Pup - the AI's own browser
Public Made by Adomby adom
pup gives your AI a real browser on your desktop that it drives completely, in the background, signed in as you: windows that never jump in front of your work, one shared profile that learns your logins, and every window labeled on the taskbar with its AI thread's name.
Releases 1153
Standalone per-platform binaries to download and run, no tools needed. The newest is pinned on top.
Annotate's quick colors are red, blue and green: the muddy yellow/orange third color is gone from the trio and from Multi's automatic cycle (red, blue, green, purple), so every mark has a color anyone can name to the AI. Yellow stays in the More flyout, and every swatch shows its color name on hover (John, 2026-10-07).
Stable link for websites and docs: /download/adom/pup-bridge/latest
All releases showing 581-600 of 1153
Stops pup from creating an Adom Pup entry in the users Start Menu, which Adom users dislike. The main app-identity registration ran on every bridge start and registered the anchor AUMID WITH a Start Menu shortcut (the pinnable launcher). It now registers registry-only with shortcut false and brands the AUMID by writing IconResource straight into HKCU, the same shortcut-free technique the per-window AUMIDs already used, so grouped taskbar mode keeps its grouping anchor but no Start Menu shortcut is ever created. Existing machines self-heal: the stale Adom Pup.lnk is deleted on the next bridge start. The pinnable launcher is dropped deliberately since users did not want it
Fixes a data-loss race in pup_quit_idle_browsers that could close a browser holding live windows. It judged idle purely by adopted in-memory sessions, so right after a bridge restart, before re-adoption runs, a warm browser still holding real windows looked session-less and got closed, taking every window with it. It now inspects the browsers ACTUAL open pages before closing and skips any browser that still holds a non-blank page, or that cannot be inspected, so a browser mid-re-adoption or user-held is never reaped
Pup now closes Chrome gracefully instead of force-killing it, so the profiles prefs actually flush to disk on close (John). The teardown did call browser.close but then unconditionally force-killed the PID, which could truncate the pref write mid-flush; that is why the toolbar pins were lost every relaunch, and it also caused Chromes unclean-exit Restore tabs bubble. Now pup waits for the process to exit on its own after the graceful close and only force-kills a genuinely wedged process; the profile-scoped reap still guarantees no reparented renderer lingers. This lets the once-per-launch pin state persist
Fixes the owner parameter being ignored on pup_open_window. An explicit owner arg now wins over the callers ai-thread (it is the documented your thread/task label), and it stamps both the owner label and the _ownerThread gate/resolution identity, so one thread can faithfully reopen a window ON BEHALF of another thread, e.g. a reload cycle, and that thread still finds and owns it with zero ids. With no owner arg the callers ai-thread remains the owner, unchanged. Found when a reload stamped six other threads windows as mine
Fixes the pup toolbar logo for real, and roots out why it was missing. Chrome for Testing now DISABLES unpacked (load-extension) extensions until the profiles Developer mode is on, so the Adom action icons had no action, could not be pinned, and hid in the puzzle-piece overflow. Developer mode lives in HMAC-signed Secure Preferences that pup cannot seed by writing files, so pup now calls the developerPrivate API on a short-lived background chrome://extensions page at each launch to turn Developer mode on and pin every Adom action icon. This is also the only path that fixes a fresh profile, where dev mode starts off. The four-dot pup mark, the identity avatar, and the annotate pen now sit pinned in the toolbar
Fresh-user defaults now match Johns working config, since the AUMID crash concern that kept them off is resolved and John confirmed they work great. A new user now gets per-window taskbar identity (aumidIcons on), jump lists (jumpLists on), the category icon style, and split taskbar grouping by default, instead of the old all-windows-stacked-under-one-Chrome-button mode. Existing users explicit choices are untouched via the _chosen tracking, so this only moves users who never set these keys
Credential hints surface on any verb, not just render verbs: the anti-phishing auto-fill note (which regurgitates the live domain) and the login-capture note now drain unconditionally so the caller sees them on its very next call whatever it is
Fixes login capture missing form submits that navigate: capture now fires through a synchronous Puppeteer binding at submit time, reaching the keychain vault BEFORE the navigation wipes the page, with the sweep-harvested global kept only as the fallback for SPA logins that never navigate. Same keychain-only, never-logged storage
pup-native credential manager (John authorized), so the AI manages logins without Chromes foreground picker. Auto-capture: as any login is submitted in a pup window, the username and password are recorded into the OS keychain vault (encrypted at rest, never in the index, never logged, never echoed) and the owning thread is hinted that its adom-you identity just grew. Auto-fill on return: matching pages fill in the background over CDP, no Chrome dropdown, no foregrounding. Submit is REASON-GATED and domain-confirmed per John: pup never auto-submits; the AI must call pup_login submit true with a submitReason, and the refusal regurgitates the exact live host so a lookalike or phishing domain is caught before the secret is sent. New pup_credentials verb lists saved logins host and username only; captureLogins and the richer autoLogin modes are dashboard settings and pup_configure keys
The anonymous identity tile is recut per John: it no longer wears the pup four-dot mark, which read as pup-again rather than nobody. It is now the universal empty-avatar signal, a muted blank head-and-shoulders silhouette inside the same dark avatar disc on the family tile, so the identity slot reads avatar equals you, blank head equals no identity. Popup card mark updated to match, anon extension 0.1.1
One pup logo, finally. John picked the four-dot mark; until now pup wore three unrelated identities that accreted feature by feature: the borrowed two-lobe adom mark on the extension tile and legacy icos, a one-off two-windows-and-pulse dashboard favicon, and the four-dot mark only in the popup header and the anonymous tile. The canonical mark is now the teal rounded tile with the adom four offset dots in dark logo teal, worn by the pup toolbar extension icon set at 0.2.5 and the dashboard favicon; the purpose-variants stay because they carry meaning: pen for annotate, avatar for signed-in-as-you, dots-on-dark-disc for anonymous, category glyphs on taskbar tiles
pup_my_windows stops lying by omission during recovery: for about 90 seconds after a bridge restart an empty listing now says the bridge is still re-adopting surviving windows and to retry, instead of letting a thread conclude its window is gone. Found by hitting exactly that window myself while verifying the ai-thread rename
The thread-addressing parameter is spelled ai-thread, exactly like the CLI flag, per John; the camelCase forms from earlier today remain silent aliases. Docs and describe updated
Teaching refinement to the next-steps block after Johns question about screenshots: pup_screenshot is the loudly-stated default, page-perfect over CDP with zero ids, and the one legitimate reason to touch a desktop verb, needing the browser chrome itself in frame, now comes with its rail: pup_window_info hands the caller its own windows hwnd so nothing is ever searched for
The thread-name addressing parameter is aiThread, matching abs own --ai-thread vocabulary exactly per John; aiThreadName from an hour ago stays as a silent alias. Docs, describe, and the my-windows payload all speak aiThread
AI-thread ergonomics overhaul after John watched the ah-build thread hwnd-hunt its own window. New pup_my_windows verb: zero args, everything the calling thread owns with ready-to-run next steps. Thread-name addressing: any targeting verb accepts aiThreadName in place of sessionId, resolving to that threads window, first step of retiring sessionId from the public surface. And every open and navigate response now carries a _next block teaching the caller to keep driving its window with zero ids, screenshot via pup_screenshot, reload via pup_reload, and never to hunt hwnds with desktop verbs for a pup window. SKILL.md gains the addressing section as the second thing a reader sees
The owner-in-tab-title experiment is removed outright. John: stop mangling the title of the page. The page title belongs to the page; attach and the 10s sweep now inject only the cleanup build that strips any prefix an elder keeper still applies and kills its interval, the settings row is retired, and the doctrine is written down in the new dev-skills pup-page-integrity skill so it never comes back. Ownership signals stay on pup-owned surfaces only: taskbar tooltip, dashboard, extension hover, identity tile. Also replaces the dashboard header close-all icon, a bare X that read as close-this-dashboard, with a stacked-windows-with-x glyph and a tooltip spelling out that it closes every pup window, not the dashboard
Profile-consistency doctrine from John: every pup window ALWAYS opens on the shared adom-you profile, and isolation becomes reason-gated exactly like foregrounding — an explicit isolated:true without an isolationReason is refused with a teaching hint, while the two definitional cases, webSecurity false and the wiki public view, carry their own built-in reason. And a window that does run on an alternate profile now still shows an identity tile: a new anonymous variant with the pup four-dot mark set in the circular avatar inset, whose popup card explains the window is not signed in as you, so a not-you window is visible at a glance instead of just missing an avatar
Immediate relief for the initials badge John kept seeing over the pup toolbar icon. Investigation found the adom-you Chrome stays warm across bridge restarts, never reloads staged extensions, and currently hosts other AI threads windows, so it must not be relaunched; the new pup_quit_idle_browsers verb correctly refused. Instead the health endpoint renames the session owner field to ownerThread: the stale worker paints its badge from that field every 30 seconds, so the rename starves the retired badge within one sweep with zero disruption to running windows. Extension 0.2.4 readers use the new field; ownership itself now lives directly visible in the tab title prefix
Adds the pup_quit_idle_browsers maintenance verb: gracefully Browser.close every profile browser carrying zero live sessions, pup-native and never an OS process kill. Needed because pup keeps Chrome warm across window closes and bridge restarts, and a warm browser never reloads its staged extensions, so extension updates could not actually land without it. Rides with the 2.0.98 sweep title re-assert