# Changelog

## October 3, 2026

- The command line, `23a`, now has a release path: each version is built for npm (`npm install -g 23artifacts`) and as one compiled file for macOS and Linux through Homebrew (`brew install 23made/tap/23artifacts`). On npm a new version waits for a maintainer to approve it with two-factor authentication before anyone can install it, so a compromised build machine cannot ship one on its own.
- The command line, `23a`, still unreleased, can now list what a search finds (`23a list kind:deck`), open an artifact or its page in your browser (`23a open`, `--manage`), and print the open comment threads on an artifact (`23a comments`, `--all` for the resolved too). When your browser is on another machine, `23a login --no-browser` takes the address the browser ended on, pasted back into the terminal.
- The help page for a refused publish now covers a token made in another workspace: it quotes the refusal, says a token works only in the workspace it was made in, and says to make one in the workspace your job saves into (one per workspace, for a job that saves into two). Behind the scenes, our spec-review pages all live in one workspace, and the scripts that publish them say plainly when they are handed a token from another.
- A very large page — a single-file deck or export with its media inside, hundreds of megabytes — is now sent as it is read, with its crate and link-preview tags added on the way, instead of being read whole first; a few such pages opened at once can no longer run the server out of memory and take every artifact down with it. Embeds and previews of large pages are sent the same way.
- Assistants now know how to read what you draw on a page: a loop around something means "this", an arrow points a direction, and a cross means take it out — the same shapes you'd use with a person. Marks stay what you drew, never a picture. Also settled for launch: making something before signing up happens only in the builder, browser notifications come after launch, and "favorites" is gone from the plan because watching already covers it.
- The command line, `23a`, is built, though not yet released: it signs in through your browser (and appears as "23a on <your machine>" among the apps connected to your account), publishes a folder or a file of any size in one go and prints its address, publishes the same folder again as the next version, and tells you who is signed in, with `--json` on every command for scripts. Along the way: saying no on the consent page now tells the app that asked, instead of leaving it waiting; a script staging large files over the API can name the workspace they are for; and `GET /api/v1/me` names your handle and each workspace's.
- Nothing changes for you: our own publishing scripts (the spec review pages and a page-tools probe) send `key` like everyone else, after the rename stopped them publishing.
- Nothing changes for you: operators now see a short list of the old `23artifacts.app` addresses whose names sound like 23artifacts itself (such as `security-…` or `…-login`), so a page made to look official can be checked and taken down.
- In the iPhone app (not yet in the App Store), an artifact is shown by its `23a.so` address instead of its old name, and a piece of material's reference is its key. When Siri makes a deck, it says the deck's address.
- Behind the scenes: every bug, idea and improvement we find now becomes a GitHub issue — checked for duplicates, grouped with related work and given a priority — and the next work is picked from those issues, so nothing found along the way is lost in a conversation.
- The documentation's Help tab: five pages for when something is not working — an assistant that will not connect, signing in, someone who cannot open what you shared, a refused publish, a page that looks different once published — each quoting what 23artifacts says and what to do about it; and this changelog, grouped by day, with a feed to subscribe to at `/docs/changelog.xml`.
- An artifact's page in the dashboard is now `23artifacts.com/p/<its id>`, the same id as its address, and older `/p/<name>` links still land there. Its settings have a quiet "Key for tools" card where you can copy, rename, give or clear the key that assistants and scripts publish by. Mails and notices link to the page by its id.
- Every page of the documentation asks whether it helped: answer yes or no, add a note if you like — what you were looking for, or anything to add — signed in or not, and without giving your address. A search in the documentation that finds nothing is counted, with nothing about who searched, so we can see what is missing. The privacy policy says how both are kept.
- Assistants and scripts now name an artifact's key as `key` instead of `slug`, and you can set, rename or clear an artifact's key in its settings. A request that still says `slug` is told to say `key`. Search with `key:`. Links to an earlier version, the deck editor, downloads and previews of a new artifact now point at its `23a.so` address; for a day, some of them pointed at a `23artifacts.app` address that new artifacts don't have.
- An API token now works only in the workspace it was made in. A token that used to save into, list or change another workspace you belong to — your Personal, or another team's — is refused, and the refusal names the token's own workspace; artifacts kept elsewhere are not found through it, and the inbox and workspace list it reads show its own workspace alone. If a job of yours publishes into two workspaces, make a token in each and give the job the right one for each. Signing in yourself, and assistants you connect, still reach every workspace you belong to.
- New artifacts get one address, their short `23a.so` link, and no `23artifacts.app` address; every `23artifacts.app` link already out there keeps working. The name you give an artifact when you publish is now its key, which only your workspace sees: publishing again with the same key saves a new version of that artifact instead of being refused, and two workspaces can each use the same key.
- Comments on a pull request's review page are answered and resolved again when the spec change that addresses them is published; since tool surface v3 renamed the reply field, the reply had been refused and the thread left open.
- The tabs on an artifact's page, in workspace and account settings and on the operator pages are now a segmented control, the open one raised on a recessed track, like the list and grid switch beside the artifact list; that switch now reads correctly in dark mode, where its chosen side had looked sunk rather than raised. On a phone a row of tabs too long for the screen scrolls sideways behind a soft fade and brings the open tab into view, and the keyboard's focus ring is drawn whole instead of clipped.
- Decided, and written down before it is built: every artifact will have exactly one address, its short `23a.so` link. The long `23artifacts.app` addresses you already have keep working forever, but new artifacts won't get one. The name you could pick for an artifact (its "slug") stops being part of any web address. It becomes a key that only your workspace sees, which assistants, scripts and the command line use to find the artifact and publish its next version in place. Nobody can claim a lookalike address such as `security-alert.23artifacts.app` any more.
- Decided, to be built before launch: a command line, `23a` (also installed as `23artifacts`), that signs you in through your browser and publishes a folder of any size from a terminal, a script or an agent's shell, with `open`, `list` and `comments` beside it and a `--json` answer from every command for programs.

## October 2, 2026

- The new documentation portal, and everything that landed after it today, now reaches 23artifacts.com: the release build had been failing since the portal landed, so none of it had gone live.
- The documentation has a search: ⌘K (Ctrl K) or the field in its header searches every page, guide and API operation as you type, on your own device, and a search that finds nothing offers the way to ask your assistant instead. From inside the app, ⌘K now offers to search the documentation for what you typed. Every page has a menu beside its title to copy it as markdown, open it as markdown, hand it to Claude or ChatGPT, or copy the connector's address.
- The API reference now sits inside the documentation, under Agents & API: every operation is listed in the sidebar, the reference follows light and dark with the rest of the page instead of staying dark, and trying an operation acts as you when you are signed in — signed out, the page says so and shows the answer as it came.
- The documentation's Agents & API tab now holds every guide your assistant reads, each as a page you can read too, with links from one guide to the next, and a page listing every tool name the connector retired beside the one that does its job now. The full corpus for assistants, `/llms-full.txt`, now also carries every page of Using 23artifacts.
- The documentation is now a portal: tabs for using 23artifacts and for agents and the API, a sidebar of pages in groups, and a page of its own for each thing you can do — sharing, versions, comments, decks, themes, the library and the rest — each at an address of its own with a markdown copy beside it. Links to the old one-page documentation still open the right page, every help mark in the product opens the page that explains it, and signed in, the documentation keeps one button back to your artifacts.
- Nothing you see changes: a note to ourselves after this morning's server change briefly restarted the database behind 23artifacts (about a minute of errors around 12:05 UTC), so that the next such change is scheduled and announced like any other maintenance.
- Decided, and being put in place as the server changes go live: when 23artifacts has to be down for a minute of server maintenance, it will happen at a time we choose, never as a side effect of an update, and instead of an error you will see a short "Back in a minute" page that tries again on its own, while programs and assistants get a proper "unavailable, retry in 60 seconds" answer.
- Every on-or-off setting is now a switch rather than a checkbox: taking comments, letting visitors comment, the shared room, hiding the corner crate, the link preview's screenshot and weekly backups each read as a sentence with its switch at the end, and the switch can be clicked, tapped, dragged or set from the keyboard.
- The switch between list and cards on your artifacts, and between gallery and table in the library, is now one segmented control whose chosen view sits raised in its track and slides when you pick the other; a screen reader hears it as the views it is, and the arrow keys move between them.
- Choices made from a menu — each kind of notification mail, the digest's hour, where mail goes, a link preview's level, what the activity chart shows and how it is grouped — open our own menu instead of the browser's, and picking an entry page for an upload or what members get in a new workspace is a list of options with the chosen one marked.
- Dialogs are a little wider — 480 px, where they had been 400 — so a question and its fields read on fewer lines; publishing files and sharing keep their wider dialogs.
- Checked from outside: the first release after that change answered every one of 580 requests made while it rolled out, where the three before it each failed between 8 and 37.
- The documentation, the plugin, support and everything else that gives the 23artifacts connector's address now gives its permanent one, `https://mcp.23artifacts.com/mcp`. If your assistant is already connected, leave it as it is: the old address keeps working, with the sign-in you already have.
- Nothing you see changes, and that is the point: when we release a new version, the one being replaced now keeps answering until the new one has taken over, instead of stopping at once. Each release used to make 23artifacts fail or stall for one to ten seconds.
- The 23artifacts connector is getting its own permanent address, `https://mcp.23artifacts.com/mcp`, ready for the assistant directories; opening `mcp.23artifacts.com` in a browser explains how to connect. Nothing changes for you if your assistant is already connected: `https://23artifacts.com/mcp` keeps working for good, with the sign-in you already have.
- Nothing in the product changes; this is how its design gets decided. A change to 23artifacts held for Martin's ruling now comes with one review page instead of a link to the whole specification: it opens on the calls to decide, each with its options and a recommendation, shows the new pieces built and photographed in light and dark on desktop and phone, and lists only the parts of the specification that changed, with what arrived and what left marked.
- A backup or export now says it is format `23artifacts-backup/2`, in its README, `workspace.json` and `_backup/manifest.json`, because the archive's layout changed on 2026-10-01: each artifact's facts moved from its `artifact.json` to `_backup/artifacts/<slug>/facts.json`, and its access became a list of entries. An archive marked `/1` from before then holds the older layout; the few made on 2026-10-01 and 2026-10-02 say `/1` but already hold the new one, which you can tell by the `facts.json` files.
- The plan for a much better documentation is written down: three sections — using 23artifacts, agents and the API, and help — each with its own pages and sidebar, search on ⌘K, a menu on every page that hands it to your assistant, the API reference inside it in light or dark, troubleshooting pages, this changelog with a feed, a way to say whether a page helped, and real examples to look at. Nothing about today's documentation changes yet, and every link to it will keep working.
- Your assistant now knows that an `artifact.json` at the top of the files it saves sets the artifact's name, description, tags, library, room, crate and agent policy, and checks its access and link preview, rather than being told the name is reserved. A folder from a backup saved back as it stands changes nothing, and saved as a new artifact makes one with the same settings; a folder from a backup made before 2026-10-01 is refused until its `artifact.json` is removed or cut down to its name, description and tags, and the refusal names what to take out.
- Nothing you see changes; this is what keeps it safe. Every night a copy of everything 23artifacts holds for you — your artifacts and their history, comments, recordings, and the files behind them — leaves the machines it lives on, encrypted, and every week we restore the newest copy on its own and check it against the original, down to each table's row count and a sample of files by their contents. A failed copy or a failed check alerts us at once. Anything lost by mistake can be brought back from a copy for five weeks. Until now the database's copy was taken while it was running and had never been restored, and the files had no copy at all.
- The new set of tools your assistant uses with 23artifacts is complete and checked end to end: thirty tools in one grammar, every older tool name answering with the one that replaced it, and every retired address of our API answering with the one that took its job. The phone app is updated to match.
- The 23artifacts plugin can be installed straight from its repository, github.com/23made/23artifacts-plugin, which now follows every release. In Claude, add it under Customize → Plugins → Add → Add marketplace; in Claude Code and Codex, add the repository as a marketplace and install the plugin — the documentation's connect steps now lead with these, with the connector on its own as the other way. The plugin's README says where to report a problem: an issue in that repository, or the support page.
- You can tell us about 23artifacts from your assistant: ask it to send feedback — something that got in your way, something broken, or an idea — and it answers with a reference to quote. Your assistant also sends feedback on its own when 23artifacts gets in its way, such as a refusal that didn't say what to do, and tells you in a line when it does; it never sends what your artifacts contain. Programs send the same through `POST /api/v1/feedback`. Only the people who run 23artifacts read it, and it is deleted with your account.
- Codex can sign in to 23artifacts. Codex listens for the sign-in on whatever local port is free, and we had insisted on the exact address it registered, so every Codex sign-in ended in "Invalid redirect URI". A local loopback address is now accepted on any port, as the OAuth rules for native apps require, and only that.
- Every photo saved to 23artifacts now loses where it was taken, however it arrives: from your assistant, a script with a token or an upload link, the phone app, or our own pages. GPS coordinates, a named place, the camera's and lens's serial numbers and the owner's name are removed; the picture itself, how to turn it, the date it was taken and the camera's make and model stay. HEIC photos are covered too. When you do want a photo published with its location, ask your assistant to save it with `keepPhotoMetadata: true` (in a script, the same field on the save or the library batch); the answer says, for each photo, whether its metadata was removed or kept. Photos saved before today are unchanged.
- Someone editing your deck from outside your workspace can now always undo their own changes. If they remove a picture or switch away from a theme, putting it back works, because the deck editor remembers what the deck held when they opened it. They can also use anything any earlier version of the deck carried. They still can't reach anything else in your library.
- A photo you add from your own device through our pages no longer carries where it was taken. Add material in the library, an image added from the deck editor, and an image attached to a comment are now kept without GPS coordinates or a named place, and without the camera's and lens's serial numbers and the owner's name; the picture itself, how to turn it, when it was taken and the camera's make and model stay as they were. Files your assistant or a script saves with a token are still kept exactly as sent.
- Someone you let edit a deck from outside your workspace, by their address or through a share link, no longer sees a Publish button they cannot use. They still edit and save, and the bar says there are unpublished changes; Publish shows only for people of your workspace who may make changes live, in the editor in our page and in its own tab alike.
- For whoever builds this next: a photograph given to the builder (still behind its flag) no longer carries where it was taken. Before it is kept with the page, its GPS coordinates and any place named in it are removed, along with the camera's and lens's serial numbers and the owner's name; the picture itself is untouched, and its orientation, the date it was taken and the camera's make and model stay. A HEIC photograph, converted to JPEG, now keeps its date and camera too. A phone's motion photo is kept as the still.
- Someone you let edit a deck from outside your workspace, through a share link or by their address, no longer sees your whole library in the deck editor. They find our material and what the deck already uses — in its draft or its published version — and the theme it took its look from, and the picker tells them so; they cannot browse, search or place the rest, and a save from them naming anything else is refused with a sentence saying why. Members of the workspace keep the whole library, and adding to it stays theirs.
- Your library now takes SVG logos and artwork as images, from Add material, the deck editor's library picker, or your assistant. An SVG is kept only as what is left once nothing in it can run or load anything from elsewhere: scripts, event handlers, embedded web pages and links to other files or addresses are taken out, and pictures it carries inside it stay. Only that cleaned copy is kept and served, so a logo that loaded a web font or a remote image may look different — embed what it needs, or turn text into outlines. An SVG can be up to 2 MB; one that will not read as XML, or declares its own entities, is refused with the reason.
- For whoever builds this next: the builder (still behind its flag) now makes things in the workspace's own look. It is shown the workspace's default theme and the material in its library, builds with the theme unless the person asks for another look, and brings in a logo, screenshot or typeface from the library by reference wherever the page uses one.
- For whoever builds this next: the builder (still behind its flag) can now turn a spoken request into words where the browser cannot listen on its own. The recording goes through the same transcription as a recording's words, counted against the workspace's minutes for the day, and only the words come back to the box; what it cost goes on the make.
- For whoever builds this next: the builder (still behind its flag) now takes photographs and files with the words. A JPEG, PNG, WebP or HEIC photograph up to 25 MB, and a PDF, CSV, TSV, text file or .xlsx spreadsheet up to 10 MB, four of each a make, are recognised by their bytes when added and refused beside the attachment with the reason; the model sees a photograph scaled to 1,568 px, a PDF as a document, a text file and each sheet as text, and the originals — a HEIC as its JPEG — are files in the artifact the page refers to by name. Attachments no make used are cleared away after a day, as other unused uploads now are too.
- In the deck editor, every place that takes material now opens your library: images, videos and sounds from the Image and Media menus, a picture's or clip's replacement, a video's poster, and a font from the text panel. It shows your workspace's library and ours (marked as ours) by the same search the library uses, and the deck uses what you choose by name, so it takes the material's live version when you publish. You can also add a file from your computer to the library right there and use it at once; a file used in one deck alone still goes straight into that deck.
- In the sidebar, Decks, Pages, Markdown and Files now sit as a proper sub-menu beneath Artifacts, and Themes beneath Library: a thin guide line marks them as part of the list above, their names line up with it, and the one you are on is highlighted like any other row. The highlight that follows your pointer down the sidebar now starts at the row you point at. The ⌘K palette opens a little lower in the window, with its rows packed slightly closer.
- Enterprise workspaces now get their own rates, a hundred times Free's: 6,000 saves and 6,000 library batches an hour, and 3,000 each of pictures, upload addresses and staged files. Team stays at ten times Free. A refusal now writes its numbers with thousands separators, and the operators' rates table has a column for each of Free, Pro, Team and Enterprise. Prices and plans are unchanged.
- For the people running 23artifacts: the operator screens now show every plan's rates in one table under moderation, the number in force in each cell with the default beside any that was changed. Change any number and save, or put every rate back to its default in one click, with no release needed.
- How often you can save, send a batch to the library, ask for a picture, make an upload address and stage a file now depends on your plan: Free keeps today's numbers (60 saves an hour, 30 pictures), Pro allows three times as many and Team ten times. You get the best plan among the workspaces you belong to. When you reach one, the message says the number, your plan and when you can go again; a program also gets a `retry-after` header and a `rate` object naming the plan that allows more. The people running 23artifacts can change these numbers without a release.
- You can move an artifact to another workspace you own or administer — from Personal into an organization, between organizations, or back — up to 50 at a time, by asking your assistant or with `moveTo` on the settings route. Each keeps its address, versions, comments, share links, room and history; people who had it because they were members of the old workspace now get it as members of the new one, and its maker keeps their entry only if they belong there. Ask for a dry run first (`validate: true`) to see exactly who gains or loses access before anything moves. An API key cannot move artifacts; your own sign-in or your assistant can.
- For whoever builds this next: moving an artifact to another workspace is specified. Its owner, when they also own or administer the destination, moves up to 50 at a time, through an assistant or a program; each keeps its address, versions, comments, share links and history, and a dry run says beforehand who will gain or lose access by it. Nothing moves yet: the building comes next.
- For whoever builds this next: the builder eval keeps its new pages in the `awesome-artifacts` workspace rather than Martin's Personal. Martin's rulings of the day are recorded: decks and themes are on for everyone, the agents' calls stand, and a themed deck stays linked to its theme after hand edits.
- For whoever builds this next: the product's own rule now says an artifact can be moved by its owner to another workspace they also administer, keeping its address and its history.

## October 1, 2026

- For whoever builds this next: the deck editor has a theme control, behind the `decks-themes` switch that is off. It sits at the head of the slide panel's Theme section, names the theme the deck took its look from, and lists the workspace's themes and ours as rows of their ground, text and accent. Choosing one recolours the deck in place with the same rule a save uses; colours set by hand stay, and undo takes it back. The draft then records which theme version it wears, and publishing carries that onto the version, as a save naming the theme does.
- In the assistant's recordings, a line where something was marked is now led by the pen the page's comment tool carries (a nib over a stroke of ink) instead of a pencil. The pencil stays for editing, and the person who made an artifact keeps it on the sharing list.
- For whoever builds this next: applying a theme to a deck is now one rule that the save and the deck editor can both run (`src/shared/deck-theme.ts`). A deck saved with a theme comes out exactly as before, held to that by 50 recorded deck-and-theme pairs; the deck editor's theme control will use the same rule, so choosing a theme there gives the deck a save naming that theme would.
- A backup's artifact folders now hold each artifact's settings as the same `artifact.json` a save reads, so saving a folder back as it is changes nothing, and saving it as a new artifact makes one with the same name, tags, access and preview. What an artifact is beyond its settings — its addresses, dates and state — moved beside it, to `_backup/artifacts/<slug>/facts.json`.
- For whoever builds this next: the builder now checks each page as a phone and a laptop show it before it goes live, still behind the switch that is off. It takes one picture at each width through the same renderer as preview images, hears the page's errors and the files that failed to load, and gets one turn to fix what it sees; a version gets at most two such pictures, ten a minute across the service, and if the renderer is slow or down the page goes live after the safety scan alone and says it went live unpictured. The scan also reads the page as its scripts built it.
- For whoever builds this next: the builder now scans every page before it goes live, still behind the switch that is off. A page asking for a password, a card, a bank account or an identity number, a form sending what it collects to another site, or a sign-in form beside our name or a well-known brand's — Microsoft, Google, Apple, PayPal, the largest banks — is refused and never goes live, with words saying what was left out and what the builder can make instead; a fix the check makes is scanned the same way. The builder eval scans with the very same code.
- For whoever builds this next: the builder eval keeps a full run's pages under 23artifacts' limit of 60 saves an hour. It paces its saves over the hour, waits out a refusal by the limit and saves again instead of leaving the page unkept, saves a later turn straight to its artifact's versions, and `publish` over a run already kept now changes only the descriptions, which costs no save.
- For whoever builds this next: the themes place and a theme's page, still behind the `decks-themes` switch that is off. Themes in the library show as theme rows (their ground, text and accent as a strip, the name, the live version, *Default* on the workspace's default) and as cards drawn in their own colours with the name in their own face; *Make default* is in a theme's menu for whoever may change the workspace's defaults; a theme's page shows its colours, its type and its guidance where it used to say there was nothing to draw, and says when it is the default.
- For whoever builds this next: decks and themes get their own rows in the sidebar, behind the `decks-themes` switch that is off. Under Artifacts sit Decks, Pages, Markdown and Files, and under Library sits Themes; each is the list narrowed to that kind, lit whenever the search keeps that kind alone, with the kind named at the end of the trail, counted in the bar, left off each row, and an empty state saying what the kind is for.
- For whoever builds this next: the builder eval keeps its pages through v3's saving routes. It makes the artifact, then saves each later turn as a version and sets the description apart, since the publish route it used retired with the cut. With a publish-only token, versions are kept and a description waits for a token with `manage`.
- For whoever builds this next: the builder eval's two-phone test on the pub quiz now has the watching phone join as a player first, as a real person watching a quiz would; it used to stand at the join form, where no quiz shows anyone. A new `rescore` command checks a kept run's pages again without asking any model, and the quiz was rescored that way: it now passes for Sonnet 5.5 at low and Opus 5.5 at low (it had failed), still passes for Muse, and no run's verdict on the bar changes.
- For whoever builds this next: Martin's rulings on the night's work are recorded. The builder's five calls and config-as-code's six stand as built, and the eval's quiz check is to be fixed and rescored on the pages already kept.
- For whoever builds this next: blueprint 0.6.0. GIT.md now says where the ledgers' union merge holds, to lease a force push with the commit you started from, and to re-diff every ledger against the base after a rebase. PRODUCT.md's last unused alias is gone.
- For whoever builds this next: the builder page has its routes on the server, behind the switch that is off. Signed in, you can ask for a make, watch its steps and the page being written as they happen, ask for a change while it works and have it applied right after, and stop it. Eight makes run at once on each server and the rest wait their turn, told how many are ahead; if the builder cannot reach its model it says so before making anything, and charges nothing.
- For whoever builds this next: the builder can now make a page end to end on the server, still behind the switch that is off. It writes the page, saves it as a new private artifact that stays offline until it is checked, switches its room on when the page needs one, and puts it live; each change you ask for lands as small edits to the live page, saved and checked the same way. Every version it saves carries its note, and the artifact's history shows the builder acting for you. Until the phone-and-laptop check is built, pages go live unpictured.
- For whoever builds this next: blueprint 0.5.1. Conflict markers are now the blueprint's BP-58; the spec's cross-references are this project's registered check, LOCAL-02. The Muse eval run's record is kept with the harness, and `make -C ios install` targets Martin's iPhone 18 Pro.
- For whoever builds this next: each make the builder starts is now kept as one record — what was asked, every step and model turn, what it cost at list price, the artifact and versions it made, and how it ended — and a make whose server stops mid-way ends as failed on our side rather than hanging. Deleting your account deletes these records. Still behind the switch that is off.
- For whoever builds this next: the builder has its first pieces on the server, behind a switch that is off — the ten recipes it reads, its standing instructions with the recipes' index, and its connection to the model, which streams the page as it is written, reads a recipe when a brief needs one, and counts the model's thinking in what a make costs. Nothing anyone sees changes yet.
- For scripts and agents: an artifact's settings can now travel with its files. Put an `artifact.json` at the root of what you save — its name, description, tags, whether it is in the library, its room, its crate, its agent policy — and the save applies it, the same as changing those settings directly and with the same permissions; a file that matches what is already set changes nothing. The file itself is never published or kept in a version, and an existing artifact's access still changes only through the sharing controls. This is the first half of the workspace as a Git repository.
- For whoever builds this next: the builder eval's safety scan no longer takes the word "pan" for a card number, or anything that "expires" for a card's expiry. A lasagna recipe's step checkbox ("…in the 9×13 pan…") had its page refused as a card form.
- For whoever builds this next: the spec now says how decks and themes get places of their own — Decks under Artifacts and Themes under Library in the sidebar, New deck to start one by hand in the editor with your library and themes, and a theme you can change yourself beside a live specimen. Nothing changes in the product yet.
- For whoever builds this next: an artifact page no longer answers `/__review/activity`. Its only reader was the crate's old Activity menu, which moved to the artifact page's log.
- For scripts: reading an artifact can now bring back a picture of any version or of the draft, at a desktop or a phone width (`?version=3&viewport=phone`). It is made the first time it is asked for and kept, so asking again is instant; a draft's picture is only ever shown for the draft as it is now. A version needs the artifact opened and the draft needs Edit, and you can ask for 30 new pictures an hour. The assistant's `get_artifact` gets the same options with the new tools.
- For scripts and agents keeping a library in step with a folder: sending a batch again now updates it. A file whose slug is already in the library becomes a new version of it, a file that hasn't changed stores nothing, and new files are added; nothing you leave out is touched. Each file's answer says which happened, with a count of each. Material someone took offline gets the new version without coming back online, and a member who can't change a piece is told to ask an owner or admin, or use a new slug. Uploads without a slug, like the iPhone app's photos, are always new.
- The iPhone app, and anything else signed in through 23artifacts' own sign-in, can now read an artifact's files and its draft; that one route used to answer "unauthorized" to it while every other route let it in. In the assistant's deck card, *Open the editor* now shows a pencil, since the pen means commenting.

## September 29, 2026

- For whoever builds this next: the builder's eval can now run Sonnet and Opus on Martin's Claude subscription instead of the API bill, pacing itself and stopping before it uses up his week, with Muse's key coming from 1Password. The three judges' agreement is now read by Gwet's AC1, which does not fail a model for being consistently good; the whiteboard brief attaches a real photograph; the runs load the ten draft recipes; and every page a run makes, and every judging round, is kept privately on 23artifacts, tagged model-eval, the turns as versions.
- Your artifact list and your library are now one list seen two ways: the library page shows your images, clips, sounds, typefaces and themes (and the ones 23artifacts supplies, marked as ours) from the same search as your artifacts, and each piece opens its own artifact page, with the file at full size and the name to give your assistant. Every row, card and artifact page says whether it is offline or deleted, and a staged version shows beside the live one. Take an artifact offline from its versions or its menu; pick Deleted in the filters to see what you deleted in the last thirty days, and restore it in one click, back live or offline as it was. A filter you leave out reads as a struck-through chip with a minus, and turns back in place. The Agents card shows each agent that is waiting or working on your comments, and what it holds, with pause, resume and remove.
- The iPhone app speaks the new version of the API, ready for the day the old one is switched off. It publishes, makes and edits decks by voice (a deck from a template now starts in that theme's colours), adds photos to your library, and shows and comments as before; "Unpublish" is now "Take offline", which stops the address serving and keeps everything until you make a version live again. The comments screen no longer freezes when the server starts sending something new, and when the server refuses something the app says what it said. Scripts can resolve or reopen several threads at once, each named by any comment in it.
- How an offline or deleted artifact is marked, taking one offline and bringing it back, a filter you leave out, and the page an offline address shows are now part of the product's design, exactly as you see them.
- The assistant tools are redesigned: twenty-nine tools, one per job, in one grammar. `save_artifact` is now the one way content changes — a page, a deck, a theme or a piece of material for your library, sent whole or as changes on an earlier version, live, staged or into the draft; `update_artifact_settings` changes settings, on up to fifty artifacts at once; `set_artifact_state` makes a version live, takes an artifact offline or brings a deleted one back; `list_artifacts` finds everything, your library included (`in:library`, with our own material beside yours); `get_artifact` shows one; `list_comments` reads the whole conversation and `await_activity` waits for anything new on it. The old names — `publish_artifact`, `show_artifact`, `list_assets`, the deck and theme tools and eleven more — no longer do anything: calling one says which tool took its job, and reconnecting your assistant lists the new ones. For scripts, the old routes (`POST /api/v1/publish`, the assets, themes and decks routes, the live-version route and the rest) are gone the same day and answer with the route that replaced each; upload addresses now save through `/api/v1/artifacts` and fill the library through `/api/v1/library`, and the phone app needs its new version to publish. A deleted artifact now keeps its room, with everything else, for the thirty days it can be brought back.
- Your library moves into artifacts. Every image, clip, sound, font and theme you keep becomes an artifact of that kind, with its versions in order, its tags (the old library folder among them), its description and an address of its own. Decks still being edited now name the new material, and your default theme points at the moved theme. Nothing you published changes by a single byte, and nothing is deleted. Until the switch to the new assistant tools, the library page, the phone app and the current assistant tools keep working as before, and whatever they add or change is carried across as it happens.
- For whoever builds this next: the builder now has the test it must pass before anyone uses it. `scripts/builder-eval/` runs the twenty-four fixed briefs, with their photographs and files, through a candidate model, checks each result as a phone and a laptop show it (with two phones trying the shared ones), asks for one change on each, and writes a blind judging page for three people and a report that says, gate by gate, whether the bar holds. It runs end to end without a key on recorded answers; the real runs, about $20 for the four models, wait on Martin.
- For scripts, and ahead of the assistant tools: an image, a video, a sound, a font or a theme can now be saved as an artifact of that kind, by naming the kind. It goes straight into your library, every member of the workspace can open and use it, and only the owners and admins change it. What a file is is decided by its bytes, each kind to its size limit (15 MB for an image or a font, 25 MB for a video or a sound), and a theme is saved as its document, with a draft like any artifact. A page saved with `theme` copies that theme's stylesheet, and a file named `from` a piece of material copies it, costing no storage twice. Material counts against your library's space, never against your plan's number of artifacts, and your artifact list shows it only when you ask for the library. A batch of up to 500 pieces is one request: `POST /api/v1/library`. Your library page, the assistant tools and the phone app keep working exactly as before.
- For whoever builds this next: the builder's eval can now run Sonnet and Opus on Martin's Claude subscription instead of the API bill, pacing itself and stopping before it uses up his week, with Muse's key coming from 1Password. The three judges' agreement is now read by Gwet's AC1, which does not fail a model for being consistently good; the whiteboard brief attaches a real photograph; and the runs load the ten draft recipes.
- For whoever builds this next: the builder now has the test it must pass before anyone uses it. `scripts/builder-eval/` runs the twenty-four fixed briefs, with their photographs and files, through a candidate model, checks each result as a phone and a laptop show it (with two phones trying the shared ones), asks for one change on each, and writes a blind judging page for three people and a report that says, gate by gate, whether the bar holds. It runs end to end without a key on recorded answers; the real runs, about $20 for the four models, wait on Martin.
- An assistant takes a group of comments on as one piece of work in a single step, with no session to open first: while it holds the work, people on the page see it as working, and if it goes quiet for a minute and a half the work is free again for anyone. As an artifact's owner you can pause or remove an agent there, or cancel a piece of work, and work whose comments were all deleted ends by itself. An assistant can now read the whole conversation on an artifact in one go (comments, recordings, work and the versions saved) and wait for any of it.
- Searching leaves things out with a minus, everywhere you can search: `-tag:old` on your artifacts and your library, `-bot:*` in the log, `-kind:comment` in the inbox, and on the dashboard a left-out filter shows as its own chip, struck through, that you can turn back. A word only on the second page of a site now finds it. The log and the inbox take one search line in the same terms. Two old search terms changed their names: `state:draft` is now `state:offline`, `state:ready` is now `has:staged`, and searching a page's words alone is `text:`; the old ones say what to use instead. And `state:deleted` finds what you deleted in the last thirty days, while it can still be brought back.
- You can now take an artifact offline without deleting it: its address says nothing is live there, and its versions, draft, comments and history stay exactly as they were until you make a version live again. Bringing back a deleted artifact puts it back live or offline, as you choose — with the version that was live, unless you pick another. Settings can now be changed on up to fifty artifacts at once (tags added or taken away, the room, the crate, the agent policy), and nothing changes unless every change is allowed on every one; an artifact can also be marked as being in your library. For scripts: `PUT /api/v1/artifacts/{artifact}/state` and `PATCH /api/v1/artifacts`.
- Scripts and programs can now save an artifact in one request that says exactly what happens: send the whole thing, or only what changed on an earlier version — a file added, removed or a line of text edited — and it goes live, is saved without going live, or goes into the artifact's draft, which nobody sees until it is saved as a version. Leaving files out of a whole save is never silent: the reply lists every one, and leaving out the page served at the address is refused unless you name the new one. Saving what is already there says nothing changed and makes no new version. A deck is saved the same way, and a misspelled field is refused, naming the one you meant. Copying someone else's artifact to change it records where it came from, and an agent working on comments under a rule that needs approval has its change held for a person to make live. The new routes are `POST /api/v1/artifacts` and `POST /api/v1/artifacts/{artifact}/versions`; publishing as before keeps working.
- An artifact with nothing live now says so at its address: "Nothing is live here right now", instead of claiming nothing was ever there, to anyone — before any sign-in. A version you saved without making it live still opens at its own address for you and anyone else who can edit it; everyone else sees the same page, with a way to sign in. Every artifact now reads as offline, live or deleted, and says whether it has a draft or a version waiting to go live. And an artifact deleted more than thirty days ago keeps its name reserved: its address still says it is gone, and nothing new can take it.
- For whoever builds this next: the redesigned assistant tools (v3) are built next, with the builder's test bench alongside them.
- Searching leaves things out with a minus, everywhere you can search: `-tag:old` on your artifacts and your library, `-bot:*` in the log, `-kind:comment` in the inbox, and on the dashboard a left-out filter shows as its own chip, struck through, that you can turn back. A word only on the second page of a site now finds it. The log and the inbox take one search line in the same terms. Two old search terms changed their names: `state:draft` is now `state:offline`, `state:ready` is now `has:staged`, and searching a page's words alone is `text:`; the old ones say what to use instead. And `state:deleted` finds what you deleted in the last thirty days, while it can still be brought back.
- For whoever builds this next: the assistant tools' next shape is written down as a spec you can build from, waiting on Martin's word. Your library's images, clips, sounds, fonts and themes become artifacts with an address, comments and a history of their own; any artifact can be offline, live or deleted, and can keep a draft you look at before it goes live; saving can send only what changed; a search can leave things out with a minus; and an agent takes a group of comments on in one call, with no session to open.
- For whoever builds this next: the spec's STACK and UX layers had reached their size limits, so two sections moved into their own files, how the product is built and tested, and UX's open questions, with nothing reworded.
- For whoever builds this next: the builder is now written into the spec, so it can be built from it: the box and every state it shows, what happens before someone signs up and when they keep what they made, remix from Share and an artifact's page, the check that looks at a page on a phone before it goes live, credits as a mechanism, the models it may run on and never one that trains on what people give it, and twenty-four briefs it must pass before anyone sees it. Held for Martin.
- For whoever builds this next: every account now has a handle. A suggested handle may include the company in a work address (for example @dent-ischemaview), and anyone can change theirs on the handle card.
- For whoever builds this next: the crate's menu stays as it shipped today. Hiding sits at its head, a deck keeps its Edit row for editors, and the version and audience show when the menu opens, not on the crate itself.
- For whoever builds this next: the server and CI now run the exact same Bun release (1.4.2), and a CI run no longer needs the internet to install it.
- For whoever builds this next: the assistant tools' next shape is decided. It is 29 tools in one grammar. Your library's material becomes artifacts like any other. An artifact is offline, live or deleted, and any kind can keep a draft. Saving content, changing settings and changing state each have their own verb. An agent takes a group of comments on in one call. Search has one grammar everywhere, with negation.
- The crate in every artifact's corner is simpler. Its menu is now five things: **Share**, **Comment**, **Versions**, **Manage** and **Report**. Share opens your device's share sheet or copies the address, says which it did, and shows a code a phone can scan; it always hands out the artifact's plain address, never the one you arrived on. Pointing at the crate, or opening it, tells you which version you're looking at and roughly who can see it — public, restricted or private. Hiding the crate moved to the top of the menu, well away from Report, and double Shift still brings it back. The comment bar now sits right beside the crate, and dragging either one moves both. What left the menu is where it belongs: a deck presents itself at its address, activity is on the artifact's page, inviting an agent is in the comment bar's list of who's here and on the artifact's page, and **?** lists every key in comment mode.
- Everyone now has a handle from the moment they sign up. The sign-up form fills it in from the name you type — `martin-may`, not `martin_may_4471` — and if you don't care you never touch it; if you do, you change it there, and it tells you at once if a name is taken or reserved. When your name is taken, the next suggestion is still a name (a middle initial, the name your email uses, your company's) before any number. Signing in with Google, Apple or your organization's own sign-in gives you the handle your name suggests, and you can change it once straight away in your settings. A new workspace's handle is suggested from its name the same way. Everyone who signed up before this, and every workspace without one, gets theirs at the next update, and deleting an account or a workspace frees its handle.
- Adding to your library now says how many assets it added, not "images", and mentions descriptions only when there was a picture to describe. The library search no longer offers `format:webm`, which it never held.
- For whoever builds this next: the builder's shape is decided. It makes pages with Claude Sonnet 5.5, lets someone start before signing up, offers Remix from Share and the artifact's page, starts from ten hand-written recipes, and may take a phone-width picture of what it made before it goes live.
- For whoever builds this next: two tests that flickered under load now hold steady. The recording's orphan-sweep test no longer reads a backup mid-write elsewhere in the suite as a reason its own bytes were never swept, and the inbox test no longer mistakes another suite's turn at the notification queue for its own access request never having arrived. Nothing you see changes.
- For whoever builds this next: a markdown file you publish will open as a readable page with comments, rather than downloading. That is decided now and built as its own piece of work.
- For whoever builds this next: the checks on every change now run on our own machine (mini6) instead of paid hosted runners, in a fresh virtual machine per run; one setting switches them back.
- Comments now work from the keyboard. Press C on any artifact you can comment on and comment mode opens — never while you're typing into the artifact, and an artifact that uses C for itself keeps it. Inside, J and K move from comment to comment, Enter opens the one you're on ready for your reply, E resolves it, ? lists every key, and Shift-C leaves. Screen readers now hear where you are — which comment of how many, whose, and how it begins — and every notice as it appears. A key comment mode uses no longer also sets off the artifact's own shortcut (on a deck, F and O used to do both), and ⌘ and Ctrl shortcuts such as copy and reload are left alone.

## September 28, 2026

- The comment bar now says where a stopped recording is in a few words — *Uploading 41%*, *Safe to leave*, *Saved* — with the whole sentence when you point at it or tap it, and read out to screen readers. It no longer has a second ✕ of its own next to the bar's: the bar's ✕ is the one close, and leaving never costs the recording. On a phone the bar keeps its ✕ in view while the recording uploads.
- The comment bar now says where a stopped recording is in a few words — *Uploading 41%*, *Safe to leave*, *Saved* — with the whole sentence when you point at it or tap it, and read out to screen readers. It no longer has a second ✕ of its own next to the bar's: the bar's ✕ is the one close, and leaving never costs the recording. On a phone the bar keeps its ✕ in view while the recording uploads.
- For whoever builds this next: the launch list now includes the builder, Git, workspace domains, a help portal, a place for decks and themes, a simpler crate, keyboard in comment mode and handles at signup, as Martin ruled; the comment bar keeps its count and avatars.
- When we ship a new version of the deck player, every published deck now moves to it, including one you opened in the editor or saved without publishing since. Before, just opening a deck to edit it could leave its audience on the old player, fixes included, until you next published.
- Leaving comment mode never costs you what you made there. Stop a recording and leave, or close comment mode while it uploads: it keeps going on its own, the browser asks before the tab closes until it has arrived, and coming back shows where it got to instead of offering it again as unsent. Leaving while still recording asks first, and *Stop & submit* now stops, sends and leaves in one go. Words you haven't posted — a new comment, a reply or an edit — are kept as you type: after Escape, a click elsewhere, leaving or a reload they're waiting in the next comment you start, or in the thread's field when you open it again, until you post them or press Cancel. And the note saying comment mode is showing what changed no longer sits on top of the comment bar for its first seconds.
- Choosing a comment in the list on the page now opens it beside its pin, however far down the page it is. On a long page, a comment you jumped to could open at the top or bottom edge of the window while the page was still scrolling to it, far from the row it was about, and the ring marking its spot pulsed where nothing was. It showed most on the comments a recording leaves, which are spread down the whole page. Walking the comments with J and K, following a link to one comment, and jumping to a change in the changes list now also wait until the page has stopped.
- Checking a publish first (a dry run) now gives the same answer the publish itself would about who can open the artifact. Before, a dry run passed three things the real publish then refused: your organization's own single sign-on as the way in, "everyone in the organization" in a personal workspace, and a workspace default nobody could get through. The single sign-on refusal now also says how to add it: publish first, then add your organization's sign-in to the artifact's access.
- For whoever builds this next: the search test that asks "what was touched after today" no longer fails for the few minutes after midnight UTC; it asks about the day its own fixtures were made.
- When we ship a new version of the deck player, every published deck now moves to it, including one you opened in the editor or saved without publishing since. Before, just opening a deck to edit it could leave its audience on the old player, fixes included, until you next published.
- When we ship a new version of the deck player, every published deck now moves to it, including one you opened in the editor or saved without publishing since. Before, just opening a deck to edit it could leave its audience on the old player, fixes included, until you next published.
- A workspace's own sign-in (single sign-on by OIDC, under Security in the workspace's settings) now works end to end. Registering your identity provider reads its settings from the issuer you enter, and says plainly what went wrong when it can't. Then you prove you own your email domain by adding one DNS record the page shows you, and check for it. From then on, people at that domain who sign in through it land in the workspace with their email already confirmed — no "Confirm your email" message — and someone who already had a password account at that address is signed into that same account. Your sign-in can only ever vouch for addresses at your proven domain: it never opens anyone else's account, and when it can't open one, the sign-in page says why and what to do instead of showing an empty form. Removing the provider now asks first, and takes that way in off every account that used it; the accounts stay, and open by email as before.
- When someone talks an artifact through and points or draws as they go, each of those marks now arrives in the comments like any typed one: it says what they were saying as they made it, sits among the other comments by when it was made, and can be answered and resolved without playing anything. Each says at what moment of the recording it was made and plays from there; one made while nothing was being said says so, and so does one whose words are still being written down. A recording is still one notification, however many marks it leaves, and the words someone spoke are not edited like the words they typed. Recordings made before today have been given their comments too — in the thread list on the page, on the artifact's Comments card, through your assistant and in the app.
- For whoever builds this next: the specification now says Google sign-in is on, instead of waiting on a decision made on 2026-09-24; it says where the reason the deck editor's live connection goes around bento's offline switch is actually written down; it marks "People who can comment here see everyone's comments." as still to come rather than built; and it closes two questions on the pending list that were settled weeks ago. Nothing you see changes.
- Choosing SAML single sign-on as the way into an artifact is now refused everywhere, with the reason, since nobody can get in through it yet: your assistant no longer offers it, a dry run of a publish says so just as the real publish does, and the refusal points you to your organization's OIDC sign-in or to email verification for your domain instead of "not available yet".
- Your published decks can no longer lose anything if we ever have to take a release back: a deck that a newer version of the deck player has already drawn stays on that version rather than being redrawn by the older one, so lists and headings never quietly disappear. Decks drawn by an older player still move up to the new one as before.
- For whoever builds this next: the launch list no longer lists the privacy policy's payment and sign-in providers or the edge rules' check as open, since both were already done, and it says which domains already refuse spoofed mail.
- Editing a deck now takes the whole page. **Edit** sits beside Open and Share at the top of the artifact's page, in place of the line that said the artifact is a deck; it opens the editor edge to edge, with the page's margins, sections and footer out of the way and the sidebar folded for the visit. The bar above it says whether you have unpublished changes and which version is live, and carries the one **Publish** — named for the version it makes, *Publish v5*, which goes live at once and rolls back like any other — and **Done**, which takes you back. The editor now looks like the rest of 23artifacts, in light or dark as you have it, and follows when you switch. Presenting stays in the deck's own Slideshow control, which now also opens the editor in a window of its own; the extra back link, the second Publish and the View button are gone. On a phone the trail keeps its last two steps.
- 23artifacts' own pages — sign-in, the dashboard, settings, the documentation and the gate — now run nothing but their own code, and refuse to be shown inside another site's page, so a site that tries to trick you into clicking inside one of ours gets a blank box. Nothing you do on them changes, and your published artifacts keep the rules they had.
- Mail pretending to come from 23artifacts.app or 23a.so, the addresses your artifacts live at, is now refused by the receiving mail servers that check.
- The specification's design notes now record the workspace's week in your assistant as built. Nothing you see changes.
- Asking your assistant what was opened across your workspace this week now shows it as a table, where the assistant can show its own interface: one row per artifact opened in the last seven days, most opened first, with its opens, each day's drawn small and the day it was last opened; past ten, one line opens the rest. Choose a name to see that artifact's traffic in place, and come back to the week; the arrow opens the artifact in a new window. With this, every page of 23artifacts has its surface inside the assistant.
- Asking your assistant about an artifact's recordings now shows them, where it can show its own interface: each with its title, the version, who made it, its length, its marks and the start of its words. Open one to play it right there under the version's preview image — a track with a tick at every mark, the line being spoken as it plays, and every line one tap away — or open it on the page, where its marks replay over the artifact. A recording whose words aren't ready says which case it is, and plays anyway.
- Asking your assistant for your themes now shows them, where it can show its own interface: each with its colours drawn small, its version, and which is the default. Open one to see every colour as a swatch with its value, its type set in its own faces — from your library, or from your computer where the face is installed — and its guidance. Owners and admins can make a theme the workspace's default there, or go back to letting the agent decide.
- Your assistant can show your library to pick from: pictures, a video's first frame, a sound that plays right there and a typeface set in itself, with a field to ask for something else; pick a few and choose Use, and the assistant knows which to build with. It can also give you a place to hand it files from your computer — drop them or choose them, and each goes straight to 23artifacts, never through the conversation, with its progress shown; hand them over and the assistant publishes them or keeps them in the library. Files too big say so before anything is sent. The plugin is 0.1.5, its large-sites guide saying how.
- When your assistant reads, makes or changes a deck, it can now show the deck's outline: its picture, its name and address, how many slides and whether it has changes not yet published, and each slide by its title (or its first words where it has none), with buttons that open the editor and the deck in a new window. A long deck shows eight slides and says how many more.
- Asking your assistant about your workspace now shows it, where the assistant can show its own interface: the plan against its limits (amber when one is nearly full), the defaults every new artifact gets, and the members and waiting invitations. Owners and admins change a member's role, remove someone, cancel an invitation, invite by email, choose the default theme and what an agent's change needs — and a default that reaches artifacts already published says how many before it applies. Your other workspaces are one pick away.
- Nothing changes for you here: your inbox and mail keep naming people by their email address where that is the useful name, and a commenter nobody can name still reads "anonymous". Both are now written down as decisions.
- In an assistant that shows its own interfaces (Claude, ChatGPT and others), asking who can open an artifact now shows its sharing list, and asking what's waiting shows your inbox. On the sharing list you can add people, change a role, rename, copy or revoke a share link, let someone in or turn them away, and close comments; making it public first says plainly what public means, and anything that lets more people in is also said in the conversation. The inbox shows what waits on you, everything one tap away, lets you clear what only tells you something, mark or silence a thread, and let someone in right from their request. Long lists show eight rows and say how many more. Where your assistant shows no interface, its answers are exactly as before.
- Comments now name the people who left them by name and handle for everyone, the artifact's owner included, in place of an email address: on the page, on the artifact's page in the dashboard, in the list of who is here, on recordings and in the activity. Commenters see each other by name rather than as "anonymous". The owner still finds a commenter's email address in one place, the thread itself: open it, and each person's address sits beneath their name. On an organization's artifact, the addresses are for its owners and admins alone; the person who published it, when they are neither, sees names like everyone else.
- An embedded artifact whose share link you turn off now says so in the box it was placed in: "This link was turned off", in 23artifacts' look, asking the reader to get a new link from whoever shared it — never the artifact's name or anything it held, and never a sign-in inside someone else's page. Before, the box showed one line of plain text.
- When you open comments on a page while others are commenting, the live connection now sends each comment exactly once and in order. Before, a comment that arrived at the moment you connected could be sent twice. The page already ignored the second copy, so nothing looked different.
- What you wrote through your assistant, or on the artifact's page in the dashboard, now counts as yours on the artifact itself, whichever of your verified addresses let you in. It is listed for you there, and you can answer it, resolve it, edit it and remove it on the page. Words your assistant wrote still carry the assistant's mark on the page, not your picture.
- Editors on an artifact can now look after its comments as the owner can: resolve or reopen anyone's thread and remove anyone's comment on the page itself, and hide someone's comment or show it again from the artifact's page, the API or their assistant, which still list a hidden comment for them so whoever hid it can bring it back. Commenters and Viewers act only on their own words, and nobody edits anyone else's. On the page, Resolve now appears only on a thread you may resolve.
- A link that opens an artifact straight into comment mode, or onto one thread, now does so on the first visit even when the artifact asks you to sign in or prove your address first; before, the gate brought you back to the plain page and only a second visit opened comment mode. And reading an artifact's comments on its page in the dashboard now counts as looking at them: while you are reading along there, a new comment is not also mailed to you at once.
- Visit records in an artifact's log — pages served, grants, refusals and arrivals by link — are now kept for up to 12 months and then deleted, as the privacy policy says; until now the log kept them for as long as the artifact lived. The privacy policy now also says when one record is kept longer: when it is needed for an open abuse report or a legal claim, or the law requires it, until the matter is resolved.
- The documentation, the terms and the privacy policy now read in full where scripts don't run — for someone without JavaScript, a search engine, and an assistant asked to follow the setup — with every assistant's connect steps listed together. The documentation now covers comments, decks, themes, your asset library, Activity, finding anything and publishing markdown (ask your assistant for a page: a markdown file on its own downloads rather than shows), in the words the screens use, and names the apps that run a model on your own computer and connect to 23artifacts: Codex, Goose, Open WebUI and VS Code. The home page's deck tile no longer shows people following a presenter, which decks stopped doing on 2026-09-10.
- A page of yours that can't be read now says so where its content would be, with a Try again, instead of staying blank or saying "Loading…" forever: your artifacts, one artifact's page, a tag's page, your assets and one asset, your credentials, Activity, your workspace's settings and its plan, teams and publishing default, your notification settings, and the operator screens (which no longer call a failed read "not authorized"). It says whether to check your connection or that the fault is ours, and shows a refusal the server wrote in its own words; once a page has shown something, a failed refresh keeps it and says so in a notice. The buttons in 23artifacts' mail now open the right part of an artifact's page — "See the activity" opens Activity and "Answer the request" opens Access — even when you have to sign in first, and so do the entries in your inbox; mail already sent opens the right place too.
- A comment you pin on the page now shows your picture the moment you place it, not your initial until you reload. The same goes for comments other people leave while you watch, and for comments that arrive after your connection drops and comes back. Anyone the page doesn't show your name to still doesn't see your picture. If you signed in with another of your confirmed email addresses, your comments still show your picture. Comments an assistant writes for you keep the assistant's own mark instead of your picture.
- A recording someone leaves on your artifact no longer turns up as an artifact of its own ("Recording of …"), and no longer uses up your workspace's artifacts or storage — three recordings used to fill a free workspace. It plays where you left it: on the version it was made on, in comment mode, with its player open, and that is where "Play" on the artifact page and your assistant now send you. The recordings already made moved over the same way, and their old artifacts are gone.
- Everyone who is an Editor on an artifact now reads everyone's comments, recordings and summary on it — on the page itself, on the artifact's page, through the API and through their assistant — not only the person who made it; a commenter's email address still reaches only the owner. Commenters and Viewers still read only their own. The line under the comment box says so: "Seen by the owner and editors" where it said "Seen by the owner and the person who made it", and an Editor you can mention now appears in the name picker when they can read what you are writing.
- An upload address that has made every publish or batch it was made for, or whose minutes are up, now answers that it is gone (410) — saying which, and that a new one comes from asking your assistant for another upload address — instead of refusing you as though you lacked permission (403) or had signed in wrongly (401), so neither you nor your assistant goes looking for a credential problem that is not there.
- Signing in before confirming your email no longer stops at "Email not verified": the page says which address is waiting to be confirmed, that the link we sent confirms it and signs you in, and sends that link again with one click. After signing up, the check-your-email page says what the link does — confirms your email and signs you in, or signs in the account the address already has — and what to do if it doesn't arrive: look in spam, check the address, send the link again, or use a different email.
- An address with nothing to show now says so on a page instead of one bare word. An address that doesn't exist or was mistyped, an artifact that was deleted, one taken down for breaking the terms, and one with no live version each answer with a short page in 23artifacts' own look, light or dark: it names the address you came by — never the artifact's name or anything it held — and offers a way on, to 23artifacts and its documentation, or to the terms for one taken down. A page missing inside a live artifact offers the artifact's first page. An embedded artifact that is gone says so inside the box it was given. A script, a stylesheet or a program asking for one of these addresses still gets the plain line it always did.
- A card whose preview image could not be made now says so, and why, instead of saying it is being made forever: the page did not finish loading within 60 seconds, drawing it gave back something other than an image, the page could not be opened, every attempt failed while other pages were drawn fine, or the trouble is on our side. The artifact list's cards and rows, the artifact page, your assistant's artifact card and its answers all say the same thing, and none of them shows a broken-image icon any more. As the owner you can ask for another attempt — **Try again** under the preview on the artifact page, or ask your assistant — and it is tried again at once; asking again while it is being made changes nothing, and you can ask up to ten times an hour.
- Before you write a comment or a reply, a line under the box now says who will read it — "Seen by the owner", "Seen by the owner and the person who started this thread", or "Only you will see this" — on the page itself and on the artifact's page. The artifact page's Comments card lists what people said by the version they were looking at: each version with how many of its threads are still open, when it was published and a link that opens it in comment mode, and inside it the threads, the recordings made on it and a summary on demand; it no longer lists one entry per person or per recording. "Invite an agent" is there from the start, before anyone has commented.
- The design system now says how the artifact page draws the line naming who will read your reply, and a recording listed under the version it was made on, so both look the same wherever they appear on the product's own pages.
- An agent that installs skills from a site's `/.well-known/skills/` address — Hermes Agent among them — now finds 23artifacts' publish-artifact skill there, with every guide it links, beside the `/.well-known/agent-skills/` address the discovery draft uses today.
- On an artifact's page and through their assistant, a member of the workspace sees the people its owner added by address again — each by name and handle, never by the address, which only the owner sees; since the member-permissions landing those entries had dropped out of everyone's list but the owner's. Someone outside the workspace whom an entry lets in sees the entries and their roles, naming nobody.
- Your assistant can put a whole folder of screenshots, clips or fonts into your workspace's library from its shell with nothing of yours on the machine: it asks for a one-time upload address for the library and sends the files straight from disk to it, never through the conversation, and each file says whether it landed. The address lasts minutes, is spent by one batch unless more were asked for (a batch that stored nothing costs nothing), adds only what you could add yourself — in an organization a member adds new names and leaves the ones already there to its admins — and reaches nothing else. The guides no longer ask you to put a credential in your assistant's shell for this. Sending files to the library through the API is limited to 60 batches an hour. The plugin is 0.1.2.
- Email addresses in what you publish reach your visitors exactly as you wrote them: until today our network provider rewrote them into "[email protected]" placeholders and added its own script to decode them. Our help page's address reads the same way, even without JavaScript.
- The 23artifacts plugin for Claude, ChatGPT and Codex is MIT-licensed: anyone may read, reuse and adapt its skill and commands, which is what the plugin directories expect of a listing.

## September 27, 2026

- How the chat surfaces still to come will look inside your assistant is set down for review, each drawn working in both themes at a desktop's and a phone's width: the sharing list and share links, the inbox, the workspace, a deck's outline, a theme, the library picker, the recordings with a player, handing over a file, and the workspace's week on the log; the cards and the log already in your assistant are recorded as they look today, and so are the two initials on a workspace without a picture in the switcher. Nothing you use changes yet.
- You can see every assistant you've let act for you, and take the access back: Settings → Account → Assistants lists each one — its name, where it comes from, when you allowed it and when it last connected, and what it may do — with Revoke, which ends its access at once; its next request is refused and it has to ask you again. The page you allow an assistant on now says where to find this, and so does the support page.
- The specification now says what each of the chat surfaces still to come will show and let you do inside your assistant, before any is built: the sharing list and share links, the inbox, the workspace with its members and defaults, a deck's outline, a theme's colours and type, the library to pick material from, your recordings with a player, handing your assistant a file straight from your device, and the workspace's week as a table on the log. Nothing you use changes yet.
- Help has a page: 23artifacts.com/support says where to write (hello@23artifacts.com), how to connect your assistant, where the documentation is, how to report an artifact or a security problem, and what you can do about your account and data yourself — and it reads even where scripts don't run. Every page's foot links it. The documentation's connect steps are current for Claude (Customize → Connectors), ChatGPT (developer mode, then chatgpt.com/plugins), Claude Code, Codex, Cursor and VS Code, and any other assistant that connects to remote MCP servers. The guide for large sites no longer suggests handing the assistant's shell a token from your machine: the one-use upload address, or staging over the connection, covers it. The plugin is 0.1.1.
- Someone you invite to one artifact — by their email address, their domain, or a share link — can now reach it through their own assistant exactly as they can on the page: read it, and comment where their role allows, and nothing else of your workspace; a share link pasted to the assistant opens the artifact with the link's role. A credential still reaches only its own workspace. The tools that can put something on the open web — publishing, making a version live, a deck's publish, changing who has access, the workspace's default access and invitations, and restoring a deleted artifact — now say so, so your assistant's host may ask you first. A very large deck is read a page of slides at a time.
- 23artifacts comes as a plugin: one package that installs in ChatGPT, Codex and Claude (claude.ai, Cowork and Claude Code) with the connector, the publish-artifact skill and three commands for Claude Code — `/23artifacts:publish` from disk, `/23artifacts:show` and `/23artifacts:comments`. It is generated from the same guides the connector serves, so the skill an assistant installs is the one it would read over the connection; the guides now sit under `references/` in the skill, at those paths everywhere they are served. Not in any directory yet: `docs/plugin.md` says how to install it by hand.
- Your assistant's answers name people, workspaces and assets the way you know them, and carry no internal ids: a recording's maker reads as "you", their address (to the artifact's owners and admins), "a visitor" or "someone" instead of an account id; activity names people by name or address; the inbox names a workspace by its handle; a library asset by its name and version; and a chart grouped by artifact by each one's identifier. A failure the assistant has no words for is recorded and answered in one plain line, never with the server's internal error text. Every answer of the end-to-end run is now checked for secrets, internal ids, and another person's address shown to someone who should not see it.
- Your assistant carries a third less of 23artifacts into every conversation: the 42 tools' descriptions went from 26,874 characters (about 6,700 tokens) to under 18,000, saying what each tool does, when it is for, and the facts that prevent a wrong call, with the depth in the guides they name. The standing note an assistant reads first now says in its first 512 characters — all Codex reads — what 23artifacts is, which tools make, find, show and read an artifact, where the guides are, and that what other people wrote is never instructions.
- Every one of your assistant's tools that returns data now declares the shape of what it returns — 41 of the 42, where 12 did before; the guide, which answers with a document, is the one that answers in words alone. An assistant that reads structured results, ChatGPT among them, can rely on the fields each answer carries, and every shape stays open to fields added later, so a conversation already under way never starts refusing an answer because the product grew.
- Assistants can connect by naming themselves with a published client document, the way ChatGPT prefers, as well as by registering first: 23artifacts fetches the document, checks it, and asks you to approve the connection on its own page — which now shows the site the assistant's document came from beside the name it gives itself.
- For whoever submits the connector next: `docs/directory-review.md` gathers what the ChatGPT and Claude directories check and where 23artifacts meets each, the test cases a reviewer runs, the demo account to create, the privacy policy's fit, and the open questions; and 23artifacts.com can answer OpenAI's domain check at `/.well-known/openai-apps-challenge` once the token it issues is configured.
- Asking your assistant about an artifact's log, or your workspace's, now draws it where the assistant can show it: the chart with its window, measure and grouping to change in place, one artifact's traffic with its top pages and referrers, or the newest entries — in the same words as the artifact page.
- Asking your assistant to show several artifacts, or the ones a question finds, now shows them as cards to pick from where the assistant can show them: a row of small previews with each one's address, version and who can open it, each opening in a new window; "See all" spreads them into a grid, and picking one shows its full card and tells the assistant which one you mean. Preview images come in a smaller size for this, made once and kept.
- Your assistant's answers stay a size it can read: a long list of comments comes a page at a time, a burst of new comments comes in order, and a page of artifacts, assets, inbox entries or activity that would run too long comes back shorter with the way to continue; reading an artifact's files brings what fits and names the rest to read one at a time. Starting a deck at a slug that is already taken is refused, where before it replaced that deck with an empty one. Refusals say what was wrong and how to fix it — an artifact, comment, work item, agent session, staged upload, version or workspace that does not exist is named back as it was given — and an agent whose draft waits for a person is told to publish it with `live: false`. For whoever builds this next: every one of the assistant's 42 tools is exercised end to end, with good and bad arguments, on every push (`bun run mcp:e2e` prints the table).
- Your assistant can set a workspace's default access: the list of people and roles every new artifact starts with, and whether comments are closed across the workspace. New artifacts follow that setting until you switch comments on the artifact itself, and the assistant can hand an artifact back to the workspace's setting. Changing it when existing artifacts follow it first says how many it would reach and changes nothing until confirmed, and opening comments that way is refused where it would let anyone holding an address or a share link comment. Who can open an artifact now says, entry by entry, why each holds what it holds. The assistant's tools are worded as facts rather than instructions, and each says whether it only reads, adds, or needs your confirmation. The API's workspace routes are now `/api/v1/workspaces` and `/api/v1/workspaces/{workspace}`.
- Three small fixes from Martin's review: a workspace's initials in the switcher keep their colour when you point at them; cards on an artifact's Collaborate, Access and Settings tabs stand level, with no gap under the shorter one; and a long list of workspaces scrolls inside the switcher, keeping Settings and New workspace in view and the menu clear of the screen's edge on a phone.
- The iOS app opens and edits decks again: since this morning's change to how the API names artifacts, reading or changing a deck through `/api/v1/decks/{deck}` answered "not found". A deck there is now named the way every artifact is — its address, its identifier or its slug.
- Your assistant's library, theme, deck and inbox tools are simpler. It finds material in the library with the one question the artifact search takes, stores a video it has staged rather than relaying it as text, and corrects the descriptions and tags of many assets at once or deletes them in the same step. Saving a theme makes a new one or a new version of it, and deleting the workspace's default theme says so. A new deck takes the same access a publish does and says who can open it. The inbox, a room and a deck are named however the assistant holds them — address, identifier or slug — and a workspace by its handle. The API gains `PATCH /api/v1/decks/{deck}` for changing a deck a piece at a time.
- Your assistant's comment and agent tools are simpler: comments, replies and recordings name an artifact however it holds it; one tool changes a comment — your own words, removing it, or, for owners and editors, hiding someone's; one tool joins an artifact as an agent and keeps its place; and one tool takes a piece of work from creation through claiming and reporting to letting it go. Agents working from a shell get the same through the API: an invitation to paste, agent sessions and work items.
- Your assistant can manage your organization's members: invite people by email as members or admins, send an invitation again or cancel it, change someone's role and remove them — under the same rules as the workspace page (owners and admins do it, only an owner touches an owner, a workspace always keeps one), with the same email, the same limit of 50 invitations a day, and nobody joining until they accept. Your workspace's handle, its settings and the credentials that publish into it now all live in the two workspace tools, and one tool makes a credential for your CI — its secret shown only on a page you open signed in — or a single-use upload address for one big publish, with one more to revoke either.
- Your assistant reads and changes who can open an artifact the way its page shows it: a list of entries — a person, a domain, your workspace, anyone with the address, a share link — each with its role, Viewer, Commenter or Editor. Two tools replace five: one reads the list with its share links and waiting access requests (a stranger's message arrives quoted), and one changes it in a single step — adding and removing people, changing roles, closing comments, setting the link preview, making and revoking share links, and letting in or declining whoever asked — announcing in words whenever more people can open it. Publishing a new artifact takes the same entries. The API's `PATCH /api/v1/artifacts/{artifact}/access` does the same, and the iOS app's Unpublish uses it; the app builds again, after the library's sounds had stopped it compiling.
- Your assistant publishes and changes your artifacts with five tools where it had nine. Publishing names an existing artifact however it holds it — address, identifier or slug — for a new version, or a slug for a new one, and never publishes over a slug that is taken; it sets who can open an artifact only when it makes it, and its reply leads with the address and says what comes next. Staging a large file is one tool in three steps. One tool now changes an artifact's own settings together — its name, description and tags, its room, the crate, whether an agent's change goes live without asking — and brings back an artifact deleted in the last 30 days, which nothing could do before; deleting says until when. The API's `PATCH /api/v1/artifacts/{artifact}` does the same, replacing the separate tags and room-settings routes.
- Your assistant finds and shows your work with four tools where it had eight, and names an artifact however it holds it — its address, its identifier or its slug. Finding takes one question (`tag:brand kind:deck touched:7d`), and each artifact it finds leads with its address and says who can open it. Showing takes one artifact, several, or a question's matches, and brings every fact with the version history and the preview image itself, so the assistant can see what it is showing; it replaces reading an artifact's details separately. Reading a version's files is now `get_artifact_files`, and one tool, `get_log`, reads an artifact's or your whole workspace's activity as entries, as a chart or as its traffic. The API's artifact routes take the identifier in place of the slug too.
- For whoever builds this next: the design system now describes an artifact page's header — the name with its menu and info mark, the bell, Open and Share, and the line of facts with a worded Copy link — the bell's menu of watch levels, and the field that adds people by email at the head of who has access, all as they were built in the dashboard pass.
- For whoever builds this next: the design system now describes the quiet table heads, the activity log's one-row header (the window as one control, the Filters capsule, the chips), its day headers in words, rows parted by space, the list that extends itself, and one asset's page — its preview, its checkerboard and the references that copy — all as they were built in the dashboard pass.
- Filters work the same everywhere: on your artifacts, your assets, your share links and Activity, one Filters button opens a panel with quick time ranges (7 days, 30 days and so on) or a custom range of your own, then everything else you can narrow by, each with its counts. What you chose shows as chips under the search, each removable. Activity's time window moved into the panel and always shows as the first chip. Share links can now be narrowed by when they were made, their artifact, whether anyone opened them, and their role. Artifact cards now show the artifact's address under its name.
- For whoever builds this next: the design system now describes the lists' one-row toolbar, the sort that says what it sorts by, tags held to one line, the artifact row's columns and the order they fold away, the level cards with their foot line, the access summary, and the empty workspace that shows the connector address — all as they were built in the dashboard pass.
- For whoever builds this next: the design system now describes the one Filters sheet every list and Activity share (time presets and a custom range, then each fact's values in place, and the chips), the lists' toolbar, the sort that says what it sorts by, tags held to one line, the artifact row's columns and the order they fold away, the level cards with their address and foot line, the access summary, and the empty workspace that shows the connector address — all as they were built in the dashboard pass.
- For whoever builds this next: backups are checked for every kind of workspace — an account's export and weekly backup come from its personal workspace, an organization's are its owners' and hold every artifact in it, a member's private ones included — and two backup tests that failed whenever the database's clock ran a millisecond ahead no longer depend on it. Nothing changed in how backups work.
- An artifact's page opens with a header instead of a card: its name with a menu for renaming, the description, copying the link, opening it and deleting it; an info mark for its address, who can open it and which version is live; and a Share button that opens who has access right where you are. Type one or more email addresses or a domain, pick what they can do, and add them in one go — each person is emailed the link, with a note if you write one, unless you untick Notify people; share links and the other ways in are one menu away, and Copy link sits at the bottom. The watch control is a bell. Whether to take comments, and the room, moved from Collaborate to Settings, the tabs are underlined rather than boxed, and the footer is one quiet line.
- For whoever builds this next: every push and pull request now also runs the tests that need a database and file storage, in their own CI job, and the tests that used to collide when the whole suite ran at once no longer do. The job reports without blocking a landing until it has shown itself green on main.
- Your personal workspace is now a workspace like any other underneath: every account has one, made with it and removed with it, and everything you had — your artifacts, publish tokens, plan and subscription, backups and their schedule and bucket, custom domains, usage — moved into it with nothing about it changed. Nobody can do anything on any artifact they could not before, and nothing you see changes: it is still "Personal", your handle and picture are still yours, your library keeps its 250 MB, and the app and the API still name it as you. It takes no second member yet; inviting someone, adding a team, renaming or deleting it, or giving it an identity provider is refused.
- In an organization, the asset library and themes are kept by its owners and admins: every member still sees everything in them and adds new images, videos, fonts and themes, while changing what is there — a new version under a name already used, a description, tags — and deleting are the owners' and admins'. A member who tries is told to add theirs under a new name, and the library page shows them no edit or delete controls. Your personal library is still yours to change.

## September 26, 2026

- For whoever builds this next: the design system now describes the question-mark circle beside a card's title, and an artifact's row in the list with its description, not its slug, under its name — both as they were built in the dashboard pass.
- The sidebar leads with your artifacts. The inbox is a bell beside your name that shows how many things are waiting; Docs and your workspace's Settings sit quietly at the foot; the account menu holds account settings, light or dark, and sign out; and the operator screens are reached from that menu instead of sitting in everyone's sidebar. A workspace's settings — every workspace, your Personal one included — are tabs now: General, Members, Defaults, Plan, Security and Backups, each with its own address, and every workspace in the switcher has a gear that opens its settings. Your account is tabs too: Profile, Emails, Sign-in, Notifications, Appearance and Credentials. Adding people to a team is a search with checkboxes, several at once.
- For whoever builds this next: the design system now describes the sidebar's new foot as it was built in the dashboard pass — the inbox bell with its count on the account row, the quieter Docs and Settings rows above it, the light/dark/system choice in the account menu and on the account's Appearance tab, and the gear on each workspace in the switcher.
- Activity is calmer and keeps going: the window is one control beside the search, and Type and Event now sit inside Filters with every other narrowing, each value showing how many entries it matches. Days are named quietly (Today, Yesterday, Sunday, Sep 20) with no rules between rows, the chart's numbers no longer lose their first digit, and scrolling to the end of the log loads older entries by itself until it says that's everything. Every table's column heads are quieter. An asset's page shows the asset without a frame round it — a checkerboard appears only behind an image that is actually see-through — names its library and its name as two things, and adds a Use it card with the name to give your assistant, and the same name pinned to that exact version, each one click to copy.
- Your artifact list and your library are easier to narrow and easier to read. One row now holds the search, a Filters button (kind, access, lifecycle or format and library, and when it changed), a Tags picker that finds among every tag you use and opens the chosen ones as a page, and a sort that says its direction — Recently changed, Name A–Z, Largest first; whatever is active shows beneath as chips you can remove one by one or clear at once. Each row now leads with a small preview image, keeps its tags to one line and says how the artifact is reached — "Private · 2 links", "3 people · 1 domain", "Public" — with every way in named on hover. Cards show the description, keep their tags to one line so a grid stands level even for an artifact with twenty tags, and end in a quiet line of access, version and time. New artifact starts with connecting your assistant — the address to add and how to connect — before uploading files, with pasting HTML one click away; an empty workspace says the same. The bar no longer counts gated artifacts.
- The comment panel's tabs fit on one line again: each count is a small badge beside its label, and the button that copies the open view for an agent sits in the row beneath the tabs. The panel's tabs, its open/all filter and a few of its buttons also render at the sizes they were designed at, rather than the browser's larger default they had fallen back to.
- Your assistant's connector no longer answers to its old names. The review-named tools that kept working after the comment tools were renamed — `add_review_comment`, `list_reviews`, `create_review` and the rest — and their API routes (`/api/v1/reviews`, `/api/v1/artifacts/{slug}/reviews`, and the `/api/v1/projects/…` spellings) are gone, as Martin ruled: nobody depended on them yet. The prompts are now `show`, `publish` and `comments`, each taking `artifact`; the comments card is served at `ui://23artifacts/comments/v1.html`; and the comments card no longer retries a tool under an old name.
- Ready for agents that work inside a browser: every served artifact now offers an agent in the viewer's own browser two read-only page tools — one saying what the artifact is, which version is showing and what that viewer may do there, and one listing the comment threads that viewer can already see, each comment quoted as someone else's words. ChatGPT's desktop browser reads them today; Chrome and Edge will once our WebMCP trial token is in place. Nothing can be changed through them, a gated artifact offers nothing to someone it has not let in, and a browser without page tools gets the page exactly as before.
- Your workspace now has a default theme, beside its default access in settings. It starts at "Let the agent decide": your assistant designs each artifact its own way, instead of being nudged toward your themes before it builds anything. Choose one of your themes (or ours) and an assistant building in that workspace uses it unless you ask for another look; name a theme when you ask for something and you get that one. Your assistant can now read your workspace — its plan and how much of it you have used, its defaults, its members and the credentials that publish into it — and change its default theme, its agent policy and your handle, with the same on the API (`GET`/`PATCH /api/v1/workspace`). Your themes list marks the default, and publishing something new without it says so.
- In chat apps that can show them — Claude and ChatGPT among them — publishing an artifact or asking to see one now shows its card: the preview image (or that it is still being made, or could not be made), its address, its version and who can open it, with an Open button that opens it in a new window and a button that copies its address. Publish again and the older card steps aside for the newer one. The artifact itself never runs inside the chat, and assistants that show no cards, such as Claude Code, get exactly the text they got before.
- A first round of Martin's dashboard pass. An artifact now has one address everywhere you see it: the long .23artifacts.app address is gone from the artifact's settings, the crate card, the crate on the page and its version links, and every link is written as `<id>.23a.so` (the long address still works). Inviting someone to a workspace no longer asks you to prove you are human. The platform's operator can claim names like `23made` for their own workspace. Cards say what they are in one line, with a question-mark circle beside the title that opens the rest and a docs section that actually explains it — new ones for handles, members and roles, the corner crate, comments and the asset library. Going back to the artifact list, the library, share links or activity finds the list exactly as you left it, scrolled where you were, and the Artifacts and Assets crumbs take you back rather than reloading. The share links table fits the window with no sideways scroll, its menu no longer wraps, and revoking a link asks first in a proper step. The artifact list drops the repeated slug under each name; activity says it covers every artifact in the workspace and names each entry's kind and every filter on hover; the asset page loses its extra back link; and nothing on the artifact, asset or settings pages scrolls sideways on a phone.
- Feedback is called comments everywhere you meet it. The artifact page's card is Comments and counts comments, not reviews; the role that can comment is Commenter; a spoken pass is a recording, with its own Recordings tab on the page's comment bar beside the Summary; the log says "started a recording", "resolved a thread" and "made a share link Commenter"; and the crate, the markdown you copy for an agent, the report, the landing page, the privacy policy, the iPhone app and the card your assistant shows all use the same words. That card now wears the crate instead of the retired "23" badge, and no longer asks you to label a comment as praise, an issue or a question. An artifact's address is its id, like `k3v9x2qa.23a.so`, wherever it is written down: the handle card says a handle is how you are credited, mentioned and found and that no address carries it, so changing it breaks nothing; the docs and the artifact page say the same; your assistant's publish reply, its listing and the agent invite lead with that address; and the email telling someone their access request was approved names the artifact and links to its address.
- For whoever builds this next: the new tool surface is now the spec. Martin approved the catalog at https://rzsiqhhf.23a.so by answering its four questions — a tool takes an artifact by its address, its id or its slug; workspace members can be invited, removed and given another role from the assistant; sound joins the library before launch; and every in-chat surface comes before launch — and the layers now name all forty-two tools and their API twins. Inviting someone to a workspace no longer needs a human check, from the page or from an assistant: the daily limit and the invitee's acceptance by email still apply. Nothing changes in the product yet; the build follows in its own landings.
- Your workspace's library now keeps sound: add an MP3, an M4A, an Ogg (Vorbis or Opus) or a WAV up to 25 MB beside your images, video and typefaces, find it with `kind:sound` or its format, and reference it when you publish like any other asset. The library tells a sound from a video by what is inside the file, so an audio-only MP4 is kept as a sound. Pages you publish now serve M4A, Ogg, Opus, AAC and FLAC files under their proper types, so browsers play them.
- For whoever builds this next: Martin's rulings on the agent-surfaces round are recorded, and the spec now says what they change. Your assistant's tool descriptions are to state facts, with what to do next said in each result; the interactive cards an assistant can show become the product's control surface in the chat — what the dashboard shows and does, never the artifact itself running, which opens in a new window — starting with the artifact card; the submission to OpenAI keeps those cards; a tool that replaces, removes or widens something asks before it runs; a renamed tool stops answering under its old name, with no aliases kept; and the product and its plugin are named 23artifacts for good. A workspace gets a default theme, set like its default access and starting at "let the agent decide", and no agent is nudged toward a theme any more; an artifact is described as whatever it carries — images, video and sound as well as pages. Cowork, Hermes Agent, OpenClaw and Meta Muse join the clients we measure against. Two questions stay open — the plugin repository's licence, and whether WebMCP ships now — and the whole tool surface is being redesigned from scratch, proposed on the private page tool-surface-v2 (https://rzsiqhhf.23a.so) before anything is built. Nothing changes in the product yet.
- For whoever builds this next: what a workspace member may do is written down before it is built. The person who made an artifact gets an entry of their own on its list, starting at Editor and lasting while they are a member; every door — the dashboard, your assistant, the API and the served page — asks one answer what someone may do, a table says what each act needs, and someone no entry names holds nothing. Martin has answered its three questions: share links stay with the workspace's owners and admins, a member chooses who sees a new artifact they make, and the shared assets and themes are the owners' and admins' to change and remove while every member reads and adds to them. Nothing changes in the product yet.
- Making a workspace now asks what its members get on each other's artifacts — nothing, Viewer, Reviewer or Editor — with nothing chosen until you pick, and the workspace page's default-access card changes it later. Whatever you choose is given to each new artifact published without its own access; anything already published keeps its own list, and an artifact you publish with its own access gets exactly that.
- Being in a workspace no longer opens everything in it. A member of an organization now gets on each artifact exactly what its access list gives them: the owners and admins keep everything; whoever made an artifact keeps an Editor entry of their own while they are a member, which the owners can lower or remove; everyone else gets what an entry names them for — including "Workspace members", whose role (Viewer, Reviewer or Editor) you now pick on that entry — and nothing otherwise. A member's list, search and assistant see only those artifacts. Changing who has access, share links, the activity log and downloading a version's files stay with the owners and admins, and publishing a version or promoting one needs Editor. Someone who leaves or is removed is back at the sign-in gate on their next visit, whatever they still had open. And publishing with a role on each access entry now keeps those roles.
- For whoever builds this next: Martin's answer on Claude plugins is recorded. 23artifacts takes them up as one rung of a ladder every agent can climb: a floor that any MCP client can use from tool names, descriptions and results alone, with each richer capability used where a client has it — a plugin's skill, MCP Apps showing results in the chat, and later WebMCP on a served page. The round that designs it — the capability ladder measured across clients, where guidance lives on each rung, the MCP Apps inventory, WebMCP's status and the plugin plan, with nine forks for Martin — is the private page agent-surfaces-round (https://ogj6t4ij.23a.so). Nothing changes in the product yet.
- We now find out when 23artifacts is down or going wrong, rather than hearing it from you: an outage is noticed from outside our servers within about three minutes, and so are pages answering with errors, a server process killed for running out of memory, an update that quietly failed to go out, and the daily cleanup that keeps the privacy policy's promises — deleted artifacts erased after their 30 days — falling behind or failing. A dropped database connection no longer restarts the service and interrupts every page being served. And a large upload is refused at the start, with the plan's storage limit, when it would not fit — rather than after all of it has been sent.
- The last two review tools are gone from your assistant's list. To leave a verdict on a whole version it now simply adds a comment with nothing pinned, and `list_recordings` lists the recordings people make by talking through an artifact — title, version, length, the start of what they said — for `get_recording` to read in full; the same list and read are on the API at `/api/v1/artifacts/{slug}/recordings`. An assistant that learned the old `create_review` and `list_reviews` keeps using them, and so do the old API routes. A Google-only artifact whose deployment has Google sign-in off no longer shows a Google button that goes nowhere: it says so and offers its owner the ordinary sign-in.
- Your assistant's comment tools now speak the product's words: `add_comment`, `list_comments`, `edit_comment`, `delete_comment`, `resolve_comment`, `await_comment_activity`, `get_recording`, `get_agent_invite` and `join_comments`, and the guide it reads is `comments`. A conversation that started before the change keeps working under the old names. The assistant also tells the truth about who can see a page: a new artifact is private unless you say otherwise; changing who has access applies at once, not when old access runs out; `create_deck` takes who can see the deck and says what it got; the log says a private artifact admits only its owner instead of "sign-in"; and the dashboard names each way in — Email verification, Google sign-in, Workspace members — instead of showing its code. A Google-only gate is refused, with a way to do the same by email, on any deployment where Google sign-in is off.
- Preview images no longer give up for good when the renderer is busy or down, or when the picture could not be stored: a version whose picture could not be made because the renderer was rate-limited, erroring or silent, or because the store refused the image, waits and is made when that returns, and only a render that was actually performed and produced nothing usable counts against it. A page that alone makes the renderer fail while everything else renders fine is given up after four tries rather than holding up every newer picture behind it. An attempt cut short by a deploy is tried again rather than counted as spent, and a render answering after the platform has moved on can no longer overwrite what happened since. How many preview images are waiting, and how many could not be made, are now numbers the platform reports, so an outage like the one that silently gave up fifty-three pictures between September 10 and 12 would be seen, how much browser time each preview image costs is now counted, and a page that takes up to a minute to load still gets its picture.
- The privacy policy now says where your portable copy is: Export now, in the Backups card of your account settings, with no email to us. On the sign-in pages, the check-your-mail card's glyph is green and the expired-link card's amber, and the inbox marks what waits for you with the vermilion dot the design calls for. For whoever builds this next: the learnings inbox is drained to zero — test files that run the maintenance sweep now take turns, the overlay build refuses a source git does not track, a large call to the assistant connector is logged before its body is read, and three design choices wait for Martin under Pending in the decisions ledger.
- For whoever builds this next: `main` now refuses a merge without an approving review, a rule meant for the bot accounts agents use on another machine; agents working on Martin's own account keep landing green changes as before, with `--admin`, by his ruling. Nothing changes in the product.
- Every page published here now carries its own crawling policy instead of the network’s default one: search engines may list a public artifact, and training a model on it is refused, because what you publish stays yours and we only host it. Publish a robots.txt inside your artifact and it replaces ours — which is, for now, how you keep a public artifact out of search.

## September 25, 2026

- Custom domains are off while we redesign them. Instead of one domain for one artifact, a workspace's own domain will carry every artifact's address — `abc123.artifacts.yourcompany.com` — and be the address shown everywhere. Until then the artifact page, the assistant's tools, the API and the docs no longer offer them; every artifact keeps its `23a.so` address.
- Opening an artifact directly always shows its Report link and the crate again. Since Cloudflare started caching artifact files on 2026-09-24, one embedded view of a page could fill the cache with the copy that leaves them out, and the next visitors got that copy — for up to a minute, or as long as a year on a version's own address. Pages are now kept only in each viewer's own browser; the files around them still come from the edge.
- Every 23artifacts address was unavailable for about six minutes (04:22–04:28 UTC) when custom domains were switched on: the server took its own health check for a visit to a custom domain. The proxy now checks with our own address, and the server never mistakes an internal address for someone's domain.

## September 24, 2026

- You can name someone in a comment: type @ in the comment box on the page, or in a reply on the artifact's page, and pick from the people who can already read it. They hear about it in their inbox even if they've muted the artifact — unless they've silenced that thread — and a name you add while editing tells only the newly named. People who commented through the gate without an account now get an email when someone replies in their thread, with a one-click stop for that thread.
- Your inbox now emails you. The first thing that lands on something you made — a comment, a reply in your thread, an agent's finished work — comes at once; while more keep arriving they're gathered into one message ten, twenty, then every thirty minutes, and never more than 24 a day. If you're already looking at the page or your inbox, we don't email you at all. Requests for access and drafts waiting for your approval always come at once; activity comes in a daily digest at the hour you choose. Every message says why you got it and has a one-click stop that works without signing in, with an undo; if your address bounces, the Notifications card says so and lets you try again. Notification email starts once its own sending address is set up — until then your inbox holds everything.
- A large file in an artifact — a video, a big download — no longer strains the server when someone opens it on a slow connection: it is sent as fast as they take it instead of being held whole in memory. If very many large files are going out at once, the next one asks to be tried again in a few seconds.
- For whoever builds this next: the design notes for sign in and sign up now match the pages that shipped — providers first and stacked with their full titles, the emailed link as a quiet option in the same form, and the site header's logo standing for the page. Nothing changes in the product.
- Sign in and sign up are redesigned: Continue with Google and Continue with Apple come first, on sign-up too, then your email and password in one short form. "Email me a sign-in link instead" turns that same form into the link request, and the "are you human" check only appears when Cloudflare actually needs you to click. An expired or already-used link now lands back on sign-in and offers a new one, and when Google or Apple can't join an account whose email isn't confirmed yet, the page says so and tells you how to fix it.
- For whoever builds this next: custom domains are complete. Operators can block a domain — it stops serving at once and is refused to everyone, and every name under it — and are told at once when a domain that reads like phishing is attached; a report citing a custom domain finds the artifact it serves or served. Still switched off until Cloudflare for SaaS is set up.
- On Pro and Team, every backup can also land in your own S3-compatible bucket (Amazon S3, Backblaze B2, Google Cloud Storage, Cloudflare R2, MinIO…): add it in Settings → Backups with a key that can only write there, and we test it with one small file before saving. Your secret is kept sealed and never shown again; if your bucket ever refuses a backup, we tell you in its own words and the backup stays here to download.
- On Pro and Team you can switch on a weekly backup in Settings → Backups: every week, at an hour of its own shown in your time, the workspace is archived and we email you when it's ready. The newest one stays until the next replaces it.
- Your inbox has a page. It leads the sidebar with a count of what waits for you — access requests, comments and replies, an agent's finished work, share-link openings you asked to hear about — one row per thread or request, across every workspace you're in. Opening a row answers it and takes you to the thing itself; Clear answers every notice at once and leaves the requests that need you to act. Each artifact's page lets you choose what it tells you: everything, what involves you, or nothing. The account page has a Notifications card for how each kind will be emailed; the email itself comes next.
- For whoever builds this next: the sign-in redesign is ruled — the centered layout (B), provider buttons first and on sign-up too, stacked with full titles, and the emailed link as a quiet option in the same form. The pages change in the landing that builds it.
- For whoever builds this next: an artifact's settings now carry a custom domain card — attach a domain, see the one record to add and what DNS says now, check again, watch it serve, remove it — and assistants and programs can do the same (`set_custom_domain`, and `PUT /api/v1/artifacts/:slug/custom-domain`). Owners are emailed when a domain serves, stops pointing here, can't be set up, or will leave with a cancelled plan. The card stays hidden until Cloudflare for SaaS is set up.
- A private artifact opened at its short address now brings you back to that same address once you are let in, rather than to its longer one. For whoever builds this next: an artifact's custom domain, once one serves, is now the address everything hands out, and the domain serves the artifact, forwards to it after removal and answers unavailable when blocked — still switched off until Cloudflare for SaaS is set up.
- Your assistant can read your inbox: what is waiting on you across every workspace — access requests and agent drafts to approve, comments and replies on what you made or joined, an agent's finished work, share-link openings you asked to hear about, and access widened by someone else — one entry per thread or request, newest first. It can answer notices, clear them, or set how much each artifact tells you (`list_inbox`, `update_inbox`, and `/api/v1/inbox` for programs). The inbox page, its settings and the email come next.
- You can export your whole workspace, on any plan, once a day: Settings → Backups gives you one zip with every artifact and its versions, comments, assets, themes and log, and nothing secret. From your account the export is your own — your workspace, your account, and what you wrote elsewhere — and deleting your account offers it first. An organization's owners and admins export theirs from the organization's page. We email you when it is ready; the download needs you signed in and is kept for seven days.
- For whoever builds this next: custom domains now have their record keeping and their checks — the name and its refusals, the proof read from public DNS, the certificate at the edge, and every state from waiting to serving to forwarding — switched off until Cloudflare for SaaS is set up. Nothing changes in the product yet.
- Downloading a version with large files no longer strains the server: the download is prepared once and then comes straight from storage, a version of several files arrives as one zip that opens even past 4 GB, and the Download button says it is preparing while a large zip is made.
- For whoever builds this next: seven rulings from the custom-domain, backup and inbox spec rounds are recorded — Cloudflare for SaaS, subdomains only in v1, comped-only domains during the beta, an on-demand export on every plan, backups by link first, mentions built last, and reply emails for commenters without an account. Nothing changes in the product yet.
- For whoever builds this next: custom domains, backups and the inbox with notifications move ahead of the pricing session on the launch list, so plans are set against a complete product; the builder and Git follow launch. Nothing changes in the product.
- For whoever builds this next: how backups will work is now specified — what a workspace's archive holds and in what shape, the export every plan can ask for once a day, the weekly backup on Pro and Team, the download that needs a sign-in, and, after it, the owner's own bucket. Nothing changes in the product yet.
- For whoever builds this next: the inbox and notifications are specified as Martin ruled them — one inbox per person across workspaces, what reaches it and who hears what, the watch control on each artifact, mail that tells you of the first thing at once and gathers the rest while more keeps coming, a daily digest, and a one-click stop in every notification. Nothing changes in the product yet.
- For whoever builds this next: custom domains are specified — the owner adds one record pointing at the artifact's own address, the certificate comes by itself, the domain becomes the address while it serves, and a removed one forwards to the address for up to ninety days. Subdomains only for now, and during the free beta only comped workspaces. Nothing changes in the product yet.
- The Continue with Google button is back on the sign-in page, and Google sign-in is offered again as a way to let people into a gated artifact.
- You can sign in with Google. Artifacts gated to Google sign-in now open for the people they name.
- A token can no longer be turned into a full sign-in to your account. The iPhone app opens private artifacts by handing its sign-in to the page it shows, and any token allowed to manage artifacts could ask for the same handoff — which could then create new tokens, claim a handle, change your password or reach billing, and kept working after the token was revoked. That handed-over sign-in now keeps the token's own limits: it opens and comments on the artifacts you can see, only if the token may read them, never reaches your account's settings, and ends the moment the token is revoked or expires. Private artifacts open in the app as before.
- For whoever builds this next: Martin confirmed the account-deletion rules and ruled how far a suspension reaches (everything the person made) and that a suspended account cannot sign in. Nothing changes in the product.
- Names other people choose now reach your assistant as names. A commenter's own name, a review's title, and the pages visitors asked for and the sites they came from — in the activity log, the traffic summary and the log chart — arrive on one line inside quotation marks, with invisible characters removed, in both the text your assistant reads and the structured copy beside it. Before, a line break in a commenter's name or in an address a visitor typed could put a line of their choosing into the answer as if it were part of it. A name given with a comment is now stored that way too, at most sixty-four characters, and so is a recorded walkthrough's title, at most two hundred.
- Connecting an assistant always asks you first. Before, a site that registered itself as an assistant could send someone who was signed in to 23artifacts through the connect link and get access to their account without the "allow" page ever appearing; now access is granted only after you say yes on our page, or when you already said yes to that same assistant for the same access.
- Artifact pages now load only over HTTPS: a plain http:// link to any artifact redirects, browsers are told to use HTTPS from then on, and only the certificate authorities we use may issue certificates for the artifact domains.
- For whoever builds this next: what was left on the refinements and search pages is now tracked — one more launch brick (a session made from a credential keeps its limits), three items folded into existing bricks, the rest as issues #460–#471. Nothing changes in the product.
- Deleting your account now cancels a paid personal plan at once, so a deleted account is never charged again; the current period isn't refunded. Until now the subscription kept renewing, with no way left to reach billing. If the payment provider can't be reached at that moment, the account is still deleted and the cancellation is retried every day until it goes through. The only owner of an organization that pays for a plan is asked to make another member an owner, or cancel that plan, before deleting their account. A checkout finished in another tab after the account was deleted is cancelled and refunded.
- Inviting someone to a workspace, and making a new workspace, now carry the same quick human check as signing up. An account can send fifty invitations a day across all its workspaces, and the names in an invitation — the sender's and the workspace's — arrive in quotes, on one line, without links and at most sixty-four characters, so nobody can dress an invitation up as a message from us. The artifact name in an access code's email is shown the same way. A person's or a workspace's name can be at most sixty-four characters.
- Asking for an image's description again no longer throws the old one away first: your description stays until a new one is written, and if it can't be — too many tries in a minute, the day's limit reached, an image that can't be described, or a failure — you're told why and nothing changes. Descriptions written from images now count toward your workspace's daily limit on the assistant's work, as summaries already did, and so do the words added to recordings, up to 120 minutes of recordings a day per workspace. A recording made after that is kept and plays as usual, and gets its words after midnight UTC. When a daily limit is reached, the message says what waits and when it starts again.
- What other people wrote now reaches your assistant marked as quoted in every copy of an answer. Comments, recorded walkthroughs, review summaries, a room's contents, the note someone sends when asking for access, asset descriptions and theme guidance were quoted in the text an assistant reads, but the structured copy beside it — the one Claude Code and ChatGPT's apps read — carried them as written, so an instruction planted in a comment reached the assistant word for word. Both copies are now quoted the same way, and each says so first. The connector also answers more completely: reading an artifact returns its access settings and every version, listing share links returns each link's address, and a dry-run publish says it was only checked rather than that nothing had changed. A theme's guidance longer than 4,000 characters now reaches the assistant whole.
- Signing in with Apple can no longer make you a member of a stranger's organization. Any account could create an organization that claimed your email's domain, and your next Apple sign-in would have added you to it without asking, showing its owner your name and address. You now join an organization only by creating it, accepting its invitation or signing in through its own sign-in. An organization claiming a domain adds nobody until it proves the domain is its own, and the same will hold for Google sign-in.
- Reporting a page works end to end. Every artifact now keeps a way to report it: adding `?crate=0` to a link no longer removes the crate (it only ever needed to work inside an embed, where the crate is absent anyway), and an owner who hides the crate now leaves a small Report link in its corner. The report form accepts any address a page is known by — its `…23a.so` address, its longer address, a version's, or a whole link as copied — and finds the artifact from it. Our team is emailed when reports arrive (the first at once, then at most every fifteen minutes during a burst), and anyone who leaves an email address hears back that their report arrived. Taking a reported page down now works from the report itself, and an account that breaks the terms can be suspended: everything it made stops serving, it can't publish from anywhere, and it can't sign in.
- The privacy policy now says what signing in with Apple or Google shares with us (name, email, an account identifier, and from Google a profile picture — nothing else) and how it's used, and names Stripe, Apple and Google among the services that handle data.
- For whoever builds this next: the launch list now carries the launch review's blockers and workstreams in order, with Martin's eight rulings recorded — member permissions before launch, a pricing session then a free limited-time beta, the review tools renamed first, public artifacts listed in search, #416 landed, the Google gate refused until Google sign-in is on. Nothing changes in the product.
- The scheduled clean-up works again: a deleted artifact is erased thirty days after you delete it, and old access and view records are cleared on time, as the privacy policy says. Since 23 September it had stopped at a deleted artifact that had a deck, a room or an access request, and done nothing after it. Those now go with the artifact, as do the drawings and images attached to its comments, and one artifact that can't be erased no longer holds up everything else.
- Publishing through an assistant no longer takes the service down. A publish of a few megabytes arriving over an ordinary internet connection could make the server hold hundreds of times its size in memory and restart, dropping every request in flight — three times today, one of them rolling back a release. A publish now costs the server about its own size however it arrives, and the sign-in forms and comments, which anyone could have used the same way, are held to the same rule.
- Signing up, asking for a sign-in link and asking to reset a password now carry the same quick human check the artifact gate's email-code form has, so scripts can no longer use them to make accounts or send mail in bulk. For almost everyone it passes on its own; when it asks, it's one click. Signing in with a password is unchanged.
- For whoever builds this next: the launch list no longer counts a publish rate limit as missing — it has been in place since July. Nothing changes in the product.
- For whoever builds this next: the launch list now sends the connector to OpenAI's plugin directory first, while the launch gates are finished, and to Anthropic's directory once they are green, under the name 23artifacts. Nothing changes in the product.

## September 20, 2026

- For whoever builds this next: the learnings inbox notes the cached-schema lesson for the blueprint. Nothing changes in the product.
- An assistant whose session began before a deploy no longer loses the artifact listing when the answer gains a field: the connector's list_artifacts declares its shape as open to more, the way the log entry already does. Nothing changes in the product.
- Search on the Artifacts and Assets pages is one question. Type words, or terms such as `tag:brand`, `kind:deck`, `state:live`, `touched:7d`; a finished term becomes a chip, the same chip a value picked from a facet becomes, and while you type a term the field offers the facts it knows and their values with counts. Facets for kind, access and state (kind and format in the library), a span of time, the tags in use, and a sort — touched, made, name, size, or match once words are given. The whole question lives in the page's address, so a narrowed list is a link. A row shows the artifact's description under its name and, when the words matched inside the page, the line they matched on; nothing-matches restates the question with a way to clear it. An artifact's description is written in place under its name on its page, and the publish dialog takes one.
- The words inside a page now find it. When a version goes live its text — the page with its title and description, markdown as written, a deck's slide text — is kept beside the artifact's facts, so a search for a word that appears only inside the page finds it, `in:` narrows to the page's words alone, and a matching row says where the words matched. Everything published before today is indexed once in the background; until it is reached, a listing says so. Nothing changes on the pages yet.
- Finding artifacts and assets is one question, on the connector and the API first. `q` takes words, quoted phrases and terms such as `tag:brand`, `kind:deck`, `state:live`, `touched:7d`, `made:2026-09`, `after:2026-09-01`, `sort:name`; a word matches a whole word or its beginning in the name, slug, description or tags, accents folded; a quoted phrase must appear as written; a term with comma-separated values means any of them and the same field twice means both. Every answer carries facets — what kind, access, state and tag (for assets: kind, format, library, tag) would hold with that one fact unset, with counts — and a sort-aware cursor. An artifact now has a one-line description, sent with a publish or written on its page's own route, and reports its kind: page, deck, markdown or file. The dashboard and the library still draw the old toolbar; the words inside a page are not indexed yet.

## September 19, 2026

- For whoever builds this next: the specification now says how search will work across artifacts and assets — one question of words and `field:value` terms, every value offered with its count, a span of time, a sort, the words inside a page indexed when it goes live, and a one-line description on every artifact. Nothing changes in the product yet.

## September 18, 2026

- The sharing list is tidier. Someone's role is now a control on their row: click it and pick another, with each role explained. The add control just says Add access, its menu is three short lines with the public choice explained in its own words rather than labelled as different, and the row menu is wide enough that nothing wraps and no longer repeats the role.
- For whoever builds this next: the agent may now land a change that waited on Martin the moment he says so, with no command from him. Nothing changes in the product.
- For whoever builds this next: a landing that waited on Martin is landed by the agent on his word, and the procedure says which two permission rules make that possible. An assistant reading an artifact's log through the connector no longer loses the whole answer when an entry gains a field. Nothing changes in the product.
- A share link can email you when someone opens it. Switch it on in the link's menu, on the artifact's Access section or on Share links, and you get one message naming the link, the artifact, where the opening came from as far as the network can tell, and when, with a way to the artifact's activity. Only a person's opening sends it, never a chat or mail client drawing the link's card, and a busy link sends at most one message every fifteen minutes. The connector's create_share_link takes notifyOnOpen, and the API reports it.
- For whoever builds this next: only a change to the identity or to what the product is waits for Martin now; the rest lands when its checks are green, and he reads the spec as the render on main. The learnings inbox is empty again. Nothing changes in the product.
- Two new pages in the sidebar. Activity is the log across every artifact in the workspace: the same record and the same filters as an artifact's own activity, every entry naming its artifact, and the artifact as one more filter and one more way to group the chart, so “did anyone open anything I sent this week” is one question. Share links is every link the workspace has made, with its artifact, its role, how many people opened it, whether it was previewed but never opened, and when a person last opened it, with copy, copy-as-embed and revoke in place. The connector gains get_workspace_log, list_share_links with no project lists the workspace's, and the API has /api/v1/log, /api/v1/log/chart and /api/v1/share-links.
- A share link no longer credits the person you sent it to with an open they never made. When Mail, Messages or a chat draws the card for a pasted link, the fetch comes from your own device the moment you paste, and the log used to record it as “Dan Becker arrived”. It now reads as what it is — “Apple link preview fetched a preview through link ‘Dan Becker’” — and counts as neither a view, a visitor, an open of the link nor its last use; the sharing list says “not opened yet · previewed once” until someone follows the link, and the connector and API report `previews` beside `views`. The bot once called iMessage is named Apple link preview, since Messages, Mail and Notes all send the same string. The activity headline’s visitor count now means people who opened a page: a sign-in with no page behind it no longer counts as a third visitor beside two page views.

## September 17, 2026

- A returning visitor now re-downloads none of the home page’s fonts, screenshots or link-preview card: each is named after its own contents, so it can be kept for a year and a change arrives under a new name. The page itself is also compressed as well as it can be before it leaves us — though the network in front of us currently recompresses it less well on the way out, so that part is not yet something a visitor feels.
- Two notes for whoever builds this next: the procedure for landing a change that waited on Martin now matches the rules it is supposed to follow, and the check that measures how far a composed spec has drifted from its layers is recorded as blind to the ones filed in a subdirectory. Nothing changes in the product.
- The landing is dark, like the rest of the product. It used to follow your system setting, so anyone on a light Mac met a page on paper and then a dashboard on ink; now the front door matches what is behind it, and the control in the footer still switches to light and remembers it.
- The landing paints sooner and its markup is valid: the three font preloads raced first paint without bringing the fonts any earlier, and four images in the hero shipped as empty boxes until scripts ran. Nothing looks different; the page just arrives faster and reads correctly to anything parsing it.
- What this product tells a machine about itself — the icon a search engine shows, the card a share unfurls, the list of pages handed to a crawler, what a phone reads to put it on a home screen — is now written down as a contract, including the terms the reader imposes and the fact that every one of those readers fails silently. Nothing changes in the product today; it is what stops the next change breaking one of them unnoticed.
- The icon Google shows beside 23artifacts.com in its results is the crate, not the mark retired in September: the home page was offering Search an icon in a format it cannot read, so Search kept showing the one it had cached. Sharing the home page also shows its card again, which had been resolving to a missing file, and the list of pages handed to search engines is generated from the pages that actually exist.

## September 15, 2026

- The deck editor moves to bento 1.1.0: a Layers list to reorder a slide's elements, curved connectors with seven more tip styles and double-headed arrows, pictures you can move and zoom inside their frame, slides exported as PNG or JPEG, photos shrunk at insert so a deck stays small, live broadcast to an audience, and a maths engine of bento's own. Everything 23artifacts adds on top — images from the workspace library, HTML embeds, the theme's arrowheads, saves through the host — carries over unchanged.

## September 13, 2026

- The API reference and the credentials page now say what a publishing credential can and cannot reach, in the words the rules use: a publish-only credential lists artifacts by name and never opens content; read reaches published file content, a preview of it, the log and the comments.
- The page the specification is reviewed on no longer falls behind when a publish or a reply hits a transient error during a deploy: the machinery tries again, a bounded number of times, waiting as long as the server asks, and only a real refusal stops it.
- The ledger now says when a specification layer leaves Martin's held list, the friction inbox is drained to the two entries still open, the harness agents verify with gains four rules for working side by side, the 2026-09-11 change to the management interface's pages gets the line it was owed here, and the specification's own index stops mis-describing one of its legacy files. Nothing changes in the product.
- A credential that may only publish can no longer read or change reviews and recordings: a review's title, summary and narrated-session digest need the same read permission as the comments beside them, and attaching or updating a review needs manage. Listing your artifacts with a publish-only credential still works.
- Two promises are stated where they are promised rather than only where they are kept: a credential's secret is shown on a page you signed in to reach and never in a conversation, and whatever you are asked to consent to is asked away from an artifact rather than in front of it.

## September 12, 2026

- Four more decisions about how this product is described are written down where the next session reads them, rather than living in a conversation.
- How this product gets built is now written down where it can be checked: what it should be is decided at the top, everything below it is worked out from that, and a new check catches a piece of design made for a screen nobody specified. Nothing changes in the product today; it is what keeps it coherent from one change to the next.
- The specification of this product now reads like the product. It opens with what the thing is, then with what you can do with it in the order that matters, then with what has to be true of it — so anyone who stops after the first page knows what 23artifacts is. Its headings are plain words rather than sales lines, it no longer explains its own filing system to the reader, and the words it defines are twenty-four, defined once, with the rest of the vocabulary explained beside the rules that use it. How the product should look and feel — honest, crafted, trustworthy, the work of neither a giant corporation nor a solo developer — is now written down where the look is decided. Nothing changes in the product.
- Every page of the specification of what this product is now states what is true, rather than arguing for it. The two sections whose job was to make a case, and the forty-odd asides that explained why a rule exists, are gone from the pages and kept where the reasoning is kept. Four things it had quietly stopped saying are said again: what the word *wanted* means beside the first thing marked with it, that a name can be changed once a day and only so many can be tried in an hour, that the artifact you make before signing up is yours once you do, and the whole of the promise that a published page's code reaches nothing belonging to the person who published it, to another page, to anyone looking at it, or to us. Nothing changes in the product.
- The specification of this product now says what the thing is, rather than what it is not. Where it used to explain how a rule was arrived at — the alternative that lost, the mistake being avoided — it states what is true, and the reasoning is kept where reasoning is kept, so it can still be read by anyone who wants to know why. The address is the example: the specification says what an address is made of, so nothing has to list what it leaves out. Nearly three hundred sentences are rewritten and the whole of it is a tenth shorter. The list of what is inside the product layer is gone from the page too — it is built from the files themselves, so it is right the moment a file is added. Nothing changes in the product.
- The page the specification is reviewed on reads like a document again: it opens with what it is rather than with which commit it was made from, that line now sits in small print at the foot, every page has a Raw link to exactly what git holds, and the list of what is inside a layer is built from the files themselves — so it is right the moment a file is added, and a page can be jumped around by its own headings. Nothing changes in the product.
- Read a clause at a time rather than only a sentence at a time, the specification of what this product is still said seventeen things twice: a promise made in the index and made again inside a longer sentence on the page beneath it, and three things said in three places. Each is now said once, and the other places point at it in their own words instead of repeating it — a pointer written word for word from what it points at is a copy to anyone searching the text, which is how several of these survived three passes. Every check the project has now reports nothing repeated inside this part of the specification; the few pairs that are kept are listed with a sentence each saying why the two really do say different things. Nothing changes in the product.
- The check that keeps the specification from saying the same thing twice now reads it a clause at a time rather than only a sentence at a time. That is how a fact most often ends up with two homes here: a long sentence carries it as one clause, and a long sentence somewhere else carries the same clause, so compared whole the two look different enough to pass — one pair is word-for-word identical in part and still slipped through. Reading clauses turns up forty-two such pairs in the product layer alone, twenty-nine of them real second homes. It needs no model, takes a twentieth of a second, and like everything above the first pass it cannot fail a build. Nothing changes in the product.
- Every word the specification of this product defines is now defined in one place, and only defined there: a glossary entry says what something is, and the rules that say what must be true of it live with the rules. Reading the specification for meaning rather than for matching words turned up forty-eight places where one fact was written twice; thirty-three of them were real and are now written once, and the remaining fifteen are listed with a sentence each saying why the two really do say different things. Nothing changes in the product.
- The check that keeps the specification from saying the same thing twice can now read for meaning as well as for wording, when a model is on the machine to do it. It finds pairs that state one fact in two sets of words — a definition and the rule that quietly re-defines it — which matching words alone cannot see. Nothing it reads for meaning can fail a build, it says out loud which of its passes actually ran and which could not, and with no model present it does exactly what it did before. Nothing changes in the product.
- The specification of what this product is now says each thing in one place. What used to be told four ways over four sections — what it is, who it is for, why it exists, what it must do — is now one short statement of the product, one named rule for every promise another part of the specification depends on, and a page each for the audiences, the reasoning and the world it gets used in. Promises are no longer numbered, so nothing points at a number that moved; each one carries the test it passes, right underneath it. Every word the specification defines is defined in one place, and the rules that use it point there instead of saying it again. Nothing changes in the product, and everything written about it gets easier to keep true.
- The lane that holds a change back for Martin to see works again for more than one kind of change. Nothing changes in the product.
- Four decisions from reading the specification: a comment whose place on the page is gone says where it was and offers to take you there; an artifact belongs to its workspace and credits whoever made it; how many people viewed an artifact is kept long after who they were is not; and taking something down stays one setting, with the page telling a visitor the owner took it down rather than inviting them to ask.
- How work is reviewed here is written down where it binds: what gets reviewed is the specification rendered at a commit, and never a copy that can drift from it.
- The job that keeps the spec's review page current no longer fails on an ordinary landing.

## September 11, 2026

- The pages of the management interface stop introducing themselves: the bar's trail names the page you are on, so the headings, the workspace subtitles and the stat cards are gone; the footer lines up with the page; the library says "Add files"; the docs keep a contents rail; and an artifact's preview sits beside its versions.
- The checks that keep the specification honest can now be proved able to fail. A word only counts as described when the specification writes it out in full, so "review" no longer passes because "preview" contains it; every value the product lets someone choose is either described or written down as plumbing with a reason; the specification's index can no longer claim something its own files contradict; and a fresh checkout now wires its own checks without that being able to break a deploy. Nothing changes in the product.
- Comments on the specification page are now answered by the machinery rather than by hand. When the change that settles a comment lands, the page republishes itself, is checked byte for byte against the commit it renders, and the thread gets a reply naming that commit and is marked resolved. The page also stops republishing on every landing: it waits for the change that answers you, and otherwise refreshes at most every six hours, so a thread you are reading stays on the version you are reading.
- The checks that guard how this product is built now run at every point where a mistake is cheap to catch — as you edit, as you commit, as you amend or rebase, as you push — and each one can name the command that fixes what it refused. Nothing changes in the product.
- How the project's rules are enforced is decided: by scripts that are proved able to fail, not by anyone remembering. Nothing changes in the product.
- The rules for automation credentials are written down as they now behave: a publishing credential can see the names of what exists, and nothing inside it.
- A publish-only token can no longer open private artifacts. Listing your artifacts with one still works, but it no longer hands out a preview link (`previewPath` is null unless the token also carries `read`), and a republish with such a token can no longer change an existing artifact's access or link preview — it is refused with a 403 saying so, while sending the settings it already has, or leaving them out, still publishes as before. Preview links handed out earlier expire within an hour. Signed-in pages, the connector and tokens with `read` see no change.
- The specification can now be read and commented on as a page of its own: every layer, the decision ledger and each open question, rendered exactly as committed, with the design tokens shown beside the values the product ships today. Comments on it change the specification itself, and each is answered with the change that settled it.
- On an artifact with several pages, a comment now stays on the page it was left on. A pin from one page no longer turns up at the same spot on every other page; the comment list still shows comments from the other pages, says which page each is on, and opening one takes you there — as does a link to a comment from the dashboard. Replaying a recording no longer shows marks made on a different page. A few comments left before today whose spot on the page can no longer be found are no longer drawn at a guessed position; they stay in the list.
- Who can do what on an artifact now has one written model, ready to build; nothing on screen changes yet. Everyone on an artifact's list gets a role, and a role is made of permissions you can read — open it, see earlier versions, comment, record, see everyone's comments, edit, make changes live. In place of a comments switch, a visitors switch and four visibility settings, an artifact can switch on a sentence we write: "Comments are closed." or "People who can comment here see everyone's comments." The comment box will say who reads what you write, a share link will add to what you already have rather than replace it, editing a deck will no longer publish it, and a new workspace will share nothing with its members until its creator chooses what they get.
- The product's specification is now complete, in five layers: what 23artifacts is, how it is used, how it looks, how it is built, and what it is built with. It speaks in comments rather than reviews throughout, and the old brand brief is folded into it, so there is one place to read how the product should look.
- A handle can now begin with another workspace's: "acme-labs" can be yours while "acme" is someone else's, in either order. Only the exact name belongs to one workspace. Names that would speak for 23artifacts are still refused along with everything built on them ("security-alerts" as much as "security"), and a handle still changes at most once a day.
- The specification stopped saying the same thing twice: everything the PRODUCT layer now states was removed from the older prose files it was drawn from, which are 43% shorter. Twelve places where the old prose and the new layer disagreed were resolved in the layer's favour and written down. Nothing changes in the product.
- Feedback has one vocabulary and one less concept. What used to be called a review is simply the comments on a version: a comment can be typed, drawn, or spoken, it belongs to the version it was left on, and its thread stays open until someone resolves it. A recording is a spoken pass over the page that works whether or not an assistant ever listens to it — the words and the summary are what an assistant adds, not what makes it work. Nothing changes on screen yet; this is the language everything after it is built in.
- Six more product decisions written down where the next build will find them: a person's own workspace becomes a real workspace; the inbox's count will only ever mean what is waiting for you; old long addresses keep working without a redirect; two workspaces may now hold names like "acme" and "acme-labs"; avatars are called avatars; and presenting a deck stays in the deck.
- The way 23artifacts is built is now written down where it is enforced: a product specification in layers, a ledger of every decision (including the ninety-odd that had lived only in review pages and notes), a friction inbox, and checks that run on every commit and every pull request. Nothing changes for a reader of the product today; what changes is that the next feature arrives with its reasons attached.
- The product now has a written statement of what it is, for whom, and what must be true of it: the PRODUCT layer of the specification, with the four things still to come (making artifacts here, the workspace as a repository, an inbox, plans) written as intent rather than implied. Nothing changes in the product itself.
