Please read
A new API key could go to the previous provider. If you use the OpenAI-compatible engine and moved it to a different provider, then turned any engine on or off (or set an engine's CLI path), Murage kept the old address and sent your new key there. That is fixed, and a settings file that already carries the old address is repaired when it loads. Connections with their own key are untouched.
Windows: scheduled backups can be set up again. On 0.1.55, choosing a destination and recovery key for a scheduled backup always failed on Windows. If setup failed for you, choose them again. Existing schedules were not affected.
Bots and teams
Every bot is itself, everywhere. Each bot now brings its own notebook (MEMORY.md) and its team's shared instructions to every conversation: direct chats, handed-over work, routines and channels. The team instructions you could already edit are now actually delivered; before, no bot received them. In a channel, each bot now also keeps its own memory and its team's, alongside the channel's, instead of only the channel's. A bot changes its notebook only when you ask it to remember, forget or correct something, and routines read it without changing it.
New Team, right in the + menu. The + menu now names what each item makes: New Bot, New Bot from Template, New Team and New Channel, with Export bots and Archived bots below. New Team asks for a name, the bots, and optionally a lead and team instructions, all in one step. Before, making a team meant finding "Move to section" on each bot. Teams are now called teams everywhere, so a bot's menu reads "Move to team…".
Talk to Moss, get Moss. In a channel, "Moss, can you…" now goes to Moss, not the channel lead, with or without the @. Bots are told never to answer as another bot, and a Chief of Staff no longer picks up messages addressed to someone else.
The right face on every message. In a channel, a reply from a bot that isn't a member, such as a teammate answering work handed to it, showed the default flame mascot instead of that bot's own avatar. It now shows the real avatar and name.
A new channel task starts unlocked. After New task in a channel, the folder card kept saying the folder was fixed for the task until you reloaded. It now shows the new task's real state straight away.
Private notes stay private. In a channel or conversation that includes people from Slack, Discord or Telegram, your bots' private notes and team instructions are left out, and only what you have explicitly shared is used.
Backups
Backups have their own section. Backups moved out of General into a Backups section in Settings. At the top, "Your backups" says when the last backup ran, how big it was, when the next one is due, whether an off-site copy is on, and anything that needs a look. Setup is three numbered steps: where to save, your recovery key, and when. The time zone is a list set to your computer's zone, and the limits start filled in (12 hours to catch up, 50 GB, 30 minutes), so setup needs no guesswork. Off-site copy, Restore and Advanced are folded away until you need them. Every check and confirmation from before is still there.
One checkbox to back up while Murage is closed. "Also back up when Murage is closed" sets up the background job for you; before, it took two separate buttons.
Create my recovery key. Backups need a recovery key, and until now making one meant using a terminal. Murage now creates it for you and saves it wherever you choose. It will not save it inside Murage's own folder or inside your backup folder, and it never overwrites an existing file. Keep a copy somewhere safe, such as a password manager or a USB drive: without it nobody, including you, can open your backups.
Back up now. Take a backup straight away instead of waiting for the daily time. Murage closes and reopens its window to take it, as a scheduled backup does. If a daily backup is already waiting, that one runs instead of a second.
Linux: backups on Ubuntu 24.04. Taking a backup, whether Back up now, the daily one or the one before an update, restarts Murage, and on Ubuntu 24.04 that restart could crash, so Murage simply disappeared. The installer now sets up the permission Ubuntu requires, and Murage checks first and tells you if a restart can't work, instead of closing. "Also back up when Murage is closed" was always unavailable on Ubuntu because of how Murage's own data folder was created; the folder is now private to you, and if it is still the reason the message says so. A backup while Murage is closed needs you to be signed in to your desktop; if it can't run, the Backups card says why instead of staying silent.
A failed backup leaves no unencrypted copy behind. A backup prepares its copy inside your backup folder. On Windows, a backup that failed left that working folder behind, with an unencrypted copy of your bots and messages, in a folder you might sync or share. A failed backup now removes it on every system.
Windows: backups finish. On Windows a backup was written to your folder but then recorded as failed, because Murage compared the folder's name with different capital letters. Backups now finish and Murage reopens to your workspace. Backups can't run while Murage runs as administrator; Murage now says so before closing anything.
A backup that didn't finish no longer locks Backups. If a backup stopped before Murage could confirm it, every backup control stayed disabled, even after a restart. Your backups now says so and offers Clear and try again. Closing Murage while it was still indexing skills, for example right after installing, also made every later backup fail; that no longer happens.
Backups, smaller things. If backing up while Murage is closed isn't possible on your system, the reason now shows right under the checkbox. Saving a recovery key suggests a file name that doesn't exist yet and remembers the folder you used. The wording throughout Backups is plainer.
Approvals
Full access. A third level above Auto. In conversations you start, a bot on Full access asks for nothing: not Auto's stops for destructive or sensitive actions, not the screen-control guard, and not the card before it contacts another bot. What still asks: turns started by a webhook or a routine (judged exactly as Auto judges them), image generation before it spends, questions the bot puts to you, and the one-time "use this computer" confirm. Full access can be switched on only from the desktop app, and the first time for each bot it shows a warning you confirm. Full access can also be a bot's default: Bot Settings now offers Ask, Auto or Full access, new conversations start there, and you can still change a single conversation from the message box. Two options, both off unless you turn them on: let Full access also cover your own messages from Telegram, Slack and Discord (messages from anyone else, webhooks and routines still ask), and let it approve setup requests: installing skills, proposing routines and trusting folders. Connecting an app always asks, because you sign in to it in your own browser.
Clearer approval screens. Full access shows as unavailable outside the desktop app, and a refused change snaps back with a plain reason instead of looking as if it worked. The "Ask me before contacting other bots" switch now says truthfully what it does, including that Full access skips it. The "use this computer" card reads "@Moss wants to use this computer", then Allowed or Not allowed.
Auto asks once before it first uses your screen. On a Mac, a bot left on the Auto computer setting used to be handed your screen, mouse and keyboard without being asked. The first time such a bot acts on the screen, you now answer a one-time card for that bot. Allow is remembered. Don't allow is remembered too: the action is refused and Auto stops offering this computer to that bot. Bots you set to This computer are never asked, and bots that were already using your screen with your say-so keep working. Ask again resets it from the Computer panel.
Stop
Stop withdraws a desktop action already under way. Before, Stop prevented the next action but waited for the current one to finish, up to 60 seconds. Stop, taking the screen back, switching the computer Off and the emergency stop now cancel it at once. A click or keystroke already sent to the system cannot be recalled, so the chat now tells you it may have finished anyway and to check the screen before retrying.
The emergency stop reaches every task on this computer. A bot can run up to three tasks at once, chats and routines together, and the emergency stop used to reach only one per bot. It now stops each of them and says which did not confirm. On Linux, the local control panel shows a line when a task did not confirm it stopped.
The browser works after a Stop. Stopping a bot in the middle of a browser task could leave its next turn's browser refused. Fixed.
When Murage stops a turn itself, the chat no longer also says "Stopped by you".
Browser
Use my Chrome. One bot at a time can use your own running Google Chrome, signed in as you, instead of its separate browser. It is off for every bot. Turn it on per bot from the Browser panel's profile menu, after turning on remote debugging at chrome://inspect/#remote-debugging (Chrome 144 or newer). The bot works in a tab of its own and can see your open tabs. Its session is never saved, switching back closes it, and Chrome itself is never closed.
A browser that cannot start no longer fails the turn. When the browser could not start, often because the computer was busy, the whole request failed with a card pointing at Provider settings. The turn now runs without the browser, the bot is told it has none, and the chat shows one quiet "browser unavailable" note. The browser check is quicker after the first time, and the note is in plain words with the technical reason tucked under Details. When Use my Chrome can't reach your Chrome, the chat says so and how to turn remote debugging on. A failure of this computer's browser, screen or working folder gets its own card with Retry and no advice about providers.
A protected page no longer takes a bot's browser away. When you type in a bot's browser, or a page has a password field, card field or embedded frame, Murage stops the bot from reading that page, which is deliberate. Before, the bot then lost every browser tool without being told why, and some bots went looking for other browsers on your computer. Now the bot keeps its browser, says exactly why it can't use that page, and can move on to another page by itself. If you typed in it, the Browser panel says so in plain words: take control and reopen a blank page to give the bot its browser back. Browsers that were already locked before this update need that once.
Chat
Live thinking. While a bot thinks, a collapsed "Thinking" row shows its reasoning as it arrives, so a long think no longer looks like a hang. It folds again when the answer starts. It is never saved or exported.
The agent's plan. Engines that publish a step-by-step plan (ACP engines) now show it as a checklist that updates as the turn runs.
The turn timer keeps counting. Switching conversations mid-turn and back restarted the elapsed time at 0s. It now counts from when the turn really began, and rooms show the speaker's elapsed time.
Windows file links open. A link a bot writes to a file on Windows, such as C:\Users\me\report.md, rendered as a dead link. It opens now.
Short file links open. A link a bot writes relative to the conversation, such as reports/today.md, now opens the file, including one it saved in its outputs folder.
A cut-off answer is called cut off. An answer that stopped in the middle of its last piece was reported as "Part of this answer arrived damaged". It now says it stopped before it finished.
Bot settings on a phone now fits above the on-screen keyboard.
Task list
Tasks grouped by date. A bot's task list now groups tasks under Today, Yesterday, Previous 7 days, and then by month, and older tasks show their date instead of a time that looked like today's.
Most recent activity first. Tasks are ordered by when something last happened in them; you can switch to the order they were created, and Murage remembers your choice.
Filters and tidier rows. Filter by Chats, Routines, From other bots or Unread. Repeated runs of a routine fold into one row you can open. Work handed over by another bot reads "From Kessler: …". Empty untitled tasks no longer clutter the list, and token counts say "tokens".
The sidebar says when, too. A conversation's last-message time now reads like a messaging app: the time today, Yesterday, the weekday this week, then a date, with the full date and time on hover.
First run and everyday polish
A new install opens on the welcome screen. New users were dropped straight into the starter bot's questions; they now see "What would you like to do?" first.
Links to files a bot wrote open that file. A link like "reports/weekly.md" opened a blank browser tab; it now opens the file from the conversation's folder. Windows paths written in replies keep every backslash.
The model picker, in order. Flux Router's tiers come first, every row is labeled correctly, the empty "no local server" note sits at the bottom, and on a phone the list fills the screen instead of showing three rows.
One thinking timer. While a bot thinks you see one "Thinking" timer; once it starts answering, the status says "Answering".
The Flux Router offer no longer covers the message box.
Smaller things: friendlier folder names in the chat header, each bot's real role in the calendar, labeled routine times ("Last run … · Next …"), menus and dialogs that work better with screen readers, and more room in Bot settings on small phones.
Routines
Routines no longer wait for an idle bot. A routine that came due waited until every conversation on its bot was idle, so a busy bot quietly postponed its routines. A routine now runs in one of the bot's three task slots; when all three are busy it shows "Waiting for a free slot" and starts as soon as one frees.
Routines finish on their own. A routine run now puts its answer in its reply, and creates or changes files only when the routine's instructions ask for that. Before, a bot in Ask mode that decided to save a note waited for an approval nobody was there to give.
Models and engines
Current vLLM thinking. vLLM 0.16 and newer send reasoning under a new name, which Murage did not read, so their thinking was dropped and a think longer than three minutes failed the turn. Both names are read now, and thinking counts as activity.
Token usage on OpenAI-compatible and Grok servers. Streamed turns on servers that only report usage when asked now ask, so usage and cost are counted.
Rooms and images. A room member is now told whether an attached picture is in front of it, reached it only as a file to open, or cannot be seen, the same as in a direct conversation.
Connected apps
The original connected-apps service says when it has ended. When the legacy Composio service reaches its daily cap or retires, the bot gets one plain sentence instead of a raw error, the panel says the service has ended, and Flux Router takes over for anyone with a Flux Router key.
Also
Your version is shown. Settings → General → Updates now starts with the version you're running, and Settings search finds "version" and "recovery key".
Linux: murage works in a terminal, and install links register. The .deb now adds the murage command and refreshes the desktop's file-type records, so murage://install links open Murage.
Linux: installs on minimal systems. The .deb now declares the sound and graphics libraries Murage needs, so it installs and starts on minimal Ubuntu 22.04, 24.04 and Debian 12, not only on full desktop installs.
Known issues:
The bundled computer driver ignores a cancel, so a click or keystroke already sent may still land after Stop. Check the screen before retrying.
Use my Chrome has been tested against Chrome's documented remote-debugging switch but not yet against every Chrome release; a Chrome 150 report on macOS may affect it.
Flux Router pinned models may show "Price unavailable" until Flux exposes their pricing.
The legacy Composio connection is capped at 2,000 calls a day and retires on 2026-11-10; connected apps through Flux Router are the supported path.
Intel Macs still have no local semantic memory.
Bundled Fuigo on Linux needs glibc 2.39 or newer.
The phone apps still show the flame mascot for every bot.