Changelog

Everything that shipped.

Liberde is built in the open, in both editions at once — the hosted app and the self-host build get the same change on the same day. This is the whole list, newest first, including the things that were fixed because they were wrong.

4 Sep 2026
Everything reachable, and a check that keeps it that way

Agents

New

A named configuration you start a chat as: a model, standing instructions, a project's knowledge, the skills it always loads, and the connectors and custom tools it should reach for. Build one in Settings → Agents; start a chat as it from the chips under the greeting on a new chat.

A skill describes how to do a task and waits for one to match. An agent's skills are in force from the first message, because picking the agent already said what kind of work this is. Its model and project stay defaults — anything the conversation says outranks them, since switching mid-thread is deliberate.

Workspaces and the audit log got interfaces

New

Both features were complete and had no screen at all — no way to create a workspace, set a cap, add a member, read the log or verify the chain. They are now Settings → Workspaces and Settings → Audit log. The documentation had been describing them as though they had a home.

Semantic search no longer needs a second API key

Improved

OpenRouter serves an embeddings endpoint with the key you already have. The previous requirement for a separate provider rested on a belief that turned out to be wrong, written into a code comment and repeated in the docs. It is one switch now — a separate endpoint is still there for a local Ollama or LM Studio.

Comparing models on a thread with an image

Fixed

The picker offered models that cannot read an image, and when they failed the column showed the provider's raw JSON. Text-only models are now unselectable with the reason given, and every upstream error is reported as a sentence.

Agents did nothing on a self-hosted install

Fixed

The API and the database schema were there, but the self-host chat route never read them — so choosing an agent changed nothing at all.

The image model had to be typed by hand

Fixed

A typo in the model id became a runtime failure at generation time. It is a list of the models that can actually emit an image.

4 Sep 2026
Code that runs, and a home for everything you build

A code interpreter that runs in your browser

New

The model writes Python and runs it — real CPython with pandas, numpy, matplotlib, scipy and scikit-learn, loaded on demand from the code's own imports. Files you attach to the conversation are handed to it as real files, and anything it produces comes back as a download: a chart, a spreadsheet, a cleaned CSV. Charts appear inline. The kernel stays alive per conversation, so a follow-up question builds on the last result instead of recomputing it.

It runs in a sandboxed frame on your own machine — no sandbox service, no credentials, no per-run billing, and it behaves identically on a self-hosted install, which a hosted sandbox could never do.

An artifacts gallery

New

Every artifact you have built, and everything shared with you, in one browsable grid with previews, filters and full-text search across contents. Opening one of yours jumps to its conversation; opening a shared one clones an editable copy that leaves the original untouched. "Shared with you" used to be its own view — it is a tab here now, because two places to look for the same kind of thing is one too many.

A council verdict on second opinions

New

Run a question through several models side by side and a separate model now reads all the answers and writes a verdict: what they agree on, every place they genuinely contradict each other, and one consolidated answer you can keep in a click. Real conflicts of fact or recommendation are named rather than smoothed over.

Semantic search over project knowledge

New

Project files can now be searched by meaning rather than by keyword, so a paragraph that answers your question in different words is still found. Point Liberde at any OpenAI-compatible embeddings endpoint — OpenAI, a local Ollama, LM Studio.

Relevance is judged relative to the best match rather than against a fixed score, because embedding models do not share a scale and any absolute cut-off is tuned for exactly one of them. If the endpoint goes away, retrieval quietly returns to keyword matching instead of failing the chat.

Install a skill from a URL

New

Paste a link to any SKILL.md and Liberde fetches it for review — what it says, which tools it wants, and the lines worth a second look — before anything is written.

Reviewing first is the whole point. A skill is prose that enters the system prompt and that the model then follows, so taking one from a stranger's repository is closer to running their code than to opening their document.

Design systems that actually prescribe

Improved

A saved brand now carries icon rules alongside its palette, typography, spacing and voice, and every artifact built under one gets checked against it: colours outside the palette, fonts the system never named, and emoji used where an icon belongs are reported in the panel. It reports drift rather than blocking, because the check reads source text and a design system is a guide.

Real icons, everywhere

Improved

Emoji used as interface icons have been replaced with a single drawn set. Emoji render differently on every platform, ignore your theme, and cannot be sized or coloured with the rest of the interface.

Longer runs before the clock stops them

Improved

Long routes now run to 800 seconds rather than the 300-second default. A job that would still exceed it checkpoints and resumes on the next invocation, so a long plan survives the limit instead of racing it.

Gallery cards say what the artifact is

Fixed

Card previews were slicing the first few hundred characters of the source, which for an HTML artifact is a doctype and a stylesheet and for a React one is an import block — every card showed the same wall of custom properties. Previews now pull out the headings and prose a person would use to describe the thing, plus a strip of the artifact's own palette.

Auto routing reads content before length

Fixed

A short message containing a stack trace was being classified as a trivial follow-up and sent to the cheapest model, because brevity was checked before content. What a message contains is now asked first.

3 Sep 2026
Governance, cost, and the way it feels to use

A tamper-evident audit log

New

Every entry is hashed against the one before it, so an edited or deleted row breaks verification and the log reports which one. It records logins and failures, key creation and revocation, tool calls, skill imports, membership and budget changes. Verify the chain on demand; export JSONL or CEF straight into a SIEM.

Tool arguments are logged by name only, never by value — the log outlives the conversation, and an audit trail should not become a second copy of your data.

Workspaces, roles and spend caps

New

Group people under a workspace with owner, admin, member and viewer roles. An admin can manage members but cannot mint or demote an owner, and the last owner cannot be removed. Set a monthly workspace budget, a per-person allowance, or both — an over-budget request is refused with a message naming the limit it hit, before any model is called.

Prompt caching

New

Anthropic and Qwen bill the whole prompt again every turn unless a cache breakpoint says otherwise. The system prompt is now split into a stable head and a volatile tail so the cached prefix stays byte-identical between turns, and a session id pins a conversation to one upstream provider so the cache is actually reachable. Hover any reply's cost to see how much of its input came from cache.

Every other model family on OpenRouter caches automatically and is deliberately left alone — adding breakpoints where they are not needed is not free.

Auto routing ranked by price, not by name

Improved

Model tiers are now derived from the live price distribution rather than from patterns in model names, so a vendor rename can no longer quietly drop a flagship out of the deep tier.

Streaming that feels like streaming

Improved

Blocks fade in as they arrive, a caret marks where the model is writing, and the scroll yields the moment you scroll up instead of dragging you back down. The app also gained one motion vocabulary rather than a different animation per component, and it respects a reduced-motion preference.

Type while a reply is still streaming

Improved

Your message waits instead of vanishing. A pill above the composer shows it, and it sends the moment the reply finishes — or you discard it.

Parallel agent steps

Improved

The planner marks which steps are independent and those now run at the same time, while dependent steps stay ordered. Resume behaviour is unchanged.

Artifacts report what went wrong

Fixed

An artifact that failed to render used to fail silently. It now says what broke, so the model can be asked to fix it.

Code blocks are readable in light mode

Fixed

Code block text was rendering invisible against a light background.

11 Aug 2026
Documents the model can actually read

Word documents, including the legacy format

New

.docx attachments are extracted server-side, and so are legacy .doc files — detected by sniffing the actual format rather than trusting the file extension, because the two are routinely mislabelled.

An unreadable attachment is never dropped in silence

Fixed

A file the server could not extract used to disappear from the conversation with no indication, so the model answered as though you had sent nothing.

PDFs work on every provider

Fixed

PDF text is now extracted locally for every provider rather than relying on upstream support, which fixes both models that never received the text and a DOMMatrix is not defined crash on deployed extraction.

1 Aug 2026
Small fix, large blast radius

The model knows what day it is

Fixed

Today's date is injected into system prompts everywhere. Without it a model answers "this year" and "recently" from its training cutoff, confidently and wrongly.

29–31 Jul 2026
Ready to be a public, multi-user service

Secrets encrypted at rest

New

Provider API keys, custom-tool secrets and MCP tokens are encrypted with AES-256-GCM using a master key held only in the environment, never in the database.

A database-only compromise — a leaked backup, stolen credentials, a read replica — now yields ciphertext an attacker cannot read without also stealing the application environment.

The full multi-user platform

New

Per-user keys, settings and data with row-level isolation enforced on every route, an admin panel with a server-side paginated and searchable user list, per-user platform API keys, scheduled tasks, and user-to-user sharing.

Admin cannot reset a Google account's password

Fixed

Accounts that sign in through Google have no password to reset, and offering the action implied a local credential that does not exist.

25 Jul 2026
Accounts you can recover

Password reset and email verification

New

With a security-hardening pass alongside it. A password reset invalidates every existing session.

23–24 Jul 2026
Artifacts grow up

Second opinion, design systems, and cost attribution

New

Run the same question through several models in streaming columns and swap the reply you prefer into the thread. Save named brand specs — palette, typography, spacing, components, voice — and lock a design to one, or share it with another user. Every reply records its real cost and tokens, attributed by category.

Edit an artifact yourself

Improved

A syntax-highlighted editor in the panel, plus Adjust and comment-to-edit on any visual artifact rather than only inside the design workspace.

Presentations and documents worth exporting

Improved

Slides render on a fixed 1920×1080 canvas with editable speaker notes in the player, and PDF export produces a typeset document instead of a raw markdown dump.

Never lose a turn in silence

Fixed

A tool-loop budget, a hard turn deadline and a resume banner, so a run that hits a limit says so instead of ending with nothing on screen.

21–22 Jul 2026
Bring your own clouds

OpenAI and Anthropic direct

New

Route to either provider with your own credentials instead of through OpenRouter, with full feature parity.

Search your own past chats

New

The model can look things up in your history — "what did we decide?" — behind a setting that is off until you turn it on.

Settings you can navigate

Improved

A grouped, searchable tab rail on desktop with icons, and stacked tabs on mobile.

Stop actually stops

Fixed

Stop now releases the lock through a cancel endpoint, and research and image generation use the conversation's context rather than starting cold.

20 Jul 2026
First release

Liberde

New

A self-hosted, model-agnostic AI platform: streaming chat across 400+ models, artifacts, projects, web search, plan mode, MCP connectors, skills and memory — shipping from day one as two editions of the same app, hosted and self-host.