Changelog
What's new in Command-D, newest first.
28 September 2026
- Share links. Share one item (the new share button on a card) or a whole tag (Share #tag next to the tag filter) as a read-only link,
cmd-d.com/s/<id>. The page shows the previews; anyone can save an item, or all of them, into their own list with one tap, and a list is made for them if they have none. A tag link also shows what you tag later. Other tags, notes and where you saved from stay private; links aren't indexed. Devices & links (was Pair a device) lists live links, and Stop sharing makes one 404 immediately.POST/GET /api/shares,DELETE /api/shares/:id,POST /api/shares/:id/save. New events:share_created,share_viewed,share_saved. - iPhone. iOS has no install prompt and keeps home-screen web apps out of the share sheet, so: a bottom sheet in iPhone/iPad Safari shows the two taps for Add to Home Screen (or says to open Safari when in an in-app browser), and
/iphonewalks through it plus a Shortcut for Share → Command-D from any app, with a Get my key button. SetIOS_SHORTCUT_URLto an iCloud Shortcut link and the page offers that one-tap Shortcut instead of the build-it-yourself steps. Saves from it count as clientios. - Homepage and navigation. The hero has one button for the device you're on (Download for Mac, Set up iPhone, …). Get Command-D shows four equal cards (Mac, iPhone & iPad, Android, Windows) with their icons, a one-line "how you save there" and one button; yours is marked Your device. Below them: any browser, and your AI. Every card leads to a setup page with the same shape and platform tabs on top: new
/macand/windowsnext to/iphoneand/android. Header: Get the app, Docs, Open my list. A shared footer links all setup pages. - Link a device by QR. Devices & links → Show code & QR shows a QR code next to the code. Scanning it opens
/pair?code=…on the other device, which links it to the list and opens it. No typing. - Changelog on the site.
/changelogrenders this file, built into each deploy (scripts/gen-changelog.mjsruns before dev, test and build). - Install, clearer. Chrome's own install bar is no longer suppressed, so Android gets asked automatically and has the button; both say Installed ✓ when opened from the installed app.
/iphoneleads with the install steps (now ••• → Share, as Safari has it since iOS 26), shows Installed ✓ in the Home Screen app, and points at Safari's bar. On a computer,/iphoneand/androidshow a QR code to open them on the phone (qrcode, rendered server-side). /androidsetup page: install from Chrome, share from any app, pair with your other devices. The landing page links both.- Schema: added a missing
;after thesnapshotcolumn so the migration runs again.
25 September 2026
- Reddit posts are kept. Saving a Reddit link also stores our own copy of the post (text, flair, preview image, video url) and up to 60 comments from the Arctic Shift archive in a new
items.snapshotcolumn, merged so a later read never loses text or comments. The post text joins the card description and search; oEmbed stays the card's source, the archive stands in when it fails. The archive re-reads posts ~1.5 days in, so unfinished copies are re-checked daily (max 4). Deleted posts say "deleted on Reddit, copy saved"; MCPget_itemreturns the snapshot. Enrichment v9 backfills older posts. - Search finds tags. Every word may match a tag (or part of one) as well as the text;
#tagin a query only matches items tagged with it.
23 September 2026
- Admin list view.
/admin/lists?key=…shows every list and how it uses Command-D: items by kind, clients, paired tokens, well-known platforms, saves this week, retrievals, searches, MCP calls, done/tagged, last active, and a status (new, retrieving, active, quiet). Filter by status or "uses MCP", sort by activity, age or size; empty lists (a web visit mints one) are hidden by default./admin/lists/<id>adds saves per week and a timeline of the list's events in words. Never content, links, titles, tags or search terms.pnpm smokenow deletes the item its MCP step saves, and everysmoke-testlist is internal. - Usage analytics, first-party. API routes record small events in a new
eventstable (save, open, search, archive, tag, pair, list created, MCP tool calls) with the client kind and, for opens, the item's age. Never content, URLs, titles, search terms or IPs; events are deleted after 13 months. The north star is retrieving lists: lists that opened something saved more than a day earlier that week./admin/stats?key=<ADMIN_TOKEN>shows weekly numbers, cohorts (activation, week 1 / week 4), saves by client, MCP tools and search success.internal_listskeeps our own lists out (&internal=1puts them back);pnpm smokelists are marked internal automatically,node scripts/internal-list.mjsmarks the Mac app's list. The web list now reports every open, not only the first. Privacy page updated. - Drop to save. On the web list you can drop images, links or text anywhere on the page, paste an image, or pick images with the new button. The save box is a dashed "drop here" box with a Save button; search is its own filled field with a magnifier (
/to focus, Esc to clear), so the two no longer look alike. Several files saved in one go share adrop_id(new column;POST /api/itemstakes it), so a set of screenshots stays linked. Each file is still its own item. - MCP server 0.4.0: an AI can now go through everything.
search_itemsandget_recent_itemstake up to 100 items and page withbefore; they return{items, next_before}. Newlist_tags: the tags and platforms in use with counts, so an AI reuses your tags instead of inventing new ones. List results are lean: long titles and notes are shortened, a description that only repeats the title (Instagram, LinkedIn captions) and a link's preview image are left out;get_itemstill has the full record.GET /api/itemstakesbeforetoo.
11 September 2026
- Done, not deleted. Items have an inbox/done state (
archived_at) and an automaticopened_at. On the web list, ✓ on a card marks it done (with Undo), the ✓ Done chip shows what you finished, ↩ restores. Opening a link from the list or the Mac menu stamps it opened. In the Mac menu bar, hold ⌥ on a recent item to mark it done without opening it. Re-saving a done item brings it back to the inbox.PATCH /api/items/:id(archived,opened,tags,add_tags,remove_tags,title);GET /api/itemstakesstatus=inbox|archived|all(default inbox),media=video,tag=. - Optional tags.
tags text[]per item, editable from the card (#), by API and by MCP; clicking a tag filters. Search matches tags too. - One media block for every video. Enrichment writes
meta.media(kind,provider,url,src,thumbnail,duration_s, …) for YouTube, X, TikTok and any page that announces anog:video/twitter:player. The list's ▶ Videos filter and MCPmedia=videoare the watch list; cards show a play badge, the duration, and a ▶ Watch link when the video lives behind the saved link (a tweet embedding YouTube opens YouTube). - X posts get their content. Tweets are read from X's own syndication JSON (no API key): the card leads with the tweet text (t.co links expanded), the byline is
@handle · Name, photos/video posters are the preview, native video is saved as media with an mp4src, and a player card or bare YouTube link becomes YouTube media with its real thumbnail.meta.linkskeeps the expanded links. - TikTok cards. Share links (
vm.,vt.,/t/) are resolved with the link-preview bot UAs (TikTok redirects plain fetches to its homepage), then looked up via TikTok's official oEmbed: real title,TikTok · @handle, thumbnail, media block for videos; profile pages get the creator's name. The "TikTok - Make Your Day" challenge title is treated as junk. TikTok signs thumbnails with an expiry, someta.image_expires_atis recorded and the card is re-enriched once it lapses instead of showing a broken image. - Cleaner URLs at save time. Host-specific tracking params (
x.coms/t, TikTok_r/_t/…, YouTubefeature) are stripped before storing, so the same post shared from two apps dedupes. - MCP server 0.3.0:
get_item,update_item,save_itemacceptstags; item output includesmedia,tags,archived_at,opened_at,canonical_url,author.search_itemssearches done items too by default. - macOS 0.3.0.
8 September 2026
- macOS 0.2.1 — the app answers when you launch it. Command-D is an
LSUIElementapp, so relaunching a running copy used to do nothing at all, and its ⌘D menu bar item can be pushed under the notch on a full menu bar where it is invisible. Opening the app again now pops the menu (Store clipboard now / Open my list / Start at login / Quit), so the controls stay reachable with no icon to click; the launch log records where the status item actually landed. - Saving is visible. ⌘D shows a "Saving…" toast for the length of the request instead of staying silent until it finished, then swaps to "Stored ✓" / "Already saved — bumped up ✓" / "Store failed ✕". The toast clears itself after 10s if a request never comes back.
28 August 2026
- Own favicon endpoint (
/api/favicon?host=): icons are fetched server-side (Google, then DuckDuckGo) and CDN-cached per host for a week; when neither has one, a generated letter tile is served — so a card can never show a broken favicon image, and visitors’ browsers no longer contact Google for every saved host. Existing items pick it up automatically (the list derives the icon from the link’s hostname). - Reddit links get real titles. App share links (
/r/x/s/…,/u/x/s/…,redd.it) are resolved to the canonical post, then looked up via Reddit's oEmbed (the site itself serves a JS challenge to servers). Cards show the post title plusr/Subreddit · u/author;meta.canonical_urlholds the clean URL. - Enrichment retries. Every attempt is recorded (
enrich_attempts,enrich_status,enrichment_version); un-enriched links are retried in the background on list load (max 3 attempts, 1-min backoff), so older items get fixed up too. The web list refetches once after a save so cards fill in without a reload. Tracking params (utm_*,share_id, …) are stripped from stored canonical URLs.
22 July 2026
- Shared Header component — consistent logo/width/actions across all pages (privacy/terms previously had a bare text nav).
21 July 2026
- PWA install button on the landing page (beforeinstallprompt, Chrome/Edge on Android + desktop; fallback instructions elsewhere).
- Windows support (light), documented: installing the PWA via Chrome/Edge registers Command-D in the Windows Share menu. Native tray app with global hotkey stays on the roadmap.
- Source context on saves:
meta.platformderived from the URL (youtube/instagram/x/linkedin/tiktok/… — works for shares from any client, since the OSes don't expose the sending app) andmeta.source_appfrom the Mac app (frontmost application at ⌘D). Shown in the list, exposed over MCP, noted in the privacy policy. Windows will get true share-source when built; Android/iOS share APIs don't provide it.
21 July 2026
- Rate limiting (app-level, per IP): identity endpoints 20/min, writes 60/min, MCP 120/min — verified with a live 429 test. (WAF edge rules need Vercel Pro; revisit on upgrade.)
- Privacy & terms pages (/privacy, /terms) — also a Claude-directory submission requirement.
20 July 2026
- macOS 0.2.0 — first downloadable release: cmd-d.com/download, app icon, GitHub release v0.2.0, install docs incl. Gatekeeper steps.
- Docs site (/docs): saving, search, pairing, MCP setup for Claude/ChatGPT/Gemini (incl. Gemini US-only caveat + CLI config), API.
- Connect your AI in the list UI — mints a personal MCP URL (web users previously had no way to get a token).
- Zero-friction dedupe: re-saving a url/text bumps the existing item and counts saves; surfaced in web toast, Mac HUD, MCP reply.
- Search loading spinner in the list view.
- Ingest hygiene: explicit URLs normalized + scheme-validated (blocks javascript:/data:), trims, size caps (text 100KB, images 4MB, image/* only), sanitized blob filenames, og:image scheme check.
- Storage policy decided: references-not-media — videos are saved as links, never as files.
17 July 2026
- MCP server at /api/mcp: search_items, get_recent_items, save_item; Bearer or ?token= auth.
- Full-text search: generated tsvector + GIN index ('simple' config).
- Share styling: OG card (og.png) + Twitter/OpenGraph metadata.
- SEO: robots.txt, sitemap.xml, JSON-LD, canonical, title template.
- Auth plan written (docs/AUTH.md): OAuth 2.1 over anonymous identity.
- macOS: crash fix (HUD over-release), HUD anchored to menu bar icon + icon flash, native theme-aware HUD material, run-at-boot default, file logging.
- Naming consistency: Command-D everywhere user-facing.
16 July 2026
- MVP shipped on cmd-d.com: Next.js app (landing, list view, PWA share target, device-token REST API + OpenAPI), Neon + Blob, keyless enrichment (OG metadata, YouTube oEmbed, favicons), device pairing via 6-char codes.
- macOS menu bar app: global ⌘D hotkey, clipboard type detection, Stored ✓ HUD.
- Domain cmd-d.com live (Vercel nameservers via TransIP).
- Test set: vitest unit tests, API e2e smoke (self-cleaning, runs against prod), macOS capture smoke.
- GitHub repo + CI (github.com/joost/cmd-d): web test+build every push, Swift build on macos changes; Vercel git integration → push-to-deploy.
- ⌘D keycap brand: logo SVG, icons, favicon.