Fix blank forwarded emails from plain-text senders
Inbound email forwarding no longer arrives blank when the original message was plain text only — the sender's body is now always included.
Updates to memsprout, newest at the top.
Inbound email forwarding no longer arrives blank when the original message was plain text only — the sender's body is now always included.
memsprout now publishes its MCP ownership metadata on the main site as well as the MCP endpoint, so directory listings can verify the server is officially maintained.
Mail sent to any @memsprout.com address, including support@memsprout.com, is now forwarded to the team's personal inboxes instead of sitting unread in the Resend dashboard until it's deleted after 30 days.
memsprout's MCP server now publishes ownership metadata, so our listing on MCP directories like Glama shows as officially claimed and maintained.
memsprout now has a public support page at /support with a direct email contact and links to related pages, so you always have a straightforward way to reach a human for help.
The file_bug_report tool has been removed from the memsprout MCP server — connected AI agents no longer see it in the tool list. If you run into a bug, please report it directly on GitHub instead.
memsprout's MCP tools now tell connected clients (Claude, ChatGPT) more precisely what kind of action each one performs — every tool is marked as operating only within your own memsprout data rather than the open web, and safe-to-retry actions like updating, moving, or deleting a memory are marked as such. Clients that respect these hints should prompt less aggressively before running memsprout's tools.
Every public page now ends with the same organized footer, grouping every destination under Product, Resources, Legal, and Account headings alongside the memsprout wordmark and tagline.
The marketing and legal pages — Changelog, Connect, Support, Privacy, and Terms — that previously stopped abruptly now share this footer, so you can reach any part of the site from anywhere without scrolling back up.
memsprout now has a public terms of service at /terms — the plain-language agreement covering your content and its license, shared spaces, AI processing, billing, and liability. Creating an account now notes your agreement to the terms and privacy policy right on the sign-up form.
In ChatGPT, memory retrieval now renders a single full-content memory card instead of a truncated search-results card stacked on a duplicate detail card. Searching and listing memories stays fast and text-only; opening a specific memory is what shows the rich card.
Semantic search's default relevance floor is back to its original, stricter setting after a recent experimental change shipped without approval. Most searches won't look any different, but very loosely related memories may again be excluded from results by default.
Memory search and detail cards now render as interactive widgets inside ChatGPT, not just other MCP Apps hosts — the tool and resource declarations were updated to use ChatGPT's own metadata keys and content type alongside the existing open-standard ones.
Confirming whether to revoke a connected agent now stays steady instead of reshuffling the row. The prompt is a single short line with Cancel and Revoke access tucked to the trailing edge, so the list no longer jumps or wraps into a jumble when you click through — on narrow screens the confirm buttons drop cleanly to their own line.
Revoking a connected agent from Settings → Agent used to also end your own signed-in session in the web app, because the agent and your browser session were linked together behind the scenes. Newly connected agents now get their own independent session, so revoking one only disconnects the agent — you stay signed in. Agents connected before this fix are also covered: revoking them now leaves your web session untouched while still cutting off the agent's access immediately.
ChatGPT now shows the visual memory-results and memory-detail cards even when it answers with its built-in search/fetch tools instead of search_memories/get_memory — previously those responses came back as plain text with no widget. Retrieval answers, links, and metadata are unchanged; only the rendering behavior in ChatGPT is affected.
Saving a memory that exactly matches one already stored in the same space now returns the existing memory instead of creating a copy, so a retried save from any connected client (ChatGPT, Claude, Cursor, Codex) is always safe. When a new memory is very similar to — but not identical to — an existing one, the response now includes a quiet note pointing at the similar memory so you can clean it up if it was unintentional.
The Connect page's Claude Code tab now leads with installing the memsprout plugin, which wires the MCP server and the using-memsprout skill in one step, keeping the manual claude mcp add command as a fallback below it. The Codex, Cursor, and Gemini CLI tabs each gained a short step for installing the using-memsprout skill via the skills CLI, so those clients get the same guidance on when to search and capture memory.
The connect page now has a ChatGPT tab showing how to wire memsprout in as a custom connector on any paid ChatGPT plan, including the plan requirements, the workspace-admin note for Business/Enterprise/Edu, and a copyable server URL — plus a note that memsprout also works with ChatGPT's deep research.
memsprout now works with ChatGPT's deep research and connector features — it can search your memories and pull up the full text of any one of them by following a search result.
Memory search results now render as visual cards in ChatGPT and other MCP Apps hosts, with a matching expanded view for a single memory — light and dark are both supported. Clients without MCP Apps support (Claude, Cursor) are unaffected and keep seeing the existing plain-text results.
Search and read tools now return structured results that AI clients can render richly.
Internal documentation update only — no user-facing change. prompts/CONTEXT.md now lists the npx memsprout installer alongside the other distribution artifacts and records its doctrine-copy drift risks, keeping agent-facing docs in sync with what actually shipped.
The connect page's Codex tab now covers the IDE extension and team setup — one CLI command wires every Codex surface, and one copyable AGENTS.md snippet teaches every agent in your repo to use the team's shared memory.
The connect page now covers Cursor team setup — commit the MCP config and a memsprout rules file to your repo so every teammate's Cursor shares the same memory, with copyable blocks for both files.
During team-lead onboarding, the interview question about the tools a team relies on now notes how that ties into the "What to capture first" catalog's team-level tooling suggestion, so the two parts of the conversation read as one connected flow instead of two separate lists.
The memory-capture tool now guides the agent to give most Memories a clear, descriptive title by default — especially decisions, procedures, facts, and anything shared into a Space — instead of defaulting to untitled raw captures. Quick, ephemeral personal notes can still be captured untitled with no extra friction.
The MCP onboarding flow now suggests concrete team-level Memory types to capture first — systems and projects, terminology, taxonomy, repos, team structure, team-level tooling, and company objectives — framed as prompts to pick from rather than a required checklist, and tied back to how Spaces get split.
The onboarding tour now appears right after you create a team, instead of waiting until you navigate to your home.
The Team plan card in Settings → Teams now clearly explains that the team owner is billed for everyone and adds teammates who pay nothing and just get access, replacing the ambiguous "you add and cover members" phrasing.
After you request a sign-up link, the signup page now shows only the "Check your inbox to finish creating your account." confirmation instead of leaving the email input and button on screen, which used to look like the submission hadn't gone through. A "Use a different email" link brings the form back if you need to fix a typo, and the password sign-up flow is unchanged.
The first-run welcome tour no longer reads you four slides in a modal. It now walks the actual app: each step spotlights the real region it's describing — the capture composer, the Shared Spaces nav, your Topics, the Settings entry for connecting agents — with a small popover anchored beside it. Next/Back/Skip and a step counter, Esc to skip, arrow keys to move, and the final "Get started" lands you on your Personal Space home.
The "Set up your team" checklist on your home Space now walks the actual first-run path — connect an agent, then run the onboarding command from it — instead of leading with capture and Space-creation steps that assumed you already knew the product.
Each step tracks real progress: the first completes once an agent is connected, and the second completes once you've asked your connected agent to get started (a one-click "Copy prompt" button is included).
The MCP onboarding flow now always explains what memsprout is — Spaces, Topics, and Memories — before it asks how to split up your Spaces, so the questions make sense before you're asked to answer them. The space-split guidance now leads with framing Spaces as areas of expertise or ownership: if you'd expect someone to own everything about a topic, they should have a Space for it.
When an AI agent captures a Memory through memsprout's MCP tools, it will now only file it into a shared Space when you've named that Space by name in the conversation — otherwise it always lands safely in your personal space, never a team Space by inference or guess. Whenever a Memory does land in a shared Space, the response names the Space and how many people can see it, so a shared write is always visible, never silent.
MCP access (Claude Desktop, claude.ai, and any other connected agent) now requires an active plan or trial, not just a valid login — a signed-in account whose trial has expired or that never subscribed gets a clear "subscription required" message instead of being able to keep capturing and reading memories indefinitely. Covered users, including active trials and paid plans, see no change; logging in and paying still work the same way.
memsprout.com now has a privacy policy at /privacy, linked quietly from the homepage footer. It says plainly what we store, exactly which third-party services touch your data and why, what our AI providers see (and that they don't train on it), and how deletion actually behaves — no boilerplate, every claim checked against the code.
memsprout no longer loads its Geist and Geist Mono fonts from Google Fonts — they're now served from our own origin, so the app makes no third-party font requests and works the same for anyone with strict tracker or ad blocking enabled. Text rendering, weights, and light/dark themes are unchanged.
Space memories now land in the right topic: agents are guided to pick a topic at capture time, and when they don't, memsprout classifies the memory into your topics automatically instead of defaulting everything to General.
The onboarding tool's description, shown to your AI assistant when it looks up memsprout's available tools, now says it "gathers" your context instead of "harvests" it — matching the language used everywhere else in the onboarding guide.
The MCP onboarding flow now captures knowledge as discrete, individually titled Memories — one concept per Memory — instead of rolling composite source material like a repository map into one giant summary. Importing a list of services or systems now produces a separate, self-contained "What is X?" Memory for each entity, so every one is searchable, correctable, and readable on its own in the memsprout UI.
Adding someone to a Space now shows a dropdown of people already in your org instead of a free-text email field, so you can no longer accidentally invite someone from outside the org into a Space. Picking a member and a role adds them right away — no email or sign-in link involved — and if everyone in the org is already in the Space, the dialog points you to the team members page to bring someone new into the org first. Bringing brand-new people into the org itself is still done from Plan & team, unchanged.
You can now replay the onboarding tour any time from the "Replay tour" action in the app sidebar footer, even after you've already dismissed it. Replaying works from anywhere in the app — it takes you to your home page and reopens the tour from the beginning — and won't affect the normal one-time tour shown to new users.
There's now a public /connect page — reachable without an account — that walks through wiring memsprout into Claude, Claude Code, Codex CLI, Gemini CLI, Cursor, or any other MCP client, each behind its own tab so you only see the steps for the tool you use. The landing page footer now links to it, and a ?client= link (for example ?client=codex) opens straight to that client's tab for anyone arriving from a directory listing or another distribution channel.
Inviting someone brand-new to your team now leaves them showing as Pending in Plan & team until they sign in for the first time, matching the badge and "Revoke invite" controls shipped earlier — previously every invitee showed as active immediately, even before they'd ever logged in.
The "Plan & team" settings page now shows a clear "Pending" badge and "Invited X ago" timestamp for teammates who haven't accepted their invite yet, matching the treatment already used on Space settings pages. The row action for a pending teammate now reads "Revoke invite" instead of "Remove," making it clear the invite — not an active membership — is being cancelled.
The MCP server now identifies itself as memsprout instead of vello in the authentication challenge that connecting clients see, matching the branded mcp.memsprout.com endpoint it's served from.
The "Connect an agent" button shown after creating a Shared Space now takes you directly to the Agent settings tab instead of the generic Account settings page.
Connected agents now get an honest token lifetime from memsprout, so they refresh access silently instead of getting logged out and bounced back through sign-in every hour. Reconnecting an agent you've already approved will also skip the approval screen entirely going forward, once the consent page finishes rolling out — for now it still shows the one-click approve screen every time.
Onboarding now teaches the Space → Topic → Memory hierarchy with a real worked example — an "Acme" organization with a team Space, a project Space, and a personal Space — instead of an abstract diagram, and the same example appears both in the app and in the onboarding agent's guide so they teach the same shape.
The onboarding agent can now also suggest concrete ways to split Spaces (by team, product line, audience, client, initiative, or a dedicated onboarding Space) when helping a team lead plan their structure.
The onboarding "Connect an agent" step now takes you straight to the agent-connect instructions, and shows a ready-to-paste prompt to have your agent walk you through setup.
You can now name your workspace when you create a team, and rename it any time from Settings > Teams.
Memories can now only be filed into topics that already exist — to use a new topic, create it first (with a real description). No more auto-generated "Memories about …" topic descriptions.
New signups now get a short first-run tour on their first visit to the app, walking through how memsprout thinks: everything is a Memory, Spaces decide who sees it, and Topics group related Memories — plus how agents read and write the same Memories over MCP. The public site now explains this same model in a new "The model" section with a Space → Topic → Memory diagram, right after "How it works".
When you connect an MCP client (Claude Desktop, Claude Code) and you're already signed in to memsprout in that browser, the authorize screen now recognizes your session: you just confirm "Connecting as <you> — Approve" instead of signing in again. You're still asked to explicitly approve each connection.
The connector sign-in email still arrived as a plain magic link with no 6-digit code. The OTP request anchored its redirect on the consent page's origin (auth.memsprout.com), which the Supabase Auth redirect allow-list does not cover — so the redirect was rejected, fell back to the Site URL, and lost the marker the email hook uses to include the code. The OTP redirect now anchors on the app origin (memsprout.com), which is allow-listed, so the marker survives and the email always includes the code. Enter that code on the consent screen to finish connecting.
When connecting an MCP client (Claude Desktop, Claude Code) via the OAuth consent screen, the sign-in email now always includes the 6-digit code alongside the magic link. Previously, the code was missing from the email because the OTP request carried no redirect URL, causing the email hook's MCP-flow detection to fail silently — users were left with an unusable code-entry screen.
Adding memsprout as an MCP server in Claude Desktop or Claude Code via https://mcp.memsprout.com/mcp now completes successfully. The OAuth flow no longer silently aborts after the consent screen — the fix adds the three path-aware discovery endpoints (/.well-known/oauth-authorization-server/mcp, /.well-known/openid-configuration/mcp, /.well-known/oauth-protected-resource/mcp) required by spec-strict MCP clients that connect through a path-based server URL.
Agent settings now leads with your Connected agents when you have any, so the list and revoke controls are immediately visible at the top of the page rather than buried beneath the setup steps.
Removing a member from an org now immediately revokes their access to all of that org's team spaces — previously the space membership persisted after the org removal, leaving the former member able to read shared content. The change also writes an "access revoked" event to the Change History audit log for each affected space, so offboarding is fully traceable.
Owners and admins can now see every agent connected to their org's shared spaces under Settings → Audit & governance → Connected agents. The roster shows each member, their connected client, connection date, and last-used date; filter by member, client, activity (active vs stale), or connected date range. Revoking a connection from the roster cuts the agent's access immediately — the same hard-kill used by the self-service revoke on the personal Agent settings page.
You can now see and revoke your own connected agents from Settings → Agent. The new "Connected agents" card lists each agent that has authorized through your account via OAuth, showing its name, when it connected, and when it was last used. Revoking a connection cuts access immediately — the agent must re-authorize through your browser to reconnect.
The audit log now records when team members connect a new agent and when a connection is revoked, including who acted and whether a revoke was self- or admin-initiated. Connected agent names appear in the event feed in violet, consistent with other AI-provenance metadata. A new "Connection" filter group lets admins narrow the log to agent lifecycle events.
memsprout now tracks which agent (MCP client) holds which live session, one durable record per install. A new revoke_agent_connection RPC immediately kills the underlying session and stamps the record so that even an un-expired token is rejected on the next MCP call — giving admins and users a real per-agent kill switch for the first time. Applies to new connections from this release forward; existing sessions age out naturally.
Audit & Governance: widened the Audit log's Who column so long emails and the "via Claude" tag no longer get cut off, and rebalanced the other columns to fit the wider table.
The Audit log now uses more of the screen — the table stretches to ~1300 px so long email addresses and event descriptions are no longer cramped. Filters apply as soon as you make a selection (no more Apply button): changing Who, Space, or When updates the feed immediately, and the event-type dropdown applies when you close it. The event dropdown also gained a search box that filters options by label, caps its height so it no longer overflows the screen, and can be dismissed by clicking outside it or pressing Escape.
The Audit log now correctly stamps a plain-text preview (entity_snippet) on activity events for untitled memories, and the four memory write operations route through the shared activity logger. This fixes the deploy failure from #429 caused by PostgreSQL rejecting a CREATE OR REPLACE FUNCTION that changed the return type of memsprout.audit_log — the migration has been corrected to DROP the old function first, then CREATE the new one.
Audit & Governance: renamed Change history to Audit log (route is now /app/settings/governance/audit-log); clicking an entry now links directly to the affected memory, insight, or file; untitled memories show a plain-text content snippet instead of "an item"; the "via Claude" provenance tag no longer clips on long actor emails; and the Event filter dropdown is now solid and readable.
Change history now records space lifecycle events (created, renamed, archived), access changes (granted, revoked, role changed), invitation actions (sent, declined, revoked), and report exports (access review and audit log) — alongside the memory and file activity introduced in the previous release. The Event filter shows all new grouped types; each entry reads as a plain-English sentence in the feed.
The Change history view in Audit & Governance now shows who changed what across your team's shared spaces — covering both memory and file activity — filterable by person, event type, space, and date range, and exportable as CSV. Rows for deleted users still show who made the change, pulled from the audit trail's denormalized metadata. Activities that came through the MCP server (Claude and other agents) are labelled "via Claude" in the Who column.
Access review is now a single filterable list — filter members by space, role, and status or search by email; a per-space column set (Role · Since) appears when you pick a space from the dropdown. Pending invitations appear inline as rows instead of a separate section. The external/privileged/stale flags bar, flag chips, and expand/collapse are removed.
The memsprout onboarding guide now opens with an intent gate that identifies whether you are a team lead setting up a new Space, a team member who was invited to an existing one, or an individual building a personal vault — and routes the entire flow accordingly. Before any structural question is asked, a brief Spaces ▸ Topics ▸ Memories hierarchy diagram is shown so every choice makes sense. Team leads get a focused team-and-project discovery step that proposes three to five Spaces (team-axis first), a personal-vs-org truth check at every candidate memory (under-share by default), and a wire-in step that leads with the spread value and lets them decide without pressure. Team members are first checked for their role in the invited Space — viewers get orientation and assistant wiring only, with no contribution prompts; editors and owners get the full flow including an offer to contribute org-worthy knowledge they hold. Individuals get a personal vault that prefers the General topic and proposes a handful of starter memories mined from their recent areas of focus rather than starting blank. The gather step now explicitly mines the agent's own stored memories as its first lane across all personas.
The homepage comparison table now labels Claude's column "Claude-native memory" instead of "Claude team memory", since Claude has personal/native memory only and no shared team memory.
When the deploy-recover pipeline routes a failure to a new fix ticket, it now explicitly closes the originating ticket with a cross-link comment ("Deploy failure handed off to #M"), so it no longer lingers open indefinitely with status:deploy-failed. For transient failures, the status:deploy-failed label is now removed before the re-run is triggered, preventing a race where the re-run's success path could leave the issue double-labeled.
When a deploy fails, the pipeline now automatically diagnoses and routes it: transient failures (network timeouts, registry blips) are re-run immediately with no human intervention; code or build errors open a ready-to-build fix ticket; migration conflicts are triaged as either auto-fixable (routine timestamp collision) or human-gated (potentially bad SQL or partial schema drift). Each issue gets one automated recovery attempt before the pipeline hands off to a human, so the factory stays moving without looping forever.
The memsprout onboarding tool (vello-mcp-v2) was broken since PR #401 — the Deno bundler failed to parse onboarding.ts because triple-backtick code fences inside the template-literal prompt string were closing the string early. The two fences are now escaped so the file parses correctly and the edge function deploys successfully again.
The pricing section on the marketing page now shows a third card for Enterprise alongside Individual and Team. Clicking "Contact us" opens a small form — name, company, work email, and message — and routes the inquiry to sales@memsprout.com via Resend, with no email client required.
Any org owner can now manage team roles and access billing — ownership is a trust level shared equally across all owners, not tied to the account founder. The billing owner's founding row remains permanently immutable in the DB; all other display distinctions (the "co-owner" label) have been removed.
During onboarding, the agent now renders its proposed workspace as a side-by-side column grid — one column per Space — each showing the Space description and a flat topic list. The segmentation question ("does this split make sense?") is front and center, so it's easy to see at a glance how your knowledge would be divided before anything is written. Edits are conversational: just say "rename X", "merge these two Spaces", or "add a topic" and the agent adjusts the preview before building anything.
Space owners can now create, rename, and delete Topics via the MCP tools create_topic, update_topic, and delete_topic. Editors retain the ability to store memories and assign them to existing topics, but only owners can reshape a Space's taxonomy — preventing unintended structural changes by members without full access. The distinction is enforced at both the application layer (clear error messages) and the database layer (owner-only permission check on each RPC).
The onboarding guide now checks, as part of the initial Orient phase, whether the team already has a structured internal knowledge base — a wiki (Notion, Confluence, Coda, Tettra, GitBook, SharePoint), a shared doc repository, or an existing memsprout Space. When one is found, the guide names it, shifts to an import-first strategy (treating the KB as the primary source rather than starting from scratch), and abbreviates the interview to fill only the gaps the KB doesn't cover. If the existing KB is a memsprout Space, the guide searches it first and raises the dedup threshold to avoid near-duplicate captures.
The memsprout onboarding guide no longer leads with developer-native concepts. Orient question 3 now surfaces your assistant and connectors first (before asking about context files), Lane B leads with shareable docs (brand guides, SOPs, strategy memos) and treats dev-specific file lists as a secondary note for dev environments, and the section formerly titled "Harvest" is now "Bring in their context." All eight uses of "harvest" / "harvested" have been replaced with "gather" / "gathered" throughout the prompt and tool description — the language is now equally legible to marketers, consultants, and ops teams as it is to engineers.
Owners and admins can open Settings → Audit & governance → Access review to see, for one team at a time, who can reach each shared space and at what level — with external members, privileged members, and stale invitations flagged. The full grant list is downloadable as a dated CSV.
The Access review card in Settings now reads clearly as a link: it lifts on hover, shows a quiet arrow, and picks up a keyboard focus ring. The section is also retitled Audit & Governance.
Settings: member-only team cards are now cleaner — they show the org name, your role badge, and just the plan type ("Team" or "Individual") with no pricing, and the "Billing and members are managed by the org owner." note has been removed. Pricing and billing copy aren't relevant to plain members.
The Teams settings tab is now visible to every signed-in user, not just org admins and owners. Members see each org they belong to with its name, plan, and their role, along with a note that billing and the member roster are managed by the org owner. Full management controls (roster, roles, billing, invoices) remain exclusive to org owners and admins.
The onboarding guide no longer displays stray & characters in MCP clients that render tool output as HTML. Section headings and cross-references now use standard markdown, which displays cleanly in every AI assistant.
Pressing Enter on the memsprout MCP authorization page (the login screen shown when connecting an AI client like Claude Code or Cursor) now submits the form correctly. Previously, switching to the Password tab or advancing to the email-code entry step left the form unresponsive to Enter key because the browser's implicit-submission algorithm was blocked by a disabled button earlier in the page's DOM order.
Settings: the Teams tab is now hidden from members and shown only to org admins and owners.
Onboarding now creates your Shared Space on demand — no more switching to the web app mid-setup. When you seed a workspace, the agent confirms the name and creates the Space over MCP, then captures straight into it, so the whole flow runs end to end in your assistant.
You can now create a Shared Space directly from your AI assistant (via MCP), so onboarding can set up your team's Spaces without leaving the chat. The new create_space tool handles org resolution automatically — if you belong to exactly one organization it picks it for you, and it gracefully blocks creation when there's no active subscription. Calling create_space with the same name twice is safe: if the Space already exists, the existing one is returned unchanged.
A new "Audit & governance" section appears in Settings for owners and admins of team orgs, giving managers a dedicated home for org-wide oversight. The section opens with two upcoming features — Access review and Change history — that will fill in as they ship.
Leaving a shared space no longer drops you on a 404 page — you are now returned to the main app home after leaving successfully.
The Teams section is now hidden from the Settings sidebar for users who are plain members of an org (covered by the org's plan but without owner or admin access). Navigating directly to /app/settings/teams as a plain member redirects to Account settings. Owners and admins continue to see and use the Teams page as before.
Team owners can now promote any member or admin to a co-owner role, giving them full team management rights (add/remove seats, change member roles, update org settings) without sharing billing access. Billing — payment method, invoices, and plan cancellation — remains exclusively with the founding account owner, and co-owners see a quiet note in its place.
Starting a free trial no longer fails with a duplicate-key error for accounts that already had a space. Creating a shared space now requires a billing account to exist first — if none is set up, you'll see a clear prompt to choose a plan before continuing.
AI clients can now move any memory to a different space using the new move_memory tool. The memory's id, full version history, creation date, and all attached assets travel with it automatically. Space editors (not just the memory owner) can move memories between shared spaces; only the owner can pull a memory into their personal vault to prevent silent visibility loss. The tool returns pre-move notices whenever a move reduces access — including a count of members who will lose visibility — so the AI can inform the user before acting.
memsprout now has a guided onboarding you trigger right from your AI assistant — just ask it to onboard or seed your workspace, and it runs the new memsprout_onboarding tool. It harvests the context you already have — from your assistant's own memory, your context files (CLAUDE.md, AGENTS.md, .cursorrules), your connected tools, and a short interview about your team — and turns it into organized Memories in a Space, deduped and with provenance. It then shows the value back immediately (the connections only unified memory reveals) and offers to wire your tools to use memsprout alongside your existing context files in every future session — one shared memory the whole team's agents can read and grow.
The MCP OAuth authorization page (shown when connecting an AI client like Claude) has been restyled to match the memsprout design system. It now uses the Geist typeface, the cool OKLCH neutral color ramp, moss-green action elements, and hairline-border inputs — matching the visual language of the main app. Dark mode is also supported via the OS preference.
Settings now has a sticky side nav — Account, Teams, Appearance, and Agent — instead of one long scroll. Plan, billing, and team members are unified on a single Teams page, where you can manage your card, see invoices, add or remove members, and start a brand-new team of your own.
Team owners and admins can now change a member's role between Member and Admin directly from the Teams page — no need to remove and re-invite. A small inline role selector appears next to each non-owner member; the owner's role remains fixed. No billing change occurs on a role switch, since both roles occupy the same seat.
The Plan & billing page now has proper page spacing, and adding a card uses a compact single-line card form instead of a tall checkout block.
You can now add or update your card, see your invoices, and cancel your plan right inside memsprout — no more trip to an external Stripe page. Card details are entered securely through Stripe's embedded form.
Starting a free trial now happens right inside memsprout — pick Individual or Team on the billing page and your 14-day trial begins immediately, with no redirect to an external payment page. The billing page also got a cleaner layout.
The list_spaces MCP tool now includes the owning team name alongside each shared space, so agents can tell at a glance which organisation a space belongs to. The team name is shown as · team: <name> on each space line when the caller has access to that org; spaces without a visible org (cross-org guests, or personal-space-linked entries) continue to display without it.
The billing page now shows when your free trial ends or your plan renews — a Stripe API change had been leaving that date blank.
The billing page now lists only the teams and plans you actually have a billing relationship with, instead of prompting you to "start a free trial" for an empty personal workspace you never set up. Your individual plan is created only when you actually need it (start one, or make a space that's just yours).
Every shared space now belongs to a team, and the space shows which team it's under so the context is always clear. When you create a space and you're on more than one team, you pick which team it belongs to; otherwise it uses your own. Your private personal space stays private — never attached to a team or visible to team admins.
Team owners and admins can see their team's spaces, and the owner of an older unassigned space can place it on a team.
list_topics now accepts an omitted space_id and resolves it to your personal space automatically (via ensure_personal_space()), so personal-space topics are reachable over MCP without knowing or copying any id. list_spaces now ends with a short note explaining that the personal space is not a shared space and is reached by omitting space_id — so agents and users no longer get stuck when personal topics aren't visible in the spaces list.
Personal Memories are now correctly identified by their personal-space UUID rather than a null space_id across all surfaces: the scope labels on the All Memories feed, Asset detail, Insight detail, and Search palette all render "Personal" correctly for both legacy null-space rows and post-migration rows stored with the personal-space id. MCP store_memory and the move_memory RPC no longer write null space_ids for personal captures — they resolve the caller's personal space first so every Memory lands in a real space row with proper membership-based access control.
Personal Memories now correctly show "Personal Space (private)" in the Space field of the Memory detail view instead of a blank selector. Moving a shared Memory back to Personal Space now targets the real personal space row rather than writing a null space_id.
Opening a Topic now loads all of its Memories from the server (scoped to that topic's ID), so the list you see always matches the count shown on the Topic card — no more silent truncation when a Space holds more Memories than the page's previous load cap. The "All Memories" total on the Topics overview also now reflects the true count of every Memory in the Space, not just the most-recently-updated slice.
Two migrations sharing the same 20260621000003 timestamp caused one to be rejected when pushed to the database. This release ships a new migration that applies the missing move_memory fix from issue #283 (destination-space membership guard, topic reassignment to the General Topic on move) on top of the updated_at fixes from issue #302, ensuring all metadata-only RPCs leave updated_at unchanged and that moving a Memory into a shared Space lands it in a valid Topic bucket.
A memory's "updated" date now reflects only real edits to its text, title, or tags — reassigning a topic, changing its type, or moving it between Personal Space and a shared space no longer alters the date. The correct "updated" dates have been restored for memories that were affected by recent type-classification and topic-assignment operations.
When viewing a personal-space memory as its owner, the Space metadata field now clearly shows "Personal Space (private)" instead of rendering blank. Owners can still move the memory to a Shared Space using a dedicated "Move to a Shared Space…" selector that appears below the label.
Space owners can now invite people as owners, not just editors and viewers — spaces can have more than one owner. The invite dialog already offered this option; a database constraint was the only thing blocking it.
Memory type (Decision, How-to, Standard, Fact, Event, Note) is now decided by the AI for every capture where you haven't set a type explicitly. The old keyword-matching classifier has been removed — if the AI is unavailable, captures fall back to Note rather than making a potentially wrong guess.
Change a Memory's type in one click, right from the memory — no need to open the full edit form. The type chip now shows a "Change" button for owners; clicking it swaps in a compact picker that saves and collapses the moment you choose a new type.
You can now set a Memory to any of the six types (Decision, How-to, Standard, Fact, Event, Note) from the edit drawer, and a type you choose by hand sticks — the classifier won't overwrite it. Previously, editing a Memory's type to How-to, Standard, Event, or Note was silently ignored because the REST handler still checked a legacy four-type list. Creating a Memory with an explicit type now also marks it as a human override so automatic reclassification leaves it alone.
The memory type system has been updated from four legacy types (decision, asset, fact, context) to six named types — Decision, How-to, Standard, Fact, Event, and Note — plus an Auto state that lets the backend classify the memory. The composer and New Memory dialog no longer show a flipping predicted label ("Auto · Fact") on every keystroke; the button simply reads "Auto" while no explicit type is chosen.
Memory types are now richer and more accurate — six kinds (Decision, How-to, Standard, Fact, Event, Note) replace the old four, and the MCP store_memory tool now returns the resolved type in its confirmation so agents see exactly how each memory was classified. Filtering by type in list_memories now works correctly — it was previously filtering the wrong column against a retired vocabulary and returning nothing useful.
memsprout now supports six memory types — Decision, How-To, Standard, Fact, Event, and Note — replacing the original four (Decision, Asset, Fact, Context). A new type_origin field tracks whether a type was set by AI during capture or chosen by you, mirroring the same provenance model used for topic assignment. Existing memories previously classified as Context or Asset have been migrated to Note automatically.
Fixed a bug where moving a Memory from one Space to another caused it to disappear from the destination Space's Topics grid. The Memory was still present in the flat "All memories" feed, but the Space page's per-Topic buckets only show Memories whose Topic belongs to that Space — so a Memory carrying its old Space's Topic fell into no bucket. Moving a Memory to a Space now automatically places it in the destination Space's General Topic. Moving to your personal vault clears the Topic assignment entirely, as the personal vault has no Topics.
memsprout now has paid plans: an Individual plan at $10/month and a Team plan at $15 per user per month, each starting with a 14-day free trial. The Team plan puts the whole team on one bill that the owner controls — you add members and cover their seats, while they just get access.
A new Billing page (under Settings → Billing) lets organization owners and admins see their plan, trial status, and seat count, start a subscription, or open the Stripe customer portal to manage their card and invoices.
Team owners and admins now have a Team members page (Settings → Team members) to add and remove people on their team. Adding someone takes a seat and adjusts the bill automatically (prorated); new teammates get an email invite to join.
Billing is now enforced: once your free trial ends without an active plan, memsprout asks you to start a plan before continuing — you can still sign in and reach the Billing page to subscribe. Joining a shared space requires an active plan or trial, or for a team admin to add you to their team.
Rebuilt the public homepage as a dark-mode-first, conversion-optimised page. Replaced the features-list layout with a hero → proof moment → value beats → social proof → pricing flow. Drops the "how it works" process breakdown and the parallel hero CTA in favour of a single primary action and outcome-framing value beats.
The signed-out homepage is redesigned as a real go-to-market page. It opens with the team-AI-context story and shows it in action — a live-looking MCP call pulling a team's shared memories into an agent — then makes the case the old page never did: which AI tools it works with (Claude Code, Cursor, Copilot, ChatGPT, any MCP client), the problem it solves, how it works in three steps, a side-by-side comparison with the alternatives, the trust and governance it gives teams, and pricing. Same calm look and feel, in both light and dark.
Removed the crown icon that appeared next to spaces you own in the sidebar, and removed the icon from the Owner role badge on space pages. The "Owner" label remains; only the iconography is gone.
Fixed uneven topic card heights in the Shared Space grid so cards in a row align to equal height with bottom-aligned footers. The "updated" timestamp and contributor meta now sit flush at the bottom of every card, giving the Topics grid a clean, consistent look regardless of how long each Topic's description is.
A migration that moved 842 memories into your Personal Space accidentally stamped them all with today's date as their "last updated" time, making your entire knowledge base appear to have been edited moments ago. This release restores each memory's true content-edit date and prevents the same mis-stamping from happening on lazy migration calls going forward.
The new-space setup wizard's invite step now offers the Owner role alongside Editor and Viewer, closing the gap left by issue #230. The invite subtitle copy has been updated to reflect all three roles.
The Personal Space header now shows a "Settings" button in the same position as other spaces — making it easy to find alongside the space title, instead of buried in a small eyebrow link. Space ownership is now consistently marked with a crown icon everywhere it appears: the sidebar marker and the Owner role badge in space headers and settings.
The What's new page is now a single page linked from both the public site and the app, and the in-app duplicate and the Settings changelog link were removed.
The Personal Space now has a Settings page accessible via a "Settings" link in the Personal Space header. From there you can rename the space, edit its description, and manage Topics — create, rename, merge, and delete — with the same full UI as Shared Spaces. Members, Invite, Archive, and Leave are intentionally absent; those controls are not applicable to the personal vault.
Personal Space memories were hidden after the #233 upgrade: Topic cards showed the correct memory count (e.g. "57") but opening a Topic listed nothing. The cause was a missing acceptance timestamp on the personal vault membership row — the security check that gates direct memory queries requires it, while the count-returning RPCs bypass it. This migration backfills the timestamp on all existing personal memberships and updates the provisioning function so new users are never affected.
The sun/moon theme-cycle button at the top of the sidebar showed a tooltip ("Theme: light/dark/system") on hover, but the tooltip appeared above the button and was completely cut off by the top edge of the viewport. The tooltip now appears below the button where it has room to display.
The "Forgot password?" link on the password sign-in form was too close to the "Sign in" button above it due to a negative top margin. It now has clear, comfortable spacing so the two elements are visually distinct and easy to read.
Auth emails (sign-in, signup confirmation, password reset, invitation, email change) now use the memsprout calm-infrastructure aesthetic: cool slate-toned colors, system-ui body font, SF Mono signal layer, and a clean white card on a light cool-gray background — replacing the retired editorial-broadsheet palette. Password reset and email-change emails no longer show a 6-digit OTP code, which was surfaced by accident and is not useful outside of MCP OAuth flows. All email subjects updated from "Vello" to "memsprout".
The personal home (/app) now treats the personal vault as a real space row (kind='personal') in the database, giving it full topic management parity with Shared Spaces. A new ensure_personal_space() RPC lazily creates the personal space row on first visit and backfills any legacy null-space topics and memories into it. The personal home now shows a gear button on each non-General topic card; clicking it opens a "Manage topic" dialog with Rename, Merge into, and Delete panels. Deleted topics reassign their memories to General automatically. A new kind column on the spaces table ('team' / 'personal') gates the shared-spaces sidebar and the MCP list_spaces tool to team spaces only, keeping the personal vault private. The MCP store_memory tool resolves the personal space via ensure_personal_space() instead of the former ensure_personal_general(), and update_memory, list_memories, and search_memories all accept an optional topic filter parameter. The migration is additive (Migration A); a separate backfill migration (Migration B) drops the legacy personal-only RPCs and RLS policies once all users have been lazily migrated.
When inviting someone to a Space, the Role dropdown now includes "Owner — full access, can manage the space" as a third option alongside Editor and Viewer. Owners can also promote any existing Editor or Viewer to Owner directly from the Members tab. Once a member holds the Owner role, no further role-change controls appear for them — preventing ownership conflicts.
The homepage now leads with memsprout's team story: a sharper headline, a problem section explaining the cross-functional context gap, and a refreshed how-it-works that ends on "Connect" with the MCP endpoint.
New Memories captured through the web app are now correctly auto-assigned to a matching Topic in your Personal Space — the previous web capture path was querying a stale location and assigning nothing (MCP captures via Claude were unaffected). The auto-assignment decision rule is now stricter: a Memory only moves to a Topic when it scores well above the runner-up, preventing ambiguous captures from being arbitrarily pinned to a near-tie winner. Memories that fell to General by default are now reconsidered when you rename or re-describe a Topic, so improving a Topic's description actually pulls in relevant General members. Editing an auto-assigned Memory also re-runs the assignment check so the topic stays current with the new content. The Topic description placeholder in both Personal Space and Shared Space settings has been reworded to "What belongs here — new Memories are matched to it by similarity" — removing the inaccurate "AI classifier" framing.
The public homepage now shows pricing tiers (Personal free, Team and Team+ coming soon) so visitors know what the product costs before signing up. A social-proof quote and a repeated call-to-action were added below the how-it-works section to give the page a clear conversion arc.
The Settings page is now organized into four labeled groups — Account (Profile, Password, Sessions), Appearance (Theme), Agent (Connect, Instructions), and More (Changelog) — replacing the previous flat list of seven ungrouped cards. The ownership icon on space entries in the sidebar has been changed from a shield to a key, which reads more clearly at small size. System theme now correctly follows OS-level dark/light preference changes in real time: if your OS switches to dark mode while memsprout has "System" selected, the app theme updates immediately without requiring a page reload.
On the OAuth/MCP authorization screen, typing your email and password and pressing Enter would silently email you a 6-digit code and drop you on the code-entry screen instead of signing you in. Clicking "Sign in & approve" always worked; only the Enter key was broken. The fix disables the inactive submit buttons so implicit form submission fires the correct action for whichever tab and state is active. The "No Vello account found for that email" error copy is also corrected to "No memsprout account found for that email."
Sign-in now works reliably across all three paths. Clicking a magic link no longer loops back silently to a blank sign-in page — expired or already-used links show a clear "Sign-in link expired or already used" message instead. Password sign-in correctly reports "email not confirmed" when an account hasn't been verified yet, with a one-click "Resend confirmation email" option. A new "Forgot password?" link in password mode triggers a reset email via Resend. Magic-link emails sent for plain web sign-ins now contain only the clickable button — the 6-digit OTP code is included only when connecting an MCP client through the OAuth consent screen, where you actually need to type it in.
The feature that places a new Memory into the best-matching Topic was called "auto-filing" — a leftover from older filing-cabinet language that never fit. It's now auto-assignment everywhere it's visible: the capture confirmation reads "Assigned to [Topic]" (was "Filed to"), the Topic card's agent-placement badge reads "N auto-assigned" (was "N auto-filing"), the New Memory destination option is "Auto-assign" (was "Auto-file"), and the Topic-description helper text refers to auto-assigning. Behavior is unchanged — same embedding-similarity matching, same sticky human assignments. Under the hood the edge-function helpers and the topic-card metadata column were renamed to match (auto_filed → auto_assigned); a migration recreates the two topic-list RPCs with the new column name. The topic_origin provenance values (auto / human) are untouched.
Searching your memories would sometimes come back empty even when you had clearly relevant memories saved — and a moment later the same search would work fine. The cause was the embedding service occasionally routing a search to a substitute provider whose output wasn't comparable to your stored memories, which quietly produced zero matches with no error. Searches are now pinned to a single provider so a query and the memories it's matched against always speak the same language.
Memory "updated X ago" labels and All Memories feed ordering were wrong for most existing memories — showing the time of a background data migration rather than the actual last edit. The root cause was an overly broad database trigger that recorded every internal update (topic assignment, embedding refresh) as a content edit. The trigger has been tightened to only advance the timestamp when title, content, or tags actually change, and a one-time restore pulled every affected memory's timestamp back to its true edit time from append-only ledgers.
Members can now leave a Shared Space from space settings — the "Leave space" button appears on the caller's row in the Members tab, with a confirm step and a disabled state for the last owner. This ships the web layer that was missing from #198.
Connecting Claude (Desktop or claude.ai) to the custom domain failed with "Authorization with the MCP server failed." Tracing the live OAuth flow showed Claude completing the whole handshake — discovery, registration, login, and token issuance all succeeded — and then silently giving up before making a single authenticated call. The trigger was the bare-domain server URL: Claude's connector aborts after token exchange when the OAuth resource is an origin root, but works when it has a path (which is why the raw edge-function URL always connected). The MCP server now lives at a path, https://mcp.memsprout.com/mcp, so it behaves like any conventional MCP endpoint. Reconnect using the /mcp URL. The bare-domain and legacy vello-mcp.matteo-3bc.workers.dev URLs keep working for already-connected clients.
Members who have accepted an invite to a Shared Space can now leave it themselves from the Members tab in Space settings — no need to ask the owner to revoke access. The last remaining owner is blocked from leaving (to prevent orphaned spaces) and is shown an inline note to transfer ownership or delete the space first.
The New Memory button in the sidebar now opens a modal dialog instead of navigating to your Personal Space. You can capture a Memory from any page — a Space, All Memories, Settings — without losing your place. The dialog lets you pick the destination (Personal Space or any Shared Space), optionally assign a Topic, and set a type, with the same type-pill affordance as the inline composer. A toast confirms where the Memory was filed. The ⌘N keyboard shortcut also opens the dialog when focus is outside a text field.
The Memory drawer's edit form now includes a Type selector so you can reclassify a Memory as Context, Decision, Fact, or Asset without leaving the drawer. The drawer itself is wider on desktop (680 px) to give long Memories room to breathe, and the Memory content is now height-constrained with its own scroll so the metadata and actions below it stay visible without needing to scroll the whole panel. The update_memory MCP tool also accepts a new optional type parameter so AI clients can reclassify memories in the same edit call.
Clicking a Memory was silently failing instead of opening its detail drawer — nothing happened and the console showed a cloning error. The drawer now opens reliably from every feed, and edits made inside it refresh in place as intended.
Clicking a Memory card anywhere in the app — Personal Space feed, Space feed, All Memories, or Search palette — now opens a 460 px right-side drawer that slides over the feed instead of navigating to a separate page. Every action available on the full page — edit, delete, move to a Space, assign a Topic, restore a version, attach or detach assets — works inside the drawer; dismiss with Esc, a backdrop click, or the × button. The URL still updates as each Memory opens, so deep links, refreshes, and shared URLs all render the full Memory page as before.
Every email memsprout sends — magic-link sign-in, signup confirmation, password reset, email-change confirmation, and Space invitations — now comes from a dedicated, properly branded template and is delivered through Resend instead of Supabase's built-in mailer. The look matches the app: warm paper, editorial type, the memsprout mark.
Space invitations also got better: when you invite someone who already has a memsprout account, they now receive the same branded "You've been invited to
Three small fidelity fixes. Free-text tags are now fully gone from the UI — type retired tags as a concept, and this clears them from the last places they still showed up: Memory and Space capture and detail, plus the asset and insight detail views. The composer's attach control is now a compact "Attach" chip (paperclip + label) instead of a full drop box, matching the design; drag-and-drop still works, and the dedicated upload page keeps its large dropzone. And Space Owners can now rename a Space: the Space settings → Details tab has an editable Space name field alongside the description, saved together with one Save changes button.
The sidebar now earns its keep. Each Shared Space shows a live Memory count and an Owner shield when you own it, and Spaces you've archived collapse into an "Archived" disclosure at the bottom of the list instead of disappearing. A new All Memories item sits above your Shared Spaces — it opens a single feed of every Memory you can read across your Personal Space and all your Shared Spaces, newest first, with the same Type filter used elsewhere and a scope marker on each card. And any Memory you own can now be moved: the Memory detail page gains a Space control that promotes a private Memory to a Shared Space (so your team and their agents can build on it), moves it between Spaces, or pulls it back to your Personal Space. The sidebar footer also grows two new affordances: a prominent New Memory button that drops you straight into your Personal Space composer, and a What's new item that opens this changelog inside the app.
Your Personal Space is supposed to open on Topic cards, but it was coming up empty — because personal Topics could never be created. The Topics table required every Topic to belong to a Shared Space, so the personal-Topic path (and the auto-filing behind it) had been silently failing. That's fixed: personal Topics are now allowed, every account gets a General Topic, and existing personal Memories are filed into it — so the Topics overview renders instead of showing nothing. Separately, the deploy pipeline now applies database changes that arrive out of order instead of stalling, which had quietly left one earlier change unshipped.
Space Owners get a new Insights tab: weekly sparklines of Memories captured and recall (how often Memories are opened from search), with week-over-week deltas; how many Topics are active; your fastest-growing Topics; Topics that have gone quiet; and your most-recalled Memories. It's all computed from existing activity — nothing new to turn on — and visible only to Owners.
The Memory detail page now surfaces a Version history section. Every edit already snapshots the prior text into a version ledger; that history is now visible as a newest-first timeline — the current version is marked, and each past version shows its version number, when it was saved, and a snippet of its text. Owners can restore any past version with one click (behind an inline "Restore to v{n}?" confirm). Restoring archives your current text into history first, so nothing is lost, then re-applies and re-embeds the chosen version so search stays accurate. When there are no edits yet, the section explains that history starts after the first change.
A global search palette is now a keystroke away. Press ⌘K (Ctrl+K on Windows/Linux) — or click Search in the sidebar — to open a command palette that searches the titles and previews of every Memory you can see, across your Personal Space and all your Shared Spaces. Results are grouped by Space, with your Personal Space first, and each row shows its Space, Topic, and when it was last updated. Use ↑/↓ to move, ↵ to open, and Esc to close.
Your Personal Space now opens on its Topics, just like a Shared Space — a searchable grid of Topic cards. New captures auto-file into the best-matching personal Topic (or your General Topic), and you can create your own Topics to organize private work. After you capture, the composer confirms where it landed — "Filed to [Topic]" — with a one-click way to change it.
A Shared Space now opens on its Topics, not a tabbed settings screen. The landing is a searchable grid of Topic cards — each showing how many Memories it holds, description, latest capture, and who's been filing into it (including how many an agent auto-filed). Open a Topic to read and capture only within it (a Memory you add there is filed into that Topic), or hit "All Memories" for the flat feed. Type filters and the per-memory Topic reassign carry over. Everything administrative — Details, Topics, Members, and an Owner-only Insights tab — now lives on a dedicated Space settings page reached from the header.
The capture box now starts as a quiet "Add a Memory…" row that expands when you click it (and collapses after you capture). Shared Space headers now show your role with a clear badge — Owner, Editor, or Viewer — and new members get a short "Getting started here" card. Viewer access is now spelled out where capture isn't available, Owners are marked with a shield, and your own row shows a "You" tag. Copy tightened throughout.
memsprout now lives on its own domain: the app at memsprout.com, the MCP server at mcp.memsprout.com, and sign-in/authorization at auth.memsprout.com. The connect guide now shows the mcp.memsprout.com server URL. Existing connections on the old *.workers.dev / *.pages.dev URLs keep working as permanent aliases — the MCP server's OAuth discovery is host-derived, so already-connected agents are unaffected.
Every Memory now has a type — Decision, Asset, Fact, or Context — that says what kind of content it holds, shown as a chip on every card and the detail view, and filterable in both your Personal Space and Shared Spaces. Type is auto-classified the moment a memory is captured (by you or an agent via MCP — store_memory takes an optional type), and you can override it. The personal feed now also shows each memory's Topic. With type doing the "what kind of thing is this" job and Topics doing the grouping, free-text tags are retired from capture and the UI.
A new look and a new name. The product is now memsprout — the shared AI-context layer for teams. This ships a fresh design system (Geist typography, a calm cool-neutral palette with a Moss green accent, and a reserved violet that marks anything captured by an AI agent), a light/dark theme toggle, and a rebuilt component set across every screen. Each Memory now shows quiet provenance — who captured it, you or an agent. New Owner setup: a guided checklist and a space-setup wizard that takes you from zero to a Shared Space with Topics and invited teammates. The product's internal database schema was also renamed end-to-end; existing AI-client connections keep working unchanged.
The MCP connect guide on Help and Settings now shows the dedicated proxy URL (vello-mcp.matteo-3bc.workers.dev) as the single canonical server address — replacing the internal Supabase function URL that spec-strict clients like mcp-remote couldn't use for OAuth. Two new connection sections have been added: step-by-step instructions for Claude Code CLI (claude mcp add --transport http) and a ready-to-paste mcp-remote config snippet for clients that only support local stdio servers.
Patches two database migrations from issue #144 that failed to apply. The update_memory RPC was blocked because PostgreSQL treats a parameter-list change as a new overload, leaving an ambiguous GRANT; the fix drops the old 5-param signature before replacing it and uses a fully-qualified grant. The match_memories rewrite was at risk of a return-type-change error (new topic_id column); the fix drops and recreates that function cleanly. Migrations 3–6 from the #144 batch can now apply in sequence.
The /app/upload page now correctly handles ?memory_id= links generated by the MCP tool get_upload_link. Previously, uploading a file through an MCP-generated link would land the file in storage but leave it unattached — no entry in memory_assets was created, silently breaking every AI-client upload flow that relied on the auto-attach contract. Files uploaded via a ?memory_id= link now attach to the memory through the edge function REST API, matching how the memory detail page attaches files. Legacy ?thought_id= and ?insight_id= links continue to work unchanged.
The Vello MCP server now speaks one language: memories. The 17 legacy thought/insight tools are retired (everything they captured has been folded into memories, including records created since the June 9 unification), memories gain full version history with change notes, file attachments now target memories directly, and search/list default to everything you can read instead of personal-only.
The MCP server is now also served from https://vello-mcp.matteo-3bc.workers.dev — a Cloudflare Worker that proxies every request to the vello-mcp-v2 edge function. This fixes mcp-remote (and any spec-strict MCP client) failing at the token-exchange step with an opaque ServerError: those clients re-run OAuth discovery at the origin root of the server URL, and on *.supabase.co the root /.well-known/* paths belong to Supabase's gateway, so discovery failed and the token request went to the wrong URL. When connecting through the new origin, the OAuth discovery documents and WWW-Authenticate breadcrumb advertise the proxy origin, so every discovery path resolves. Existing claude.ai connectors pointed at the supabase.co URL are unaffected. To connect Claude Desktop via mcp-remote, use the new URL: npx -y mcp-remote https://vello-mcp.matteo-3bc.workers.dev.
Adding Vello as an MCP server via mcp-remote was silently failing before the OAuth flow could start. The MCP client validates the server's OAuth discovery document and requires a jwks_uri field — we were omitting it. The discovery document now includes the correct JWKS endpoint, letting the OAuth handshake complete and mcp-remote connect successfully.
On entering a space, all topic chips now appear selected by default so memories are immediately visible. Memory detail pages now show which topic a memory belongs to, with a one-click control to change it. Removed outdated language throughout.
Internal migration fix: the backfill query that seeds a General topic into every existing space referenced deleted_at on vello.spaces, but that table uses archived_at for soft-delete. The corrected column name allows migration 000002 to apply cleanly.
Patches the database migration for the General topic (#130) so it applies cleanly. PostgreSQL's CREATE OR REPLACE cannot change a function's return type, so the migration was blocked at apply time — adding is_general to the list_topics_for_space return set hit error 42P13 and rolled the whole migration back. The migration now drops and recreates that function, clearing the blocker and allowing the General topic to go live.
Spaces now automatically include a General topic that catches miscellaneous memories — replacing the Unfiled bucket with a real, named topic. All existing space memories have been auto-filed into General (with a backfill endpoint available to re-run the LLM classifier for better topic placement). The General topic cannot be edited or deleted, appears first in the topic filter strip, and the cap of 20 topics still applies to user-created topics only — General doesn't count. Topic management is accessible directly from the space view via the Topics & Settings link.
Clicking a memory in a shared space now navigates to the memory detail page. The Topics PR (#125) accidentally replaced the clickable link on memory rows with a plain div, so tapping a memory did nothing. The body text on each row is now an anchor pointing to /app/memories/[id], restoring the navigation that existed before the Topics feature landed.
Spaces now organize memories into Topics — a curated, per-space taxonomy with auto-filing on every save. Each Topic carries a short description that doubles as the classifier's instruction, so the AI files intelligently without a predefined vocabulary. Human assignments are always sticky and are never overridden by auto-filing. Hard cap of 20 topics per space (warning at 12) keeps spaces from fragmenting. Full topic management — create, rename, merge, delete — lives in Space Settings.
Every agent reads Vello for shared context at the start of a run, but a broken connection (empty/invalid JWT, Supabase down, dead MCP edge function) used to pass silently — the agent just ran context-blind. All 11 Vello-using workflows now preflight in the JWT-mint step: they verify a token actually minted and that the vello-mcp-v2 endpoint is reachable, and hard-fail the run (which posts an in-thread failure notice) on a real outage. A reachable endpoint that returns a 4xx only warns, so transient handshake quirks don't false-alarm.
Storing a memory failed for every client with new row for relation "activity_log" violates check constraint "activity_log_entity_type_chk". The unified-memory RPCs log activity as entity_type='memory', but the activity_log entity_type check constraint was never extended past ('insight','thought') when memories were introduced — so every store_memory/update_memory/delete_memory/move_memory aborted. A new migration extends the constraint to allow 'memory'. ⚠️ Apply manually: supabase db push (or run supabase/migrations/20260609000004_vello_activity_log_allow_memory.sql); CI does not run migrations.
The six GTM (Atlas) and PRODUCT (Prometheus) agent workflows were wiring the Vello MCP server through an mcp_config: input that claude-code-action@v1 does not accept — it was silently dropped, so the mcp__vello__* tools never loaded and those agents couldn't search or store memory at all. They now write the MCP config to a file and pass it via --mcp-config, matching the pattern the core build/review/QA/respond/rework workflows already use. No user-facing UI change; the GTM and PRODUCT agents now actually participate in Vello memory as intended.
Memories no longer split into "raw" and "titled" categories in the UI — that was an implementation artifact, not a user concept. Untitled captures now display their first ~80 characters as a label, matching how Apple Notes, Bear, and Notion handle untitled items. The Raw/Titled filter tabs, kind badges, and two-mode composer language have all been removed.
The backfill migration that copies insights into vello.memories now handles insights whose body is empty (file-anchored records like uploaded PDFs). Previously the migration failed with a check-constraint violation; it now falls back to using the insight's title as the memory content when the body is blank.
The build, review, QA, respond, and rework agents now store a memory in Vello at the end of every run — not just in exceptional cases. Each agent records a concrete summary of what it did: decisions made, files changed, verdicts given, conflicts resolved, and anything a future agent should know when working in the same area. Agents also search the new unified memories store (alongside thoughts and insights) at the start of each run, so prior context is always consulted. This builds a growing, searchable institutional memory the whole pipeline learns from over time.
Thoughts and insights are now a single vello.memories entity. A memory with no title is a raw capture (equivalent to the old thought — personal-only, cheap, unfiltered). A memory with a title is a curated write-up (equivalent to the old insight). The home page composer is now a single-tab MemoryComposer; the feed shows "Raw" and "Titled" filter tabs instead of "Thoughts" and "Insights". Old /app/thoughts/:id and /app/insights/:id URLs redirect to /app/memories/:id once the backfill migration has been applied. Legacy MCP tools (capture_thought, capture_insight, etc.) remain working; the new default tool is store_memory. Four migration files are included in supabase/migrations/ — apply manually; CI does not run them automatically.
⚠️ After merging, deploy the edge function: supabase functions deploy vello-mcp-v2
When you mention @product or @gtm in a GitHub issue comment, those agents now immediately post a "Got it — thinking…" acknowledgment (just like @vello already did), then update that same comment with their full response rather than posting a second one. This means you get a visible signal within seconds that the agent is working, and the thread stays clean with one comment per invocation.
You can now attach a new file to a thought or insight without leaving the page. An inline uploader appears in the "Attached assets" section of both the thought detail page and the insight detail page — pick a file, and it uploads and links to the current record immediately, with the attached list refreshing in place. The existing "search to attach" picker for already-uploaded files remains alongside it.
A new get_upload_link MCP tool generates a Vello web URL your AI assistant can hand you when it cannot upload files directly — for example, in sandboxed or corporate-proxy environments that block *.supabase.co. You open the link in your browser, drop the file onto the focused upload page, and it is automatically attached to the target thought or insight. No configuration changes required on your end.
When you use the capture_thought MCP tool, the response now includes the thought_id of the newly created thought alongside its type, topics, people, and action items — matching the structured JSON already returned by capture_insight and promote_thought. You can use this ID immediately in follow-up tool calls (e.g. promote_thought, get_thought, attach_asset) without a separate lookup.
The build, review, QA, respond, and rework agents can now actually read and write Vello memory — searching prior thoughts and insights for context and capturing new ones as they work. They had silently lost that ability for two reasons: the MCP server was wired up with a setting the GitHub action no longer recognizes, and the connector it launches was pinned to a version that doesn't exist — so it never started and every memory tool was missing. As a bonus, when you mention @vello its "Got it — thinking..." acknowledgment now appears within seconds instead of after a setup delay, reliably updates the same comment with the final reply, and flips that comment to a clear failure notice if the run crashes.
When you mention @vello on an issue or PR, it now posts an instant "Got it — thinking..." acknowledgment within seconds so you know the agent is running. The agent then edits that comment in place with its final reply, so the thread stays clean. If the agent crashes mid-run, a follow-up failure notice is posted with a link to the action run.
When you navigate to an insight that belongs to a shared space, the breadcrumb at the top of the page now reads "← [Space Name]" and links back to that space — instead of always showing "← Home". Personal insights continue to show "← Home" as before.
Space editors who didn't originally create an insight can now call update_insight successfully — version history is recorded and the insight body is updated as expected. Previously the insight_versions RLS policy blocked the version-record insert for any non-author editor, even after ticket #40 fixed the insight row itself, forcing a destructive workaround of creating a new insight and superseding the old one. Note: the workaround applied during the original incident (insight 87e9c1c5 superseded by 3d5d39ee) is not automatically reversed — the new insight is live and fully editable.
When viewing insights in a shared space, you can now see who created each one — in both the insight list and the insight detail byline. Former members who have since left the space appear as "former member".
The Vello MCP server now exposes a file_bug_report tool so any connected AI agent can open a GitHub issue in the Vello repo on your behalf — title, description, optional steps to reproduce, and optional context. Issues are filed with the bug label and the tool returns the issue number and URL, so you never have to leave the conversation to report a problem.
The build pipeline now automatically detects merge conflicts on open PRs after any push to main. When a PR develops a conflict because an unrelated PR was merged, the pipeline queues rework without requiring a human nudge — as long as the 3-round rework budget has not been exhausted. The auto-rework budget counter is never touched by this automated trigger; only a @vello human nudge can reset it, preserving the runaway-loop guarantee.
The second tab in the Space view now reads "Settings" instead of "Members", better reflecting that it contains both member management and space-level controls.
Space descriptions are now shown in the Settings tab so all members can see them when they navigate to a space. Owners get an inline "Edit description" button that opens a textarea form — save with ⌘↵ or the Save button, clear the description to remove it entirely. The description is also still shown above the tab strip as before.
The build, rework, and QA agents in the automated pipeline now have a shared Vello account (agents@vello). Before each run, agents search Vello for relevant prior context from past builds. After a build or rework, agents write to Vello when they make a non-obvious judgment call or resolve a tricky error — so future runs can benefit from accumulated institutional knowledge.
All contributions — including manual, local, or hot-fix PRs — must be backed by a GitHub Issue and linked with Closes #N in the PR body. This gives the automation pipeline the hook it needs to run QA after deploy and track the status:* lifecycle labels. A bare issue ("manual fix: what and why") is enough to satisfy the requirement.
Fenced code blocks and inline code in insight bodies now display with readable dark text. Previously the background was overridden to the light paper cream while the text color was left at the typography plugin's light-grey default, making code near-invisible. Long lines in code blocks now also wrap instead of overflowing the container.
AI agents running in sandboxed environments (such as Claude Code with limited egress) can now upload files to Vello without needing to reach the Supabase Storage CDN directly. POST the raw file bytes as multipart/form-data to /api/upload on the MCP server URL; the endpoint writes the bytes to Storage server-side and returns a storage_path. Pass that path to attach_asset in mode 2 to register the asset and link it to a thought or insight. The existing inline base64 path (mode 3, ≤ 5 MB) is unchanged; the new endpoint handles larger files up to the 50 MB hard cap.
AI agents can now retrieve a single thought (get_thought) or insight (get_insight) directly by UUID — no search round-trip needed. This closes the gap where an agent holding an id (from a prior search result, a stored reference, or the source_thought_id backref left by promote_thought) had no way to pull the full record. get_insight also returns a version history summary so agents know how many revisions an insight has and what the latest change note says.
When an AI agent searches or lists your thoughts and insights, each result now includes the list of files attached to it — asset id, title, description, MIME type, and kind (image, document, audio, etc.). This closes the loop that was opened in ticket 6: an agent that finds a thought can now immediately see its attachments and act on them (call get_asset for a signed download URL, or detach_asset to remove one) without a separate lookup step. This unblocks the real-world case where a user uploaded an image and asked their AI assistant to find it.
When an AI agent searches or lists your thoughts and insights, each result now includes the object's UUID. This means an agent that finds a thought via search_thoughts or list_thoughts can immediately use its id to attach a file, update, promote, or delete it — without needing a separate lookup. The same applies to search_insights. This unblocks the case where an agent could describe a thought it found but couldn't act on it.
Deleting an insight or thought from its detail page used to fail with a database error. It now deletes cleanly and the item drops out of your feed (and can still be restored). The confirmation prompt was also reworded into plain language.
Connected AI clients gained three tools: move an insight between your personal vault and shared spaces (in place — it keeps its history, versions, attachments, and link), and soft-delete an insight or a thought. Deletes drop the item from search and lists right away and are recoverable by an admin.
You can now upload files to Vello from network-restricted AI clients — like Claude's sandboxed code-execution environment — that can't reach storage directly. Attach the file inline through the MCP tool call (up to 5 MB); every other client keeps using the existing signed-URL upload, which stays the right path for larger files.
A space's creator can now archive it from the space page (with a confirm step). Archiving hides the space and everything in it — including its insights, which stop showing up in search and lists everywhere. Nothing is deleted; an admin can restore it.
The signed-out homepage now explains Vello properly: the capture → promote → supersede lifecycle, why it's MCP-native, and how it fits alongside a team wiki rather than replacing it. Terminology is current too — it says "Insights" everywhere instead of the old "Notes".
The page you're reading. Vello now keeps a public changelog, and every shipped change from here on adds a short, plain-language note at the top of this list — so you can follow how the product evolves without reading the code.