Releases: openclaw/Peekaboo
Release list
v3.9.6
[3.9.6] - 2026-07-19
Highlights
- Peekaboo 3.9.6 completes the signing migration: the app, CLI, nested helpers, zip payload, and DMG now use the OpenClaw Foundation Developer ID. macOS treats the changed CLI signer as a new TCC identity, so re-grant Screen Recording, Accessibility, and any Automation access you use after updating.
Changed
- Sign and notarize every shipped macOS code object with
Developer ID Application: OpenClaw Foundation (FWJYW4S8P8)while preserving bundle identifiers and the existing Sparkle EdDSA update key; 3.8+ bridge hosts continue accepting transition-era personal-team clients, while the 3.9.6 CLI requires a 3.8+ host.
Fixed
- Reopen permission onboarding once for users whose required grants are missing after the signing migration, with direct guidance to re-grant Screen Recording, Accessibility, and Automation access.
Distribution
- npm: @steipete/peekaboo@3.9.6
- Registry tarball: peekaboo-3.9.6.tgz
- npm integrity:
sha512-aG2SxlkNVtIgkWNt5SZ5HYT9U1ukO0FfS3u4EcgHmZwLOXYQs1VA8qVJpDXGzfZgKnWhlMyj1RbriCPxGsjkIw== - Published:
2026-07-19T09:53:08.229Z
Verification
- Built from
b1c0ebcb7a111aa4af13600db3af14dc8095db80; macOS CI passed. - The standalone CLI, npm binary, app bundle and all seven nested Mach-O payloads, zip payload, and DMG verify as
Developer ID Application: OpenClaw Foundation (FWJYW4S8P8)and pass strict notarization checks. - Apple accepted CLI submission
1eb7cfc5-e7fe-4d95-9c27-4b4a12498a9a, app submission0188aa8b-f610-4ea9-83d7-1cf3a3c1bdf2, and DMG submission6547dfd1-5c3c-46d7-88bf-1ea7a9e63f85; app and DMG tickets are stapled and validate successfully. - The 3.9.6 Sparkle enclosure signature and byte length validate with the same public key and bundle identifier shipped in 3.9.5.
v3.9.5
[3.9.5] - 2026-07-18
Highlights
- Browser coordinate automation now fails closed instead of claiming success when Chrome exposes only non-actionable accessibility containers, and exact-window focus/selection keeps multi-window clicks on the intended window.
Added
- Add
peekaboo screen listdisplay enumeration and expose key/frontmost, layer, and accessibility subrole metadata inwindow list --json.
Changed
- Refresh
chrome-devtools-mcpto 1.6.0.
Fixed
- Make coordinate clicking fail closed on generic or unverified accessibility press targets, prefer the app's actual key window over helper panels, and require exact-window focus verification before foreground input.
Verification
- npm: @steipete/peekaboo@3.9.5, published 2026-07-19T03:45:34.701Z with
latestpointing to 3.9.5. - Registry tarball: peekaboo-3.9.5.tgz, integrity
sha512-3QrXAU35wT7+q+ZR1jsrOR+fyzD2G5MhN1MFxwKeQTgrw+cBf1FCvcWQxfGL7wsc11Qd8UZR1IXrUPLmiQA49Q==. - Exact-head CI: run 29671345815 passed on
7f3fc32ae89f1bf01bb294e47e23f62cfa2cb850. - Universal CLI and npm artifacts are signed by Developer ID Application: Peter Steinberger (Y5PE65HELJ). The app zip and DMG are signed, notarized, and stapled by Developer ID Application: OpenClaw Foundation (FWJYW4S8P8).
- The Sparkle signature and archive length were verified against the published appcast; both the 3.9.4 and 3.9.5 apps embed the matching update public key.
Peekaboo 3.9.4
Changed
- Refresh AXorcist, Commander, Swiftdansi, Tachikoma, and TauTUI, including stricter SwiftPM checkout handling for Tachikoma's Commander dependency plus corrected AXorcist app resolution, attribute serialization, and descendant filtering.
Fixed
- Resolve applications by executable name, so
--app <name>finds an app by the process/binary name shown inps,pgrep, and Activity Monitor even when it differs from the app's localized name (e.g. anopenclaw-desktopbinary whose bundle name is "OpenClaw Desktop Test"). - Keep bridge acceptance and request handling responsive, and retry timed-out snapshot invalidation handshakes once so busy local endpoints are not mistaken for stale sockets.
Peekaboo 3.9.3
Fixed
- Keep swift-log calls usable from nonisolated code when importing AXorcist under current Swift 6 toolchains.
v3.9.2
[3.9.2] - 2026-07-14
Added
- GitHub releases now include a signed, notarized Peekaboo DMG with a branded drag-to-Applications layout; release automation builds, verifies, checksums, and uploads it alongside the app zip.
Fixed
- AX error descriptions remain available to nonisolated automation classifiers under Swift 6.2 strict concurrency.
Package
- npm: @steipete/peekaboo@3.9.2
- Registry tarball: peekaboo-3.9.2.tgz
- Integrity:
sha512-5ahaJmyu0a8oXMHuAWAAZNxAw59zliudFNeRdwkXRaIpmDi/VwjVBfnQofRZqqbS3iKHrCbM2VVXyBquLgoRwQ== - Published:
2026-07-15T00:52:35.654Z - Tag commit:
6778f5871d66b2019c3a8cbbf26dd1fe0453cf53
Release proof
pnpm run prepare-release: SwiftFormat clean; SwiftLint 0 serious findings; no Swift compiler warnings; 747 tests in 85 suites passed.- Universal CLI: arm64 + x86_64; signed;
--helpverified; npm contents and package size checked. - Peekaboo.app notarization accepted:
51ecb04b-76bc-4953-85ef-a2e30f64afaa; ticket stapled;spctlaccepted as Notarized Developer ID. - DMG notarization accepted:
4e253068-b47e-40e0-8df2-1b74497e3134; ticket stapled;hdiutil verify,codesign, andspctlpassed.
SHA-256
7de7cf8ef19bee2856563492d18e5b5d4ee4dc29f1fab0b1ebafe240b3f5b9d3 peekaboo-macos-universal.tar.gz
01acfd9fbb2adb4517b813eb594afc9b98ef0a43179ab527b40c3d9fda797ebd steipete-peekaboo-3.9.2.tgz
55534f4deb5bf43246bbb50dd9a708d659848efbda6f7267d8ed5bfc9da6e2f3 Peekaboo-3.9.2.app.zip
d1f9a2d3f76a271439479d6974791830f0bf97c4ba4a483a07c4b55f8f7d5250 Peekaboo-3.9.2.dmg
v3.9.1
[3.9.1] - 2026-07-14
Changed
-
peekaboo inspect-uinow accepts the standard--apptarget option used by other desktop commands;--app-targetremains available as a legacy alias. -
peekaboo move --smoothnow uses natural eased pointer arcs by default, while--profile linearpreserves deterministic straight-line travel; explicit--stepsvalues are honored and human paths are capped at 96 samples to avoid redundant input events. -
Pointer-movement feedback now follows the real move with a short fading tail and one coalesced overlay instead of replaying a slow, thick line across the screen after the pointer arrives.
Fixed
-
Canceling
peekaboo window closenow propagates through disappearance checks and stops before focus, hotkey, or pointer fallbacks. Thanks @SebTardif for #270. -
Canceling
peekaboo window maximizenow stops frame-settling polls before any additional accessibility reads. Thanks @SebTardif for #271. -
Default action-first clicks now synthesize a real pointer click for SwiftUI segmented tabs, whose accessibility
AXPressaction can report success without changing the selected tab. -
Local
seenow confirms snapshot publication before reporting success, preserving its timeout and failure guarantees when a command-level mutation barrier is active. -
Human pointer paths now use bounded minimum-jerk Bézier motion, land exactly on the requested coordinate, and drive the real drag/swipe event path instead of calculating an organic path and then discarding it for a linear drag.
Verification
-
Source:
bab94a26fd84477f474d793d43d185a1dcb731d6 -
Registry tarball: peekaboo-3.9.1.tgz
-
Integrity:
sha512-DmGy2e9zjHga2qYoNo8v6yi3IvAI95SMnDIssdCmdyj+l01MKXJxUFsEttKJhrh73jzVglFCdnrmovUmhx/EhQ== -
Published:
2026-07-14T01:35:27.635Z -
Local proof: autoreview clean; SwiftLint passed with 13 baseline warnings; docs lint/site passed; 747 safe tests passed; universal CLI and npm tarballs verified; Foundation-signed app notarized, stapled, and Gatekeeper accepted.
-
DMG: Peekaboo-3.9.1.dmg; SHA-256
b3639fad9303e8784af583ba49f79a807f210136a79b75333545de832749bb54; Foundation-signed, Apple-notarized/stapled, Gatekeeper accepted, and mounted drag-to-Applications layout/background verified. Release workflow: 860d6bc3. -
Install proof: fresh
/tmpnpm execreturnedPeekaboo 3.9.1 (main/bab94a26)and rendered command help.
v3.9.0
[3.9.0] - 2026-07-11
Added
peekaboo click --long-pressperforms a stationary 1.2-second mouse down/hold/up gesture for controls such as SwiftUILongPressGesture; it uses foreground delivery so the press cannot be misrouted to a background window.peekaboo agentsupports GPT-5.6 (gpt-5.6,gpt-5.6-sol,gpt-5.6-terra,gpt-5.6-luna) and Claude Sonnet 5 (claude-sonnet-5,sonnet) alongside Fable 5, with current context/output/sampling limits and matching choices in the Mac app's assistant pickers, Settings, and session view.- Bare
peekaboo pastenow pastes the current clipboard into the focused (or targeted background) app instead of erroring; payload flags without a payload still fail validation even when--restore-delay-msexplicitly uses its 150ms default, and the current clipboard's contents are never echoed into structured output. peekaboo list appsaccepts--include-hidden/--include-backgroundfor parity withapp list, andlist apps,list menubar, anddock listJSON now emit snake_case keys (apps,menu_bar_items,dock_items) alongside the legacy keys.
Changed
- The Mac app's Settings window was reorganized: the overloaded AI tab split into Agent (enable switch, model, generation, vision) and Providers (API keys, local models, custom providers) and no longer disappears when agent mode is off, Shortcuts and the Sparkle update preferences moved into General, "Show in Dock" became a "Show Peekaboo in" menu-bar/Dock popup, the vision-model checkbox+picker collapsed into one popup with "Same as agent model", and Visualizer animations are grouped by area (Pointer, Keyboard, Screen, Apps & Windows, Extras) with consistent sentence-case names.
peekaboo clean --snapshotnow says when a valid snapshot folder name was not found in the on-disk cache instead of reporting a bare success with zero removals, andlist windows/window listhelp now explains how the two views differ.- Clicks and mouse moves are now visualized by a small animated macOS-style cursor that glides to the target and presses (double-press for double-click, blue-tinted for right-click), replacing the targeting reticle and comet.
- The accessibility element boxes drawn during
peekaboo seeare off by default now; they were visual clutter on every capture. Re-enable them in Peekaboo.app under Settings › Visualizer › Screen › Element boxes, by settingvisualizer.elementDetectionEnabledin~/.peekaboo/config.json, or per-run withPEEKABOO_VISUAL_ELEMENT_BOXES=true. The app toggle and the config file now stay in sync, and a running MCP server picks up the change without a restart.
Fixed
peekaboo run --json --output <file>now emits its structured execution report to stdout as well as saving the report file, and menu bar title matching accepts common hyphen variants such as documentedWi-Fiagainst macOS'sWiFiidentifier.- Bridge-backed CLI commands now preserve app, window, element, menu, Dock, and snapshot lookup identities in structured errors instead of collapsing them to generic failures. Thanks @SebTardif for #258.
- Click and type failures now emit
INTERACTION_FAILEDinstead ofCAPTURE_FAILEDin structured CLI output. Thanks @SebTardif for #257. - The Mac app's status bar menu now follows the system light/dark mode. It previously inherited the menu bar's wallpaper-derived vibrant appearance, which could render a dark menu while the system was in light mode (and vice versa).
- Resuming an agent session without an explicit model now preserves its credential-free provider-qualified model selection instead of silently switching to the current default and potentially sending saved context to a different provider; ambiguous legacy sessions fail closed and require an explicit override, automatic taskless piped resumes report failed turns with a nonzero exit, and chat headers show a credential-free saved-model label instead of claiming the current default.
- Agent tool execution now treats provider terminal events and cancellation as hard boundaries: late or truncated tool calls cannot run, canceled or skipped calls emit failed completions, and final
done/need_inforeasons remain visible. - Agent session lists now use persisted creation and update times for display, ordering, and expiry instead of filesystem timestamps, so atomic saves no longer make old sessions appear new.
- Multi-step Ollama agent runs now replay assistant tool calls and named results, preserve recursive arguments and array schemas, surface HTTP-200 stream errors, and fail with a resumable saved session instead of claiming success when pending tool work exhausts the step budget.
- Custom-provider models marked
supportsTools: falsenow get actionable agent guidance;config models-providerlists configured models offline unless--discoveris passed, and--savepreserves existing capabilities, limits, and parameters while keeping newly discovered models tool-disabled until explicitly enabled, including in JSON mode. - OpenRouter, Together, and OpenAI-compatible GPT-5.6 routes now preserve the 372K context/128K output capability profile, omit unsupported temperature, and recognize routing suffixes such as
:online. - Adding a macOS application bundle to the Dock now places it with applications instead of mistaking its on-disk directory for a folder.
- Synchronous default MCP tool-context access now fails fast off the main thread, with an async main-actor accessor for background callers. Thanks @SebTardif for #253.
- Default
PeekabooMCPServerstartup now throws an actionable configuration error instead of terminating the process when no default tool context was installed. Thanks @SebTardif for #252. peekaboo agentwith a local Ollama model now actually runs its tools. Ollama's streaming API returns tool calls alongside empty content, and those were being dropped, so models fell back to printing tool-call JSON as text: the agent executed nothing, reported zero tool calls and empty content, and still claimed success. Asking the agent to click a button now clicks it.peekaboo agent --model <a tool-incapable model>explains that the agent requires tool calling and points atimage --analyze/see --analyze, instead of claiming the model is "unsupported" and printing an allowlist. Vision models such asollama/qwen2.5vl:latestare real, installed models — they are simply not usable for the agent loop.peekaboo clean --snapshotnow rejects empty, traversal, nested-path, absolute-path, and symlink snapshot IDs, keeping cleanup confined to one real snapshot folder directly beneath the cache root.- Background positional clicks (
click --coordsand background--double) no longer land at the target window's top-left corner while reporting success — macOS discards the location of pid-routed mouse events, so coordinate clicks now hit-test the accessibility element at the point and press it, background double-click fails with a clear error pointing to--foreground, right-clicks that open a context menu report success promptly instead of timing out after 10 seconds (and no longer stall the bridge for other clients), andclick --foregroundactually focuses the target app before clicking as documented. - Invoking
peekaboo daemon startthroughPATHnow relaunches the canonical executable instead of looking for apeekaboofile in the current directory, startup errors now distinguish launch failures, early exits, and readiness timeouts, and daemon logs honorPEEKABOO_CONFIG_DIR. Thanks @mattash for #231. - Daemon startup no longer blocks indefinitely: child cleanup is bounded with a TERM grace period, liveness re-check, and SIGKILL escalation, and startup coordination uses cancellable lock domains so a custom
--bridge-socketcannot contend with the canonical daemon. - Daemon startup coordination and child cleanup are now bounded: startup locks are securely opened, isolate non-default custom sockets while preserving default-daemon promotion, cannot leak into spawned daemons, and honor cancellation and timeouts; child termination uses bounded TERM and SIGKILL phases instead of an unbounded Foundation wait.
- A transient lock or read failure on the snapshot invalidation watermark no longer hides every cached snapshot. When the latest snapshot really was invalidated by an earlier command, element and query targeting now says so and tells you to re-run
peekaboo see, instead of the meaningless "Snapshot not found or expired: No snapshot found". peekaboo window resize,move, andset-boundsnow report the window's real frame and warn when the app clamps the request (for example a minimum window size); a resize that has no effect at all fails instead of reporting success.window maximizereports the settled frame rather than a mid-animation one, and is now idempotent instead of toggling a maximized window back down.peekaboo list windowsno longer emits the same window twice when an app has two windows with the same title, which also shifted every later--window-indexand could target the wrong window.- The Visualizer's annotated-screenshot setting now persists across launches instead of silently resetting to enabled, and it finally has a toggle in Settings.
- The CLI no longer routes commands to a bridge host that cannot satisfy the permissions those commands need. A stale Peekaboo.app holding the bridge socket without Screen Recording or Accessibility is now skipped in favor of a permissioned daemon, instead of silently failing every capture and automation call. Screen Recording is only demanded for commands that actually capture, and hosts that do not report their permissions are still accepted.
- Canceling an app relaunch wait now stops its running-state poll immediately instead of spinning through the remaining timeout budget. Thanks @SebTardif for #230.
- Snapshot-backed MCP actions now synchronize cached application, window, and process metadata acros...
v3.8.0
[3.8.0] - 2026-07-09
Changed
- The menu bar icon was redesigned as a crisp template ghost with a camera-lens belly that echoes the app icon, now rendered at proper 1x/2x/3x resolutions; it previously shipped a single blurry 18px bitmap reused for all Retina scales.
- Peekaboo.app releases now use the OpenClaw Foundation Developer ID identity while retaining the bundle identifier and Sparkle update key; the standalone CLI keeps its legacy signing team so it remains compatible with pre-3.8 GUI bridge hosts, and 3.8 hosts trust both release teams. macOS may ask once to reconfirm protected-data access after the app signing-team migration.
Fixed
- The macOS Sessions window and agent popover stay unavailable while Agent mode is disabled, including Dock reopens, global shortcuts, notifications, and windows already open when the setting is turned off.
- The GUI bridge now enforces both signing Team ID and bundle ID on every request, preventing unrelated same-team processes from borrowing Peekaboo's protected macOS permissions.
Peekaboo 3.7.1
[3.7.1] - 2026-07-05
Changed
- The Settings window was modernized around native macOS grouped forms: the AI tab collapses seven redundant provider sections into one clean API Keys list with environment-variable status footnotes, the model pickers now always display the selected model's name (they previously rendered blank or a raw model id when the selection came from
~/.peekaboo/config.json), the Visualizer tab drops its hand-rolled iOS-style switches for native toggles with inline sliders, Shortcuts is three recorder rows plus a one-line hint instead of a wall of instructions, Permissions gets the standard grouped layout, and About uses native links (and the current year). - The macOS app icon now blends Peekaboo's translucent camera-ghost banner identity into a clearer, lens-forward mark that stays legible at small sizes.
Removed
- Poltergeist build-watcher integration is gone: the config, wrapper scripts, watchman config,
pnpm run poltergeist:*/polterscript aliases, docs page, and leftover rebuild-test comments were removed. Rebuild with./scripts/build-mac-debug.sh(Mac app) orpnpm run build:cli(CLI) instead.
Distribution
- Peekaboo.app 3.7.1 — signed, notarized, and stapled universal macOS app.
- Universal CLI — arm64 and x86_64.
- npm package —
@steipete/peekaboo@3.7.1, published 2026-07-05T09:50:03.991Z. - Registry tarball — integrity
sha512-XZTl9K2AYTf2LDWBW2jAF2UlWHsJXVRysRt/nBP615SjQZtRHlwc48+Z48FI+ATvkus0aUpRfTyMrWxNjXjiYA==. - SHA-256 checksums.
- Homebrew:
brew upgrade steipete/tap/peekaboo.
Verification
- Release commit
415f6642. - macOS CI run 28736049054 passed all five jobs for the release commit.
- Local release preflight passed 633 tests in 72 suites; formatter, docs, lint, and autoreview passed with no actionable findings.
- CLI and npm artifacts contain both arm64 and x86_64 and report Peekaboo 3.7.1.
- Peekaboo.app passed Developer ID signature verification, Apple notarization, stapling, Gatekeeper assessment, and fresh-zip validation.
- All release artifacts matched the published SHA-256 checksum manifest.
Peekaboo 3.7.0
Added
- The MCP image tool now supports native
max_dimensiondownscaling, with inlineformat: "data"captures capped at 1500 pixels by default to reduce payload and model-context overhead. Thanks @jacobjove for #219.
Changed
- The Sessions window was redesigned around native Liquid Glass: the empty-state ghost is now a smooth vector silhouette rendered as a real glass surface that floats over a soft shadow and occasionally glances around, the sidebar swaps its hand-rolled header and search box for the native toolbar search field plus a compose button (⌘N), session rows show tidier metadata with a model badge, and empty search results use the standard "No Results" view. The refreshed ghost (white with a soft gradient in both light and dark mode) also carries over to the status-bar popover and onboarding screens.
Fixed
peekaboo capture actionnow returns within a bounded interval when a child survives termination attempts, preserves graceful TERM handling for timeouts and cancellation, and eventually reaps an abandoned child. Thanks @SebTardif for #215.
Distribution
- macOS app: Peekaboo-3.7.0.app.zip
- Universal CLI: peekaboo-macos-universal.tar.gz
- Homebrew:
brew upgrade steipete/tap/peekaboo - npm: @steipete/peekaboo@3.7.0
- Registry tarball: steipete-peekaboo-3.7.0.tgz
- Integrity: sha512-PcG4Z90RllTZHJov+l87Nj1lnThjq5vuQFvq7gERnnWaadhtpIUPWPqDqNVNvZ95yBGRB+Grb7Pwsz7o64WBPA==
- Checksums: checksums.txt
Note
The npm 3.7.0 tarball contains an Apple-silicon binary. Intel Macs should use the universal GitHub asset or Homebrew formula.
- Proof: exact release commit and checks; local preflight passed 633 tests, and the app artifact passed Developer ID signing, Apple notarization, stapling, Gatekeeper assessment, and extracted-ZIP verification.