the prior production release, initial JavaScript is 7% smaller on home and 11% to 14% smaller on Agent Teams, Features, Pricing, and Showcase. The full Agent Workflow entry is 12% smaller and remains guarded by an emitted-bundle budget.
Deferred controls still fit the active viewport
Bottom-anchored context menus choose their direction before first paint, stay keyboard accessible, and open without clipping on desktop or mobile. The canonical Team Ladder, local workspace, themes, and responsive layout remain unchanged.
Signed-out pages carry materially less JavaScript
Codelit now keeps its Firestore runtime out of the signed-out homepage, Agent Teams launcher, Features, Pricing, and Showcase. Their initial JavaScript is 14% to 21% smaller while the same public actions, themes, and responsive layouts remain available.
Authentication no longer pulls in cloud persistence
Firebase Auth and Firestore now have separate browser boundaries. Cloud history, plan status, usage, sharing, hosted-run updates, and waitlist writes load only after sign-in or the exact action that needs them.
Agent Team templates open without database startup
Prebuilt Agent Teams resolve locally before Codelit considers a shared cloud record, and the sidebar does not open cloud history for a guest. The full Team Flow remains below its existing bundle ceiling.
Public Agent Team actions now start with an outcome
The shared marketing action, Features pages, Pricing free path, homepage product loop, and Showcase now open the same no-signup outcome launcher. Users see the five proven jobs and can run a zero-cost Sample instead of being dropped into the legacy composer.
The outcome launcher now counts its qualified visits
The Agent Teams launcher records one bounded page view only while that outcome-first screen is visible. Opening an existing Team does not inflate the launcher cohort.
Incomplete measurement cannot become a conversion claim
A production audit found clean events but no launcher denominator, so Codelit interpreted no rates and restarted the cohort. The Activation Lab still waits for both seven clean days and 200 qualified visitors before naming a constraint.
Telemetry now has one enforced privacy boundary
Browser events pass through a bounded, same-origin, rate-limited server sanitizer before storage. Unknown event names, content-shaped metadata, dynamic identifiers, oversized requests, forged account ids, and direct Firestore writes fail closed without interrupting the product.
One deployed Team owns one signed destination
The browser-wide task endpoint and unsigned relay are gone. Configure, test, replace, rotate, disable, inspect, and retry a result webhook beside its published automation in Projects.
Local work stays local by construction
Local Lite and open-tab work cannot inherit a hosted result destination. Old browser-stored endpoint values are removed during settings migration, and ordinary browser task completion no longer fans out to an arbitrary URL.
Delivery recovery never repeats the work
Completed, stopped, and failed hosted runs create one durable signed event with a stable delivery id. Transient failures recover from the maintenance queue, and a manual retry resends only that bounded event without calling a model, connector, browser action, or approval again.
Deletion removes the full delivery lifecycle
Deployment, workspace, and account deletion stop owned automation work and remove encrypted endpoints, signing secrets, retry markers, and delivery records. A result-delivery failure never changes the run receipt itself.
Native provider modules check setup in place
The selected Agent card can now verify its owner account, exact operation grant, required fields, and current Microsoft Team or channel. The check uses a bounded no-write readiness probe and never sends the configured provider action.
Run with my key inputs stay readable
The one-source consent panel now gives source and scope their own labels, full-width controls, unclipped native select text, and a consistent action row across desktop and mobile.
Results read like notifications, not raw payloads
Background-task email now turns bounded JSON results into a short human-readable status and useful measurements. Malformed structured output stays out of the message, and a stopped task uses failure copy instead of pretending it completed.
The email opens the project that started the task
Each background task remembers its originating Agent Team, board, or architecture route. The email returns to that exact project while removing credential-, token-, state-, and session-shaped query values; older tasks fall back to Projects.
Agent cards open with provider-specific setup
Choose the module, a provider-shaped role, the connected account and resource, and one bounded behavior before touching generic configuration. A model-only Agent can now attach any available app, browser, provider, or custom module from that same selector; its typed editor opens immediately while existing instructions stay intact. GitHub, Slack, Jira, Linear, Microsoft Teams, provider operations, custom integrations, and Browser Operator all stay in the flow.
Connected apps authorize from the selected Agent
A disconnected built-in app now shows one Connect action in its module setup. Codelit preserves the selected card through authorization, returns to that exact editing context, and keeps account-wide management secondary in Settings.
Trigger cards keep automation setup in the flow
Choose one supported source and event, then complete only the schedule, webhook, filter, account, or resource fields that event needs. The reviewed setup saves with the Team Flow and becomes the starting configuration in Trigger Hub instead of asking for the same choices twice.
Every editor follows the task
Common controls stay first, then each object shows only the flat groups it needs. Agents organize behavior, data, guardrails, modules, and structure; triggers, capabilities, decisions, approvals, handoffs, and output use smaller task-specific sets. Every closed row summarizes the effective configuration while preserving advanced fields and structural actions.
Custom inputs no longer start as JSON
Reviewed API and MCP actions turn required schema fields into typed controls, enums into dropdowns, and valid presets into the starting point. Optional inputs, structured values, operation IDs, schemas, runtime limits, and exact browser steps remain available under clearly labeled Expert controls.
The inspector keeps the canvas in reach
Desktop users can move directly between Team Flow cards without closing the right drawer, and each selected editor starts at the top. Mobile keeps its focused full-screen sheet, closing restores card focus, and a fixed save status plus one-click Undo keeps edits reversible.
Setup recovery names the exact next action
Disconnected modules show the responsible account or resource, handoffs no longer inherit unrelated provider warnings, Fix here moves to the nearest setup control, and returning from Settings preserves the selected Agent instead of reopening stale work.
Saved resources never change behind your back
If a provider stops returning a saved repository, project, page, team, file, or channel, Codelit keeps that exact value visible as unavailable and blocks the read check. The workflow changes only after you deliberately choose a current replacement or reconnect the account.
Team Flow editing stays on the canvas
Right-click cards, handoffs, or open canvas space for only the actions that apply. Edit, rename, insert, configure tools, toggle approvals, inspect evidence, reroute, delete, add workflow objects, paste, restore automatic layout, and fit view all use reversible workflow state instead of decorative menu items.
Every flow object has one truthful interaction contract
Cards and handoffs open their exact inspector by pointer or keyboard across Build, Run, History, desktop, and the mobile list. Run and History expose handoff rules and observed results without edit language, double-click no longer moves the camera, and branching labels keep separate hit areas.
Local Lite remains the supported one-click local path
Agent Teams can use a reviewed local workspace, the user's model key, a dedicated browser Worker, local checkpoints, and receipts without an extension or Codelit compute. Connected writes, managed browser use, and background continuation still route to managed execution.
The Node proof passes on measured desktop Chromium
The current WebContainer prototype again installed, tested, built, visibly previewed, and tore down committed small and medium projects. Both completed comfortably below the 30- and 90-second technical thresholds.
Technical success does not bypass production terms
Repo Lab stays disabled because Codelit has no commercial WebContainer license, production API key, or approved unit economics. A separate operator release flag now prevents a future key from enabling the benchmark accidentally.
The feasibility run keeps customer work out
The noindex route mounts committed synthetic fixtures only. It creates no account record, product analytics event, model call, managed browser session, hosted work item, or account-owned data, and tears the isolated runtime down on stop or page exit.
Runtime isolation stays separate from account services
Repo Lab no longer mounts or prefetches account, OAuth, hosted-run, open-tab-run, or notification services. Its COEP boundary stays clean without weakening authentication or changing those services on the rest of Codelit.
Every unmatched request still becomes a custom Team
The Outcome Launcher and a true zero-result Marketplace search open a custom Team with the request already filled in. Users can preview it before connecting data or spending anything, without joining a waitlist or completing another form.
Real run blockers identify the missing capability
An attempted run can now name an allowlisted gap such as GitHub, Stripe, a model key, browser control, an approval gate, or the local runtime while keeping the same one-click setup or fallback action.
Repeated demand, not repeated clicks, shapes the roadmap
Admin reconciles browser and signed-in identity, deduplicates retries, measures seven-day recovery, and hides a need until at least three distinct users encounter it. A low-recovery cohort becomes evidence for review, never an automatic product promise.
The request itself never enters analytics
Only a broad outcome category, allowlisted source, run mode, blocker reason, and capability are accepted. Prompts, searches, tool labels, URLs, repositories, accounts, resource IDs, credentials, source content, outputs, and provider responses are rejected, with no model or provider spend.
One private brief names the next useful action
A signed-in 7- or 30-day view combines completed outcomes, attention items, actual cost, explicit time assumptions, and recent Team activity without opening every receipt.
The summary never loads customer work
Field-projected queries keep prompts, source content, outputs, logs, approval proposals, credentials, identities, provider responses, and run identifiers out of the process. Aggregation uses stored operational facts and makes no model, connector, browser, or execution call.
Email is opt-in and contribution-aware
Free accounts can choose a weekly brief; Pro and Max can choose daily. Empty periods send nothing, retries are idempotent, and delivery goes only to the verified account email without storing another recipient.
Turn it off or remove it completely
In-app reporting remains available when email is off or operationally disabled. Account deletion removes the preference and its recursive notification receipts before identity deletion.
Proof and execution health stay separate
An active receipt verifies a reviewed Team and expected outcome. A separate observed-health signal summarizes how the exact published version has behaved in eligible Codelit-hosted terminal runs.
Health unlocks only after meaningful evidence
A version remains Evidence building until five eligible runs exist. Public cards then show only coarse completion, volume, and freshness bands, and a newly published workflow version starts its own evidence window.
Customer work never becomes a trust badge
Samples, BYOK runs, installs, identities, inputs, outputs, providers, run identifiers, spend, and exact low-volume counts are excluded. Private aggregates remain server-only and leave with account-owned Marketplace data.
Trust follows the adoption journey
The bounded trust state travels from Marketplace discovery through Sample, Remix, Live intent, and checkout. Admin compares those cohorts without adding listing names, customer content, or high-cardinality identifiers to analytics.
Healthy Live Runs stay one click
Codelit checks the signed-in account's model, browser, and request capacity alongside source readiness. A paid account with enough allowance launches normally; the funding chooser appears only when a real limit blocks the reservation.
Every blocker offers the relevant next step
Free accounts can choose Pro or Max, paid accounts short on managed capacity can add one Execution Pack, and every eligible Team keeps Run with my model key and deterministic Sample alternatives. A spend pack is never presented as a fix for a request ceiling.
Launch review shows the spend boundary
Before work starts, the review displays a bounded model-cost range, browser-time upper bound, and current balances. The terminal records that projection so an operator can see what Codelit reserved and why.
Receipts settle to measured usage
Completed runs now reconcile provider-reported model cost or tokens and actual managed-browser duration, return unused reservations exactly once, and carry the settlement basis into private terminal and History views. Public proof exposes only bounded totals.
The release brief is now repository plus issue
Autonomous Release Team replaces six implementation questions with one connected repository, one open GitHub issue, and optional constraints. It derives the title, default branch, smallest relevant file set, patch path, and release branch from current GitHub evidence.
Issue scoping reads metadata before file content
The first step receives only the exact issue, default branch, and a filtered path manifest. Pull requests, archived repositories, truncated manifests, secret-like paths, generated folders, binaries, traversal, and stale scopes fail closed before model or write execution.
Every destination is explicit and stable
The launch review shows the selected GitHub repository, Vercel project, Slack channel, and browser session. Codelit rediscovers each scope at launch and never falls back to a different first account when a repository, project, channel, or session changed.
Sample and Live use the same six-stage team
The deterministic Sample now covers issue scoping, bounded patch planning, approved branch and preview creation, branch checks, browser QA, and final PR, promotion, Slack, and source-issue proof on desktop and mobile.
The outcome journey now has one clean cohort
Admin follows unique visitors from the Agent Teams outcome launcher through Sample start, completed proof, receipt review, own-data selection, personalized proof, live or automation intent, and checkout. Retries, direct template entries, internal accounts, automated traffic, and events without a stable visitor id do not inflate conversion.
Results freeze at the later evidence gate
The lab collects for at least seven days and at least 200 qualified launcher visitors, then freezes the exact cohort. A short time window, low traffic, or truncated analytics remains visibly collecting instead of being presented as a product conclusion.
Every step has an explicit decision threshold
The dashboard compares current conversion with the launch hypotheses for Sample start, proof completion, receipt review, own-data proof, live or automation intent, and checkout. When the window is ready, it names the first actionable constraint instead of recommending broad redesign from sparse traffic.
Activation measurement keeps customer work out
The evaluator uses only bounded event names, timestamps, public route shapes, allowlisted attribution, and an opaque visitor id. Prompts, outputs, receipts, source content, URLs, credentials, account names, and connector values never enter the report.
Checkout verifies the Codelit merchant before it sells
Pro, Max, and Execution Pack checkout now confirm the exact live Stripe account, active product, USD amount, lookup key, and monthly or one-time billing contract before creating a private session. Active subscriptions cannot be duplicated, and returning customers reuse their Stripe record without receiving another introductory trial.
Webhook delivery is part of billing readiness
Codelit verifies the live production webhook, its signing-secret configuration, and every event needed for subscriptions, invoices, refunds, disputes, and prepaid packs. An admin-only no-store health proof makes missing billing infrastructure visible before customers depend on it.
Execution Pack refunds remove the matching capacity
Full and partial refunds or disputes now reverse unused managed-model credit and browser minutes exactly once. Capacity already consumed becomes a bounded balance against the next pack, so replay cannot restore refunded value or create ledger drift.
Self-service billing stays private and available
Checkout and Customer Portal sessions are same-origin, authenticated, and never cacheable. Existing subscribers can still manage or cancel through Stripe even when Codelit pauses unhealthy new checkout.
The visual workflow opens with materially less JavaScript
Browser control, simulations, Failure Lab, publishing, Marketplace setup, and advanced editors now load only when opened. The largest initial Agent Workflow chunk dropped 32.8%, from 187.3 KiB to 125.9 KiB gzip, while the core Team Flow and offline Sample workspace remain immediately usable.
No-write canaries guard managed execution
Every flagship Team, committed Sample, connected-app read, and provider-pack read adapter is validated before hosted work. The check sends no provider request, calls no model, allocates no browser, and writes no customer data; a failure pauses Live while Sample and local review remain available.
Runtime failures correlate without customer content
Managed-model reservations, provider approvals and executions, hosted states, canaries, and receipts now share allowlisted route and execution identifiers. Prompts, messages, emails, URLs, credentials, source excerpts, and provider bodies cannot enter this runtime log record.
Account deletion tears down delegated providers
Delete account & data now removes every encrypted Google Workspace and Microsoft 365 credential before the Firebase identity, and asks Google to revoke its token upstream where supported. New tests keep identity deletion last when provider cleanup cannot finish.
Flow remains accessible from phone to keyboard
The visual Team Flow is now a named screen-reader region, optional loading states respect reduced motion, cards retain visual keyboard order, mobile inspectors stay full-height from the right, and loaded tabs keep deterministic Samples available offline. The complete Guide remains one click away without interrupting a new user's first action.
Sample now continues through one guided install
Use with my data opens a focused setup with only the published Team brief and required connections. Values remain in the browser session until launch, and Marketplace counters receive no input, source, credential, or connection value.
Creators can guide setup without taking control
Publishers may mark harmless public brief values as recommended or locked. Repositories, sources, URLs, identity, credentials, billing, private scope, permissions, and required approvals always remain installer-owned.
Completed receipts become redacted proof cards
A completed public Run Receipt can share one canonical link and a 1200 x 630 image containing only its reviewed title, summary, mode, status, step count, and duration. Halted runs and private workflow content fail closed.
Creator attribution rewards retained outcomes
A Sample-first install can earn its creator $2 in managed-model credit and 60 browser minutes only after the referred account stays paid for 30 days. The claim is opaque, checkout-verified, deduplicated, and never grants access to the installer.
Refunds and rollback remain exact
Self-referrals and replay do not qualify; refunds, disputes, or abuse reverse unused rewards or offset a future grant. Rewards and proof sharing can be disabled independently without removing Samples, installs, listings, or receipts.
A corrected approval can become a Team example
Reviewers can explicitly save a changed approval before the run resumes. Codelit keeps only privacy-safe field names, the approval boundary, and the exact workflow version; original values, corrected values, prompts, identities, source content, and provider IDs are excluded.
Reviewed lessons pin to deterministic golden evals
An optional zero-model eval checks the same immutable workflow receipt for its approval gate and step boundary. Older examples never guide a changed workflow version, and removing one excludes it from future runs and active evals immediately.
Team Insights reports what actually happened
A private report compares completed outcomes, intervention rate, failure rate, recovery evidence, actual model cost, and pinned workflow versions. No run output, prompt, source excerpt, provider identity, or log content is returned to the reporting UI.
Time saved is always labeled as an assumption
Codelit shows no time estimate until an owner or editor enters manual minutes per completed outcome. The estimate stays visibly separate from measured counts and cost, and clearing it removes the claim without changing history.
Playbooks remain reversible and deletable
Examples can be removed or restored without mutating their immutable content. Workspace and account deletion now include every playbook example and outcome assumption, while direct Firestore access remains denied.
One private Inbox holds the whole operating loop
Agent Team Inbox combines connected requests, active runs, authenticated approvals, quiet-hour recovery, channel-delivery state, managed cost, and complete private receipts. The global bell now opens this durable queue instead of becoming a second run surface.
Conversation identity fails closed
Slack, Microsoft Teams, Gmail, and Outlook requests resolve the provider sender to a current workspace member with run permission before Codelit claims work. Unknown senders, viewers, removed members, revoked connections, and mismatched workspaces create no model call.
Slack, Teams, Gmail, and Outlook reply with receipts
Trigger Hub can choose a Microsoft Team and channel, accept explicit /codelit commands, and return status in the original Slack, Teams, Gmail, or Outlook thread. Provider-native replies contain only terminal state, step count, approximate cost, and a signed-in receipt link; model output and source content stay inside Codelit.
Approvals remain authenticated and bounded
Source replies name the exact gated step, risk, and editable-field count without granting authority. Workspace reviewers reuse one approval editor, personal owners can decide from their authenticated receipt, and expired or revoked access remains closed.
Reply failures recover without replaying work
A failed channel update appears on the existing run receipt with one Retry action. Retrying reuses the completed receipt and current connection authorization; it never reruns the Agent Team or repeats external writes.
New plans have contribution-safe included usage
New Pro and Max subscriptions use versioned Stripe prices with separate managed-model and managed-browser allowances. Active subscribers keep their original price and entitlement contract while new checkout can be disabled independently.
Every managed call reserves before provider access
Interactive model requests, hosted runs, and browser sessions atomically reserve included capacity first and prepaid balance second. Provider failures and unused duration return the reservation, while terminal settlement and expiry cleanup remain replay-safe.
Execution Packs add transparent prepaid headroom
Paid owners can add one $10 pack with $7 of managed-model credit and 300 managed-browser minutes. Stripe owner, price, payment, quantity, and pack metadata are reverified, and webhook or return-page replay cannot grant the purchase twice.
Hosted BYOK no longer consumes managed model balance
A hosted run pins its payer before the first provider call. Vaulted user keys remain user-funded across approval and resume, Codelit-funded runs keep their reservation, and a removed key fails closed instead of silently switching who pays.
Settings and Admin reconcile the same ledger
Account settings separates included use, prepaid balance, reservations, carry-forward, recent pack purchases, and estimated per-run model use. Admin includes one-time revenue, worst-case unit contribution, and a release-blocking reconciliation drift signal.
Agent Teams now begin with a result
The primary Agent Teams screen replaces the seven-step builder-first setup with five proven jobs: ship a release, respond to an incident, resolve a refund, qualify a lead, or answer a team question. Each whole row starts its deterministic Sample in one click.
A written goal finds the closest proven Team
The outcome composer matches common goals locally without a model call or infrastructure spend. It names the recommended Team before launch and opens custom creation only when no proven outcome matches.
Proof still comes before access
Every launcher path keeps the existing zero-provider Sample, exact approval checkpoint, Run Receipt, and Use my data Autopilot. Marketplace and visual flow customization remain available as secondary paths.
One calm layout works from phone to desktop
Outcome rows have one click target, familiar app marks, clear proof summaries, organic mobile height, keyboard focus, no horizontal overflow, and no overlapping controls.
Proof-backed Teams are searchable
A new Marketplace launches with 20 deterministic Codelit starters, six indexable outcome categories, creator profiles, search, sort, related Teams, stable metadata, structured data, and sitemap coverage.
Sample is one click and costs $0
Every listing exposes its required apps, effects, risk, approvals, duration, and model estimate before action. Run free Sample automatically replays the pinned proof without a model, provider, browser, connector, or managed executor call.
Remix opens the exact own-data setup
Use with my data copies only the published workflow version, preserves bounded creator attribution, opens the first required source, and never inherits credentials, private identifiers, project state, inputs, or outputs.
Publishing is moderated and revocable
Reviewed creator profiles and version-pinned public Agent Apps enter a revision-safe moderation queue. App, proof, profile, listing, or account removal makes the public Team unavailable immediately, and every transition remains audited.
The growth loop is measurable without content
Admin now follows deduplicated Marketplace discovery, Sample, proof, Remix, own-data, live or schedule, and checkout visitors by category while excluding internal and automated traffic. Public attribution stores no raw visitor id, network address, prompt, source content, or listing identifier in analytics.
Connect is no longer mistaken for Live
Reviewed OpenAPI services and remote MCP servers now move through Connect, Inspect, Test, read-only Sample, and Make Live. Only a promoted connection exposes its action selector to an Agent Team or workspace.
Every credential proves a safe read first
OpenAPI writes receive a separate fixed GET proof operation, while MCP servers must declare one read-only tool. Sample responses remain transient; Codelit stores only bounded status, attempt, and evidence metadata.
Origins, schemas, and capabilities stay pinned
Public HTTPS resolution, blocked redirects, bounded request and response sizes, timeouts, explicit scopes, conservative MCP annotations, exact approvals, read-only retries, and single-attempt writes form one runtime contract.
Capability drift pauses live work
A fingerprint covers the reviewed operation, policy, scopes, MCP protocol, server version, and tools. Definition, remote capability, or response-schema drift pauses affected actions until they are inspected and proven again.
Revoke and Delete have complete boundaries
Revoke erases credentials and active grants immediately. Delete also removes the definition, approvals, samples, action evidence, and workspace grants; account deletion covers credential-owned grants outside owned workspaces.
A demonstration becomes a visual Agent Team
Teach by example opens from any Browser Operator capability. A user approves one website boundary, demonstrates a task in the live browser, captures meaningful checkpoints, and receives a two-role Team Flow with run inputs, handoffs, evidence, and retries.
Semantic capture leaves secrets behind
Codelit retains accessible element hints and sanitized navigation, never raw keystrokes or demonstrated values. Entered fields become run-time inputs, provider video is disabled, screenshots obscure page text and form content, and all artifacts stay encrypted and deletable.
Protected gestures stay human
Sign-in, consent, verification, payment, destructive controls, uploads, downloads, and new domains become review or takeover steps instead of executable actions. Cross-domain capture stops the session and releases managed browser resources.
Sample comes before live
The inferred team remains a draft until the user confirms uncertain steps and runs a content-free Sample preview. Applying the draft preserves the normal exact-action approval, takeover, evidence, publish, and scheduling boundaries.
Teaching data has a complete deletion path
Individual checkpoints can be removed during review. Closing the wizard, deleting the account, or expiry cleanup releases the provider session, finalizes usage, and removes encrypted checkpoints and screenshots through owner-scoped server routes.
One Approval Inbox explains what is waiting
The global bell groups reviews by urgency, workspace, Agent App or automation, and run. A reviewer opens one bounded proposal, edits only server-declared action fields, and preserves the original proposal, reviewed diff, signed-in identity, and final digest before the run resumes.
Golden evals guard the workflow contract
Every candidate receives deterministic fixture checks for executable tools, approval gates, declared evaluations, evidence-capable writes, and step boundaries. An optional model judge is limited to five cases and one 256-token managed request.
Active and candidate behavior compare side by side
Trigger Hub now shows version-pinned pass rate, average cost, latency, proven actions, golden results, and exact added or removed permissions before an operator chooses a 5%, 10%, 25%, or 50% staged rollout.
Rollback stops unfinished work without replay
Promote and rollback update immutable pointers and lifecycle receipts transactionally. Rollback restores the previous workflow, pauses the automation, halts only unfinished runs, and requires a separate manual resume; completed external writes are never replayed.
Team Health can pause under an explicit policy
Health now includes expired credentials, active and candidate eval regressions, and repeated approval timeouts. Owners may opt into automatic pause for critical failure patterns; Codelit records the reason, emails one recovery action, and never auto-promotes, expands permissions, or resumes.
Repository work stays inside reviewed files
Autonomous Release Team now starts from one issue, reads only repository guidance and selected paths, writes one exact patch path, rechecks the generated branch, verifies the Vercel preview, and returns PR, promotion, Slack, and source-issue proof.
Refund ceilings are enforced before Stripe
Refund Resolution Team carries the supplied policy and maximum amount through every handoff. The server requires one exact positive amount at or below that ceiling, reuses the approved checkpoint for idempotency, and updates the customer ticket only after financial evidence exists.
Lead follow-up respects permission by construction
Lead Qualification Team keeps LinkedIn research inside its approved domain, requires an explicit allowed or blocked outreach state and campaign identity, creates only an unsent Gmail draft, and stops before any CRM mutation when permission is missing or blocked.
Each outcome has a safe repeat path
Repository issues and weekly maintenance, signed refund events, and quiet-hour lead refreshes now open with bounded Trigger Hub defaults, deduplication, daily limits, replay recovery, published Agent Apps, and the same durable Run Receipts.
One guide covers sample through automation
Searchable documentation now lists the exact brief, connections, approval boundary, evidence, recovery behavior, Agent App path, and recommended trigger for all three flagship outcomes.
A proven team becomes a one-click Agent App
After publishing a redacted proof, creators can turn the exact workflow version into a focused run page with generated inputs, visible permissions, approval boundaries, duration, payer, proof replay, and Run now.
Funding and spend fail closed
Visitor-key apps keep the visitor's model credential in their own account and run design-only in the open tab. Publisher-funded apps reuse a reviewed hosted deployment with per-run, daily, monthly, and concurrent reservations plus pause, proof, deployment, version, and deletion checks at every boundary.
Links grow into safe distribution
Creators first review the exact owner-only draft page, then publish public, sign-in, unlisted, or workspace-only apps; copy a canonical link; enable revocable embeds; let visitors save apps for later; and support Remix without copying credentials, grants, workspace access, or runtime entitlement.
Every run returns bounded proof
Visitor inputs are validated against the declared form, identifying details and credentials are summarized or removed, forged browser-key action claims are rejected, public preview endpoints are edge-throttled, and receipts show payer, cost, terminal status, and scoped evidence without exposing another visitor's run.
Agent Apps have one management and learning path
Settings now shows the plan meter, every owned app with pause, access, embed, copy, and archive controls, plus saved apps that can be reopened or removed. Pricing, searchable documentation, deletion coverage, analytics, and the public changelog use the same server-enforced plan catalog.
One catalog defines every plan promise
Free, Pro, and Max pricing, seats, in-tab runs, schedules, hosted automations, managed-model allowance, browser minutes, and safety ceilings now come from one product record across enforcement, Pricing, Settings, exports, legal copy, and documentation.
Settings shows the four limits that matter
Account settings now separates my-key runs, managed models, managed browser time, and active automations. Each meter explains who pays, when it resets, and why scheduler capacity is a safety ceiling rather than prepaid execution.
Revenue and managed cost use real subscription data
Stripe stores normalized monthly recurring revenue from the actual price, interval, and quantity. Admin now shows active paid MRR, known variable contribution, margin, and maximum plan-allowance exposure while excluding trials and manual access from recurring revenue.
Usage stays private and enforced
The authenticated usage summary combines only the caller's model, browser, in-tab, and hosted ledgers, reports effective server limits, rejects stale Free-plan spend, and is private and non-cacheable on success and failure.
Plans and billing have a plain-English guide
A new Settings-linked guide explains Sample, BYOK, managed Live, Browser Operator, hosted automation, separate allowance resets, and the difference between run capacity and Codelit-funded spend.
Every Sample proof has one clear next step
Completed Sample Runs now show the verified result and a three-stage Sample, Your data, Automate path. Use my data starts the smallest private proof instead of sending users through a general setup maze.
Organic guides open the relevant working sample
Priority Agent Team articles now lead into an attributed, outcome-matched Sample Run. Codelit can measure which guide and placement produced a useful proof without changing the zero-cost sample boundary.
Outcome Gallery starts with proof users can inspect
Ten deterministic Codelit sample proofs now demonstrate support, repository, incident, browser, lead, hiring, document, and content outcomes. Each opens a sanitized receipt and a credential-free Remix path, clearly separated from owner-published results.
A proven workflow can become a weekly automation
Automate this proof opens Trigger Hub with the safest compatible runtime selected. Scheduled work now supports weekly cadence alongside hourly, six-hour, and daily options, with the same caps, health, evidence, and pause controls.
Saved BYOK secrets stay out of Settings
A saved provider key is no longer remounted into an input. Settings shows only its suffix and explicit Replace or Clear controls, while confirmation still tells the user when compatible models are available.
Activation reporting follows people, not retries
Page views, Sample completion, own-data selection, personalized proof, and automation intent now use clean unique-visitor reporting. Legacy Web Vital page-view noise, automated browsers, and admin traffic no longer inflate the product funnel.
Microsoft 365 connects where the work starts
Codelit's production Entra registration now supports organizational and personal accounts. Outlook, Calendar, Teams, OneDrive, and SharePoint request only the delegated capability selected on the Agent card, then return to that exact setup step.
Real Outlook work keeps its approval boundary
Production verification completed a bounded Outlook read and reached the Create draft approval preview with incremental Mail consent. The action remained held during the smoke test, proving the review gate without changing the mailbox.
Provider and webhook delivery stays destination-pinned
The shared outbound HTTPS transport now handles Node 22 networking without relaxing DNS rebinding protection, restoring reliable native provider calls and signed webhook delivery through the same reviewed-address boundary.
Team Health catches drift without model spend
Deterministic ten-minute checks now surface broken shared connections, stale approvals, repeated failures, trigger trouble, cost drift, budget pressure, and declining completion in Team Settings, Projects, and the global notification bell.
Repairs stay reviewed and narrowly scoped
Health recommendations route to the existing owner surface. Only a repeatedly failing active automation can be paused directly, and that requires publish authority, an exact typed confirmation, a fresh server recomputation, ownership rechecks, and a redacted audit event.
Successful outcomes become safe, remixable proof
Outcome Gallery adds a second explicit opt-in after a reviewed Run Receipt. Public cards contain only a bounded owner-reviewed sentence and aggregate controls, while outputs, operations, identity fields, source references, URLs, and evidence payloads remain excluded.
Gallery discovery follows receipt lifecycle
Owners can add or remove a listing immediately or later from Settings. Tagged server caching expires on publish, removal, revocation, and deletion; every card opens the validated receipt and a credential-free Remix path.
Agent Teams have a shared workspace
Paid owners can invite free accounts into role-shaped Owner, Admin, Builder, Reviewer, and Viewer access. Projects remain private until deliberately shared, while Projects and hosted run feeds expose only what each member may use.
Team approvals require the signed-in reviewer
Hosted checkpoints now appear in the global notification center and reviewer inbox. Email and Slack return to Codelit without a transferable decision token, one atomic decision wins, and expired requests halt safely.
Connections are shared as exact capabilities
Owners and admins grant one owner-held connector, provider account, custom action, or browser session with exact read and write operations. Tokens never cross the API, and every hosted run rechecks grants so revocation takes effect immediately.
Seat billing follows confirmed capacity
Pro includes three seats and Max includes ten per billing block. Owner-only changes are idempotent and prorated through Stripe, decreases respect occupied and pending seats, and Codelit changes capacity only after the signed webhook confirms payment.
Workspace activity stays useful and redacted
Team Settings now includes bounded cursor-paginated history for members, projects, connections, approvals, and seats. Event metadata is allowlisted on write and sanitized again on read without exposing payloads or credentials.
Trigger Hub starts teams from real events
One publish flow now supports hourly, six-hour, and daily schedules; GitHub issues and failed workflows; Slack channel messages; Gmail searches; Sentry issue queries; and signed inbound webhooks.
Automations wait safely and run once
Exact source consent, first-check baselines, durable cursors, replay-safe delivery IDs, HMAC verification, bounded payloads, quiet-hour encryption and resume, daily caps, queue pressure, and monthly hosted budgets apply before model work begins.
Every trigger has proof in Projects
Trigger health, one-click tests, recent deliveries, run logs, pause and resume controls, and signed-webhook secret rotation now live together in Projects without reopening the Agent Team builder.
Signed webhook recipes match production
Inbound receipts reveal the HMAC secret once and generate the exact delivery-id and raw-body signature headers the server verifies. Rotating from Projects invalidates the previous secret immediately.
Google and Microsoft connect from the capability
Choose one Gmail, Calendar, Drive, Docs, Sheets, Outlook, Teams, OneDrive, or SharePoint operation, continue with the provider, and return to the same Agent card. The default flow no longer asks users to find and paste a short-lived access token.
Delegated access refreshes without broadening
PKCE, encrypted ten-minute callback intents, exact-operation scope allowlists, verified identities, encrypted refresh tokens, Microsoft token rotation, Google incremental consent, same-account reconnects, and local disconnect keep provider access narrow and durable.
Ready means the exact operation is allowed
Template binding, Team Flow status, Live Run setup, and the server executor now agree on operation-level permission readiness. A connected Gmail read cannot silently become a Gmail draft write without a scoped reconnect and the existing action approval.
Agent Teams become the primary product story
Titles, descriptions, structured data, navigation, documentation, templates, comparisons, pricing, and answer-engine facts now describe Codelit first as a visual AI Agent Team workflow builder. Plan & Ship follows as the reviewed path into Product Plans, Architecture, repo packs, and GitHub.
Plan & Ship has one canonical home
A new product and documentation pillar explains the four delivery outputs, evidence-first workflow, structural change review, and relationship to Agent Teams without competing with the primary build-and-run experience.
Search and AI discovery use product truth
Stable sitemap dates, consolidated architecture URLs, crawlable answer-first text, safe Organization and WebApplication schema, accountable authorship, and updated social previews replace stale architecture-first and false-freshness signals.
Notifications no longer cover the work
Running, completed, failed, and approval-needed tasks now live behind one global bell with accessible red and green status signals. Finished work can be dismissed permanently without removing durable run history.
Flow edits where users expect
Right-click any Team Flow responsibility to continue, require approval, duplicate, copy, or paste it. Execution steps now use the same menu for details, adding, and ordering, while deterministic side lanes keep branches, failures, cards, and labels apart.
Every planning canvas supports direct action
Drag Team Flow cards into a layout Codelit remembers, then restore the automatic route in one click. Architecture and Product Plan now use consistent right-click menus for card and blank-canvas actions, while collision-aware Architecture labels and outside return lanes keep dense diagrams legible.
Runs have a real workspace
A collapsible, resizable terminal opens along the bottom only while a team runs. Managed browser work docks on the right with independent sizing and collapse controls across desktop and mobile.
One Integrations setup, two clear methods
OAuth apps and encrypted Provider accounts now share one readiness view without pretending their security models are identical. Every ready capability remains available from Agent Team tools and setup recovery.
Connections return to the exact task
GitHub, Slack, Jira, Linear, Notion, Figma, GitLab, Bitbucket, and Vercel OAuth now preserve the originating project route. After setup, Codelit reopens the selected Team Flow capability or Settings tab instead of dropping the user at the home page.
Architecture navigation respects intent
Untouched and successfully saved Architecture canvases can navigate without a false unsaved-work warning. Escape closes the active guide or overlay without resetting the board, and missing tour anchors keep their callout at the viewport edge.
Activation follows the full proof journey
The admin funnel now measures unique Sample proofs, ordered Sample-to-own-data conversion, own-data-to-live-proof conversion, and successful OAuth returns so the next product investment can be based on completed outcomes.
One path takes a Sample proof to real data
A completed Sample Run now offers Use my data. One guided panel restores the next missing checkpoint, selects the smallest read-only source, collects the template brief and browser-local model key, then starts a private personalized proof without sending users through broad Settings.
Personalized proof cannot quietly become a write
Proof-to-Live projects the workflow onto one exact read source and keeps connector writes, browser actions, and unrelated tools simulated. A separate Pro Live Run still rechecks plan, connection, approval, and budget boundaries before any managed action.
Proof conversion is measurable without retry inflation
The activation funnel now tracks Autopilot opens, checkpoints, abandonment, personalized starts, completions, and failures as ordered unique-visitor journeys, so repeated attempts cannot produce impossible conversion rates.
Documentation is now part of the product
A searchable, filterable documentation space covers the complete build, connect, run, supervise, and manage lifecycle for technical and non-technical users. Every Settings tab links to its exact guide, including webhooks, web access, local data, custom actions, Failure Lab, and live-data selection.
Delete now includes Team workspace data
Recent-auth, same-origin deletion releases browser and Telegram resources, removes owned workspaces and joined access, revokes grants, cancels Stripe billing, recursively erases projects, runs, receipts, integrations, secrets, shares, approvals, analytics, and browser storage, then removes Firebase Auth last.
The showcase proves browser and local execution
Theme-aware SVG demonstrations now show readable flow, supervised browser control, zero-managed-compute local runs, opaque approval callouts, and logos for all 22 OAuth and native service integrations without relying on a stale product screenshot.
Every managed runtime has a stop switch
Operators can pause managed AI, managed browser allocation, hosted runs, connected-app writes, or experimental runtimes independently. Requests fail before provider allocation or mutation while workflows, receipts, evidence, and read-only operations remain available.
Hard ceilings protect every paid outcome
Browser minutes reserve before allocation, hosted runs retain step, daily, per-run, and monthly model caps, Browser Operator keeps cycle and write limits, and provider actions remain approval-bound and at most once.
Outcome economics are visible
The admin release view now measures template-to-proof time, connection recovery, read-to-action and approval success, provider p95, browser takeover and minutes, local repeat use, Free-proof-to-paid conversion, and known variable cost per activated and retained user.
Public integration claims match execution
Pricing, Features, Integrations, Settings, templates, and the capability matrix now distinguish nine OAuth apps from 13 executable provider account types, and keep design-only imports and device-local experiments labeled honestly.
The complete runtime boundary is documented
A production threat model covers OAuth, vault secrets, SSRF, browser prompt injection, local files, WebContainers, WebGPU, MCP, approvals, idempotency, evidence, entitlements, and cost abuse, with a narrow rollback runbook for each executor family.
Five teams finish recognizable jobs
Autonomous Release, Incident Response, Refund Resolution, Lead Qualification, and Knowledge Operations now coordinate native providers, connected apps, Browser Operator, approvals, and Run Receipts as complete visual outcomes instead of isolated connector demos.
One brief starts the whole team
Live, BYOK, and Local runs ask only for the case fields that outcome needs, validate required email and HTTPS inputs, seed the first Agent with a structured handoff, and preserve the brief through retry and resume.
Connect each provider once
When one ready account matches a template, Codelit binds every matching read and action automatically. Multiple accounts stay an explicit focused choice, while a blocked Run opens the exact missing provider capability instead of failing silently.
Browser QA follows the real handoff
Release previews and company research can pass an exact page URL to Browser Operator while the fixed approved-domain boundary remains unchanged. Non-HTTPS, credential-bearing, private, and out-of-scope destinations are rejected before managed browser spend is reserved.
Dynamic actions stay allowlisted
Structured Agent outputs can populate provider fields, reviewed enum values, deployment IDs, messages, and documents. The rendered value is validated again before its exact approval, and completed writes keep their existing at-most-once checkpoint.
Try every outcome for free
Each flagship team includes a committed zero-cost Sample Run with success, one meaningful approval, denial, provider evidence, partial-completion language, and recovery behavior before the user connects an account or spends model and browser budget.
Thirteen provider families run natively
Agent Teams can now use Google Workspace, Microsoft 365, Zendesk, Intercom, Stripe, Shopify, HubSpot, Salesforce, Sentry, PostHog, Datadog, PagerDuty, and Supabase through registered bounded operations instead of design-only labels.
Connect the account once
Settings groups provider accounts by work, customer resolution, revenue, and engineering outcomes. Credentials are encrypted server-side, verified through a bounded read before showing Ready, support multiple accounts, and can be rotated or revoked without exposing them to workflow JSON.
Every action keeps the same safety contract
Fixed vendor hosts, pinned public DNS, response caps, provider-specific input allowlists, untrusted-data labels, exact approval digests, single-use write checkpoints, audits, and Run Receipts apply consistently across all native packs.
Interactive and hosted runs agree
Read operations ground a step without manufacturing an approval. Write operations show the exact provider, account, operation, and rendered fields, then execute once after the existing human decision in both Live Run and hosted schedules.
Every provider has an outcome Team
Thirteen searchable two-Agent templates cover coordination, support resolution, refunds, order operations, lead routing, incident response, product insight, reliability, and RLS-scoped data work. Each includes a complete zero-cost Sample Run before setup.
Provider setup stays visual
Add one Provider operation capability from the Flow, select a vaulted account and operation, then edit only the reviewed fields that operation accepts. Provider logos, setup state, permission, scope, and evidence stay consistent with the existing Team Flow inspector.
Connect a signed webhook
Agent Teams can deliver one reviewed HTTPS action with a unique delivery ID, pinned public DNS, HMAC proof, bounded retries, and a one-time signing secret. Redirects, private addresses, oversized payloads, and ambiguous replay remain blocked.
Turn one API operation into a real tool
A reviewed OpenAPI operation can now become a hosted executor after the user separately supplies its HTTPS endpoint and owner credential. Method, host, fixed path, input placement, schema, risk, response contract, and idempotency key cannot broaden at run time.
Remote MCP tools run through the same Flow
Codelit inspects stable Streamable HTTP MCP servers live, negotiates the supported protocol, discovers OAuth metadata, reviews bounded tool schemas, and executes only the selected tool. Stdio, commands, environment values, roots, sampling, elicitation, and server-initiated requests stay unavailable.
Custom actions pause on the exact request
Every generic action renders its destination and structured input before approval, consumes a digest-bound decision once, checkpoints uncertain writes, and returns bounded evidence without exposing credentials, private payloads, or provider response headers.
Secrets stay in the owner vault
API credentials and webhook signing secrets are encrypted server-side and never enter workflow JSON, browser storage, analytics, or public receipts. Imported OpenAPI and MCP files continue to discard runtime URLs, credentials, commands, and environment values.
Setup happens on the selected capability
The Team Flow inspector now creates and selects Signed webhook, Reviewed API, or Remote MCP connections in place, then shows scope, access, request preview, reviewed schemas, and the exact reason a tool is blocked.
A real Agent Team runs in your browser
Run locally executes the existing multi-step Agent Team engine in a dedicated browser Worker with your selected model and provider key. The new LocalBrief team turns reviewed private files into an evidence-led action brief without a Codelit-funded model or cloud runner.
You approve the exact local boundary
Included paths and excluded secret-bearing paths stay visible before Run. Connected reads, connected writes, managed browser tools, arbitrary local access, and hosted continuation remain unavailable in this mode instead of silently falling back.
Pause, reload, and continue
Completed steps checkpoint under the current account in IndexedDB. Stop or close the tab to mark the run interrupted, then resume from the next unfinished step after reload with bounded artifacts and a durable Run Receipt.
Local schedules catch up once
An open-tab schedule can reload its reviewed workspace into a fresh Worker, coordinate across tabs with Web Locks, and run one missed occurrence after sleep. Approval-gated work holds for review instead of making an unattended decision.
Your key and device fund the run
Supported providers receive requests directly from the Worker. Providers that cannot return browser-readable responses use the existing authenticated memory-only relay; keys and request content are never written to Codelit storage or analytics.
Local data leaves when you delete it
Workspaces, handles, checkpoints, receipts, artifacts, schedules, active pointers, and linked History entries share one account-scoped deletion boundary. Switching accounts cannot restore another account's local workspace or run proof.
Give the browser a goal
Agent Teams can now use a Browser Operator instead of hand-authoring every page step. Choose a website, state the outcome and visible proof of completion, then keep advanced fixed steps folded away unless the workflow needs them.
Generated plans stay inside policy
Every proposed step is parsed into the same bounded navigate, wait, click, fill, press, or select vocabulary. Domains are fixed before Run, page text is treated as untrusted, and scripts, raw selectors, private hosts, secrets, payments, purchases, destructive controls, uploads, and downloads remain blocked.
Watch, approve, or take control
The Run surface shows the live browser, current intent, progress, exact pending action, and Stop control. Login, MFA, CAPTCHA, consent, or a lost target pauses the same session for user takeover, then resumes from its checkpoint when control returns.
Reviewed runs become recipes
A successful run always finishes with current DOM evidence and a screenshot-backed audit. After reviewing it, save the goal and website boundary as a Browser Recipe and reuse it from another Agent Team without copying credentials or private page content.
Managed browsing stays bounded
Browser Operator is a Pro and Max Live Run feature with minutes reserved before provider allocation, one active session per saved website, hard action, replan, time, and token ceilings, and retryable cleanup. Free users keep the zero-cost Sample Run experience.
A browser-first team is ready to remix
The new Browser QA Investigation Team demonstrates a public website goal, policy-validated operation, evidence verification, Run Receipt, and reusable recipe as one coherent end-to-end template.
Connected apps can finish the job
Slack can deliver approved updates, Vercel can create previews or perform reviewed release changes, GitHub can comment, branch, commit bounded files, and open pull requests, Jira and Linear can manage scoped issues, and Notion can create or append bounded pages.
Every write pauses on the exact action
Agent Teams render the final provider, scope, message, fields, branches, or files before approval. Successful writes checkpoint once, uncertain writes never replay automatically, and provider timeouts and policy failures stay distinct.
Six outcome teams use real adapters
Release proof, preview deployment, issue follow-up, Jira intake, Linear incident follow-up, and Notion knowledge capture templates each separate read context from the approved action and return provider evidence instead of simulated success.
Action setup stays inside the Flow
Select a capability, switch from Read context to Take action, and configure only the fields that operation needs. Missing connections still open the exact Integrations setup and return to the selected Agent.
Write consent and proof stay private
Jira and Linear request write consent on reconnect, owner credentials remain in the encrypted hosted vault, approval records retain only a cryptographic digest, and public Run Receipts show provider and evidence type without payloads, credentials, private ids, or URLs.
Read-only boundaries remain truthful
Figma, GitLab, and Bitbucket stay read-only until a measured workflow need justifies a narrow reviewed action. Standalone exports fail closed for managed connected-app writes rather than bypassing Codelit's approval and checkpoint controls.
One card, one action
Every Team Flow node now has one clear interaction: select the card to open its inspector. Tools, setup state, and outputs remain readable labels instead of competing buttons inside the flow.
Handoffs stay outside the work
Direct handoffs use centered ports while approvals, conditions, and failure routes use labeled side rails. Automated geometry checks keep connection paths and labels from hiding behind cards.
Editing belongs in the inspector
Agent, tool, output, and Add next controls now live in one full-height inspector that slides from the right on desktop and mobile. Adding work creates and connects the next step instead of leaving an unlinked item.
Cards grow with their content
Node height now follows its complete label, description, and tool summary with consistent padding. Vertical ranks expand with the tallest card so content, handoffs, and connection labels remain clear.
Team Flow is the new Build
Agent Teams now open as a visual flow of triggers, specialist Agents, handoffs, approvals, decisions, and outputs. Select the work to configure it, describe changes in plain language, or open exact Execution and Details controls when needed.
One Flow for design and runs
Flow now combines design and execution in one full-screen workspace, with History reserved for durable proof. Centered vertical ranks keep handoffs clear, the wheel zooms instead of scrolling the page, provider marks identify connected tools, and Team Flow and Execution share the same node frames, canvas controls, toolbar, inspector, and responsive visual system.
Browser work is a first-class tool
Teams can read public sites, use signed-in browser sessions, request approval before actions, hand control to the user, return control safely, and retain bounded evidence without an extension.
Plan & Ship stays with the project
Generate and review Architecture, Product Plan, repo packs, and GitHub handoffs from an Agent Team. Structural previews require explicit acceptance and never overwrite approved edits silently.
Projects hold multiple Agent Teams
Ordered teams, child runs, schedules, defaults, and planning artifacts now share one project context, while legacy projects and routes remain readable through the compatible migration path.
Rollout and product proof are measurable
A reversible internal, new-user cohort, and all-user rollout tracks anonymous visual exposure, edit-to-run time, Details use, repeat runs, blocked-run recovery, browser-backed completion, Plan & Ship use, support contacts, and managed compute cost without recording prompts or secrets.
Four outcome teams start in one click
Lead qualification, candidate screening, document intake, and content repurposing now include deterministic sample runs, human approvals, one-source live setup, and structured terminal handoffs.
Hosted teams return signed results
Schedules can deliver completed, halted, and failed outcomes to a generic HTTPS webhook with HMAC signatures, stable delivery ids, bounded payloads, private-address blocking, pinned DNS, and transient retries.
Template readiness is explicit
The library distinguishes instant samples, executor-backed live setup, and design blueprints. Existing connected and browser tools now map to their real runtime boundary instead of relying on blanket runnable claims.
Flow actions stay in the canvas
Add opens from the Flow itself with a portaled palette, while the estimated run cost again expands into the same model and step breakdown used by History.
Browser-key runs choose before they read
Workflows can reference several integrations without blocking Run with my key. Each active-tab run still selects exactly one read-only source, and steps using other integrations stop instead of inventing live data.
Run options say what they do
Managed source selection is labeled Select live data (Pro), while Failure Lab opens from Safety check with an explicit Static analysis label and zero-execution explanation.
Analytics keep content and identifiers out
A shared allowlist now strips dynamic record ids, receipt ids, nested data, content fields, and full referrer paths before first-party analytics writes. Firestore accepts the complete growth-event catalog and rejects unapproved metadata.
Connected apps stay with the right account
OAuth sessions now carry an HttpOnly account owner. Direct account switches clear device sessions instead of copying one user's connected-app tokens into another user's hosted vault.
Every workflow connector is exercised
GitHub, Jira, Notion, Linear, Figma, Slack, GitLab, Bitbucket, and Vercel now have automated in-tab and hosted read coverage. Scope validation, eight-second provider timeouts, and capability labels make failures and write boundaries explicit.
Live Run setup has a way forward
When a required app or website is missing, Live Run now opens the exact Integrations or Web access tab that resolves it. Public copy makes clear that the one-click run begins after required apps are connected.
Model relays are bounded and private
Managed, keyless, and documented generation routes cap requests and output, apply timeouts and no-store headers, reject malformed roles and scopes, and never log or echo raw provider account and credit details.
Mobile approvals stay above analytics consent
Optional cookie consent now yields while a workflow run is active, so Sample, BYOK, and managed approval and completion controls remain reachable on small screens while analytics storage continues to default to denied.
Hosted work claims exactly once
Scheduled occurrences, queue claims, active deployment limits, stale-run recovery, approval expiry, and browser reservations now use bounded transactional ownership so overlapping ticks cannot duplicate work or spend.
Open-tab schedules belong to one account
Schedules and pending hosted promotions are tied to the signed-in account, recurrence pauses without Web Locks, account switches reset local tasks, and deleted work cannot reappear after a late completion.
Imported tools stay honest
OpenAPI, MCP, and n8n imports preserve an explicit design-only execution boundary. They remain available for planning, Dry Run, Failure Lab, and export without silently becoming a live connected-app tool by name.
Local file consent survives reloads
Reviewed file selections now persist with the browser-only workspace index, so future runs use the same bounded excerpts until the user changes or deletes that selection.
Run Receipts are harder to leak or over-create
Receipt creation and revocation use transactional owner caps, while redaction now rejects additional cloud keys, personal tokens, webhook credentials, and generic secret assignments before publication.
Mobile controls stay reachable
Board overflow now includes Home on phones, run consent and scheduling avoid first-tour collisions, import tabs support keyboard navigation, and proof and command surfaces expose cleaner landmarks and labels.
Failure Lab says exactly what it proves
Results now describe deterministic static readiness analysis and control coverage, avoiding claims that network failures or containment were actually executed.
Private local workspaces
Add reviewed JSON, CSV, Markdown, text, YAML, pasted context, or a local repository to any builder. Bounded indexes stay in browser storage, and only checked excerpts reach the selected model provider.
Secrets and build output stay out
Local indexing skips dependencies, build output, env files, keys, certificates, binaries, and oversized inputs. Secret-bearing files are flagged and excluded before a model can receive context.
Local data remains under your control
Worker-backed indexes survive reloads without cloud persistence. Settings shows device usage separately from model cache and can delete one workspace or all local agent data permanently.
Run agents with your own model key
Signed-in users can run eligible workflows in the active tab with any of 11 provider keys. The selected provider and model stay fixed, completed steps checkpoint locally, and the run cannot fall back to a Codelit-funded or alternate model.
BYOK transport is explicit and bounded
Most provider requests go straight from the browser. Cerebras uses an authenticated memory-only relay because its responses are not browser-readable; request bodies and keys are never logged or stored, and every route is size, owner, provider, and run limited.
Instant Sample Runs need no model
Eligible agent templates now execute committed sample inputs and artifacts with approval gates, zero external calls, and zero model cost, giving every visitor a truthful one-click first run.
Publish redacted proof, then Remix
Completed runs can become revocable public Run Receipts with field-level output controls. Recipients can remix the sanitized workflow into their own board and complete a Sample Run without inheriting private ids, credentials, or project state.
Failure Lab tests resilience for free
Run nine deterministic timeout, rate-limit, malformed-output, auth, injection, approval, cost-cap, and partial-failure scenarios with zero model or connector calls. Fix missing controls, open Launch Review, and publish a bounded scorecard for Remix.
Bring existing workflows into the same loop
Import OpenAPI 3, MCP manifests, or n8n JSON through a bounded review. Codelit shows mapped items and exact warnings, discards runtime secrets and code, requires confirmation before replacement, and keeps Undo, Dry Run, Failure Lab, sharing, and export available.
Repeat agents while Codelit is open
Free users can schedule one eligible workflow with their own model key. Web Locks prevent duplicate runs across tabs, sleep catches up at most once, task and desktop notifications deduplicate, and pause, delete, or Clear finished tasks remain durable.
Promote the same schedule to hosted
Keep it running after I leave carries the workflow, interval, model route, approvals, notifications, and compatible sources into existing hosted operation. Local file handles and content are never copied; local-only inputs require explicit exclusion or replacement.
GitHub Actions runs natively
Live workflows can inspect recent Actions runs and jobs. Dispatch, rerun-failed, and cancel operations show the exact action first and require a one-time approval bound to that run and step.
Architecture docs become real context
Repository instructions, architecture files, ADRs, and Notion docs can ground agent steps through explicit executors instead of being labeled as design-only tools.
Live Run starts in one click
Pro Live Runs now respond immediately, select relevant connected sources automatically, and use an isolated managed browser without requiring an extension. Advanced source selection remains in Run options.
Writes run exactly once
Browser writes require a concrete preview and single-use approval. Verification reuses the completed action's evidence instead of replaying the write, while unsafe targets and redirects remain blocked.
Connect a website, not infrastructure
Settings now needs only one website address. Codelit derives the allowed domain, opens sign-in, encrypts the saved access, and makes it available to future Pro Live Runs.
Web access and notifications get focused settings
Web access and Notifications now have dedicated tabs. Live Runs join the shared task status, desktop and email alerts are explicit preferences, Slack can send a test, and completion webhooks remain one click away.
Connected-app tokens leave browser storage
GitHub, GitLab, Bitbucket, Jira, Notion, Linear, Figma, Slack, and Vercel sessions now use secure HttpOnly cookies, unique OAuth state, automatic token rotation, and encrypted hosted-run sync instead of exposing credentials to browser storage or callback URLs.
Every advertised integration reaches a workflow
All nine connected apps now have explicit import, live-read, notification, or deploy capabilities. GitLab, Bitbucket, and Linear reads run through Codelit's server boundary, and scheduled runs reuse the same encrypted credentials.
Hosted runs stay visible and stay cleared
Queued, running, approval, completed, halted, and failed hosted runs now appear in the shared task bar, send deduplicated completion email when enabled, and honor Clear finished tasks across reloads.
Scheduled work cannot disappear behind history
A bounded active-run queue now drains new schedules, webhooks, approvals, and Telegram triggers independently from old run history, recovers interrupted work, expires stale approvals, and retains concise user-visible summaries.
Exports include executable adapters
Repo packs now include GitHub Actions, architecture-doc, and Browserbase/Playwright adapters plus the required environment manifest, so shipped workflows preserve the same execution boundaries.
Public pages follow the device
Showcase, pricing, features, integrations, docs, templates, blog, changelog, and legal pages now resolve Light, Dark, or System before first paint and update live when a device preference changes.
One visual system across the public site
The showcase's technical grid, high-contrast surfaces, translucent navigation, compact geometry, and violet, cyan, and pink accents now form the shared public-page theme.
Product workspaces stay focused
The shared public shell is deliberately scoped away from Agent Studio, projects, saved work, admin, embeds, and other operational surfaces so their interaction contracts do not change.
A product film leads the page
The showcase now opens with a large launch-review film and a sharper product promise, framed by Codelit's violet, cyan, and pink technical rails.
Motion starts without a refresh
The Remotion sequences are rendered into lightweight native video, so muted inline autoplay works on direct loads and in-app navigation without depending on the player hydration lifecycle.
A stronger, simpler product story
Small repeated feature cards gave way to four editorial bands for context mapping, failure simulation, review handoff, model choice, integrations, and hosted operation.
Clearer review and failure motion
The Refund resolution film opens on a complete workflow, while failure simulation keeps solid node labels above its connectors so every stage stays readable on desktop and mobile.
Every supported AI provider is visible
The showcase now lists all 11 bring-your-own-key providers from the shared provider configuration: OpenRouter, OpenAI, Anthropic, Gemini, xAI, Mistral, Groq, Perplexity, Together, DeepSeek, and Cerebras.
Sharper, current feature language
Import consent, simulations, launch reviews, repo packs, hosted schedules, webhooks, audits, linked builders, templates, parsers, and encrypted BYOK now read as one coherent workflow instead of disconnected features.
Builder choice is clear at the composer
The homepage restores its short rotating brace headlines and places Agent Workflow, Architecture, and Product Plan directly above the composer, without repeating the selected mode in extra helper copy.
Launch review before editor complexity
Templates and newly generated workflows now open with readiness, the projected run path, approval gates, release checks, final output, and trace evidence before the full editor tour appears.
Run the dry simulation from the review
The launch review starts the existing step-by-step dry run directly, including human approval pauses and completion evidence, without calling models or external tools.
Shared links open on the evidence
Agent workflow shares now deep-link recipients into the launch review. The admin funnel separately measures review opens, simulation starts and completions, shares, unique shared-link opens, and production handoffs.
Light, dark, and system themes
Codelit now ships a full light theme alongside dark. Pick Light, Dark, or System in the new Settings → Appearance tab. System follows your device and switches live when your OS does, with no flash on load.
Higher contrast across both themes
Muted text is brighter, borders are clearer, and surfaces read as distinct layers. Accent colors were tuned so status pills, colored text, and diagram edge labels stay legible in light mode instead of washing out on white.
Webhooks get their own settings tab
A dedicated Webhooks tab leads with the live inbound trigger URL. POST to it from Zapier, Make, n8n, or curl to start a run from anywhere. The outbound endpoint moved here too, with a payload preview and a working Send-test button.
Learn more, without leaving the app
A new Learn more tab in Settings puts the footer's Product, Resources, and Legal links (docs, guides, pricing, changelog, and more) one click away for signed-in users.
API docs cover the run-trigger endpoint
The API reference now documents POST /api/runs/trigger, the webhook that starts a deployed workflow from any app, alongside architecture generation and repository analysis.
Live runs: the workflow you design now actually runs
Live Run executes every step as a real streamed model call with step-to-step artifact handoffs and Approve/Hold gates. Dry Runs remain free for simulation; Pro Live Runs can use bounded connected-app and browser executors.
Ground runs in your real GitHub data
Connect GitHub and a per-run consent bar offers read-only grounding: pick a repo and the run's tool calls read your actual open issues, so streamed output reasons about your real backlog. Strictly read-only, one decision per run, and reads only happen after approval gates are granted.
Actual cost next to the estimate
Completed live runs show what the run approximately cost against the estimator's predicted range, so route and model choices are grounded in observed numbers before you ship.
Repo packs ship with a recorded reference run
A completed live run rides along in the Pro repo pack as fixtures/live-run.json with a generated contract test that replays it. The export starts life as a repo with a passing, recorded reference run instead of empty scaffolding.
Design → Run → Ship on the homepage
The landing page now tells the full loop with a three-panel strip: design the workflow, run it live before it touches your systems, then ship a run-backed repo pack. The pricing page presents Pro as concrete deliverables with the repo pack's actual file list.
Trust and accessibility polish across the app
Cloud saves now show a quiet Saving/Saved indicator, canvases support keyboard panning and zoom with labeled controls, sidebar actions are keyboard-reachable, mobile chrome surfaces the readiness score and coach chip, and contrast was raised to a readable floor everywhere.
Vercel integration install flow
Vercel OAuth now uses the marketplace integration authorize URL, validates install callbacks, stores scoped access safely, and exposes status, projects, and disconnect endpoints for the app.
Bring-your-own-key settings are easier to find
The Models settings tab now opens API keys by default with a clearer Advanced section for OpenRouter, OpenAI, Anthropic, and Gemini.
Model dropdowns link straight to API keys
Every shared AI model selector now includes an API keys affordance, and locked model prompts route users directly to the expanded provider-key settings.
More complete integration roadmap
Settings now surfaces suggested next integrations for Confluence, Google Drive, Sentry, Datadog, PostHog, Supabase, cloud providers, and Zendesk.
Centered app icons
The SVG favicon and generated favicon, touch icon, and PWA icon assets were regenerated so the Codelit mark sits visually centered at every size.
Workflow review modal spacing
The Agent Workflow review modal now pads the AI security audit and resilience lint content so headings, actions, and findings align with the dialog header.
Skills and MCP in the guided path
Agent Studio now walks users through Skills and MCP before the handoff step, with plain-language helpers and quick-add presets instead of hiding reusable behavior in Advanced.
Searchable agent tool catalog
The setup tool catalog and Add Tool dialog now support search and category filters, making Slack, GitHub, browser, data, runtime, and custom tools easier to find.
Simulation path preview
The simulation modal now shows the trigger, agent steps, tool calls, approvals, final output, and trace events in one readable run path before production is connected.
One-click readiness fixes
Failed readiness checks now fix common gaps directly: triggers, specialist agents, tool contracts, approval gates, Skills, MCP servers, model routes, runtime services, evals, and harnesses.
Cleaner Agent Studio tab transitions
Setup, Runbook, and Advanced now use standard Framer Motion enter/exit transitions without layout morphing the surrounding panel.
Agent-specific admin funnel
The admin dashboard now tracks agent interest, template opens, workflow starts, simulations, repo pack downloads, and GitHub handoffs as a dedicated product funnel.
Clearer agent template onboarding
The /agents first-run screen now explains that templates include agents, tools, Skills, MCP, evals, and handoff files so users know what they get before opening one.
More high-intent agent workflow articles
Added new practical guides for MCP vs REST APIs, permission matrices, issue-to-PR coding agents, n8n AI workflows, Slack agents with Skills, and customer onboarding agents.
Agent Workflow is now first
The homepage now opens with Agent Workflow selected, placing Claude Code, OpenAI Agents SDK, Hermes, OpenClaw, LangGraph, n8n, and CrewAI-style workflows at the front of the product story.
Unified work history
The home sidebar now saves and restores agent workflows, product plans, and architectures in one timeline, with type badges and counts so every workspace can be reopened from the same menu.
Projects for every workspace
The Projects page now supports agent workflows and product plans alongside architectures, with type-aware cards, readiness checks, run timelines, and the right open action for each workspace.
Sharper agent starters
Cleaned up the homepage agent cards with more useful production workflows: repo maintenance, SDK-grade support, stateful incidents, browser operations, workflow automation, research desks, evals, billing, and data quality.
Branded agent templates
Agent template cards now use recognizable marks for Hermes and OpenClaw plus platform-specific icons for Claude, OpenAI, LangGraph, n8n, CrewAI, and the rest of the workflow library.
Agent readiness, simulation, and repo handoffs
The Agent Workflow Studio now scores launch readiness, shows actionable gaps, simulates a run without touching tools, downloads a GitHub-ready repo pack, and can push verified agent workflow handoff files through the existing GitHub export path.
Agent studio visual polish
The /agents workspace now uses the same Codelit palette, surfaces, borders, inputs, and primary/accent states as the rest of the site, with cleaner desktop and mobile readability.
Expanded agent tool catalog
The Add Tool flow now includes presets for Linear, Zendesk, Intercom, Gmail, Calendar, Teams, Discord, Confluence, Drive, Figma, GitLab, Bitbucket, Stripe, HubSpot, Salesforce, Supabase, Snowflake, BigQuery, Sentry, Datadog, PostHog, PagerDuty, Vercel, Kubernetes, AWS, GCP, LaunchDarkly, Vault, MCP, browser, database, and custom APIs.
Calmer agent builder UX
The /agents workspace now uses shared tabs for Setup, Runbook, and Advanced, softer panel motion with reduced-motion support, and a mobile inspector drawer for focused editing.
Organic agent workflow content
Added 15 research-informed blog posts for agent workflow examples, MCP server architecture, Skills governance, eval metrics, SRE, RAG, SDR, customer success, finance ops, security, governance, and agentic SDLC.
Production agent SEO expansion
Added 13 more high-intent guides for AgentOps, non-human identity, context engineering, agent memory, deployment checklists, ROI, runtime governance, release gates, MCP security, reliability, PM scoping, regulated industries, and data pipelines.
Agent-first blog categories
The blog now prioritizes current agent search categories like AI agents, agentic workflow, MCP, AgentOps, evals, Skills, context engineering, governance, workflow automation, security, DevOps, and SaaS instead of only sorting by old post volume.
Agent-first roadmap and creator entry
Documented the agentic workflow roadmap and replaced the empty /agents state with a guided creator entry, prompt start, template shortcuts, and clear simulate/readiness/repo-pack outcomes.
More professional Agent Studio
The /agents workspace now matches the main Codelit background, surface, border, and purple-pink action palette, with fewer nested boxes, flatter setup rails, cleaner section headers, and in-place workflow editing cues.
Operator-grade admin dashboard
The /admin page now shows acquisition, activation, handoff intent, Pro conversion, 7-day event volume, high-intent actions, top content, model/export usage, and recent activity in one command center.
Admin-only metrics API
Admin analytics now aggregate through an authenticated server route, so protected user/auth tables can be shown without relying on client-side Firestore reads.
Unique users and auth tables
Admins can inspect unique users by provider, journey stage, subscription state, verification, usage, sessions, account creation, and last seen activity.
Third creation mode
Home now supports Agent Workflow alongside Architecture and Product Plan, so teams can design autonomous work before wiring tools.
Sharper home positioning
The homepage now frames Codelit around architecture-first SDLC work: system maps, product plans, agent workflows, and production handoffs without redundant feature copy.
More home agent workflow starters
The Agent Workflow mode now has 22 home-page starters, matching the depth of Architecture and Product Plan with workflows for support, billing, browser ops, evals, data, compliance, DevRel, and model routing.
Agent Workflow Studio
The /agents page now uses animated high-contrast cockpit views for setup, runbook review, and advanced controls, with cleaner Claude-style surfaces, responsive phone layouts, shadcn-style fields, searchable agent/model pickers, and a real tool creator for presets or custom capabilities.
Workflow spec view
Generated workflows include specialist agents, triggers, tools, model routes, guardrails, evaluations, deploy targets, and a handoff export.
Runtime and cloud controls
Agent workflows now expose trigger modes, cloud services, credential vaults, queues, streaming channels, memory stores, replay traces, and output contracts from the Advanced tab.
Research-informed agent patterns
Prompting and UI now account for current Gumloop, Claude, and n8n patterns: chat/webhook/schedule triggers, Skills, MCP, human approvals, output contracts, streaming, evals, and run replay.
Skills, MCP, and harnesses
Agent workflows now model skill packs, MCP servers, exposed tools/resources/prompts, eval harnesses, sandboxes, replays, and approval gates as first-class production pieces.
Arch-style agent chat
The /agents chat now matches the architecture editor composer with contextual suggestions, live updating state, model controls, handoff actions, and workflow readiness context.
SEO-ready agent templates
Added /agent-templates and per-template pages for Hermes, OpenClaw, PatchPilot, AnswerOps, EvalForge, Scout, Sentinel, LedgerOps, LaunchPilot, DataSmith, PR review, and internal operations workflows.
Agent workflow field guides
Added 49 practical blog posts for agent workflow use cases: Slack triage, PR review, support, MCP, Skills, evals, approval gates, browser ops, billing, incidents, BYOK, AI infra, and production architecture.
Architecture and board handoff
Agent workflows can generate a production architecture or product plan, keeping agent planning connected to the existing Codelit build path.
Agent workflow launch content
Added the Agent Workflow feature page, sitemap entry, footer link, and launch guide for teams building Slack, GitHub, and internal operations agents.
Sharper welcome email
New accounts now get a first-run goal: bring one real system into Codelit and turn it into an architecture another engineer can review.
More useful transactional emails
Pro lifecycle, task-complete, billing, cancellation, and GitHub handoff emails now explain the next action instead of just announcing status.
Contextual guide links in emails
Welcome, Pro, task-complete, and GitHub handoff emails now include relevant Codelit guides and how-to posts as secondary next reads.
Blog post loading restored
Blog, template, and product-spec detail pages are now generated as static routes at build time instead of relying on on-demand ISR for local content.
Stale chunk protection
Removed custom stale-while-revalidate headers from HTML routes so cached pages no longer point browsers at old Next.js route chunks after deployments.
One-time chunk recovery
If an open browser tab still has an older app runtime, ChunkLoadError screens now refresh once automatically to pick up the current deployment.
Lower ISR usage
Local content pages avoid runtime ISR reads and writes, helping keep the Vercel Hobby quota available for features that actually need server-side generation.
Welcome emails for new accounts
First-time sign-ins now receive a branded Codelit welcome email with a clear path from prompt, README, repo, or spec into architecture work.
Pro subscription lifecycle emails
Stripe webhooks now send thoughtful transactional emails for Pro activation, trial-ending reminders, failed payments, and canceled subscriptions.
GitHub handoff-ready emails
When a production handoff is verified on GitHub, Codelit can email the repo link and confirmation details so users know the scaffold is ready.
GitHub sign-in callback fix
GitHub sign-in now uses Codelit's own OAuth callback and Firebase custom tokens, avoiding callback conflicts with the GitHub repo connection flow.
Cleaner auth form inputs
Auth fields now use stable form keys, explicit autocomplete metadata, and controlled focus so typed text is not reselected while users sign in or create an account.
Verified task-complete notifications
Background task emails now use the signed-in Firebase session instead of accepting arbitrary email addresses from the browser.
Production readiness checklist
Projects now show a clear readiness score across architecture capture, AI iteration history, GitHub handoff, review pack generation, and deploy target linkage.
Selectable run detail panel
The Projects timeline now opens each run into a focused detail panel with status, timestamps, summary, and the artifacts created by that run.
Cleaner artifact actions
GitHub repos, deploy links, architecture snapshots, and handoff reports are easier to open or copy from one place without hunting through timeline cards.
Pinned Vercel Node runtime
Production builds now target Node 22.x explicitly, reducing surprise runtime drift when Vercel updates default Node majors.
Project workspaces
Signed-in users now get a Projects dashboard that groups saved architectures, GitHub handoffs, deploy links, generated artifacts, and run history around each system.
Project memory in architecture chat
Opening a project keeps it active in /arch. Follow-up prompts can use recent project runs as context, then write AI architecture updates back into the project timeline.
Verified production handoff exports
GitHub handoffs now generate architecture docs, decisions, security review, cost estimate, CI, runtime files, and service scaffolds, then verify required files before reporting success.
Saved architecture backfill
Existing saved architectures can be indexed into Projects automatically, so older work appears in the new workspace view without manual migration.
Private workspace SEO cleanup
Account-only workspace routes are no longer advertised in the public sitemap, while saved and project pages keep noindex metadata.
Production build fix
Vercel now builds with webpack for this Next.js 16 app, avoiding the Turbopack CSS panic from @xyflow/react and restoring reliable production deploys.
Searchable dynamic model menu
The model picker now has autocomplete on the home page, /arch, and board chat surfaces. It pulls refreshed provider catalogs so new models appear without hardcoding every option.
Gemini + provider BYOK routing
Added Gemini model support and unified BYOK handling for OpenRouter, OpenAI, Anthropic, and Gemini. Chat requests now use the user-provided key for the selected provider.
Clear AI error messages
Rate limits, missing keys, invalid keys, model access issues, and unavailable endpoints now surface actionable messages instead of generic failures.
Stop button for every AI chat
Home generation, architecture follow-ups, and product plan updates now keep the input editable while loading and turn the send button into a square stop control that cancels without applying changes.
GitHub export clarity
Repo creation and scaffold export now explain partial, existing, and empty-repo states more clearly, with safer success handling only after generated files are confirmed.
Cleaner loading and overlay UX
Solid model dropdowns, right-panel-aware status bars, better input alignment, and product plan loading states now match the architecture chat experience.
Multi-Agent Builder (Phase 5)
8 specialized AI agents (Frontend, Backend, Database, Queue, Cache, CDN, External, Platform). Build All runs agents in parallel: nodes pulse amber while building, turn green on completion
Orchestrator + Download Project ZIP
After all agents finish, orchestrator auto-generates docker-compose, API contracts, shared types, and README. Download everything as a ZIP (Pro)
Shareable slug URLs
Architectures and boards get clean URLs like /arch/uber-ride-matching-k7x9m. Rich OG/Twitter previews + JSON-LD structured data for SEO
Product Plan wireframes
Screen-type cards now show mini SVG wireframe previews: login forms, dashboards, list views. Variable row spacing for visual balance
Agent chat + version diff
Chat with any built node's agent to refine code. Hover version timeline pills to see added/removed/modified nodes between versions
Webhooks, task persistence, error boundaries
CI/CD webhooks (Pro), build results saved to Firestore, canvas-specific error recovery, and 45+ architecture URLs in sitemap
Slack, GitLab & Bitbucket integrations
Share diagrams to Slack channels, import repos from GitLab and Bitbucket. Now 8 OAuth integrations total
7 audit tools, new: Vulnerability Scan, Code Quality, Load Test
Dependency vulnerability scanner (16 rules), SonarQube-style code quality grading (A-F), and load test simulation with RPS/latency estimates
8 new export formats
Pulumi GCP, Railway, Render, Docker Hub CI/CD, Storybook, Monitoring (Datadog/Sentry/Grafana), and more
AI Architecture Coach
8 guided system design challenges (Easy→Hard) with hints, reference components, and one-click AI solutions at /features/coach
100 product specs, full PRD framework
Every spec now has non-functional requirements, release milestones, acceptance criteria, and success metrics
Architecture diff & key audit log
Compare two architectures with similarity scoring. Track all integration key usage in Settings
6 new SEO blog posts
System architecture guide, diagram generator comparison, AI system design, interview questions, microservices vs monolith, and why you need a system design tool
Figma integration
Connect Figma and paste a design URL. Codelit extracts screens, detects UI patterns, and generates system architecture
Jira, Notion & Linear integrations
Import epics, pages, or issues directly. 5 integrations in Settings with one-click OAuth
100 product specs
/specs page with Uber, Netflix, Figma, OpenAI, Cursor, LangChain, and 54 more. Features, user stories, tech stacks, and one-click architecture generation
Build This: diagram to code
Generate a complete project scaffold from any architecture. Docker Compose, .env, CI/CD, setup guide, then push to a GitHub repo
Security Audit & Compliance Report
OWASP security checks plus PCI-DSS, HIPAA, SOC2, GDPR compliance. Instant, deterministic, free
Background task queue
Long exports run in the background with browser notifications. Start multiple tasks and keep working
Premium model access
Premium provider models available for Pro users, with dynamic model catalog refresh
Save architectures to your account
Save button on canvas toolbar, /saved page to browse, share, embed, or delete. 5 free, unlimited Pro
oEmbed API for auto-embeds
Confluence, Notion, and Slack auto-discover and embed Codelit diagrams when you paste a share link
Dockerfile parser
13 instant file parsers. The new Dockerfile parser detects base images, ports, env vars, and infers services
Figma-style toolbar cleanup
Primary tools visible (Add, Layout, Insights, Chaos), secondary actions collapsed into clean overflow menu
Enhanced upgrade prompt
Free vs Pro comparison grid when daily limit is reached: a concrete side-by-side of what you're missing
GitHub Integration: Repo to Architecture
Connect GitHub or paste any repo URL. Codelit analyzes your codebase (docker-compose, package.json, Terraform, K8s) and generates an interactive architecture diagram from your actual code
Chaos Mode: Cascading Failure Simulation
Click the skull to enter Chaos Mode, then click any node to kill it. Watch failures cascade through downstream dependencies with animated propagation
Live Cost Estimator
Instant AWS cost breakdown per architecture: total monthly estimate, per-category bar chart, and per-component pricing mapped to real AWS services
Unified Insight Panel
Summary, Audit, Review, Cost, and Diff consolidated into one tabbed panel. Async streaming, tab caching, zero flicker
90+ Template Detail Pages
Each prebuilt architecture has its own SEO-optimized page at /templates/[slug] with components, data flow, related templates, and blog posts
Copy Embed Code
One-click iframe embed code on shared architectures. Paste into blogs, docs, or wikis with 'Built with Codelit' attribution
Architecture Generator API
REST API at POST /api/generate. Send a prompt, get a full architecture as JSON. Docs at /docs with live playground
AI Architecture Review
Holistic review with score, missing components, single points of failure, scaling bottlenecks, and security gaps
Architecture Diff
Visual comparison between architecture versions. See added, removed, and modified nodes and edges
Generate from README
Paste a README or spec and AI extracts the system architecture automatically
SSR shared architectures
Every shared architecture is now server-rendered with JSON-LD, fully indexable by Google
Blog comments with likes
Signed-in users can comment on blog posts, like comments, and share on X
Multi-size favicons
High-quality icons for all devices, 16px to 512px, Apple Touch Icon, and SVG
Web Vitals tracking
Real-user performance monitoring: LCP, FID, CLS, TTFB, and INP sent to analytics
28 keyboard shortcuts
Cmd+N new, Cmd+R regenerate, Cmd+0 fit, Cmd+Shift+T copy as text, Cmd+, settings, and more
Pro exports: PDF, Terraform, Kubernetes
Professional architecture documents, AWS IaC, and K8s manifests. Pro only
Watermark-free screenshots for Pro
Free users get codelit.io watermark, Pro users get clean PNG exports
Regenerate button + Cmd+R
One-click regenerate with the same prompt for different AI results
Complexity score (1-10)
Live metric based on node count, connection density, and type diversity
Dynamic social previews
Shared architecture links show actual title on Twitter and LinkedIn cards
Mobile tap-to-navigate
Tap connections on mobile to scroll to and expand the target node
Smart conversion funnel
8 touchpoints: usage badge, post-gen toast, export previews, command palette CTA, and more
9 export formats
Mermaid, PlantUML, Markdown, YAML, Docker Compose, README, Terraform, AI Prompt, Screenshot
Mermaid import
Paste Mermaid diagrams to create interactive architectures, full round-trip
Full edge CRUD
Create edges by dragging, edit labels and data flow inline, delete with one click
Double-click to add nodes
Double-click canvas to add components, double-click nodes to edit
7-day free trial ($5/month)
Card required, full Pro access, automatically renews after trial unless canceled.
Smart suggestions
Follow-up suggestions scored by priority based on architecture gaps
Node connections inspector
Click any node to see and navigate all incoming and outgoing connections
48 blog posts
Complete system design curriculum: DNS, caching, sharding, CAP theorem, Kafka, Docker, and more
55 prebuilt architectures
Uber, Netflix, Kubernetes, Tinder, eBay, Zendesk, blockchain, autonomous vehicles, all load instantly
Claude-style composer
Multi-line textarea with arrow submit, Shift+Enter for new lines
Keyboard shortcuts (press ?)
11 shortcuts for power users: ⌘K, ⌘Z, Tab navigation, duplicate, delete
Security headers
XSS protection, clickjacking prevention, MIME sniffing block, permissions policy
24 E2E tests
Playwright test suite covering all critical paths, all passing
PWA + Accessibility
Installable app, skip-to-content, focus outlines, ARIA landmarks
Instant canvas: zero-wait diagram loading
Skeleton nodes build progressively, then live AI nodes appear as they're discovered from the stream
Stripe Pro subscriptions ($5/month)
Full payment flow: checkout, webhook, customer portal for subscription management
Prebuilt showcase on landing page
Browse and click any of 30 architectures to load instantly, no AI needed
Smooth page transitions
Subtle fade+slide animation on every route change for a polished feel
Error boundaries & offline detection
Graceful crash recovery and network-down messaging, no more white screens
Loading skeletons on every page
Shimmer-animated placeholders on blog, pricing, changelog, and root
SEO structured data everywhere
Article + BreadcrumbList on blog, FAQPage on pricing, SoftwareApplication on home
Interactive case study blog posts
Deep dives into Uber, OpenAI, and product engineering with embedded architecture diagrams
Full node editing: add, duplicate, rename, retype, delete
Complete manual CRUD for architecture nodes with undo/redo support
Undo/Redo (⌘Z/⌘⇧Z)
Full history navigation for manual edits: add, delete, duplicate all undoable
Node type selector
Change any node's type (frontend, backend, database, etc.) from the side panel
Auto-retry with model fallback
If AI returns bad output, automatically retries with a different model
Version timeline with complexity trend
See node count changes between versions and track how architecture evolved
Smart topological layout
BFS-based node positioning by data flow depth with cycle protection
Architecture diff highlighting
New nodes glow green with 'NEW' badge after follow-ups
Full system audit report
One-click comprehensive review: security, scaling, cost, compliance, reliability
Contextual suggestions + minimap + node search
Smart follow-ups, bird's-eye navigation, and type-to-filter nodes
Terms, Privacy, Changelog pages
Legal foundation + public changelog for trust and transparency
Pro waitlist + feature gating
Email capture on pricing page, PRO badges on premium models and Terraform
Embeddable widget
Embed interactive architectures on any website via iframe
Multi-provider AI
Free/open models plus premium provider models with auto-fallback
Architecture comparison
Compare two approaches side-by-side (monolith vs microservices)
Export as code
Docker Compose, Terraform, README, AI Prompt, from any architecture
11 audit tools
Security, stress test, cost, compliance, accessibility, SEO, bundle size, backup, throughput, API design
Version timeline
Track architecture iterations and jump to any version instantly
Share as link
Permalink sharing with social buttons and 'Built with Codelit' branding
Mobile card view
Expandable cards with animated connections, a canvas replacement for phones
Command palette
⌘K to search actions, templates, and tools
4 instant templates
SaaS Starter, E-commerce, AI Agents, Real-time Chat, all load in 1 second
Codelit.io launched
Interactive AI system architecture simulator. Describe any system, watch it come alive
10 blog posts
Dev-voiced articles on system design, AI tools, and architecture patterns
Analytics & admin dashboard
Track generations, shares, exports with Firestore events
Want to try these features?
Launch Codelit