## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The release pipeline publishes a beta, waits three days, and then promotes it to stable. > - The stable promotion reads `releases/beta/v<beta-version>.md` from `master` and publishes it as the GitHub Release body. > - Beta `2026.1002.0-beta.0` (source `467125fa`, 179 commits after v2026.1001.0) is published and its soak has started. The planned stable is around 2026-10-05. > - The beta publish job pushed an auto-generated scaffold. The scaffold lists raw commit subjects and PR bodies. It is not in release-notes voice. > - This pull request replaces the scaffold with curated stable notes. > - The benefit is that the stable release ships with readable notes that tell self-hosters what changed and what they must do. ## Linked Issues or Issue Description **Issue type** Docs: release notes. **Where is the issue?** `releases/beta/v2026.1002.0-beta.0.md` on branch `release-notes/v2026.1002.0-beta.0`. **What's wrong?** The file is the auto-generated scaffold from the beta publish job. It lists 170+ raw entries with no grouping, no breaking-changes section, and no upgrade guide. **Suggested fix** Rewrite the file in the standard release-notes structure. The notes are planned as `v2026.1005.0`. **If the promotion date moves past 2026-10-05, change the title and the Released date before you dispatch stable.** ## What Changed - Rewrote `releases/beta/v2026.1002.0-beta.0.md` into the standard structure: overview, Breaking Changes, Highlights, Fixes, Improvements, Upgrade Guide, and Contributors. - Breaking Changes: operator UI snippet settings removed ([#13789](https://github.com/paperclipai/paperclip/pull/13789)); keyboard-shortcut settings and `/api/auth/preferences` removed ([#14141](https://github.com/paperclipai/paperclip/pull/14141), [#14643](https://github.com/paperclipai/paperclip/pull/14643)); agent @-mentions no longer start a run ([#14577](https://github.com/paperclipai/paperclip/pull/14577)). - Highlights: Grok Build on the native runner, persistent agent files, skills synced from GitHub, Browser Use Cloud, one-screen connector setup, two-way Slack, Agent Chat navigation and handoffs, per-message model and effort picker, governed API tools on by default. - Upgrade Guide: migrations `0284`–`0293` with one-phrase descriptions, new default for `PAPERCLIP_RUNNER_API_TOOLS_ENABLED`, and the new optional variables `PAPERCLIP_RUNNER_API_COMPANY_CAPTURE_MAX_BYTES`, `PAPERCLIP_WORKSPACE_GIT_SNAPSHOT_TIMEOUT_MS`, and `PAPERCLIP_WORKSPACE_MANIFEST_MIN_FREE_BYTES` with their defaults. - Removed release-infra noise: CI-only PRs, eval and test-only PRs, lockfile refreshes, release-notes bookkeeping commits, and cloud-control-plane-only changes. ## Verification - Docs only. Each PR number and commit SHA in the notes is in `git log v2026.1001.0..467125fafb47a8520856504fecc48d6e32055db1`. - Migration range `0284`–`0293` checked against the `packages/db/src/migrations` diff for that range. - Environment variable defaults checked in the code, not in commit subjects. - Contributor count and external handles computed from `git shortlog` over the same range. ## Risks Low. Documentation only. The stable preflight only requires that the file exists on `master`. The content can change during the soak. ## Model Used Anthropic Claude Fable 5.1 (`claude-fable-5-1`) via Claude Code, with tool use and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass (docs only; no tests apply) - [x] I have added or updated tests where applicable (none apply) - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green (pending on this fresh PR) - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups (pending) - [x] I will address all Greptile and reviewer comments before requesting merge 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: devinfoley <139239+devinfoley@users.noreply.github.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
23 KiB
Paperclip v2026.1005.0
Released: 2026-10-05
Paperclip v2026.1005.0 carries 179 commits, promoted from 2026.1002.0-beta.0. The headline is agents that carry more with them: Grok Build runs on the native runner, agents keep their own files across tasks, company skills sync from GitHub repositories, and Browser Use Cloud gives agents a live browser that people can watch and take over from the task. Around those: most connectors now set up in one click with MCP aggregators on by default, Slack conversations round-trip between the board and the thread, Agent Chat gets its own navigation and hands finished work back to the conversation, and the task composer picks model and effort per message. Underneath, a long reliability pass hardens the native runner, sandbox transport, and the heartbeat scheduler, including a fix for a server crash loop caused by a permanently rejected queued run.
Breaking Changes
- Operator UI snippet injection is removed. The
PAPERCLIP_CLOUD_UI_SNIPPETandPAPERCLIP_CLOUD_UI_SNIPPET_B64settings no longer inject HTML into static or development pages. Operators who relied on them should move the integration to a plugin UI contribution before upgrading. (#13789) - Keyboard shortcuts are always on, and their settings are gone. The instance-wide General toggle and the per-user Profile preference are both removed, along with the
GET/PATCH /api/auth/preferencesroutes;PATCH /api/instance/settings/generalno longer acceptskeyboardShortcuts. Every signed-in user now has shortcuts enabled. (#14141, #14643) - @-mentioning an agent no longer starts a run. Mentions in task comments are kept as context for the assignee; only explicit assignment and review requests start work. Workflows that used a mention to pull a second agent onto a task must assign or request review instead. (#14577)
Highlights
- Grok Build on the native runner — Grok Build joins the Paperclip Runner through ACP for both local and Daytona execution, with separate subscription-login and API-key credential paths and governed tools (#13882); it ships in public installs with sandbox-owned binaries rather than a download at install time (#14024). The shared harness runtimes move to Codex 0.156.0, Claude Agent SDK 0.3.280, and OpenCode 1.18.32 (#13838), model catalogs and reasoning controls are refreshed across the Claude, Codex, Grok, Gemini, Cursor, Kimi, and OpenCode adapters (#13829), and remote native Codex accepts compatible releases from 0.149.0 instead of one exact pin (#13853).
- Agents keep their own files — An agent's directory (AGENTS.md and its supporting files) now persists across tasks and sessions and is shared with the Instructions Editor; concurrent runs apply only the files they changed, and new saves no longer create revision history (#14420), on top of a new plain-directory sync transport with conflict preflight (#14416). Warm native Codex sessions survive managed-file collection by checkpointing only changed files after each turn (#14735).
- Skills synced from GitHub — Skills gains a Sources tab: pick a repository through an existing GitHub connection, choose which skill folders to import, and refresh on demand. Installed snapshots mean agents never fetch GitHub mid-run, and a failed refresh leaves the last good version in place (#14713).
- Browser Use Cloud, live in the task — A new Browser Use Cloud connector gives agents governed browser automation, and tasks show interactive browser tabs where people can follow along, take over the page, and keep the browser after the run finishes, with costs recorded against the run (#14627).
- Connections set up in one click — Connector setup collapses to one screen that states its defaults and tucks the rest behind "Change" and the Permissions tab (#14811). The Zapier, Arcade, Composio Connect, and Executor MCP aggregators are on by default with the experimental toggle removed (#13964), and they can be configured from inline task cards (#13879). Connection search prefers native apps, asks the user to choose an external provider before setup (#13941), and understands natural-language queries (#14725). New in the catalog: Fireflies with summary-ready routines (#13890), five experimental memory providers (Mem0, Zep, Supermemory, Cognee, Honcho) behind the default-off
enableMemoryConnectorssetting, plus assigned MCP tools delivered to remote native Codex (#13942), and GitHub Code Review Bot as its own card separate from GitHub tools (#14750). Personal pasted credentials are validated the same way at setup, health check, and invocation, and new connections request the write scopes their actions need (#14739). - Slack goes both ways — Replies entered on the board reach the linked Slack thread and resume the same conversation, and assigned agents get their Slack tools during ordinary tasks and scheduled routines (#13920). Slack-origin tasks get governed tools to read the surrounding discussion, create follow-ups, and collaborate through the inviting bot (#13828), and an answered conversation settles to Idle instead of lingering In Progress (#13809).
- Agent Chat grows up — A secondary chat sidebar and landing page give conversations their own home (#14706); tasks delegated from a chat durably deliver their completion back to it (#14408); a clear approval typed in chat resolves the pending card, and unanswered questions move into history where they can be answered later (#14613); and a chat continues after its native worker is lost (#13813).
- A composer that picks the run — The task composer gains a per-message model and effort picker that follows the selected agent, keeps pending cards visible above it, and works on mobile (#14322); effort options match what each adapter actually executes, including Codex on the native runner (#14568, #14576). Tasks can be created from a prompt alone and the assigned agent names them (#14761). Artifacts get rich cards with previews (#14469), an image and video gallery with full-row links (#13825), and Markdown and text attachments open in task tabs with rendered, raw, and download views (#14297).
- Governed API tools, on by default — The native runner's
search_apiandcall_apitools are enabled without an environment variable (#14186); large API responses stream to disk up to 1 GiB and saved text is readable in bounded pages (#14301); and when an assigned app catalog pushes the tool contract past its limit, agents still reach those tools through search and call (#14218).
Fixes
- Native runner and sessions — Tool outcomes survive shutdown and restart instead of recording a false failure (#14734); failed warm sessions are retired before their sandbox stops (#14747) and recovered cleanup honors the run's terminal outcome (#14767); switching a task to a warm lifecycle acquires a reusable lease (#14187); the OpenCode event stream stays open across turns (#14582) and delivers its shutdown settlement (#14668); Codex account notifications no longer abort a turn (#13902); Claude and Codex quota exhaustion is classified for the proper backoff (#13831, #13945); ACP terminal failures keep their redacted provider diagnostics (#14573) and identity guards name the failed check (#14481); the native journal read limit is 256 MiB everywhere (#14711); pending finalization of an accepted result is protected from the stale-lock sweep (#14219); adapters expose a verified provider stop before workspace restoration (#14311); warm sessions keep running under managed GitHub access (#13815); and a run that hits a provider authentication failure offers an inline connection card in the task so the user can repair and continue (#14629).
- Sandboxes and workspaces — Daytona commands stay alive after the log socket closes (#14799), confirmed container loss is recognized when resuming leases (1f3ff75d), failed allocations are cleaned up (#13979), and provider acquisition timeouts honor the driver's default (#14097). ACP input delivery retries after a gateway 502 without duplicating input (#14485), oversized launch payloads and duplicated wake context no longer fail with
E2BIG(#13793, #13891), process proxies close after remote exit (#13777), and relative symlinks in secondary repositories are preserved (#13953). Workspace exports finalize and recover safely (#14402), restore failures keep the adapter's result and record what failed (#14035, #14064), large Git snapshots stream through disk manifests instead of hitting a 1 MiB output limit (#14194, #14253), readiness checks accept larger status output (#14414), background scans stop refreshing the Git index (#14666), partial task overrides retain project setup commands (#14502), and repository-free low-trust tasks get a private directory (#14766). - Scheduler and recovery — A queued run whose claim is permanently rejected is cancelled instead of crash-looping the server (#14738); wakes that arrive during a drain stay queued and interrupted corrective runs get a transient retry (#14028); an issue whose run has spent its retry budget is escalated to a visible blocked state rather than skipped forever (#14046); continuation and retry budgets use persisted state (#13888); task ownership is claimed atomically with queued runs (#13973); obsolete continuations are cancelled before dispatch (#13761); a status reply that still lists blocking work keeps the task moving (#14626); Done and Cancelled tasks keep their assignee on release (#14561); interaction continuations stay scoped to their task (ded156a9) and question recipients are derived and validated (#14742); remote Grok runs stop before queued messages continue (#14100); run-identity locks no longer deadlock with audit inserts (#14478); and ambiguous database disconnects are no longer replayed (#14773).
- Connections and apps — OAuth sign-in challenges and reconnect states return 422 instead of being reported as crashes (#13786, #13794); MCP OAuth setup explains failed or cancelled consent (#13855); a disabled Slack MCP app gets actionable setup instructions (a7d3b17a); broker and AgentMail failures keep allowlisted reason codes (#14098, #14768); Google Chat and the Docs, Sheets, Slides, and Calendar profiles request fewer scopes (#13820, #14740); work products validate their execution-workspace reference (#14063); and malformed CLI auth challenge IDs return 400 (#14095).
- Board UI — The board recovers during server restarts with a connection message and retries, keeping open editors mounted (#14560), and offers a retry screen when the app fails before React starts (#13970). Code highlighting no longer crashes on a Lezer version mismatch (a3749aac), destructive confirm buttons are readable in the light theme (#14328), mobile pickers stay in view above the keyboard and scroll by touch (#14022, #14249, #14250, #14599), newer drafts survive receipt cleanup (#14332), other users' failed runs stay out of Mine (#14572), "Recovery needed" is distinguished from "Recovery in progress" (#14326) and a misleading Retry no longer appears when recovery is blocked (#13775), new artifacts register a tab without opening the panel (#14193), the Tasks panel shows ancestors (#13823), and task content appears sooner with parallel server reads (#14727). Also: property icons align with avatars (#13319), runner commentary aligns with replies (#14716), project save indicators stack below their label (#14765), archiving a company navigates away (#13846), experimental settings are alphabetized with empty groups hidden (#13905), and the Cursor adapter picks the real error over a trace notice (#14636).
- Observability — Browser errors carry
SENTRY_ENVIRONMENT(#13784) and bounded component context (#13904); run errors are isolated from later exceptions and a runtime capability header is redacted (#13826); and run failure reports retain exit details, stacks, causes, runtime activity, and restore classification (#14575, #14585, #14665, #14639, #14787).
Improvements
- The account menu drops its profile rows for a header link and gains an Invite shortcut (#14480); plugins can supply an organization switcher (#13832, #13854);
PAPERCLIP_HIDDEN_SETTINGSaccepts a wildcard with named exceptions so new experimental flags stay hidden automatically (#13980) and aworkspaces.isolationkey hides isolation controls (#13907); the native runner gains a shared rich-ACP transport foundation for upcoming Cursor, GitHub Copilot, and Pi providers (#14430); the coordination skill no longer tells agents to escalate through managers instead of asking the human who can act (#14188); worktree seed-source failures explain the supported setups (#14795); Google Workspace connectors are temporarily hidden from the Connections page while Google OAuth verification is pending, with saved connections and runtime access untouched (#14774); and the README is refreshed with current harnesses, guide links, and an npx-first Quickstart (#14741, #14744).
Upgrade Guide
- Migrations
0284–0293run on upgrade:0284adds and0289drops the per-userkeyboard_shortcutscolumn;0285widensassets.byte_sizetobigint;0286adds API response capture reservations;0287adds agent instruction heads, revisions, and working copies for persistent agent files;0288adds chat completion deliveries and task handoffs;0290adds Browser Use Cloud sessions, runs, and browsers;0291–0292add company skill sources and entries, and0291also adopts existing skills imported fromgithub.cominto them (one source per repository and tracking ref, one entry per skill, andlegacySkillSourceId/skillSourcePathstamped into each skill's metadata; skills imported from GitHub Enterprise hosts, bundled skills, and catalog skills are left as they are, and no provider requests or content rewrites happen);0293addsissues.title_needs_generation. - Operator UI snippets are removed (#13789):
PAPERCLIP_CLOUD_UI_SNIPPETandPAPERCLIP_CLOUD_UI_SNIPPET_B64are ignored. Move the integration to a plugin UI contribution before upgrading. - Keyboard shortcut settings are removed (#14643): drop any automation that calls
/api/auth/preferencesor sendskeyboardShortcutsto the general settings route. - Agent mentions no longer dispatch (#14577): use assignment or a review request to bring another agent onto a task.
- New defaults: the native runner's API tools are enabled unless
PAPERCLIP_RUNNER_API_TOOLS_ENABLEDis set to anything other thantrue;PAPERCLIP_RUNNER_API_TOOLS_COMPANY_IDSstill narrows them (#14186). The MCP aggregators are available without the formerenableMcpAggregatorsflag (#13964). - New environment variables, all optional:
PAPERCLIP_RUNNER_API_COMPANY_CAPTURE_MAX_BYTEScaps captured API response bytes per company (default 20 GiB, minimum 1 GiB; #14301);PAPERCLIP_WORKSPACE_GIT_SNAPSHOT_TIMEOUT_MSbounds workspace snapshot time (default 30 minutes, maximum 24 hours) andPAPERCLIP_WORKSPACE_MANIFEST_MIN_FREE_BYTESsets the free-disk reserve for snapshot manifests (default 256 MiB, minimum 64 MiB; #14253). Codex ACP runs acceptCODEX_API_KEYas an alternative toOPENAI_API_KEY(#14322). - Harness pins moved to Codex 0.156.0, Claude Agent SDK 0.3.280, and OpenCode 1.18.32 (#13838); shared installations should refresh their provider CLIs to match.
- No other configuration or API changes require action.
Contributors
This release has 179 commits from 7 contributors. Thank you to everyone who contributed to this release!
@MrBlackTongue, @gentslava