Mercury CLI
Documentation

Releases

1.0.0-beta.21

published 26 September 2026

  • Added /jevor on, which runs Jev through the existing OpenRouter sign-in with its own stated-cost meter and cap; /jev on keeps the official TypeSafe service, and signing in never switches JEV on
  • Added a ContextLeft tool: the model can ask how much of the context window is used and how many tokens are left before a compaction, measured on the wire
  • Added a per-call output budget on the Bash and PowerShell tools (max_output_chars): the inline window shrinks or grows, the whole output is still saved, a value outside the bounds is clamped and said, a failing command's error text honours it, and a spill notice is never cut away
  • Changed the Edit match to forgive indentation, trailing whitespace and typographic dashes and spaces, never content; the result says what it matched and how (the file's own indentation or dash), and two differing candidate blocks refuse as ambiguous rather than not found
  • Changed a provider's retry-after to be honoured first when a request is rate-limited
  • Changed an empty reply to be asked again once, carrying a one-line note that asks for the answer or the tool call
  • Changed every wait with a ceiling (Monitor, Sleep, Service, Workshop) to clamp to it and say so instead of refusing the call; Sleep waits a real second at least, and its row and spinner name the wait that really happens
  • Fixed an Edit refused as unread on a file this session itself wrote, and every applied edit now says no re-read is needed
  • Changed an interrupted tool call's result to tell the model what may have happened, and a call abandoned after an interrupt had started it no longer claims nothing was changed
  • Fixed a tool call refused for a name in the wrong case: it runs; an unknown name is answered with the closest advertised tool
  • Changed a tool-result image that was shrunk to say so, with its original and delivered pixel sizes
  • Fixed a finished sub-agent answering only to its id: it answers to its launch name too, and the name survives a compaction
  • Changed Grep to fall back to PCRE2 for a look-around or a backreference instead of refusing, and to name ripgrep's reason when it still refuses
  • Fixed the daemon, and every writer into its home, recreating a home it had been told is gone
  • Fixed a daemon stop or restart issued from inside a hosted session ending that session's own turn: it refuses and says where to run it
  • Changed a network outage on every provider to take its own bounded reconnect steps, never spending the API retry budget and never counting as a fault; the status row says it is reconnecting (MERCURY_RECONNECT_BUDGET_MINUTES, MERCURY_RECONNECT_SCALE)
  • Fixed the model picker opening stale for a Kimi plan or a DeepSeek key: the list is read when the picker opens, and the heading says how many models are live
  • Fixed a tabbed added or removed line in a transcript diff box running through the box's border: it wraps inside the box, the band ending at the border; a tabbed file's syntax-coloured rows and its consent card count the tab's cells too, so the card fits the pane
  • Changed the signed-in Claude account to be named from its own credential on the logins roster, the face chip, the usage summary, the accounts board and auth status, never from the config file's copy; the recorded snapshot is shown only when it differs
  • Fixed a session resumed inside a recorded worktree losing the prompt sections its first exchange recorded
  • Fixed a session runner that died from outside waiting the crash backoff's first step before coming back: the first death respawns at once, the backoff waits only for a loop
  • Fixed a Browser op on a browser that had died waiting out its whole deadline, and a lapsed close now really ends the browser process
  • Fixed two sub-agents in one session sharing one scratchpad folder and writing over each other's helpers: each is told its own folder under the session's
  • Fixed a self-paced wake on a seatless run that fired into a closed usage window re-arming every minute: it waits the window's own delay once; a fired wake's row names the tick's own fire instant
  • Changed every persisted attachment kind to carry a body-shape row, so a malformed row of any kind is thinned and named on resume
  • Fixed a session resumed from a recorded transcript home (the daemon's cold resume inside a worktree) losing its title, agent, mode and worktree record and writing its next turns into the worktree's project directory; a resume by session id keeps its agent name, colour, mode and PR link too
  • Added two write wards: an edit or write carrying an omission placeholder ("rest of code unchanged") is refused before any byte lands, on every path that lands bytes, and a hand edit of a generated file, by name or by its leading marker, is refused with the generator named
  • Changed the usage warning's one stray 70 percent floor to follow the warning tiers: nothing speaks before 80 percent of a window, and a warning never offers a handoff
  • Changed mercury daemon stop to take no flags: --keep and --any are retired (nothing ever kept a worker), and an unknown flag is refused by name
  • Added a loop guard: a tool call repeated with identical arguments and an identical result is reminded at the third, fifth and eighth repeat, a cycle of up to five calls repeated five times is named, and a reply that chants one stretch is asked once to continue past it; with loopGuardStopEnabled true in settings the second detection of the same cycle ends the turn as loop_stopped (by default nothing is ended)
  • Changed the OpenAI, Z.AI and compatible providers (Moonshot, DeepSeek, Gemini, Hugging Face, OpenRouter, the local servers) to publish every busy and plain retry wait to the status row
  • Fixed a started tool call that answered an interrupt with its own AbortError settling as an error: it settles as the interrupt
  • Fixed a hook's additional context on a tool call ending the turn with a thrown error, and a stopped-continuation row showing no reason
  • Added a title to CronCreate: the Saturn row's first line and CronList read it in place of the schedule id
  • Fixed a scheduled wake batched into the operator's queued turn, or re-queued after a runner restart, painting under the operator's handle: it paints as the Saturn row with its origin
  • Changed Sleep and a blocking wait for background output to end the moment new input lands for the active turn
  • Fixed an MCP call's idle clock running while the operator answered the server's own question: it waits
  • Added an Interrupt hook event: it fires once per cut on every abort path and can never change the cut
  • Changed a compaction to carry the operator's own messages verbatim, newest first within a budget, ahead of the summary
  • Fixed a resumed session's ledger reading one per-project slot: it is rebuilt from the transcript's own records
  • Changed a sandbox denial to ask once inside the same Bash call, from the runtime's own record; the sandbox violation monitor is on, and on macOS Mercury reads every deny line of the log stream itself
  • Fixed the up-arrow recalling a stale list after a compaction or an earlier walk: history is read afresh at every walk, and a submit ends the walk
  • Fixed a bare run's own wake painting under the operator's handle: it paints the Saturn row like a seated fire, and a wake's slash-led words reach the model as words
  • Changed the session facts a hosted session answers to name the signed-in Claude account by its own credential
  • Added data breakpoints, instruction breakpoints and writeMemory to the Debug tool: it stops on the write of a variable or at a machine instruction and patches debuggee memory
  • Changed a scheduled fire to bill as scheduled work wherever it fires, in its own usage bucket; the usage popup, the rail, /cost and the SDK result frame show a scheduled row
  • Added a pause gate: p in the crew view parks every agent of the chat on screen at its next safe point and resumes it from exactly there, through one control verb the daemon relays to the session's runner; the chip reads the runner's own fact; a workflow run pause parks the run's agents at the same gate when the runner hosts nothing but that run
  • Fixed a workflow pause admitting the script's next agent call: the run parks before it, is saved with its position, and a resume by run id starts there with no finished call repeated
  • Changed the operator's ! shell row to name its exit code and how long it ran
  • Fixed the editor bridge pushing only the selection to a terminal session: the open-files context rides too, named once per prompt
  • Changed a bare live model list to paint every id the signed-in account answers as a selectable row; an id the catalogue cannot name reads live · unknown to mercury and paints no context window it was never told
  • Changed a rule that denies a Bash command to say the rule's reason in every one of its sentences, the compound aggregate included
  • Added a strategy-mode refusal of any shell command that modifies files, in the Bash and PowerShell verdicts, said in the mode's own words
  • Fixed a click on the usage or files rail header eating the composer's draft: a click that runs a command leaves the draft where it was
  • Changed the Bash tool's zsh to split an unquoted expansion into words the way bash does (SH_WORD_SPLIT joins the tool's preamble); a quoted expansion still stays one word
  • Fixed a cut tool call never reaching PostToolUseFailure hooks: it fires once, under its own signal, with is_interrupt true and the cut's words, whichever way the call was cut
  • Fixed a forked sub-agent not being told its own scratchpad folder, and every transcript reader now derives the resume facts the same way
  • Fixed the approaching-weekly-limit mock scenario answering nothing: it speaks the weekly figure at the warning tier
  • Fixed the splash deploy refusing a launcher it did not write: it skips it with one quiet line and writes nothing
  • Changed the model picker: providers first, each a heading that opens and closes like the files menu, with the sign-in as a sub-heading only when two are signed in; every row is alias, raw id, state and context size, and an id Mercury cannot name reads new · no alias; the signed-in account's own provider sits on top and the rest follow by most recent use; / opens a filter; the state column says only current; the title is the one line Mercury · model
  • Fixed the Eval tool's Python kernel aborting at exit under Python 3.14, which raised a crash dialog per kernel on macOS: every kernel end flushes its pipes and exits cleanly
  • Fixed a live thinking block dropped on the turn after the loop guard spoke, and its drop recorded twice: the guard's reminder keeps one wire shape across the turn boundary
  • Fixed a runner's fresh model answer sometimes never reaching the session facts: two publications inside one millisecond no longer share a stamp
  • Changed a model switch that lands on a runner that had just exited and come back to say so in its receipt
  • Fixed a hosted session's facts moving only at the ten-second heartbeat on Linux: the directory watch's dropped twin report no longer hides a publish
  • Changed a lapsed browser close to end the whole process tree, on Windows through taskkill
  • Changed the ContextLeft tool to load on demand through ToolSearch, so the first request keeps twelve eager tools
  • Changed every tool description to say each rule once and narrate no result, so the first request's tool definitions are smaller on every provider
  • Fixed a status-row wait line cut to its budget clause on a narrow terminal painting the clause bare after the separator: the ellipsis leads it