Krit Beta · Progress · Updated August 8, 2026

Built from nothing to a full chat, voice, and community platform in under three weeks.

This page replaces the old project-status dump with a curated view of what's actually live, how fast this has moved, and — the part that matters most going forward — what's next, in priority order, with realistic timelines.

28 daysJuly 11 → August 8, first commit to today
644 / 645automated tests passing · 1 environment-gated skip
51production database migrations shipped
5platforms: web, Windows, Linux, Android, desktop-in-progress macOS

How we got here

A sample of the pace — not every change, just the shape of it

Jul 11Public SFU voice + first logo pass
Jul 12Rich messages, staff Control Center, Focus Stack UI
Jul 13DeepFilterNet noise suppression, tabbed settings
Jul 14PostgreSQL + Redis cutover, security foundation
Jul 15Email verification, 2FA, adult-media safety, mobile swipe nav
Jul 16Six landing-page directions studied
Jul 17Split Send composer, media send polish
Jul 18Control Center themes + performance dashboard
Jul 19Spotify, DM calling, Kris rename, desktop 2.0.30/31 signed
Jul 20Game Lobby privacy + cross-worker voice scaling
Jul 21Soak test passed, bot admin-lockdown, production scaled to two nodes (OVH2 + OVH1)
Jul 22Independent audit fixes, atomic voice limits, live Spotify updates, and stable chat scrolling
Jul 23Full-size categorized settings, hierarchy-safe roles, separated member sections, and role-colored chat names
Jul 24Hybrid Steam/Epic/GOG/Xbox/Battle.net game-activity detection shipped in desktop 2.0.32, load-balancer rebalanced, clickable message links with previews
Jul 25Private custom server emotes, compact typography, and a stable single-row desktop composer
Jul 26Privacy-safe moderation search and the hardened Kris moderation bot shipped to the two-node platform
Jul 26Safe confirmed server ownership transfer, a staged desktop-release pipeline in Control Center, and three real-hardware-driven desktop fixes (game-activity false positives eliminated via a full package audit, a startup race that could freeze the tray/quit/update controls) shipped as 2.0.35–2.0.38, with the public release history caught up to match
Jul 27Two independent full-codebase security audits completed and every Critical/High finding fixed across three hardening rounds; a desktop fullscreen dead-end and a stream-pause bandwidth bug shipped as 2.0.39
Jul 27KLIPY clips & stickers, a real webhook-notification bug fixed, and per-server/per-channel notification overrides
Jul 27DM poll/event voting, tiered custom-emote limits with reduced-motion static variants, and group direct messages
Jul 31Desktop window-control fixes and the first slice of the public bot developer platform: bot identities, server-owner install consent, and bot messaging
Aug 1Bot event delivery: signed, SSRF-safe webhook payloads whenever a message is created, edited, deleted, or reacted to in a channel an installed bot can see
Aug 1Interactive message actions: bots can attach clickable buttons to their messages, with server-authorized click-time delivery back to the bot
Aug 1OAuth login ("Sign in with Krit") closes out the bot developer platform: authorization-code grant, consent screen, and a Connected Apps settings pane to revoke access
Aug 2Public bot directory: opt-in listing, search, and a Browse Bots dialog that installs straight from the catalogue

What's actually live

Grouped, not itemized — see NEXT_STEPS.md for full technical detail

💬Core chat & voice

Real-time text and voice channels, self-hosted LiveKit SFU with screen share and webcams, DM voice/video calls, group direct messages, DM polls and events, Unicode and private custom server emotes with reduced-motion static variants, reactions, replies, mentions, pins, search, polls, versioned rich-message formatting, per-server/per-channel notification overrides, and clickable links with automatic preview cards.

🛡️Accounts & safety

Required verified email, optional 2FA and recovery codes, Argon2id password hashing, encrypted media-safety quarantine, an 18+ policy with fail-closed consent, privacy-conscious active-session inventory, a protected first-party moderation bot with scoped AutoMod, warnings, reversible mutes, case history, and Control Center operations — hardened by two independent full-codebase security audits with every Critical/High finding fixed.

🎲Game Hub

Campaign Desk, Game Lobby, and Community Atlas as owner-toggled channels — with join policies (open / invite / request), session details, host notes, temp voice channels, and IGDB search.

🔌Integrations

Spotify OAuth listening status with in-app Premium playback, Twitch watch parties with live chat and emotes, IGDB-powered game search with cover art, and KLIPY-powered GIF, sticker, and clip search.

Developer platform

A live Developers portal for registering applications and bots, declaring scoped permissions, managing redirect URIs, and issuing one-time hash-only credentials. Bots have a real in-app identity: a server owner can review and approve an install link with a chosen permission subset — found either directly or through an opt-in, searchable public directory — an installed bot can send messages (optionally with clickable action buttons) through its own token, and can receive signed webhook events for channel activity and button clicks. Third-party sites can also let users sign in with their Krit identity via OAuth, with a Connected Apps pane to review and revoke access at any time.

Roles & permissions

Managed @everyone and custom roles, fixed theme-safe colors, owner self-assignment, optional role sections in the right member panel, role-colored names in server chat, hierarchy-safe assignment, 37 granular permissions, role/member channel overrides, member removal and bans, and server-side enforcement across chat, media, voice, video, settings, invites, and webhooks.

🖥️Desktop & mobile

Windows (Authenticode-signed via Azure Trusted Signing), Linux (AppImage/DEB/RPM plus a checksum-verified universal install command), and Android native apps, with a public source-free numerically ordered GitHub history containing all 33 retained releases and 64 installer packages, in-app auto-update, hybrid local game-activity detection across Steam/Epic/GOG/Xbox/Battle.net (2.0.32), and taskbar/dock unread badges. The release hub no longer advertises or links back to this direct-access progress page.

⚙️Infrastructure

PostgreSQL 17 + Redis 7.4 in production, two load-balanced application nodes (OVH1 + OVH2) sharing one database over a private WireGuard link with nginx weighting tuned to each node's actual fixed overhead, plus durable maintenance and audited feature kill switches in the staff Control Center.

Priorities & timeline

What's next, ranked by what actually matters, with realistic estimates

Now

This week

Backlog cleared — remaining items are blocked
Bot developer platform, including discovery: done

Identity, server-owner install consent, a public opt-in directory, bot messaging with action buttons, signed event delivery, click-time authorization, and OAuth login are all live. Everything else on this roadmap needs physical hardware, a business decision (signing keys, developer accounts), or a deliberate production-topology change — nothing left that's a straightforward next build.

LowAwaiting direction
Next

1–2 weeks

Platform reach and polish
Real-hardware verification pass

Windows and Linux confirmed on real machines: title bar, taskbar unread badge, fast clean startup, tray reliability, and the game detector correctly identifying real installed titles while a full package audit closed out several false-positive reports. Android device pass still outstanding.

Medium1–2 days
First real macOS build

Build target exists but isn't signed, notarized, or published. Needs a macOS runner and Apple Developer signing.

Medium3–5 days
Android production signing key

Still on the debug keystore convention — needs a protected release key before any Play Store submission.

Medium1 day + store review
Screen share & webcam polish

A dead-end fullscreen bug and a bandwidth-pause bug fixed and shipped on desktop. Remaining: camera/screen-recording permission handling on macOS, once real macOS hardware is available to verify against.

LowBlocked on macOS hardware
Later

Bigger bets

Larger scope, no immediate deadline
Horizontal scale validation past two workers

A real production-topology change (Redis-backed realtime routing and voice membership, multiple app containers behind the live load balancer), not a routine feature — needs deliberate planning and explicit go-ahead before touching it. Once multi-worker is live, stage the 400 / 750 / 1,400 concurrent-user soak tests outlined in the scaling plan.

LowOngoing, growth-driven