Changelog
0.13.0 2026-10-06
Added
kaloko <command> --help(or-h) andkaloko help <command>show the help of that one command, with the options every command takes and the exit codes: 0 done, 1 checks found problems or the command failed, 2 a usage error.kaloko --version,-vandkaloko versionprint the version.kaloko start --jsonprints the run id and its folder,kaloko status --jsonwhat each step has captured.--org <slug>on every command works with another organization thanorg:in the config.- API errors name their reason in
codenext toerror. When the plan does not include something (HTTP 402) the answer links the organization's Plan & billing inbilling_url, and the CLI prints that link. - Webhooks carry
Kaloko-SignatureandKaloko-Eventnext toQAwalk-SignatureandQAwalk-Event, with the same values, so receivers written before the rename keep working. - The trust page names a contact for reporting abuse (phishing, malware) on kaloko.app, files.kaloko.app and design previews at
*.kaloko-usercontent.com. - The trust page explains how Kaloko hides personal data in captures (masks,
[hidden]in the stored HTML and the outline evaluators read,pii: redact) and links the how-to. The subprocessor list now names Workers AI at Cloudflare, which Clef triage uses only when an admin turns the experiment on. - Every guide is also plain Markdown at its own address with
.mdadded (/guides/ci.md,/cs/pruvodci/ci.md), for agents and answer engines.llms-full.txtnow carries the pricing table and billing questions, the comparisons, the situations and the trust facts. - The comparison pages answer the questions people ask about them.
Changed
- An option a command does not take gets a "Did you mean --env?" instead of being skipped quietly.
prune,trash,restore,keep,archive,public,releaseandcommentstop before they change anything; other commands say it and go on. - A usage mistake (unknown command or option, missing argument) exits with code 2 and points to
kaloko help <command>, without the support line. runs,pruneandscreenstake--envlike the other commands;--environmentstill works.archivetakes--offlikekeepandpublic(--undostill works), andprunetakes--dry-run, which is what it does without--yes.- A service account token on a plan without service accounts is answered with HTTP 402 (it was 403): the plan, not the token, has to change.
- Webhook requests say
User-Agent: Kaloko-Webhooks/1. - Pricing: the print-quality row is gone, a row shows that hiding personal data works on every plan, and another that the GitHub check on the pull request comes with Team. The site says plainly that your data stays readable on every plan and that exporting a run as a ZIP comes with Team.
- Terms of service, version 4: a trial started with an invitation code needs no card; if none is added, the organization returns to Free when the trial ends. The terms and the pricing page call the billing settings Plan & billing, as the app does.
- Kaloko's public changelog and help have one address per language, which search engines and link previews now understand. The Czech changelog page says that the release notes are written in English.
/designand/cs/navrhlead straight to the guide on designing with your agent.
Fixed
kaloko prune --env preview --yespruned the runs of every environment:--envwas not read. It now prunes only that environment.--key=valuekeeps everything after the first=:--map="Sign in=login"arrives whole.- Commands run without
org:in the config say how to set it instead of failing with a 404 on/orgs/undefined. kaloko runssays when the list stops at the newest 300 and how to narrow it.kaloko design import --jsonprints only the JSON on standard output; progress goes to standard error.
0.12.2 2026-10-06
Fixed
- Czech changelog headings (Přidáno, Změněno, Opraveno, Odstraněno, Zastaralé, Bezpečnost) count as Added, Changed, Fixed and the other Keep a Changelog groups, so a Czech
CHANGELOG.mdis grouped like an English one. - A form that needed a fresh second sign-in step (inviting someone, changing a setting) is sent again after the step instead of coming back empty. The fields wait in the browser tab, never on the service.
Changed
- Screens on the canvas cards stay sharp: thumbnails are 640 wide and scaled down step by step (one big jump made small text fall apart), and when you zoom in past what a thumbnail holds, the visible cards load the full screenshot. Runs shared before this get the zoom part too.
- Videos play on: once you play a step's video, the next step's video starts by itself in the step detail, and replay with video moves to the next step when a video ends (a decision waits for you, a still step shows its screenshot for three seconds). The next step's video loads while the current one plays.
- A step's video is at least 2.5 seconds long, held on its last frame, so a quick step no longer flashes past. A step where nothing moved keeps no video at all, and the canvas shows its screenshot.
- kaloko.com and www.kaloko.com lead to the same address on kaloko.app.
0.12.1 2026-10-05
Added
- A trial code from us gives an organization's first subscription a longer free trial without a card. Open the sign-up link with the code, or enter it under Plan & billing. Two weeks before the trial ends, admins are asked for a card; without one the organization goes back to Free on its own and keeps its runs.
Changed
kaloko sharerefuses unmasked personal data only in a run that hides it (piion the run, scenario or environment, ormask: auto); other runs are shared with the same list as a warning. The site's own contacts no longer count: e-mails on the environment's domain, e-mails and phone numbers in the page footer, and those of an Organization or ContactPoint in JSON-LD (pii: { site_contacts: false }checks them again). Sample addresses such asyou@company.com, placeholder text and SVG drawings are not read as personal data.- Phone numbers written 603 123 456 count only next to a word like Telefon or Mobil, and amounts, EANs and order numbers no longer read as phone numbers. The nine-digit birth number needs its label (RČ), as does one without the slash.
pii: pseudonymizegives one value the same stand-in in every run of the scenario, so screenshots and approvals carry over, and two values never share one.KALOKO_PII_SALTadds a secret of your own.
Fixed
- Hidden form fields, value attributes and personal data in URLs (also encoded,
jan%40firma.cz) are masked. - The capture record no longer keeps real data: page title, headings, JSON-LD, microdata, console lines, blocked requests, the URL and check evidence all go through the mask, and a capture whose masked page cannot be read stores nothing.
- Masking no longer changes what the page reacts to: console errors are read before it,
data-*attributes are masked only in the stored HTML, and the keyboard walk runs on the real page with masked focus shots. - Short masked values such as
2024orPrahaare no longer replaced across the whole run (width:100%stays). - Recordings cover personal data in modal dialogs and popovers, open shadow DOM and same-origin frames, and on a new page from its first frame with everything masked so far. Screenshots of steps mask the same places.
- Values masked in one
kalokoprocess are masked in the next process of the run too. - Triage (experimental) fits long pages into Clef: two page tiles and smaller recording frames instead of four full tiles, and a request still too large is asked again with half the images. A Cloudflare token in the project that cannot use Workers AI hands triage to Kaloko instead of stopping it, and such a token is used only when
evaluators.triageis set inkaloko.config.yml. - A failure while masking leaves the page as it was.
- Long words without spaces no longer slow down detection.
0.12.0 2026-10-05
Added
- Triage, an experiment an admin switches on in Settings → Security → Experiments.
kaloko evaluateshows each screen, and a few frames of its recording, to Clef on Cloudflare, which names the kind of problem it sees: overlapping elements, cut-off text, a raw translation key, a placeholder, an error, an endless spinner, a layout that jumps. The canvas lists them under "Possible problems"; one click turns a right one into an ordinary comment, and findings never change a verdict.evaluators.triageinkaloko.config.ymltunes or turns it off. - MCP tools
get_findingsandanswer_finding. - Masks hide personal data in everything a step stores, not only in the screenshot. The captured HTML and the page outline the evaluators read get
[hidden]of the same length ([skryto]in Czech runs), and traces, recordings, crops, focus shots and the HTML view are covered too. Checks still read the real page, so their verdicts do not change. pii: redacton a scenario finds e-mails, phone numbers, birth numbers, IBANs, account numbers, dates of birth, addresses and names in greetings without a selector, in Czech formats too;capture: { mask: auto }does it for one step.pii.allowinkaloko.config.ymllists values that only look personal, such as your support line.pii: pseudonymizereplaces personal data with made-up values instead of boxes. One value gets the same stand-in for the whole run, so you can still see a name travel from the form to the summary and the e-mail.- Captured e-mails hide their recipients (To and Cc, now captured too) whenever a step masks anything; greetings and payer blocks follow the step's masks.
kaloko sharechecks the run before it uploads: an unmasked e-mail, phone number, birth number or IBAN stops it, with the step and the element.--allow-piiuploads anyway.- An environment with
pii: requiredgets no run that would keep personal data;kaloko start --pii redact(orpii:on the scenario or the environment) satisfies it. - The canvas says "Personal data hidden" on such runs and outlines the masked places in the step detail, so a dark box is not taken for a bug in the app.
Changed
- The masks of a scenario and of its step now add up; before, a step's
capture.maskreplaced the scenario's. - kaloko.app serves its own fonts and the canvas you open from disk carries them inside, so no page asks Google Fonts for anything and Google Fonts is off the subprocessor list on the trust page.
0.11.0 2026-10-04
Added
- The approval page of
kaloko loginsays where the request came from (city, country and address), which terminal asked and when, and starts with a plain warning: approve only a sign-in you started yourself, just now. When the request came from another country than the one you are in, the page says so in red. - SCIM tokens are valid for a year. Settings → Security → SCIM shows the date, and "Renew for a year" keeps the same token, so nothing changes in your identity provider. Admins get a reminder in the inbox 30 days before a token expires. Tokens you already have run for a year from this release.
- A company sign-in over SAML set up before "Require a signed response" existed turns it on with one click in Settings → Security. Kaloko offers the button once it has seen your identity provider sign its responses, so people keep signing in as before.
Changed
- A passkey used as the second step must ask for your PIN, fingerprint or face. A security key that signs without asking no longer counts; your account page names the key and says how to bring it back (set a PIN on it, or add another passkey).
- A run whose title, environment, branch, commit message or another field is too long is refused at the start of the upload with a message that names the field and the limit, instead of an unexpected error halfway through.
Fixed
- A browser that launched but then stopped answering no longer holds
kaloko walk,evaluate --recheckor a capture until someone kills it. A new browser must open its first window within 20 seconds or it is closed and started once more, and later windows have the same limit.kaloko browser start,kaloko doctor,kaloko auth save, the PDF export and connecting to the shared browser now have the time limit and the second try too (KALOKO_LAUNCH_TIMEOUT, seconds). - A
js_equalscheck on a busy machine no longer fails when the page answers a little late: the expression keeps its 2-second limit, and Kaloko waits up to 17 seconds for the page to reply.
Security
- The sign-in cookie can be set only by kaloko.app itself. You stay signed in while it changes over. Your session also gets a new id at every sign-in and right after the second step.
- App and website pages tell the browser which features they never use (camera, microphone, location, payments and the like), and a Kaloko tab opened from another site is cut off from that site's window.
- Billing events from Stripe and pull request events from GitHub are applied once, also when someone sends a captured copy again.
0.10.0 2026-10-04
Added
- A step can list its other states:
states: [empty, error, loading]. Walks run the step script once per state (it getsstate), a design drawscart/empty.htmlnext tocart/index.html, and each state gets its own screenshots and verdicts. The canvas has a State switcher next to the language, and review mode and the grid show the state you pick. A criterion withstates: [empty]is judged on the empty cart only. - A design whose token set has several modes, such as two brands, is rendered in each of them. Switch modes on the canvas like colour schemes;
tokens_modein the environment stays the default. Light and dark alone still followcolor_schemes. Variants of a stack step are captured in every state and mode too. kaloko capture --state,kaloko spec --stateand astateoption on the MCP step tools (get_step,get_step_spec,get_step_drift,get_step_assets,get_step_recording).- A design step can come in variants of one template, such as an e-mail for each reason support can pick. Make it a stack step and give each variant a folder,
design/<step>/<variant>/index.html.kaloko walkcaptures every variant in every viewport,kaloko syncsends them to the draft, and in a published version the step opens a list of its variants with their results. Each variant opens live.kaloko design lintreports a variant folder without its page, and both design exports include the variant folders. - Web fonts on live design steps. An organization admin lists the addresses designs may take fonts, stylesheets and images from (Google Fonts, Adobe Fonts, your CDN) in Settings → Security, and live steps load them instead of falling back to a system font. Scripts still load only from the design itself. List the addresses under
originsof the design environment andkaloko design lintsays which of them the organization does not allow yet. - Prototypes remember things between steps: a cart filled on one step shows on the next, in Live mode and in the presentation. The state stays in the viewer's browser tab, every step opened alone still shows its own sample data, and "Start over" in the presentation clears it. Design agents use
window.kaloko.state.
Changed
- Large runs are quicker on the canvas. On a run of 500 steps in seven languages on three devices, with the CPU slowed down to a phone's, a zoom step takes 33 ms instead of 133 ms, switching between desktop and mobile 650 ms instead of 910 ms, and the map is drawn once when it opens (it was drawn twice). Scrolling the step index no longer sorts every step on each frame.
- On kaloko.app a large run's canvas data and a scenario's history page come from a cache after the first visit (27 ms instead of 113 ms, 9 ms instead of 230 ms), and the changelog, the products page, the screen library and review mode ask the database far fewer times.
0.9.0 2026-10-04
Added
- After a release, people who read the product see a short "What's new" bar in the app that links its illustrated changelog. It comes once per release and person; open the changelog or close the bar and it stays gone.
- The canvas tells you when the connection drops or Kaloko cannot save. Comments, approvals and verdicts wait and go out once you are back online, or with "Try again"; nothing is posted twice and nothing is lost quietly.
kaloko doctor --fixinstalls a missing browser, creates missing folders and fills inorg:from your token. An expired token points you tokaloko login.- Long stack walks show roughly how much time is left.
Changed
- On a phone, review mode puts Approve and Return under your thumb at the bottom of the screen and says what you just decided and which step comes next.
- The first-steps list links straight to where each step is done: your newest run for comments and approvals, with the command to copy for the steps done in the terminal.
- Every error page has a way to write to support, with the address already in the e-mail, and a link to the status page. The app and website footers link the status page too.
- CLI errors say what happened and what to do next (sign in again, wait and retry, check the network) and end with support@sinfin.cz. Losing the connection no longer prints a stack trace.
Fixed
- A browser video encoder that stops responding no longer holds
kaloko walk --record: the recording ends with a note and the walk goes on. - Dark mode is easier to read: form fields have visible edges, the highlighted plan column on the pricing page is readable, and shortcut keys on the canvas's review buttons stand out.
0.8.0 2026-10-04
Added
- Steps and scenarios say what kind of page they are:
page: landing,work,list,settings,formordoc. The usability pack asks questions that fit: "one clear primary action" only on landing pages, and on lists, settings, forms and docs a question of their own. Withoutpage, public pages count as landing pages and app screens as work pages, so a signed-in overview is no longer asked for a single call to action. - A criterion can apply to some environments only:
environments: [production]on hreflang pairs, a live demo or the production sitemap. On a local or staging walk it shows as not applicable to that environment and does not make the step partial. kaloko validatewarns when a scenario walks several languages and a text check matches only one of them, for examplepattern: "Plans and payment"without the Czech wording.- Empty pages in the app say what to do next and give the command with a copy button: a product without a release or docs, its changelog and docs, an organization without runs, the runs and projects lists, the inbox and the screen library. People who only read a product see a plain sentence instead of a command.
- Kaloko's help covers the whole product, in English and Czech: two tutorials, how-to guides from writing a scenario to company sign-in, a reference of every CLI command, scenario key, check, pack, config key and MCP tool, and explanations of how verdicts are decided and how Kaloko maps to your applications.
- The website links Kaloko's own public changelog and help, so you can see both working before you set them up.

The home page · en · desktop - Company sign-in over SAML can require a signed response: the identity provider must sign the whole response, not only the assertion. New connections start with it on. Connections set up earlier keep working as before, and Settings → Security recommends turning it on.
Changed
- Error pages say why you got there and how to go on. A missing page offers the overview or another sign-in; a page that needs a role you do not have offers an e-mail to your organization's admins, already written; an expired link says to ask for a new one; an ended session signs you in and brings you back to the same address.
- Unsent text on the canvas survives. The verdict, return and issue notes keep their draft like comments do, and when your session expires while you write, the canvas says so, keeps the text and returns you to the same step after you sign in again.
Fixed
- A browser that starts but never answers no longer leaves
kaloko walk,videoor a check waiting: each launch has a time limit and one more try (KALOKO_LAUNCH_TIMEOUTin seconds, default 45). kaloko initproposes products from npm, Yarn and pnpm workspaces and frompackages/too, not only fromapps/; shared libraries without adev,startorservescript are left out.kaloko stability --pullnames the button people use on kaloko.app: Mark a changing region.- A table in published docs can hold a pipe inside a cell, written as
\|. - Hosted runs open only pages whose address leads to the public internet. An address that points into a private network is refused when you schedule the run and again before each run. Saved passwords and cookies are sent only to https addresses.
- Text and attribute checks in hosted runs finish quickly whatever the pattern. Patterns with backreferences or lookahead are reported as not evaluated there, with the reason;
kaloko walkstill checks them in full. - Signing in, sign-up, invitation links and the second step have their own limits on repeated attempts. Exports and new API tokens have a generous hourly or daily limit per person.
0.7.1 2026-10-04
Fixed
kaloko walkof an Android, iOS, desktop or Electron app ends with the verdicts, like a walk of a website; before, the criteria stayed unchecked until you rankaloko evaluate.
0.7.0 2026-10-04
Added
- Products in the app. The main menu has Products: every product you read with its newest version, its docs, its modules and projects, who reads it and links to its changelog and docs. A project page names the products it belongs to.
kaloko products syncputs the products ofkaloko.config.ymlon Kaloko before their first release, andkaloko products listshows which ones are there.
The Products page · en · desktop - A trust page at kaloko.app/trust (in Czech at /cs/duvera): where your data lives, how it is encrypted, who can get in, which companies process it and where our SOC 2 preparation stands. Kaloko is not SOC 2 certified yet, and the page says so. The security contact is also in
/.well-known/security.txt.
The trust page · en · desktop - Seat warnings. When 80 % of the paid seats are taken, and again when all are, organization admins see a banner on the home page, in Settings and on the billing page, and get one e-mail per threshold in each billing period.
GET /api/v1/orgs/<org>/usagereports the seats too. - Yearly Enterprise subscriptions can go above their paid seats. Kaloko keeps the highest number of seats in each quarter; after the quarter, Kaloko billing reviews the true-up and invoices the extra seats for the rest of the subscription year or waives them. Seats added in the last quarter are not charged for that year: a week before the renewal the subscription rises to them and the renewal invoice includes them. The billing page shows the current quarter and every earlier true-up.
- Company sign-in over SAML accepts encrypted assertions. Create the organization's key pair under Settings → Security → Company sign-in; its certificate is in the SP metadata, and a new key pair keeps the old one working until you remove it.
- Single logout with your identity provider: signing out at the provider signs people out of Kaloko, and signing out of Kaloko can sign them out at the provider too.
- Sign-in from the app tile of your identity provider, off until an admin turns it on, with a default page people land on.
Fixed
- The keyboard checks of
kaloko walkno longer report a trap inside a third-party widget such as an anti-bot check, and judge a link wrapped over two lines and a small radio inside its label as people see them. Tab lists with arrow keys count as one tab stop. - The canvas works better from the keyboard: every control shows a clear focus ring in light and dark mode, a "Skip to content" link jumps past the top bar, and while a step detail or another overlay is open, Tab stays in it instead of wandering through the hidden canvas. Screen readers get named side panels and dialogs.
- The canvas no longer jumps while it loads.
- A link from a comment notification opens the step with its comments in view, on a phone too.
- On a phone, a live page in the step detail fills the room above the sheet instead of a short strip, an open sheet leaves a strip of the preview that you can tap to lower it, and "Ctrl+Enter sends" shows only with a keyboard.
0.6.0 2026-10-03
Added
- A visual changelog.
kaloko changelog draftwrites the Unreleased entry ofCHANGELOG.mdfrom the pull requests since the last release and adds before and after pictures of the screens your accepted runs show differently.kaloko release <version>records the release with its pictures, and kaloko.app shows it as a page you can share with clients, support or anyone outside development. - Step references in Markdown:
always shows the newest accepted screen, and?version=2.4.0the screen of that release.kaloko:checkout/payment
- Products and modules in
kaloko.config.ymlfor repositories with several apps; scenarios say which product they show (product:,module:). Without them the project is the product. - Readers from your domain: everyone who signs in from a verified domain reads the changelogs, also of restricted projects (Business and up).
kaloko initasks whether to keep a visual changelog,kaloko doctorchecks that every product's version can be read, and agents getget_changelog,draft_changelog_entryandresolve_step_imageover MCP.- Docs that keep up with the app. Guides in your
docs/folder show steps instead of screenshots;kaloko docs publishputs them on kaloko.app with a version picker, language and screen switches and search, and every picture opens its step on the canvas.
A guide with its pictures · en · desktop - When a screen changes after its guide was written, the section says "the screen changed in 2.4 — check the text", and
kaloko docs checklists it with broken references, missing translations and changelog items without a picture, so CI can stop on them. - A guide plays as a walkthrough, one step at a time with its words as the caption, and readers tick off the steps they tried.
- Exports for your own docs site:
kaloko export --format md,docusaurus,vitepress,mkdocs,html,pdforjson, with the pictures as files. The docs and changelog pages offer the same downloads. - A "What's new" e-mail: readers ask for it on a product's changelog and get each new release with its pictures in their language (Business and up).
kaloko ci github --releaserecords every release that release-please, changesets or semantic-release publishes.- Issues in Jira and Linear from a returned step or a failing criterion, on the canvas, in review mode or with
kaloko issue create. The issue gets the screenshot, the criterion, the notes and a link back, and the comment on the step is resolved when the issue is done. Branches and pull request titles that name an issue link the run to it. - Slack and Teams channels per project, each with the events it wants and quiet hours. Restricted projects reach only channels chosen for them.
- A short list of first steps on the home page (share, comment, approve, invite, CI, release) until the team has done them.
- Hosted runs: Kaloko opens the pages of a read-only scenario every day or week and shares the run (
kaloko schedule add, Business).kaloko schedule export githubwrites a scheduled workflow for the full walk.
0.5.2 2026-10-03
Added
- The first version of the visual changelog:
kaloko changelog draft,kaloko release, step references and the changelog page on kaloko.app with a before and after slider. It is described in full under 0.6.0.
0.5.1 2026-10-03
Added
- Swipe and onion skin compare next to side by side and diff, in the step detail and in review mode.
- Regions to ignore can be drawn by hand on a capture. The canvas diff skips them, and
kaloko stability --pullwrites them into the scenario. - A grid (key G) shows one step in every language and screen size at once, also on a phone and in review mode.
- Comments can carry drawn boxes, arrows and lines, and attached images. Agents get the marked region in pixels.
- An accepted run has a signed acceptance record: a PDF with thumbnails and a printable page.
kaloko signoff --verifychecks the signature.
0.5.0 2026-10-03
Added
- Checks of the page itself: the address a step ends on, computed styles of an element and values the page exposes, so scenarios no longer need
data-qamarkers. - Runs in WebKit and Firefox besides Chromium, on device presets (phones, foldables, tablets, TV), in dark mode, with reduced motion, forced colours or as an installed web app. Every step is captured in each combination.
- App walks on several devices at once: Android emulators, iOS simulators, a real iPhone and Android WebViews, and Windows apps next to macOS ones.
- One picker on the canvas for language, browser and colour scheme that stays usable with many values.

The canvas of a run · en · desktop - Workflows written by
kaloko ciinstall the browser engines your scenarios walk.
Fixed
- Design drafts keep the browsers, schemes and device presets of their scope.
- An e-mail captured during a walk in several browsers counts once.
- Language and theme switchers work in the phone menu.
- Ignored regions, imported screenshots and cached evaluator answers carry over between capture variants.
0.4.11 2026-10-03
Added
- Recordings:
kaloko walk --recordfilms each step from the previous screen to its capture, or the whole flow with a chapter per step, and keeps a trace of actions, requests and console messages for every step. - The canvas plays a step's recording and shows its trace.

A recording on the canvas · en · desktop kaloko video exportturns the recordings into one walkthrough video with a title card per step.- Shared runs carry their recordings on the Business and Enterprise plans, kept for 30 days unless the organization chooses otherwise.
Fixed
- A recording too large to upload stays in the local preview instead of failing the share.
0.4.10 2026-10-03
Added
kaloko ci github|gitlabwrites a workflow that walks what each pull request changes on its preview deployment and comments on the pull request;kaloko ci preview-urlfinds the preview address in CI.kaloko importlays out screenshots, recordings and traces that an agent or Playwright already produced as a run.kaloko walk --affectedandkaloko affectedwalk only the steps that the changed files reach, and say why.kaloko walk --healproposes a new selector when the page lost the old one, and applies it once the step passes.- Several languages walk at the same time (
--concurrency). kaloko initrecognises the framework, the dev server, languages and main routes, and drafts a first scenario.- Uploads skip screenshots the service already has and resume after a broken connection.
0.4.9 2026-10-03
Added
- A vision evaluator that looks at the screenshot and says why, keyboard and screen reader checks, and regions that change on every run can be ignored.
- Dev mode in the step detail of a design: box model, tokens, redlines, states and assets.

Dev mode in the step detail · en · desktop kaloko spectells an agent what to build for an approved design step, andkaloko driftwhat its implementation does differently.
Fixed
- The canvas on phones: a smaller stack badge, readable stack lists, the step header above its tabs and no sideways scrolling.

A stack page on a phone · en · mobile - Page counts in Czech use the right plural.
0.4.8 2026-10-03
Added
- Review mode: the canvas walks a person through what still needs a decision, with keyboard shortcuts, and
kaloko reviewlists the same for agents. - Approvals carry over to steps whose screenshots did not change since the last accepted run.
- Every new organization gets a sample run with a guided first review.
- Two-step verification with passkeys or an authenticator app, and an organization rule that requires it.
- An audit log for admins, tokens limited to chosen projects, and company sign-in with SAML or OIDC, SCIM and an IP allowlist on Enterprise.
Fixed
- Plan badges on the pricing page no longer overflow on phones.
0.4.7 2026-10-03
Added
- Sign in with Google, Microsoft or GitHub where the service offers it.

The sign-in page · en · desktop kaloko loginapproves a token in the browser instead of copying it from Settings.- Invitations: people outside the organization join single projects as guests, and the Share dialog of a project shows who has access.
0.4.5 2026-10-03
Added
- A Designer role and API tokens with chosen scopes (read, comment, design, upload).
- Focus mode shows the preview alone, and the step detail has a layout for phones.
0.4.4 2026-10-02
Fixed
kaloko evaluate --rechecksays that it asks the semantic questions again too.- A lane on the canvas is as tall as its tallest card.
0.4.3 2026-10-02
Fixed
- Signed-in pages that Kaloko's own walk found wanting: labelled fields, real settings tabs, cards on phones and the whole inbox.

Settings · en · desktop - The canvas has a main landmark, readable badges and a visible compare button, and no longer shifts while loading.
- Pages load their fonts sooner and keep their layout when the font arrives.
0.4.2 2026-10-02
Added
- The Kaloko wordmark with a yellow marker and a new icon.

The home page · en · desktop - The Czech website lives under
/cs/, so each language has its own address. - Pages of a stack may carry their own purpose for the semantic evaluator.
- Live design revisions open on their own domain.
Fixed
kaloko doctorprints the config file it actually read.
0.4.1 2026-10-02
Added
links_okandhreflang_pairschecks for pages and stacks.
Fixed
- Unknown addresses on kaloko.app answer 404 instead of the sign-in form.
- Every language version of the website answers at its own address.
0.4.0 2026-10-02
Changed
- QAwalk is now Kaloko: the CLI is
kaloko(theqawalkcommand andqawalk.config.ymlkeep working) and the service lives at kaloko.app.
The landing page · en · desktop
Added
- Kaloko Design presents interactive HTML designs, lints pages that must work from disk, and exports a design in open formats.
0.3.0 2026-10-02
Changed
- The CLI is on npm as
kalokoinstead of@qawalk/cli. Theqawalkcommand,qawalk.config.yml, theQAWALK_*variables and~/.config/qawalk/.envkeep working, andkaloko initreplaces the old skill. - The app and the website share kaloko.app. Pages on qawalk.com redirect there; the API, MCP, webhooks and file links on the old addresses keep answering.
Added
- A "Group by issue" switch on the lists of runs and scenarios. The lists remember it, and "Latest per scenario" too.
0.2.22 2026-09-30
Fixed
- Large runs open faster on the canvas, and
kaloko evaluateneeds less memory for big stacks.
0.2.21 2026-09-30
Fixed
- A kept run cannot be trashed, and releasing it gives it at least a week. Kept design versions are not pruned.
- The "no project" filter on runs works, failed step details load again, and an unusual cookie no longer breaks the lists.
- Lists, the home page and scenario history load faster.
0.2.20 2026-09-30
Added
- The project you pick is remembered across the lists and the scenario browser on the canvas.
- Scenarios and runs of one issue, or of one pull request when there is no issue, are listed together.
0.2.19 2026-09-30
Changed
- Shortcuts and help open from a keyboard button in the top bar, and the list now includes ← → and Esc.
0.2.18 2026-09-29
Changed
- A shorter top bar on the canvas: Projects, Scenarios and Runs, the view switch, and the inbox at the right end.
0.2.17 2026-09-29
Changed
- Projects, scenarios and runs share one layout with the navigation on the left, so switching views does not jump. "All runs" is now "Runs".
- The run verdict has Accept and Return as the main buttons; note, baseline and public sit below them.
0.2.16 2026-09-29
Added
- A projects page: scenarios, runs and how the newest runs stand in each project.
- Console errors in the step detail are highlighted, wrapped and can be copied one by one or all at once.
- Times follow the reader's time zone, set in Settings → Profile or taken from the browser.
Changed
- Screen size switches say the name and width (Desktop 1440, Mobile 360), and a click anywhere on a card opens the step.
0.2.15 2026-09-29
Changed
- The step detail has three tabs: Criteria, Page and Technical. Criteria that need attention come first; passing ones take one line.
- When only phones are shown, the map shows larger phone screenshots.
0.2.14 2026-09-29
Changed
- Evidence of built-in checks reads as a sentence in Czech or English ("TTFB 950 ms, the limit is 800 ms"); the raw text stays under Technical detail.
0.2.13 2026-09-29
Added
- Every criterion of the built-in packs says why it matters and how to fix a failure, in Czech and English. The walk summary prints the fix for the agent.
0.2.12 2026-09-29
Changed
- The run summary sorts problems by what to do: what failed and why, what a person should decide, and screens that look off.
0.2.11 2026-09-29
Added
- Quick signals on every screen: the evaluator also says whether the page does what it is for, is in the expected language or looks broken. Signals never change a verdict.
kaloko walkevaluates while it walks and ends with a list of what failed or is unsure.
0.2.10 2026-09-29
Added
- Every criterion says how it was checked, in words: the check as a sentence, or the question the AI was asked with its score and the pass threshold.
- Hosted AI evaluation from the Team plan up, with a monthly allowance shown on the billing page and in
kaloko doctor. Your own evaluator key still works. - Design tokens in the current DTCG format, with aliases, modes and deprecated tokens;
kaloko tokens validate.
Fixed
- Manual decisions show the criterion on its own line, with reason and verdict below.
0.2.9 2026-09-29
Added
- Scenarios come first in the navigation, and Runs show the newest run per scenario unless you filter.
- Keep a run so it never expires, prune old runs (dry run first) and archive scenarios you no longer walk, in the app or with
kaloko runs,trash,restore,prune,keepandarchive.
0.2.8 2026-09-29
Changed
- A claimed sign-in domain lets people join only once it is verified.
- Comments on public runs name nobody, and upload tokens cannot delete runs.
- Below 1500 px the navigation and view options fold into one menu.
Fixed
- The canvas shows the map sooner and loads step details after it; large runs upload faster.
- When the service asks the CLI to slow down, it waits and tries again.
0.2.7 2026-09-29
Added
- Comments on steps, whole runs and whole flows: threads, pins on the screenshot, resolve and reopen. Mentions are mailed at once, the rest goes to the digest, and agents use
kaloko commentor MCP. - Kaloko Design: design drafts as live HTML steps on the canvas, versions, an inspector with token names, comments pinned to elements, edits on the canvas, branches linked to git, and a
designpack that checks an implementation against the approved design. - An HTML view of captured pages (experimental) that can be forked into a design draft.
Changed
- A calmer run view on smaller screens: one top bar, view options in a popover, help behind
?.
Fixed
- A long step path no longer widens its card over the next one.
- macOS desktop captures ask for the Screen Recording and Accessibility permissions they need.
0.2.6 2026-09-29
Added
- Mobile and desktop apps: Android, iOS Simulator, Electron and macOS windows, with UI tree checks, touch target sizes, crash detection and an
apppack.kaloko capture --imageimports screens from other tools. - A run index next to the map (key I): every step in a list with filters, search and CSV, and stacks as folders.
0.2.5 2026-09-29
Added
- The HTTP status of every capture, an
errorspack for error pages, and{random}in a path for an address that cannot exist.kaloko draftadds a not-found step. - The run card links the issue next to the pull request.
0.2.4 2026-09-29
Added
- Stacks: one step stands for many pages of one template, taken from a list, a sitemap, a crawl or a script. The canvas shows them as a stack with an index you can filter, search, sort and export as CSV.

A stack opened as a folder · en · desktop
0.2.3 2026-09-28
Added
acceptDialogs()for step scripts, flags on text checks,kaloko evaluate --recheckafter a scenario fix, andkaloko walk --ephemeralfor parallel walks.
Fixed
kaloko mailreads only messages received since the run started.- A walk captures fresh screens after
--steps, basic auth survives a redirect, and only one walk at a time uses a shared browser.
0.2.2 2026-09-28
Added
kaloko draft <url…>writes a first scenario and acceptance plan for public pages.- Check packs
a11y,perfandconsole. - Live presence on the canvas: who is looking, their cursors, and following someone's view.
- Large flows stay readable: lanes with headers, long lanes wrapped into rows, tidy edges and a zoomed-out view.
- Scenario history with pass rate and criterion stability, and
kaloko calibrateto tune evaluator thresholds. - Print-quality captures for documentation, with masks over personal data and numbered marks.
- The newest capture of every step at a stable address, a list of changes, signed webhooks and
kaloko export --scenariofor documentation (Business and up). - GitHub checks on pull requests that complete when the run is accepted or returned.
- A sign-in domain can be proved by signing in with Google Workspace or Microsoft 365, and Settings shows the DNS host with copyable record fields.
Fixed
- The overview follows reviewers' criterion verdicts.
- Public mailbox domains such as gmail.com cannot be claimed.
- A walk stops a session after three steps fail with the same error, instead of trying a wrong password again and again.
- An open menu or popover stays on the capture, signed links in the page lose their credentials, and text check evidence shows the actual match.
kaloko sharesays when the plan grants a shorter lifetime than requested.
0.2.1 2026-09-25
Added
- Protected environments: HTTP Basic, service-token headers and client certificates, sent only to the environment's own addresses.
- Accounts per scenario with password and TOTP, and
kaloko auth savefor a single sign-on a person does once. ${VAR}inbase_urlfor review apps, and secrets named in the config are removed from captures.- Any mailbox through a script adapter, and
kaloko mail --filefor saved messages.
0.2.0 2026-09-25
Added
- The CLI is on npm (as
@qawalk/cliuntil 0.3.0). - Plans with a billing page, a 14-day trial and a public pricing page.
- Named sessions: several people in one flow, each in their own browser, shown in swimlanes on the canvas.
- Run verdicts, a baseline run, required approvers and reviewer verdicts for manual criteria.
- Compare a run with the baseline or any earlier run: pixel differences, changed criteria and evidence, and
kaloko compare. - Replay walks the run one step at a time with a branch choice at decisions, and the canvas has a minimap.
- An inbox with notifications, a daily or weekly digest, and Slack.
kaloko share --prcomments on the pull request;kaloko exportand the canvas download a run as a ZIP.- An MCP server for agents.
- Check packs
seoandusability, plan coverage withkaloko validate --coverage, and flaky criteria. - A public demo run anyone can open without signing in.
- Projects per scenario, and a runs list filtered by project, scenario, verdict, author, environment and branch.
- Sign-in domains verified by a DNS record, token scopes and expiry, a list of your sessions, and a 7-day trash.
kaloko doctorchecks your setup and says what to fix.- Guides on the website for use cases and agents.
0.1.0 2026-09-23
Added
- The first version. The CLI walks scenarios in Chrome, captures every step, runs the checks and asks an AI evaluator what a check cannot answer. A read-only policy keeps production safe.
- The canvas shows the run as a map of screens with criteria, page metadata (Open Graph, hreflang, structured data, headings) and links to a single step. A click on a criterion highlights it on the screenshot.
- The agent skill for Claude Code and Codex, installed with
kaloko init --agent. - The service: organizations by e-mail domain, sign-in by link, roles and API tokens.
kaloko shareuploads a run, reviewers approve or comment on each step, andkaloko feedbackbrings their notes back to the agent. - The app and the website in Czech and English, with sign-up for new organizations.
Kaloko · latest · 2026-10-06