{
  "latest": "4.2.33",
  "releases": [
    {
      "version": "4.2.33",
      "date": "2026-10-07",
      "notes": "Claspt 4.2.33 is about how secure you want your vault to be, and about a\nbrowser extension that stays connected. Four security profiles, from Relaxed\nto Paranoid, set every lock and factor in one choice at setup or in Settings;\na PIN, a key file, a security key or your phone can stand at the password\ndoor; and the extension no longer reads a page to show you a list, so a vault\nof thousands of logins is as quick as one of ten. For everyone on 4.2.0 this\nis one update through the app; nothing between 4.2.0 and 4.2.33 was published.\n\n### Security\n- **How secure do you want it?** Four profiles, Relaxed, Standard, Strict and\n  Paranoid, chosen at setup and in Settings › Security. Each sets the screen\n  lock, the key lock, what happens on sleep, on the screen locking and on a\n  new network, how often the master password is asked, how the browser fills,\n  and what quick unlock is allowed. Every setting behind a profile can still\n  be changed on its own, and Settings says which ones you changed. A vault set\n  up before profiles existed is shown the choice once.\n- **A PIN for the quick way back in.** Four to eight digits on an on-screen\n  keypad, shuffled in Strict and Paranoid, opens the vault after a lock; the\n  master password is asked after a restart and every fortnight. Quick unlock\n  can be PIN only, biometrics only, either, or neither. A PIN you set once is\n  offered back when you turn PIN unlock on again, never shown.\n- **A second thing the vault will not open without.** A key file on a USB\n  stick, a security key you touch (FIDO2, with a second one beside it and a\n  lock the moment it is unplugged), a code from your phone, or your phone\n  itself, which releases the key after Face ID and a check code shown on both\n  screens. The factor travels to a synced vault's other devices through the\n  key file, and the phone can import it. Paranoid needs one of them.\n- **The vault locks when the machine does**, when the lid closes, when the\n  screen locks and, if you ask, when the network changes or a security key\n  is pulled. A tool polling the app no longer keeps the key alive; only real\n  use does.\n- **Relaxed and Standard keep the browser extension open until you lock the\n  vault yourself.** The idle timer, sleep and the screen locking hide the\n  app's screen and leave the key, so the extension works again the moment\n  the machine wakes; pressing Lock, or quitting the app, clears it. Strict\n  and Paranoid lock as before. The switch is in Settings › Security, and the\n  threat model says what it costs.\n- **A secret shows only when its own eye is pressed.** An open card shows\n  every value masked, each with a three-step eye (first characters, in full,\n  hidden), and one more eye on the card for all of them; a value can be\n  copied without ever being shown. The status the app reports to tools says\n  unlocked only while the key is in memory.\n- **Windows Hello no longer hangs the app** when biometric unlock is turned on\n  or used on Windows.\n\n### Browser extension (3.1.21)\n- **A warning is a choice, not a refusal.** On a page without HTTPS, or for\n  a login saved for another site, the banner says why and offers Fill anyway\n  or Don't fill; the choice is the person's own click on an untouched\n  banner, and such a fill is never submitted for them. A `*.localhost`\n  development host needs no warning.\n- **Nothing is fetched on a clock.** Every list is held until the app says\n  its login table moved; the popup fetches the whole table only when the\n  All tab is looked at, and asks only for the count until then.\n- **The list draws twenty rows, then more as you scroll**, instead of every\n  login in the vault at once; pinned and recent first, search over the list\n  held in memory.\n- **Sign-in forms in a frame of their own site work.** Apple's sign-in form,\n  and any form a site draws in a frame of its own, gets the icon in the\n  field, fills from the popup and is captured on submit; a frame embedded by\n  another site is still left alone. The popup concludes nothing before the\n  app answers, lists no pages on opening, and Settings › Timing shows how\n  long the last open took.\n- **The waiting-to-save band no longer hides the logins.** Two captures\n  show; the rest scroll inside the band, and the band folds to its heading\n  with a click, which is remembered.\n- **It is quick again.** The popup opens at once and asks the app in the\n  background; a login fills the moment it is chosen. Behind the slowness: a\n  second and third copy of the extension's wait-for-work request were left\n  running after each lock and unlock, each one holding one of the six\n  connections the browser allows to the app, so the popup and the fill\n  waited for a free one; and the toolbar badge listed every page in the\n  vault every fifteen seconds to count the logins waiting to be saved. The\n  wait-for-work request now runs once, and the count comes from the app's\n  login table without a page being read.\n- **Lists hold no values.** The logins for a site, the All tab and search come\n  from a table the app keeps in memory, with no page read to show them; a\n  login is read from the vault at the moment you fill, copy or open it, and\n  the save bar reads only the account you just submitted. The table also\n  says why a login matched, so a login whose only mention of the site is its\n  address is listed. The app tells the extension when the table moved, so a\n  change made in the app shows in the popup within seconds.\n- **It stays connected.** The extension no longer asks to be paired again\n  after Chrome wakes it or after its own idle lock, never shows \"not\n  connected\" over an app that is answering, and says why when the vault\n  cannot be read, with a Reconnect, Unlock or Pair again button where it says\n  so. It has its own, higher ceiling on reads in the app's settings, apart\n  from the brake meant for AI tools. Its error page in the browser stays\n  empty: a page that removes the picker, a tab with no page script and a\n  worker that restarts are answered as \"nobody\", not listed as failures.\n- **Setup carries on where it left off** after Chrome's permission window\n  closes the popup, and a freshly installed extension says it is not set up\n  yet. Unlock from the popup or a page's picker brings the app's unlock\n  screen forward, and a Strict vault never fills by itself when you asked for\n  a click.\n\n### Fixes\n- The app answers the extension's status call without walking the vault on\n  the request; the walk that keeps the login table current runs on its own\n  thread, as does listing every page and writing the access log, so a slow\n  disk no longer slows every answer with it.\n\n### Utilities\n- **Credential Format** brings every login to one shape, only when asked: one\n  scan, four switches, one Apply, with a progress bar, a readable outcome, a\n  list of the pages left out and why, with a tick to include any of them, and\n  no page refused over two blocks wanting the same label.\n\n### UI\n- **The connection is shown.** The sidebar footer says whether the browser\n  extension is connected, and Settings › Integrations says whether the local\n  API is running and on which port. When the API is switched on but not\n  running, the footer says so and offers Start.\n- **Switching the local API off and on again brings it back.** A switch turned\n  back on while the server was still closing was ignored, which left the\n  extension unable to connect until the app was restarted.\n- Icons beside the settings, the profiles and the factors; a settings list\n  that scrolls, with an arrow on the sections that open; readable text on\n  every theme's accent colour.\n- The page's actions sit on its title line with icons; a long title is cut\n  with an ellipsis and shown whole on hover; the folder chip shows where the\n  page file sits.\n- The sidebar's cloud of every tag is one line until asked for.\n- What changed is shown once after an update, and again from Settings › About.\n\n### Phone (2.9.2)\n- Follows the vault's profile: lock on leaving the app, biometrics allowed or\n  not, and a PIN-only profile treated as the master password. Imports the key\n  file and opens a vault that has one. Can be the key for a desktop that\n  asks. Writes the URL match policy under the field the desktop and the\n  extension read.\n\n### Server (0.2.24)\n- Carries the phone key exchange between a desktop and a phone, sealed to the\n  asking desktop and answered once.",
      "artifacts": {
        "macos-universal-dmg": "v4.2.33/claspt-4.2.33-macos-universal.dmg"
      }
    },
    {
      "version": "4.2.0",
      "date": "2026-09-27",
      "notes": "Claspt 4.2 closes the one gap the vault had: a credential could sit in a page\nin plain text, on disk and in the page's history, in the minutes between\npasting it and making it a secret. It no longer can. For everyone on 4.1 this\nis one update through the app; nothing between 4.1.1 and 4.2.0 was published.\n\n### Security\n- **A credential never rests in plain text.** On every save, a page that holds\n  a recognisable credential outside a secret block, an API token, a key, a\n  password with a generated-looking value, is stored fully encrypted until\n  the credential is inside a block or gone. Disk, version history, sync and\n  any backup see ciphertext. The rule is conservative, so ordinary notes are\n  never sealed by it, and a page you chose to encrypt is never unsealed by it.\n- **Version history can be started afresh.** Settings › Utilities › Version\n  History removes every earlier version on this device and starts again from\n  the pages as they are. Your pages are never touched. Use it once for any\n  page whose earlier versions held a credential before it was made a secret.\n- **A value that just became a secret leaves the recent versions of its\n  page.** After a conversion, the recent run of versions holding the value is\n  rewritten so it appears in none of them; everything older keeps its versions\n  exactly. If the value sits further back than the app will rewrite on its\n  own, the inspector says so and points to the reset.\n\n### Editor\n- **An encrypted page is unmistakable.** A band under the title says what is\n  true: \"Fully encrypted page. Notes and secrets alike are ciphertext on\n  disk\", or \"Stored encrypted while it holds 3 lines that look like\n  credentials\", with a button that selects those lines and opens the convert\n  dialog. The title bar takes the accent colour, a faint lock sits behind the\n  text, and the sidebar and inspector mark the page.\n- **A paste that looks like credentials offers the conversion** the moment it\n  lands, before the first save, with the pasted lines already selected.\n- **Convert to Secret takes every key and value line in the selection**, not\n  only the ones whose key looked like a credential, and moves only those lines\n  into the block. A note, a heading or a sentence inside the selection stays\n  exactly where it was. Untick a line and it stays in the page.\n\n### Fixes\n- **The biometric prompt waits for you.** After the idle lock, Touch ID and\n  Windows Hello no longer appear on their own on top of whatever else you are\n  doing. The prompt comes when you click the button on the lock screen, or on\n  a cold start with the app in front.\n- **Convert to Secret no longer deletes the lines it did not convert.**\n\n### Browser extension (3.1.1)\n- **Firefox 140 and up**, 142 on Android, and no HTML is ever set from a\n  value, not even by the library the extension is built on. Mozilla's\n  validator reports no warnings. The same build is the next Chrome Web Store\n  version.",
      "artifacts": {
        "macos-universal-dmg": "v4.2.0/claspt-4.2.0-macos-universal.dmg",
        "windows-x86_64-exe": "v4.2.0/claspt-4.2.0-windows-x86_64.exe",
        "windows-x86_64-msi": "v4.2.0/claspt-4.2.0-windows-x86_64.msi",
        "linux-x86_64-deb": "v4.2.0/claspt-4.2.0-linux-x86_64.deb",
        "linux-x86_64-AppImage": "v4.2.0/claspt-4.2.0-linux-x86_64.AppImage"
      }
    },
    {
      "version": "4.1.1",
      "date": "2026-09-24",
      "notes": "### Fixes\n- **Windows vaults store paths the same way as every other platform.** Folder\n  names and page paths written on Windows used the Windows separator, so an\n  attachment could be reported as unused, a captured login could be stored\n  twice, passkeys could go unlisted, and a vault synced from Windows disagreed\n  with the same vault on a Mac. Every path is now written and compared with\n  `/` everywhere.",
      "artifacts": {
        "macos-universal-dmg": "v4.1.1/claspt-4.1.1-macos-universal.dmg",
        "windows-x86_64-exe": "v4.1.1/claspt-4.1.1-windows-x86_64.exe",
        "windows-x86_64-msi": "v4.1.1/claspt-4.1.1-windows-x86_64.msi",
        "linux-x86_64-deb": "v4.1.1/claspt-4.1.1-linux-x86_64.deb",
        "linux-x86_64-AppImage": "v4.1.1/claspt-4.1.1-linux-x86_64.AppImage"
      }
    },
    {
      "version": "4.1.0",
      "date": "2026-09-24",
      "notes": "Claspt 4 is the vault that also works for your AI tools. It is still markdown\nnotes with encrypted secrets in a folder you own. Now an agent can keep its\nmemory in it and use your credentials without ever seeing them, the browser\nextension keeps every login you type, a deleted page waits in the trash, files\nsit next to the notes they belong to, and a second device is two steps away.\nFor everyone on 3.0.6 this is one update: nothing between 3.0.6 and 4.1 was\never published.\n\n### AI tools\n- **Agent memory and secrets over MCP.** Connect Claude, ChatGPT, Cursor, Codex\n  or any MCP client and it keeps notes between sessions in your vault, in plain\n  markdown you can read and edit, and uses your credentials by reference: the\n  value goes to the program that needs it, never into the conversation. You\n  decide what a tool may read, and every read is logged.\n- **One key for all your AI tools.** `claspt mcp install claude-code\n  claude-desktop` connects every tool on the machine with one shared key and\n  writes their configs for you; a tool can have a key of its own when you want\n  to revoke it alone. `claspt mcp doctor` shows which config holds a key the\n  vault does not know, and a refused request says which key and how to fix it.\n- **Programs use a secret the agent never sees.** `claspt run` hands a\n  credential to a command in its environment. SSH keys stay in the vault, and\n  rotation reminders say when a secret is due.\n- **Lock the screen, keep the tools working.** Screen lock hides the vault; key\n  lock clears the key. A tool at work counts as activity, so an agent mid-task\n  is not cut off.\n\n### Your vault\n- **Attachments.** Pick, drag or paste images and PDFs into a page. Each time,\n  one question: encrypt this file? Sealed files open only inside Claspt. Every\n  attachment keeps its original name and can carry a comment.\n- **Deleted is not gone.** A deleted page waits in the trash. Undo at once, or\n  restore it later from Settings. Its secrets stay encrypted while it waits.\n- **Secret templates.** Thirteen built-in templates (login, API key, SSH key,\n  card, licence, database and more) plus your own, in the editor and in the\n  browser extension. The Help pages list them.\n- **Recovery keys can be saved and printed**, not only copied, with the vault,\n  the date and the steps to use it written on the sheet. Changing your master\n  password does not change the key.\n- **Help choosing a master password:** strength as you type, and a generator\n  offering a passphrase or a password at any length. **Change your master\n  password** from Settings.\n- **The editor opens in split view** and remembers the view you choose. A\n  redesigned first-run screen, a setup walkthrough that only offers what it can\n  set up, and an unlock screen that shows what Claspt does while you type.\n- **Import and export.** KeePass XML imports are read as XML. A full-vault export\n  refuses the vault itself as a destination and is written owner-only.\n\n### Generator\n- **The same generator everywhere.** Password, passphrase, memorable, PIN and\n  UUID on the desktop, in the extension and on the phone, with the same options\n  and the same results. **Limit symbols** for sites that accept only a few.\n- **Every generated password is kept**, encrypted, whether or not you use it.\n  A History tab lists them newest first with where each came from and whether\n  it was used; copying or inserting marks it. Passwords generated in the\n  extension appear here too. Clear unused entries older than thirty days at\n  any time; nothing is removed on its own.\n\n### Sync and sharing (Pro)\n- **A second device in two steps.** Each device proves itself with its own key.\n  Restore on a new device by password or by recovery key.\n- **If two devices edit the same page while apart,** the newer edit wins and\n  Claspt tells you which pages it chose between; the older edit is kept as a\n  version.\n- **A vault whose account was set up for another vault is found at unlock,**\n  even offline, and a guided Fix repairs it in place, showing every step and a\n  clock while it runs.\n- **Sharing we cannot read.** A share is encrypted on your machine and opened in\n  the other person's browser. Add a code, an expiry, or burn after one reading.\n  A link can carry its own key.\n- **Claspt keeps itself up to date.** Installed copies are offered new releases\n  and install them through the signed updater.\n\n### Browser extension (3.1)\n- **A login you type is kept the moment you submit it.** It goes into the vault\n  at once, so a redirect, a second factor, a lock or a crash cannot lose it. The\n  bar asks what to make of it and comes back on every page of the site until\n  you answer; the popup lists what is waiting. If the app is not running, the\n  login is kept in the extension and written when the app is back.\n- **The right account is updated.** Update is offered only for the same account;\n  a second account on the same site is a new login. A password the site plainly\n  rejects is dropped.\n- **It fills who you are.** Save an identity once and checkout forms fill\n  themselves. Passkeys and two-factor codes sit beside the passwords they\n  protect.\n- **The toolbar icon says what is wrong.** Hover text for every state (app not\n  running, vault locked, key refused, permission needed), a dimmed icon when it\n  cannot fill, and the count of logins waiting to be saved. The inline picker\n  says why a list is empty.\n- **Pairing from Settings.** Pair the extension from Settings › Integrations,\n  not only during first-run setup. An extension meeting a desktop older than 4\n  says so and asks for the update.\n\n### Phone (2.7)\n- **Sealed attachments open in memory only.** Images show a lock badge, PDFs\n  appear as chips, and every attachment shows its original name and comment.\n- **Restore by password or by recovery key**, one-time codes, and a pull that\n  refuses data belonging to another vault.\n- The phone is read-only until writing from it ships.\n\n### Changes\n- **Free is the resting state.** New installs are Free rather than starting a\n  silent trial. One paid tier, Pro, for sync, sharing and the mobile apps.\n- **Account and Sync are one tab.** Update checks no longer require the server\n  connection; they are available to everyone.\n\n### Fixes\n- Creating a vault in a folder containing a git repository no longer fails, and\n  a folder holding a damaged vault is never written over.\n- macOS text substitution could capitalise a typed password. Every credential\n  field now refuses autocapitalise and autocorrect.\n- Biometric keys are stored per vault, so two vaults on one machine no longer\n  overwrite each other.\n- A code block that quotes `:::secret` text no longer hides the real secret\n  block after it.\n- The version is shown once, in the sidebar footer. Logs keep five dated files\n  of about 2 MB each instead of one file that forgets nothing.\n- Security hardening throughout the desktop, the extension, the server and the\n  phone, following a full review before the source was published.",
      "artifacts": {
        "macos-universal-dmg": "v4.1.0/claspt-4.1.0-macos-universal.dmg",
        "windows-x86_64-exe": "v4.1.0/claspt-4.1.0-windows-x86_64.exe",
        "windows-x86_64-msi": "v4.1.0/claspt-4.1.0-windows-x86_64.msi",
        "linux-x86_64-deb": "v4.1.0/claspt-4.1.0-linux-x86_64.deb",
        "linux-x86_64-AppImage": "v4.1.0/claspt-4.1.0-linux-x86_64.AppImage"
      }
    },
    {
      "version": "3.0.6",
      "date": "2026-07-07",
      "notes": "A follow-up to 3.0 that fixes editor rendering in installed builds, makes AI/API\nchanges sync automatically, and refines the AI-integration workflow.\n\n### Fixes\n\n- **Editor renders correctly in installed builds.** Fixed a Content-Security-Policy\n  interaction that left the editor unstyled after installation — on long pages the\n  line-number gutter detached from the text. Development builds were unaffected,\n  which is why it only appeared once installed.\n- **AI and API changes sync automatically.** Notes, memory, and credentials created,\n  updated, or deleted through the local API or an AI assistant now index,\n  auto-commit, and sync to your other devices with no manual step — matching the\n  in-app save behaviour.\n\n### AI integration\n\n- **Per-project memory.** Your AI assistant now keeps separate memory for each\n  project automatically, plus a shared space for standards and preferences that\n  apply across all your projects.\n- **Set it up once.** The AI Integration guide now shows how to save the assistant's\n  instructions in its rules file so they apply to every session, and covers\n  organising stored credentials per project.\n\n### UI\n\n- **Scrollable tag filter.** The Pages tag filter caps its height and scrolls, so a\n  vault with hundreds of tags no longer pushes the note list off-screen.",
      "artifacts": {
        "macos-universal-dmg": "v3.0.6/claspt-3.0.6-macos-universal.dmg",
        "windows-x86_64-exe": "v3.0.6/claspt-3.0.6-windows-x86_64.exe",
        "windows-x86_64-msi": "v3.0.6/claspt-3.0.6-windows-x86_64.msi",
        "linux-x86_64-deb": "v3.0.6/claspt-3.0.6-linux-x86_64.deb",
        "linux-x86_64-AppImage": "v3.0.6/claspt-3.0.6-linux-x86_64.AppImage"
      }
    }
  ]
}
