Features Docs Changelog Download GitHub

Changelog

Release Notes

Version history for Claude Control Center. All releases are available on the GitHub Releases page.

v0.4.0 Latest
2026-06-30 DMG

Security

Timing-safe token comparison: replaced string equality with timingsafe_bcmp (Darwin) to eliminate token timing side-channels on the local HTTP server.
Connection rate limiting: the local HTTP server now caps concurrent connections at 20, returning 429 Too Many Requests for excess, preventing local DoS flooding.
Atomic token file creation: ccc_token is written via POSIX open(O_CREAT | O_EXCL, 0600) — never world-readable, never has a window where it is empty.
Atomic settings.json writes: installer now writes to a temp file and uses os.replace() — no more corruption window if the process dies mid-write.
Wildcard rule prevention: "Always Allow" no longer creates a * wildcard rule when the primary input is unrecognized — prevents accidentally greenlighting all future invocations of a tool.

Fixed

Exact-command session approvals: "Allow for Session" is now keyed on (sessionId, toolName, primaryInput) — approving echo hello never auto-approves a different command.
rm -r now critical: recursive delete without -f (e.g. rm -r dir, rm -R dir, rm --recursive dir) is now correctly classified as critical, not medium.
alwaysAllow / allowForSession in activity feed: these decisions were previously displayed as "denied" in the activity feed. Fixed.
Session allow list cleared on session end: "Allow for Session" entries are now properly cleared when the session ends, not carried over to the next session.
UI freeze on hook install: checkAndInstallHooks now runs the installer subprocess off the main thread using Process.terminationHandler — no more UI freeze during first-launch hook setup.
Force-unwrap crash paths eliminated: ApprovalModal, SessionAllowList, and DynamicIslandController no longer use ! force-unwraps on optionals that can be nil at runtime.
DMG version substitution: build_dmg.sh now correctly stamps the current version into Info.plist for any 3-part version string (was hardcoded to match 0.1.0 only).
Pending approvals cancelled on server stop: stopping the server while an approval dialog is open now correctly resolves it with deny instead of hanging indefinitely.

Tests

Test suite expanded from 0 to 173 tests covering SessionAllowList (15 tests), RiskClassifier (46 tests), approval flow, and HTTP server auth.
v0.3.1 Stable
2025-06-28 DMG

Fixed

Active status fallback: the Dynamic Island pill now shows Active when a session is running but no specific tool label is set — e.g. between tool calls when menuBarStatusText has cleared. Previously the pill would disappear even though Claude was still mid-session.
Pill visibility regression: DynamicIslandController now observes activeSession?.status in addition to menuBarStatusText. The pill stays visible for the full duration of a running session.
State observation gap: added isSessionRunning to hasStatus check in syncPanelSize(), so the wide-active strip no longer collapses during inter-tool-call pauses.
v0.3.0 Stable
2025-06-20 DMG

New

Dynamic Island pill — three-state design: idle (hidden, alpha 0), wide-active strip (full menu-bar height, animated status text), and expanded card (hover or ⌘⇧I).
Expanded card: shows the app icon GIF, session name, project directory, and last 4 activity events inline — no need to open the full panel for a quick glance.
Inline approval in pill: when a permission request is pending, the expanded card shows an inline Allow / Deny card so you can respond without leaving your current window.
Global hotkey ⌘⇧I: toggle the expanded pill from any app.
Full-screen auto-hide: pill hides automatically when the front app enters full-screen, and reappears when it exits.
Atoll invariant: pill is anchored so panel.frame.maxY == screen.frame.maxY at all times, matching the notch hardware position exactly.

Changed

Menu bar and Dynamic Island are now selectable in Settings — no restart needed to switch modes.
Status text clears after 90 seconds of inactivity (was immediate after Stop hook).
v0.2.0 Stable
2025-06-08

New

Allow Rules: whitelist tool + glob-pattern combinations that skip the approval dialog permanently. Stored in UserDefaults, editable in the Rules tab, take effect immediately.
Risk classification engine: all bash commands now classified as NONE / LOW / MEDIUM / HIGH / CRITICAL based on NSRegularExpression pattern matching. Risk level shown in every activity row and approval dialog.
Files Changed tab: tracks every file read, written, or edited in the session with operation type, relative path, and diff line counts.
Session grouping: sessions are now grouped by project directory in the sidebar for easier multi-project navigation.
Notification Center integration: native macOS notification fires when an approval is needed, so you're alerted even when not looking at the screen.

Fixed

Hook installer now checks for existing entries before appending, preventing duplicate hooks on repeated launches.
Approval modal now surfaces the correct session ID when multiple Claude Code sessions run concurrently.
v0.1.0 Initial Release
2025-05-28

New

Native macOS menu bar app with animated GIF status icons for 14 activity states (thinking, reading, editing, searching, approval, approved, denied, warning, error, finished, idle, working, network, tool).
Pre-tool approval system: PreToolUse hook intercepts every tool call; CCC shows an approval dialog for medium/high/critical-risk commands. 30-second auto-allow timeout.
PermissionRequest hook: handles Claude Code's native "Allow this tool?" prompt — always bypasses allow rules and shows the dialog.
Activity feed: live log of every tool call with tool name, primary input, and timestamp.
Automatic hook installation: on first launch, CCC patches ~/.claude/settings.json with all required hook entries. No terminal commands needed.
Local HTTP server: NWListener-based server on localhost:40440 with no third-party dependencies.
Universal binary: compiled for arm64 and x86_64 — runs natively on Apple Silicon and Intel Macs.
Privacy first: zero network egress beyond localhost:40440. No telemetry, analytics, or accounts.