Second

Changelog

Features, improvements, and fixes across all six Second apps, drawn from their versioned changelogs.

Each app has its own version. Unreleased entries are pending changes, not a release announcement. A versioned entry does not establish App Store availability. See public Mac and CLI downloads or platform availability for installation options.

Recent highlights

Web v1.22.1

1.22.1

Fixes and improvements

  • Refresh every public marketing page with current product capabilities, an evidence-backed Free/Pro comparison, proposed prices, payment-required trial and renewal terms, and complimentary-invitation details, and accurate platform availability. Fix Mac and CLI download links to use the public mirror, remove inaccessible private setup links, clarify Obsidian sync limits, and update privacy and terms for usage and invitation records.

1.22.0

Highlights

  • Add account-bound complimentary lifetime access with administrator grants, single-use invitations, unlimited commercial allowances, and native access recognition.

1.21.0

Highlights

  • Add account-bound subscription contracts, provider reconciliation, usage accounting and billing controls across Second's clients. Payment activation and quota enforcement remain gated by the approved measured catalog and provider rollout checks; saved content and pending work remain recoverable when access changes.

Fixes and improvements

  • Add the Better Auth Stripe server seam with origin-scoped customer email synchronization while keeping Second's billing catalog, subscriptions, entitlements, and usage ledger authoritative.
  • Record measured storage cost for successful new Markdown captures without double-billing idempotent replays.
  • Compare founder renewal notice requirements using the effective discounted charge while preserving the published Stripe price and continuation coupon.
  • Enroll verified founder checkouts from their eligible selection, preserve authorized ongoing-price re-enrollment clocks, and keep trials or unrelated paid purchases from creating or reviving founder eligibility.
  • Refresh the public changelog with recent AI workspace, search, cross-platform account, and capture-recovery improvements. Second remains free during the current beta; paid plans and public Apple App Store availability have not been announced.
  • Add locked, atomic sandbox billing provisioning state with macOS Keychain secret storage.
  • Preserve verified Stripe payment evidence across same-second webhook deliveries without treating event types as payment proof.
  • Add a Keychain-backed dated sandbox authentication harness for account-bound native OAuth PKCE and refresh verification.
  • Store sandbox provisioning credentials in macOS Keychain, lock retries and write receipts atomically. Validate the authenticated sandbox catalog against the standard account's eligible offers.
  • Require the configured Stripe merchant account and verify it through the official account endpoint before billing or Better Auth customer operations.
  • Add an isolated subscription sandbox runtime contract, scoped catalog seed/readback/teardown tooling, and authenticated lifecycle/quota proof harness.
  • Add account-pinned Stripe sandbox provisioning with verified catalog readbacks and separate storage for webhook secrets.
  • Update the public privacy policy and Apple privacy declaration for conditional billing metadata, native audio and image originals, and account-bound device identifiers.

1.20.6

Fixes and improvements

  • Make sign-out accessible across Second: add macOS menu and sidebar actions that work offline, move iOS sign-out beside account details and keep failed credential cleanup locked across restarts, expose extension sign-out without requiring a loaded identity, add Obsidian sign-out with in-flight sync fencing, and support the CLI's sign-out alias with environment-token guidance.

1.20.5

Fixes and improvements

  • Add a sign-out action to the web app sidebar, with pending and error feedback, account cache cleanup, and a return to the login screen.

1.20.4

Fixes and improvements

  • Refresh the homepage, feature overview, pricing, integrations, privacy policy, and terms to describe current capabilities and platform availability. Show versioned changelogs and clearly labeled unreleased changes for all six apps, and link policies from signup.
  • Bind OAuth authorization codes, refresh families, and access credentials to durable grant generations so disconnect and replay cannot revive credentials after reconnect.

1.20.3

Fixes and improvements

  • Allow AI hosts to request all advertised OAuth scopes by selecting explicit save and organize permissions before consent, and show actionable authorization errors.

1.20.2

Fixes and improvements

  • Fix OAuth consent and PARA pages failing to load by keeping database helpers out of browser bundles. Reject server runtime imports during production builds.

1.20.1

Fixes and improvements

  • Advertise save and organize capabilities in MCP OAuth discovery so AI apps can request the everyday permission levels.

1.20.0

Highlights

  • Add scoped AI connection permissions, versioned knowledge retrieval, and shared save and organization workflows with durable recovery. Retain and export original files, materialize versioned file evidence with bounded MCP reads, and provide a separately consented native original-retention connection. Make introductory guidance optional and preserve account-bound connection and onboarding state across supported surfaces.

    Apply the authority, operation/file storage, evidence-erasure, original-file erasure, and immutable extraction migrations before deploying. Provision the private original-file bucket separately. Host setup packages describe supported connection paths; real-host qualification and listing publication remain separate release steps.

Fixes and improvements

  • Check live OAuth client and consent permissions on API and MCP access. Connected-app revocation now atomically removes stored credentials and records a cutoff so already-issued access tokens remain rejected after reconnection. Apply the new database migration before deploying.

1.19.5

Fixes and improvements

  • Use stable server account IDs and API origins for native sessions and caches, and reject stale credential refreshes and callbacks across account changes.

1.19.4

Fixes and improvements

  • Reconcile release tooling with App Store preparation for iOS, macOS, and embedded Safari while publishing GitHub, Homebrew, and Sparkle artifacts independently.

1.19.3

Fixes and improvements

  • Keep the selected audio file's sandbox access grant active while reading its duration, so App Store audio imports can be saved to Inbox.

    Finish account cleanup successfully when its AI Search tenant is already absent.

1.19.2

Fixes and improvements

  • Upgrade dependencies and native error reporting to current compatible releases. Migrate OAuth provider resources and client redirects for Better Auth 1.7, preserve existing registrations, enforce token revocation/session checks, and update Notion sync for the current data-source API.
  • Fix account deletion when search projections exist and reject signed OAuth requests after the owning account is deleted.

1.19.1

Fixes and improvements

  • Prepare unified Apple App Store distribution with Safari embedded in both native apps, a sandboxed Mac target using App Store updates, required-reason privacy manifests, and native account-deletion links. Make Safari's background compatible with iOS and clarify privacy disclosures for captures and diagnostics. Require explicit cloud and AI processing consent before connecting the native App Store apps and browser extension, and keep iOS dictation on-device.

1.19.0

Highlights

  • Add shared Search action contracts, revision-pinned contexts, account preferences, durable Brief generation and grounded conversation evidence.
  • Add exhaustive Search actions for pinned-source chats and durable Briefs, with account preferences, Background Work, revision-aware evidence, and AI processing disclosure.

Fixes and improvements

  • Keep Search responsive for long saved articles by reusing unique fallback terms and skipping fields that cannot improve a match.
  • Speed up Search excerpts for long saved articles while preserving Unicode highlights and exhaustive Chat/Brief sources.
  • Rebuild expired Search snapshots so source collection can finish, and use current search postings to keep long-article results responsive.
  • Allow an explicitly non-iOS release to publish the remaining platforms without changing iOS signing requirements, and prevent hosted publication from racing a locally owned release.
  • Fix the Assistant History menu crashing when opening saved conversations.
  • Give each Search Chat and Brief its own context invocation identity, preserving it across transient transport retries and renewing it after stale-source refresh.

1.18.5

Fixes and improvements

  • Route error reporting through the personal Sentry organization and add crash reporting to the iOS app.

1.18.4

Fixes and improvements

  • Bound web search requests and defer native derived search-index repairs until after the workspace is usable.

1.18.3

Fixes and improvements

  • Restore the native macOS release artifact build on current GitHub runners while preserving the web search authentication fix in the release train.

1.18.2

Fixes and improvements

  • Restore global search for signed-in web sessions and keep its failure messages accurate.

1.18.1

Fixes and improvements

  • Remove deleted global-search entities from AI Search and keep AI index generations current after tombstones settle.
  • Preserve assistant conversation deletion after the global-search projection migration.
  • Show the current web version and pending release notes on the public changelog while removing internal commit ids, dependency bumps, and Changesets terminology from published entries.

1.18.0

Highlights

  • Replace capped item retrieval with complete global search across Direct, AI, and exhaustive typo-tolerant Matches sections, including opaque pagination, caching, filters, and native search surfaces.

Fixes and improvements

  • Add restrained state, feedback, onboarding, and completion motion across web, iOS, and macOS, including reduced-motion behavior and iOS sensory feedback.

1.17.1

Fixes and improvements

  • Flatten the Daily Focus categories into open sections with a simpler single-container layout across web, iOS, and macOS.

1.17.0

Highlights

  • Add shared Daily Focus checklists with Must Do and Should Do categories, offline sync, and deterministic five-item capacity resolution across web, iOS, and macOS.

Fixes and improvements

  • Page web item collections on demand with bounded server-backed windows and exact Inbox stats.

1.16.4

Fixes and improvements

  • Keep the web search input mounted and focused while debounced URL search state updates.

1.16.3

Fixes and improvements

  • Restore browser-extension OAuth client registration compatibility with the web app's Better Auth schema.

1.16.2

Fixes and improvements

  • Refresh application runtime and build dependencies, including the CLI parser, browser error reporting, authentication, TanStack, Cloudflare, and test tooling.

1.16.1

Fixes and improvements

  • Bound large-library retrieval, hydration, pagination, and sync work across Second's clients while coalescing assistant streaming presentation updates.

    • Index web hybrid fallback retrieval, page the item library, batch sync-push authority reads, and delta-gate Notion ingestion.
    • Batch native workspace hydration, bound exact and semantic knowledge search, and incrementally project managed-agent streams.
    • Move Obsidian pulls to retry-safe delta cursors and coalesce assistant stream rendering on iOS and web.

1.16.0

Highlights

  • Add a versioned, user-controlled AI Profile with deterministic import and export, context receipts, and profile-aware assistant behavior across web, iOS, and macOS.

1.15.0

Highlights

  • Assistant conversations now persist server-side. Reload past chats from the new History menu, start a fresh chat, or delete a conversation; assistant answers render citations as inline links to the referenced item. Adds GET/DELETE/PUT /api/v1/assistant/conversations[/$id] (idempotent upsert for cross-device push, dual cookie/bearer auth) backed by new assistant_conversations/assistant_messages tables, covered by export and account deletion.
  • The inbox and PARA node views gain a newest/oldest-first sort toggle (list and table modes). Inbox still defaults to oldest-first for triage; node lists default to newest-first.

1.14.4

Fixes and improvements

  • Assistant answers no longer leak raw capture ids: the prompt now cites sources by title, and a server-side stream sanitizer strips any residual [[cite:…]] markers or UUIDs for every client. Reasoning effort lowered to low for faster time-to-first-token.

    iOS: capture detail and assistant chat now render Markdown with real structure (headings, paragraphs, lists, quotes, code) instead of one run-on block — AttributedString(markdown:) drops block newlines, so a block-aware MarkdownText renderer handles layout. Share-sheet, widget, and App Intent captures now appear in the inbox without pull-to-refresh: the outbox posts a Darwin notification, the running app drains and reloads, and foreground drains also refresh the inbox. "Capture Screen Text" intent rewritten with a fallback chain — piped image (OCR) → text → link → clipboard text → clipboard image (OCR) — so a bare Action Button press always captures something useful.

1.14.3

Fixes and improvements

  • GET /api/v1/items feed mode accepts direction=asc for oldest-first ordering (default stays newest-first; rejected with order=updatedAt).

1.14.2

Fixes and improvements

  • Surface the shipped native apps and features: landing gains "Native Mac & iPhone apps" and "Ask your Second" cards plus widget/share-sheet/hotkey capture mentions and the Sunday review email digest; /integrations gains Second for Mac, Second for iPhone (beta), Homebrew CLI install, Notion continuous sync, and Apple Notes sync; pricing/privacy/onboarding-surfaces updated to match. Also adds PATCH /api/v1/rules/:id (toggle enabled) so the iOS settings screen can pause/resume filing rules.

1.14.1

Fixes and improvements

  • Accept OAuth 2.1 bearer tokens (and personal sb_… API tokens) on /api/assistant alongside browser cookie sessions, gated on the second:read scope — enables the native iOS agent screen to authenticate with the same tokens as the v1 API.

1.14.0

Highlights

  • Desktop 1.2.0: a full performance and reliability pass on the macOS app. Search no longer decrypts the library under the storage lock and semantic indexing is incremental and off the query path; lists, the inspector, and review surfaces render capped excerpts instead of full documents; the agent panel throttles streaming and draft saves. Fixes: share-sheet and drag-and-drop file captures no longer race the system's temp-file cleanup, session refresh is single-flight (no more spurious sign-outs), Apple Notes updates commit atomically (no phantom conflicts), remote deletes no longer flip search into a slow fallback, text-field undo is no longer shadowed (organization undo moved to ⌘⌥Z), and VoiceOver no longer reads whole documents as row labels. Adds versioned local schema migrations and a much-expanded test suite.

1.13.0

Highlights

  • Sentry error reporting across every surface: the web Worker reports fetch/cron/queue failures (errors only, production-gated, release-tagged second-brain@<version>), the CLI captures uncaught exceptions and unhandled rejections without slowing the happy path, the extension reports background/popup/oauth-callback errors with breadcrumbs disabled so page URLs and titles never attach, and the Obsidian plugin reports plugin errors with request/extra stripping so vault paths stay local. Everywhere: sendDefaultPii: false, no tracing, no user content in events.

1.12.9

Fixes and improvements

  • Re-saving an already-captured URL with page-extracted content now also heals items whose latest revision is a thin ready stub (bot-wall skeleton or OG blurb below the 500-char provided-content floor), not just failed or empty revisions. Ready content of real size is still never replaced, and provided content must beat the stub it displaces.

1.12.8

Fixes and improvements

  • Tolerate the AI Search instance create race: concurrent first-time ingestions on a fresh account both miss the instance and both create it; the loser's already_exist now re-reads the winner's instance instead of failing the capture's indexing.

1.12.7

Fixes and improvements

  • Fix AI Search tenant auto-creation being dead since mid-August: the not-found detector only matched "not found"/"404", but the binding reports ai_search_not_found — so a missing instance was never created and every indexing call failed. New users' search instances now self-create on first capture.

1.12.6

Fixes and improvements

  • Successful AI Search indexing now clears any stale index_failed marker on the revision (healed rows no longer display an error that no longer applies).
  • Search indexing now records the real error message (and logs it to Workers Logs) instead of a flat index_failed. Uploads are accept-and-go — Cloudflare finalizes indexing asynchronously — and a failed upload is retried through the existing retry-ingestion path on demand.

1.12.5

Fixes and improvements

  • Fix AI Search indexing failing on every capture: uploads are now accepted without polling for finalization (uploadAndPoll's fixed timeout turned the platform's slow finalization into fake index_failed on 400+ items — the documents indexed fine in the background). Also fixes re-running ingestion for an already-live revision crashing on the active-ready constraint.

1.12.4

Fixes and improvements

  • Re-saving an already-captured URL with page-extracted content now heals it: when the existing item's latest revision failed or never got content, the provided Markdown becomes a new revision and re-indexes (previously dedupe dropped the content entirely). Captures that already have ready content are untouched.

1.12.3

Fixes and improvements

  • Canonical Markdown normalization no longer skips consecutive raw HTML nodes (splice-during-visit now revisits the shifted sibling), so captured content can't leak stray markup.
  • URL captures accept page-extracted Markdown (contentMarkdown) so browser-extension saves carry real content from the user's session; the ingestion pipeline skips rendering when a revision already has content.

1.12.2

Fixes and improvements

  • Harden PDF capture ingestion: converter output that arrives as raw HTML (table-dense documents like service manuals) is salvaged to plain text instead of failing as empty, PDF responses are validated by magic bytes so bot-wall stubs can't poison conversions, and the size cap rises to 25 MB for large manuals and brochures.

1.12.1

Fixes and improvements

  • Fix capture ingestion for non-HTML targets and failure reporting. PDF URL captures now materialize through Workers AI toMarkdown (SSRF-safe bounded fetch, ai-conversion origin, title from the filename) instead of permanently failing. Permanent failures are no longer retried four times or flattened to a generic materialization_failed — the real code (not_html, http_status, pdf_too_large, …) is recorded on the revision.

1.12.0

Highlights

  • Add a public /changelog page that renders the web changelog, linked from the marketing footer.

1.11.2

Fixes and improvements

  • Fix HTTP 500 on the sync bootstrap (/api/v1/sync/bootstrap) for accounts past 100 items — the desktop sign-in completed OAuth but died on bootstrap, presenting as "sign-in doesn't work". Root cause: D1 allows at most 100 bound parameters per statement, and the content-summary IN (...) query bound one parameter per item. Every id-list query and multi-row insert that scales with caller data is now chunked under the cap via lib/d1-chunk.ts: sync bootstrap, bulk archive/unarchive/delete, account reset, weekly-review content loading, and AI-search retrieval loaders.

1.11.1

Fixes and improvements

  • Accept UUID v4/v5/v8 alongside v7 for client-supplied capture ids (captureIdSchema). Older desktop builds queued captures with random (v4) and deterministic content-hash (v8) ids; the strict v7 check permanently rejected them with HTTP 400, which poisoned the desktop sync outbox. The idempotency contract needs uniqueness, not time ordering.

1.11.0

Highlights

  • Desktop 1.1.0: the macOS app now checks for and installs updates in-app (Sparkle 2, EdDSA-signed), a long-session AttributeGraph crash is fixed, and the workspace lists got a full performance pass (lazy rendering, rows no longer re-render on every model publish).

1.10.1

Fixes and improvements

  • macOS 1.0.3: Apple Notes sync rewritten. Fixes a stdout pipe deadlock that hung every sync on any real library, switches to an incremental two-phase transport (lightweight index scan, batched body fetches only for new or changed notes), adds runner timeout/cancellation with distinct permission error mapping, tombstones rejected oversized notes so they are not refetched every poll, and shows a syncing state in Settings.

1.10.0

Highlights

  • Assistant chat rebuilt on shadcn chat components with shadcn/typeset rendering, a dedicated YouTube capture parser (metadata plus transcript, each layer degrading independently), a Linear-style mouse-aware inbox, and the items table view rebuilt on TanStack Table v9 with shadcn table primitives and TanStack Virtual.

1.9.1

Fixes and improvements

  • Fix the macOS sidebar divider painting an accent-colored focus bar

    • With Full Keyboard Access enabled, HSplitView's divider joins the key view loop and dragging it leaves it focused, and AppKit paints a focused divider in the accent color. The app now drops acceptsFirstResponder on NSSplitView (scoped to that class) so the divider can never hold keyboard focus; the canvas stays the focus owner and divider dragging is unaffected.

1.9.0

Highlights

  • Sync onboarding completion across surfaces and fix desktop sign-in stalling

    • /api/v1/me now returns onboardingCompletedAt, and a new idempotent POST /api/v1/me/onboarding lets the desktop (and other token clients) mark onboarding complete. The desktop seeds its local wizard gate from the server after sign-in and pushes completion back, so onboarding happens once per account instead of once per surface.
    • Fix the OAuth 2.1 continuation after login/signup: the sign-in/sign-up pages no longer SPA-navigate over the SDK's redirect, and the login/signup cross-links preserve the signed OAuth query byte-for-byte. The desktop loopback listener is always reached now instead of hanging after a fresh signup.
    • Rework the onboarding surfaces step: the browser-matched extension comes first, then the desktop app and CLI, with the remaining tools under an "Other tools" split and a pointer to Integrations.

1.8.0

Highlights

  • Add a PARA-teaching onboarding flow across surfaces

    • Web: new-user wizard at /onboarding (welcome, first capture, project, area, resource, surfaces) driven by a ?step= search param. Each PARA step creates the node for real and has a disclosure explaining the concept. The capture step accepts a link or a note. Completion is required: /app redirects to the wizard until user.onboarding_completed_at is set, and finishing lands in the Inbox.
    • packages/utils: new para-guide module with the canonical PARA concept definitions and onboarding steps, shared verbatim by the web wizard, CLI, and MCP.
    • CLI: second onboarding walks the same flow interactively (capture, project with goal/deadline, area with standard, resource); --guide or a non-TTY prints the guide instead.
    • MCP: new read-only get_onboarding_guide tool returning the steps and concept definitions (second:read scope).
    • Agent skills: second-onboarding in skills/ (MCP or CLI transport) and plugins/second/skills/ (MCP-only).
    • Item page and content dialog now split ingestion states: while a capture is still processing the page polls and shows a working state with no retry button; only a failed revision shows the error with retry.
    • Migration 0011 backfills onboarding_completed_at for existing users so only new signups see the wizard; account reset clears it so a wiped account re-onboards. Apply the prod D1 migration before merging this.

1.7.4

Fixes and improvements

  • Polish the native macOS workspace with resizable navigation, persistent search results, reversible conversation archiving, redesigned review and capture surfaces, real permission requests, and complete keyboard navigation.

1.7.3

Fixes and improvements

  • Ship the native macOS conversation experience with all-content search, direct conversation actions, a clearer context picker, centered empty states, and simplified navigation.

1.7.2

Fixes and improvements

  • Route background text generation through OpenAI GPT-5.6 Luna via Cloudflare AI Gateway.

1.7.1

Fixes and improvements

  • Fix managed reasoning authentication and streaming across the native macOS client and web service, including bounded handling for rejected requests, terminal stream markers, and whitespace-preserving response deltas.

1.7.0

Highlights

  • Add scoped managed-agent tool contracts for native preview, approval, audit, and local execution.
  • Add provider-neutral typed managed-agent action proposals for native preview, approval, execution, undo, and audit flows.
  • Add managed audio transcription mediation for native voice captures.
  • Add the managed Ask Second turn endpoint for the native persistent global thread.
  • Add explainable semantic retrieval and enforce citations for managed answers grounded in local context.

Fixes and improvements

  • Add the versioned desktop sync contract for offline captures and PARA edits.
  • Add transparent, typed filing rules with exact scopes and native-first synchronization.

1.6.0

Highlights

  • Add global capture search across metadata, saved content, PARA locations, and Archive with URL-backed filters, pagination, and an unindexed-data fallback.
  • Make permanent item and PARA-node deletion discoverable across web and desktop, preserving node captures in Inbox and syncing deletion cleanup.

Fixes and improvements

  • Add a standards-compliant Agent Plugin package for Second's production MCP server and capture/search/PARA workflows.
  • Use the supplied Second product artwork across web, extension, and desktop branding and packaging surfaces.
  • Use the official Chrome Web Store listing for extension installation links.
  • Make second the CLI and Homebrew distribution name, and update the public tap through the sanctioned release flow.
  • Make Start over permanently delete ownership-scoped Second data, revoke access credentials, queue search-tenant cleanup, and converge local-first clients with sync tombstones.
  • Move filing rules into a user-facing Automation settings tab and keep Developer focused on API tokens.
  • Keep the authenticated app shell within a bounded viewport so the global header stays fixed while route content scrolls in one accessible area.

1.5.2

1.5.1

Fixes and improvements

  • Enforce v1 OAuth scopes and validate sync mutation values.
  • Recover interrupted sync item deletions on retry
  • Use stable keyset cursors for desktop item discovery.

1.5.0

Highlights

@second/web adds:

  • Migration 0010: sync_ops (the oplog table — entityType/entityId/field/value/hlc/deviceId, composite (userId, hlc) index for pull, composite (userId, entityType, entityId, field, hlc) index for LWW lookups and compaction).
  • POST /api/v1/sync/push, GET /api/v1/sync/pull?cursor=, GET /api/v1/sync/bootstrap — the standard authorizeV1 + zod + rate-limited v1 pattern. Push applies per-op LWW via hlc comparison, is idempotent under retry (a resubmitted op with an already-recorded hlc reports accepted without double-applying), and returns the canonical row for losers. Pull is one indexed range query. Bootstrap returns the full current snapshot (items via the same mapping GET /api/v1/items uses, para nodes, rules) plus a starting cursor.
  • Every existing mutation of a client-mutable field (item title/note/paraNodeId/archivedAt; para-node name/goal/deadline/standard/sortOrder/archivedAt/completedAt; rule create/delete) now writes its oplog row in the same db.batch() as the row mutation, across both the web app's server functions and the v1 REST routes — a device syncing sees edits made from any client, not just ones that go through push. Deletes are tombstones (field: "_deleted") rather than a silent row disappearing; hard-delete-after-tombstone-propagation stays a deferred, separate decision, and this cycle's compaction policy is written to never prune a field's current/latest row, so a tombstone is never pruned by it either.
  • The capture-ingestion workflow's two terminal steps (materialization failure, revision activation) write a synthetic _contentStatus oplog row (reserved "server" deviceId) so pull observes ingestion completing without instrumenting every intermediate status transition — the one deliberately-scoped-down part of "server-mastered fields flow down"; see apps/web/CONTEXT.md and this change's own documentation for the boundary.
  • A new daily cron (0 3 * * *, alongside the existing 15-minute integration sync and daily review digest) compacts superseded oplog history behind a 30-day retention window. No device-registry table: cursors are stateless, client-held opaque hlc strings — a device that hasn't synced in over the retention window falls back to bootstrap rather than an incremental pull, a defined degraded path, not data loss.

@second/api-client gains typed syncBootstrap, syncPull, syncPush methods, response-validated against the new @second/types/sync schemas.

  • GET /api/v1/transitions?days= — recent transitions (was web-only).
  • GET /api/v1/items/:id/transitions — per-item transition history (was web-only).
  • POST /api/v1/para/:id gains a "complete" action (project-only; archive/restore unchanged).
  • POST /api/v1/items/archive-all — the information-bankruptcy reset (was web-only).
  • POST /api/v1/rules/offer — rule-offer suggestion, including its "already covered by an existing rule" check (was web-only).
  • GET /api/v1/url-metadata?url= — bounded URL preview; now goes through the same public-URL SSRF guard (assertPublicHttpUrl) used by capture extraction, which this endpoint was missing.
  • GET /api/v1/search gains cursor pagination (cursor=, nextCursor in the response) past the previous silent 20-result cap, bounded by AI Search's own 50-result ceiling; existing no-cursor callers are unaffected other than now correctly honoring a limit above 20.
  • GET /api/v1/items gains since= (ISO or epoch-millis, filters on updatedAt) and order=updatedAt (ascending) for delta sync pulls, alongside the existing createdAt DESC default. Fulfils the ?since= wish noted at apps/obsidian-plugin/src/sync.ts:146.
  • POST /api/v1/captures accepts an optional client-supplied id (UUIDv7-shaped). A repeat of the same id by the same user returns the existing item as a duplicate-style 200 (idempotent outbox retries); the same id under a different user is rejected with 409.

@second/api-client gains typed methods for all of the above (listRecentTransitions, listItemTransitions, archiveAllItems, offerRule, getUrlMetadata, widened transitionParaNode, and since/order/cursor options on listItems/searchItems). @second/types gains the shared captureIdSchema (UUIDv7 shape) on capture inputs.

1.4.0

Highlights

  • Rebuild URL content extraction on Browser Run quick actions: one snapshot pass renders the page (HTML + whole-page Markdown + status/title), then an html-mode markdown pass prunes page chrome in the browser and converts — replacing the HTMLRewriter clean + Workers AI conversion path. Transient Browser Run failures (429/5xx) now retry through the ingestion workflow, exhausted retries mark the revision failed instead of leaving it stuck materializing, bot-walled preflight fetches no longer block the browser render, and rendered page titles replace hostname-placeholder item titles.

1.3.0

Highlights

  • Captures now store the content instead of the page. Per-host parsers (x/twitter, youtube, reddit, hacker news, github threads) build Markdown from the page's own metadata, and everything else goes through an HTMLRewriter pass that strips nav, footers, cookie walls and login prompts before conversion — applied on both the Browser Rendering and AI-conversion paths. Images are kept as images end to end rather than being rewritten to links at storage time.

    Clicking a capture now opens /app/items/$itemId with the ingested content, not the source site, and a signed-in visitor landing on / is sent to the Inbox. Ingestion no longer marks a capture failed when only search indexing fails, so materialized Markdown stays readable. Fixes horizontal page scroll caused by the sidebar inset refusing to shrink, inbox rows overflowing instead of truncating, and inbox lists loading every revision's full Markdown to render a 280-character excerpt. The extension popup lists its keyboard shortcuts, read from the browser so they reflect user remaps.

1.2.0

Highlights

  • Move every surface to the custom domain 2nd.thedevdavid.com and send email from 2nd@thedevdavid.com. The Worker now serves only the custom domain — workers_dev is off, so there is a single origin for auth cookies and the OAuth issuer. Adds Smart Placement (the app makes several sequential D1 queries per request), Workers Logs with tracing and source-map upload, and shows the running version in every app: Settings → About on the web, the extension popup's settings panel, the desktop settings window, the Obsidian settings tab, and brain status.

1.1.0

Highlights

  • Restore the one-shot Notion import card, which plan 001 dropped when it rebuilt the integrations page; enforce reserved usernames so role and RFC 2142 names cannot be claimed; compute the triage rule offer server-side so a host already covered by a rule no longer offers a duplicate; and remove dead exports, the unreachable legacy categorize input shape, and the web-only PARA node delete that duplicated DELETE /api/v1/para/$id.

1.0.2

Fixes and improvements

  • Handle standard Workers AI chat-completion responses and retry one invalid weekly-review generation before falling back.

1.0.1

Fixes and improvements

  • Use the highest chunk overlap accepted by the current Cloudflare AI Search API.
  • Rework the weekly review email around saved-content synthesis and recall cards, move activity metrics to the end, and reject internal evidence metadata in user-facing prose.

1.0.0

Major updates

  • Plan 007 replaces URL-only item creation with a strict URL/Markdown capture contract. Captures are stored as canonical Markdown, ingested durably, and retrieved through private per-user AI Search. REST, MCP, CLI, desktop, extension, Obsidian, and web writers now use the new capture/content APIs; legacy create commands and tools are removed.

0.8.0

Highlights

  • Add AI-powered weekly reviews grounded in captures, assistant prompts, and MCP activity.

0.7.0

Highlights

  • All email now sends through a Cloudflare Queue with retries and react-email templates. Weekly review digest arrives Sunday early evening in each user's timezone and can be turned off in Settings → General → Weekly review; users without a saved timezone default to UTC.

0.6.1

Fixes and improvements

  • List extension keyboard shortcuts and context-menu actions on the integrations page

0.6.0

Highlights

  • Assistant redesigned: centered empty state, large prompt composer, suggestion chips
  • Enable better-auth admin, username, and organization plugins (backend support, no UI)
  • Adopt the beanz shadcn config (base-lyra/taupe) and theme tokens
  • Migrate all shadcn/ui primitives to the base-lyra style (squared corners, compact type) to match the adopted beanz theme
  • Settings reorganized into tabs with section-row layouts (General, Security, Developer, Data, Danger Zone)

Fixes and improvements

  • Integrations pages: CLI icon, full surface list with disabled upcoming entries, copy cleanup

0.5.1

Fixes and improvements

  • Deduplicate parseScopes/parseJson and escapeHtml into single shared helpers
  • Split /app/integrations cards into per-card component files (no behavior change)
  • Split settings cards into per-domain component files (no behavior change)

0.5.0

Highlights

  • Notion import: one-shot page import into the Inbox from the integrations page (token never stored)
  • Notion integration foundation: persistent connections, sync engine with 15-minute cron, token connect with first-sync import
  • Notion OAuth connect routes, HMAC-verified webhook ingestion, and opt-in archive propagation (secrets pending — see docs/notion-oauth-setup.md)

Fixes and improvements

  • Item sources gain notion, obsidian, and apple-notes for the upcoming import integrations, with matching source badges
  • Shared marketing header/footer across /, /pricing, /integrations, /privacy (nav no longer differs per page); deduplicated GitHub link constants into lib/links

0.4.0

Highlights

  • Integrations pages: marketing /integrations catalog and /app/integrations with MCP setup and OAuth connected-apps management

0.3.0

Highlights

  • Spec-compliant OAuth for the MCP server: RFC 9728/8414 discovery, resource audiences, JWKS verification, second:read/second:write scopes
  • v1 items list gains inboxOnly/paraNodeId/paraType filters and a GET /api/v1/items/count endpoint; getInboxCount no longer downloads 500 items per poll.
  • Surfaced per-item transition history in the edit dialog and a weekly triage-activity card on /app/review, backed by the existing item_transitions table
  • Capture now detects duplicate URLs (normalized: tracking params and fragments stripped) and returns duplicateOf instead of inserting a second row
  • Settings → Danger zone gains the information-bankruptcy reset: archive every node and capture with a type-to-confirm dialog
  • v1 gains single-resource reads: GET /api/v1/items/$id and /api/v1/para/$id, with matching getItem/getParaNode api-client methods
  • Rules manageable over v1 (GET/POST/DELETE /api/v1/rules) and brain rules list/add/rm
  • Bulk archive/unarchive over POST /api/v1/items/bulk; brain archive/unarchive accept multiple ids
  • Export everything: brain export --format json|csv and a Settings → Export download
  • Archive rows show og-image thumbnails (favicon/icon fallbacks) — the imageUrl captured since day one is finally visible

Fixes and improvements

  • Weekly-review digest email pipeline behind a Cron Trigger — spike + decision record (docs/research/07-weekly-review-cron-spike.md); sends only when the review has content
  • Spiked an MCP endpoint (/api/mcp) exposing save/search/inbox/nodes/categorize over the existing v1 logic — design record in docs/research/08
  • Replace scaffold README with real project documentation
  • Pricing page marks Pro as planned and notes AI features are free during the beta

0.2.2

Fixes and improvements

  • Throttle the lastUsedAt write in API-token verification to once per minute — the v1 auth path is now a single D1 read in the common case.
  • Stop the wasted updateItemFn round-trip on archive/unarchive, and roll back with an error toast when the archive server call fails.

0.2.1

Fixes and improvements

  • Remove the deprecated paraNodeId field from CategorizeResponse (suggestedNodeId is the single canonical field now), resolving the last deferred cleanup-audit items.

    • Web: new public /privacy page (linked from the landing and pricing footers) — required by both extension stores.
    • Extension: fix the settings panel's quick-save hotkey label (⌘⇧2, matching the save-close-tab manifest command); wxt.config.ts imports DEFAULT_API_URL from @second/api-client instead of a hardcoded literal; store listing copy + submission checklists in store/ (Chrome Web Store + Apple App Store).

0.2.0

Highlights

  • First coordinated release of the Second brain companion — complete PARA system, OAuth-secured surfaces, and shared packages.

    PARA canon (web + all surfaces)

    • Archive is a state, not a category: archived_at on nodes and items, with Projects/Areas/Resources as the only node types. Item transitions (move/archive/restore/complete) are recorded in item_transitions.
    • Capture→organize separation: nothing auto-files at capture; everything lands in the Inbox. Rules + Workers AI suggest destinations at triage time with reasoning ("has a goal and a deadline → Project") and confidence-aware policy.
    • Keyboard-first triage: X archives (never silent-deletes), ⇧X deletes with undo window, ⌘Z undo, auto-advance, AI suggestion bar with one-key accept, just-in-time node creation, rule-learning offers (R).
    • PARA surfaces: node form with goal/deadline/standard prompts and false-project nudges, complete-project salvage flow, 10–15 active-project gauge, /app dashboard home, /app/review weekly sweep, archive restore/reactivation, command palette with item search (archived ranked last), assistant bundle scoping.

    Surfaces

    • CLI (brain): nodes list/create with goal/deadline/standard, move, retitle, archive/unarchive, inbox --archived, server-side search with pagination, review weekly summary. rm warns it's permanent.
    • Extension: standards-based OAuth 2.1 + PKCE sign-in (dynamic public-client registration, consent page, refresh-token rotation) — no pasted URLs or tokens; API URL is build-time env. Hotkey workflow: ⌘⇧S silent save, ⌘⇧1 detailed save via popup, ⌘⇧2 save+close tab, ⌘⇧3 save+close window, with system notifications for every outcome. Safari (MV2) target with generated Xcode project.

    Shared packages

    • @second/types: zod contracts for items, PARA nodes, API responses.
    • @second/utils: PARA constants (actionability order, labels), formatAge, deadline helpers, computeReviewSummary.
    • @second/api-client: typed v1 API client (items, nodes, transitions, inbox count, me, categorize) used by CLI, extension, and desktop. The v1 API accepts both OAuth access tokens and sb_ API tokens.
Mac v1.10.1

1.10.1 — 2026-09-23

  • Keep packaged verification fixtures isolated from the installed app's sign-out state.

1.10.0 — 2026-09-23

  • Add account-bound complimentary lifetime access with administrator grants, single-use invitations, unlimited commercial allowances, and native access recognition.

1.9.1 — 2026-09-21

  • Include the Apple billing package in the macOS App Store target.

1.9.0 — 2026-09-21

  • Add account-bound subscription contracts, provider reconciliation, usage accounting and billing controls across Second's clients. Payment activation and quota enforcement remain gated by the approved measured catalog and provider rollout checks; saved content and pending work remain recoverable when access changes.

  • Add account-bound Apple subscription settings with localized StoreKit pricing, explicit unconfigured-store states, restore/manage controls, trial eligibility copy, and build-time review-origin configuration.

  • Prepare Apple RevenueCat builds with fail-closed first-party OAuth metadata, typed provider error handling, and a validated App Store introductory-offer request draft.

1.8.6 — 2026-09-20

  • Make sign-out accessible across Second: add macOS menu and sidebar actions that work offline, move iOS sign-out beside account details and keep failed credential cleanup locked across restarts, expose extension sign-out without requiring a loaded identity, add Obsidian sign-out with in-flight sync fencing, and support the CLI's sign-out alias with environment-token guidance.

1.8.5 — 2026-09-15

  • Add scoped AI connection permissions, versioned knowledge retrieval, and shared save and organization workflows with durable recovery. Retain and export original files, materialize versioned file evidence with bounded MCP reads, and provide a separately consented native original-retention connection. Make introductory guidance optional and preserve account-bound connection and onboarding state across supported surfaces.

    Apply the authority, operation/file storage, evidence-erasure, original-file erasure, and immutable extraction migrations before deploying. Provision the private original-file bucket separately. Host setup packages describe supported connection paths; real-host qualification and listing publication remain separate release steps.

1.8.4 — 2026-09-14

  • Keep macOS account data isolated across sign-out and delayed work, bind Daily Focus and AI Profile caches to validated identities, and add support/privacy links in Settings.
  • Use stable server account IDs and API origins for native sessions and caches, and reject stale credential refreshes and callbacks across account changes.
  • Scrub user-derived payloads from native Sentry events while retaining crash classification and stack diagnostics.

1.8.3 — 2026-09-14

  • Add a read-only App Store Connect submission-readiness command for the unified iOS and macOS 1.7 drafts.
  • Reconcile release tooling with App Store preparation for iOS, macOS, and embedded Safari while publishing GitHub, Homebrew, and Sparkle artifacts independently.

1.8.2 — 2026-09-14

  • Keep the selected audio file's sandbox access grant active while reading its duration, so App Store audio imports can be saved to Inbox.

    Finish account cleanup successfully when its AI Search tenant is already absent.

1.8.1 — 2026-09-14

  • Upgrade dependencies and native error reporting to current compatible releases. Migrate OAuth provider resources and client redirects for Better Auth 1.7, preserve existing registrations, enforce token revocation/session checks, and update Notion sync for the current data-source API.

1.8.0 — 2026-09-11

  • Prepare unified Apple App Store distribution with Safari embedded in both native apps, a sandboxed Mac target using App Store updates, required-reason privacy manifests, and native account-deletion links. Make Safari's background compatible with iOS and clarify privacy disclosures for captures and diagnostics. Require explicit cloud and AI processing consent before connecting the native App Store apps and browser extension, and keep iOS dictation on-device.

1.7.0 — 2026-09-07

  • Add Search-backed chats and durable Brief generation with synchronized sources, account templates, and pinned evidence.

1.6.4 — 2026-09-05

  • Keep the macOS app responsive during startup by reading the saved sign-in session from Keychain in the background before unlocking the workspace.

1.6.3 — 2026-09-04

  • Route error reporting through the personal Sentry organization and add crash reporting to the iOS app.

1.6.2 — 2026-09-04

  • Bound web search requests and defer native derived search-index repairs until after the workspace is usable.

1.6.1 — 2026-09-03

  • Restore the native macOS release artifact build on current GitHub runners while preserving the web search authentication fix in the release train.

1.6.0 — 2026-08-31

  • Replace capped item retrieval with complete global search across Direct, AI, and exhaustive typo-tolerant Matches sections, including opaque pagination, caching, filters, and native search surfaces.

  • Add restrained state, feedback, onboarding, and completion motion across web, iOS, and macOS, including reduced-motion behavior and iOS sensory feedback.

  • Bound semantic-vector decoding into cancellable concurrent batches while preserving deterministic ordering and lowest-index failures, reusing one decoder per worker batch. Reuse a lazily loaded, synchronized on-device Natural Language sentence model per provider runtime so corpus rebuilds do not recreate model assets for every document. Reuse normalized query tokens, batch healthy knowledge-search metadata and semantic capture reads, and preserve canonical ordering, current scope evidence, citations, malformed-row behavior, and cancellation boundaries without per-candidate database statements. Bound the packaged performance benchmark's unmeasured setup, report clean child exits immediately, and retain privacy-safe stage and count diagnostics when the benchmark fails before publishing its full report. Launch packaged performance phases in the background without reactivating their primary window or allowing App Nap to demote measured user-initiated work, so benchmark setup cannot steal focus or receive an unrelated quit command, and keep synthetic performance fixtures out of the user's Spotlight index.

1.5.1 — 2026-08-30

  • Flatten the Daily Focus categories into open sections with a simpler single-container layout across web, iOS, and macOS.

1.5.0 — 2026-08-30

  • Add shared Daily Focus checklists with Must Do and Should Do categories, offline sync, and deterministic five-item capacity resolution across web, iOS, and macOS.

1.4.4 — 2026-08-29

  • Prevent macOS semantic indexing from crashing on oversized local documents and keep cached knowledge available while transient OAuth or server failures recover.

1.4.3 — 2026-08-27

  • Update the native crash-reporting SDK to Sentry Cocoa 9.26.1.

1.4.2 — 2026-08-27

  • Keep the macOS workspace responsive while Spotlight failures and existing split analyses finish startup work.

1.4.1 — 2026-08-27

  • Bound large-library retrieval, hydration, pagination, and sync work across Second's clients while coalescing assistant streaming presentation updates.

    • Index web hybrid fallback retrieval, page the item library, batch sync-push authority reads, and delta-gate Notion ingestion.
    • Batch native workspace hydration, bound exact and semantic knowledge search, and incrementally project managed-agent streams.
    • Move Obsidian pulls to retry-safe delta cursors and coalesce assistant stream rendering on iOS and web.

1.4.0 — 2026-08-26

  • Add a versioned, user-controlled AI Profile with deterministic import and export, context receipts, and profile-aware assistant behavior across web, iOS, and macOS.

1.3.0 — 2026-08-23

  • Ask Second now renders Markdown in the transcript and opens item citation links in-app instead of the browser. Assistant history syncs across devices: conversations started on the Mac appear on web and iOS, and web/iOS conversations are pulled into the local thread list. Knowledge search gains a Newest/Oldest/Relevance sort.

1.2.6 — 2026-08-23

  • Make global-hotkey registration failures observable and self-healing: failures are reported to Sentry with the OSStatus, Capture settings show a persistent "Global shortcut is inactive" warning with a Retry button, and registration retries automatically whenever the app becomes active. Rollback on shortcut-change failure now also reports and updates state.

1.2.5 — 2026-08-22

  • Use a proper Second.icns app icon — the canonical Second mark re-rendered at full resolution with the macOS rounded-tile treatment (via the new scripts/generate-app-icons.swift) — instead of stapling the raw 512px web PNG into the bundle. The in-app SecondLogo.png is unchanged.

1.2.4 — 2026-08-22

  • Complete the iOS keychain fix: the add-only patch left SecItemUpdate/SecItemDelete still carrying kSecUseAuthenticationUI, which iOS rejects with errSecParam (-50) on every mutation, so token saves still failed on the update-first path. All mutations now omit the attribute on iOS via a shared mutationQuery; reads keep it. Verified with a working on-device sign-in.

1.2.3 — 2026-08-22

  • Fix iOS keychain writes failing with errSecParam (-50): SecItemAdd rejects kSecUseAuthenticationUI on iOS (macOS tolerates it), so every credential save on the iOS app failed with "could not access sign-in storage". The shared store now drops that attribute from adds on iOS only; reads/updates/deletes keep it. The keychain error message now includes the OSStatus for diagnosis. Proven with a simulator probe and on-device sign-in.

1.2.2 — 2026-08-22

  • Fix a startup crash on libraries created before 1.2.0: the base schema batch created the source_url_hmac index before migration v2 could add the column, so opening an older database failed with "no such column: source_url_hmac" and the app could not start. The index now lives only in the migration, and a regression test proves a legacy database opens, migrates, and stays usable. No data is affected.

1.2.1 — 2026-08-22

  • iOS companion app groundwork: SecondCore is now multiplatform (.iOS(.v17) alongside macOS 13) with SecTask and security-scoped bookmark calls platform-gated, OAuth dynamic client registration registering an injectable redirect URI alongside the macOS loopback, an injectable OAuth client name, and a shared keychain access group on the credential store for app↔widget session sharing. Powers the new iOS app in apps/ios (versioned separately as @second/ios). macOS behavior is unchanged (full suite green).

1.2.0 — 2026-08-22

  • Search stays instant as your library grows — lookups no longer decrypt your whole library behind the scenes, and semantic search updates itself in the background instead of making you wait
  • Lists, the inspector, and review screens scroll smoothly even with very long captures — rows now show short excerpts instead of laying out entire documents
  • The agent panel stays responsive while answers stream in and while you type — drafts and thread updates are now batched instead of hitting the database on every keystroke and token
  • Sharing files from the share sheet or dropping them onto Second no longer intermittently fails — file captures are copied before the system reclaims them, and sharing several items at once now captures all of them
  • Fewer surprise sign-outs — renewing an expiring session is now single-flight, so a rotated credential can no longer be overwritten out of order
  • Apple Notes sync is sturdier: multi-step updates now commit atomically (no more phantom conflicts after an interrupted sync), crash recovery works again, and outbound sync no longer decrypts your library to decide what to send
  • VoiceOver no longer reads entire documents as row labels, keyboard focus follows the onboarding steps, and Space/Return no longer trigger search actions while you're focused elsewhere
  • Text undo works everywhere again — ⌘Z belongs to text editing; undoing an organization action moved to ⌘⌥Z
  • Syncing deletions from your other devices no longer flips search into a slow fallback mode
  • Under the hood: versioned local database migrations, faster startup index rebuilds, and a much-expanded test suite

1.1.9 — 2026-08-20

  • Crash, watchdog, and app-hang reporting via Sentry (no PII, no content, errors only) — startup freezes and crashes are now reported automatically instead of needing to be described by hand
  • Launching Second no longer freezes on the spinner while your library opens — the app window stays responsive and the workspace appears as soon as it's ready
  • Syncing a large library from your other devices no longer stalls the app — downloads now commit in small batches so the interface keeps responding
  • Content downloaded in the background now updates the affected items in place instead of briefly reloading the whole workspace
  • Apple Notes now runs its first sync a few seconds after launch instead of competing with startup
  • Signing in no longer loads your workspace twice

1.1.8 — 2026-08-20

  • Apple Notes "Needs attention" entries now say what failed, which capture or note it concerned, and what to do next — including plain-language permission guidance — instead of a bare "The local operation could not be completed."
  • Removing Second-created notes now stops at the first permission or availability failure and explains it in Needs attention, instead of spinning on "Removing…" while every note fails the same way
  • The "Remove Second-created Notes…" action now lives inside the Apple Notes settings section instead of a separate Removal section
  • Telemetry and Diagnostics "Stored events" counts now update live as events are recorded
  • Private usage counts and troubleshooting history (Telemetry and Diagnostics) are now on by default — they stay on this Mac and never include content or credentials; you can turn them off in Settings

1.1.7 — 2026-08-20

  • The update dialog with release notes now appears instead of silent installs; checks still run at every launch
  • Enabling Apple Notes sync no longer creates notes in Apple Notes unless you opt in separately
  • Turning Apple Notes sync on or off now asks for confirmation first
  • New action removes only the notes Second created in Apple Notes — everything else in Notes stays untouched

1.1.6 — 2026-08-20

  • Fixed the background content download never starting when there were no local changes to sync — it now runs at every launch

1.1.5 — 2026-08-20

  • Items captured on the browser extension and web app now download their full ingested content automatically in the background
  • Opening any synced item upgrades it to the server's canonical content (previously only notes, not web pages)

1.1.4 — 2026-08-19

  • Checks for updates on every app launch, in the background
  • Release notes now appear directly in the update dialog
  • New in-app Changelog pane in Settings
  • New document reader for captures with rendered Markdown
  • Fixed clipped content in Settings panes
  • Faster capture and search list rendering

1.1.3 — 2026-08-19

  • Fixed desktop sync so items captured on the browser extension and web app now appear on the desktop
  • Remote items upgrade to their full content on first open
  • Fixed ISO8601 timestamp parsing during sync

1.1.2 — 2026-08-19

  • Fixed a class of freezes and crashes caused by unbounded suggestion rows (pruned 18,000+ rows)
  • Improved list rendering performance

1.1.1 — 2026-08-19

  • Bug fixes and performance improvements

1.1.0 — 2026-08-18

  • In-app update checking and installation via Sparkle, EdDSA-signed

1.0.0 — 2026-08-10

  • Initial Desktop 1.0 release
iPhone & iPad v1.10.0

1.10.0

Highlights

  • Add account-bound complimentary lifetime access with administrator grants, single-use invitations, unlimited commercial allowances, and native access recognition.

1.9.0

Highlights

  • Add account-bound subscription contracts, provider reconciliation, usage accounting and billing controls across Second's clients. Payment activation and quota enforcement remain gated by the approved measured catalog and provider rollout checks; saved content and pending work remain recoverable when access changes.

Fixes and improvements

  • Add an isolated, synthetic fixture target for producing populated iOS store screenshots without changing the production iOS target or using real account data.
  • Add account-bound Apple subscription settings with localized StoreKit pricing, explicit unconfigured-store states, restore/manage controls, trial eligibility copy, and build-time review-origin configuration.
  • Prepare Apple RevenueCat builds with fail-closed first-party OAuth metadata, typed provider error handling, and a validated App Store introductory-offer request draft.

1.8.5

Fixes and improvements

  • Make sign-out accessible across Second: add macOS menu and sidebar actions that work offline, move iOS sign-out beside account details and keep failed credential cleanup locked across restarts, expose extension sign-out without requiring a loaded identity, add Obsidian sign-out with in-flight sync fencing, and support the CLI's sign-out alias with environment-token guidance.

1.8.4

Fixes and improvements

  • Add scoped AI connection permissions, versioned knowledge retrieval, and shared save and organization workflows with durable recovery. Retain and export original files, materialize versioned file evidence with bounded MCP reads, and provide a separately consented native original-retention connection. Make introductory guidance optional and preserve account-bound connection and onboarding state across supported surfaces.

    Apply the authority, operation/file storage, evidence-erasure, original-file erasure, and immutable extraction migrations before deploying. Provision the private original-file bucket separately. Host setup packages describe supported connection paths; real-host qualification and listing publication remain separate release steps.

1.8.3

Fixes and improvements

  • Make Capture paste user initiated and cancel iOS dictation safely across lifecycle changes.
  • Fence iOS account projections, navigation, Spotlight, and widget cache data across session changes.
  • Use stable server account IDs and API origins for native sessions and caches, and reject stale credential refreshes and callbacks across account changes.
  • Fence iOS search, assistant, AI Profile, Daily Focus, archive, edit, and PARA-picker work to the captured account context.
  • Scrub user-derived payloads from native Sentry events while retaining crash classification and stack diagnostics.
  • Save complete iOS captures durably before delivery, reuse their IDs during retries, preserve account-owned and damaged records, and provide retry, adoption, export, and discard recovery.

1.8.2

Fixes and improvements

  • Add a read-only App Store Connect submission-readiness command for the unified iOS and macOS 1.7 drafts.
  • Reconcile release tooling with App Store preparation for iOS, macOS, and embedded Safari while publishing GitHub, Homebrew, and Sparkle artifacts independently.

1.8.1

Fixes and improvements

  • Upgrade dependencies and native error reporting to current compatible releases. Migrate OAuth provider resources and client redirects for Better Auth 1.7, preserve existing registrations, enforce token revocation/session checks, and update Notion sync for the current data-source API.

1.8.0

Highlights

  • Prepare unified Apple App Store distribution with Safari embedded in both native apps, a sandboxed Mac target using App Store updates, required-reason privacy manifests, and native account-deletion links. Make Safari's background compatible with iOS and clarify privacy disclosures for captures and diagnostics. Require explicit cloud and AI processing consent before connecting the native App Store apps and browser extension, and keep iOS dictation on-device.

1.7.0

Highlights

  • Add Search-backed chats and brief generation with exhaustive source counts, shared preferences, pinned revision evidence, and durable Background Work.

1.6.3

Fixes and improvements

  • Route error reporting through the personal Sentry organization and add crash reporting to the iOS app.

1.6.2

Fixes and improvements

  • Collapse Daily Focus into a compact Inbox summary with quick category adding and automatic conflict expansion.

1.6.1

Fixes and improvements

  • Bound web search requests and defer native derived search-index repairs until after the workspace is usable.

1.6.0

Highlights

  • Replace capped item retrieval with complete global search across Direct, AI, and exhaustive typo-tolerant Matches sections, including opaque pagination, caching, filters, and native search surfaces.

Fixes and improvements

  • Add restrained state, feedback, onboarding, and completion motion across web, iOS, and macOS, including reduced-motion behavior and iOS sensory feedback.

1.5.1

Fixes and improvements

  • Automatically build and verify the registered-device development IPA through Bitrise before release-local publishes release tags.
  • Flatten the Daily Focus categories into open sections with a simpler single-container layout across web, iOS, and macOS.

1.5.0

Highlights

  • Add shared Daily Focus checklists with Must Do and Should Do categories, offline sync, and deterministic five-item capacity resolution across web, iOS, and macOS.

Fixes and improvements

  • Add a registered-device Apple Development signing workflow for zero-cost iOS distribution.

1.4.1

Fixes and improvements

  • Bound large-library retrieval, hydration, pagination, and sync work across Second's clients while coalescing assistant streaming presentation updates.

    • Index web hybrid fallback retrieval, page the item library, batch sync-push authority reads, and delta-gate Notion ingestion.
    • Batch native workspace hydration, bound exact and semantic knowledge search, and incrementally project managed-agent streams.
    • Move Obsidian pulls to retry-safe delta cursors and coalesce assistant stream rendering on iOS and web.

1.4.0

Highlights

  • Add a versioned, user-controlled AI Profile with deterministic import and export, context receipts, and profile-aware assistant behavior across web, iOS, and macOS.

1.3.0

Highlights

  • Captures are indexed in Spotlight and open straight to the item from a search result or an assistant citation link. The assistant gains cross-device conversation history, iPad gets an adaptive split-view layout, and a Lock Screen quick-capture widget is added.

1.2.3

Fixes and improvements

  • Assistant answers no longer leak raw capture ids: the prompt now cites sources by title, and a server-side stream sanitizer strips any residual [[cite:…]] markers or UUIDs for every client. Reasoning effort lowered to low for faster time-to-first-token.

    iOS: capture detail and assistant chat now render Markdown with real structure (headings, paragraphs, lists, quotes, code) instead of one run-on block — AttributedString(markdown:) drops block newlines, so a block-aware MarkdownText renderer handles layout. Share-sheet, widget, and App Intent captures now appear in the inbox without pull-to-refresh: the outbox posts a Darwin notification, the running app drains and reloads, and foreground drains also refresh the inbox. "Capture Screen Text" intent rewritten with a fallback chain — piped image (OCR) → text → link → clipboard text → clipboard image (OCR) — so a bare Action Button press always captures something useful.

1.2.2

Fixes and improvements

  • Capture Screen Text now accepts text and URL inputs in addition to images (OCR), so one Shortcut can capture whatever is on screen or in hand. The Capture keyboard dismisses on tap-outside and via a Done button above the keyboard.

1.2.1

Fixes and improvements

  • Inbox sort menu gains a working "Oldest first" option (uses the new direction=asc feed parameter).

1.2.0

Highlights

  • Design overhaul and OS integration. Density + stability pass across Inbox/Library/Capture/Settings: inline titles, skeleton loading rows (no more layout jumps), compact rows with real favicons, permanent filter row with source/sort overflow menu, count moved to the toolbar, overlay toasts. Capture is now zero-friction: autofocus, auto-derived titles, collapsed Options, haptics. The agent launcher is a compact input-field-style glass capsule (no more full-width bar). Settings gains Appearance (theme), Capture prefs, and a working Rules section (pause/resume/delete via the new rules PATCH). Widget timelines now refresh after drains and inbox loads. App icon fixed for real (full multi-slot iconset — Xcode 27 beta dropped single-slot expansion). Adds App Shortcuts for the Action Button (Quick Capture, Capture Clipboard, Capture Screen Text via on-device OCR) and a share extension for capturing text/URLs/images from any app.

1.1.0

Highlights

  • Full mobile build-out. New Settings tab (account profile, sync status with manual drain, version info, sign-out); item detail screen rendering full Markdown content with Open Source/Copy/Share/Archive, edit sheet, filing history, retry-ingestion, and delete; a fully-fledged Capture screen (Auto/Note/Link kinds, title + note + PARA destination, URL metadata preview, clipboard paste, on-device voice dictation); an Inbox with server search, kind/archived filters, pagination, favicons + source badges, move/edit/delete context actions, and undo toasts; a Library tab for browsing PARA nodes with node detail item lists, create/complete/archive/edit node actions, and an Archive view with restore; a streaming AI Assistant screen (AG-UI SSE client, PARA scope picker, starter prompts) behind a permanent liquid-glass launcher on iOS 26; a large widget family with recent inbox items from a shared cache plus quick-note and clipboard-paste actions on all sizes; and the real Second app icon (regenerated at 1024px from the canonical mark).

1.0.1

Fixes and improvements

  • Fix the small quick-capture widget layout: headline, subtitle, and button all truncated ("Quick… / Tap to open S… / Cap…") because the medium layout was crammed into systemSmall. The small widget now uses a compact layout (icon, pending count, one-line Paste button); medium keeps the fuller layout.
Browser extension v1.5.1

1.5.1

1.5.0

Highlights

  • Add account-bound subscription contracts, provider reconciliation, usage accounting and billing controls across Second's clients. Payment activation and quota enforcement remain gated by the approved measured catalog and provider rollout checks; saved content and pending work remain recoverable when access changes.

Fixes and improvements

  • Clarify Chrome Web Store permissions and user-data disclosures for OAuth, selected-text capture, local queueing, and error diagnostics.

1.4.12

Fixes and improvements

  • Make sign-out accessible across Second: add macOS menu and sidebar actions that work offline, move iOS sign-out beside account details and keep failed credential cleanup locked across restarts, expose extension sign-out without requiring a loaded identity, add Obsidian sign-out with in-flight sync fencing, and support the CLI's sign-out alias with environment-token guidance.

1.4.11

1.4.10

Fixes and improvements

  • Preserve complete Chrome and Safari captures in an account-owned durable queue, reuse IDs on retry, and fence OAuth, recovery actions, popup projections, and destinations across account changes.

1.4.9

Fixes and improvements

  • Upgrade dependencies and native error reporting to current compatible releases. Migrate OAuth provider resources and client redirects for Better Auth 1.7, preserve existing registrations, enforce token revocation/session checks, and update Notion sync for the current data-source API.

1.4.8

Fixes and improvements

  • Prepare unified Apple App Store distribution with Safari embedded in both native apps, a sandboxed Mac target using App Store updates, required-reason privacy manifests, and native account-deletion links. Make Safari's background compatible with iOS and clarify privacy disclosures for captures and diagnostics. Require explicit cloud and AI processing consent before connecting the native App Store apps and browser extension, and keep iOS dictation on-device.

1.4.7

1.4.6

Fixes and improvements

  • Route error reporting through the personal Sentry organization and add crash reporting to the iOS app.

1.4.5

1.4.4

1.4.3

Fixes and improvements

  • Refresh application runtime and build dependencies, including the CLI parser, browser error reporting, authentication, TanStack, Cloudflare, and test tooling.

1.4.2

1.4.1

1.4.0

Highlights

  • Sentry error reporting across every surface: the web Worker reports fetch/cron/queue failures (errors only, production-gated, release-tagged second-brain@<version>), the CLI captures uncaught exceptions and unhandled rejections without slowing the happy path, the extension reports background/popup/oauth-callback errors with breadcrumbs disabled so page URLs and titles never attach, and the Obsidian plugin reports plugin errors with request/extra stripping so vault paths stay local. Everywhere: sendDefaultPii: false, no tracing, no user content in events.

1.3.0

Highlights

  • Saves now include page-extracted Markdown from the browser session, so bot-walled and login-gated pages arrive with real content; server-parsed hosts (X, YouTube, Reddit, GitHub, HN) keep the server pipeline.

1.2.4

1.2.3

1.2.2

Fixes and improvements

  • Use the supplied Second product artwork across web, extension, and desktop branding and packaging surfaces.
  • Make second the CLI and Homebrew distribution name, and update the public tap through the sanctioned release flow.

1.2.1

1.2.0

Highlights

  • The "Sign in with Second" flow now runs on the shared @second/oauth package instead of a locally duplicated OAuth module. Behavior is unchanged (same extension-page redirect + background message hand-off), except the requested scopes now include second:read second:write alongside the existing openid profile email offline_access — so a fresh sign-in also authorizes MCP tool calls. Existing sessions keep working as-is; the new scopes only apply the next time you sign in, and the consent screen will show them then.

1.1.1

Fixes and improvements

  • Captures now store the content instead of the page. Per-host parsers (x/twitter, youtube, reddit, hacker news, github threads) build Markdown from the page's own metadata, and everything else goes through an HTMLRewriter pass that strips nav, footers, cookie walls and login prompts before conversion — applied on both the Browser Rendering and AI-conversion paths. Images are kept as images end to end rather than being rewritten to links at storage time.

    Clicking a capture now opens /app/items/$itemId with the ingested content, not the source site, and a signed-in visitor landing on / is sent to the Inbox. Ingestion no longer marks a capture failed when only search indexing fails, so materialized Markdown stays readable. Fixes horizontal page scroll caused by the sidebar inset refusing to shrink, inbox rows overflowing instead of truncating, and inbox lists loading every revision's full Markdown to render a 280-character excerpt. The extension popup lists its keyboard shortcuts, read from the browser so they reflect user remaps.

1.1.0

Highlights

  • Move every surface to the custom domain 2nd.thedevdavid.com and send email from 2nd@thedevdavid.com. The Worker now serves only the custom domain — workers_dev is off, so there is a single origin for auth cookies and the OAuth issuer. Adds Smart Placement (the app makes several sequential D1 queries per request), Workers Logs with tracing and source-map upload, and shows the running version in every app: Settings → About on the web, the extension popup's settings panel, the desktop settings window, the Obsidian settings tab, and brain status.

1.0.1

1.0.0

Major updates

  • Plan 007 replaces URL-only item creation with a strict URL/Markdown capture contract. Captures are stored as canonical Markdown, ingested durably, and retrieved through private per-user AI Search. REST, MCP, CLI, desktop, extension, Obsidian, and web writers now use the new capture/content APIs; legacy create commands and tools are removed.

0.3.3

0.3.2

Fixes and improvements

  • Extract popup panels into components (no behavior change)

0.3.1

0.3.0

Highlights

  • Right-click a text selection to save the page with the selection as the note
  • Save now tells you how to act on the AI suggestion: a ready brain-move command in the CLI, a File-to button in the extension popup

0.2.2

Fixes and improvements

  • Keep the previous refresh token when a refresh response omits refresh_token — silent-refresh no longer degrades into a forced re-sign-in if the server stops rotating tokens.
  • Only discard the stored OAuth client registration when the token endpoint rejects the client (invalid_client) — transient exchange errors no longer force re-registration and pile up dead rows in oauth_client.

0.2.1

Fixes and improvements

  • Remove the deprecated paraNodeId field from CategorizeResponse (suggestedNodeId is the single canonical field now), resolving the last deferred cleanup-audit items.

    • Web: new public /privacy page (linked from the landing and pricing footers) — required by both extension stores.
    • Extension: fix the settings panel's quick-save hotkey label (⌘⇧2, matching the save-close-tab manifest command); wxt.config.ts imports DEFAULT_API_URL from @second/api-client instead of a hardcoded literal; store listing copy + submission checklists in store/ (Chrome Web Store + Apple App Store).

0.2.0

Highlights

  • First coordinated release of the Second brain companion — complete PARA system, OAuth-secured surfaces, and shared packages.

    PARA canon (web + all surfaces)

    • Archive is a state, not a category: archived_at on nodes and items, with Projects/Areas/Resources as the only node types. Item transitions (move/archive/restore/complete) are recorded in item_transitions.
    • Capture→organize separation: nothing auto-files at capture; everything lands in the Inbox. Rules + Workers AI suggest destinations at triage time with reasoning ("has a goal and a deadline → Project") and confidence-aware policy.
    • Keyboard-first triage: X archives (never silent-deletes), ⇧X deletes with undo window, ⌘Z undo, auto-advance, AI suggestion bar with one-key accept, just-in-time node creation, rule-learning offers (R).
    • PARA surfaces: node form with goal/deadline/standard prompts and false-project nudges, complete-project salvage flow, 10–15 active-project gauge, /app dashboard home, /app/review weekly sweep, archive restore/reactivation, command palette with item search (archived ranked last), assistant bundle scoping.

    Surfaces

    • CLI (brain): nodes list/create with goal/deadline/standard, move, retitle, archive/unarchive, inbox --archived, server-side search with pagination, review weekly summary. rm warns it's permanent.
    • Extension: standards-based OAuth 2.1 + PKCE sign-in (dynamic public-client registration, consent page, refresh-token rotation) — no pasted URLs or tokens; API URL is build-time env. Hotkey workflow: ⌘⇧S silent save, ⌘⇧1 detailed save via popup, ⌘⇧2 save+close tab, ⌘⇧3 save+close window, with system notifications for every outcome. Safari (MV2) target with generated Xcode project.

    Shared packages

    • @second/types: zod contracts for items, PARA nodes, API responses.
    • @second/utils: PARA constants (actionability order, labels), formatAge, deadline helpers, computeReviewSummary.
    • @second/api-client: typed v1 API client (items, nodes, transitions, inbox count, me, categorize) used by CLI, extension, and desktop. The v1 API accepts both OAuth access tokens and sb_ API tokens.
CLI v1.6.1

1.6.1

1.6.0

Highlights

  • Add account-bound subscription contracts, provider reconciliation, usage accounting and billing controls across Second's clients. Payment activation and quota enforcement remain gated by the approved measured catalog and provider rollout checks; saved content and pending work remain recoverable when access changes.

1.5.6

Fixes and improvements

  • Make sign-out accessible across Second: add macOS menu and sidebar actions that work offline, move iOS sign-out beside account details and keep failed credential cleanup locked across restarts, expose extension sign-out without requiring a loaded identity, add Obsidian sign-out with in-flight sync fencing, and support the CLI's sign-out alias with environment-token guidance.

1.5.5

1.5.4

1.5.3

Fixes and improvements

  • Upgrade dependencies and native error reporting to current compatible releases. Migrate OAuth provider resources and client redirects for Better Auth 1.7, preserve existing registrations, enforce token revocation/session checks, and update Notion sync for the current data-source API.

1.5.2

Fixes and improvements

  • Refresh CLI and Obsidian distribution packages for the reconciled Second release.

1.5.1

1.5.0

Highlights

  • Replace capped item retrieval with complete global search across Direct, AI, and exhaustive typo-tolerant Matches sections, including opaque pagination, caching, filters, and native search surfaces.

1.4.3

1.4.2

Fixes and improvements

  • Refresh application runtime and build dependencies, including the CLI parser, browser error reporting, authentication, TanStack, Cloudflare, and test tooling.

1.4.1

1.4.0

Highlights

  • second inbox gains --oldest (oldest-first ordering), --kind links|notes, and --source <source> filters, and the archive view honors them too — matching the sort/filter controls on the other clients.

1.3.0

Highlights

  • Sentry error reporting across every surface: the web Worker reports fetch/cron/queue failures (errors only, production-gated, release-tagged second-brain@<version>), the CLI captures uncaught exceptions and unhandled rejections without slowing the happy path, the extension reports background/popup/oauth-callback errors with breadcrumbs disabled so page URLs and titles never attach, and the Obsidian plugin reports plugin errors with request/extra stripping so vault paths stay local. Everywhere: sendDefaultPii: false, no tracing, no user content in events.

1.2.2

1.2.1

1.2.0

Highlights

  • Add a PARA-teaching onboarding flow across surfaces

    • Web: new-user wizard at /onboarding (welcome, first capture, project, area, resource, surfaces) driven by a ?step= search param. Each PARA step creates the node for real and has a disclosure explaining the concept. The capture step accepts a link or a note. Completion is required: /app redirects to the wizard until user.onboarding_completed_at is set, and finishing lands in the Inbox.
    • packages/utils: new para-guide module with the canonical PARA concept definitions and onboarding steps, shared verbatim by the web wizard, CLI, and MCP.
    • CLI: second onboarding walks the same flow interactively (capture, project with goal/deadline, area with standard, resource); --guide or a non-TTY prints the guide instead.
    • MCP: new read-only get_onboarding_guide tool returning the steps and concept definitions (second:read scope).
    • Agent skills: second-onboarding in skills/ (MCP or CLI transport) and plugins/second/skills/ (MCP-only).
    • Item page and content dialog now split ingestion states: while a capture is still processing the page polls and shows a working state with no retry button; only a failed revision shows the error with retry.
    • Migration 0011 backfills onboarding_completed_at for existing users so only new signups see the wizard; account reset clears it so a wiped account re-onboards. Apply the prod D1 migration before merging this.

1.1.3

1.1.2

Fixes and improvements

  • Make second the CLI and Homebrew distribution name, and update the public tap through the sanctioned release flow.

1.1.1

1.1.0

Highlights

  • brain login now runs on the shared @second/oauth package instead of a locally duplicated OAuth module. Behavior is unchanged (same loopback port, BRAIN_NO_BROWSER, and 3-minute timeout), except the requested scopes now include second:read second:write alongside the existing openid profile email offline_access — so a fresh brain login also authorizes MCP tool calls. Existing sessions keep working as-is; the new scopes only apply the next time you sign in, and the consent screen will show them then.

1.0.2

Fixes and improvements

  • Move every surface to the custom domain 2nd.thedevdavid.com and send email from 2nd@thedevdavid.com. The Worker now serves only the custom domain — workers_dev is off, so there is a single origin for auth cookies and the OAuth issuer. Adds Smart Placement (the app makes several sequential D1 queries per request), Workers Logs with tracing and source-map upload, and shows the running version in every app: Settings → About on the web, the extension popup's settings panel, the desktop settings window, the Obsidian settings tab, and brain status.

1.0.1

1.0.0

Major updates

  • Plan 007 replaces URL-only item creation with a strict URL/Markdown capture contract. Captures are stored as canonical Markdown, ingested durably, and retrieved through private per-user AI Search. REST, MCP, CLI, desktop, extension, Obsidian, and web writers now use the new capture/content APIs; legacy create commands and tools are removed.

0.4.2

0.4.1

Fixes and improvements

  • Split CLI commands into per-domain modules (no behavior change)

0.4.0

Highlights

  • brain import obsidian <vault> and brain import apple-notes: one-shot, idempotent imports into the Inbox with deep links back to the source

0.3.0

Highlights

  • Rules manageable over v1 (GET/POST/DELETE /api/v1/rules) and brain rules list/add/rm
  • Bulk archive/unarchive over POST /api/v1/items/bulk; brain archive/unarchive accept multiple ids
  • Export everything: brain export --format json|csv and a Settings → Export download
  • brain login opens a browser OAuth 2.1 + PKCE flow (loopback redirect on 127.0.0.1:8976); --token remains for headless use.
  • brain save reads URLs from stdin (one per line) when the positional is omitted; inbox, search, nodes, and review gain --json for pipelines.
  • Save now tells you how to act on the AI suggestion: a ready brain-move command in the CLI, a File-to button in the extension popup

Fixes and improvements

  • Derive brain --version from package.json instead of a hard-coded string

0.2.1

0.2.0

Highlights

  • First coordinated release of the Second brain companion — complete PARA system, OAuth-secured surfaces, and shared packages.

    PARA canon (web + all surfaces)

    • Archive is a state, not a category: archived_at on nodes and items, with Projects/Areas/Resources as the only node types. Item transitions (move/archive/restore/complete) are recorded in item_transitions.
    • Capture→organize separation: nothing auto-files at capture; everything lands in the Inbox. Rules + Workers AI suggest destinations at triage time with reasoning ("has a goal and a deadline → Project") and confidence-aware policy.
    • Keyboard-first triage: X archives (never silent-deletes), ⇧X deletes with undo window, ⌘Z undo, auto-advance, AI suggestion bar with one-key accept, just-in-time node creation, rule-learning offers (R).
    • PARA surfaces: node form with goal/deadline/standard prompts and false-project nudges, complete-project salvage flow, 10–15 active-project gauge, /app dashboard home, /app/review weekly sweep, archive restore/reactivation, command palette with item search (archived ranked last), assistant bundle scoping.

    Surfaces

    • CLI (brain): nodes list/create with goal/deadline/standard, move, retitle, archive/unarchive, inbox --archived, server-side search with pagination, review weekly summary. rm warns it's permanent.
    • Extension: standards-based OAuth 2.1 + PKCE sign-in (dynamic public-client registration, consent page, refresh-token rotation) — no pasted URLs or tokens; API URL is build-time env. Hotkey workflow: ⌘⇧S silent save, ⌘⇧1 detailed save via popup, ⌘⇧2 save+close tab, ⌘⇧3 save+close window, with system notifications for every outcome. Safari (MV2) target with generated Xcode project.

    Shared packages

    • @second/types: zod contracts for items, PARA nodes, API responses.
    • @second/utils: PARA constants (actionability order, labels), formatAge, deadline helpers, computeReviewSummary.
    • @second/api-client: typed v1 API client (items, nodes, transitions, inbox count, me, categorize) used by CLI, extension, and desktop. The v1 API accepts both OAuth access tokens and sb_ API tokens.
Obsidian plugin v1.3.1

1.3.1

1.3.0

Highlights

  • Add account-bound subscription contracts, provider reconciliation, usage accounting and billing controls across Second's clients. Payment activation and quota enforcement remain gated by the approved measured catalog and provider rollout checks; saved content and pending work remain recoverable when access changes.

1.2.5

Fixes and improvements

  • Make sign-out accessible across Second: add macOS menu and sidebar actions that work offline, move iOS sign-out beside account details and keep failed credential cleanup locked across restarts, expose extension sign-out without requiring a loaded identity, add Obsidian sign-out with in-flight sync fencing, and support the CLI's sign-out alias with environment-token guidance.

1.2.4

Fixes and improvements

  • Upgrade dependencies and native error reporting to current compatible releases. Migrate OAuth provider resources and client redirects for Better Auth 1.7, preserve existing registrations, enforce token revocation/session checks, and update Notion sync for the current data-source API.

1.2.3

Fixes and improvements

  • Refresh CLI and Obsidian distribution packages for the reconciled Second release.

1.2.2

Fixes and improvements

  • Refresh application runtime and build dependencies, including the CLI parser, browser error reporting, authentication, TanStack, Cloudflare, and test tooling.

1.2.1

Fixes and improvements

  • Bound large-library retrieval, hydration, pagination, and sync work across Second's clients while coalescing assistant streaming presentation updates.

    • Index web hybrid fallback retrieval, page the item library, batch sync-push authority reads, and delta-gate Notion ingestion.
    • Batch native workspace hydration, bound exact and semantic knowledge search, and incrementally project managed-agent streams.
    • Move Obsidian pulls to retry-safe delta cursors and coalesce assistant stream rendering on iOS and web.

1.2.0

Highlights

  • Sentry error reporting across every surface: the web Worker reports fetch/cron/queue failures (errors only, production-gated, release-tagged second-brain@<version>), the CLI captures uncaught exceptions and unhandled rejections without slowing the happy path, the extension reports background/popup/oauth-callback errors with breadcrumbs disabled so page URLs and titles never attach, and the Obsidian plugin reports plugin errors with request/extra stripping so vault paths stay local. Everywhere: sendDefaultPii: false, no tracing, no user content in events.

1.1.2

Fixes and improvements

  • Make second the CLI and Homebrew distribution name, and update the public tap through the sanctioned release flow.

1.1.1

Fixes and improvements

  • Sync manifest.json and versions.json from package.json at build time and attach main.js/manifest.json/versions.json to every GitHub Release, so BRAT installs and updates actually work. The manifest had been pinned at 0.0.0 because Changesets only bumps package.json, and no release ever carried the plugin's build output.

1.1.0

Highlights

  • Move every surface to the custom domain 2nd.thedevdavid.com and send email from 2nd@thedevdavid.com. The Worker now serves only the custom domain — workers_dev is off, so there is a single origin for auth cookies and the OAuth issuer. Adds Smart Placement (the app makes several sequential D1 queries per request), Workers Logs with tracing and source-map upload, and shows the running version in every app: Settings → About on the web, the extension popup's settings panel, the desktop settings window, the Obsidian settings tab, and brain status.

1.0.1

Fixes and improvements

  • Restore the one-shot Notion import card, which plan 001 dropped when it rebuilt the integrations page; enforce reserved usernames so role and RFC 2142 names cannot be claimed; compute the triage rule offer server-side so a host already covered by a rule no longer offers a duplicate; and remove dead exports, the unreachable legacy categorize input shape, and the web-only PARA node delete that duplicated DELETE /api/v1/para/$id.

1.0.0

Major updates

  • Plan 007 replaces URL-only item creation with a strict URL/Markdown capture contract. Captures are stored as canonical Markdown, ingested durably, and retrieved through private per-user AI Search. REST, MCP, CLI, desktop, extension, Obsidian, and web writers now use the new capture/content APIs; legacy create commands and tools are removed.

0.1.0

Highlights

  • Obsidian community plugin: save-note command plus continuous, idempotent two-way vault sync