Kavor 1.1.0
Highlights
- Replaces operating-system private-protocol sign-in in new packages with a short-lived, attempt-bound
127.0.0.1callback. Google, GitHub, and passwordless email Authentication now return directly to Kavor through the system browser, with PKCE for provider flows and an explicit clipboard fallback. - Adds first-use legal consent to Authentication and keeps account lifecycle synchronization behind Kavor's versioned public API.
- Lets CodingAgents propose File and Specification Nodes through the same atomic Canvas proposal catalog used by other reviewed changes. Connection Skills now lead with applicable rules and Git-aware context.
- Improves Terminal and CodingAgent session presentation, Workspace switching, startup, and recovery under concurrent PTY activity.
- Simplifies Specification navigation and actions while retaining direct access to File-backed work from the Workspace.
Fixes
- Corrected Google Desktop authorization-code exchange and GitHub's server-side confidential exchange so both providers complete direct loopback Authentication without shipping GitHub credentials in the application.
- Removed private-protocol registration from new desktop packages, avoiding Linux desktop-handler failures while preserving hosted compatibility paths for older supported versions.
- Hardened loopback callbacks against stale, repeated, malformed, or mismatched attempts and kept provider credentials and callback responses out of persistent storage and logs.
- Corrected PTY hydration and presentation ownership during Workspace changes, including recovery from delayed or interrupted host handshakes without fabricating process exits.
- Reduced unnecessary Canvas and panel work around Terminal, CodingAgent, File, and Specification Nodes and clarified Specification panel actions.
- Routed release discovery through Kavor's stable download API instead of coupling the desktop client directly to the release host.
Installation
Download Kavor from https://download.agentkavor.com. The page detects the current platform and also exposes all available packages.
- Windows x64 uses the assisted per-User NSIS installer. The installer is currently unsigned, so Microsoft SmartScreen may require explicit confirmation.
- macOS 13+ provides separate arm64 and x64 DMGs. Builds are ad-hoc signed but not notarized; follow the download page's Gatekeeper instructions. Kavor-managed updates use the matching architecture-specific ZIP and expose an explicit coordinated restart after the cached artifact is revalidated. The manual download remains available at all times.
- Linux x64 provides AppImage and DEB packages. AppImage supports Kavor-managed updates with an explicit coordinated restart; DEB updates are installed manually from the download page.
Known limitations
- Released versions through 1.0.6 can no longer initiate a new GitHub sign-in because their legacy GitHub OAuth App was retired after the provider-direct cutover. Existing authenticated sessions remain valid; install Kavor 1.1.0 to sign in with GitHub again.
- Windows ARM64 and Linux ARM64 packages are not included until their native PTY, SQLite, process-containment, and packaged-runtime gates can run on matching CI environments.
- Windows direct downloads do not yet have an Authenticode publisher certificate.
- macOS packages do not yet have Developer ID signing or notarization. Gatekeeper may require manual confirmation,
and replacing an ad-hoc build may cause macOS to request access to
Kavor Safe Storagein Keychain again. - Microsoft Store distribution is not part of this release.