API keys work. If you ever pasted a key into blu, saved it, and found it gone when you came back — that was blu, not you. Keys were never reaching your Mac's keychain at all, in any version we have released. They do now. Please paste your keys in once more: there was never anything stored, so there is nothing to recover.
Your keys go into your Mac's own keychain — the encrypted store macOS already uses for your other passwords, locked with your login password — and nowhere else. No copy on disk, in any version of blu, including the ones we build for ourselves.
Kimi accepts your key now. blu was asking api.moonshot.cn, which is Moonshot's China service and refuses keys issued on the international one, however many times you paste it. It now asks api.moonshot.ai. Kimi K2.7 Code and K2.6 join K3 in the list.
Seven GLM models instead of one — GLM 5.2, 5.1, 5 Turbo, 5, 4.7, 4.7 FlashX and 4.6 — each with its published price, so a turn on any of them is costed from real rates rather than left blank.
Fixed: the model list offered things that cannot hold a conversation. Asking a provider what it serves returns everything the account can reach, including models that only make images, transcribe speech, or turn text into numbers for search. One provider alone listed over a hundred. They are gone from the picker — including on your own Mac, where an embedding model had been sitting in the list of local models all along.
Fixed: a Groq key could be saved and then never recognised.
If you are coming from 0.2.1, three things changed in 0.3.0 that you have not seen yet. blu's own agent can hand parts of a job to helper agents, each on a model you choose. Claude Code and Codex now keep their own controls, under their own names, instead of blu's. And "Allow always" remembers exactly what you agreed to rather than roughly — so you may be asked once more about something you had already allowed. The connectors panel was removed; it could report "connected" while the AI was never able to use it.
Helper agents. blu's own agent can now hand parts of a job to several helpers at once, and each helper runs on a model you choose — a cheap one to read and fetch, an expensive one to think. You watch them work, and every helper is priced at its own rate rather than the main model's. If the model you are chatting with is a small one running on your Mac, blu checks it has room to read the answers back before it spawns anything, and tells you plainly when it does not instead of quietly cutting them short. This is blu's own agent only; Claude Code and Codex cannot do it.
Chats keep working while you look at something else. Switch to another chat, start a new one, rename one, or open Settings — the reply keeps coming, and the sidebar shows you which chats are still working. If a chat stops to ask your permission, blu now tells you wherever you are and takes you to it. It will never ask you to approve something from a screen that cannot show you what you are approving.
Nothing is lost if blu closes in the middle of a reply. Your question is saved before the model is ever called, chats are named the moment they start instead of after the first answer, and blu asks before closing while work is running. A chat that was interrupted says so, rather than opening empty.
Claude Code and Codex now keep their own controls. If you use either one, the setting beside the model is theirs, not blu's — Claude Code's own permission modes and Codex's own sandbox settings, under their own names. blu passes your choice through and stops overriding it, so what you get is the tool you already know, in blu's window. blu also stopped putting its own rules in front of Claude Code: when Claude Code decides something needs your approval, that question now comes to you directly, and when it doesn't, blu no longer interrupts.
One second opinion, on a model you picked. blu could have another model check a risky action before you approved it, but the model doing the checking was chosen for you and there was no setting to change it. There is now one review, it names the model doing it, and you can change that model on the card itself or switch the whole thing off. It is also shown the entire thing it is judging — it used to be handed the first couple of hundred characters and asked for a verdict.
Skills from a project are held until you have read them. A repository you clone can carry written instructions for the AI, and one of those could quietly replace a skill of your own with the same name. blu now shows you the file first and asks. Anything already in your own skills folder was let through once, so nothing you installed yourself has changed.
"Allow always" now remembers exactly what you agreed to. It used to remember roughly — approving a read of one file could cover the .env sitting next to it, and approving one python command could cover every later one. It no longer does. You may be asked once more about things you had already allowed; that is the correction landing.
The connectors panel has been removed. It could add a server, store its password and report "connected" while the AI was never actually able to call any of its tools. Rather than leave a switch with nothing behind it, the panel is gone until the part behind it works.
Fixed: opening Settings ended every chat that was working.
Fixed: several numbers were wrong. Turns priced against the wrong rate, five Claude models with no price at all, a conversation total that left out real money, and writing speed measured against the time a model spent waiting for a command rather than the time it spent writing.
Fixed: the model list. It offered models blu had no key for and models the runner could not reach, and it reported a key as rejected when the key was fine. Saving a key now takes effect immediately, and the list names the company each model comes from, newest first.
Fixed: menus that opened off the bottom of the screen, changes shown as two walls of text instead of a diff, an approval that asked you to accept a plan you could not read, and a chat saved the instant the window opened whether you typed anything or not. blu also says which version it is now, under Settings.
Also fixed, all of it security: text blu reads on your behalf — from a file, a web page or a tool — is now marked so the AI treats it as information rather than as instructions from you. A file could be swapped for a shortcut in the instant between blu checking it and opening it. A link could lead the agent out of the folder you had locked, or to an address only your own Mac can reach. On the OpenCode runner, blu was answering yes on your behalf to every edit and command — it now asks.
Plainer language throughout. Messages said things like "Harness error" and "exited exit status: 1". They now say what happened and what to do about it.
A test of the update path itself. If you are reading this inside blu, the thing it was testing worked.
Fixed: an update could fail if it was installed in the first minute or two after a new version went up. blu would offer the new version, download the previous one from a cache, and refuse it because the two did not match. Each release now has its own address, so there is nothing stale to serve.
Nothing else has changed from 0.2.0.
The first public release. blu runs every AI model — the free ones on your Mac and the paid ones you rent — from one window, and lets you change your mind mid-conversation.
Four ways to work, and you can switch between them in the middle of a chat: blu's own agent, the Claude Code CLI, Codex on a ChatGPT plan, or OpenCode. The conversation goes with you — whatever you switch to can see what was said before it arrived.
Every turn says what it cost, and the conversation's totals sit at the top of the chat. Models running on your Mac say "free", because that zero is real. Work covered by a subscription is counted separately from money that actually left an account, and the two are never added together. Where blu does not know a price, it says so instead of showing you a zero.
Fixed: blu can now find the programs installed on your Mac. On earlier builds a downloaded copy could not run node, pnpm or Homebrew tools, and the Claude Code runner would not start at all.
Fixed: changing model or runner used to lose the conversation on every runner except blu's own.
Fixed: several numbers on screen were wrong — a free turn shown as $0.00, tokens counted as words, and writing speed measured against time the model spent waiting for a command rather than time it spent writing.
This release is chat and settings. Jobs and compare are not in it — they are being rebuilt properly and will arrive as downloads.
stuck on anything? write to [email protected] and a person will answer.