OtōtoOtōto

(•)Changelog

Every release, newest first.

What each release added or changed, as its package's own notes say. ototo update installs the newest.

2.8.6 beta

  • A tidier ototo --help. The commands are grouped by what they do: asking the small model (ask, locate, callers, edit, routine), reading the code with no model (read, outline, find, changes, history, replace, digest), watching and checking (tail, ui, doctor, report), setting up and updating (init, update, managed, settings), and the server Claude Code and OpenCode start (serve). Each has a one-line description; ototo <command> --help has the rest.

Coming from 2.8.4 or earlier? 2.8.5's changes are new to you too: routines, and the reporting names (INSTALL.md, "New in beta 2.8.5").

2.8.5 beta

  • Routines (experimental). A job you do again and again, described once in a markdown file, done by Otōto's small model with its read-only tools: ototo routine list, ototo routine run <name> [input], ototo routine new <name>. install.sh puts five examples in ~/.config/ototo/routines/ (the CI jobs, the dependencies, the HTTP endpoints, the configuration, and a file's ticket number and summary for Jira), never over a file of the same name. Claude Code and OpenCode get a routine tool only with routines = true in config.toml; until then nothing changes for them. routines/README.md shows how to use them and write your own.
  • Reporting that fits beside our other products, when you send Otōto's counts to a collector: service.namespace, the standard OTEL_RESOURCE_ATTRIBUTES read as well as otlp_attributes, and OpenTelemetry's own names for tool calls (mcp.server.operation.duration) and small-model tokens (gen_ai.client.token.usage) beside Otōto's. Otōto's own metrics are unchanged.
  • ototo update keeps what it unpacked, so the "Undo all" path install.sh prints at the end still works.

2.8.4 beta

  • ototo update. Put the package we send, with its .SHA256SUMS and .sig, in ~/Downloads and run ototo update: it checks them against Otōto's release key, then runs the package's install.sh, which keeps your settings. --dry-run only checks; a path picks another package. This one you still install with sh install.sh.
  • OpenCode. install.sh now sets Otōto up in OpenCode too, beside Claude Code or on its own. In ~/.config/opencode/opencode.json it registers Otōto with 30 minutes for each call (OpenCode otherwise gives up on a tool after about a minute, and an ask can take longer), lists Otōto's instructions (your own AGENTS.md is left as it is), and turns OpenCode's own grep and glob off (--keep-search keeps them). A config with comments is left alone, and it prints what to add by hand. ototo doctor checks it; uninstall.sh takes it out. Set OpenCode up by hand before? Its mcp.ototo needs "timeout": 1800000.
  • Fewer wasted reads. A list of files sent as a string of JSON ("[\"src/a.rs\"]") is now read as that list, not as one file that is not there.

2.8.3 beta

  • ototo report, for when something goes wrong. It writes one file to send us: Otōto's version and your machine's, what ototo doctor finds, your settings with API keys and headers taken out, the run log's counts for the last week, and the messages of its latest errors. Not your questions, the code Otōto read or its answers. Read it, then send it with what you asked and what happened.
  • Reads Claude garbles still work. Claude sometimes sends read's or outline's list of files under another name, and Otōto used to answer "give at least one target", which did not say what was wrong, so Claude tried the same call again. Otōto now takes the list; and when a call has none at all, it says what the argument is called and what the call sent instead. The dashboard shows what such a call sent, rather than "(not recorded)".

2.8.2 beta

  • Directories you add to a session. A Claude Code session can reach beyond the repo it started in (/add-dir, or claude --add-dir), and Otōto now works there too: an absolute path inside an added directory, or naming one in a question, is enough. It serves only what the session lists, never your whole home directory. A path outside all of them gets a note saying to add its directory with /add-dir first.
  • Secrets stay out. Environment files (.env; not .env.example), private keys, credentials files (.netrc, .npmrc, .aws/credentials, …) and Terraform state are no longer read or listed by Otōto, so they never reach a model server. Claude Code's own tools are unaffected. read_secrets = true in config.toml turns this off.
  • Your files are yours only. The run log, the live trace and config.toml are readable by you alone, and so is ~/.ototo; files from earlier betas are tightened on first use, and ototo doctor warns about any that are not.
  • The dashboard needs its link. Its data now needs a key only you can read, so other users on the machine cannot see your questions and answers through it. Open it once with the link ototo ui prints (ototo ui --link prints it again); the page remembers it. A bookmark of the plain address says how to get the link.
  • Harder to steer through the code. The small model is told that what it reads in a repository is data, never instructions, and text in a file shaped like its own control tokens can no longer open a turn of its own.
  • ototo doctor warns when a model server or collector on another machine is reached over plain HTTP, and shows the check command (check_cmd) edits run, if one is set.
  • Signed checksums. Each release now comes with ototo-<version>-<commit>.SHA256SUMS and its .sig. To check a download, save the key line from https://ototo.dev/release-key.txt as release-key.txt, then: ssh-keygen -Y verify -f release-key.txt -I ototo-release -n ototo-release -s <sums>.sig < <sums> and shasum -a 256 -c <sums> (sha256sum -c on Linux).
  • For organisations: ototo managed --install with --base-url and --model now enforces those model servers, so users cannot send code elsewhere; --allow-user-endpoints lets them add their own.

2.8.1 beta

  • Fewer wasted turns. The small model sometimes answered its first turn in prose ("no repository was provided") or called Claude Code's tools by name. Now a prose answer is asked again with a tool call required (on servers that allow it), shell commands that only look at files (grep, cat, sed -n, ls, find) run as Otōto's own tools, and a search that finds nothing says why and which kinds of file the repository has.
  • Safe from a model server's stale cache. On 27 September our vLLM server's shared prompt cache held wrong data for part of Otōto's instructions, and every question that reused it went wrong until a restart. Each question now keeps its own cache on the server (cache_salt), and ototo doctor checks whether a server's cache answers as a fresh request would, and says to restart it if not.
  • Running your own vLLM? vllm/README.md in this package has the flags we run, a chat template for coding clients (Qwen's own, plus what those clients send that Qwen's refuses) with a script that checks it, and what to do when the prompt cache goes bad.
  • Plugins, sealed. Compiled plugins are cached with a key of your own (~/.config/ototo/cache.key, made on first use), so code put in the cache by anything else is compiled over, never run. The first start after upgrading compiles them once, in about a second.
  • Reporting: if your team collects Otōto's counts, they now carry your Claude account's e-mail, as Claude Code's own do, so the dashboard shows the two side by side per person without any setting. user.email= in otlp_attributes sends none, and ototo doctor says which address goes out.
  • For organisations: ototo managed --install run twice no longer loses the backup of the original settings, and ototo doctor no longer gives managed users advice they cannot take.

2.8 beta

  • A new look. Otōto has a new logo, ( • ): two arms round a little one, which is what otōto (弟, little brother) means. It is in the dashboard and on the tab's icon.
  • (•) in the terminal. ototo ask, locate, callers and edit show the call on the last line while it runs: the time so far, the small model's turn and what it is doing. Through a pipe, or from Claude Code, nothing changes.
  • The dashboard (ototo ui): - Plugins: every plugin with its version, the files it reads, who signed it and whether it loads (and why not). Switch one off or on, remove it, or add one from its .wasm and .wasm.sig (only plugins signed by a key you already trust). - What the small model did is now a table that stays inside its panel: its own tools, tools it made up, turns it answered in prose, and garbled calls, with the share of turns wasted; click a row for examples. - Light, dark or automatic, from the switch at the top right.
  • For organisations rolling Otōto out to many machines: organisation-wide settings that users cannot override, ototo managed to push the setup to every machine through Claude Code's managed settings, and a fleet dashboard of what is running where. Ask us for the admin guide.
  • For your security team: SECURITY.md (what runs, what it reads, what leaves the machine) and sbom.cdx.json (every dependency and its licence) are in this package.
  • Version numbers: ototo --version now says 2.8.0, not 0.1.0.

2.7 beta

  • Fixes plugins on macOS. Beta 2.6's Mac build was signed in a way that let macOS stop it the moment a plugin loaded, and Otōto loads plugins when it starts, so with the plugins installed Claude Code lost Otōto altogether (claude mcp get ototo said it failed). This build carries the permission plugins need.
  • ototo doctor checks the whole setup and says what to do about anything wrong: the settings, each model server (reachable, serving the model, and answering a test request with a tool call), Claude Code's registration, settings.json and CLAUDE.md, whether the plugins load and run, reporting, and the run log.
  • ototo init (what install.sh now runs) finds the model server, tests it, shows what it will change and asks. Run it again to switch models: ototo init --base-url <url>. --preset gpu-server|mac-bonsai|haiku|other picks the settings for that kind of model and shows what we measured on it; --haiku-fallback adds Claude Haiku as the paid last resort.
  • Docker Compose files are read as Compose merges them (overrides, extends, include, .env values), by a second plugin: read compose.yaml#api is the api service as it will run.

2.6 beta

  • More languages and formats: Go, C#, shell scripts and SQL (any dialect: tables with their columns, procedures, migrations); XML by element (Maven POMs, MSBuild, Spring: read pom.xml#spring-core); properties files; CSV by column; Dockerfiles by stage and Makefiles by target.
  • What changed, and why: Claude can ask changes (what this branch changed, by function) and history (the commits behind some lines) instead of reading git diff and log output.
  • Test output: Claude runs tests as ototo digest -- <command> and sees the failures and the summary, not every line. Your permissions still decide what runs.
  • Plugins: GitLab CI jobs are read as GitLab runs them (includes, extends, anchors resolved), by a plugin: a sandboxed WebAssembly file that loads only because it is signed, by the key this package trusts for plugins.

2.5 beta

  • Linux. A build for x86-64 Linux, with the same installer.
  • No more reading code through Bash. A hook refuses Bash commands that only print lines of your repo's files (sed -n '10,40p', head, tail, cat, awk 'NR>=…') and tells Claude the ototo read to use instead; Claude had kept cd-ing into worktrees to read files that way. Anything else in Bash runs as before (pipes, redirections, other commands, files outside the repo). --keep-search leaves Bash alone.
  • The installer edits settings.json with ototo settings add|remove, on macOS and Linux alike.

2.4 beta

  • Git worktrees. If you work in a git worktree (a second checkout of the same repo, from git worktree add) while Claude Code was started in the main one, Otōto now reaches it too: Claude gives it a path inside the worktree, or names the worktree. Before this Otōto refused those files, so Claude read them itself.

2.3 beta

  • Agents use Otōto too. When Claude starts one of its own agents (to explore or audit code), a new hook tells the agent that Otōto is there and to outline files and read only the parts it needs, and the CLAUDE.md block tells Claude to say the same in the agent's brief. Before this, agents read whole files.
  • Upgrading updates the CLAUDE.md block in place when it has changed (backed up first), instead of leaving the old one.

2.2 beta

  • Works in plan mode. Otōto's tools now say which of them only read (all but edit and replace_all), so Claude Code's plan mode uses them without asking for permission.

2 beta

  • Signed and notarised with a Developer ID (beta 2.1), so macOS runs it without warnings.
  • Fallback endpoints. List several model servers in ~/.config/ototo/config.toml and each request goes to the first that answers; Claude Haiku can be the paid last resort (below).
  • Reporting. Counts (never code) to an OpenTelemetry collector, next to Claude Code's own metrics.
  • HTTPS endpoints work without any extra setup.