This is the first release of PatchArc that you can install, run, and share from. It is also a release with visible seams, and we would rather list them than let you find them. Here is what 0.2.0 does end to end, what it only pretends to do, and what comes next.
What works end to end
Local loop
init: config, Ed25519 signing key (0600), SQLite session store,.gitignoreentries.start --detach: a background observer that records commits and touched files from Git plumbing on a 1.5-second poll, across branches and worktrees, with no hooks.note,decision,risk,checkpoint,status.stop: computes the deterministic six-section review and seals a.parc(canonical-JSON manifest, Ed25519 signature, per-file SHA-256, per-commit patches, scope index).verifyandinspect: seven offline checks; exit 1 on failure.scopesandscopes:graph: ten workspace detectors or explicit config.doctor: four environment checks.
Cloud
login: device flow with GitHub or Google approval; credentials at~/.patcharc/credentials.json(0600); refresh tokens hashed at rest and rotated on use.share: hash-checked upload, server-side re-verification of the signature and every file hash, publish, and an ArcLink with a random 96-bit slug and 30-day default expiry.- Share revoke (410), rotate, and expiry updates through the API; audit events for each.
- BYOK connections: provider keys envelope-encrypted inside an isolated key service with no public endpoint.
- Per-identity rate limits on the API.
What prints a message and exits
These commands exist so their names are stable, and do nothing else in 0.2.0: ai:add, ai:list, ai:use, ai:test, ai:usage, account, update, scopes:configure, preview, redact, revoke (prints the API endpoint), and open (prints the capsule path). serve exposes the verified review JSON on localhost but has no viewer page yet.
What exists but is not wired
- Redaction. The engine with 13 detectors, env-file rules, entropy scanning, forbidden paths, and custom regexes ships inside the CLI, but
stopdoes not call it. Capsules record your configured rules andredaction_applied: false. - Test parsing. No parser exists; the Verification section is zero.
- Agent adapters. Planned; commits are captured, transcripts are not.
- The hosted review. The pipeline verifies, extracts the sealed six-section review from the capsule, and publishes it; the ArcLink page renders the same review that lives in the capsule.
- Private and team links. Accepted by the API, no browser viewer; use public or capability.
- AI summaries. Wallet, ledger, and the key service exist; no summary reaches a link yet.
- Billing. Stripe is switched off; checkout returns a mock.
Two things we got wrong in our own docs
Earlier drafts of the website said the redaction engine ran at seal and that the product recorded test runs. Neither was true of the product. The site now says what the product does. If you find another gap, email hello@patcharc.dev and we will fix the page before we fix the feature.
Next
- Wire the redaction engine into
stop, with the report populated andredaction_applied: true. - Extract the full review from the capsule in the cloud pipeline and render it on the ArcLink page.
- Test-output parsing (JUnit first), so Verification stops reading zero.
- A non-interactive token for CI sharing.
- A viewer for private links, then teams.
Install from the docs; the CLI reference marks every print-only command.