Native Computer Use on Windows, isolated development, and safer account boundaries
Use native Computer Use on Windows, run isolated local clients, give miniapps workspace storage, and keep permissions and identities inside their scope.
Computer Use now ships with a native Windows runtime. Windows release bundles are Authenticode-signed, updater packages use the current Tauri format, and activation no longer risks a callback deadlock.
Local development and releases
The TAP development host can run isolated local clients with stable signing, targeted startup, and clearer publication gates. Trusted desktop builds reuse more cached work, automatic macOS builds are signed, and updater fixes cover both macOS ARM and Windows.
Chat, specialists, and miniapps
Channels can optionally share history with new participants. Specialist harnesses have typed bindings and enforce channel policies, while remote credential grants stay scoped to the command that needs them. Miniapps gain workspace storage and native embeddings, and their conversation components now handle specialist presence consistently. Server-side project permissions remain authoritative when work executes outside the desktop app.
Marketplace install actions now align with the rest of the app, and silent specialist turns use canonical specialist identities. Channel administrators can be assigned again after the prior regression.
Development and production use separate Auth0 tenants, closing a path where an identity from one environment could bleed into another. Public directory ingress now handles every supported case explicitly.
The release also removes placeholder MCP specialist commands and restores the previous chat inference implementation after the new provider-native path proved unsafe to ship. Local signing avoids unnecessary keychain prompts and production release dependencies can no longer be skipped.
A fully discounted subscription upgrade now grants the credits it includes. Pricing FAQ questions also stay left-aligned and wrap cleanly on narrow screens.
An Always Allow decision with no explicit scope is now limited to the concrete tool call instead of becoming a wider grant. Directory token-verifier outages report authority as unavailable rather than misclassifying the request as denied.