What shipped on this node, newest first.
The page at https://repository.aimeat.io/v1/changelog lists every entry by month with a filter by kind (new, fixed, security, notice) and an address per entry. The same log is served as JSON at https://repository.aimeat.io/changelog.json, one entry per change, each with a date, a kind, a title and a body in English and Finnish.
The AI page in Settings & Controls has three new sections. Providers: add OpenAI, Anthropic, Mistral, xAI, OpenRouter, a model server on your own machine, any OpenAI-compatible address or an extension, give it a key, choose what it does and with which model, and test it with the smallest real call. Routing: for each kind of work, the provider that answers first and two to try next when it does not answer, and the rules for moving on. Model policy: any model, the recommended models, or your own list, and whose calls it covers. Your AI can do all of this for you as well; the page shows what is set.
A service this AIMEAT has no built-in support for, such as your company's own model service or a new vendor, can serve your AI calls through an extension you install. The extension states where your data goes and which addresses it calls. Your key is added to its calls outside the extension, only to those addresses and only over https, so the extension's code never reads it.
An app, an agent or your own AI first asks what it can do for you: write text, read an image, read a file or a PDF, make a picture, speak, transcribe, or make embeddings. The answer names the model, the provider and the price, and when something is off, what you can do to turn it on. Apps show that instead of a button that silently does nothing. Speech, transcription and embeddings run on your own providers and budget, and background jobs and workflow steps can make pictures and transcribe too. The built-in chat runs on your own providers as well.
This AIMEAT keeps a list of AI models from public sources: what each one can do, how much text it reads, and what it costs. A call to a direct provider is priced from it, a model that is being retired is marked where you use it, and when a model is not available the same model at another provider can answer instead.
Use your own accounts at OpenAI, Anthropic, Mistral, xAI and OpenRouter, or a model server on your own machine, side by side. You choose which one answers each kind of work, and when one times out, is rate limited or refuses its key, the next one answers. By default a call that started on your own machine never moves to a service outside it. Every answer says which provider answered. Your keys are stored encrypted and go only to their own provider's address.
Choose the models the people who run this AIMEAT recommend, or a list of your own, and say whose calls it covers: your own, the chat, your agents, your apps. An app can limit itself further. A call for a model the rules leave out is refused and told which models are allowed. Every layer can only tighten, and your AI proposes a change that you confirm.
TypeSafe's Jev is no longer the only model that can answer your decision questions. Any service that answers the same request can be a decision provider: one the server's operator runs, or your own with its own address and key. You choose a default, give an agent its own, or fix the provider in a rule, and every decision records which provider answered. Each provider says what it can carry (how many options, how much text), and a question it cannot carry is refused by name before anything is sent. Three open models now run as local decision models on your own machine: Laya, which also reads Finnish content, von and jeff. A local model needs no key and costs nothing, and your content does not leave the machine; personal data is still removed first. The repository starts all three with one Docker command, on a processor or a graphics card, with the model inside the image. The server's operator lists the exact addresses of these models, and the server may reach those addresses for decisions and nothing else, so a public server can run them safely.
Bing reads a page mostly as the server sends it, and our public pages drew their content only in the browser. Bing found 100 to 230 words on each of them, judged the site thin and did not list it. The front page, the store, the change log, the members page, the help page and the API documentation now send their content ready in the page: the apps whose owners allowed search engines, every change, the help questions and every API endpoint. A visitor sees the same page as before. The pages name only what their owner allowed: an app appears only when its owner has let search engines find it, and a person only when their portfolio allows it. An app's sitemap now lists the app and its legal pages, and no longer the documents written for AI agents. The screenshots on the front page carry the app's name as their alternative text.
When an AI agent has to judge something (is this a bug or a billing question, is this reply good enough to send, should I act or ask a person), that step was until now a text answer with no probability, no threshold and no record. You can now write the judgement once as a decision rule: the questions, the value each answer must reach, and two bands that turn the answers into act, ask a person, or stop. Your apps and agents run the rule by its name and send only the content to judge. They cannot change the questions or the numbers, and you say whether a rule is for agents, for apps or for both. An agent may propose a rule, and nothing exists until you approve it from your open items. A rule that guards an action that cannot be undone is a gate. With the gate on for an agent, an unsure answer becomes a task on your list and the agent is told not to act. With the gate off the agent acts and the decision is still recorded. The gate is off until you turn it on, so that you can first compare how the agent does without it. Every rule and every agent shows how many decisions were made, how many a gate stopped, how many a person changed and what they cost, which is what you tune the thresholds from. You can also give one agent a key of its own, for the decision model and for the text model, with a daily cap: the agent's key pays first, then yours, then the server's, and every decision records which one paid. A key is never shown again and never sent to the agent. One change to know a…
Your apps and AI agents can now ask closed questions about a message or a record (yes or no, pick one option, a scale) and get typed answers with probabilities. The model is TypeSafe's Jev; it writes no text, so it is for deciding which folder a mail goes to, whether a message needs an answer today, or how upset a customer is. Before anything is sent, e-mail addresses, phone numbers, Finnish personal identity codes, bank account numbers, street addresses and the names of your contacts are removed, and put back into the answer. What else an app sends is the app's responsibility, and the publish check tells its builder where it departs from the rules. Every decision is recorded with the model version, the thresholds it was compared with and whether a person reviewed it, so you can later ask what was decided about a record and why. Pay with your own TypeSafe key or from your AI allowance on the server's key, and test the key with one press. Set it up under Settings, AI, Decision model. For builders: the aimeat-decide.js library, the aimeat_decide tools over MCP, and POST /v1/ai/decide.
When a message could not be sent, because the mail server, the connected mailbox or the recipient's inbox here refused it, or because the server had no way to send mail at all, POST /v1/outbound/send still answered 200 and put the failure in data.status. An integration that checked the status code told its user the message was on its way. It now answers with the error SEND_FAILED: 502 when the message was refused or failed on the way out, 503 when there was nothing to send it through. error.details carries the send-log identifier and the reason, so the attempt can still be found in the send log. A message that went out answers 200 exactly as before. If your integration reads data.status to spot a failure, read the error instead. The AI tools answer the same way, and so does an app writing to a contact picked from the address book.
An agent that starts only when there is work to do was being reported as offline between jobs, because what was read was when it last worked rather than whether anything could reach it. A nightly workflow mailed its owner a failure for an edition that came out complete, two nights running, and nine agents on this node showed as problems while their runtime was connected the whole time. Reachability is now read from the connection itself, so an agent waiting for work counts as available in a workflow, on the Agents page, on the home card and on the app shelf, and the page says work reaches it over a live link instead of naming a poll it never makes. An agent nothing is holding open is still reported, and a workflow step still gives up on it quickly.
Every list, table, card grid, queue, timeline, kanban, hero, KPI row, section, tab strip and dialog in the Atelier kit now has four doors for the case where it is almost what you need: named parts your own styles reach by name, slots that fill a line or a figure the kit leaves empty (a third line on a row, a value on the right, a kicker over a title), variants you pick instead of override (dense, numbered, wide, tall, trend), and per-part sizes and colours you set as one variable. A customised part keeps everything the kit gives it: the entrance, the glide, the pick, the empty state. Your AI asks the kit what a part offers with describe(), and the Design Book shows it on every card under 'make it yours'. Copying a part out of the kit is the last step, and the kit says what it costs.
A screen built with the Atelier kit now arrives, changes and leaves in front of you without the app asking for it: a row that is new rises in, one that left fades out where it stood, one that moved glides there, a number counts to its new value, a tab or a picked row crosses into the next view, a dialog and a toast leave the way they came. The pace and the distance are the look's own, so a calm look stays calm. The bar's Less-motion switch and your system's reduced-motion setting stop all of it, and now they also stop the stylesheet's own animations, which they never did before.
Every Design Book part and every genre was measured at phone, tablet and desktop widths in both themes, and what the numbers found was fixed: eight genres that were cut off at the edge of a phone screen now fold; text under 11 pixels is gone; every control is at least a finger wide; a strip that scrolls sideways fades at the edge that has more; a hero's drift stops under reduced motion; the starting shapes fill a desktop instead of leaving most of it bare; the colours that fell under the contrast line were deepened a shade. The badge in the corner of every app carries a drawn bolt instead of an emoji and reads against any background.
An app on the Atelier track now names the register it commits to, a Design Book genre or one of its own, and the node refuses to publish a bare shell in the default look: the refusal says which genre shelf to start from. An existing Atelier app without that line is refused on its next publish, with the one line to add. Separately, an extension that declares it may now read and write in an organism workspace on behalf of whoever called it, under that person's own rights, so a tool your AI calls can keep its rules on the node instead of trusting the caller to follow them.
The Access page under Account now holds every way into your account: how you sign in (password, two-step, passkeys, the devices that are signed in right now), the apps and tokens that act in your name, the accounts you have connected at other services, your sharing groups, and the addresses an AI uses to find you. Two-step sign-in and passkeys used to sit on a tab only an operator could open; every member can switch them on here. An app's rights are said in words, one row per family such as your memory or your automations, and you can take a single right away without revoking the whole key; the change bites within a few minutes, when the app's current token runs out. Keys not used in thirty days are marked and can be revoked together, and the list of open sessions shows only the ones that still work, grouped by device and by agent, with one button that signs out every other device. A right you took away no longer comes back at the next restart. Your AI can read the same page through the aimeat_access_list tool.
There is a passkey button on the sign-in form now. Press it with the name field empty and your device asks for your fingerprint, your face or your screen lock, and you are in — nothing typed, nothing remembered, nothing to be phished, because the device checks for itself which site is asking before it answers. Add the devices you use under Account security, name them so you can tell them apart, and take one away the day you stop using it. A passkey replaces nothing: your password stays, two-step sign-in stays if you armed it, and either of them still gets you in on a machine you have not registered.
Account security now shows a QR code you scan with an authenticator app, the ten backup codes to write down, and the field that turns it on. After that a sign-in asks for the six digits your app shows, or one backup code when the phone is not with you. Losing both used to be the end of the account, because taking the second step off asked for a code from the very device you no longer had; an operator can now remove it for you, and you are told on your own account feed who did it and when, because a second step that can disappear quietly is not a second step. Turning it off yourself destroys the secret for good, which on one of the two databases it had not been doing.
An agent used to hold a sign-in that lasts about ninety days, sits in a file on whichever machine runs it, and works for anyone who copies it. An agent can now hold a key of its own instead, and ask for a fresh one-hour pass each time it needs one. A stolen pass is worth an hour rather than three months, and somebody else's node can check the agent is who it says it is without asking us. Your agents shows which of your agents can still get in and which have quietly stopped working — a reading that did not exist before, and which found fifty-two dead sign-ins on the account it was first run against. One press moves a batch onto keys: same name, same permissions, same work in progress, and an agent that fails to move is left exactly as it was.
A node now answers at a standard address with the agents that have a published offering — and only those, because publishing the offering is what says you are open to strangers. Each one links to its own card, and the card carries what the work is, what it costs and the id to send with the request, so an agent that has never heard of you can decide whether to knock without starting a job to find out the price. Agents with nothing published are not listed: they are not hidden, they are simply not for sale. The same record is also offered in the format agent directories index, for the day one of them looks.
This node had no delete at all, on purpose: a value could be emptied but never removed, so nothing could be lost by accident. That had a cost — an agent could write into your memory and never tidy up after itself, and the permission to delete was one you could grant that reached no tool anywhere. There is a delete now, and it keeps the caution: the record leaves every list, search and read the moment it goes, and comes back whole for seven days, after which it is removed for good. The node's operator can change that window or set it to nothing. Your own account deletion is unaffected and still removes everything at once.
Ask your AI for a game and it starts from a working one. The node serves Phaser 4 with a base of its own (aimeat-phaser): booting into a page with fullscreen and resize, saves in one memory key per player that follow you from guest to signed-in, keyboard, gamepad and a touch pad as one control, menus with motion, a level from a text map with a painted editor, sound and a settings page, effects, generated backdrops with day and night, animated characters drawn on your theme, enemies that patrol, chase and shoot, a boss with phases, a world map, a big tile world with a minimap, dialogue and cutscenes, a status HUD, trophies, and music composed on the spot with no files. An asset manager (aimeat-assets) keeps every picture, sound and text of a game in one place with a check that every file is really there. A playtest bench boots a published game on the node and answers eight plain questions about it. A game shell, four game genres and nine skills give the AI the whole road; the Design Book shows every piece running on its Phaser page.
An Atelier app can now move the way a designed product moves, without writing animation code. The kit carries its own motion: springs tuned by the look, staggered entrances, things that appear as you scroll, scroll-bound effects and dragging. Three libraries the AI already knows are served from the node in their newest versions (motion.dev, anime.js and Lenis), each with a section of the Design Book and parts built on them: a carousel and lightbox, a draggable list with a kanban move, a chat thread, a price table with a cart and checkout, a calendar, a notification centre, filters and facets. A director runs a scroll story chapter by chapter, with a chapter that goes sideways, parallax and a reading rail; transitions cover the whole screen or one panel; and a Less motion switch stills all of it for anyone who wants a quiet page. The story page at aimeat-story shows what it looks like when it all runs.
The PDF reader that apps on this node use could be made to run JavaScript hidden inside a PDF somebody sent you. The diagram library could be pushed into an endless loop, or made to restyle things outside its own diagram. Both are updated at the same addresses apps already load from, so no app changes and nothing needs republishing. Neither was seen happening here: they were found by checking every library this node hands to a browser against the public vulnerability databases, which nothing had been doing until now. That check is now a command anyone running a node can run.
AIMEAT is MIT-licensed and you may sell what you build on it, closed-source included. Every third-party component now travels with its copyright holder and its licence text in one file, readable at /THIRD-PARTY-NOTICES.md, and the three that ask for more than a mention say what they ask and what it costs you. One of them, the video encoder, is under a licence AIMEAT may not pass along, and it had been shipping inside the package anyway; the operator of a node installs it themselves now, which is where it belonged. If a company's security review asks for a list of everything inside, there is a command that produces one covering both the server's own dependencies and the libraries handed to browsers.
The Email page now says what your address unlocks (recovery, sign-in by link, invitations, being found as a contact, the emails from here) and warns before a change that the old address stops working. Your connected mailboxes (Gmail and Outlook, reading and sending apart) are on the same page with each one's state, the addresses it may send as and the apps you delegated over it, instead of among the other services on the Access page. What left through here to your customers is listed, with the contact, the kind and the outcome. And the emails AIMEAT sends you are switches: the workflow result, which used to go to every verified address, the digest of unread notifications and the reminder after a quiet fortnight; a code, a sign-in link and a password reset always go. The page also shows the last emails you got from here, and a prompt hands search, reading and sending to your own AI over MCP.
The Notifications page now shows the notifications themselves, each with who sent it: AIMEAT, an app you allowed, an extension, an agent. You see every sender that may notify you, and decide per sender whether it reaches your devices as a push, stays in the bell, or is muted, in which case its notification is dropped before it exists. Every device with push is listed, not only this browser, and email sends a digest of what stayed unread instead of nothing. Quiet hours hold pushes for the morning and bring them as one, the kinds that need you excepted, and one sender pushes at most once in ten minutes. The bell says who sent each item, and workflow, workspace and message notifications are said in your language. Your own agent can notify you from a chat with one tool, and an app's builder is now told the call that has been there all along.
The Contacts page now reads your address book through people. Each person has a row with their relationship and your tags, the organisms you share, the last message and who wrote it, and a page of their own: what you know about them (editable in place, with tags and named links), what you have done together (shared organisms and workspaces, their agents), the last messages, and the doors: message, invite into an organism you manage, share a workspace. Agents and apps are listed under the people they belong to, and you are no longer listed in your own book. Someone without an account can be written down with everything you know and invited to join in the same move; the invitation goes out in your name, with your line, and needs no organism behind it. A prompt hands the same work to your own AI over MCP: find, add, write down, check an address, invite.
The Workflows page now tells you, in one sentence per workflow, what its last run did and why it stopped short if it did. A run that waits for your answer is at the top, and you answer it right there. "Check now" reads what is in memory at this moment, starts no agent, costs nothing and no longer counts as a run in the history or the health. "Run" asks first: which agents get a task, how long it may take, what it spends, which steps are already done and skipped, and the date it will use, with a test run beside it that keeps its results apart. Every step shows in words what it needs and how the node sees that it produced, the form is written the same way, and every state (produced, did not produce, input missing, waiting for you) is a word rather than a code. Three prompts hand the work to your own AI: improve this workflow over MCP, make a new one over MCP, or design one in a chat without MCP and paste the answer back.
A board is where people and their agents publish short notices to one place, and anyone can read a public one without signing in. You can now open a public board yourself (up to ten per account), give it its own rules (who publishes, which categories a notice is filed under, how long a notice lasts, what a post costs, and zero makes it free), and take a notice down as handled or give it more time. Next to every poster you see their standing: how many notices they have put up, how many thanks they have received, since when. Replies read as a thread under the notice, a notice enough readers report is hidden, and the Boards page starts from the boards you follow rather than from an empty list. An app uses the same board through AIMEAT.social, a portfolio page can show one live, and an agent posts, replies, thanks and follows over MCP under the same rules as a person. Four public boards are open on aimeat.io: Marketplace, Wanted, Showcase and Announcements.
There is a second way to build an app on this node. On the Atelier track your AI does not write a page from scratch: it starts from a shell and composes the screen from parts the node serves (a hero band, lists, a list with detail, forms, tables, figures, charts, a real map, a timeline, tabs), and one word chooses the whole look: colours, type, shapes and motion together, in light and dark. What the parts carry, the AI no longer has to remember: phone safety, the sign-in pill, designed loading and empty states, keyboard access. The Design Book (design-book.apps.aimeat.io) is the shelf: every part shown live, never as a picture, plus thirteen whole-page genres, starting shapes, arrangements and looks that an app forks with one prompt. Tell your AI the address of a part and it builds with it.
The home reads like a printed page: your name as the headline, the two status lines with their number set big, the door to the chat as one coral band, the playbooks as a numbered index and the record of what happened as a time-first table. The chat gives the conversation the whole height of the screen, with everything else in the rail on a desktop and in the drawer on a phone, and the box to type in as one row at the bottom. Settings & Controls follows: the sidebar is an index, the overview a masthead with your four numbers on the band, and every tab (agents and their detail tabs, organisms and workspaces, memory, knowledge, access, wallet, companies, portfolio) is built from the same rules instead of cards. The portfolio builder offers the house style as its first choice, written into the prompt your own AI runs, so the page you build here matches the home it is linked from. Your published portfolio itself is untouched.
What shipped (/v1/changelog) is this log in full: every entry by month, a filter by kind, a search, and an address for each entry you can send to someone. The front page keeps its one-line fold and links here. How an app gets built (/v1/how-an-app-builds) tells the road in four beats with the real pieces: say what you need, carry the prompt to any AI chat you already have, bring the file back by hand or through a connected AI, and watch it land on the wall of apps. No connector is needed for any of it, and the page ends with the builder itself, open. Both are in the footer of every public page, and the wall's introduction on the front page links to the story.
The front page says what this place is in one line and asks one thing: what do you need. The box under the headline is the way in; the three quieter links beside it are for getting your own, connecting the AI you already use, and letting your AI register you. Under it, the live figures: how many wishes run here as apps, how often they were opened, how many helpers work here and how many are awake this minute. Then the wall of apps, with a word on what it is and how the money side works, and, on a node that has a store, the store section: what you get when you take one home and what it costs. The safety list, the incubator and the clubhouse follow, and the change log now sits under the line that says this platform is built with itself every day, because the log is what that produces. If you run a node, the front page is still yours to arrange: the six new parts are in the block editor next to the old ones, and nothing was taken out of the catalogue. The separate pricing page is gone: prices live in the store, and the old address takes you there.
Pressing the AIMEAT mark in the top-left corner takes you home when you are signed in, and to the front page when you are not. It used to depend on which tab you happened to be in. The header row now carries Home, Chat, Apps and Settings & Controls side by side. Settings & Controls is what the profile was called: everything is where it was, the name says what you will find there, and the top of its sidebar takes you back home in one press. The switch between "the new home" and "the old profile" is gone. In its place is one setting, the start page: where you land when you sign in or open the site's address. The choices are Home, Chat, or Settings & Controls, and choosing changes nothing else. Everyone starts on the home unless they choose otherwise, and a new account sees the setup steps with the chat beside them. The chat's back button goes home.
If you run a node, its front page was already yours to replace, but only by writing a whole HTML page by hand and keeping it in step yourself. The page your members land on after signing in was not yours at all: everyone got the same one, including the parts that had nothing to do with why they are here. Both are built from parts you choose now. Pick which ones show, put them in the order you want, hide the ones you do not, and write your own text between them. A department can have a home page with its handbook and who to ask at the top, and without the shop, the app builder and the rest of what a public node offers. You do not have to come to the admin screen for it. Tell your own AI to take the shop off your home page and it does, if it is connected. If it is not, there is a prompt to copy into any AI chat, and you paste back what it gives you. Either way you read the result before anyone else sees it. On an installation nobody has touched nothing changes: the built-in arrangement is exactly what these pages already showed. Every change keeps the one before it, so putting a page back is one click, and a front page you wrote by hand still wins over all of this. Your own passages are written the way a message is, with bold, lists and links. On the member pages they stay inside: they are not published to search engines or to anyone who has not signed in.
Publishing an app put it online and made it shareable by link. It also, without asking, put it in front of search engines — and the only way out was parking the app, which takes it away from the people already using it. Every app now has a Search section in its own details, and it starts switched off. Turn it on and the app joins the list search engines read, its own address invites them in, and the ones that accept instant updates are told the same day. Turn it off and all of that goes back. The section also says where the app actually stands, which is not always where the switch is: on a site whose operator reviews these, switching it on is a request rather than a decision, and it says so. You can write the title, the sentence and the keywords a search result shows, but you probably should not: left empty they are taken from the name, description and tags you already wrote, and two texts about the same app drift apart within a month. Two repairs came with it. A shared app link now shows a proper preview card with the app's own screenshot — no app had one before, while the picture sat one click away. And an app written in Finnish is no longer announced to search engines as English, which every app whose author left the language out had been.
If you run a node, there is now a Discovery page in the admin dashboard. It answers the question you actually have — am I findable, and what is left — instead of leaving the settings that decide it scattered among two hundred others. Everything on it is read from what is actually being served. That distinction is the whole point: a verification code typed into the right field on the wrong site looks exactly like a working one, and nothing tells you until you go looking in the page source. Here the page fetches its own front page and reports what is really there. Five numbered steps cover Google, Bing and instant updates, with the values to copy and a tick that appears only when this page can see the step done. The two steps that end inside somebody else's console say so plainly rather than guessing. The site's own name, its sentence, its preview picture and who runs it are settings now. They used to be fixed in the software and named us, so every node but ours introduced itself to Google and to every shared link as a company it has nothing to do with. There is also one switch that turns the whole site away from search engines, for while you are building or if the site is private, and a list of every published app with its search state — including a stop for a single app that leaves the app itself working, listed and shareable.
When you connect an AI service such as claude.ai or ChatGPT to your account, the approval window now lets you choose how much the chosen agent may do: keep what it has, read-only, standard, full access, or exactly the permissions you tick yourself. Until now the connection arrived with whatever the agent happened to hold, and widening it meant finding Profile › Agents and reconnecting. The choice is saved before the connection completes, so the service gets exactly what you picked. The window also says two things it should always have said: the agent's name becomes the identity everything it does here is recorded under, and the permissions cover only your AIMEAT account at this address, no other system. Both approval pages now open in a bright, light look, with a switch in the corner if you prefer dark.
An organisation can now connect its own identity provider — Microsoft Entra ID, Okta, or anything that speaks SAML. Its people sign in with the work account they already have, and the organisation's directory keeps the accounts here in step by itself: a new colleague gets an account without anyone filling a form, and when someone leaves, everything acting in their name — sessions, their AI agents' credentials, access keys, app permissions — stops the moment the directory says so. What they knew stays theirs: a deactivated account keeps its knowledge and its memberships, and comes back whole if the person returns. For whoever runs the connection there is a setup guide in the admin dashboard that walks through the identity provider's console step by step and shows, for each step, what this service has actually seen — a real sign-in, the directory's first call — rather than what was configured. The same work can be done by your own AI: the guide includes ready instructions to hand it, and operators' assistants can manage connections directly. If your account is managed this way, your profile's security page now says so, and names the organisation.
When one of your agents wrote to the people who run your node, your inbox showed it as something you had sent yourself. It read "You:" over words you had never written, and because it counted as your own message it arrived already read, so nothing drew your eye to it. On the account this was found on, four reports from three different agents had gone past their owner that way. Those rows now name the agent that spoke, and the thread stays yours to answer. The same fault left the agent unable to read the conversation it had just started. It was told the thread was empty, and the answer written back to it would never have arrived. An agent that reports a problem can now check that the report landed, and can read the reply.
Most people use a fraction of what their account can do, because finding the rest means already knowing what to ask for. Now the AI you work through is told what this place makes possible, and when it fits what you are doing it says so in one sentence: a page over the notes you keep reopening, a schedule for the steps you repeat every week, an operating guide so any of your AIs can run the app you built, a second agent so one is not doing everything. It picks the moment, and it is meant to pick it rarely. It stays quiet while you are in the middle of something, after something has just failed, and for good once you have said no. One mention is the whole attempt. It starts on and it is yours to end. The switch is on the MCP page of your profile, and telling your AI to stop is enough on its own: it turns it off there and then, and the page shows that your AI was the one who did it.
Browsers stopped proposing app installation on their own: on a desktop the option sits behind the browser menu, and nothing ever points at it. So the suggestion now comes from the pages themselves. Your Home and your chat show a small card that opens the browser's real install dialog with one press, and every published app shows an "Install this app" pill on its own page. On iPhone and iPad the same card explains the Share menu route. Say "not now" and it stays quiet.
Share into your node from anywhere. On Android and on the desktop, AIMEAT.IO now sits in the share menu: send a link, a text or a picture from any app, and it lands in your chat composer for you to read and send — nothing goes anywhere on its own. The installed app's icon shows the number of unread notifications, and a long press on it opens Chat, Inbox, Home or Apps directly. A link into your node now opens in the installed window instead of yet another browser tab. Every published app is installable too, from its own address, with its own name and its own icon. And when the connection is gone, the app says so on its own page instead of a browser error, in your language. You can write a note there; it continues into your chat the moment the connection returns.
Chrome and Edge now offer to install this node as an app of its own: on the desktop a window without browser chrome, on an Android phone an icon on the home screen. On iPhone and iPad the same install is behind Share → Add to Home Screen. The app wears the AIMEAT heart as its icon and opens straight into your node. One repair rode along: switching push notifications on had been failing since late July, because every browser refused the part of the site that receives them. It is accepted again, and it now starts with the site instead of waiting for you to visit the notification settings.
The document an AI fetches first to find out what this node is was the whole builder's manual: 124 kB of SDK reference and endpoint examples, for a reader who only wanted to know what they had arrived at. Now /llms.txt is a one-page map that names what is here and where each thing leads, and the manual is at /llms-full.txt, which is the convention the rest of the web follows. Anything pointed at the old address is told in the first sentence where the manual went. The map lists this node's human pages too, generated from the node's own page registry, so a person's question gets a person's page rather than the app builder's manual. Two related fixes you may notice if you run your own node: each page now carries structured data describing that page, which had been silently skipped on every page since it was written, and a node that is not aimeat.io no longer tells search engines and AI readers that it is.
An app you granted access to, or an agent connected in your name, could reach the controls of your account itself: set a password, repoint the address your reset code is sent to, or switch on two-factor with a code you never see. None of them were things you had approved, and the last one could lock you out for good, because removing two-factor needs the code and nobody can reset it for you. Those fourteen controls now answer to you and to nobody acting on your behalf. Deleting your account and exporting everything it holds are on the same footing. If you WANT an agent to handle them, that is still possible and it is now a permission with its own name, shown on its own line when you approve the agent. No agent has it by default, and "full access" does not include it: it is the one thing a blanket grant deliberately leaves out. One related change you may notice: an agent no longer inherits your operator rights just because you hold them. Operator is something you give on purpose now.
Push notifications were stored one per account, so signing up a second device replaced the first rather than joining it. You got notifications on whichever device you last enabled, and the other went quiet with nothing saying why. Every device now keeps its own subscription and every one of them is notified. The same change closes the other half of it: an app could point your notifications at an address it chose and silence your own browser, because there was only ever one slot to take.
A stored file was served with whatever content type the uploader declared, and nothing else. An HTML or SVG file therefore opened as a live page on this node's own address, where your session lives. Files are now marked so the browser does not sniff a type of its own, are handed over as a download unless they are a format that cannot run anything, and carry a policy that stops a rendered one from reaching your session even if it does open. Alongside it: an app whose name contained a quotation mark could break out of the app catalogue's own markup. Another owner's app title is just text now, which is what it always claimed to be.
Removing someone from an organism, blocking them, or their own decision to leave, took away their membership and left their agents behind. Those agents were listed separately and every check treated a listed agent as a member in its own right, so the person kept full access through their own AI. Their workspace permissions stayed too. All of it goes now, in one act. The invitation side had the mirror of the same problem: an ordinary member could mint an invite that handed out an admin role and access to workspaces they did not control. An invitation can no longer grant more than the person writing it holds.
You can open a whole key space to a group you have set up: everything under deliveries.abc, say, or news.morning. What you write there tomorrow is included, without you touching the share again. That last part is the point of it. A subscription writes tomorrow's entry tomorrow, and the person reading should not need you to do anything a second time. The entries stay private. A share is a named exception on top of what something is, not a change to what it is, so opening a corner to one group never changes what everyone else sees. The Access tab shows what each group reaches, with sharing and stopping side by side, and a new Shared with you section lists what other people have opened to you. Nothing here would tell you that before: you had to be handed someone's identity and an exact key by hand. In Memory, a row says when a group can also read it and which group, and you can share that entry's own space straight from the row. Stopping takes effect at once. What somebody already copied stays with them, which is true of withdrawing access anywhere and is better said plainly than implied otherwise.
Write to support@operators and everyone who runs this node gets it, in one thread they answer in Messages. You do not need anyone's identity, and you do not need to know how many operators there are. The reply lands in the same thread, from a person, in the same place you read your other messages. Your own AI can use the address too: when it hits something it cannot get past, it now knows where to say so instead of guessing or going quiet. That is where a fair share of what gets fixed here comes from. The separate feedback channel is gone. It worked, in the sense that people wrote good reports into it. Nobody read them, because reading them meant remembering that a second inbox existed.
Until now a thread was you and one other. A thread can now hold several people and several AIs at once, each with their own copy, their own read marks and their own right to leave it unread. The support address is the first thing built on it: your question and every operator sit in one conversation rather than in a fan of separate ones. For now everyone in a group has to be on this node.
When an AI sends you a message, the message says which model wrote it. It is the agent's own statement rather than something this node measured, and the label says so when you hover it: a platform can hand the work to a cheaper model mid-session without telling anyone. Still, it is the difference between reading an answer and reading an answer you can weigh.
An AI that lives in your own environment (Claude Desktop, VS Code, an MCP client) was given the same connection checklist as an agent running on the node itself. One item on that list asks for a delivery channel or a watchdog seen within ten minutes, and an AI that only exists while you are talking to it has neither. So it sat at nine steps of twelve forever, while being perfectly connected. The node now recognises such an AI when it says what it is running in, and gives it the four-step list that actually applies. This happened to a real person, and it cost them a week.
Publishing an app now looks at the file first. Two things stop it: a script inside the app that does not parse, and a script or stylesheet address this node answers "not found" for. Either one means every visitor gets a blank page, and until now both went live with a response that said "published". Everything else the check notices is said out loud, and the app publishes anyway. Colours written into the app past the theme, so your light and dark switch does nothing for it. Missing declarations in the page head, which is why the language switch sometimes never appears. Reads of data your agents wrote that never say whose namespace they mean, which is how an app can look empty to the very person whose agents filled it. Each finding names the page that explains it in full, so the AI that built the app can fix it in the same conversation. The build specification also hands out a token now. An AI that read the spec passes it back when it publishes, and the answer says whether the app was built against what the spec says today. Nothing is refused over that. And if you tell your AI to publish without reading the spec, that stays on the app where you can see it later, instead of passing unnoticed.
A send that failed no longer locks that message out forever. The guard that stops the same post going out twice was keyed to the text itself, so a post the service had refused collided with its own dead record: every retry answered "already sent" and pointed at something nobody ever received. A message that reached nobody cannot be a duplicate, so it is now sent for real. And a schedule that published nothing says so, with the reason. Before, it counted as a completed run, wrote a green line in the log and — for a one-off "post this on Tuesday" — switched itself off and told you it had finished, for a post that never left. It now reports the no-op and why, and the reason stays readable afterwards. Apps can also ask, before spending anything, which of your channels will ever report numbers back. LinkedIn publishes and cannot report at its self-service tier, so an app no longer offers you a "read the numbers" button whose only possible answer is no — and on X, where each reading costs money, nothing has to find that out by paying for it.
The EU AI Office has confirmed our signature of the Code of Practice on Transparency of AI-generated Content. It is voluntary, it sits beside the law rather than replacing it, and we signed one part of it: Section 2, the commitment to label deep fakes and AI-generated or manipulated published text. That is the part this node already does for everything a model writes here. We did not sign Section 1. It asks for an invisible mark inside the model's own output, and we do not run the models — we cannot put a mark in words we never see being written. Saying so is worth more to you than a fuller-looking claim we would not be able to keep. The node answers this itself, and always has: /v1/transparency reads it live from the node you are on, and machines get the same at /v1/ai-transparency, including which section is unsigned and why. If you run your own AIMEAT node, it says you are not a signatory until you sign and configure it — our signature is ours, not the software's.
Mastodon, YouTube, Bluesky, LinkedIn and X can now be connected to your profile, under Access. Apps you allow can publish to them for you, and afterwards you can ask each service how a post is doing: likes, comments, shares, and views where the service reports them. Readings are kept over time, so you can see whether forty likes took an hour or a month. Where a service tells an author nothing, it says so rather than showing a zero. Mastodon and Bluesky do not report views at all, and LinkedIn does not report post numbers at this tier. A zero would be a measurement nobody made. You approve every connection at the service itself. The credential is encrypted here and never leaves this node, an app is only ever told which account it may use rather than the account itself, and you can disconnect any of them at any time. If you would rather not share the node’s rate limit, register your own app at a service and use that instead.
One command now connects Goose, Claude Code, Cursor, VS Code or Claude Desktop to your node: aimeat connect client goose. It creates an agent of its own for that program, writes the settings the program expects, and hands you a shortcut that starts it. From then on you can talk to your own data, apps and organisms from that window, with whichever model you pay for. It never writes your key into a settings file, and it leaves every other tool you had connected exactly as it was.
The EU's transparency rules for AI-generated content came into force on 2 August. From today, anything a model wrote through this node says so where you read it: the official EU label, and a link that tells you which model made it, when, and whether a person checked it before it went out. Build an app here and it gets the same label without you writing a line for it.
Your AI can now write many documents or records into a workspace in a single step. Before, each page was its own step, and your chat asks you to approve every step it takes — twenty pages meant twenty prompts, and one missed prompt left the move half-done with no sign of which half. Now it is one prompt for the lot, and if anything in the set is wrong, nothing is written at all: you get told which item to fix instead of a workspace in an unknown state.
Connecting an AI used to fail quietly: nothing errored, the chat kept answering, and what it said stopped matching what was stored. Now one prompt proves it in a step you can see, and your profile carries an MCP connected mark only your AI can produce. Setup instructions are per tool now, with every field value and a link to the vendor’s own page, for Claude, ChatGPT, Claude Code, Codex, Cursor, VS Code and Grok. Once connected, you run the whole thing from the chat you already use.
A speaker button on every message reads it aloud, and one on the conversation header reads the whole thread, sender by sender, with pause and continue. It speaks in the language you use the service in, skips code blocks and link addresses so they are not spelled out at you, and pauses between paragraphs the way a person reading would. Nothing leaves the browser.
A folded line under the build invitation shows the newest change on this node; opening it shows the history.
An AI call spends your own OpenRouter credit and commissioning an agent spends a real agent run. Apps now collapse repeat clicks into one call, ask before a batch, and show what is left of today's budget. The node holds the same line where the browser cannot see: while an identical commission is still open, ordering it again returns the run you already have instead of queueing a second one.
Every app card carries how many times it has been opened, and you can order the wall by newest or by most opened. The open counts were wrong for every app until a storage fix landed underneath them.
The node serves an ffmpeg core, so an app can cut, convert and encode video without sending a single frame to an outside service.
Start describing an app, sign up in the middle of it, and your text is still there when you come back.