Apps can now declare private, named storage buckets that are provisioned and bound automatically on deploy. Prefix-based lifecycle rules can expire temporary files or move older objects to lower-cost storage, and each bucket appears in Data with its environment and retention policy.
Keep uploads, exports and caches private behind your own App routes
Give different prefixes their own retention or archival rules
Confirm destructive bucket removals explicitly before deploy
App code can now ask focused choice, score and yes-or-no questions and receive typed answers with probabilities. This gives routing, classification, moderation and verification a faster, lower-cost path than prompting a general chat model.
Use the built-in decisions client from routes, real-time rooms or agents
Ask several independent questions about the same state in one request
Use the same team balance and spending controls as other model calls
The desktop App can now install and sign in to Codex in place, checks provider, model and reasoning support before sending, and reads model choices from your own account. A cleaner chat workspace makes settings, activity and operations easier to follow.
See each provider CLI's version and sign-in state before starting work
Adjust chat settings from the composer and open common actions from the Operations menu
Follow grouped activity, timestamps and notification links more reliably
A new public pricing catalog shows current rates for AI models, tools, voice, search, browsers and App infrastructure. Metered usage now pairs readable service names with filters that make a specific charge easier to find and understand.
Search rates by service, provider and category before you use them
Filter usage by date, App, environment, spending type or service name
See clearer spending categories while retaining the underlying accounting details
Connector checks now validate provider credentials when the provider supports it and distinguish an unavailable test from a successful connection. Expired GitHub access shows what happened and provides a direct path to replace the token.
Get a concrete authentication result instead of a simulated success
Replace an expired GitHub token without recreating the connector
See when a provider cannot be tested automatically
Team chats now collapse into one row per teammate and open into a card that brings their current work, recent chats, deployments and source history together. Each shared chat also shows the client and model settings driving it.
See live runs, presence, chat count and recent activity at a glance
Open a teammate's latest chats or mention them in the App channel
Tell whether a chat runs in the desktop App or on a managed computer, with its model, effort, CLI versions and context pressure
A notification bell in the web console and desktop App now collects mentions, channel and Talk messages, and completed runs without making you open every App. Read and mute state stays in sync across devices.
Mentions come first, with other unread threads grouped by team and App
Open the exact conversation from an inbox row or system notification
Browser and desktop notifications share the same read state and mute controls
A new Storage section in Settings finds rebuildable App artifacts and old job logs, shows how much space they use and removes them with one confirmed action.
Active and recently used workspaces are left alone
Only files that can be safely rebuilt are eligible for cleanup
Conversations completed by agents running on your own computers now appear alongside cloud-model conversations in the console, desktop App and CLI after the App is redeployed.
New edge-agent sessions appear after the App's next deploy
Earlier edge-only conversations are not backfilled
Deleting an App now takes its sites and endpoints offline within seconds while preserving the existing 30-day recovery window. Final cleanup retries safely until all resources due for removal have been handled.
The same behavior applies whether deletion starts in the console, CLI or an agent workflow
Cached responses can no longer keep a deleted App available
Temporary cleanup failures resume automatically instead of leaving resources behind
Claude-powered managed-computer chats can now compact their context before it fills, reducing repeated token use during long-running work. A corrected context meter makes the remaining capacity easier to judge.
Use the Compact button or /compact to condense a continuing session
Use /usage or /cost to check consumption, /clear to start fresh and /help to see commands
Command suggestions appear as soon as you type / in the composer
Free and legacy teams can now move to Pro or Business directly from Usage & plan. Limits are enforced consistently at the point of action, with clear messages when a plan cap is reached.
Choose a paid tier without waiting for support
Plan limits now apply consistently to Apps, seats, environments, domains and connected computers
Existing legacy teams keep their current allowances until they choose a plan
Connect an Atlassian site from the Connectors page and let agents work with Jira issues using the access level you choose. The integration covers the full issue lifecycle, from discovery and creation through assignment and transitions.
Choose a read-only or read-write permission preset when connecting a site
Search, inspect, create, update, assign, transition or delete issues
Read and write comments, users, projects, fields, priorities and statuses
Every agent and computer chat now has a human-only Talk thread, plus an App-wide channel for team coordination. The conversation stays next to the work without becoming part of the agent's context.
Share files and references to chats, deployments and traces
Mention teammates and receive notifications even when the App or Chat tab is not open
Mute general activity while keeping direct mentions visible
Apps can now connect securely to services that require mutual TLS, including Apple Pay merchant validation, banking APIs and payment providers. Spikefrost manages the certificate binding while your App makes a normal request through it.
Register a certificate once without committing certificate material to your App
Choose which environments receive each certificate binding
Rotate a certificate under the same name and check its expiry and binding status
App decision logs now keep a compact index with each decision in its own file, so builders and agents can load only the rationale they need. Existing single-file logs migrate automatically without losing their history.
New decisions use collision-resistant names for safer concurrent work
Local changes to decision files are protected during checkout and pull
New Apps and older checkouts receive the same decision-log structure
Connect your Grok or Kimi subscription and use it for App chats or agents running on a Spikefrost-managed computer. Provider, model and reasoning controls stay with each conversation.
Choose Claude, Codex, Grok or Kimi when creating a managed computer
Use the same subscriptions from the web console and desktop app
Open Compute directly from the main navigation and see which deployed agents use each machine
Browse public assets and private environment files from the web console or desktop app, with folders, previews, uploads, downloads, moves and deliberate deletion. New CLI and agent tools bring the same asset library into automated workflows.
Switch between list and gallery views, filter loaded files and preview images or video
Upload folders by drag and drop, with explicit choices when a file already exists
List, inspect, copy, remove or sync assets from the CLI; sync transfers only changed files
See storage totals and estimated monthly cost alongside the files
Apps now open directly into Chat and remember each provider's last-used model settings. New trace and deployment views make it easier to follow agent work and shipping progress without switching tools.
Explore a conversation turn by turn or render every turn in one sequence diagram
Open a running deployment to follow each resource live and see failure reasons
Pair a new edge computer directly from the Machines page
Run App chats and agents on a Spikefrost-managed computer using your own ChatGPT/Codex or Claude subscription. There is nothing to install, and the computer sleeps when it is idle.
CLI sessions resume across turns, so follow-up instructions keep their context
The App checkout refreshes for every turn and declared repositories mount into the workspace
Tool calls stream back live while the computer works
Connect, replace or disconnect Claude and Codex accounts from AI Subscriptions
Create, animate, edit, extend and compose Seedance 2.5 videos with synchronized dialogue, sound and music. Seedream 5.0 Pro creates trusted casting images, while the asset library keeps characters, voices and references reusable across productions.
Generate up to 30 seconds per segment at 480p or 720p
Group persistent face, body, angle and voice assets into one character kit
The App view now brings source history, deployments and deployed agents into the web console, alongside schedules, data, logs and security. Environment-aware actions open the right site or mobile preview without leaving the App.
Read Spike VCS history with changed files and inline diffs
Inspect deployment attempts and their status per environment
Switch environments once in the header, then open that environment's site
New Apps start with semantic design tokens and guidance matched to the surface being built. Builds now report advisory design warnings without blocking deployment, making common contrast, typography and generated-design problems visible early.
Palette, typography, shadows and state colors live in one token system
Design guidance distinguishes marketing, operational, reading and showcase surfaces
Advisory checks flag real issues while leaving judgment with the builder
Team App chats can be shared live with teammates and read from a paired phone even when the owner's Mac is offline. Agent traces are grouped by conversation and can render every turn, child agent and tool call as one sequence diagram.
Team chats show live activity and resync automatically after reconnecting
Private chats remain visible only to the owner's devices
A participation gate protects the owner's machine and provider quota
Show all turns turns a full conversation into one trace timeline
Declare an inbound receiver in app/email.json and every accepted email thread becomes its own agent conversation. Replies retain native threading, and a custom domain can provide one branded address for both sending and receiving.
Sender policies reject unknown or denied senders at SMTP time
Attachments land in the App's asset storage instead of the model context
Each thread keeps its own durable memory
Custom mailboxes are bound to one environment so dev and production stay isolated
Agents can opt into web search, page reading, screenshots, PDFs and interactive browser sessions that navigate, click, type and wait. Browser work is budget-gated and metered per action.
Search finds relevant pages; page reading verifies the source before an answer
Interactive sessions preserve browser state across several actions
Screenshots and PDFs save into the App's own asset storage
Typed limits and recovery errors keep failed sessions from hanging a turn
Voice agents are now ordinary SpikeAgent classes powered by OpenAI Realtime, with full-duplex speech, barge-in, server-side tools and durable transcripts. This replaces the former ElevenLabs voice-chat stack and retires custom team voices.
Audio travels directly between the browser or mobile client and OpenAI
Tool calls execute inside the App with the caller's verified identity
Dropped calls and return visits resume from the agent's durable conversation memory
Voice agents can consult text agents for deeper work without slowing the live interface
Routine scheduling no longer runs on AWS EventBridge. Schedules are now read and armed entirely on Cloudflare, which removes a cross-cloud hop from every scheduled run and means nothing can re-arm a stale AWS schedule behind your back.
Routine reads come from Cloudflare rather than DynamoDB
EventBridge scheduling is decommissioned — no path remains for an old schedule to fire
Agent wakes were already in-sandbox; this aligns Hono routines with them
A real machine you own can now be an agent. Declare it on an agent class and the machine becomes the thing that does the work, running your own Claude or Codex seat, with the result arriving back in the same conversation.
The app repository and any declared repositories are checked out fresh before every run
The conversation is the session, so follow-up instructions resume the same CLI session
One job per computer and app at a time, with a typed error rather than a silent queue
Inspect and operate connected machines with sf ops
The largest change in this period. An agent is a TypeScript class in your app under app/agents/**, compiled into your own Worker on deploy. It holds your app's bindings, so it reads your data in-process rather than through a platform API — and deploying it is what registers it.
Tools are thin adapters over your own domain functions, so business rules bind every caller
sf agents lint validates every class locally — routes, bindings, model ids, evals — before a remote build
Traces stitch child agent runs inline in the parent diagram, and a delegating tree bills as one turn
The chassis is vendored into the build, so no npm dependency is required
A Usage tab showing infrastructure usage and cost per app, so spend is attributable to the thing that caused it rather than arriving as one line at the end of the month.
The full store journey is now something an agent can walk you through: enrolling, creating the API keys, and submitting. Testing on a real device stays a single QR scan with no developer account needed.
Expo preview works end to end — scan once, reopen after every deploy
Click-by-click guides for Apple Developer Program and Google Play Console setup
Tabs-first native scaffold so a new mobile app feels native rather than webby
Declare a sender in app/email.json and your Worker gets a binding plus an assigned From address. No API keys, no SMTP configuration — the binding is the whole integration.
Each environment gets its own address automatically
From is pinned to the assigned address, so a misconfigured sender fails loudly instead of silently spoofing
Declare a queue in app/queues.json and deploy provisions it along with a dead-letter twin. Produce from app code, consume with a handler or an agent, with retries and backoff you configure.
At-least-once delivery with exponential backoff, then the DLQ
Inspect and replay failures with sf queues dlq peek / redrive
A desktop app for building by conversation. Your teams and apps in a rail, a chat per app, and the project on disk — with no terminal required, though everything it does is still available from the CLI.
Per-app design chats with your own Claude Code or Codex seat
Switch provider and model per chat, and steer mid-run by typing while it works
Live streaming of agent turns, with mermaid diagrams and rich blocks rendered in chat
Team management, per-app usage, Finder / Terminal / Editor / Data / Logs shortcuts
Auto-update for both the app and the bundled sf CLI
Ask for a mobile app and a real native companion is built alongside your web app. Scan the QR code once with Expo Go and reopen it after every deploy — no cables, no store account.
Opt a route in with one line and it is served from the edge without running your Worker at all. Every deploy invalidates the app's cache automatically, so a release can never leave stale HTML behind.
Analytics and consent cookies no longer defeat caching — those requests are treated as anonymous
Declare your own session cookies inert to cache logged-in traffic safely
stale-while-revalidate serves instantly while refreshing behind it
x-sf-cache and x-sf-version headers make the behaviour observable
Reads can be served by regional replicas, multiplying read throughput. The scaffold wires a per-request session so every visitor still reads their own writes.
Query c.get('db') for ~95% of routes and read-your-writes is automatic
Use withSession('first-primary') where cross-user freshness is mandatory
Design a voice, audition three takes, and keep the one you want as a team voice for voice-enabled chat. This ElevenLabs-based capability was retired on 4 August when voice agents moved to OpenAI Realtime.
Sonnet 5 becomes the default for new work, with Sonnet 4.6 and Opus 4.7 retired. GLM 5.2 and Kimi 2.7 Code join the registry, including a high-speed Kimi variant.
GLM 5.2 with a 1M context window and 128K max output
Run sf models for the current list — the catalog moves
A Workers KV namespace is now bound to every app as env.KV, with no setup. Use it for caching, sessions, feature flags and counters — and as the fastest mitigation you have during an incident, since a flag flips in seconds without a deploy.
Author a write as an operation route and every caller — an agent, an HTTP route, a scheduled job — goes through the same invariant. The build fails if an operation route skips caller verification, because an unauthenticated write path is one anyone can invoke.
Verified conversation identity is carried into the operation token
Operations can be granted to specific agents as tools
IP, country and ASN rules, a bot threshold, blocked paths and maintenance mode — enforced at the edge before your code runs, so filtered traffic costs you nothing.
A filter language for request logs with click-to-filter, so finding the failing request stops being a scroll. Available in the console and from sf logs.
Filter by status, path, error state and time window
Opt in per app to capture request and response bodies for 14 days
A thread rooted on the bot's own message continues naturally — no need to mention it again on every reply. In channels with several bots, messages are attributed so each one knows what is meant for it.
Deep-copy an existing app, optionally into another team — useful for spinning a variant off something that already works. A clone is a separate app from then on; for a staging copy of the same app, use an environment instead.
One app can start work in another, governed by an explicit invocation policy that says who may call in. Templates became team-wide and apps can be grouped.
Per-app policy: self, controller, or an allowlist of apps
Cross-app work appears in the job tree like any other
Building on Spikefrost? The documentation covers everything here in depth.
We value your privacy
We use cookies to enhance your development experience and keep your data secure. Essential cookies are always active. You can choose to enable analytics and marketing cookies.
Manage Cookie Preferences
Essential
Required for authentication, security, and core functionality.
Analytics
Help us understand how you use Spikefrost so we can improve it.
Marketing
Used for targeted advertising and campaign measurement.
Ask SpikefrostAsk about Spikefrost
Answers come from the documentation. Frost can be wrong — check the linked page.