Generated images and music
Agents picked up two new crafts this week: making original art and writing their own music, right in the middle of a build. The apps they hand back also look noticeably more finished the moment you open them. On your phone, anything an agent points you at now floats up as a live picture-in-picture window, and the mobile app finally stops crashing after updates. On the deeper end, SootSim’s photorealistic 3D device mode got a wide fidelity pass, previewed apps started running their own backend routes, and PR previews landed as a Pro plan feature.
Platform
Generate original images and music inside your app
Instead of wiring up placeholders, agents building your app can now make the real thing. They produce app imagery, logos, splash art, and illustrations, and they compose instrumental and ambient music that comes back in about eight seconds rather than cold-queuing for minutes. Whatever they generate rides the same asset pipeline as everything else, so audio and images bundle, deploy, and commit into your repo like any other file.
Spend stays transparent and in your hands. Cheap iterations run instantly, but any single generation over twenty-five cents stops and asks you to confirm in chat first, so a build can never quietly rack up cost. A per-model rates table spells out the exact price for every model and generation type, and it shows up on the pricing page, in your billing usage view, and in the docs.
The apps you build look better by default
The design quality of what agents produce took a real step up, distilled from studying a polished reference app. The biggest gap used to be lists and feeds, the single largest surface they had no guidance for, and that is now a taught skill. Alongside it comes a richer vocabulary: three-tier physical feedback, warm temperature-tinted neutrals with accent pairings, product-voice copy for empty and loading states, and named visual patterns like photo mattes, card piles, sticker cutouts, kinetic titles, and onboarding intros.
The starter templates that seed new apps were upgraded to match. They now ship documented brand color ramps, haptics wired into natural spots (swipes, game damage, saves, posting), virtualized feeds with staggered entrance and press feedback, and designed empty states. Text on accent colors was deepened to genuinely accessible contrast, so labels read clearly on colored fills.
Your phone becomes a real build cockpit
You are building on your phone, an agent mentions something it is working on, and that note now arrives as a tappable chip. Tap it and the matching surface floats up as a small picture-in-picture window over whatever you were already looking at, whether that is the build floor, the plan board, or a live preview, so you can keep an eye on it without leaving your place. The factory and plan views were rebuilt to live in that same floating stage, so moving between them feels continuous instead of jumping between full screens.
The phone gained real building surfaces of its own. The new Plan tab is a swipeable kanban board with Backlog, In Progress, Review, and Done lanes that mirror the web, and a native tap-to-menu moves a task between lanes through the exact same path the web board uses, so the two stay perfectly in sync. The Factory tab lays chat and floor out as two floating cards over a draggable seam you pull to resize the split; the resize runs entirely on the animation thread for a butter-smooth feel, with soft haptic taps on grab and release. And when an agent needs a decision, chat now shows a real interactive question card you answer or skip inline instead of raw tool text.
Following a build got steadier, too. Your very first message to a brand-new project can no longer silently vanish. The activity feed collapses a run of identical beats into one card with a count. Opening the Plan board mid-build drops you on the first lane that actually has work. And the live floor shows readable name tags that stay legible even when a dozen workers pile onto the same spot.
A warmer, more reliable mobile app
The mobile app used to crash immediately after every over-the-air update. Now updates download quietly in the background and apply on the next cold launch, so nothing reloads mid-session: the app just picks up the new version the next time you open it, with no crash, and a background watchdog can self-heal if a project connection ever gets stuck. It got a broad feel pass alongside that fix. There is one consistent vocabulary of taps, selections, and success buzzes, a pulsing skeleton of tiles while the project grid loads, staggered tile entrance, designed empty states, and a native task detail screen that opens instantly from cache. Flipping between dark and light repaints the live app immediately, the way native iOS does. Signing in with a valid saved session takes you straight home instead of hanging on “Signing in.” Settings was rebuilt as a real iOS grouped list with a large title, back button, and swipe-back. A warm cream brand palette got an experimental run during the week and was then dropped in favor of the stock subtle theme, but every one of the tactile and reliability improvements stayed.
Live updates when your dependencies change
Change your app’s dependencies, whether you edit package.json yourself or an agent adds a package, and a live card now appears in chat that walks the update through its stages: resolving the new packages, restarting and rebuilding, then ready. If a step fails you get a clear, recoverable error you can retry from. Before this, an agent adding a dependency did nothing visible at all, with nothing restarting and no feedback in chat.
More npm packages just work in preview
Apps that pull common npm packages with a React peer, like Zustand or Zod, now load in both web and native previews. Previewing one used to crash with a hooks error, because the CDN served its own copy of React that was not tied back to the app’s, and named exports like Zod’s { z } could silently go missing. Both are fixed. And a native-only package that cannot run on the web now reports its own name, so you know exactly which dependency is the problem.
A sharper, more photorealistic 3D device mode
SootSim’s 3D device mode renders your live app on a rotatable photorealistic iPhone for demos and App Store shots, and it got a broad quality and controls pass. The headline is a real photographic Focus depth-of-field control: you can dial focus strength from soft through dramatic, set how wide the sharp band is and its falloff, and tapping the phone screen pulls the focus point there before easing back. The device model was re-baked crease-free at higher subdivision so circular parts stop scalloping, the screen sits as a true rounded-rect inset so the bezel no longer pinches at the corners, and studio lighting was rebalanced so the chrome rail reads as real tonal chrome instead of blown-out white at side angles. The whole stage looks materially better: smoother gradient backdrops without banding, a resin-like phone body, a cover-glass edge highlight, three new camera presets, and a lights-rail spin that sweeps reflections across the glass. The rail controls were reorganized, and the clunky OS color picker gave way to an in-place popover. One mid-pass room-lighting experiment was reverted after in-person testing; everything else stayed.
Pricing you can read in credits or dollars
Billing is now a transparent, dollar-native model. The rate card on the pricing page is driven from the model registry, so it shows the actual charged rate for every model, and a toggle flips the whole page between a credits view and a dollars view so you can read your spend whichever way you prefer. This replaced an earlier credits-first experiment and returns to the dollar ledger the system was always built on, so no balances or caps changed.
PR previews for your team’s GitHub repos
GitHub PR previews are now a Pro plan feature, gated at every entry point through one shared resolver so free or unlinked installs cannot trigger AI spend, with the sticky PR comment surfacing a Pro upsell. Owners also get a dismissible “set up PR previews” card above the org repo grid, linking to the setup docs, so the feature is discoverable straight from the org page. And the underlying contrast-preview GitHub Action no longer requires pnpm: it detects your package manager from your lockfile and installs with npm, yarn, pnpm, or bun.
Record an issue from the Forge companion app
The Forge mobile companion gained a one-tap “Record issue” flow under Settings. Tap it and the app restarts into a verbose diagnostic session, capturing a session replay, console warnings and errors, native crashes, and Zero and auth context, all tagged with a single report id and an app-wide “Stop and send” banner. Sessions auto-cap at five minutes with a live countdown and expire on relaunch, so a forgotten recording can never run forever.
A redesigned marketing site
The Soot and SootSim marketing sites got a broad visual refresh: reworked home heroes, simplified pricing pages, a redesigned developer page, and a living aurora backdrop that drifts behind and through the hero lettering, blending differently in light and dark and respecting reduced-motion. The SootSim home now leads with its test-driver pitch and plays a looping three-mode video demo, and a new public deep-dive page walks through how the SootSim engine works, with a runner benchmark chart and a diagram of its three execution contexts. The redesigned homes are live in production, and the old staging versions were retired, so there is a single home page.
Tech
Project connections no longer wedge on “Reconnecting”
On Cloudflare, every web and mobile project-to-Zero connection was wedging in a needs-auth “Reconnecting” state. The chain is subtle: the zero-cache transform hop runs the whole handler wrapped in the project’s namespace, so the session lookup hit the project SQL Durable Object, which holds no session or user rows, and returned null. The anonymous fallback then produced userID:'anon', and Zero 1.7.0’s strict validateConnection rejected the mismatch as Unauthorized. The fix adds a runInControlNamespace escape that resolves auth against the singleton control DO, where session and user rows actually live, while the data transform stays project-scoped; it is a no-op on node and local.
Previewed apps now run their +api backend routes
Preview now runs an app’s +api backend routes in both web and native, so a previewed app behaves like the deployed one. Templates advertise +api endpoints, but preview previously only proxied /api/auth, so a route like a flights template’s demo-seed endpoint returned 404 in preview (empty demo data on the iOS pane) even though it worked once deployed. One’s route semantics are now mirrored into the project-server worker, which stays the single route authority, and native preview forwards all same-origin /api/* fetches to it. Two auth bugs surfaced along the way: Zero bearer tokens are better-auth session tokens rather than JWTs, so JWT verification was dropping every authenticated pull to anonymous, and the worker must hold exactly one on-zero instance or user-scoped queries come back empty.
Deploy fails fast and names the offending package
Deploy gained two up-front guards so a bad dependency fails in seconds with a name, instead of a cryptic rollup crash minutes in or a broken app on device. The app build now preflights every bare source import against the workspace install and fails immediately, naming each missing package (a dep that resolved from the CDN in preview but was absent from node_modules used to surface deep inside rollup). Separately, the shell payload assembler classifies every payload dependency against the frozen iOS shell contract and flags a native module the shell did not compile, detecting native modules by a real autolinking signal (a root podspec or Apple expo-module config) rather than the unreliable ios/ directory. The gate is two-tier: fatal for known-impossible natives and unresolved declared deps, a loud warning for out-of-contract natives that still autolink.
The 3D depth-of-field pipeline, rebuilt for color-accuracy
The old depth-of-field leaned on a hand-rolled full-screen quad that bypassed three.js per-material tone mapping and sRGB encode, so every color shifted the instant Focus turned on, and it paid two full scene renders plus a fifty-tap full-resolution blur. It was replaced with a single RenderPass into a 4x MSAA half-float buffer (flagged so toneMapped:false materials keep exact colors), a half-resolution DepthOfFieldEffect from the postprocessing library, and an SMAA antialiasing tail. The “noisy screen edges” turned out to be texture minification that no amount of MSAA could fix, so the screen texture gained mipmaps and anisotropic filtering and the 1.25x supersample multiplier was dropped. Net effect: color-exact output, a cleaner screen, and the legacy three-mode DOF module and its test deleted.
Hosted builds stop burning CPU on unwatched pages
Two fixes cut the hosted factory runtime’s CPU and GPU cost. The headless-Chrome supervisor was flapping: reaching “app ready” reset the relaunch backoff, so a page that wedged seconds later spawned a fresh Chrome roughly every minute, forever. The backoff now only resets after a session runs healthily for two full minutes, with a rolling-window guard that hard-stops runaway relaunches. The other half was pure waste: opening the dev workspace eagerly booted both preview iframes that nobody was watching. The visible preview panes now gate their iframe mount on the same headless signal that already gated paint, so an unwatched page mounts no preview and mounts on demand when someone actually looks. On top of that, the guided-tour pointer’s infinite drift, which held an idle host awake at 60 to 100 percent of a core, is now gated off in the headless runtime, and an idle host with no agents exits after ten minutes.
Cloudflare backup fix and cost tripwires after a $118 burn
This one started as a Durable Object rows-written cost burn. A restore had re-seeded orez’s replication table with a backlog the consumer could never confirm, so every zero-cache embed boot re-streamed all of it. Exports now skip the six orez replication-bookkeeping tables, and restores skip them in old dumps and truncate them in the target namespace. The cost watchdog also gained a five-minute-bucket tripwire (200k rows, polled every five minutes so alerts fire within five to ten minutes of onset) plus a one-million-rows-per-hour backstop, and alert emails now describe the system-wide auto-shutdown.
SootSim engine: WebSocket remapping and a double-keystroke fix
Two runtime correctness fixes turned up while driving real external React Native apps from a remote Metro bundle. First, network remapping now applies to guest WebSockets, not just fetches: a remapped app reached its REST host, but its WebSocket lanes (app socket, Zero sync) still dialed the original host and died with a 1006 close, so live sync was silently dead. The WebSocket native module now takes a resolve hook fed the same remap table as the fetch patch, proven by live Zero-synced rows arriving through a forwarded port. Second, a WebKit double-evaluation bug was inserting two characters per keystroke: WebKit does not share a worker’s module-map entry with a later static import of the same URL, so importing shared symbols out of a worker entry chunk evaluated the whole entry twice and doubled the message listener. That was fixed by splitting export-free bootstrap entries with manualChunks rules that pin the implementation into its own chunk.
The engine renders and hit-tests correctly at desktop scale under zoom
An experimental prototype pushed the CanvasKit engine well outside its usual iPhone chrome: a 1440x900 “Canvas Workspace” device hosting an infinite Figma-like artboard grid you can pan and zoom from 0.32x to 1.85x. Making that work drove real engine changes: desktop pointer and wheel input in the render worker, zoom-scaled culling so offscreen artboards are skipped at any zoom, and a rewritten hit-test that keeps controls clickable and prefers transformed descendants under zoom. Read it as proof the engine paints and hit-tests correctly at desktop scale under arbitrary zoom, not as a shipped feature: the device is marked experimental and filtered out of every device picker, reachable only by exact id.
AI model routing collapsed to one provider path
The agent model config carried two dev-only forks, and both are gone. glm-5.2 used to reach Cloudflare Workers AI only in prod while dev and CI went through an OpenRouter stand-in; it now routes through Workers AI in every environment, so dev and CI exercise the exact prod provider path with matching context and output caps. And where dev and prod used to default to different models entirely, both now default to the same deepseek-v4-flash. That same work fixed a production chat 500: prod’s then-default glm-5.2 routed through Cloudflare Workers AI, whose key was never set on the deployed worker, so the deploy flip now bulk-syncs every provider-key secret and fails fast if one is missing, guarded by a new CI check.
SootSim
- iOS long-press context menus render their titles and subtitles, resize the highlight cleanly instead of scaling, and hide the underlying view behind the lifted preview scrim exactly like real iOS; action sheets gained a centered title, and the developer menu now comes up through the real native action-sheet surface.
- Press feedback cancels correctly when a scroll takes over the touch, so a tap never sticks mid-scroll, and a long-press menu no longer fires the underlying card’s onPress on release under the two-worker split.
- Device frames in previews and screenshots now derive bezel width, corner radius, island position, and button placement from Apple-referenced geometry across 52 iPhone models; the iPhone Air renders at its real 420x912 size and the SE gets its real Touch ID body.
- Animated SVG props (progress rings, donut charts) now animate instead of freezing at the first frame, now that animated attributes route to the node’s props rather than its style.
- Text inside a view with only a percentage max-width (a chat bubble at 84 percent) now wraps at the constrained width instead of overflowing, matching real React Native.
- expo-router apps no longer land on “Unmatched Route” at first launch, now that the expo-constants seam receives Metro’s full manifest so upstream derives the developer flag that strips the dev host.
- Hot-reload does a real JS-context bundle reload when Metro escalates to a full reload (a deleted module, a no-boundary apply, or an explicit reload), so newly added route files register without a manual Metro restart.
- The expo-screen-capture seam now registers eagerly for Metro-bundled apps, and the MMKV seam survives detached method calls, fixing Forge’s logout crash under SootSim.
- The SootSim CLI shortened its post-write auto-settle budgets so commands return sooner, and the onboarding welcome copy was trimmed to lead with why it makes agents faster.
- A new preview trace panel captures per-frame stats over a pre-roll and post-roll window against a 16.7ms jank budget, breaking a home-launch into layout, render, and copy averages with p95, max, and jank counts, attached to each recorded flow step.
- An early Expo-Go-like in-app React Native runner (“Soot Forge”) gained a native-target preview bundle endpoint that serves the tenant bundle as CommonJS with native externals left as
require(), avoiding a dual-React-instance problem (experimental).
Mobile app
- Tapping anywhere on the chat composer’s glass card focuses the input, and pull-to-minimize now receives drags even while the keyboard is up, where three stacked causes had swallowed the gesture.
- The selected-agent read-out moved into the header as a proper pill next to the settings gear, an empty plan board mid-build says it is syncing rather than reading like a bug, and switching to light mode no longer leaves chat avatars stuck on the dark color.
- The in-app assistant can rename projects again after an allowlist had filtered the tool out, and it now maps the product-spec build beat to a plan card.
- Creating a new project on mobile uses the same welcome template picker as the web, backed by shared project-creation logic.
- Tapping the version row in Settings copies the full build identity (version, build number, update commit) for pasting into a bug report.
- The Preview tab’s top-bar toggle uses plain theme tokens so it reads correctly in both light and dark, and the redundant expand button was removed since tapping the preview already goes fullscreen.
- The preview control bar got a taller hit area raised for one-handed thumb reach with a border for dark mode, and the factory floor now extends under the floating tab bar with a theme-aware split seam.
- Sending a message while the backend is still cold shows a brief “waking up the factory” beat, and the branch switcher is now plain liquid glass matching the other header controls.
Examples and templates
- The RPG example grew into a real game: defeated enemies drop gold and items, story steps pay out, and level, XP, bag, and quest flags survive a reload (before, progress silently reset). Each area has its own mood, enemies telegraph and spread into a pack instead of instantly dogpiling you, and an automated playtest flagged an early fight as too brutal so it was softened into a winnable encounter.
- The pet example gained four distinct cel-shaded creature species with soft shadows, rim light, and an ink outline, a species picker with generated names you can rename, a live animated creature idling behind the title menu, and a top-keepers leaderboard.
- A batch of first-preview fixes so starter apps look right the moment you preview them on web: post and avatar images that came up blank now load, documentation pages that returned a hard 404 now serve, the nav no longer flickers or double-draws, and eleven fixes landed across the finance, travel, todo, website, and game starters.
- Fixed headers on the web now clear the iPhone notch by reading the device’s real safe-area inset, applied across the app starter plus the finance and travel examples, with everything below the header measured from that same inset.
- The finance splash photo no longer washes out to near-white in light theme, and the travel example’s logout control got a proper accessible label.
- The Slipfare flights template’s login hero now loads in preview (moved from a public path to a bundled import), and its price-source labels read as product-flavored copy instead of “Mock provider.”
- A battery-draining infinite reanimated loop that outlived its component and kept the frame pump running at 120hz now cancels on unmount, with a cancel-on-cleanup rule added to the agent skill doc so factory-built apps avoid the same leak.
- A WebGPU shader fix: current Chrome’s compiler rejects a descending
smoothsteprange and invalidates the whole pipeline, blanking several game canvases, so all constantsmoothstepcalls were rewritten to ascending ranges.
Reliability and infra
- Opening the preview projects picker no longer 500s on Cloudflare, where a timestamp was treated as a JS Date that the DO SQLite driver hands back differently.
- Creating a project from a template no longer produces a duplicate project or hits a database race, now that intro chat messages are gated on the project row’s commit.
- A database-unavailable session lookup now surfaces as a retryable 5xx instead of a false 401 that wedged Zero clients in a needs-auth state, and a fleet-wide 429 storm that wedged mobile session polling was fixed by trusting
cf-connecting-ipfor rate-limit keys. - The factory that builds your app stops spawning duplicate-task storms: task reads now wait for the board to fully sync (one build had spun up eleven duplicates from a single issue), a repeated internal failure shows one friendly line instead of dumping raw errors, and the lead agent can rename the project tile so the grid stops filling with “New Project N.”
- The app factory now latches a five-minute global start hold when an LLM account fails on billing or auth, after a drained account hot-looped roughly 3,800 error messages in thirty minutes.
- orez moved to 0.4.41, fixing a zero-cache crash-loop where a purge lock held through initial sync blocked replication-slot creation until lock-timeout after any restart.
- Embedded previews render in the on-device phone webview again, with the seeded session cookie now setting the right attributes per client and context (partitioned SameSite=None+Secure for chrome embeds, lax for webkit over dev http and the on-device WKWebView).
- Deployed apps ship a working favicon instead of 404ing on
/favicon.icoat load, and the deploy validator allows that benign probe while a real asset 404 still fails. - The shell build no longer deletes authored homepage media during the SootSim Pages build, unblocking every main-branch deploy that had been hard-failing with “sootsim static subtree missing.”
- Agents no longer get stuck on “do not merge” after a crash loop recovers, now that alerts older than the preview’s latest successful render are dropped.
Editor and CLI
- The native preview pane holds a correctly-sized placeholder matching the real device instead of a fixed fake phone about 15 percent smaller, so it no longer visibly jumps when the live simulator swaps in, and it stays put until the live device actually renders.
- First-time CLI login no longer hangs forever on the GitHub authorize screen when a stray localhost request hits the callback; login now waits up to five minutes with clear messaging, ignores non-matching requests, and retries the token fetch across a cookie timing race.
- Tamagui was upgraded to 2.4.2 for faster server-side rendering across the root and every workspace and template, with the deploy size gate rebaselined against a freshly measured build to keep the same regression headroom.
- The guided onboarding tour got a dedicated End button, the SootSim FAQ was corrected and shared across the homepage and pricing page, and a new /docs/stack page explains each layer of the standardized stack.
Fixes & polish
Beyond the headline work, 171 fixes and 4 performance improvements landed this week. A few worth calling out: the mobile app no longer crashes after every over-the-air update, since updates now download in the background and apply on the next cold launch; opening the preview projects picker and creating a project from a template both work reliably in production again after a Cloudflare timestamp bug and a database race; and starter apps now render correctly the moment you preview them on the web, with blank images, hard 404 doc pages, and nav flicker all fixed across the finance, travel, todo, website, and game examples.