MCP sign-ins and larger war rooms
- MCP servers that need a sign-in get Connect. Kepler now asks a remote MCP server that does not say how it signs in whether it needs one. If it does, its row in Settings > Tools & MCP shows Sign in and a Connect button. Before, Kepler treated these servers as open, and every request failed with 401 Unauthorized. See Signing in.
- Plugin servers that declare a sign-in work. A plugin’s MCP server that declares its sign-in the Claude Code way, with an
oauthblock, gets a working Connect. Installing or updating a plugin, and/plugins, say which of its servers still need a sign-in. See Servers that need a sign-in. - A server whose sign-in settings are wrong or unsupported shows Config error and says what to fix, instead of sending requests with no token.
- Slack’s MCP server signs in through Kepler’s own Slack app, so the consent page names Kepler.
- War rooms with more than four members. The room shows the lead and the first four members, and the rest keep working without a pane. Before, a fifth member took over the room: the lead, its composer and the other members disappeared. See What you see.
Hooks, plugins, channels and chat automations
Extend Kepler
- Hooks. Run your own check at moments in Kepler’s work: before a tool runs, when a message arrives, when a run ends, when a watcher fires. Hooks can block or ask, never approve. Hooks written for Claude Code run unchanged. Describe one with
/hookand Kepler drafts it for you to confirm. See Hooks. - Plugins and marketplaces. Install bundles of skills, commands, agents, hooks, MCP servers and chat channels from a marketplace, GitHub, a git URL or a folder. You see everything a plugin runs before it runs. Plugins can ask for settings, and secrets go to the keychain. Plugins in the Claude Code and Cursor formats install too. Ask with
/plugins. See Plugins. - Customize. Settings > Customize is now one place for plugins, skills, hooks, commands and agents, with one search and a workspace filter. Commands get an editor. Agents moved here from their own settings page, and Signature moved to Settings > General. See Customize.
- AGENTS.md. Kepler reads a workspace’s
AGENTS.mdalongside itskepler.md. See Memory.
- Channel plugins. A plugin can bring a new chat channel. Add channel on the Gateway page installs one, wraps a channel server you already have, or has Kepler build one with
/channels. See Add a channel. - Warm and cold sessions. A chat keeps its session while you keep talking. After six quiet hours the next message starts a fresh one, and
/sessionsand/switchtake you back. Each thread is its own session. See Which session a message goes to. - Kepler can post first. In Assist and Yolo, Kepler can send a message to a channel. Anything other than your own chat or a conversation you approved waits for your OK.
- Approvals on plugin channels. A channel with its own approval buttons shows them, and Kepler accepts the answer only for a request it asked on that channel.
- One account, one channel. Connecting a second channel with a bot token already in use is refused.
- A message that cannot be delivered lands in the Feed instead of being lost. A channel that keeps failing stops and shows why.
- Chat trigger. Give an automation a
/commandand anyone you allowed can run it from a connected chat, or you from the desktop/menu. See Run one from a chat. - Post step. Answer in the chat that started the run, send the result to you on a channel, or post to a named conversation, which asks your OK at Go live. See Post in a chat.
- Decide item by item. A decision step can judge each item in a list, up to 200, in one step.
- Background lanes over the limit wait in a queue and start in order, instead of being refused. See Specialist agents.
- The hook log is on the Hooks tab of Activity, under Settings > Plan & Usage.
- Kepler’s own tools can no longer read or use the key Kepler signs in with.
The decision model
- Decision model. An optional second model, picked under Settings > Models, that answers typed questions in about a second. See Decision model.
- It double-checks shell commands and MCP calls. It can only make a decision stricter: a confident “write” on a command the rules would have let through asks you instead. Its verdict shows as a pill on the tool row.
- On the unknown-command card it suggests whether the command reads or writes. You still decide.
- In chat and war rooms Kepler can use it to classify, score and pick across many items in one call.
- Automations get a Decide with a decision model step.
- A watcher that checks for a condition in plain words uses it when one is picked.
- Run once everywhere. The unknown-command card offers Run once in every posture, Observe included. Watchers and automations still never run a command Kepler cannot vouch for. See The unknown-command card.
- Reasoning effort is a slider in the model picker. Auto lets the model decide on OpenAI and OpenRouter too.
- An MCP tool call shows its server’s icon, and its label names the action.
- A System One endpoint lists the models it serves.
- A model that can draw images does so without an image model set up.
- A topology source that fails to scan offers Try again, Ignore and Ask Kepler.
- A run you cancel still counts the tokens it spent in Plan & Usage.
- Settings > General > About shows the product version.
Remote access and a map that knows more
Work on other machines
- Remote access. Turn on Work on other machines in Settings > Remote access, then pick a host, a cloud VM, a container or a sandbox from the control beside Send, or type
/connect <host>. Kepler connects with your own logins and never asks for or stores a password. See Remote access. - Machines come from your SSH config, Google Cloud and AWS, Teleport, Docker, Kubernetes pods, Ansible inventories, and groups made from SSH config patterns. Windows hosts work over SSH.
- Connected is not the same as allowed. A thread uses a machine only after you pick it or approve it there, and each machine can carry its own limits.
- Save a machine appends a
Hostblock to your own~/.ssh/config, after showing it to you. - Commands that keep running. Kepler can keep a port-forward or a log tail running for up to twelve hours, with a Stop button. End a shell-mode line with
&to do the same yourself. See Commands running in the background.
- How things got there. CI workflows from GitHub Actions, GitLab CI, CircleCI and Jenkins, Helm releases, and Argo CD and Flux applications are on the map. See Topology.
- Where the data lives. Databases, caches, queues and buckets on AWS and Google Cloud, with their addresses. Azure joins the scan, one source per subscription.
- Where to look. Prometheus, Grafana, Alertmanager, Loki, Jaeger and similar tools found in your clusters, with their addresses.
- Things no scan can see. Add them to Kepler’s own list, or accept what Kepler proposes from your conversations under Activity > Needs you. See Add what no scan can see.
- The composer fits a narrow panel, and the conversation’s card stays beside it in narrower windows.
- Choosing a command that takes an argument puts it in the composer and waits.
Tabcompletes any command andEnterruns it. - Rows from a connected Grafana, Datadog, Prometheus or OpenTelemetry integration reach the map.
- One integration tool with an unusual schema can no longer make every turn fail.
Tabs and split panes
- Tabs.
Cmd+Topens a tab,Cmd+1toCmd+9pick one, andCmd+Wcloses one.Cmd-click a session in the sidebar, or choose Open in new tab, to open it in a tab. See Tabs and split panes. - Split panes.
Cmd+Dsplits right andCmd+Shift+Dsplits below. Drag a session onto a pane to place it. Panes you are not typing in keep streaming. - Tabs and splits come back after a relaunch.
- Every shortcut in one place. Press
Cmd+/or type/shortcuts. On Windows and Linux, keys are written asCtrl,ShiftandAlteverywhere in the app. See Commands and shortcuts. - Your own messages sit on the right, and code blocks use the editor’s colours.
- What Kepler can do (
/help) has walkthroughs for Automations and for tabs and panes. Ctrl+Dsplits on Windows and Linux.Cmd+Wcloses the pane or tab, never the window.
Automations
- Automations have their own place. Describe one, or start from one of 15 templates. The list puts the ones waiting on you first. See Automations.
- The automation builder. The chat on an automation’s page tries each step before adding it, and cannot run, delete or take an automation live. See The automation builder.
- Automations can change things, with your permission. Go live lists every step that changes something and asks how each may run: Every run or Ask me each time. See What an automation may change.
- Event triggers. An automation can start when a check’s result changes, or when a webhook arrives. Webhooks have Send a test and New token. See Webhooks.
- Approvals and reports in the Feed. Waiting is the one place to answer an approval. Reports can land quietly, and an alert clears itself when a later run finds the problem gone. See The Feed.
- Integrations stay signed in. Sign-ins renew in the background. See Signing in.
- Spike and Oodle join the integrations catalog.
- Sources in web answers show as chips with each site’s icon and name.