Klass Personal OS

Release notes

Version 1.2.0

Connect other MCP servers, use built-in tools through REST, work with PDFs, inspect websites, and put outbound email behind a human approval step. The free tier now includes three automations and two API keys.

Connect other MCP servers

  • Add a third-party MCP server in the app and discover its tools. You choose which tools each API key may call; the owner key does not receive them automatically. Free includes up to three connected servers.
  • Connect to remote HTTPS servers, local HTTP servers, or local commands over stdio. Cleartext HTTP on a private network requires a separate opt-in for that server and cannot use header or OAuth credentials. Local commands run with your macOS permissions.

Use the REST API

  • Built-in tools now have REST routes that use the same API keys, grants, tool switches, and license checks as MCP calls. The app includes an API Reference and can export an OpenAPI specification.
  • The server still listens on your Mac only by default. Pro can explicitly allow direct connections from a private network or specified IP ranges.

Files, PDFs, and site checks

  • Search file contents inside granted roots using text or regular-expression matches.
  • Render, merge, split, stamp, or rasterize PDFs, and list their form fields. Form filling is not included.
  • Scan a website for common exposure and configuration indicators, save the result, and compare later scans. Scheduled endpoint monitors keep history for repeated DNS, domain, certificate, and endpoint checks. Monitor definitions do not yet have a dedicated editor.

Review outbound mail before it sends

  • An outbound mail account can hold each send for your approval. Review it from a notification or the Approvals screen. Denial or timeout sends nothing; the decision is recorded. This currently applies to outbound email only.

Automations and account setup

  • Free now includes three enabled automations and two API keys. Automations can start from a schedule, incoming email or messages, feed updates, or watched folder changes. A file gate can hold a run until required files are present.
  • Consumer Outlook.com accounts can connect for IMAP receive through Microsoft OAuth. Microsoft 365 work and school mail is not supported.

Version 1.1.0

Codex CLI support, remote commands against Windows machines, on-device text and barcode reading, domain and certificate monitoring, structured extraction from email, and a batch of scheduler fixes - including one that could silently stop an automation forever.

Ask Codex, from an automation or from an agent

  • A new Ask Codex automation action runs a prompt through the Codex CLI you already have installed, alongside the existing Ask Claude action. Pick the model, the reasoning effort, whether the run is read-only or allowed to write, and whether it starts a new conversation or resumes the previous one.
  • Codex_runPrompt exposes the same thing to an agent. It is off by default and requires both a paid license and an API key explicitly authorized for it.
  • The app launches your own Codex CLI and never copies or stores your Codex credentials. Finding the CLI is not the same as being signed in to it, so the settings screen checks both and tells you which one is missing.
  • In write mode, the folders Codex may write to are set once in settings - not per job, and not by whatever folder a caller asks to run in. A working directory outside those folders is refused rather than quietly allowed.

Remote commands now work against Windows machines

  • Remote_exec and Remote_execScript can now target Windows hosts over SSH. Set the new Remote shell dialect field on the SFTP account to "Windows PowerShell"; it stays "POSIX" for Mac and Linux hosts, which are unaffected.
  • On a Windows account, Remote_exec's command should be an absolute path - Windows resolves a relative program name against the launching process's directory, not the working directory you asked for. A bare name on PATH like git still works.
  • Remote_exec's stdin parameter isn't supported on a Windows account and is rejected with a clear error rather than silently dropped; PowerShell needs that channel to receive the command itself.
  • Two Windows bugs found and fixed before this release: a script containing any multi-line construct silently stopped running after the first one while still reporting success, and $args[0]/$args[1] never received the values you passed. Both work correctly now. One behavior change worth knowing: an uncaught error anywhere in a Windows script now stops the rest of the script and exits with status 1.

Read text and scan barcodes off any image - entirely on-device

  • Vision_recognizeText reads the text out of a photo or image - a business card, a whiteboard, a scanned form - as lines with confidence and position, in reading order.
  • Vision_detectBarcodes finds and decodes QR codes and other barcodes in an image or a single PDF page.
  • Both run through Apple's on-device Vision framework: no API key, no per-call cost, and no image data ever leaves your Mac. They work on any file in a folder you have already granted. Free, no cap.

Watch your domains, certificates, DNS, and endpoints

  • Domain_expiry reports a domain's registrar, nameservers, status codes, DNSSEC signing, and expiry date straight from the registry. Free.
  • Dns_lookup queries DNS for A, AAAA, CNAME, MX, NS, TXT, SOA, and CAA records. Free.
  • Tls_certInfo reports the TLS certificate a host presents - validity, issuer, fingerprint, whether it is trusted - without sending or receiving page content. Pro.
  • Endpoint_probe checks whether HTTP(S) endpoints answer, with status, timing, and the redirect chain, again without returning page content. Pro.
  • A timeout, a refused connection, or a domain that no longer resolves is a normal successful result on all four, not an error - that is the point of a monitoring tool. Each result carries a plain severity field to alert on, and a stable fingerprint so a scheduled automation can ask "did anything change since last time" with no extra setup.

Confirm a bill's amount instead of retyping it

  • Mail_extractStructured reads up to 25 messages at once and returns the currency amounts, dates, tracking numbers, account numbers, and reference numbers it finds - each paired with the exact spot in the message it came from, so a model can confirm the value against the source instead of transcribing it.
  • A bill with "Total Amount Due," "Minimum Payment Due," and "Previous Balance" comes back as three separate values, never one guessed total. It reads the subject, the plain-text body, and the HTML body independently, since some senders only put the amount in the HTML part.
  • A genuinely ambiguous value - 1,234 with nothing else in the message to say which number format it is - comes back as two possible readings rather than a silent guess. Free, no cap.

Scheduling across CalDAV, and recurring rules

  • Calendar_findFreeSlots now works against CalDAV calendars, not just the Mac's own Calendar app. Nothing about how you call it changed.
  • System_expandRecurrence expands a recurring-event rule into concrete occurrences, each with its correct weekday and local date already worked out. Free, no grant required.
  • Both share one recurrence engine, so free/busy and rule expansion always agree. A rule the app cannot safely interpret comes back as a named error rather than a silently wrong answer.

Undo now covers email, calendar, contacts, cloud storage, and more

  • Email: reverting EmailStore_markRead, flagMessage, moveMessage, deleteMessage, and saveDraft. A revert re-checks the account's write policy and read-only folders exactly as a fresh edit would. A permanent delete stays permanent and is never offered as revertible.
  • Calendar and contacts: reverting event and contact uploads and deletes, and contact-group membership changes, each checked against what the server currently reports. Restoring a deleted item recreates it as a new item and says so plainly. Reminders changes still cannot be undone - Reminders keeps no record of the prior state - but now appear in Undo History marked that way instead of not appearing at all.
  • Cloud storage: reverting Storage_upload, Storage_delete, and Storage_deleteMany, opt-in per storage account since capturing an object's prior bytes costs time and, on some providers, money. Off by default, with a size cap you set. Storage_deleteMany reverts key by key and reports exactly which came back.
  • Files and media: reverting Media_transformImage, Media_stripMetadata, Archive_create, Archive_extract, Pdf_split, Media_extractFrames, ImageGen_generateImage, Storage_download, and EmailStore_copyAttachmentToFolder. A call that writes many files reverts all of them together as one operation.
  • A revert always refuses if the target changed since, and now says how it checked, so you know how much to trust an override.

Obsidian_queryNotes keeps frontmatter types (breaking)

  • A projected frontmatter value now keeps its original type instead of always being a string. amount_due: 100 projects as a JSON number, and an unquoted true/false projects as a boolean. This brings the tool in line with Obsidian_readFrontmatterProperties, which already returned typed values - the two previously disagreed about the same key.
  • This breaks any caller comparing a queried value as a string, for example row.amount_due === "100", or a schema expecting type: "string".
  • Also fixed: a fractional value like 1.50 had started losing its trailing zero internally, which silently broke an eq "1.50" filter. Equality and membership filters again match the value's exact written text.

Fixes

  • An automation that missed one run could stop running forever, silently. A cron or interval automation with "catch up on wake" off that missed a single run by more than a minute - the Mac asleep, busy, or the app briefly closed - could stop firing permanently with nothing on screen saying so. A missed run is still skipped as intended, but the schedule now resumes afterward. An automation that seemed to stop on its own should start firing again on its normal schedule.
  • The Automations list no longer claims "Last ran" for an occurrence that was skipped and never actually executed, and the status dashboard now tells you when an automation's schedule can never fire at all.
  • A brand-new automation could run immediately instead of waiting for its first scheduled time, if that time had already passed when it was enabled. It now waits.
  • Dns_lookup could hang for minutes. A lookup for a name with no answer of the requested type could take up to about 16.7 minutes to return no matter what timeout you set, and could briefly make other endpoint checks report "busy." Separately, a name that genuinely does not exist was reported as a resolver failure at critical severity, which would make a monitoring automation alert forever on a perfectly normal negative answer. Both fixed.
  • Max output tokens could only be set on Anthropic providers, and a value set there was never actually sent to OpenAI-compatible or Ollama endpoints. The field now appears for every provider kind and is honored. An answer cut off at your cap now fails with a clear message instead of quietly returning a truncated answer.

Version 1.0.1

Thirty-two new tools, taking the MCP surface from 123 to 155. Everything here is additive - no existing tool was renamed, removed, or reshaped.

Agents can stop guessing whether they already did something

A new Agent State area gives an agent durable bookkeeping that survives a crash, a restart, or a dropped connection.

  • Hash_bytes, Hash_file, Hash_files return md5 and sha256 over inline content or over files in your granted folders. A language model cannot compute a digest, so asked for one it will invent it; these exist so it never has to.
  • Manifest_diff, Manifest_commit, Manifest_listNamespaces, Manifest_reset track what content looked like last time, per named namespace. Diff never changes anything; commit is the only call that advances the stored manifest, so an interrupted run re-does work rather than silently skipping it.
  • Ledger_filterUnseen, Ledger_claimUnseen, Ledger_markProcessed answer "have I processed this id before" as an exact set operation. claimUnseen filters and marks in one transaction, so two agents working the same queue cannot both claim the same item.
  • Cursor_get, Cursor_advance keep a named watermark that refuses to move backwards unless you explicitly reset it.
  • Filesystem_writeTextFileIfUnchanged writes only if the file still matches the hash you expect, so two agents editing the same note cannot silently overwrite each other.

Free includes 3 namespaces; Pro raises the cap.

Query your notes instead of reading them all

  • Obsidian_queryNotes runs a declarative query over note frontmatter: multiple source folders each with their own filter, a full predicate grammar, relative dates (today+7d, startOfWeek), computed fields, date bucketing, multi-key sorting, and group-by aggregation. A dashboard that meant reading several hundred notes into context is now one call. A malformed query fails loudly with the exact path to the problem rather than quietly returning the wrong rows.

Scheduling

  • Calendar_findFreeSlots finds open time across your calendars with working hours, buffers between meetings, minimum notice, and clock alignment, handling daylight-saving transitions correctly - the part models reliably get wrong. Free covers the next 7 days; Pro searches up to 90. On Free, a longer request still gets a real answer over the shorter window, clearly marked as narrowed.
  • System_describeDate returns a date's weekday, relative wording, business-day distance, and overdue flag in one call, so no agent derives them by hand. Free, no limit.

Undo History

A journal that records every file change an agent makes through this app, so a bad edit is recoverable.

  • Every write, move, delete, and directory creation through the Filesystem_* and Obsidian_* tools is journaled with its prior content, before the change happens.
  • The Undo History screen lists what happened, groups it by run, and offers Restore for a single change or an entire agent run. A restore refuses if the file changed after the change being undone, and shows you both hashes rather than overwriting newer work.
  • Operations that genuinely cannot be undone - a sent email, a remote command - are still recorded and shown as not undoable, with the reason. The journal never stays silent about something it cannot reverse.
  • Undo_list, Undo_get, Undo_revert, Undo_revertRun expose the same thing to agents. The journal and the screen are Free; the tools are Pro.

Ask an AI provider from a prompt or a job

  • AiPrompt_run calls a configured AI provider (OpenAI-compatible, Anthropic, or Ollama) and returns its response, so a scheduled job or an agent can get a second model's answer without wiring up an HTTP call by hand. It accepts image input.
  • AiPrompt_listProviders and AiPrompt_listModels list your configured providers and the models each currently offers, so a caller picks a valid model name instead of guessing.

Listing is Free; AiPrompt_run requires a paid license.

Adding an email account is now a guided setup

  • A new Add Email Account wizard walks through picking a provider, entering credentials, and confirming the connection, instead of hand-filling every IMAP field up front, with a preset picker that fills in host, port, and security defaults for common providers.
  • Microsoft/Outlook.com accounts are now supported via OAuth (consumers only, IMAP receive), alongside the existing Google OAuth flow.
  • Outbound mail supports multiple recipients per send and an optional domain allowlist restricting who an account may send to.

Keep the Mac awake for a scheduled job

  • A per-job "keep system awake" option holds the Mac awake through a job that is about to fire, instead of the job silently missing its window.
  • A misfire diagnostic records when a job was scheduled to run but the Mac was asleep, so a missed run is visible rather than absent from the log.
  • This is "keep awake for a moment," not "wake the Mac from sleep" - the app cannot do the latter without elevated privileges it does not ask for.

Smaller changes

  • Ten Settings list screens now put each row's actions behind a single ⋯ button instead of a cluster of icons. No action moved or changed what it does, only how you reach it.
  • Run History's retention cap is now configurable instead of fixed.
  • Fixed IMAP AUTH= capability parsing, which truncated every SASL mechanism name to the bare word "AUTH" and could make an account look like it did not support a login method it actually did.
  • Fixed an OpenAI-compatible provider's base URL resolution, which was missing the trailing /v1 segment.
  • Fixed the dashboard's Check for Updates button and the release-notes panel's sizing, and a List-collapse layout bug on Run History.

Upgrade note

This release adds three permission areas (agentState, undo, and file hashing). Existing API keys do not receive new permissions automatically, by design. Re-issue or re-save any key that should use the new tools, including your owner key. Keys scoped to other areas keep working untouched.

Version 1.0.0

The first public release - public beta. Expect rough edges; email [email protected] if something breaks.

  • 123 MCP tools across 15 permission domains, served over streamable HTTP on localhost.
  • Mail: IMAP sync with search, plus a triage path (mark read, flag, move, delete, save draft). Write access is off per account until you enable it.
  • Calendar, contacts, and reminders over CalDAV and CardDAV, or the Mac's own Calendar, Contacts, and Reminders.
  • Files: named folder roots you allow, with Markdown and Obsidian-aware editing, Spotlight search, on-device text extraction, media handling, and archive inspection.
  • Cloud storage across S3, R2, B2, FTP, FTPS, SFTP, and WebDAV.
  • SSH command execution against servers you opt in, per account (Pro).
  • Feeds, an HTTP client with saved connection profiles, image generation, outbound mail, notifications, and a Shortcuts runner.
  • Scheduler with cron, interval, and inbound-mail triggers running shell commands, Claude prompts, or prompts against your own AI provider, with run history and a dead-letter queue (Pro).
  • Scoped API keys: one key per agent, scoped by domain, operation, and specific resource (Pro for more than one key).
  • Per-tool kill switches that disable any tool app-wide, for every key.
  • Claude Desktop extension with one-click install from inside the app.
  • First-run setup assistant and an in-app help reference covering 26 topics.

Get these by email

I send a short note when a new version ships. Nothing else.

Sign up for release notes