Skip to content
Ward

Changelog

Version history

Newest first. Removals are listed as prominently as additions, because a feature that disappeared is the thing a returning user most needs to be told about.

1.1.1

Current

21 August 2026

macOS and Linux, the right icon, and an uninstall that takes its downloads with it

Ward can be downloaded on a Mac and on a Linux desktop for the first time - four builds added to this version on 29 August, a week after it shipped. Plus two things a customer sees on Windows: an icon belonging to a product that no longer exists, and an uninstall that left every byte Ward had ever downloaded behind, measured at 7.7 GB on one machine.

Added
  • Downloads for macOS and Linux. Four of them: Apple silicon and Intel for the Mac, a Debian package and a distribution-neutral archive for Linux. Added on 29 August to the version that shipped on the 21st, so it is the same program - the same jar, the same 2 151 tests - carrying the native libraries for each platform instead of Windows ones.
  • Nobody has ever started Ward on macOS or on Linux, and that is worth reading before downloading either. The test suite passes on both and the parts a unit test cannot reach are the Windows-only ones: finding a browser you already have, working out which program holds a port. Expect to point a profile at an explicit browser path. The download page says which platform stands where, per file.
Changed
  • Your profiles and your Android emulators are still a question, and the answer still defaults to keeping them. Those are logged-in sessions and trusted-device tokens; nothing removes them without being told to, and a silent uninstall never asks and so never deletes them.
Fixed
  • The download page no longer redirects to itself. Seven routes - the download page, pricing, docs, blog, changelog and both sign-in pages - answered their own address with a permanent redirect back to it, which a browser reports as too many redirects. A rule meant to send /Download to /download was matching /download as well, because that matcher ignores case. The live site was unaffected: it serves those pages as static files before the rule ever runs.
  • The application icon is Ward’s. It was a blue shield with a keyhole, drawn for the access-governance product this one replaced; the generator that made it said in its own comment that the keyhole "says governed access, which is what Ward actually does". It is now the moss mark on ink that the website and the wordmark already use, generated from the brand file rather than drawn a second time.
  • Uninstalling removes what Ward downloaded. The browser builds, the Android SDK and Chromium’s component cache are program material - every byte re-downloadable - and they stayed on the disk after the program was gone. On the machine this was measured on, uninstalling now frees 7.7 GB where it previously freed none.

1.1.0

21 August 2026

A Ward account, and an API an agent can drive

Ward now asks you to sign in, with a free account it can also create for you. Nothing about where your data lives has changed: every profile, proxy and device identity is still in a database on your own PC and none of it is uploaded. The local automation API grew from four endpoints to the whole surface, with scoped tokens, so a script - or a coding agent - can build a fleet rather than only start one.

Compatibility

Your profiles are untouched. Scripts using the pairing token keep working: it still authenticates and still carries full control, and the four original endpoints answer exactly as they did.

Added
  • The local API covers what the window covers: profiles, folders, proxies, device identities, per-surface policies, templates and engines, with create, change and delete. Thirty-four endpoints, all on 127.0.0.1 only.
  • Scoped automation tokens, minted under Settings. Read, read-and-launch, or full control - so an agent can be given the smallest one that does the job, and revoking it does not take your own scripts down. No scope reads a proxy password, and no route mints a token.
  • GET /v1/openapi.json and GET /v1/agent-guide, generated by your own copy of Ward from the route table it dispatches on, so they describe the build in front of you.
  • The plan panel says what your machine still needs to do what your plan includes - a browser to launch, Android’s tools for mobile profiles - with a button to each.
Changed
  • Ward asks you to sign in. The account is free, the application creates one for you if you have none, and there is no card and no trial clock. A stored session is honoured offline, so signing in once is enough and a dropped connection does not lock you out of your own profiles.
Fixed
  • A profile set to reopen its previous tabs leaked this machine to the sites it was signed in to. Restored tabs begin loading before Ward can tell the browser what device it is, so the first requests carried the real user agent, screen and timezone and the profile’s device arrived a moment later - a device that changes mid-session is a stronger signal than a wrong one. A masked profile no longer restores, the editor says so beside the setting, and the launch log records it. A profile with no device identity is unaffected.
  • Camoufox could not be assigned to a profile. Ward downloads it, recommends it above every other engine, and then refused to save a profile pointing at it, because a check added to stop imported archives naming arbitrary programs knew about five browser names and not that one.
  • Setting a window size, an extra launch flag or a start page quietly switched session restore off, on both engines.

1.0.0

13 August 2026

Ward becomes a browser profile manager

Everything below the surface is new. Ward now runs many isolated browser profiles on one PC, each with its own cookies, storage, cache, proxy and device identity. The access-governance product that occupied this repository through 0.2.0 has been removed in full, not deprecated.

Compatibility

There is no upgrade path from 0.2.0. The database, the domain model and the desktop app are different; install 1.0.0 as a new application.

Added
  • Local-first storage. Profiles, folders, proxies and fingerprints live in a SQLite database on your PC, and every browser profile directory lives on your disk. Ward is fully usable with no account and no network connection.
  • Profile organisation: folders, tags and free-text notes, so a few hundred profiles stay navigable.
  • Per-profile proxies over HTTP, HTTPS, SOCKS4, SOCKS4a and SOCKS5. Paste the string your provider gave you in any of the shapes providers write it, including scheme://host:port:user:pass and the inverted user:pass:host:port; Ward works out which part is which from evidence and says so when a reading was ambiguous. Credentials are supplied by a local forwarding relay bound to 127.0.0.1 rather than by a browser extension, because Chrome cannot authenticate to a SOCKS5 proxy at all and an installed extension is itself a fingerprint.
  • Coherent device identities. User agent, platform, screen metrics, device pixel ratio, hardware concurrency, device memory, timezone, locale, languages and WebGL vendor and renderer are generated as one internally consistent set matching a real device class, then applied over the DevTools Protocol before any page script runs. Timezone is derived from the proxy exit address so it cannot contradict the IP.
  • WebRTC leak prevention on both engines: the non-proxied-UDP handling policy on Chromium, and host-candidate suppression in the generated Firefox preferences.
  • A launch that fails closed. A profile whose proxy does not answer refuses to open a window rather than browsing from your own address, and the relay refuses the browser’s connection rather than falling back to the destination when the upstream is dead, rejects the credentials or goes silent. A flag typed into the Advanced tab cannot countermand it either: --no-proxy-server, a second --proxy-server, a proxy bypass list and a WebRTC policy override are refused when the profile is saved and again when it is launched.
  • An engine picker that can download most of what it offers. Camoufox, Ungoogled Chromium and Brave are fetched as portable builds against a pinned SHA-256; plain Chromium is not, because its project publishes snapshots with no checksum to pin. Chrome and Edge are behind a toggle that is off by default. The reason is stated in the picker and it is not the obvious one: the engine is not what reveals a device - Ward applies the same identity to any of them - it is what the installation reports to its vendor about this machine, some of it from an updater service no flag can reach. Every Chromium build shares one flag set; Camoufox and Firefox get a generated user.js. Installed browsers are still detected from the standard Windows locations and the registry, and any binary can be pointed at by hand.
Removed
  • The delegation rail, the eight platform adapters, the credential vault, the hash-chained audit ledger, the posture monitor and the browser extension. That was a different product; none of it is carried forward.
  • The operator web console. The website is now only a place to download the software and read the documentation. No profile is created, opened or managed from a browser.

0.2.0

3 August 2026

The access-governance build

A rebuild of the original platform against the written specification: a sanctioned delegation rail across eight platforms, an envelope-encrypted credential vault for agency-owned accounts, and an append-only hash-chained audit ledger. Superseded in full by 1.0.0.

Added
  • Delegation adapters for eight advertising and marketplace platforms.
  • Envelope-encrypted credential vault with a single audited decrypt path.
  • Hash-chained audit ledger with database-enforced append-only semantics.
  • Java 21 and JavaFX desktop host with a loopback-only local API.
Fixed
  • A sign-in dead end that bounced a signed-in operator between two routes forever.

0.1.0

31 July 2026

First internal build

The initial cut, then named Conduit. Schema, row-level security, authentication and a first pass at the desktop agent.

Added
  • Postgres schema with forced row-level security, tested against real Postgres.
  • Authentication, session middleware and operator provisioning.
  • A first browser profile manager in the desktop agent.
Changed
  • Renamed from Conduit to Ward, with a brand kit.