* feat(capture): dictation, personalities, 0.5.0 Ships the Capture release end to end. Global-hotkey dictation with synthetic paste into the focused app on macOS and Windows, an on-screen pill across recording / transcribing / refining, customizable push-to- talk and toggle chords, and an accessibility-permission prompt scoped to Settings → Captures with inline re-check feedback. Voice profiles gain optional personalities that power compose / rewrite / respond actions via a local Qwen3 LLM — shared with refinement, so there is one local LLM in the app, not two. Refinement hardened with deterministic Whisper-loop collapse before the LLM sees the transcript, per-capture flag snapshots for re-runs, and a ten-transcript evaluation harness across every bundled refinement size. Version bump 0.4.5 → 0.5.0. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * feat(mcp): local MCP server exposes voicebox.* tools to AI agents Mounts FastMCP at /mcp (Streamable HTTP) so Claude Code, Cursor, Windsurf, and the VS Code MCP extensions can call voicebox.speak, voicebox.transcribe, voicebox.list_captures, and voicebox.list_profiles against the running Voicebox server. Backend - new backend/mcp_server package (tools, middleware, profile resolve, pub/sub events); named mcp_server to avoid shadowing the installed mcp PyPI package FastMCP imports internally - app.py migrated from @app.on_event to lifespan= so FastMCP's session manager cohabits with Voicebox's startup/shutdown - new MCPClientBinding table + /mcp/bindings CRUD; ClientIdMiddleware reads X-Voicebox-Client-Id into a ContextVar and stamps last_seen_at - profile resolution precedence: explicit -> per-client binding -> capture_settings.default_playback_voice_id - POST /speak REST wrapper for non-MCP callers (shell, ACP, A2A) - GET /events/speak SSE broadcasts speak-start / speak-end so the pill surfaces agent-initiated speech - backend/mcp_shim proxy (plain httpx) for stdio-only MCP clients - PyInstaller spec updates + new --shim build target (~18 MB) Frontend - Settings -> MCP page with HTTP / stdio / claude-mcp-add copy snippets, default voice picker, per-client bindings table, connection status - useMCPBindings, useSpeakEvents hooks - CapturePill gains 'speaking' state; DictateWindow subscribes to SSE and emits dictate:show so the Rust side surfaces the pill window Native - tauri.conf.json externalBin now includes voicebox-mcp - show_dictate_window helper + dictate:show listener in main.rs - (also in this commit: InputMonitoringGate UX, hotkey_monitor tweaks, landing footer/navbar updates, new overview docs for captures / dictation / mcp-server / voice-personalities) Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * feat(mcp): Rust-owned speaking pill with self-contained audio playback The pill window now surfaces for agent-initiated speech without main-window involvement. Rust subscribes to /events/speak via a tokio task + reqwest streaming body (speak_monitor.rs), shows the pill, and forwards events to the dictate webview over Tauri's event bus. The pill plays audio via a plain HTMLAudioElement and emits dictate:hide when playback ends. The pill stays hidden through the ~1 s generation wait and only surfaces when audio actually starts, with the counter armed at that moment. Fixes a shared-dict mutation in mcp_server/events.publish() that caused the second subscriber (Rust speak_monitor) to receive `event: message` instead of named speak-start/speak-end frames. Also teaches the speak_monitor parser to handle CRLF framing (sse-starlette default). Main-window AudioPlayer now skips autoplay for source in {mcp, rest} to avoid double-play when both windows are alive. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * readme and dev script * feat(capture): gate global hotkey on dictation readiness checklist Stops the "stuck pill" failure where pressing the chord with missing STT/LLM models triggers a recording that has nowhere to land. The hotkey now stays disarmed until every gate (models downloaded, Input Monitoring + Accessibility granted) is green; the empty-state checklist in CapturesTab surfaces each unmet gate with a one-click action and auto-arms the chord once everything turns green. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * color * model download status * progress * personality: bool API, i18n across the app - Collapse intent tri-state (respond/rewrite/compose) to `personality: bool` on /generate, /speak, and voicebox.speak. Drop respond entirely; keep compose as a standalone button via /profiles/{id}/compose. Remove /rewrite, /respond, and /speak profile endpoints. - FloatingGenerateBox: Wand2 persona toggle + Dices compose button appear when the selected profile has a personality. ProfileCard badges Wand2 alongside the effects Sparkles. - MCP bindings: default_intent column → default_personality: bool. Migration drops the legacy column. - i18n: en / ja / zh-CN / zh-TW translation files filled out and wired through the capture, server, and profile UI. ```ts voicebox.speak({ text: "Deploy complete.", profile: "Morgan", personality: true, // rewrite through the profile's personality LLM }); ``` * i18n: GenerationPage sidebar copy * fix: BOOL import for windows crate 0.62 BOOL moved from Win32::Foundation to windows::core in 0.62. Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]> * fix(capture): layout-aware V keycode for synthetic paste on macOS macOS apps match Cmd+V against the layout-translated character via NSMenu key equivalents, so posting kVK_ANSI_V (= 9, the QWERTY V position) on Dvorak produces Cmd+. and never triggers Paste. New keyboard_layout module resolves the active layout's V keycode via TISCopyCurrentKeyboardLayoutInputSource + UCKeyTranslate, caches it in an AtomicU16, and refreshes on kTISNotifySelectedKeyboardInputSourceChanged. All TIS calls run on the main thread (init from Tauri setup; observer callback delivered to the main runloop); synthetic_keys::send_paste reads the cached value once per paste. Falls back to kVK_ANSI_V when resolution fails or the active input source carries no Unicode key layout data. Windows is intentionally left on hardcoded VK_V — SendInput delivers WM_KEYDOWN with wParam = VK_V to the target regardless of the active layout, which is why `Send "^v"` works for AutoHotkey on Dvorak Windows. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * fix(capture): cooperative app activation for synthetic paste on macOS 14+ macOS 14 deprecated NSRunningApplication.activateWithOptions: in favour of a cooperative-activation pattern: the caller first yields activation rights to the target, then the target activate()s against the tightened Sonoma foreground rules. Without the yield, activate() on 14+ sometimes silently fails or only bounces the dock icon — the exact "paste lands in the wrong app" symptom we were previously one API break away from. activate_pid now discovers the 14+ selector via respondsToSelector: and branches: on 14+ it yieldActivationToApplication:'s from NSRunningApplication.current then calls -activate on the target; on 11–13 it stays on -activateWithOptions: (still the only option). Both branches propagate the BOOL return — if activation is refused we error out before clobbering the clipboard instead of silently proceeding. The respondsToSelector: result is cached in a OnceLock so the probe isn't repeated on every paste. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * fix(capture): conditional clipboard restore + always-attempt on paste failure Two bugs in paste_final_text' clipboard handling: 1. Restore was unconditional. If the user ⌘C'd in the target app during the 400 ms paste-consume window — or a clipboard history tool (Paste, Pastebot, Maccy) or Universal Clipboard sync snapshotted our staged text — the blind restore overwrote their newer content with the pre-paste snapshot, silently losing user data. 2. send_paste' errors were propagated with ? before the restore, so a CGEventPost / SendInput failure left the user's clipboard stuck on the transcript. Fix folds both into one pattern: capture the post-write change count, re-read it after paste-consume, restore only when they match (plus treat a change-count read failure as "unknown, don't overwrite"). Isolate send_paste's error so the restore runs regardless of paste success, then propagate the paste error after. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * chore(deps): pin rdev to jamiepine/rdev fork Upstream Narsil/rdev has shipped no release since 2023-06 (crates.io still serves 0.5.3), so the Sonoma main-thread fix we depend on — PR #147, applied at hotkey_monitor.rs:184 — is only reachable via a git pin. A pin to a third-party repo breaks the build whenever the remote force-pushes, renames, or is taken down, and Cargo does not durably cache git-dep archives the way it does crates.io tarballs. Forking to jamiepine/rdev at the same SHA removes that failure mode without changing crate behavior and gives us a place to cherry-pick future OS-compatibility fixes on our own timeline. The SHA was verified to exist on the fork before re-pinning. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * fix(mcp): idle timeout + escalating backoff for speak-SSE monitor Two reliability gaps in the /events/speak subscriber: 1. resp.chunk().await had no idle timeout. A backend that accepts the TCP connection but stops producing frames (deadlocked SSE endpoint, zombie process) would block the task forever without reconnecting. The pill window would never surface for agent-initiated speech and there would be nothing to log. Backend emits a `:ping` heartbeat every 15 s, so 45 s without any data is now treated as a dead stream — the task errors out and the reconnect loop takes over. 2. Flat 2 s backoff escalates nowhere. Logs fill with reconnect lines when the backend is down for minutes, and a backend that accepts + immediately closes connections (no data) spins the loop tightly. Backoff now escalates 500 ms → 30 s on unproductive rounds and resets only when at least one frame arrives (the connection was genuinely productive, not just accepted). Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * fix(refinement): character-level loop collapse + pytest coverage The word-level pass catches single-word Whisper loops ("URL URL URL…") but misses two common hallucination patterns the PR had to claim as "edge cases": 1. Multi-word English loops — "thanks for watching thanks for watching…" × 6 sails through because no two consecutive tokens are identical after text.split(). 2. CJK loops — "謝謝觀看" × 7 sails through because text.split() returns a single unsplit token for the whole loop (no whitespace between characters). Add a character-level second pass: a non-greedy regex finds any 2–60 char substring that repeats min_run+ times immediately after itself and strips the run. The 2-char floor keeps emphasised single-letter runs ("wooooooow") intact. The 60-char ceiling covers every observed Whisper tail hallucination ("Please like and subscribe to my channel.", "Subtitles by the Amara.org community") while staying short enough that coincidental long-phrase repetition in legitimate speech doesn't hit the threshold. Whitespace normalisation only runs when the pass actually stripped something, so untouched transcripts keep their original spacing. New test_refinement_collapse.py gives the pre-processor its first deterministic unit-test coverage: 17 tests pinning the word-level legacy behaviour plus the new multi-word English / CJK / Japanese / emphasis-preservation cases. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * fix(db): graceful fallback when SQLite < 3.35 on MCP bindings migration SQLite gained ALTER TABLE … DROP COLUMN in 3.35 (Mar 2021). Production PyInstaller builds bundle Python 3.12 which links to SQLite 3.40+ so that path is always safe, but a dev running the backend directly on Ubuntu 20.04 (3.31) or Debian 11 (3.34) would crash on first startup trying to drop the legacy default_intent column. Add _supports_drop_column(engine) — returns True on non-SQLite dialects (Postgres / MySQL have supported DROP COLUMN for decades) and gates on the runtime sqlite_version for SQLite. When unsupported, log a warning and leave the unused column in place: SQLAlchemy only maps declared columns, so a stray default_intent column does no reads or writes and can't interfere with runtime behaviour. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * fix(mcp): correct lifespan shutdown order — drain MCP before unloading models The inline lifespan ran _run_shutdown inside the MCP context, so the TTS / Whisper / LLM models were unloaded *before* FastMCP's __aexit__ got a chance to cancel its in-flight session tasks. Any MCP request mid-generate at shutdown time would crash on "model unloaded" instead of receiving a clean session-cancelled error. Rewire via compose_lifespan (which was already defined in mcp_server.server for exactly this purpose but never used): AsyncExitStack enters factories in order and exits in LIFO, so MCP teardown fires first — cancelling sessions — and _run_shutdown runs after nothing is holding the models. Smoke test shows the log order flipped as expected: Ready StreamableHTTP session manager started ... running ... StreamableHTTP session manager shutting down ← was last, now first Voicebox server shutting down... ← was first, now last As a side benefit, _run_shutdown is now paired with _run_startup via try/finally inside voicebox_lifespan, so a partial startup (models half-loaded, MCP __aenter__ fails) still unloads whatever was loaded instead of leaking it to process exit. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * fix(mcp): stamp last_seen_at on /speak too + tighten path predicate POST /speak is a REST wrapper around voicebox.speak for agents that don't talk MCP (shell scripts, ACP, A2A). It reads X-Voicebox-Client-Id and uses it for the same per-client profile resolution + default personality lookup the MCP tool does (speak.py:39-64), so its callers are first-class clients — but the ClientIdMiddleware only stamped last_seen_at on /mcp* paths. REST speak callers showed up as "never seen" in Settings → MCP despite actively acting on their bindings. Widen the stamp predicate to an explicit ("/mcp", "/speak") prefix list, and require a path boundary on match so future routes named /mcpfoo or /speakers don't silently inherit the stamp via the prefix. New test_client_id_middleware.py pins the scope with 17 parametrised cases (both the allowed set and the overlap cases that must not match). Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * feat(captures): scrubbable WaveSurfer player for capture detail view Replace the placeholder fake-waveform + play button in CapturesTab's audio card with a real CaptureInlinePlayer (wavesurfer.js). The player renders the actual waveform, lets users scrub through the clip, and shows a proper current/total timestamp pair in place of the duration-only label. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * feat(ui): persist selectedProfileId across sessions Wrap useUIStore in zustand/middleware's persist under the key voicebox-ui. partialize only selectedProfileId so volatile UI state (dialog open flags, form drafts, engine/voice pickers, sidebar) stays in-memory as before — but reopening the app no longer loses whichever profile the user was last working with. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * feat(captures): mirror readiness checklist into the settings sidebar The six-gate checklist only rendered in the CapturesTab empty state, so a user already on the settings page had no single surface showing which gate was red — the inline InputMonitoringNotice covered one, the model pickers covered another, and Accessibility was only hinted at by the auto-paste toggle. Mirror the same component into the right sidebar of the settings page so every gate (STT model, LLM model, Input Monitoring, Accessibility, plus the hotkey toggle in the main column) is always visible while the user configures dictation. New compact prop on DictationReadinessChecklist drops the centered header and empty-state max-width so it fits the 280 px sidebar next to the existing About / Differences blocks. Callers in compact mode own the heading — CapturesPage reuses the existing captures.readiness.title key (present in en / ja / zh-CN / zh-TW already) as an h3 matching the sibling sidebar sections. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * feat(captures): move sidebar checklist below differences + hide when all green Two small follow-ups to the sidebar checklist placement. Move it below the What's different section so the sticky top of the sidebar stays the page's narrative context (About → differences) and the checklist reads as a status panel rather than preamble. Gate the whole block on !readiness.allReady so once every gate is green the sidebar drops back to just About + What's different — no value in real estate full of checkmarks. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * fix(captures): refetch readiness immediately after STT/LLM model swap useCaptureSettings updated its own cache optimistically but never invalidated ['capture-readiness'], so for up to 5 s (the poll interval) after switching stt_model or llm_model the checklist kept showing the previous model's ready/missing state. The backend endpoint resolves the model live on each call — it was just the frontend cache that lagged. Invalidate in onSettled only when the patch touched a model field, so unrelated updates (chord keys, toggles) don't pay for a refetch. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * fix(captures): hide macOS-only copy when running on Windows / Linux Two surfaces leaked macOS-specific copy onto other platforms: 1. The Input Monitoring + Accessibility rows in the readiness checklist rendered everywhere. On Windows/Linux the Rust permission stubs return true, so the rows showed as permanent green checkmarks with copy like "macOS allows Voicebox to detect your global shortcut." — nonsense when you're on Windows. Gate both rows on a userAgent-based isMacOS check so they only render where the underlying TCC permission actually exists. 2. The global-shortcut setting description ended with "macOS will ask for Input Monitoring permission the first time you turn this on." That sentence rendered on every platform. The readiness checklist already surfaces the TCC requirement at the right moment on macOS, so the description doesn't need the platform note — drop it from en / ja / zh-CN / zh-TW. Other macOS strings (AccessibilityNotice, InputMonitoringNotice, their "stillMissing" hints) are already gated behind the Rust permission booleans returning false, which never happens on Windows/Linux, so they stay inert without further changes. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * feat(capture): swap the rdev fork for keytap 0.2, delete local chord state machine Dep swap: - Drop the git-pinned jamiepine/rdev fork we were carrying since the upstream crate is abandoned. - Depend on keytap 0.2 from crates.io — our own cross-platform global keyboard tap crate. Clean shutdown via Drop, Sonoma-safe by design (no TSMGetInputSourceProperty calls off the main thread, so `set_is_main_thread(false)` is gone), and properly versioned. Chord engine rewrite: - Delete hotkey_monitor.rs's internal Chord state machine (Match enum, KeyEvent enum, step()/classify() methods, associated unit tests). keytap's ChordMatcher subsumes it: Momentary chord for PTT, add_toggle() for Toggle-to-talk, longest-match resolution, sticky-end for Toggle. Net: -80 LOC in hotkey_monitor.rs; the remaining module is the dispatcher loop + Effect→Tauri translation. - Preserve the PTT→Toggle "RestartRecording" upgrade signal. keytap emits End(PTT)+Start(Toggle) atomically (same Instant) when the held set upgrades from a shorter chord to a longer superset. The dispatcher peeks at the matcher with a 5 ms recv_timeout after any End and coalesces the pair into Effect::RestartRecording so the frontend still gets the "discard the transition-moment audio" signal instead of an unrelated Stop+Start pair. - HotkeyMonitor::update_bindings now actually tears down the tap on empty bindings instead of leaving an idle CGEventTap around. New bindings rebuild the matcher and the dispatcher thread from scratch. key_codes.rs: - Rewrite the browser-code → Key table against keytap's cleaner Key variant names (`A`..`Z` not `KeyA`..`KeyZ`, `Digit0`..`Digit9` not `Num0`..`Num9`, `ArrowUp` not `UpArrow`, `AltLeft`/`AltRight` instead of `Alt`/`AltGr`, `Period` not `Dot`, …). On-disk chord string format (W3C `KeyboardEvent.code` identifiers) is unchanged, so capture_settings rows written before the swap round-trip identically. Legacy aliases (`Alt`, `AltGr`, `Num0`, `UpArrow`, `Dot`, …) kept for forward-compat on old rows. main.rs / input_monitoring.rs: - Update the few doc comments that referenced `rdev::listen` to describe keytap's Tap; no behavioural change. - build_chord_bindings now imports from keytap::Key. - enable_hotkey / disable_hotkey / update_chord_bindings reach into HotkeyMonitor via &mut since apply()/update_bindings() now mutate. Tests live in keytap now (22 chord-related tests in keytap 0.2, including the PTT→Toggle upgrade scenario that used to be tested in hotkey_monitor.rs). Voicebox's hotkey_monitor.rs is thin enough that local testing would be trivia. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]> * chore(deps): bump keytap 0.2 → 0.4 for macOS modifier-events fix 0.2 read CGEventFlags via CGEventGetIntegerValueField(event, 0x81), which is not a valid CGEventField id — macOS silently returned 0, so FlagsChanged events produced no KeyDown / KeyUp for any modifier key and the PTT / toggle chords never armed on macOS. 0.4 uses the documented CGEventGetFlags(event) API. 0.3 (tracing / serde / Fn / IntlBackslash) is picked up as a free consequence; no API surface we depend on changed. * perf(captures): stop polling readiness once both models are green useQuery was firing GET /capture/readiness every 5s forever, and also on every window focus. Once stt.ready and llm.ready are both true the answer can only change when the user swaps a model in settings, and useSettings already invalidates the query on that path — the polling was pure noise. Gate both refetchInterval and refetchOnWindowFocus on "not fully ready" so we fall silent once the checklist is green. * feat(ui): theme settings, stories polish, track editor restructure - add dark/light/system theme with persisted choice + OS change listener - restyle stories sidebar (search, item layout, border) to match captures - move floating generate box to right column of stories, add top fade mask - story track editor: sticky track labels aligned via flex rows, custom scrollbar with left/right zoom handles - capture pill light mode pass, fix inline waveform progress color - pull mcp_server hidden imports into the pyinstaller spec - notarization doc draft * fix mlx llm bundling * feat(ui): shared ListPane primitive + misc polish ListPane is a compound component (Header / TitleRow / Title / Actions / Search / Scroll) that owns the relative wrapper, faded right divider (50px top fade), top scroll mask, and absolute-positioned header used by every list-detail tab. Wires up CapturesTab, StoryList, and EffectsList. EffectsTab gets -mx-8 / pr-8 to match the edge-to-edge layout used elsewhere. Other changes: - MCPPage: native <select> → shadcn <Select> for default voice and per-binding voice pickers - Button outline variant: add hover:border-accent - Drop hover:text-destructive from trailing delete buttons (HistoryTable, GpuAcceleration, GpuPage, EffectsChainEditor, EffectsDetail) - HistoryTable empty state moved behind t('history.empty') - StoryContent scroll padding pt-14 → pt-16 - backend health reports the captures dir - landing CapturesMockup: "Send to" → "Export" with Download icon - CHANGELOG: drop [Unreleased] personality section * fix(captures): Play As autoplay + default voice + orphan recovery - Hand /generate ids to the global SSE watcher so playback fires on completion. The mutation onSuccess was checking audio_path on a queued row, which is always empty — autoplay never ran. - Bind the Play As voice selection to capture_settings.default_playback_voice_id, kept in sync with the Settings → Captures and Settings → MCP pickers. Picking from the split-button dropdown writes back to settings. - Extract AudioBars from HistoryTable into a shared component; use it for the Play As generating state in place of Loader2. - Stop the active-state hover from flashing white text when the button is in its lighter accent/10 fill. - Drop the gradient avatar swatches from the Settings → Captures voice dropdown. - Backend: when the gen worker exits without writing a terminal status (e.g. SQLite lock racing the failed-status write inside its own exception handler), the cancel endpoint now flips the row to failed instead of 409-ing. Worker also force-fails on its way out as a belt-and-suspenders. * fix(captures+chord): Stop button stops, ChordPicker accepts shorter chords Two unrelated correctness bugs caught in PR review: - The Play As "Stop" button was wired to handlePlayAs() unconditionally, so clicking it during playback kicked a fresh generation instead of halting. Now pauses the player when the click came from the main button while playbackState is 'playing'. Picking a different voice from the dropdown still kicks a new generation as before. - ChordPicker tracked the peak set of held keys but seeded the peak from initialKeys, so a user who opened the picker with a 3-key chord saved couldn't replace it with a 2-key chord — the candidate length never beat the seed. The peak now resets on the first press of a fresh sequence (when no keys were held immediately prior), then grows monotonically within that hold. * fix(settings): honor explicit null on nullable fields, ignore on the rest Routes were calling model_dump(exclude_none=True), which drops every client-sent null before it reaches the service. The service then layered on its own `if value is not None` guard. Net effect: setting a nullable column back to null was a no-op — the MCPPage default-voice picker sends null when the user picks "no default" and the row was silently keeping whatever was there before. Switched the routes to exclude_unset=True so absent fields stay absent but explicit nulls survive the dump, and centralised the per-field nullability check in the service. The check inspects the SQLAlchemy column metadata so non-nullable columns (stt_model, llm_model, the chord key lists) still drop nulls instead of crashing the request, while default_playback_voice_id can finally be cleared. * fix(captures): clean up audio files when create_capture fails The create flow wrote raw audio (and a transcoded .wav for non-wav sources) to data/captures before the DB row was committed, so any failure between the write and the commit — a webm that decoded to a 0-length array, a whisper model that errored mid-transcribe, a SQLite contention on the commit — left the audio on disk with nothing pointing at it. Over enough flaky uploads the directory grows without bound. Now every path written before the commit is tracked in a list, and the whole stretch from the first write to db.commit() runs inside a try/except that unlinks each tracked file on raise and re-raises. The transcode branch removes the raw file from the cleanup list only when the unlink actually succeeds, so an OSError on the raw-path delete still hands cleanup the original blob to retry. * fix(mcp): restrict voicebox.transcribe(audio_path=...) to loopback audio_path mode took any absolute filesystem path and returned its decoded contents as transcribed text with no caller verification beyond the existence/size checks. The X-Voicebox-Client-Id middleware records the header but never rejects an absent or fake one, so a Voicebox bound to 0.0.0.0 (the documented "remote access" mode) was effectively an unauthenticated arbitrary-local-file read primitive. The middleware now stashes the request's remote address in a ContextVar alongside the existing client_id, and audio_path mode refuses anything that doesn't parse as a loopback address (IPv4 127.0.0.0/8, IPv6 ::1). audio_base64 mode is unchanged — that path was always bounded to bytes the caller already has. Loopback callers (the Tauri webview, local CLI scripts, MCP clients on the same machine) keep working. Remote callers now have to send the audio over the wire if they want it transcribed. * fix: PR review nits — response shape, landing copy, form reset - /llm/generate's "model is downloading" branch was raising HTTPException(202, detail={...}), which wraps the payload in {"detail": ...} and forces clients to parse a success status as if it were an error. Switched to JSONResponse so the payload sits at the top level. - The landing page's "Language Models" card advertised "Qwen 3.5" with sizes 4B/2B/0.8B; we ship Qwen3 at 0.6B/1.7B/4B. Aligned to what's actually in the binary. - ProfileForm's discard-draft button reset the form without touching `personality` or `avatarFile`, so stale persona text and an attached avatar would survive the discard. The other three resets in the file already include both fields — this brings the discard path in line. * perf(mcp): move last_seen_at stamp off the request path ClientIdMiddleware was running the SQLAlchemy SELECT/INSERT/UPDATE/COMMIT inline on the event loop after every /mcp/* and /speak request. SQLite serialises writes, so concurrent MCP traffic queued behind the stamp write — the response sat waiting on a side-effect that the client never needs in band, and SSE streams would stall briefly per request. The middleware now hands the stamp to asyncio.to_thread via a fire-and- forget create_task so the response returns immediately and the write runs on the default executor. A module-level set keeps strong refs to in-flight tasks (per asyncio docs) so the GC can't collect them mid- write. The fallback path runs the stamp inline if no loop is available (tests/oddball callers) rather than silently dropping it. * fix(dictate): force-dismiss the speaking pill when SSE never comes back The pill subscribed to /generation/{id}/status to know when to start playback, but EventSource.onerror was a no-op — auto-reconnect was the intended recovery for transient drops. The gap: if the backend deletes the gen row mid-flight or the connection silently dies in a way the browser keeps retrying without ever getting a status event, the pill sits in 'speaking' forever and the user has no way to clear it. Added a 60-second hard cap that arms when the SSE opens and clears the moment any real status event lands. If it fires while the pill is still on the same id and audio never started, it force-dismisses. Same idea as the existing post-speak-end 15s grace, but covers the case where the backend never says anything at all. * fix: i18n cleanup + readiness checklist effect cadence + ChordPicker shadow - DictationReadinessChecklist was constructing downloadByModel as a fresh Map every render and listing it in the cleanup effect's deps. With the 1 s polling cadence and arbitrary parent rerenders the effect ran more often than it needed to. Memoised the Map on activeTasks; the effect now keys off the memo's identity. - zh-CN persona tooltipActive/ariaLabelActive matched their inactive twins byte-for-byte ("以人物设定朗读"). The other locales differentiate the active state with a -ing / -中 suffix; zh-CN now reads "正以人物设定朗读" when active. - personalityPlaceholder was a ~290-character paragraph that doubled as both the example text and the explanation, repeating most of what personalityHint already said. Trimmed to the example only and folded the explanation + leave-blank consequence into the hint, across all four locales. - Refinement model size keys were size06 / size17 / size4. Renamed the 4B variant to size40 so the decimal padding is consistent. - ChordPicker's open-effect bound a window.setTimeout id to a local `t`, shadowing the i18n `t` from useTranslation. Renamed to timeoutId. * perf(settings): persist generation sliders on release, not per pointer-move Both sliders on the generation settings page were calling update() — which is a React Query mutation that PATCHes /settings/generation — inside onValueChange. Dragging the chunk-limit slider from 800 to 3000 fired a request per pointer-move pixel, and a mid-drag failure plus optimistic rollback would leave persisted state visibly out of sync with the thumb position. Local state now mirrors each slider during a drag and the persist happens once on Radix's onValueCommit (pointer-up / keyboard-release). useEffects keep the local state in sync if the persisted value changes out-of-band — another window editing the same setting still updates the slider position cleanly. * chore(backend): Ruff lint pass — deprecated APIs, exception leaks, dead patterns Mechanical sweep of items called out in the PR review: - qwen_llm_backend: AutoModelForCausalLM.from_pretrained(torch_dtype=…) is deprecated in transformers ≥4.41 in favor of dtype=. Renamed. - routes/llm: try/except around backend.generate() raised HTTPException(500, detail=str(e)) which leaks stack traces / paths to clients and trips Ruff B904. Now logs the original exception server-side and hands the client a generic message; chained via `from e` to preserve traceback context. - mcp_bindings + mcp_server/context: datetime.utcnow() is deprecated since 3.12. Switched the two assignment sites to datetime.now(timezone.utc). The schema-level `default=datetime.utcnow` defaults in database/models.py are left for a later schema-aware pass. - routes/generations: `logger = …` sat between two import blocks (Ruff E402). Moved below imports. - mcp_server/server + tests/test_refinement_samples: typing.Callable / typing.Iterable have been preferred-via collections.abc since 3.9 (Ruff UP035). - routes/events: `except asyncio.TimeoutError` aliases plain `TimeoutError` since 3.11 (UP041). - services/captures: hoisted WHISPER_NATIVE_FORMATS to module scope (was a function-local UPPER_SNAKE that tripped N806) and replaced the raw_path.unlink try/except OSError-pass with contextlib.suppress (SIM105). Semantic equivalence preserved — written_files.remove(raw_path) still only runs when unlink succeeds because it sits inside the suppressed block after the unlink call. - database/migrations: hoisted the duplicate `import sqlite3` from inside two helper bodies to a single module-level import. * feat(stories): regenerate action on clips and the chat list dropdown The track editor's clip toolbar now has a regenerate icon next to Delete; clicking it kicks a fresh take of the selected clip's underlying generation through the same /generate/{id}/regenerate path the History table uses, and pushes the id into the global pending set so the SSE watcher picks it up. The chat list's per-item dropdown gets the same action between Play-from-here and Remove. Translation keys added under storyContent.itemActions / storyContent.toast across all four locales. * feat(stories): import external audio into the timeline (drag-drop + picker) You can now drop a music file onto the story content area or pick one through the new "Import audio" button in the add-clip popover. Both call POST /generate/import which writes the file to data/generations/<id>.<ext>, probes duration via librosa, and inserts a Generation row pointing at a singleton "Imported Audio" profile (created lazily on first import). The existing addStoryItem flow takes over from there — the timeline doesn't care that the row didn't come out of TTS. Engine field on the row is "import"; it's surfaced on StoryItemDetail so the chat list shows a music icon instead of the (missing) profile avatar and both the dropdown and the track-editor toolbar hide the Regenerate action — there's nothing to regenerate. Accepted formats: wav/mp3/flac/ogg/m4a/aac/webm, capped at 200 MB. Translation keys added across en/ja/zh-CN/zh-TW. * fix(audio): serve real Content-Type so imports decode in WaveSurfer /audio/{id} and /audio/version/{id} hardcoded media_type="audio/wav" on the FileResponse. That was a no-op when every generation came out of TTS (everything on disk was a .wav anyway), but imported audio keeps its source format — .mp3 / .m4a / .ogg — and the WaveSurfer MediaElement backend uses an <audio> tag that checks Content-Type before letting the clip play, so an MP3 announced as audio/wav silently failed to load. Both endpoints now derive the type via mimetypes.guess_type and fall back to audio/wav for unknown suffixes. Download filenames also keep the real extension instead of always saying ".wav". * feat(stories): zoom bar bounds tracked to project length, default 60s scope The track editor's zoom was clamped to a hardcoded [10, 200] pixels-per-second range, which had no relationship to the project — on a 4-minute story a "max zoom out" of 200 px/s still required scrolling, and on a 5-second story you could zoom all the way in to where every clip was a tiny sliver. Reframed the bounds in the unit the user actually thinks in: how many seconds of timeline are visible at once. Min scope is 10 s (most zoomed in), max scope is the entire project, and the default lands on a 60 s scope (or the full project, whichever is shorter) once the editor measures its visible track width on first mount. The pixels-per-second value still lives in component state (because every downstream calculation already uses it) but minPps/maxPps are computed from `containerWidth − LABEL_COL_WIDTH` and the project's effective duration, so the +/- buttons and the edge-drag handles on the scrollbar all clamp to bounds that move with the project. Re-clamping fires whenever those bounds shift — adding a long clip or resizing the window pulls the current zoom inside the new range instead of leaving the user parked outside it. * fix(stories): show the source filename on imported clips Imports were rendering as "Imported Audio" everywhere because every import points at the singleton voice profile. The filename was already being stored on the generation row (in the `text` field), so the chat item title and the timeline clip label now read from `text` when `engine === 'import'` and fall back to the profile name otherwise. The chat item also drops the language pill (always "en" on imports — not informative) and skips the transcript textarea since imports have no spoken text to show. * fix(stories): round split_time_ms before posting handleSplit was sending currentTimeMs - item.start_time_ms straight to the backend, which rejects it because StoryItemSplit.split_time_ms is typed as int and the playhead's currentTimeMs is a float (it's driven from HTMLAudioElement.currentTime, which carries sub-millisecond precision). Pydantic surfaced the mismatch as "Input should be a valid integer, got a number with a fractional part" and the toast read "Failed to split clip". Math.round at the call site, matching what the trim and move handlers already do. * feat(stories): per-clip volume control on the timeline Each story item now carries a volume column (linear gain, default 1.0, clamped 0.0–2.0 server-side). New PUT /stories/{}/items/{}/volume route + useUpdateStoryItemVolume hook + a Volume2 icon in the clip-edit toolbar that opens a popover with a 0–200% slider. Local slider state drives the visual during a drag; the persist fires once on onValueCommit, mirroring the generation-page slider pattern. Web Audio playback inserts a per-clip GainNode between source and master so volume changes apply live without re-decoding the buffer (source -> clipGain -> masterGain -> destination). Server-side mixdown in export multiplies the trimmed clip by its volume before summing into the timeline. Split + duplicate carry the volume forward to the new clips so trimming a faded section keeps the level you set. Migration adds the volume column with default 1.0 so existing rows read as full volume. * fix(stories): mute the clip waveform's media element so it can't bleed audio The clip waveforms drawn inside each timeline track use WaveSurfer with the default MediaElement backend, which creates an internal <audio> element to drive playback timing. Web Audio in useStoryPlayback is what actually produces sound, but WaveSurfer's element was happily preloading and — after the first user gesture unlocked browser autoplay — playing the source URL through the page output too. For TTS clips it was masked: they're short, both sources start at the same time, and stopping the BufferSourceNode at pause coincides with the natural end of the audio element. For long imports (a four-minute MP3) the BufferSourceNode stops on pause but WaveSurfer's element keeps going on its own track — which is exactly the "music keeps playing when I pause" symptom. Hand WaveSurfer a muted <audio> element via the `media` option so the visual still loads peaks but the element itself can never produce sound. preload="metadata" keeps the load lightweight. * fix(stories): hard-cut the audio graph on stop so long imports actually halt source.stop() was the only thing happening when a clip was halted, and on long imported buffers (multi-minute MP3s scheduled via source.start with a duration argument) it was silently failing to halt the buffer in some browsers — pause left the music playing and seek stacked another source on top of the original. The mute-the-WaveSurfer-element fix was a different bug along the same path; this is the one that actually addresses the duplicated audio. ActiveSource now carries the per-clip GainNode alongside the source, and stopSource detaches the onended handler before calling stop() (so the natural-end callback can't race with explicit teardown and re-delete a freshly rescheduled entry at the same id), then disconnects both nodes inside their own try/catch blocks. Even when stop() doesn't actually halt the buffer the graph is severed — no path from source to destination, no audio. * feat(stories): add empty tracks above/below the timeline Tiny + strips sit at the top of the topmost label cell and the bottom of the bottommost one, sticky-positioned in the label column so they follow horizontal scroll. Clicking either extends the visible track stack in that direction by one — above adds max(existing)+1, below adds min(existing)-1. Both compute against the full set (defaults + item-derived + previously-added) so successive clicks keep extending instead of fighting over the same number. Empty extras live in component state because a track only earns its keep once a clip lands on it. Once one does, item.track carries the number forward and the row keeps deriving from items naturally; if nothing lands there before reload, the empty row simply isn't there next time, which matches what the user expects of an unused affordance. * fix(mcp): bundle stdio shim sidecar * fix(captures): allow dictation without paste permission * fix(mcp): preserve speak engine defaults * fix(captures): use platform hotkey defaults * fix(mcp): preload speak pill window * fix(captures): hide unwired storage settings * feat(sponsors): add /sponsors page, homepage promo, and in-app strip * style(landing): drop pill chrome from /download maintainer kicker * changelog * better naming for sponsors * windows keybind note --------- Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]>
33 KiB
Voice I/O
Status: Shipping — phases 1, 2, 4, 7 (macOS) complete · 3 partial · 5, 6, 7 (Windows/Linux), 8 pending Touches: backend, Tauri shell, frontend, a new native shim crate Last reviewed: 2026-04-21
Progress
Shipped
Phase 1 — Groundwork. Audio tab retired from the sidebar; its device / channel
config lives under Settings. Captures tab is live at /captures with no feature
flag.
Phase 2 — Local LLM backend. LLMBackend protocol alongside the existing
TTS/STT backends. qwen_llm_backend.py, services/llm.py, routes/llm.py, and
a shared model-download / cache pipeline. Qwen3 0.6B / 1.7B / 4B registered and
user-selectable via capture_settings.llm_model.
Phase 4 — Captures tab. List + detail view, source badges (dictation /
recording / file), retranscribe, refine (flags + model resolved from a
server-side capture_settings singleton), delete, and the Play-as-voice
dropdown over every profile.
Partial
Phase 3 — In-app voice input. CapturesTab dictates end-to-end via
useCaptureRecordingSession, which the Phase 7 floating pill also consumes.
Outstanding: a universal mic button on other text inputs (Generate form,
profile descriptions, story titles, etc.), and the streaming
/transcribe/stream WebSocket — today's flow is a single POST /captures
with the complete audio blob.
Phase 7 — External dictation shell (macOS). Both halves shipped on macOS.
Hotkey half:
tauri/src-tauri/src/chord_engine.rs— pure state machine. Unit tests green.tauri/src-tauri/src/hotkey_monitor.rs—rdev-based global listener on a background thread, withset_is_main_thread(false)applied to sidestep the macOS 14+ TSM crash (Narsil/rdev#165). Right-hand-only defaults preserve left-hand Cmd+Option+I devtools.- Default bindings hardcoded:
Cmd+Option(push-to-talk) andCmd+Option+Space(toggle-to-talk). The PTT → Toggle upgrade transition is preserved — adding Space mid-hold promotes the session without interrupting audio. DictateWindow— transparent, always-on-top, borderless 420×64 webview pre-created hidden at app setup. Shows on chord-start, hides on capture-cycle completion. Error state on the pill auto-dismisses and copies-to-clipboard on click.
Paste half (macOS):
clipboard.rs—NSPasteboardsnapshot that walkspasteboardItemsand copies every(uti, bytes)pair so multi-type content (images, styled text, file refs) survives the round-trip.save_clipboard,write_text,restore_clipboard,current_change_count.synthetic_keys.rs—CGEventPostat the HID tap with the full four-event Cmd+V sequence (Cmd down → V down w/ flag → V up w/ flag → Cmd up).focus_capture.rs—AXUIElementCreateSystemWide+AXUIElementCopyAttributeValue(kAXFocusedUIElement)+AXUIElementGetPid, with the AX attribute key CFStrings built at runtime because they're CFSTR macros, not linkable symbols.NSRunningApplication.activateWithOptions:for re-activation.accessibility.rs—AXIsProcessTrustedgate.paste_final_textcommand — activate → 120 ms settle → save clip → write text → ⌘V → 400 ms → restore. Skips when focus was in Voicebox itself.- Focus rides the
dictate:startevent payload;DictateWindowholds the snapshot in a ref and consume-once-nulls on paste so a late-arriving refine from an earlier session can't misfire. - Dictation recording no longer hard-caps at 29 s — the limit still applies to voice-profile reference clips.
Outstanding: Windows SendInput / UIAutomation / SetForegroundWindow
equivalents, Linux uinput / AT-SPI equivalents (and the Wayland story),
first-run Accessibility prompt UI with deep-link to System Settings,
direct-injection path for focus-was-inside-Voicebox (step 6 — dictating
into our own Generate tab currently falls back to the capture list).
Not started
- Phase 5 — Agent voice output + persona loop. No
/speakendpoint, novoicebox.speakMCP tool, no per-agent voice binding, no persona metadata on profiles. - Phase 6 — STT engine expansion. Only Whisper (
mlx_backend.py). Parakeet v3, Qwen3-ASR, Kyutai — all unregistered. - Phase 8 — Pipeline routing, sinks, long-form. No preset primitive, no MCP sink, no webhook sink, no dual-stream recorder, no summary transform.
Additionally landed (not explicit in the original plan)
These fell out of the Phase 3/4/7 work but deserve their own mention:
- Server-authoritative settings. Singleton
capture_settingsandgeneration_settingstables. The client sends nothing but the audio; STT model, refine flags, refine LLM, and the auto-refine flag are all resolved server-side, so sibling Tauri webviews can't go stale. - Backend audio normalisation.
POST /capturestranscodes anything librosa can decode (webm/opus, m4a, etc.) to WAV before handing it to whisper, side-stepping miniaudio's format gaps inside mlx-audio. - Short-recording guard. Sub-300 ms blobs short-circuit client-side so a fumbled chord tap never uploads an empty webm.
- Refinement prompt. Rewritten with firmer anti-chatbot framing and inline examples covering multi-sentence preservation and self-correction.
Near-term outstanding
Called out in recent sessions but not yet in a phase:
- Configurable chord bindings. Pass 2 of the hotkey work — persist
push_to_talk_chord/toggle_to_talk_chordincapture_settings, surface a chord-picker UI inCapturesPage, and wire a Tauriupdate_chord_bindingscommand soHotkeyMonitor::update_bindingspicks up user changes live. - Generate-tab empty-state explainer. The parallel aside to the Captures explainer described in Product surface → Parallel explainer on the Generate tab. Lands alongside Phase 3's universal mic button so both tabs feel symmetric.
Overview
Voicebox ships the output half of a voice I/O loop: clone a voice, generate speech, apply effects, compose multi-voice projects. The input half — speech to text, dictation, routing — exists today as a single Whisper model wired into the Recording & Transcription panel. This doc proposes making voice input a first-class pillar: more STT engines, a dictation shell (global hotkey, audio capture, paste, streaming), a local LLM backend, and a user-configurable pipeline from captured audio to whatever the user wants to do with it.
Positioning is the key move. Voicebox becomes the local voice I/O layer for humans and AI agents — a local alternative to cloud dictation tools, with the differentiator that we also do TTS and voice cloning. The same app that captures your voice can generate a response in any voice profile you've cloned. "Anything voice is Voicebox."
Positioning shift
Before this plan, Voicebox was "the open-source AI voice cloning studio." Cloning was the headline capability.
After this plan, Voicebox is "the open-source AI voice studio." Cloning is one capability in a broader category that now spans input (STT, dictation), intelligence (local LLM, refinement, persona), output (TTS, cloning, effects, Stories), and routing. The word "cloning" drops out of the top-line descriptor because it's become a feature rather than the thesis.
Competitive frame
Voicebox ends up covering the territory of two separately-funded, separately branded cloud incumbents that operate on opposite sides of the same voice I/O loop:
- ElevenLabs (~$3B+): voice cloning and TTS — the "agents speak" side
- WisprFlow (~$70M raised): voice dictation for agents and power users — the "users talk" side
Both are cloud-only. Voicebox becomes the only local alternative to either, running in one app, with a single model directory and LLM shared between input and output. That bridging — dictation → LLM → TTS with a cloned voice in the middle — is the thing no single incumbent can match, because neither has the other half.
Launch-time copy tasks
These are not engineering tasks but should ride the Phase 4 ship so marketing and positioning stay in sync with the product.
- README.md — drop "cloning" from the top-line descriptor. Add a section that explicitly frames Voicebox as "the open-source local alternative to WisprFlow and ElevenLabs." Competitive framing belongs in the README and on the landing page — not in-app (reads as defensive).
- voicebox.sh landing page — same positioning shift.
- GitHub About / repo topics — swap "voice-cloning" or similar tags for broader "voice-io," "local-tts," "local-stt," etc.
- Release notes — the Phase 4 launch note is the "we're now voice I/O" moment.
Why now
- Cross-platform local dictation is an empty category. The tools people love (Superwhisper, MacWhisper, Aiko) are macOS-only. WisprFlow and Willow are cloud. Our Windows install base is the wedge — first-class Windows support for a local dictation product is genuinely differentiated.
- The
STTBackendprotocol already exists. The multi-engine registry pattern shipped with TTS makes adding Parakeet v3 and Qwen3-ASR a days-not-weeks effort on the backend side. - The persona loop — speak to an agent, have it reply in a cloned voice — is a feature only we can ship. Nobody with a dictation product has TTS; nobody with a TTS product has good dictation. The full duplex is ours.
- Agent harnesses already pipe Voicebox TTS into their stacks. Giving those users STT from the same app closes the loop and makes Voicebox the default voice I/O layer for the agentic dev-tool crowd.
- Typing a 2,000-character TTS script is user-hostile. The most immediate internal win is dictating directly into Voicebox's own generation form — speak the script, generate the voice. This dogfoods the whole STT pipeline without touching a single OS-level API.
- Voice-to-voice models are landing. Moshi (Kyutai), GLM-4-Voice, Qwen2.5 Omni, Mini-Omni, Sesame CSM, Spirit LM (Meta) — end-to-end speech LLMs that take audio in and emit audio out are a near-term reality. The pipeline we're building today is the scaffolding they slot into tomorrow.
Non-goals
- Cloud fallback or "bring your own API key" STT/LLM. Local is the product.
- A separate tray-only dictation app. We extend Voicebox, not fork it.
- Replacing the Stories editor with a notes layout. Long-form capture is a preset on top of the pipeline, not a new product surface.
- Real-time translation UI. It can exist as a transform later, but it's not in this plan.
- Full agent orchestration. We provide the voice rails; the agent lives elsewhere and talks to us via the developer API.
Architecture
Three new backend concepts
1. Expanded STT registry. The existing STTBackend protocol abstracts
Whisper today. Add:
- Parakeet v3 — 25 languages, very fast, the current quality leader for
non-English local STT. Python path via
nemo_toolkitortransformers. - Qwen3-ASR 0.6B int8 — 50+ languages, highest multilingual quality,
cross-platform via
transformers. - Kyutai ASR (optional) — streaming-first, small, CPU-friendly. Fills the "CPU-only laptop" tier.
All register via ModelConfig and use the same download, cache, and model
management UI we already have for TTS. Zero special-casing.
2. LLMBackend protocol. Mirror of TTSBackend / STTBackend. First
implementations are Qwen3 0.6B / 1.7B / 4B running on the same PyTorch + MLX
infrastructure we already run. One runtime, one model cache, one GPU-memory
story.
Why not llama.cpp or ollama: we already have the dependency surface and the
model download UX. A second runtime fragments cache directories and model-status
UI. If CPU-only Windows latency becomes a problem we can revisit.
3. Streaming transcribe transport. Add /transcribe/stream as a WebSocket
endpoint alongside the existing HTTP /transcribe. Audio frames flow in,
partial transcripts stream back. Same FastAPI process, same loaded models. This
keeps dictation latency off the per-request JSON-encode critical path and lets
us ship real-time partial transcripts later without a protocol change.
The pipeline abstraction
Every captured audio event flows through the same shape: Source → Transforms → Sink(s). Users configure presets that bind a source to a transform chain to one or more sinks.
Source Transform Sink
────────────────── ───────────────── ─────────────────
Hold to speak ──┐ STT model Clipboard + paste
Tap to toggle │ Refinement LLM Capture history
Long-form recorder ├──▶ Persona LLM ──▶ File on disk
File drop │ Translation (later) HTTP webhook
API call (WS / HTTP) ──┘ MCP server sink
TTS loopback (persona)
Platform sinks (later)
Source → Transform → Sink is internal, dataflow-style vocabulary (same shape
as Unix pipes, Apache Beam, Kafka) — not user-facing. The UI surface will use
Voicebox-native language (see open questions).
Concrete preset examples this shape enables:
- Dictation — hold-to-speak → Parakeet v3 → light refinement → clipboard + paste + history
- Code prompt — dedicated hotkey → Whisper Turbo → technical-vocab refinement → MCP sink for Claude Code
- Agent voice reply — hold-to-speak → STT → persona LLM → TTS with cloned profile → system audio out
- Long-form capture — dual-stream recorder → chunked STT → summary LLM → markdown file + history
Every user-facing feature collapses into (source + transform chain + sinks). Meeting-style capture isn't a separate product; it's a preset. Competing tools hardcode integrations (Trello, Granola); we make routing user-configurable.
Native shim crate
The parts Tauri doesn't handle cleanly, gathered in one Rust crate with a platform-agnostic API:
- Global hotkey with modifier-only support. Tauri's
global-shortcutplugin requires full combos. We need "hold right-cmd" or "hold ctrl" as primitives. On macOS this means a CGEventTap on a background thread with polling fallback for dropped modifier events; on Windows a low-level keyboard hook; on Linux X11 + libinput, with Wayland as a known gap. - Focus introspection. Query the frontmost app and its focused element via
OS accessibility APIs —
AXUIElementon macOS, UIAutomation on Windows, AT-SPI on Linux. Check the element's role to decide between a direct injection, a clipboard + paste, and a clipboard-only fallback with a notification. A blind paste that only "works when a text field happens to be focused" is the easy default; we should make the decision deliberately. - Simulated paste. CGEvent on macOS, SendInput on Windows, uinput / ydotool on Linux. Wayland is the hard case and needs explicit handling.
- Atomic clipboard save/restore. Save all items and all MIME representations before writing our transcript, restore atomically after paste. Pasting a transcript shouldn't clobber a user's in-progress rich-media clipboard.
- Frontmost-window context capture (later). macOS Vision, Windows OCR, Linux tesseract. Optional feature to feed the refinement LLM disambiguation hints from the window being pasted into.
Main process owns this crate. Webview never sees platform differences.
Target-aware delivery
The paste sink adapts to what's in focus. This is a single sink type with branching behavior, not four separate sinks.
| Target | Delivery strategy |
|---|---|
| Focused text field inside Voicebox | Direct React state update via event. No clipboard involved. |
| Focused text field in another app | Accessibility-verified paste: save clipboard, write transcript, simulate paste, restore clipboard. |
| No text focus detected | Clipboard only, toast notification ("Transcript copied — no text field focused"). |
| Platform-specific special cases (terminal apps, specific editors) | Per-app overrides where the generic path misbehaves. |
Where each concern lives
| Concern | Layer |
|---|---|
| STT / LLM / TTS inference | Python backend |
| Model downloads, progress, cache | Python backend |
| Pipeline runner (orchestrates transforms and sinks) | Python backend |
| Audio capture from mic / system audio | Rust (Tauri side) |
| Audio streaming over WebSocket to backend | Rust |
| Global hotkey capture | Rust (native shim crate) |
| Paste simulation, clipboard save/restore | Rust (native shim crate) |
| Pipeline preset UI, capture history, settings | React |
Model work in Python. OS work in Rust. User config in React.
Product surface
A new tab (and a sidebar reshuffle)
The current sidebar is Generate · Stories · Voices · Effects · Audio · Models · Settings. The existing Audio tab is output-device and channel routing
config — infrastructure, not a creative workspace — and the Settings page
already has a sub-tab pattern (ServerSettings/: Connection, Models, GPU,
Update) that fits it naturally.
Move Audio to a Settings sub-tab. Reclaim the sidebar slot for voice input.
The new tab shows recent captures (audio + transcript paired), active presets, dictation settings, model pickers for STT and LLM. Exact name is an open question.
Sidebar placement: Captures sits at position 3, directly under Stories and above Voices. Creates an "input voice / output voice" adjacency — captured speech is one slot away from the voices you can play it back through, which mirrors the Phase 4 "Play as voice" feature's mental model. Full order: Generate · Stories · Captures · Voices · Effects · Models · Settings.
Parallel explainer on the Generate tab
The Captures settings page gets a "What's different" aside that introduces Voicebox's dictation story. The Generate tab deserves a parallel — first-time users need to be told what voice generation is for in a post-Voice-I/O world, not just handed a text field.
Shape: an empty-state card rendered in the Generate tab when there's no generation history yet, disappearing once the user has generated anything. Teaches without claiming permanent real estate. Parallel bullets to the Captures aside so the two tabs feel like two sides of one product:
- Clone any voice in seconds — a short sample is enough
- Seven engines, 23 languages — creative range, not a single model
- Agent-ready — REST + WebSocket API, one checkbox away from giving any AI agent a voice
This lands in Phase 4 alongside the Captures tab, for visual and thematic symmetry. Not a persistent sidebar — the Generate tab is a workspace and should reclaim its space once the user is producing work.
Archival by default
Every capture saves the original audio alongside the final transcript in a
pattern that mirrors data/generations/. Optional retention setting. Free for
us — the storage and UI patterns exist today for generations.
Developer API, day one
The WebSocket transcribe endpoint is a first-class public API, documented
alongside /generate. Pipeline presets are addressable by ID via
/pipelines/{id}/run so agent harnesses and shell scripts can invoke
user-configured flows. An MCP server sink ships built-in, so integrations with
Claude Code, Cursor, Cline, etc. are one checkbox rather than a custom build.
Agent voice output
Dictation is one half of the loop — user speaks, agent listens. The other half — agent speaks, user hears — is equally load-bearing and deserves a first-class primitive rather than being buried as a TTS loopback sink or a consumer read-aloud button.
The shape is a single new capability: any agent can call Voicebox to speak arbitrary text in a user-configured voice. The same pill that surfaces during dictation surfaces during agent speech, so the user always sees what's coming out of their machine.
MCP tool: voicebox.speak({ text, profile?, style? })
REST: POST /speak { text, profile_id?, style? }
Both accept an optional voice profile (defaults to the user's configured
default), an optional delivery-style string for engines that support it, play
audio through system output, and surface the pill in a speaking state.
Key design points:
- Pill is bidirectional. States expand from
recording / transcribing / refining / restto includespeaking— voice profile name, waveform in the profile's color, visible duration. Same floating surface for both directions so users have one mental model. - Visibility is mandatory. Silent background TTS is a trust hazard. Every
agent-initiated
speak()surfaces the pill. No headless "TTS daemon" mode. - Per-source voice policy. Settings let users bind specific MCP clients or API keys to specific voice profiles — Claude Code in "Morgan," Cursor in "Scarlett" — so users can tell which agent is talking without looking.
- Mute + rate limits. One-toggle mute for all agent speech. Per-source rate limits prevent a runaway agent from monologuing.
This primitive is what makes "Voicebox as voice layer for every agent on your
machine" a concrete shipping capability rather than marketing language. MCP,
ACP, and A2A integrations all slot into it — none of those agent protocols
need to know anything about TTS models, GPU placement, or voice profiles.
They call speak().
Relationship to the persona loop. The persona loop below is one use of
speak() — STT → LLM → speak(llm_reply). Other uses skip STT entirely: a
long-running task announcing completion, a notification, an agent proactively
asking the user a question. The primitive is deliberately simpler than the
persona loop so it can serve both flows from the same API.
Relationship to voice profile samples
A capture and a voice profile sample both hold audio + text, so there's an
obvious temptation to unify them. Don't. The metadata and lifecycle
differences are real:
| Capture | Voice profile sample | |
|---|---|---|
| Profile association | Standalone | Bound to one profile |
| Text field | Raw transcript + optional LLM-refined version | Exact reference_text only |
| LLM refinement | Often applied | Must not be applied — the reference text must match the audio verbatim or cloning breaks |
| Volume | Dozens per day | ~5 per profile, semi-permanent |
| Typical content | Whatever the user said | Often scripted phrases for cloning |
A unified table would mean nullable profile_id, nullable refined_transcript,
nullable reference_text — a fat row that means different things in different
states. Not worth the complexity.
What to ship instead: a one-way promote action. Capture → Sample, zero data-model churn. Thin endpoint:
POST /profiles/{id}/samples/from-capture/{capture_id}
Reads the capture's audio path and raw transcript, calls the existing
add_sample() service with reference_text pre-filled from the transcript,
lets the user edit the reference text in a dialog before saving (transcripts
are usually 90% right but cloning wants 100%). The capture stays in the
Captures tab untouched — the sample is a copy, not a move.
UI hook: the Captures tab's Send-to menu gains a "Use as voice sample…" option that opens a profile picker (with "+ New voice" for cold starts) and a reference-text confirm dialog.
The inverse direction (sample → capture) we deliberately skip. Samples are often scripted phrases used for cloning and they'd clutter the Captures list without adding value; also a subtle privacy surprise for users who don't expect their sample text browsable alongside real captures.
Audio storage deduplication is a later optimization. Today a promoted
capture duplicates the audio file on disk. That's fine. Content-addressable
storage (data/audio/<sha256>.wav with refcounting) can come in Phase 8 as
housekeeping — it'd let a capture and a sample share one underlying file, but
it's not user-visible and not necessary to ship the promote flow.
The persona loop
One flow on top of the speak() primitive: STT → persona LLM →
speak(llm_reply). Voice profiles gain optional metadata — a natural-language
personality description and default LLM behavior. The LLM runs text through
the profile's voice context, then speak() generates TTS with the cloned
profile. End-to-end voice-to-voice with a cloned identity transforming the
content, not just reading it.
Use cases this unlocks:
- Agents that respond to spoken input in a specific voice
- Interactive character experiences (games, narrative tools, accessibility)
- Speech assistance for people who can't speak in their original voice
The shape — STT + LLM + TTS — also stages us for end-to-end speech LLMs which collapse all three into one transform. See Voice-to-voice readiness below.
Voice-to-voice readiness
The STT → LLM → TTS chain that powers the persona loop is a staged approximation
of voice-to-voice. A real end-to-end speech LLM (Moshi, GLM-4-Voice, Qwen2.5
Omni, Mini-Omni, Sesame CSM) replaces the three middle boxes with a single
fused transform: audio in, audio out, no text in between. The pipeline shape
accommodates this natively — register the model as a single LLMBackend (or
a new SpeechLLMBackend if the protocol needs to differ), expose it as a
transform type, and the same sinks work unchanged.
Framing this plan as "voice-to-voice scaffolding, with today's models as the staged fallback" is a strong pitch for agent-harness users who are already tracking these models.
Open questions
- Tab name. Leaning Captures — neutral, extensible across dictation, long-form recordings, and uploaded audio without repainting the tab later. "Dictations" is narrower (office-productivity coded, doesn't fit meeting recordings). "Notes" is the wrong mental model — nobody opens Voicebox to write notes. "Transcriptions" is flat.
- Refinement vocabulary. The LLM-post-STT step needs a user-facing name. "Refine," "polish," "rewrite," "smart edit" are candidates. "Refinement" in this doc as a placeholder only.
- Preset primitive. What do we call a user-configured pipeline? "Intent"
collides with the existing
instructfield on TTS generation. "Flow" is Zapier-coded. "Route" is too networking. Needs its own pass. - Persona metadata shape. Does personality live directly on the voice profile, or as a separate persona construct that wraps profile + LLM config? The first is simpler; the second scales better if we later want multiple personas per voice.
- Long-form capture product surface. Pure preset, or dedicated entry point in the new tab? Leaning preset, but long-form is the feature that most justifies its own landing page.
- Hotkey primitive naming. Hold-vs-tap needs Voicebox-native phrasing in UI copy. Settings can still use industry-standard terms.
Ordered phases
The v1 prototype deliberately skips the hardest parts of the long-term plan (native OS shim, global hotkeys, paste injection, new STT models). Everything in Phase 1–4 is in-process code using Whisper (which we already ship) and the existing model infra. No CGEvent taps, no SendInput, no clipboard timing. The usual OS-level sprawl of a dictation stack is exactly what we sidestep by starting in-app.
Phase 1 — Groundwork
- Move the Audio tab into a Settings sub-tab (
ServerSettings/gains one more section). Audio is device/channel config, not a creative workspace. - Reserve the sidebar slot for the new Captures tab (name TBD but leaning Captures — see open questions).
- Gate the Captures tab behind a feature flag so we can merge to
mainand iterate without shipping half-built UI to users.
Phase 2 — Local LLM backend
LLMBackend protocol alongside TTSBackend / STTBackend. Register Qwen3
0.6B / 1.7B / 4B via ModelConfig. Reuses the HF download path, cache
directory, and model management UI. MLX (4-bit community quants) on Apple
Silicon, PyTorch (transformers AutoModelForCausalLM) elsewhere, same as our
TTS split.
No new runtime. No llama.cpp, no ollama, no fragmented model cache.
Phase 3 — In-app voice input
A universal mic button on every Voicebox text input. Hold, speak, release — text lands in the focused field via direct React state update. No OS APIs involved; Voicebox owns the input.
Marquee use cases:
- Generation form. Dictate a 2,000-character TTS script instead of typing it. This alone justifies the feature.
- Voice profile descriptions. Describe a voice's personality by speaking, which then becomes the input for Phase 4's persona loop.
- Story titles, preset names, any free-text field. Free reuse.
Backend: add /transcribe/stream WebSocket endpoint. Audio frames in, partial
transcripts out. Reuses the existing Whisper model in memory. Optionally routes
through the LLM from Phase 2 for light refinement.
Phase 4 — Captures tab
Graduates the tab out from behind the feature flag. Shows recent captures (audio + transcript pairs), lets the user replay, re-transcribe with a different model, edit the transcript, and send the output through the LLM. Archival is automatic — every capture saves audio alongside transcript.
Includes the "Play as voice profile" action. This is the simplest version
of the persona loop and it lands here for free — no LLM involved, no new
backend endpoints, just a Captures-tab button that sends the transcript text
to the existing /generate endpoint with a user-selected voice profile and
plays the result. Category-defining differentiator from the v1 prototype
onward: Superwhisper and WisprFlow cannot do this because they have no TTS. Voicebox can, with one day of frontend wiring.
Keep it aggressively minimal on day one. A capture list, a detail view, a model picker, a Play-as-voice dropdown. Refinement prompt editing, correction dictionaries, per-source overrides — none of that ships here. They become Tier-2 work when someone actually asks for them.
Phase 5 — Agent voice output + persona loop
Two features that together make "Voicebox as the voice layer for every agent on your machine" a shipping reality:
speak()primitive. NewPOST /speakendpoint andvoicebox.speakMCP tool. Any agent calls Voicebox to speak arbitrary text in a user-configured voice; the pill surfaces in aspeakingstate. Settings UI for default voice, per-agent voice binding (Claude Code → Morgan, Cursor → Scarlett), and a global mute.- Persona loop. Extends
speak()with an LLM step — STT → persona LLM →speak(llm_reply). Voice profiles gain optional personality metadata and default LLM behavior. End-to-end voice-to-voice with a cloned identity transforming the content, not just reading it.
Phase 4 demoed the user-initiated direction of the loop (Play as voice). This
phase ships the agent-initiated direction, which is the category-defining
capability and the pitch that lands with agent-harness users. The persona
loop is one flow on top of the speak() primitive — notifications, proactive
agent questions, and task-completion announcements all use speak() directly
without the LLM in the middle.
Launchable headline moment for the "local voice I/O" positioning.
Phase 6 — STT engine expansion
Parakeet v3 and Qwen3-ASR register as additional STTBackend implementations.
Optional: Kyutai ASR. Multilingual coverage upgrades (50+ languages). Whisper
stays as the sensible default.
Deferred to here because Whisper is already good enough for v1 and the model picker UI exists. Adding rows to it doesn't change the product shape.
Phase 7 — External dictation shell
Native shim crate (global hotkey with modifier-only support, focus introspection via OS accessibility APIs, paste simulation, atomic clipboard save/restore). Tauri-side audio capture streams to the same WebSocket endpoint Phase 3 already ships. Paste sink with target-aware delivery.
This is the feel-good phase. It's also the riskiest: paste timing, hotkey reliability, and cross-platform focus detection are all engineering problems that have to be nailed or the product doesn't work. Phase 3's success derisks the backend plumbing before we start it.
Phase 8 — Pipeline routing, sinks, long-form
Multiple source types, user-configurable transform chains, multiple sinks per
preset. MCP server sink (the agent-harness play). HTTP webhook sink. File
sink. Developer-facing /pipelines/{id}/run endpoint. Preset editor UI in
the Captures tab.
Dual-stream recorder (mic + system audio) as a source type. Chunked STT transform with overlap-based deduplication. Summary LLM transform. Long-form capture becomes a preset, not a new tab.
Platform-specific sinks (Apple Notes on macOS, Obsidian, etc.) as opt-in integrations behind the generic sink interface.
Architectural prerequisites
Two pieces of existing docs/PROJECT_STATUS.md work become load-bearing here:
- Platform support tiers (#420, PR #465). Native shim capabilities vary by platform — Wayland paste is worse than X11, Windows system-audio capture has edge cases, frontmost-window OCR is platform-gated. Tier definitions let us ship confidently with honest user-facing expectations.
- Platform gating on
ModelConfig(bottleneck #6 in PROJECT_STATUS). Parakeet's Core ML path is Apple-only; the PyTorch path is Windows/Linux. Same gating mechanism that currently blocks shipping VoxCPM.
Neither needs to complete before Phase 1, but both should complete before Phase 4 when user-configurable pipelines surface the differences to end users.