# DIN CTRL / StreamDIN: full text > Data Integrity Network: provenance and recall for agent work Source: https://dinctrl.com/ . Every page listed in https://dinctrl.com/llms.txt; the console page's interactive panels read a synthetic demo field and are not reproduced here. ## DIN: the AI work-of-record DIN is the AI work-of-record. It captures what an AI agent actually did at the tool-call boundary, grades each claim as evidence-supported or asserted, and keeps that record on infrastructure you control. It is for teams whose agents do real work. DIN is prelaunch: the free build is one field and one AI, with no signup and no card. ### What is DIN? A log tells you the agent ran. It does not tell you whether its claims survived contact with the evidence. A transcript of a claim is still a claim, written in the same confident voice whether the work held or not. DIN keeps the grade: what was proved, what was only stated, and what was later contradicted. The record lives in a field: one canonical store per tenant, where records are placed by what they rest on rather than filed by date. It runs on a machine you control, and the field listens on that machine only: agents on the same machine connect through the plugin or the CLI, cloud chat history comes in through import, and hosted access is on the waitlist. ### How does DIN work? Five steps, the same for every producer, whether the work came from a Claude Code session or a Codex rollout: 1. Captured at the tool-call boundary. Not a summary the agent wrote about itself: the actual calls, kept while they happen. 2. Certified, claim by claim. Every claim carries a verdict: evidence-supported, or asserted. 3. Placed, not filed. A record is put where it belongs by what it rests on and what it is about. 4. Read before the next build. The next agent starts knowing what the last one established, and which parts of it held. 5. Followed forward. Take any claim and see everything built on top of it, with the part resting on unverified claims marked out. ### How does DIN grade a claim? Two questions, asked separately and never merged into one badge: how a record was obtained, and what it turned out to be worth. How it was captured is one of receipted, logged, inferred or mixed. What it proved is one of proved, asserted or refuted. A refuted claim stays in the record, marked, rather than being quietly removed. An inferred record never renders as a receipted one, anywhere in the console, at any zoom. Where the record cannot settle a position on its own, a person rules, with a name and a date on the stamp. ### What does DIN cost? One meter: fields. A field is a store, a team, a project, a client: one container of records, opened by one token. You are not billed for volume, for seats, for storage or for inference, and your model calls run on your own key, so there is no usage line. The free build is one field and one AI, with no signup and no card, and it is available to download today for Linux x86-64 and Windows x86-64. Paid plans are priced by number of fields, in USD per month. Self-hosted: Starter $29 (6 fields), Freelancer $99 (15), Team $199 (30), Small Business $299 (90), Agency $399 (90 fields across up to 5 orgs), and Enterprise I to V from $699 (180 fields) to $3,499 (1,000 fields). Hosted, where we run it: from $50 (Starter) to $4,999 (Enterprise V). Above 1,000 fields is quoted. DIN is prelaunch and no paid plan is on sale yet: the pricing page takes a waitlist signup, not a card. ### What can DIN read? DIN grades claims against the evidence that produced them, so the evidence must still exist. Eight sources import and grade today: Claude Code, Codex, Gemini CLI, Qwen Code, the Cline family, claude-mem, Grok, and Zep / Graphiti (through din-import-graphiti). Other tools that keep the original conversation (Letta, LangGraph, OpenAI Sessions, AWS AgentCore events, Azure Foundry conversations, Google Agent Engine, Supermemory, Khoj, Basic Memory, SpecStory) can be graded once a mapper for them ships. ChatGPT import is not supported yet. Tools that store only extracted facts cannot be graded, because the thing a grade would point at is gone. Live capture: the installer asks which agent to capture, Claude Code, Cursor or OpenCode (or takes --agent). Codex, Gemini CLI, Qwen, Cline and Grok are import-only. ### Frequently asked questions Q: Is DIN free? A: The free build is: one field, up to 3 people on one AI account (one AI at a time), with graded history import, live capture and the local dashboard, no signup and no card, running entirely on your own machine. Paid is the same download plus a key that turns on several agents on one field, more fields and the paid panels. DIN is prelaunch. Q: Where does my data live? A: On infrastructure you control: your laptop or your own box. The installer starts one server on loopback behind a token it mints on your machine, and the field listens on that machine only: agents on it connect through the plugin or the CLI, and cloud chat history comes in through import. Model calls run on your own key or your own local claude. Q: Which platforms does the free build run on? A: Linux x86-64 and Windows x86-64. There is no macOS binary yet, and the installer says so rather than failing halfway through a copy. Q: Is DIN open source? A: The Community Edition, the plumbing, is licensed Apache-2.0; its public repository is not published yet. The compiled grading engine and the commercial services are proprietary. Q: Are the records in this demo real? A: No. The console is real and running, and every count, trust mark and flag is read live from a field. The records in that field are invented: Northwind Trading Co. is a fictional company, nothing here is anyone's real data, and the console is read-only. ## Pages - DIN: the AI work-of-record for agent work | DIN CTRL (https://dinctrl.com/): DIN captures what an AI agent did at the tool-call boundary, grades each claim as evidence-supported or asserted, and keeps the record on your infrastructure. - Get DIN: open source, free build, or paid | DIN CTRL (https://dinctrl.com/get): Three ways into one product: read the open-source Community Edition, download the free build with no signup and no card, or add fields on a paid plan. - Download the free DIN build for Linux and Windows | DIN CTRL (https://dinctrl.com/download): The free DIN build: one field, one AI, no signup and no card, running on your own machine. Linux and Windows x86-64 releases with signed checksums. - DIN pricing: one meter, fields | DIN CTRL (https://dinctrl.com/pricing): DIN is priced by one meter: fields. No charge for volume, seats, storage or inference. The free build is one field and one AI; paid plans add fields. - DIN open source: the Community Edition | DIN CTRL (https://dinctrl.com/open-source): The DIN plumbing is open under Apache-2.0: read it, fork it, bring your own prompt. The compiled grading engine is proprietary, and the page says so. - What DIN can read: compatibility | DIN CTRL (https://dinctrl.com/compatibility): DIN grades claims against the evidence behind them. Which agent tools keep the original conversation and can be graded, and which keep only facts. - DIN docs: how it works, the family, pricing | DIN CTRL (https://dinctrl.com/docs): The DIN docs index: how capture, grading and recall work, what each member of the DIN family does, what it costs, and the three ways to get it. - How DIN works: capture, grade, place, recall | DIN CTRL (https://dinctrl.com/docs/how): DIN is the record of what an AI agent actually did: captured at the tool-call boundary, graded claim by claim, and kept on infrastructure you control. - The honesty grading: how DIN grades a claim | DIN CTRL (https://dinctrl.com/docs/grading): Two questions, asked separately and never merged into one badge: how a DIN record was obtained, and what it turned out to be worth once checked. - The blast radius: what breaks if one thing is wrong | DIN CTRL (https://dinctrl.com/docs/blast): What breaks if one thing is wrong, crossed with how much of what it touches nobody ever verified. The trust-weighted blast radius in DIN, explained. - The graded brief: decided, unproven, contradicted | DIN CTRL (https://dinctrl.com/docs/brief): One question asked across the whole record, answered in three parts: what was decided, what is still unproven, and what has been contradicted. - The review queue and the human stamp | DIN CTRL (https://dinctrl.com/docs/review): The positions the DIN record cannot settle on its own, laid out with both sides, and the human stamp, with a name and a date, that settles one. - The field and the tree: placed, not filed | DIN CTRL (https://dinctrl.com/docs/field): One canonical store per tenant, where every DIN record is placed by what it rests on and what it is about, rather than filed away by date. - DIN CTRL: trust marks and change impact | DIN CTRL (https://dinctrl.com/docs/dinctrl): DIN CTRL shows how each record was captured and what it proved, and the trust-weighted blast radius of a change. The governed bus is on the roadmap. - RecordDIN: write it | DIN CTRL (https://dinctrl.com/docs/recorddin): The write side of DIN: sessions, source, code and commits, captured at the tool-call boundary and certified before anything is written. - FieldDIN: place it | DIN CTRL (https://dinctrl.com/docs/fielddin): FieldDIN is the field itself: one canonical store where every record of agent work is placed by what it rests on and what it is about. - RecallDIN: remember it | DIN CTRL (https://dinctrl.com/docs/recalldin): RecallDIN is the read side, in real time: what your company already established, put back into the agent run that is starting now. - StreamDIN: see it | DIN CTRL (https://dinctrl.com/docs/streamdin): StreamDIN is the review layer: every piece of AI work laid out as it actually happened, marked by what the evidence behind it supports. - UpstreamDIN: recover the past | DIN CTRL (https://dinctrl.com/docs/upstreamdin): UpstreamDIN is the one-time import that fills a DIN field with everything from before there was a record: existing chats, transcripts and files. - DownloadDIN: ask it | DIN CTRL (https://dinctrl.com/docs/downloaddin): DownloadDIN is the analyst: one question across the whole record, answered as a short graded brief in an hour rather than a week. - Install DIN: verify the download, then install | DIN CTRL (https://dinctrl.com/docs/install): Install the free DIN build: which platforms are supported, how to verify the download with the published minisign key, and what the installer does. - Activate a paid DIN licence: din activate | DIN CTRL (https://dinctrl.com/docs/activate): How din activate turns a paid licence key into a signed entitlement, online or offline with --file, what it writes, and how to renew it. - Upgrade DIN to a new release | DIN CTRL (https://dinctrl.com/docs/upgrade): Upgrade DIN in place: stop the field, run the new release's installer, check it. Your records, field token and settings are kept. - Push your records to a hosted DIN field: din hosted | DIN CTRL (https://dinctrl.com/docs/hosted): How din hosted connects this machine to a hosted DIN console, pushes your records up and recalls them, and how agents and the dashboard sign in. - Uninstall DIN, and keep or remove your records | DIN CTRL (https://dinctrl.com/docs/uninstall): Remove DIN from a machine: stop the field, remove the plugin and the programs, and decide what to do with your records, which nothing deletes. - DIN command-line reference | DIN CTRL (https://dinctrl.com/docs/cli): The DIN command-line reference: the help text of din and every program in the free build, captured from the release's own programs. - DIN changelog: what changed in each release | DIN CTRL (https://dinctrl.com/docs/changelog): What changed in each published release of the free DIN build, newest first, stated from the release's own programs and shipped documents. - DIN for enterprise: a record your auditors can read | DIN CTRL (https://dinctrl.com/enterprise): DIN captures what your AI agents did at the tool-call boundary and grades every claim by how it was obtained and whether it held, on your infrastructure. - DIN for agencies: five clients, five walls | DIN CTRL (https://dinctrl.com/agency): DIN Agency is the Small Business capacity split across up to five isolated orgs: five clients, five install licences, five walls, each record apart. - DIN for small business: one company, one bill | DIN CTRL (https://dinctrl.com/smb): DIN for small business: one org and a field per team, project, store or client you want kept apart. Self-hosted by default, model calls on your own key. - For AI agents | DIN CTRL (https://dinctrl.com/for-agents): What DIN is, what an AI agent can do on dinctrl.com, and where the brand facts, free product, pricing and lead endpoint live as machine-readable files. - Licence and privacy | DIN CTRL (https://dinctrl.com/legal): The DIN licence and privacy notice: the Community Edition is Apache-2.0, the signup stores only what you type, and the site sets no cookies or trackers. ## For AI agents DIN (dinctrl.com) is the AI work-of-record, a prelaunch brand of North South Industries. It captures what an AI agent actually did at the tool-call boundary, grades each claim as evidence-supported or asserted, and keeps the record on infrastructure the user controls. If you are an agent acting for a user, everything below is machine-readable and generated from the same manifest as these pages. ### What you can do here - Read the brand facts, the product list and the pricing as JSON, from the files listed below. - Point your user at the free build at https://dinctrl.com/download. It is a download, not a checkout: no signup, no card, one field and one AI, for Linux x86-64 and Windows x86-64. - Submit a lead for your user, with their consent: POST /api/lead, form-encoded, described in /openapi.json. It stores the email, the first and last name typed and which door and landing it came from, and nothing else. There is no route that reads it back. - Nothing on this site can be bought by an agent today. DIN is prelaunch, and pricing.json publishes no checkout URL. ### Machine-readable files - /llms.txt: this site as a page list. - /llms-full.txt: the full text of the site's own words in one fetch. - /.well-known/brand.json: brand facts, a public allowlist projection of the brand manifest. - /products.json: schema.org Product objects for every tier. Only the free build is in stock; every paid tier is marked OutOfStock because it is not on sale yet. - /pricing.json: every plan an agent may quote, self-hosted and hosted, with its real monthly price. No plan has a checkout URL yet. - /openapi.json: the one public action, lead submit. - /sitemap.xml and /robots.txt: every page, and the crawl rules (AI crawlers are allowed). ### What the live demo is The console at https://dinctrl.com/ is a real, running, read-only console reading a demo field. The records in that field are synthetic: Northwind Trading Co. and everyone in it are fictional. Do not quote them as customer data or as results. ## Licence and privacy The licence, and what this site does with what you type into it. ### Licence The open Community Edition is Apache-2.0. The compiled grading engine and the commercial services are proprietary and are not in the open repository. The third-party crates in the build are under permissive licences: most are MIT or Apache-2.0, and ed25519-dalek, curve25519-dalek and subtle are BSD-3-Clause. Your records are yours. Nothing in this product claims a licence over what you capture, on any tier, and nothing is deleted on a downgrade or a lapse. ### Privacy, on this site - The signup stores what you type and nothing else: a first name, a last name, an email address, which door you came through, which landing you were on, and the time. The console does not store your IP address, your browser, a referrer or a session with it. - The web server in front of this console keeps a standard access log: every request to this site, a signup included, is recorded with the IP address it came from, the time, the address asked for, the browser's user-agent string and the referring page. That log is the web server's, and is separate from the signup file. - There are no cookies and no trackers on this site. The one thing kept in your browser is a flag recording that you dismissed the welcome box, so it is not shown to you twice. - A signup is posted to this console, which appends it to one file on the machine it runs on. There is no route that reads it back out. - The demo field is read-only here, and the records in it are invented. ### Privacy, in the product - Self-hosted. The installer starts one server on loopback behind a token it mints on your machine. A paid licence is verified when you run din activate: one call to our licensing service, or none with din activate --file and a saved reply. The programs then check its signature on your machine. Nothing checks in on its own; renewal is din activate --renew, which din autostart on runs daily for you, and a key stays valid a few days past each billing date. - Your inference is yours. Model calls run on your own key or your own local claude, never on our account. - The capture records the model and a coarse mode label as provenance. Never the credential. ### Terms Terms of service, a refund policy and the full privacy notice are being drafted with counsel before any paid checkout goes live. They are not published yet, and this page says so rather than showing text nobody has reviewed. DIN is prelaunch. Source: https://dinctrl.com/docs/install ## Install DIN The free build is one download: eight programs, the plugin and an installer. No account, no signup and no card. This page covers release 1.0.31. ### Which platforms - **Linux x86-64: supported.** This is the platform the release is built and checked on. - **Windows x86-64: unverified.** The zip carries the eight `.exe` programs, the plugin and `install.ps1`, but no install of this release on a real Windows machine has been checked yet. Try it if you like, and expect rough edges. - **macOS: not yet.** There is no macOS build. The Linux installer says so on a Mac and stops, rather than failing halfway through a copy. ### The one line ```bash curl -fsSL https://dinctrl.com/install | sh ``` That is steps 1 to 3 below, done for you, and it checks before it runs anything: 1. It refuses anything but Linux x86-64 by name (on a Mac: "DIN for macOS is not available yet"). 2. It reads `SHA256SUMS` from the [download page](/download)'s own directory. The archive's name, and so the version, comes from that list. 3. With `minisign` installed, it checks `SHA256SUMS.minisig` against the key printed below, which is written into the script and never fetched. Without it, it prints "signature not checked: install minisign to check it; the checksum was checked" and goes on. 4. It downloads the archive and stops unless its SHA-256 matches `SHA256SUMS`. 5. It unpacks the archive into a temporary directory and runs its `install.sh`, at your terminal, so the agent question below is still asked. Any mismatch: it deletes the temporary directory, installs nothing, and exits non-zero. It never uses sudo. You can read it first: open [dinctrl.com/install](https://dinctrl.com/install) in a browser. Every installer option works from the one line, after `sh -s --`: ```bash curl -fsSL https://dinctrl.com/install | sh -s -- --agent cursor curl -fsSL https://dinctrl.com/install | sh -s -- --prefix /opt/din --no-start curl -fsSL https://dinctrl.com/install | sh -s -- --path ``` `--path` is the one-liner's own option: it adds `export PATH="/bin:$PATH"` to your shell's profile (`~/.bashrc`, `~/.zshrc` or `~/.profile`). Without it, nothing is edited and the line is printed for you to run. On Windows (unverified), in PowerShell: ``` irm https://dinctrl.com/install.ps1 | iex & ([scriptblock]::Create((irm https://dinctrl.com/install.ps1))) -Agent cursor -Path ``` `-Path` adds `%USERPROFILE%\din\bin` to your user PATH. It checks the zip the same way and runs `install.ps1` with the options you gave. Or do it by hand, reading the archive before you run anything: ### 1. Download Everything is on the [download page](/download). The release is five files: ``` din-1.0.31-linux-x86_64.tar.gz the Linux build din-1.0.31-windows-x86_64.zip the Windows build SHA256SUMS the SHA-256 of both archives SHA256SUMS.minisig the minisign signature over SHA256SUMS minisign.pub the public key, also printed below ``` From a shell: ```bash curl -fsSLO https://dinctrl.com/download/din-1.0.31-linux-x86_64.tar.gz curl -fsSLO https://dinctrl.com/download/SHA256SUMS curl -fsSLO https://dinctrl.com/download/SHA256SUMS.minisig ``` ### 2. Verify the download Every release is signed with [minisign](https://jedisct1.github.io/minisign/). The public key (key id `36C9AB1B4CC4A458`) is printed here, not only shipped beside the download it vouches for: ``` RWRYpMRMG6vJNhzPUkYbbwTX9ebqgd1rW50Rlkv+/BZ4uAPzfda0KTqK ``` ```bash # install minisign first: apt install minisign / brew install minisign / scoop install minisign minisign -Vm SHA256SUMS -P RWRYpMRMG6vJNhzPUkYbbwTX9ebqgd1rW50Rlkv+/BZ4uAPzfda0KTqK # -> Signature and comment signature verified sha256sum --ignore-missing -c SHA256SUMS # -> din-1.0.31-linux-x86_64.tar.gz: OK ``` If either check fails, stop: do not run the installer. The installer does not check the signature for you. It checks only that all eight programs are present before it writes anything. On Windows, verify `SHA256SUMS` with minisign the same way, then compare the SHA-256 of the zip (for example `Get-FileHash -Algorithm SHA256 din-1.0.31-windows-x86_64.zip`) with its line in `SHA256SUMS`. ### 3. Install on Linux ```bash tar xzf din-1.0.31-linux-x86_64.tar.gz && cd din-1.0.31 sh install.sh export PATH="$HOME/din/bin:$PATH" din status ``` `din status` is the check that matters. It names every program, says whether the field is up, says whether your token opens it, and tells you what to type next. ### Pick your agent Run at a terminal, the installer asks which agent DIN should capture live: Claude Code, Cursor or OpenCode, one or several. Or say it up front with `--agent`, once per agent. With no `--agent` and no terminal (a script, a pipe) it wires Claude Code. - **Live capture:** Claude Code, Cursor, OpenCode. On the free build, one AI at a time; several agents on one field at once is paid. - **Import-only:** Codex, Gemini CLI, Qwen, Cline and Grok are import-only. `--agent codex` installs DIN, wires nothing live, and tells you `din import --source codex`. - **Graphiti and Zep:** read by `din-import-graphiti`, from a Graphiti or Zep endpoint you run. - **ChatGPT:** import is not supported yet. Pick several on the free build and each is still wired and captured, but the field serves one: the newest, with the others set aside and kept in full. The installer says so in one line. `din field activate ` switches which one is served; a paid plan keeps them all live together. To change your mind after the install, there is no need to run the installer again: ```bash din agent list # which agents are wired, and which one your field serves din agent add cursor # wire claude-code, cursor or opencode din agent remove cursor # unwire it; its records stay in your field ``` On the free build, `din agent add` first says what a second agent does and, at a terminal, asks before it wires anything (`--yes` to skip the question). The installer takes these options: ``` sh install.sh install into ~/din and bring it up sh install.sh --agent cursor which agent to capture live (repeat for several): claude-code, cursor, opencode sh install.sh --prefix /opt/din somewhere else sh install.sh --dry-run print every step, touch nothing sh install.sh --no-plugin skip the plugin: no agent is wired sh install.sh --no-start lay it down but do not start the field sh install.sh --port 8093 the field's loopback port sh install.sh --console-port 8097 the local console's loopback port sh install.sh --schedule also schedule the capture sweep (cron) ``` ### What the installer does - On an upgrade, if the field from the same install is running, stops it with `din field stop` first. If it does not stop, nothing is replaced. - Copies the eight programs into `~/din/bin`, and links `din-recall` to `din` (the name the plugin's `/din recall` looks for). - Copies `LICENSE`, `NOTICE` and `THIRD-PARTY-LICENSES` into `~/din/share/doc/din`. - Creates `~/din/records` (your records), `~/din/.din` (settings) and `~/din/logs`. - Mints a field token into `~/din/.din/field.token`, mode 600. No DIN program ever prints it. An existing token is never overwritten. - Writes `~/din/.din/field.env` with the field on `127.0.0.1:8093` and the console on `127.0.0.1:8097`. An existing file is left alone. - Writes the plugin's settings to `~/.din/plugin.env`, pointing it at this install. An existing file is left alone. - Starts the field on loopback with `din field start` and waits for it. - Wires the plugin into the agent you picked: Claude Code through its plugin installer, Cursor through its `hooks.json`, OpenCode through its plugin directory. Nothing in the install needs an API key. `din import` is the only step that calls a model, and it runs on your own key or your own `claude` CLI. ### Install on Windows (unverified) Unpack the zip, then from PowerShell in the unpacked folder: ``` powershell -ExecutionPolicy Bypass -File install.ps1 .\install.ps1 -Prefix C:\din .\install.ps1 -DryRun .\install.ps1 -Agent cursor,opencode .\install.ps1 -NoPlugin .\install.ps1 -NoStart .\install.ps1 -Port 8093 -ConsolePort 8097 ``` The default prefix is `%USERPROFILE%\din`. Windows has no mode bits, so the installer restricts the field token's ACL to your user with `icacls`, and says so if that fails. ### Next - [Activate a paid licence](/docs/activate), if you have one. The free build needs no activation. - [Upgrade](/docs/upgrade) to a later release. - [Uninstall](/docs/uninstall), and what happens to your records. - [Push your records to a hosted field](/docs/hosted), if you have a hosted plan. - [The command-line reference](/docs/cli). Source: https://dinctrl.com/docs/activate ## Activate a paid licence `din activate` turns a paid licence key into the signed entitlement file that the field, the console and the plugin read. The free build needs none of this: with no entitlement file an install runs as the free tier. DIN is prelaunch and no paid plan is on sale yet, so there are no licence keys to activate today. This page documents the command as it ships in release 1.0.31. ### Online ```bash din activate din activate - # the key read from stdin, so it stays out of your shell history din activate # re-activate with the key already saved in license.key ``` This needs `curl`. `din activate` checks the key in with the issuer (by default `https://api.dinctrl.com`, changed with `--url ` or `DIN_BILLING_URL`) and receives a signed entitlement in reply. The key is handed to `curl` on stdin, never on its command line, so it does not show in a process listing. ### Offline ```bash din activate --file ``` No network and no `curl`. The file is either the saved reply of a check-in (the JSON that `POST /api/license/verify` answered) or a bare signed envelope. On a machine that does have a network, the check-in `din activate` makes is: ```bash printf '{"key":"%s"}' '' | curl -sS -X POST -H 'content-type: application/json' --data-binary @- https://api.dinctrl.com/api/license/verify > reply.json ``` Carry `reply.json` to the offline box and pass it to `--file`. Where the bytes travelled does not matter: the signature is what is checked. ### Nothing is written unless it verifies Whatever arrives, from the network or from a file, is verified on your machine first, against the public key built into the program. It must verify, be in term, and say it is valid and entitled. Anything else is refused and nothing is written, so a bad activation never replaces a good file. ### What it writes - `/.din/entitlement.json` (by default `~/din/.din/entitlement.json`), which `din license` reads and which `din field start` and `din console` hand to the programs they start. - The same bytes to `~/.din/entitlement.json` (or `$DIN_HOME/entitlement.json`), the default a field or console started any other way, and the plugin, read. - If `DIN_ENTITLEMENT` (or `DASH_ENTITLEMENT`) names a file, that one file only. - After an online activation with a new key, the key is saved to `/.din/license.key`, so a later `din activate` on its own re-activates. Each file is written mode 600, through a temporary file and a rename, so a reader never sees half a file. ### When it takes effect The field re-reads the entitlement on its rescan tick (every 5 seconds by default), so the paid features switch on within seconds without a restart. A `din console` that is already running picks it up too: reload the page. It then shows your plan, what it includes, your agents and when the plan renews. `din license` shows the tier, and who decided it, at any time, and `din status` shows your plan, when it renews and your agents. ### Renewing A paid plan is billed by period, and each entitlement runs a few days past its period's billing date, so a renewal that lands a day late does not drop you to free. Your subscription gets a new key each period. While it is live and paid, the licensing service answers the key you saved with the current period's entitlement and the current key; `din activate` checks that key on your machine and saves it in place of the old one, so the next renewal presents a key from this period. ```bash din activate --renew # check the saved key in again; prints nothing when it works ``` `--renew` uses the saved key only (give it no key and no `--file`). When it cannot renew it prints one line saying why, writes nothing, and the entitlement you have stays in place. To have it done for you, run `din autostart on` (per user, no admin). On a paid install the login entry also runs `din activate --renew`: with systemd, two minutes after login and then daily; on Windows at logon and in a daily task named "DIN renew"; with a plain XDG autostart entry, at each login. If autostart was already on before you activated, `din activate` adds the renewal to it and says so. `din autostart off` removes it all. Without autostart, nothing on your machine checks in on its own, on a timer or at start-up; the programs only check the signature locally. `din license` and `din status` show when the entitlement expires, and in its last week `din status` says how to renew. Run `din activate --renew`, or `din activate` with the new key from your account page, or `--file` with a saved reply, offline. If the entitlement has expired, activation says so ("renew, then activate again"). A hand-edited entitlement, another key's signature, or a lapsed term is read as the free tier. Nothing in your records is deleted on a lapse. ### Related - [Install](/docs/install) - [The command-line reference](/docs/cli) - [Push your records to a hosted field](/docs/hosted) - [Pricing](/pricing) Source: https://dinctrl.com/docs/upgrade ## Upgrade DIN An upgrade is a new install over the old one: stop the field, run the new release's installer, and check the result. Your records, your token and your settings are kept. ### Why stop the field first From 1.0.30 the installer stops a field from the same install that is still running before it replaces the programs, then starts the new one (unless you pass `--no-start`). Installers before 1.0.30 did not: with those, the old field kept serving and `din field start` reported it was already up. Stopping it yourself first is harmless with any release, so the steps below keep it. ### Steps 1. See what you run now: ```bash din version ``` 2. Stop the field. If you have `din console` running in a terminal, stop that too (Ctrl-C in its terminal). ```bash din field stop ``` 3. [Download and verify](/docs/install) the new release, unpack it, and run its installer with the same options you used the first time (for example the same `--prefix` or `--port`): ```bash tar xzf din--linux-x86_64.tar.gz && cd din- sh install.sh ``` The installer starts the field again when it finishes. If you install with `--no-start`, start it yourself: ```bash din field start ``` 4. Check it: ```bash din version din status ``` ### What is kept - `~/din/records`: your records. The installer never deletes or rewrites them. - `~/din/.din/field.token`: an existing token is never overwritten, so your field opens with the same token. - `~/din/.din/field.env`: an existing settings file is left alone. To pick up a new default, delete it and install again. - `~/.din/plugin.env`: the plugin's settings, left alone if present. - `~/din/.din/license.key` and the entitlement files [`din activate`](/docs/activate) wrote: the installer does not touch them. - The login entry `din autostart on` made, if you turned it on. It runs `~/din/bin/din`, so from the next login it runs the new release. - `~/din/.din/hosted.env`, if you ran `din hosted connect`. ### What is replaced - The eight programs in `~/din/bin`, and the `din-recall` link. - The plugin payload in `~/din/plugin`. The plugin's installer runs again for the agent you pick (Claude Code, Cursor or OpenCode; see [Install](/docs/install)). ### Windows The same order applies: `din field stop`, then the new release's `install.ps1`, then `din status`. Windows installs of this release are unverified. ### Related - [Changelog](/docs/changelog): what changed in each release. - [Uninstall](/docs/uninstall) Source: https://dinctrl.com/docs/hosted ## Push your records to a hosted field A hosted DIN field keeps your records on our servers and gives you a dashboard and an agent read door for them, reachable from anywhere. Capture and grading still happen on your own machine, with your own model key: DIN never runs inference for you. Your install produces the records, and `din hosted push` sends them up. DIN is prelaunch and no hosted plan is on sale yet. This page documents how the commands work for when they are. ### What you need - A hosted DIN console address (for example `https://din.example.com`), from your hosted plan. - An agent token for that console, saved in a file only you can read. - `curl` on the machine that pushes. `din hosted` talks to the console through it. Put the token in a file and make it private. The file holds one line: either the token alone, or `name:token`, the same format the console's own token list uses. ```bash printf 'laptop:%s\n' '' > ~/.din-hosted.token chmod 600 ~/.din-hosted.token ``` A token file that other users can read is refused. ### Connect ```bash din hosted connect https://din.example.com --token-file ~/.din-hosted.token ``` This checks that the address is a hosted DIN console and that it accepts the token for a read. It then saves the address and the token file's path in `/.din/hosted.env` (mode 600). The token itself is not copied anywhere. It is read from its file on each call and handed to `curl` on stdin, never on its command line, so it does not show up in a process listing. `din hosted` never prints it. Only `https://` addresses are accepted. The one exception is `http://` to this machine (`127.0.0.1` or `localhost`), because anywhere else plain http would send the token unencrypted. ### Push ```bash din hosted push --dry-run # count what would be sent; sends nothing din hosted push # send everything stored since the last push din hosted push --since 2026-09-01 ``` A push reads the records this install has stored, the same store the capture plugin writes to, through the store's own `MANIFEST.jsonl`. It sends them 100 at a time. Each record is sent exactly as it is stored, with its store id added. For each record the console answers one of three things: - `new`: it is now on the hosted field. - `unchanged`: it was already there. Pushing the same record twice never makes a second copy. - `refused()`: it was not stored, and the push says why. `invalid` means the local store's own rules reject it. `regime` means its grade has no code on the hosted field. `cap` means the field is full. `door` means the hosted service could not be reached. The push remembers how far through the manifest it got, so the next push sends only what is new. It stops at the first `cap` or `door` refusal and keeps that record and everything after it for the next push, so nothing is skipped. `--since` sends everything stored from that date or time again. Records already on the field come back `unchanged`, and a `--since` push does not change where the next ordinary push starts. A hosted field holds a fixed number of records, set by its plan. `din hosted status` shows how many it holds against that cap. ### Keep it current Nothing pushes on its own. Pick one of these: - Run `din hosted push` yourself when you want the hosted field current. - Schedule it. With cron: `*/30 * * * * din hosted push >> ~/din-hosted-push.log 2>&1`. On Windows, add a Task Scheduler task that runs `din hosted push`. - Push at login. `din autostart on --with-push` starts the field at login as `din autostart on` does, and also runs `din hosted push`. It needs `din hosted connect` first. `din autostart off` removes it. ### Status and recall ```bash din hosted status din hosted recall "journey planner latency" ``` `status` shows the console address, the token file's path, when the last push ran and what it sent, how many local records have not been pushed yet, and how many records the hosted field holds against its cap. `recall` asks the hosted field with the same token and prints each hit with its grade and a short excerpt. ### For agents calling the console directly Every `/api/*` route on a hosted console except the health probe `/api/healthz` needs `Authorization: Bearer ` (or, for reads, the browser session described below). Without either the answer is `401` with `WWW-Authenticate: Bearer realm="din"`. A token that is sent and wrong is a `401` even from a signed-in browser. - `GET /api/recall?q=&k=` for recall. - `GET /api/query?...` for filtered rows. - `GET /api/record/` for one record, body included. - `POST /api/records` writes one record (a JSON object) or a JSON array of up to 100. The answer lists, in order, each record's `id`, its `status` (`new`, `unchanged` or `refused`) and, when refused, its `reason` and `detail`. A record pushed this way needs `"id"` set to its store id, which `din hosted push` adds for you. Only an agent token writes: a browser session gets `403` here. ### The dashboard The hosted dashboard is opened from your customer portal, not with the agent token. Sign in to the portal and choose "Open your hosted DIN". The portal hands your browser a one-time sign-in link, and the console sets its own session for 8 hours. After that, open it from the portal again. Opening the console address directly without a session shows a page that sends you to the portal. The session lets you read everything the dashboard shows. It does not write records; `din hosted push` does. An agent token opens the `/api/*` routes, not the dashboard pages. ### Related - [Install](/docs/install) - [The command-line reference](/docs/cli) Source: https://dinctrl.com/docs/uninstall ## Uninstall DIN Everything DIN installs is in three places, and one of them is your records. Read which is which before you delete anything. ### 1. Stop the field ```bash din field stop ``` If you ran `din autostart on`, remove its login entry now, while `din` is still installed. It removes exactly what `on` wrote (the systemd user unit and renewal timer, the XDG autostart entry, or the Windows logon tasks) and nothing else: ```bash din autostart off ``` ### 2. Remove the plugin The plugin ships its own uninstaller: ```bash sh ~/din/plugin/install/uninstall.sh ``` It removes the scheduled capture sweep from your crontab if you set one up with `--schedule`, takes DIN's entries out of Cursor's `hooks.json` and DIN's file out of OpenCode's plugin directory (anything else there is left alone), uninstalls the Claude Code plugin, and removes the plugin's programs. It does not delete your captures or config unless you pass `--purge`. ``` sh uninstall.sh remove the plugin and the cron sweep sh uninstall.sh --keep-plugin remove the sweep only sh uninstall.sh --purge also delete the captures and the config ``` To remove the Claude Code plugin by hand instead: `claude plugin uninstall din@din`. On Windows the same folder carries `uninstall.ps1`. The scheduled sweep can also be removed by hand: ```powershell schtasks /Delete /TN "DIN capture" /F ``` ### 3. Remove the install ```bash rm -rf ~/.din # the plugin's own state: config, spool, run directories rm -rf ~/din/bin ~/din/logs ~/din/plugin ~/din/share ~/din/.din ``` `~/din/.din` holds the field token and settings, and the licence key and entitlement if you activated one. `~/.din` holds the plugin's settings and its copy of the entitlement. ### 4. Your records **`~/din/records` is your data.** Nothing above removes it, and this page does not give you a command for it, because it is the one directory whose loss you cannot undo. To keep it, this is the whole backup: ```bash tar -czf din-records.tar.gz ~/din/records ``` A store is files, there is no database, and a new install pointed at it reads it straight back. If you want it gone, it is an ordinary directory of JSON files. ### What is not on your machine There is no account to close for the free build: the installer creates none, and the field, the console and the capture run on your machine, on loopback. Records you sent to a hosted field with `din hosted push` are on that hosted field: uninstalling here does not remove them. ### Related - [Install](/docs/install) - [Upgrade](/docs/upgrade) Source: https://dinctrl.com/docs/cli ## Command-line reference Release 1.0.31. Every block on this page is what the program printed for `--help` (or the named command), captured from the 1.0.31 Linux build. The download carries eight programs; `din` is the one you type, and it runs the field, the console, the importer and the dependency audit for you. ### din ``` din - your own field, on your own box. Nothing leaves your machine. USAGE din status: is the field up, what is in it, next steps din setup --isolated a NEW field of your own in a tree of your own: own token, own store, own auto-picked loopback port, started without root, Postgres or systemd. --port auto|N --prefix DIR --dry-run --force din field start start the field on loopback and wait for it din field stop stop the field this install started; it stays stopped (nothing starts it on its own) until `din field start` din field status ask the field how it is din field ensure start it if it is down and was not stopped on purpose (what every verb below does first) din autostart on|off|status also start it at login: a systemd user unit or XDG entry, a LaunchAgent, or a hidden logon task. Per user, no admin. `off` removes what `on` made. `on --with-push` also runs `din hosted push` at login (a hosted console must be connected). din field log [-n N] the last N lines of the field's log din field binding which field is ACTIVE, which are archived and KEPT din field activate bring an archived field back, whole (one at a time) din agent list which agents are wired here, and which one your field serves (ACTIVE) or has set aside (ARCHIVED) din agent add [--yes] wire claude-code, cursor or opencode with the plugin's own installer. On free it says first what a second agent does and asks at a terminal. din agent remove unwire it; its records stay in your field, kept din console [--no-open] run the LOCAL console on loopback din import [args...] the Upstream on-ramp (din import --dry-run first) din recall the compact, trust-marked digest din query rows as TSV: facet=claims&state=disputed din brief the graded brief: decided / unproven / contradicted din dep-audit [args] dependency risk: what your code REALLY imports, crossed with whether the upgrade was ever shown. JSON by default; --tsv for the human table. READ-ONLY - it never writes the store. din plugin install [args] install the Claude Code plugin from this bundle (also installed as `din-recall`, which the plugin's /din recall calls by that name) din activate check a paid license key in (needs curl) and install the signed entitlement it earns; it is verified here first, or nothing is written. `din activate -` reads the key from stdin. din activate --file the same OFFLINE, from a saved check-in reply din activate --renew carry a paid install into its new billing period from the saved key; silent when it works. `din autostart on` runs it for you. din license what tier this install runs as, and who decides din where every path and setting, resolved din hosted connect|push|status|recall ONLY if you have a HOSTED DIN console: push this install's records to it (the one command that sends records off this machine, and only when run). `din hosted help` for the details. din version OPTIONS --project P --since D --until D scope recall, query and brief to one project or a date window (dates are YYYY-MM-DD) --k N recall: how many hits (1..50) --json machine-readable, same rows, same grades. On `din status` it is one JSON object with the programs, the field, the token and the plugin - the headless way to check an install. Exit 0 = usable, 1 = incomplete. --timeout-ms N give up on the field after N ms (default 8000) START ON USE status, console, recall, query, brief, field binding|activate and import --status start the field first when it is down, the same way `din field start` does, and say so on stderr. Not after `din field stop`, never on a port something else holds, and not with DIN_FIELD_AUTOSTART=off. WHERE IT LOOKS $DIN_PREFIX, else the prefix this binary was installed into, else ~/din. Settings come from /.din/field.env; the process environment wins over it. `din where` prints what was resolved and from where. ($DIN_HOME is NOT this. That one is the plugin's own state directory.) ``` ### din activate See [Activate a paid licence](/docs/activate). ``` USAGE din activate check the key in with the issuer and install the signed entitlement it answers with (needs curl) din activate - the same, the key read from stdin (keeps it out of your shell history) din activate the same, with the key saved in license.key din activate --file OFFLINE: install a saved check-in reply (the JSON POST /api/license/verify answered) or a bare signed envelope. No network, no curl. din activate --renew check the saved key in again: carries a paid install into its new billing period. Prints nothing when it works, one line when it does not. `din autostart on` runs it once a day. --url the issuer, default https://api.dinctrl.com (DIN_BILLING_URL sets it too) Nothing is written unless the signed entitlement verifies on this box. ``` ### din setup --isolated ``` din setup --isolated - your own field, in your own tree, with no admin. USAGE din setup --isolated [--port auto|N] [--prefix DIR] [--force] [--dry-run] WHAT IT LAYS DOWN, under the prefix (default: this install's prefix, else ~/din) .din/field.token a freshly minted token, 0600, never printed .din/field.env the settings, so `din recall` in this tree asks THIS field .din/field.pid the running daemon, written after the kernel is asked records/ an empty store. This field serves these and nothing else. logs/field.log field.sh start | stop | restart | status | log README-FIELD.md how to run it, in the tree, so it travels with the tree OPTIONS --isolated required. The one recipe this command has. --port auto|N auto (the default) scans for a free loopback port. A number is used as given, and refused if it is taken. --console-port N the same, for `din console` in this tree. --prefix DIR where the tree goes. --programs DIR where the programs are, when this tree borrows them from an install elsewhere. Default: this install's bin/. --force re-mint the token over an EXISTING field at this prefix. Records are never deleted; the old token is kept beside the new one as field.token.previous. --no-start lay it down, do not start the daemon. --dry-run print every step, touch nothing. NO ROOT. NO POSTGRES. NO SYSTEMD. One loopback port, one token, one daemon started by the user who will use it. It does not touch any other field. NOT THE PROVISIONER. `provision-instance.sh` stands up a whole INSTANCE: a database, a service manager, a machine. This makes a workspace its own private field on a box that already works. If you are reaching for the provisioner to get a tree of your own, this is the command you wanted. ``` ### din import (din-import) `din import [args...]` runs `din-import` with the same arguments. ``` din-import - point DIN at your chats and it works. Bare `din-import` runs the wizard. It looks before it asks, it tells you what an import will cost before it starts, and it runs the review on your own inference: your own API key by default, or your own local Claude if you pick that instead. DIN never runs model calls on our account. USAGE din-import wizard (default entry point) din-import --source claude-code [--path P] detected sessions on disk din-import --source codex [--path P] Codex rollouts on disk din-import --source gemini-cli [--path P] Gemini CLI sessions on disk din-import --source chatgpt --export P the data-export zip or directory din-import --source grok --export P Grok chats in an X (Twitter) archive din-import --source cline [--path P] Cline, Kilo Code or Roo Code tasks din-import --source qwen [--path P] Qwen Code sessions on disk din-import --source claude-mem [--path P] a claude-mem store's JSONL spine din-import --source upload --file P generic, against the record contract din-import --source inbox whatever you dropped in ~/din/inbox din-import --dry-run the plan and a sample record, no calls din-import --apply run it for real, on your own inference din-import --model pick the review model din-import --max-spend pause and ask at this running estimate din-import --status progress, running cost, state din-import --pause | --resume | --stop process control din-import --log the verbose log for bug reports din-import --advanced print the plan, run nothing din-import --workers override concurrency din-import --tools show the tooling this wrapper drives WHERE YOUR CHATS GO ~/din/inbox. Drop exported conversations there and run din-import: the inbox is scanned on every run, offered like any other source, and each file in it is either read or named with the reason it cannot be. The directory and a short guide (README.txt) are created the first time this runs. $DIN_HOME/inbox if that is set, $DIN_INBOX if you set that. OTHER FLAGS --limit consider at most this many conversations --home state directory (default $DIN_HOME or ~/.din/import) --field the record store this import writes into --prompt the interpretive contract to use instead of the one this build ships. Bring your own: it is sent verbatim, exactly as the shipped one is. Also settable as DIN_PROMPT --run operate on this run id instead of the latest --yes answer yes to every confirmation (scripting) --retry-escalated with --resume: try again a run that stopped retrying after your provider refused it repeatedly --stagger seconds between worker starts (default 15) -h, --help this -V, --version version DRY RUN IS THE DEFAULT WHEN NOBODY IS THERE TO ASK Run without a terminal and without --apply and you get the dry run: the plan, the estimate, and a sample of the record this import would build, with no model call and nothing written to your field. --apply is how you say go. Interactive runs still ask on the cost screen instead. WHAT IT COSTS Nothing to us. The review runs on your own key or your own account and the bill goes to your provider. --dry-run prints the estimate and imports nothing. ``` ### din dep-audit (din-dep-audit) `din dep-audit [args]` runs `din-dep-audit`, passing its flags through. From `din` the report is JSON by default; `--tsv` asks for the table. ``` usage: din-dep-audit [-h] [--store STORE] [--json] [--top TOP] [--origin {external,stdlib,internal,unknown,all}] [--lang LANG] [--dep DEP] [--stale-days STALE_DAYS] [--evidence] [--out OUT] [--fail-over FAIL_OVER] [--now NOW] Dependency risk from the call graph crossed with the honest record. READ-ONLY: it never writes the store and never touches code. options: -h, --help show this help message and exit --store STORE the durable record store dir (else $STORE). No baked-in default. --json the full report as JSON (schema din-dep-audit/1) --top TOP rows to print (default 20; 0 = all) --origin ORIGIN which origins to report (default external; repeatable) --lang LANG restrict to a language (repeatable) --dep DEP restrict to a named dependency (repeatable) --stale-days DAYS no activity in the record for this long = quietly unmaintained (default 120) --evidence in TSV mode, print the cited claims/experiments under the table --out OUT write the report here instead of stdout - the ONLY path this tool writes --fail-over RISK exit 3 if any reported dependency scores above this risk (a CI gate) --now NOW fix 'now' for reproducible output (tests) ``` ### din-record The record producer. The plugin uses it to turn a session into records. ``` usage: din-record --run RUN [--model MODEL] [--no-model] [--repo-root REPO_ROOT] [--prompt PROMPT] [--timeout TIMEOUT] [--org-node ORG_NODE] [--by BY] [--by-kind {person,org,unknown}] [--project PROJECT] DIN CTRL receipted record producer (Rust port of receipt/record.py) options: --run RUN run dir, e.g. runs/46 --model MODEL model for the ONE interpretive call --no-model observed facets only (honest-failure path, no model call) --repo-root PATH where the FROZEN contracts live (default: two levels up) --prompt PATH the interpretive contract to use, overriding --repo-root. Without it: DIN_PROMPT, then /PROMPT-...-v1.md, then the sealed din-contract provider. --timeout TIMEOUT --org-node ORG_NODE org node id for the run's channel (e.g. echoron) --by BY identity.by id - who this run is attributed to --by-kind KIND kind for --by (default person) --project PROJECT project_affiliation.primary for this run. Without it: the base name of --repo-root when one is given, else the run's own label (DIN_CHANNEL, else the base name of the session cwd in /meta.json), else empty. ``` ### dinctrl-store The one writer that places records in the store. ``` dinctrl-store - DIN CTRL durable record store USAGE: dinctrl-store ingest --runs --store [--b6-patterns FILE] dinctrl-store check-ids --store dinctrl-store backfill-transcripts --store [--runs ] [--write] [--b6-patterns FILE] [--b6-strict] dinctrl-store backfill-transcripts --refilter --store [--write] [--b6-patterns FILE] [--b6-strict] OPTIONS: --runs runs/ root to scan: /*/record.json and /*/records/*.json --store durable store dir; records land in //.json --write backfill-transcripts only: write, instead of listing --refilter backfill-transcripts only: re-derive EXISTING sidecars through the personal-content filter and the table --b6-patterns FILE personal-content policy (default $DIN_B6_PATTERNS, else b6-patterns.json beside this binary or in ../scripts/, else the built-in copy), as din-session-record finds it --b6-strict backfill-transcripts only: redact the ambiguous shelf too -h, --help show this message ingest writes //.transcript.txt beside each new conversation record whose run has a session.jsonl: the session's text, credentials redacted, capped at DIN_TRANSCRIPT_MAX_BYTES (default 2 MiB). The field searches it, so a record made without a model is found by what was said. Personal content goes first: the producer's B6 filter runs over the text, set from the record's provenance.b6 (always on when the record was filtered; otherwise on unless DIN_B6=0). When B6 cannot run, NO sidecar is written for that record and it is counted; the unfiltered text is never written. backfill-transcripts is READ-ONLY unless --write. It lists every conversation record with no sidecar whose run (identity.path, else /) still holds the exact session.jsonl the record was made from, and with --write writes those sidecars, filtered as ingest filters them. Exit 1 when read-only and some are missing, or when B6 could not run for some. backfill-transcripts --refilter is READ-ONLY unless --write. It runs every existing //.transcript.txt (and /.transcript.txt) through B6 and the table, using the record beside it when there is one, and lists (with --write rewrites) only those whose bytes change. It needs no run, so may be a quarantine copy. It never touches a record or the manifest. Exit 1 when any would change or B6 could not run for any; with --write, 1 when B6 could not run for any or a write failed. check-ids is READ-ONLY. It lists every stored code record whose file is named by the old content-hash-only id, which a re-ingest by this build would store a second time under its new id. Exit 0 when there are none, 1 when there are. ingest itself never stores such a record twice: a code record whose file is absent under its new id, but present under its legacy id with the same card and content hash (check-ids' own test), is left alone, printed as `~`, and counted as `legacy present` in the summary. No file is renamed, rewritten or deleted and no manifest line is added for it. PHASE 1: no sqlite index and no git staging are performed. ``` ### din-contract ``` din-contract - the sealed interpretive contract provider din-contract write the contract to stdout din-contract --check open the blob and report on it, WITHOUT printing it din-contract --sha256 the sha256 of the contract, and nothing else din-contract --help din-contract --version The contract is compiled into this binary as an encrypted blob. It is written to stdout so a caller can capture it; it is never written to a file here and never reaches the customer's disk through this program. Refuses to write to a terminal unless you pass --to-terminal, so that a stray invocation in a shared shell, a screen share or a CI log does not print the contract into a scrollback buffer nobody meant to fill. ``` ### streamfieldd and dind-console The field server and the local console. They print no help: each needs its token in the environment, and `din field start` and `din console` start them with it. Run without one, each says what it needs: ``` streamfield: FIELD_TOKEN is required (env only, never hardcoded) ``` ``` dind-console: DASH_FIELD_TOKEN is required - it is this tenant's own field token. usage: DASH_FIELD_TOKEN= ./dind-console (run.sh reads it from a 0600 file) ``` ### Versions Every program answers `--version`: ``` din 1.0.31 din-contract 1.0.31 din-dep-audit 1.0.31 din-import 1.0.31 din-record 1.0.31 dinctrl-store 1.0.31 dind-console 1.0.31 streamfieldd 1.0.31 ``` ### Related - [Install](/docs/install) - [Activate a paid licence](/docs/activate) - [Push your records to a hosted field](/docs/hosted) Source: https://dinctrl.com/docs/changelog ## Changelog What changed in each published release of the free build, newest first. Each entry is stated from the release's own programs and the documents shipped in its download. ### 1.0.31 - **Your plan, your agents, one command away.** `din status` and `/din status` show your plan, when it renews, and your agents: which one your field serves, which are set aside, or, on a paid plan, all of them live together, with the exact command to switch. `din agent list`, `din agent add ` and `din agent remove ` wire Claude Code, Cursor or OpenCode after the install; removing an agent keeps its records. See [Install](/docs/install). - **Paid features without a restart.** After `din activate`, a running local dashboard turns the paid features on when you reload the page. It shows your plan, what it includes, your agents and your renewal date, and locked panels link to the plans. See [Activate a paid licence](/docs/activate). - **Renewal that does not lapse.** Each entitlement runs a few days past its billing date. `din activate --renew` carries a paid install into its new period with the saved key, silently when it works, and `din autostart on` runs it for you daily. A paying install does not drop to free at a period boundary. - **Messages name the command to type.** The field's messages say `din field activate ` or `din activate `, never an API path. - **Hosted DIN commands, for when hosting opens.** `din hosted connect | push | status | recall` push this install's records to a hosted DIN console with an agent token and ask it. Capture and grading stay on your machine, with your own model key, and nothing is sent until you run `din hosted push` (or turn on `din autostart on --with-push`). No hosted plan is on sale yet. - **Long sessions reach memory while still open.** Capture writes a checkpoint record every 30 minutes of an open session (`DIN_CHECKPOINT_SECS`, `DIN_CHECKPOINT_TURNS`; `0` turns it off). Each checkpoint replaces the last, and the final record replaces them all. `din-capture status` shows open sessions not yet recorded. - **Find a conversation by an exact phrase.** The store keeps a redacted transcript beside each conversation record, and the personal-content filter runs over it before anything is written. `dinctrl-store backfill-transcripts` adds missing transcripts to an existing store, and `--refilter` re-checks the ones already written; both only report unless given `--write`. - **Coverage in `/healthz`.** A `coverage` block reports records indexed, transcripts present, sessions captured, records stamped and project labels mapped, each as a number over a stated total, and `coverage_alarms` lists any rate below `FIELD_COVERAGE_ALARM_PCT` (default 90). - **Organisations kept apart.** A record can belong to several organisations (`FIELD_RECORD_ORGS` takes a list), `FIELD_RECORD_ORG_OVERRIDES` corrects ownership after a re-organisation, and `streamfieldd --org-report` lists unmapped project labels with suggested aliases, read-only. - **Recall prefers the current decision.** Decisions recorded in several versions are linked, and for "what do we use now" questions the newer version is preferred. On by default; each weight is a `FIELD_RECALL_*` setting. No recall figures are quoted for this release until it is measured. - **Also new:** `din-import --retry-escalated` retries a run that stopped after your provider refused it repeatedly, and `din-record --project` sets a run's project. See [the command-line reference](/docs/cli). ### 1.0.30 (2026-09-30) - **One-line install.** `curl -fsSL https://dinctrl.com/install | sh` (on Windows, `irm https://dinctrl.com/install.ps1 | iex`). It checks the release checksum, and the signature too when `minisign` is installed, refuses on any mismatch and never uses sudo. See [Install](/docs/install). - **Your field is up whenever you use DIN.** Any `din` command that needs the field, or a new Claude Code, Cursor or OpenCode session, starts it if it is not running. No service is installed, and `din field stop` is respected until you run `din field start`. Optional: `din autostart on` starts it at login, per user, with no admin rights. - **You are told when capture stops.** `/din status`, `din status` and the local dashboard show when the last capture was, and warn when there has been none for 24 hours (`DIN_CAPTURE_WARN_HOURS` changes that). - **Pick your agent at install.** The installer asks which agent to capture live: Claude Code, Cursor or OpenCode (`install.sh --agent claude-code|cursor|opencode`, repeatable; `install.ps1 -Agent cursor,opencode` on Windows). With no terminal and no flag it wires Claude Code, as before. Codex, Gemini CLI, Qwen, Cline and Grok are import-only, and the installer says so. See [Install](/docs/install). - **Each agent is its own source.** Live capture and imports of each agent's history land in that agent's own field. On the free build (one AI at a time) your imported Claude Code history and your live Claude Code capture are one field. - **New in the download: `din-import-graphiti`**, which imports from a Graphiti or Zep endpoint you run. - **Licence texts in the download.** `NOTICE` now states exactly what ships: eight programs, which of them link third-party crates and which use only the Rust standard library, and the licence of each crate. A new `THIRD-PARTY-LICENSES` file at the root of both archives carries the full licence text of every third-party crate the programs are built from. The installers copy `LICENSE`, `NOTICE` and `THIRD-PARTY-LICENSES` to `share/doc/din/` in the install prefix. - **Upgrades stop the running field.** If a field from the same install is running, the installer stops it with `din field stop` before replacing the programs, then starts the new one (not with `--no-start`). If the field does not stop, nothing is replaced. See [Upgrade DIN](/docs/upgrade). - **Recall finds more, and says when it cannot.** On the operator's real 12k-record corpus (227 blind questions, compared with 1.0.29), the right answer is in the top five for 67.5% of answerable questions (was 44.2%), 77.5% of "why did we..." questions (was 50.0%), 63.6% of known-item lookups (was 39.8%) and 13 of 25 code questions (was 0), at a median 0.66 s. When nothing matches with confidence, recall answers "not in memory" instead of guessing. Every ranking weight can be set per query or in the field's environment. - **Health you can check.** `/healthz` now shows how many store files were indexed and why any were not, record counts by class, which machines have gone quiet, and how long a capture takes to reach memory. - **More secrets removed before storage.** Capture and `din import` now also strip private-key blocks (the whole key, not just its first line), OpenAI project, service and admin keys, Hugging Face, SendGrid, DigitalOcean and Slack app tokens, Azure storage keys, secret values in lowercase and JSON/YAML assignments (the name is kept, the value is removed), and `Authorization: Basic` credentials. - **`din field stop` checks before it stops.** It signals the recorded process only when that process is the field listening on the field's port. A stale pid file is cleaned up and nothing else is touched. - **Any install location.** The installer works with install prefixes and config directories that contain spaces or apostrophes. - **Shipped documents corrected.** README, QUICKSTART, TIERS and UNINSTALL now say: plugin capture is graded `logged`; the licence is verified when you run `din activate` and renewed by running it again with the new key; the programs verify the signed entitlement; `din import` and the why-layer call your own model provider and `din activate` calls `api.dinctrl.com`; Linux is the verified platform, Windows is unverified, macOS is not yet available. ### 1.0.29 (2026-09-26) - **New: `din activate`.** Turns a paid licence key into a signed entitlement: online with `din activate ` (or `din activate -` to read the key from stdin), or offline with `din activate --file ` from a saved check-in reply. Nothing is written unless the entitlement verifies on the machine. See [Activate a paid licence](/docs/activate). - **The entitlement is verified on your machine.** `din`, the field and the console check the signed entitlement against a public key built into the programs. A hand-edited file, another key's signature or a lapsed term is read as the free tier. - **Quickstart:** lists the working importers (`claude-code`, `codex`, `gemini-cli`, `qwen`, `cline`, `claude-mem`, `grok`, `upload`, `inbox`) and documents Cursor and OpenCode capture, wired in with the scripts the plugin ships. ### 1.0.28 (2026-09-25) - **Every program answers `--version`**, and all eight report the release they shipped in. - **Signed releases.** `SHA256SUMS` is signed with minisign and ships beside the archives as `SHA256SUMS.minisig`, with the public key `minisign.pub` (key id `36C9AB1B4CC4A458`). The key is also printed in the README, the quickstart and the [install page](/docs/install), with the verify steps. - **`din-dep-audit` ships**, the eighth program: dependency risk from the call graph crossed with the record, read-only. ### 1.0.27 (2026-09-16) - **The six-level tree:** Global, Command, Org, Ops, Field, Node. Older level names still resolve. See [The field and the tree](/docs/field). ### Related - [Upgrade](/docs/upgrade): how to move to a new release. - [Download](/download)