diff --git a/README.md b/README.md
index bfc2508..68ae58e 100644
--- a/README.md
+++ b/README.md
@@ -101,6 +101,18 @@ Clients connect in the simplest shape they support:
and manages its own workers.
- **Portable Markdown/JSON handoff** when live remote MCP is unavailable.
+The dashboard provides native setup commands for OpenCode, Gemini CLI, and
+Copilot CLI, a portable plugin for OpenClaw, and a ready-to-copy Eve connection.
+Hermes can connect through its native remote MCP and OAuth support. Choose your
+tool, approve its access, and keep working in the environment you already use.
+
+Compatibility is reviewed against dated upstream releases. See the
+[portable agent guide](docs/PORTABLE-AGENT-COMPATIBILITY.md),
+[Eve setup](docs/EVE-COMPATIBILITY.md), and
+[Hermes guide](docs/HERMES-HANDS-OFF.md) for verified setup details and testing
+limits. Existing connections keep working; a naming update does not require
+reconnecting your Project.
+
No provider becomes a required dependency. See the
[compatibility guide](docs/MCP-COMPATIBILITY.md) for the current protocol and
dated client evidence.
diff --git a/apps/web/src/App.tsx b/apps/web/src/App.tsx
index 75614d9..6d61dcf 100644
--- a/apps/web/src/App.tsx
+++ b/apps/web/src/App.tsx
@@ -1245,11 +1245,11 @@ function AgentConnectionsPanel({
<>
- Eve 0.29
+ Eve
Add a user-scoped connection
- agent/connections/owd.ts
+ agent/connections/mdevolved.ts
{
it("creates Eve's user-scoped connection module", () => {
const source = createEveConnectionSource(MCP_URL);
- expect(source).toContain(`const owdMcpUrl = "${MCP_URL}";`);
- expect(source).toContain('connector: "oauth/owd"');
+ expect(source).toContain('connector: "oauth/mdevolved"');
+ expect(source).toContain(`const mdevolvedMcpUrl = "${MCP_URL}";`);
+ expect(source).toContain("resources: [mdevolvedMcpUrl]");
+ expect(source).not.toContain('connector: "oauth/owd"');
expect(source).toContain('principalType: "user"');
expect(source).toContain('"vault.read"');
- expect(source).toContain("resources: [owdMcpUrl]");
expect(source).toContain("autoProvision: true");
expect(source).not.toContain('principalType: "app"');
expect(source).not.toContain("Bearer ");
diff --git a/apps/worker/test/agent-access.test.ts b/apps/worker/test/agent-access.test.ts
index ab94f54..d356e98 100644
--- a/apps/worker/test/agent-access.test.ts
+++ b/apps/worker/test/agent-access.test.ts
@@ -1908,9 +1908,9 @@ describe("scoped universal agent access", () => {
format: "owd-client-profile-v1",
id: "eve",
source: {
- commit: "d004e6d47e9d25d0380c24b5a47b65a18f8b2784",
- connectVersion: "2.0.4",
- eveVersion: "0.63.0",
+ commit: "7bcc0d16e3f41d44fadfd06b5bac3515a82d441d",
+ connectVersion: "2.3.2",
+ eveVersion: "0.65.0",
repository: "https://github.com/vercel/eve",
},
});
diff --git a/compatibility/upstreams.json b/compatibility/upstreams.json
index 1590b15..d19451d 100644
--- a/compatibility/upstreams.json
+++ b/compatibility/upstreams.json
@@ -52,16 +52,16 @@
"source": {
"kind": "github-release",
"repository": "vercel/eve",
- "releaseTag": "eve@0.63.0",
- "commit": "d004e6d47e9d25d0380c24b5a47b65a18f8b2784",
- "reviewedAt": "2026-09-21"
+ "releaseTag": "eve@0.65.0",
+ "commit": "7bcc0d16e3f41d44fadfd06b5bac3515a82d441d",
+ "reviewedAt": "2026-09-24"
},
"dependencies": [
{
"kind": "npm",
"package": "@vercel/connect",
- "version": "2.0.4",
- "integrity": "sha512-VD0dY28Nr8uTa5yOWeHQwgn6e3Oj0gbDvkJ3EowPRSJriarPPX5I2oG6IpEg3sFz6t16AY5Us5eHRb0UMkdfVQ=="
+ "version": "2.3.2",
+ "integrity": "sha512-qNRdUI6h2zbTruYU92leapFvBRjwF70gewwuj0rBPBHyu2Bnfzm//k4Sc8kA8e/zQfwKbdpYVk8oWe3fNqImzA=="
}
],
"criticalPaths": [
@@ -80,18 +80,18 @@
{
"path": "packages/client-packs/src/eve.ts",
"requiredMarkers": [
- "commit: \"d004e6d47e9d25d0380c24b5a47b65a18f8b2784\"",
- "connectVersion: \"2.0.4\"",
- "eveVersion: \"0.63.0\"",
- "reviewedAt: \"2026-09-21\""
+ "commit: \"7bcc0d16e3f41d44fadfd06b5bac3515a82d441d\"",
+ "connectVersion: \"2.3.2\"",
+ "eveVersion: \"0.65.0\"",
+ "reviewedAt: \"2026-09-24\""
]
},
{
"path": "docs/EVE-COMPATIBILITY.md",
"requiredMarkers": [
- "`0.63.0`",
- "`d004e6d47e9d25d0380c24b5a47b65a18f8b2784`",
- "`2.0.4`"
+ "`0.65.0`",
+ "`7bcc0d16e3f41d44fadfd06b5bac3515a82d441d`",
+ "`2.3.2`"
]
}
]
@@ -153,9 +153,9 @@
"source": {
"kind": "github-release",
"repository": "NousResearch/hermes-agent",
- "releaseTag": "v2026.9.21",
- "commit": "d337b736aa1e8ebecfab043842d13e4a2d2f48a3",
- "reviewedAt": "2026-09-21"
+ "releaseTag": "v2026.9.24",
+ "commit": "f97608f178d1ffeca59860195ab7da295f7c8e5f",
+ "reviewedAt": "2026-09-24"
},
"criticalPaths": [
"pyproject.toml",
@@ -174,9 +174,9 @@
{
"path": "docs/HERMES-HANDS-OFF.md",
"requiredMarkers": [
- "`0.21.4`",
- "`d337b736aa1e8ebecfab043842d13e4a2d2f48a3`",
- "Reviewed `2026-09-21`"
+ "`0.21.5`",
+ "`f97608f178d1ffeca59860195ab7da295f7c8e5f`",
+ "Reviewed `2026-09-24`"
]
}
]
diff --git a/docs/EVE-COMPATIBILITY.md b/docs/EVE-COMPATIBILITY.md
index af019bc..1305d80 100644
--- a/docs/EVE-COMPATIBILITY.md
+++ b/docs/EVE-COMPATIBILITY.md
@@ -10,24 +10,30 @@ The reviewed profile is pinned to:
| Contract | Reviewed value |
| ----------------- | ------------------------------------------ |
-| Eve | `0.63.0` |
-| Eve source commit | `d004e6d47e9d25d0380c24b5a47b65a18f8b2784` |
-| `@vercel/connect` | `2.0.4` |
+| Eve | `0.65.0` |
+| Eve source commit | `7bcc0d16e3f41d44fadfd06b5bac3515a82d441d` |
+| `@vercel/connect` | `2.3.2` |
| License | Apache-2.0 |
-| Reviewed | September 21, 2026 |
+| Reviewed | September 24, 2026 |
This is a source-verified compatibility profile. It does not yet claim that a
live Eve deployment has completed MDevolved's independent two-agent acceptance run.
Unknown future Eve connection or identity changes fall back to MDevolved's universal
MCP setup until the profile is reviewed again.
-Eve 0.63.0 retains authored `agent/connections/*.ts` modules,
+Eve 0.65.0 retains authored `agent/connections/*.ts` modules,
`defineMcpClientConnection`, and the user-scoped `@vercel/connect/eve`
-`connect()` helper used by MDevolved. Version `2.0.4` is the newest reviewed
-helper old enough to satisfy the repository's minimum-release-age policy;
-newer releases remain monitor-visible drift. The Eve update changes background
-tool and runtime behavior but leaves this user-scoped remote connection shape
-intact; the exact generated module type-checks against both current packages.
+`connect()` helper used by MDevolved. The connection definitions, runtime, and
+connection documentation have identical Git blob identities between the
+previous `0.63.0` pin and this release. Connect `2.3.2` retains explicit user
+principals, scopes/resources, and opt-in connector provisioning; its token-cache
+eviction does not replace MDevolved's authoritative grant checks. The exact
+generated module type-checks against both pinned packages.
+
+The newer Eve `0.66.2` release was observed during this review but is not the
+installed compatibility target; the monitor deliberately continues to report
+that drift. MDevolved supports `server/discover`, so the connection keeps Eve's
+default protocol discovery rather than forcing the legacy handshake.
Until MDevolved is accepted
into Eve's registry, use the dashboard-generated module rather than claiming
an `eve add` package that does not exist.
@@ -53,7 +59,11 @@ and qualifies them with its connection name.
## Install the connection
-Create `agent/connections/owd.ts`:
+Create `agent/connections/mdevolved.ts`:
+
+Keep an existing `owd.ts` connection working as-is; do not add a duplicate,
+rename its connector, or repeat authorization just for the naming update.
+The canonical name below is for new connections.
```ts
import { connect } from "@vercel/connect/eve";
diff --git a/docs/HERMES-HANDS-OFF.md b/docs/HERMES-HANDS-OFF.md
index 238f9fa..e4f2c7d 100644
--- a/docs/HERMES-HANDS-OFF.md
+++ b/docs/HERMES-HANDS-OFF.md
@@ -4,8 +4,8 @@
**Status:** inert, script-free guidance over the generic MDevolved MCP services
-**Source-verified profile:** Hermes Agent `0.21.4`, tag `v2026.9.21`, commit
-`d337b736aa1e8ebecfab043842d13e4a2d2f48a3`. Reviewed `2026-09-21`.
+**Source-verified profile:** Hermes Agent `0.21.5`, tag `v2026.9.24`, commit
+`f97608f178d1ffeca59860195ab7da295f7c8e5f`. Reviewed `2026-09-24`.
Hermes now has native remote MCP OAuth support. Point that client at
`https://YOUR-MDEVOLVED-HOST/mcp`; do not add a transport bridge or place OAuth
@@ -17,6 +17,12 @@ OAuth with an explicit headless login path, and fenced delegated-child identity.
Hermes memory and skill state remain runtime-owned and are never ingested as
MDevolved authority or raw session history.
+The September 24 tagged-source review found no changes to `tools/mcp_tool.py`,
+`tools/mcp_oauth.py`, or `tools/mcp_oauth_manager.py` from the previous pin.
+The CLI now shares its MCP enabled-state helper; the remote URL/OAuth setup
+remains unchanged. Device login is an explicit Hermes action, not authority
+that this adapter can create.
+
The same guidance is discoverable as the MCP resource
`mdevolved://adapters/hermes/hands-off/v1`.
diff --git a/docs/PORTABLE-AGENT-COMPATIBILITY.md b/docs/PORTABLE-AGENT-COMPATIBILITY.md
index 32b3044..fc9866c 100644
--- a/docs/PORTABLE-AGENT-COMPATIBILITY.md
+++ b/docs/PORTABLE-AGENT-COMPATIBILITY.md
@@ -1,25 +1,32 @@
# Portable agent compatibility
-This receipt records the exact upstream surfaces reviewed for PAC1 on
-2026-09-21. These are compatibility claims, not vendor endorsements or claims
+This receipt records the exact upstream surfaces reviewed for PAC1, refreshed on
+2026-09-24. These are compatibility claims, not vendor endorsements or claims
that MDevolved controls a client's runtime.
| Client or standard | Reviewed release | Source contract used by MDevolved |
| ------------------ | --------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Agent Plugins | `1.0.0` | Root `plugin.json`, optional root `mcp.json`, immediate-child `skills/*/SKILL.md`, and `streamable-http`; OAuth remains client-managed. |
| OpenCode | `v1.18.32` at `545f51d26cc39a907d2867492d498d9607ea5fa4` | `opencode mcp add mdevolved --url ` creates a remote server; OpenCode owns its OAuth flow and credentials. |
-| OpenClaw | `v2026.9.5` at `ec9c1a13db8938e5a3eaa51fca2e981cde2395a9` | Local archives with root Agent Plugins metadata are installed through `openclaw plugins install`; supported skill and HTTP MCP components are mapped into OpenClaw. |
-| Gemini CLI | `v0.60.0` at `733edcb597ce690ac2e2fe3b3b3690b60a4c8f27` | `gemini mcp add mdevolved --transport http` adds the remote MCP server. |
-| GitHub Copilot CLI | `v1.0.87` at `d418dbf1061152afa17500cbc69478f8dce153d8` | `copilot mcp add --transport http mdevolved ` adds the remote MCP server; Copilot owns its interactive authorization state. |
+| OpenClaw | `v2026.9.6` at `eb377ac59e6c9fd6c7705028034812becf00271b` | Local archives with root Agent Plugins metadata are installed through `openclaw plugins install`; supported skill and HTTP MCP components are mapped into OpenClaw. |
+| Gemini CLI | `v0.61.0` at `bb523741c7429a44d03e964bc124c7c92df59d5f` | `gemini mcp add mdevolved --transport http` adds the remote MCP server. |
+| GitHub Copilot CLI | `v1.0.88` at `c13b3dcae4f1e176c5a074c0d063a6e9f258081f` | `copilot mcp add --transport http mdevolved ` adds the remote MCP server; Copilot owns its interactive authorization state. |
Primary sources:
- [Agent Plugins 1.0 specification](https://agent-plugins.org/specification)
- [OpenCode MCP command source](https://github.com/anomalyco/opencode/blob/v1.18.32/packages/opencode/src/cli/cmd/mcp.ts)
-- [OpenClaw bundle contract](https://github.com/openclaw/openclaw/blob/v2026.9.5/docs/plugins/bundles.md)
-- [Gemini CLI command reference](https://github.com/google-gemini/gemini-cli/blob/v0.60.0/docs/cli/cli-reference.md)
+- [OpenClaw bundle contract](https://github.com/openclaw/openclaw/blob/v2026.9.6/docs/plugins/bundles.md)
+- [Gemini CLI command reference](https://github.com/google-gemini/gemini-cli/blob/v0.61.0/docs/cli/cli-reference.md)
- [GitHub Copilot CLI command reference](https://docs.github.com/en/copilot/reference/copilot-cli-reference/cli-command-reference)
+The refreshed Gemini MCP-add implementation and OpenClaw bundle documentation
+are unchanged from the previous pins. OpenCode's reviewed release is still
+current. [Copilot 1.0.88 release notes](https://github.com/github/copilot-cli/releases/tag/v1.0.88)
+describe MCP reconnect, OAuth, and tool-cache fixes; its proprietary
+implementation was not inspected. No generated setup command or archive layout
+needed changing. These checks do not certify a live install or OAuth session.
+
## Boundary
The dashboard emits only a public deployment URL. The generated Agent Plugins
diff --git a/docs/RELEASE-COMPATIBILITY.md b/docs/RELEASE-COMPATIBILITY.md
index b0c662c..42974e6 100644
--- a/docs/RELEASE-COMPATIBILITY.md
+++ b/docs/RELEASE-COMPATIBILITY.md
@@ -16,9 +16,9 @@ existing `owd-sync` installations remain the supported compatibility path.
| MCP | Authenticated Streamable HTTP against MCP `2026-07-28`, with stateless `2025-11-25` compatibility | Read-only vault tools are the portable baseline. Project behavior uses ordinary MCP Tools, Resources, and Prompts. See [MCP compatibility](MCP-COMPATIBILITY.md). |
| Project lifecycle | `open_project`, `wait_for_project_connection`, and `mdevolved_resume`; lower-level `resume_project` remains compatible | Create, join, rejoin, and resume converge on one exact Project without a client-specific transport. |
| Obsidian Mind profile | `8.4.0` at commit `af615d100a1d04561409ab9a1e71e615efa1d87b` | MDevolved runs beside `qmd`/`om`, preserves native layout, and never turns local profile data into authority. |
-| Eve.dev profile | Eve `0.63.0` at commit `d004e6d47e9d25d0380c24b5a47b65a18f8b2784`; `@vercel/connect` `2.0.4` | Uses Eve's native user-scoped MCP connection. Separate attribution requires a distinct connector identity. |
+| Eve.dev profile | Eve `0.65.0` at commit `7bcc0d16e3f41d44fadfd06b5bac3515a82d441d`; `@vercel/connect` `2.3.2` | Uses Eve's native user-scoped MCP connection. Separate attribution requires a distinct connector identity. |
| Albatross profile | Albatross `2.5.0` at commit `e458e4277f463a4688f127ea6ea61f5a344b64b8`; `mcp-remote` `0.14.3` | Uses a pinned stdio bridge while MDevolved remains standard remote Streamable HTTP MCP with OAuth. |
-| Hermes hands-off adapter | Hermes `0.21.4` at commit `d337b736aa1e8ebecfab043842d13e4a2d2f48a3` | Uses Hermes's native remote MCP/OAuth client; MDevolved stores bounded evidence and never becomes its scheduler or runtime. |
+| Hermes hands-off adapter | Hermes `0.21.5` at commit `f97608f178d1ffeca59860195ab7da295f7c8e5f` | Uses Hermes's native remote MCP/OAuth client; MDevolved stores bounded evidence and never becomes its scheduler or runtime. |
| LangChain recipe | LangChain `1.4.2` at commit `a18de590e7ccf5c647fbf3d689e5f1a15f78e9f5`; built-in `langchain.mcp` beta | Uses `MCPAdapter` over FastMCP OAuth. Tools are the baseline; Prompts and Resources remain available through the underlying FastMCP client. |
| Portable backup | New writes use `mdevolved-backup-v1`; `owd-backup-v1` remains readable | Unknown or malformed formats fail before staging; credentials and live grants never restore. |
| Workspace snapshot | New writes use `mdevolved-snapshot-v3`; `owd-snapshot-v2` remains readable | Unknown required capabilities fail before staging. Credentials and live grants never restore. |
diff --git a/docs/UPDATE-PASS-2026-09-24.md b/docs/UPDATE-PASS-2026-09-24.md
new file mode 100644
index 0000000..c473eb0
--- /dev/null
+++ b/docs/UPDATE-PASS-2026-09-24.md
@@ -0,0 +1,70 @@
+# September 24 compatibility update
+
+## Outcome
+
+Local update candidate for the existing agent integrations. No schema, migration,
+sync protocol, authorization, setup command, or plugin archive layout changed.
+
+- Eve's installed compatibility target advances from `0.63.0` to `0.65.0`,
+ with `@vercel/connect` from `2.0.4` to `2.3.2`. The generated connection
+ fixture, exposed profile, release checks, and documentation advance together.
+- Tagged-source reviews advance Hermes to `0.21.5` / `v2026.9.24`, OpenClaw to
+ `v2026.9.6`, and Gemini CLI to `v0.61.0`.
+- Copilot CLI's release/documentation review advances to `v1.0.88`; its
+ implementation is proprietary, and no live certification is claimed.
+- OpenCode, Obsidian Mind, Albatross, mcp-remote, and LangChain still match
+ their existing reviewed releases.
+- Corrected the Eve dashboard and documentation to use the existing canonical
+ generator and `mdevolved.ts` filename for new connections. Existing `owd`
+ connections remain supported and must not be duplicated or re-authorized.
+
+The GitHub comparison endpoint truncated Eve's changed-file list at 300 files.
+The review therefore compared complete recursive Git trees: connection
+definitions, runtime, and documentation retain identical blob identities
+between the old pin and the selected release. Connect's published implementation
+retains explicit user principals, token scopes/resources, and opt-in connector
+provisioning. The source references are in the individual compatibility docs.
+
+## Validation
+
+- Focused Vitest: **103/103**, covering client profiles, native setup commands,
+ inert plugin archives, and MCP access/authorization behavior.
+- Focused Playwright: **2/2**, exercising agent setup including canonical Eve
+ output on desktop and narrow viewports after the review repair.
+- `pnpm typecheck`, `pnpm upstream:config:check`, `pnpm release:check`,
+ `pnpm lint`, and `pnpm build:web`: passed.
+- Changed-file formatting and `git diff --check`: passed.
+- `pnpm audit --json`: zero known vulnerabilities after installation.
+- GitHub: no open Dependabot security alerts; the latest CI, desktop/CLI,
+ and compatibility-monitor runs inspected were successful.
+
+The full repository/browser/deployment gate was not repeated for this local
+profile update. A release still requires the repository's applicable release
+gate. No real client OAuth sessions or paid model runs were exercised.
+
+An independent upstream source audit supported the selected client pins. The
+final diff critic identified a real mismatch: the dashboard still generated
+legacy Eve connection names while the docs described canonical names. Rework
+reused the existing canonical generator, corrected the displayed filename,
+removed the stale version badge, and added desktop/narrow browser assertions.
+The legacy generator and its compatibility fixtures remain supported.
+
+## Deferred updates and delivery
+
+Eve `0.66.2` was observed but is not the installed target of this pass; the
+upstream monitor intentionally continues to report that release drift.
+Newer framework/toolchain packages and the pinned YAOS/Yjs synchronization stack
+remain separate upgrade work. No known security advisory requires their
+immediate replacement. Existing Dependabot PRs #26, #29, and #71 remain open
+and were not changed or merged.
+
+The owner subsequently authorized commit, GitHub delivery, README updates, and
+deployment. The README now describes the available setup paths and links to
+dated compatibility evidence without claiming live certification. Release
+delivery requires the complete gate on the candidate commit, successful PR CI,
+and health verification of the existing production Worker. The PR and task
+delivery receipt record the resulting commit and deployment identifiers.
+
+No schema migration, npm publication, new cloud resource, or paid service is
+required. Existing alpha deployments retain their original resource identities
+through `wrangler.legacy.jsonc`; rollback uses the preceding Worker version.
diff --git a/e2e/phase8-foundation.spec.ts b/e2e/phase8-foundation.spec.ts
index 6ba6af4..6957bda 100644
--- a/e2e/phase8-foundation.spec.ts
+++ b/e2e/phase8-foundation.spec.ts
@@ -1853,6 +1853,12 @@ test("shows one compact agent setup path at a time", async ({ browser }) => {
);
}
+ await agents.getByRole("button", { name: "Eve", exact: true }).click();
+ const eveGuide = agents.locator(".agent-client-guide");
+ await expect(eveGuide).toContainText("agent/connections/mdevolved.ts");
+ await expect(eveGuide).toContainText('connector: "oauth/mdevolved"');
+ await expect(eveGuide).not.toContainText('connector: "oauth/owd"');
+
await agents.getByRole("button", { name: "OpenClaw" }).click();
await expect(
agents.getByRole("heading", { name: "Install one portable plugin" }),
diff --git a/packages/client-packs/owd-eve/SKILL.md b/packages/client-packs/owd-eve/SKILL.md
index 3e65e83..143cf5d 100644
--- a/packages/client-packs/owd-eve/SKILL.md
+++ b/packages/client-packs/owd-eve/SKILL.md
@@ -31,7 +31,7 @@ client-side Project authority, or a second MDevolved endpoint. Do not pin a loca
tool allowlist: MDevolved's advertised catalog and server-side grant remain
authoritative.
-Eve `0.63.0` can install integrations from its registry with `eve add` or
+Eve `0.65.0` can install integrations from its registry with `eve add` or
interactive `/add`. MDevolved is not represented as registry-installed until Eve's
upstream registry accepts it. Until then, use the generated
`agent/connections/owd.ts` module from the MDevolved dashboard; do not claim that
diff --git a/packages/client-packs/package.json b/packages/client-packs/package.json
index 51a2671..69bd319 100644
--- a/packages/client-packs/package.json
+++ b/packages/client-packs/package.json
@@ -15,7 +15,7 @@
"./owd-obsidian-mind": "./owd-obsidian-mind/SKILL.md"
},
"devDependencies": {
- "@vercel/connect": "2.0.4",
- "eve": "0.63.0"
+ "@vercel/connect": "2.3.2",
+ "eve": "0.65.0"
}
}
diff --git a/packages/client-packs/src/eve.ts b/packages/client-packs/src/eve.ts
index 7367aca..221bb17 100644
--- a/packages/client-packs/src/eve.ts
+++ b/packages/client-packs/src/eve.ts
@@ -103,12 +103,12 @@ export const EVE_COMPATIBILITY_PROFILE = {
"Top-level schedules run as an app/runtime principal and cannot silently borrow a user's MDevolved grant. Dispatch scheduled MDevolved work through a user-authenticated route or require an explicit user action; do not downgrade MDevolved to app-scoped authorization.",
},
source: {
- commit: "d004e6d47e9d25d0380c24b5a47b65a18f8b2784",
- connectVersion: "2.0.4",
- eveVersion: "0.63.0",
+ commit: "7bcc0d16e3f41d44fadfd06b5bac3515a82d441d",
+ connectVersion: "2.3.2",
+ eveVersion: "0.65.0",
license: "Apache-2.0",
repository: "https://github.com/vercel/eve",
- reviewedAt: "2026-09-21",
+ reviewedAt: "2026-09-24",
},
} as const satisfies OwdEveCompatibilityProfile;
diff --git a/packages/client-packs/test/eve.test.ts b/packages/client-packs/test/eve.test.ts
index d21e158..74225e1 100644
--- a/packages/client-packs/test/eve.test.ts
+++ b/packages/client-packs/test/eve.test.ts
@@ -31,12 +31,12 @@ describe("Eve compatibility profile", () => {
format: "owd-client-profile-v1",
id: "eve",
source: {
- commit: "d004e6d47e9d25d0380c24b5a47b65a18f8b2784",
- connectVersion: "2.0.4",
- eveVersion: "0.63.0",
+ commit: "7bcc0d16e3f41d44fadfd06b5bac3515a82d441d",
+ connectVersion: "2.3.2",
+ eveVersion: "0.65.0",
license: "Apache-2.0",
repository: "https://github.com/vercel/eve",
- reviewedAt: "2026-09-21",
+ reviewedAt: "2026-09-24",
},
});
expect(JSON.parse(serializeEveCompatibilityProfile())).toStrictEqual(
diff --git a/packages/client-packs/test/fixtures/eve-0.63.0-connection.ts b/packages/client-packs/test/fixtures/eve-0.65.0-connection.ts
similarity index 100%
rename from packages/client-packs/test/fixtures/eve-0.63.0-connection.ts
rename to packages/client-packs/test/fixtures/eve-0.65.0-connection.ts
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index dbca8da..00b9371 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -167,11 +167,11 @@ importers:
packages/client-packs:
devDependencies:
'@vercel/connect':
- specifier: 2.0.4
- version: 2.0.4(ai@7.0.107(zod@4.4.3))(eve@0.63.0(ai@7.0.107(zod@4.4.3)))
+ specifier: 2.3.2
+ version: 2.3.2(@modelcontextprotocol/sdk@1.30.0(@cfworker/json-schema@4.1.1)(supports-color@10.2.2)(zod@4.4.3))(ai@7.0.107(zod@4.4.3))(eve@0.65.0(ai@7.0.107(zod@4.4.3)))
eve:
- specifier: 0.63.0
- version: 0.63.0(ai@7.0.107(zod@4.4.3))
+ specifier: 0.65.0
+ version: 0.65.0(ai@7.0.107(zod@4.4.3))
packages/contracts:
dependencies:
@@ -1645,22 +1645,23 @@ packages:
cpu: [x64]
os: [win32]
- '@vercel/cli-config@0.2.6':
- resolution: {integrity: sha512-2AsKCf6gE/Eniq09ARm1RK9rQMV5pcAHU7BFcR9MISO+4/RsjjkaYbQN6G85/xi9pYZ5CJNXvYn4TI6p1jKBcg==}
+ '@vercel/cli-config@0.3.0':
+ resolution: {integrity: sha512-kQLt5Pm8wKd7/imzDY9/9u0tf8OuRkAuXI+s7j057FSUrXapAmumJSKwDqnR4ZZqdWoUcNLlFAgVIAdiwcGTcw==}
'@vercel/cli-exec@1.0.1':
resolution: {integrity: sha512-g9XerViJ/paZujufXYcu5XYI2vU2rtB4sgdpjUHde5RnOkdmpu0ngH46LCFGHoPXO/C+qDPSczIHIRN+8Q2YKQ==}
engines: {node: '>= 18'}
- '@vercel/connect@2.0.4':
- resolution: {integrity: sha512-VD0dY28Nr8uTa5yOWeHQwgn6e3Oj0gbDvkJ3EowPRSJriarPPX5I2oG6IpEg3sFz6t16AY5Us5eHRb0UMkdfVQ==}
+ '@vercel/connect@2.3.2':
+ resolution: {integrity: sha512-qNRdUI6h2zbTruYU92leapFvBRjwF70gewwuj0rBPBHyu2Bnfzm//k4Sc8kA8e/zQfwKbdpYVk8oWe3fNqImzA==}
peerDependencies:
'@ai-sdk/mcp': ^1 || ^2
'@auth/core': '>=0.37.0'
'@chat-adapter/slack': ^4.0.0
+ '@modelcontextprotocol/sdk': ^1.29.0
ai: ^6 || ^7.0.0-beta.0
better-auth: '>=1.5.0'
- eve: '>=0.13.7'
+ eve: '>=0.39.1'
peerDependenciesMeta:
'@ai-sdk/mcp':
optional: true
@@ -1668,6 +1669,8 @@ packages:
optional: true
'@chat-adapter/slack':
optional: true
+ '@modelcontextprotocol/sdk':
+ optional: true
ai:
optional: true
better-auth:
@@ -1679,8 +1682,8 @@ packages:
resolution: {integrity: sha512-UycprH3T6n3jH0k44NHMa7pnFHGu/N05MjojYr+Mc6I7obkoLIJujSWwin1pCvdy/eOxrI/l3uDLQsmcrOb4ug==}
engines: {node: '>= 20'}
- '@vercel/oidc@3.8.7':
- resolution: {integrity: sha512-fRu59npOu+1vsV570tiLKskfuRyOJ1MqceAkXbTIfWPnM+c9ve1tSK81oj4umKKirymlGUss3V60Lm5I38rKDw==}
+ '@vercel/oidc@3.8.9':
+ resolution: {integrity: sha512-TcbdH3YtGS2KU98T99dN4sbf+E4vbJZsJTRN97wKQ7QWQ0BR7U02QX3KN4+5GHxBtKTj1c5CnvTTitc2ZRad0A==}
engines: {node: '>= 20'}
'@vitejs/plugin-react@6.0.3':
@@ -2030,14 +2033,15 @@ packages:
resolution: {integrity: sha512-aIL5Fx7mawVa300al2BnEE4iNvo1qETxLrPI/o05L7z6go7fCw1J6EQmbK4FmJ2AS7kgVF/KEZWufBfdClMcPg==}
engines: {node: '>= 0.6'}
- eve@0.63.0:
- resolution: {integrity: sha512-iDv0S4MXvZimaXNTJnyB2THumRQLWQSAgpMcZsGtMNquYQpSKB1+i8sxX4KJOHHCLd04lwD+06xnh+ja7rlZIw==}
+ eve@0.65.0:
+ resolution: {integrity: sha512-16dcyvpucnMp6f1TKZROvRrDAYWIlV7ulZfEMK+IuK1AVXMQPoLLOrGuLT/qI1TjIkxZt9g1JcXXOv/uu3yjdQ==}
engines: {node: '>=24'}
hasBin: true
peerDependencies:
'@opentelemetry/api': ^1.0.0
ai: ^7.0.105
braintrust: ^3.0.0
+ chat: ^4.41.0
dd-trace: ^6.13.0
just-bash: ^3.1.0
microsandbox: ^0.5.0
@@ -2046,6 +2050,8 @@ packages:
optional: true
braintrust:
optional: true
+ chat:
+ optional: true
dd-trace:
optional: true
just-bash:
@@ -4166,7 +4172,7 @@ snapshots:
'@typescript/typescript-win32-x64@7.0.2':
optional: true
- '@vercel/cli-config@0.2.6':
+ '@vercel/cli-config@0.3.0':
dependencies:
xdg-app-paths: 5.5.1
zod: 4.1.11
@@ -4175,18 +4181,19 @@ snapshots:
dependencies:
execa: 5.1.1
- '@vercel/connect@2.0.4(ai@7.0.107(zod@4.4.3))(eve@0.63.0(ai@7.0.107(zod@4.4.3)))':
+ '@vercel/connect@2.3.2(@modelcontextprotocol/sdk@1.30.0(@cfworker/json-schema@4.1.1)(supports-color@10.2.2)(zod@4.4.3))(ai@7.0.107(zod@4.4.3))(eve@0.65.0(ai@7.0.107(zod@4.4.3)))':
dependencies:
- '@vercel/oidc': 3.8.7
+ '@vercel/oidc': 3.8.9
optionalDependencies:
+ '@modelcontextprotocol/sdk': 1.30.0(@cfworker/json-schema@4.1.1)(supports-color@10.2.2)(zod@4.4.3)
ai: 7.0.107(zod@4.4.3)
- eve: 0.63.0(ai@7.0.107(zod@4.4.3))
+ eve: 0.65.0(ai@7.0.107(zod@4.4.3))
'@vercel/oidc@3.2.0': {}
- '@vercel/oidc@3.8.7':
+ '@vercel/oidc@3.8.9':
dependencies:
- '@vercel/cli-config': 0.2.6
+ '@vercel/cli-config': 0.3.0
'@vercel/cli-exec': 1.0.1
jose: 5.10.0
@@ -4540,7 +4547,7 @@ snapshots:
etag@1.8.1: {}
- eve@0.63.0(ai@7.0.107(zod@4.4.3)):
+ eve@0.65.0(ai@7.0.107(zod@4.4.3)):
dependencies:
ai: 7.0.107(zod@4.4.3)
nitro: 3.0.260903-beta
diff --git a/scripts/check-client-profile-fixtures.test.mjs b/scripts/check-client-profile-fixtures.test.mjs
index 66e3a13..c8d6294 100644
--- a/scripts/check-client-profile-fixtures.test.mjs
+++ b/scripts/check-client-profile-fixtures.test.mjs
@@ -9,7 +9,7 @@ const normalizeSource = (source) => source.replace(/\s+/gu, " ").trim();
test("the generated Eve connection matches the pinned type-checked fixture", async () => {
const fixture = await readFile(
new URL(
- "../packages/client-packs/test/fixtures/eve-0.63.0-connection.ts",
+ "../packages/client-packs/test/fixtures/eve-0.65.0-connection.ts",
import.meta.url,
),
"utf8",
diff --git a/scripts/check-release-contract.mjs b/scripts/check-release-contract.mjs
index 0dd5178..e4f8d48 100644
--- a/scripts/check-release-contract.mjs
+++ b/scripts/check-release-contract.mjs
@@ -116,8 +116,8 @@ if (
!eveCompatibility.includes(
"This is a source-verified compatibility profile",
) ||
- !eveCompatibility.includes("| Eve | `0.63.0`") ||
- !eveCompatibility.includes("| `@vercel/connect` | `2.0.4`") ||
+ !eveCompatibility.includes("| Eve | `0.65.0`") ||
+ !eveCompatibility.includes("| `@vercel/connect` | `2.3.2`") ||
!marketingSite.includes('id="eve"') ||
!normalizedMarketingSite.includes(
"Eve runs the agent. MDevolved makes the work portable.",
@@ -153,13 +153,13 @@ if (
"`v1.18.32` at `545f51d26cc39a907d2867492d498d9607ea5fa4`",
) ||
!portableAgentCompatibility.includes(
- "`v2026.9.5` at `ec9c1a13db8938e5a3eaa51fca2e981cde2395a9`",
+ "`v2026.9.6` at `eb377ac59e6c9fd6c7705028034812becf00271b`",
) ||
!portableAgentCompatibility.includes(
- "`v0.60.0` at `733edcb597ce690ac2e2fe3b3b3690b60a4c8f27`",
+ "`v0.61.0` at `bb523741c7429a44d03e964bc124c7c92df59d5f`",
) ||
!portableAgentCompatibility.includes(
- "`v1.0.87` at `d418dbf1061152afa17500cbc69478f8dce153d8`",
+ "`v1.0.88` at `c13b3dcae4f1e176c5a074c0d063a6e9f258081f`",
)
) {
throw new Error(
@@ -167,8 +167,8 @@ if (
);
}
if (
- !hermesCompatibility.includes("Hermes Agent `0.21.4`") ||
- !hermesCompatibility.includes("`d337b736aa1e8ebecfab043842d13e4a2d2f48a3`") ||
+ !hermesCompatibility.includes("Hermes Agent `0.21.5`") ||
+ !hermesCompatibility.includes("`f97608f178d1ffeca59860195ab7da295f7c8e5f`") ||
!hermesCompatibility.includes("native remote MCP OAuth support") ||
!normalizedHermesCompatibility.includes(
"does not claim vendor certification or a completed live Hermes acceptance run",