The shipped code is V8 bytecode, not source (Fase 2.4). The main process is compiled to .jsc and the plain-JavaScript bundle is removed from the package. npx asar extract used to hand over 1.7 MB of readable TypeScript-derived source — including the Ed25519 licence verification and the trial expiry, which meant defeating either one was a text edit. Those now run from bytecode inside the main process.
Stated plainly, because it is worth being honest about: this is not encryption. String literals survive in the V8 constant pool and bytecode can be disassembled by someone determined. What it removes is casual source copying and the one-line patch. The preload script is deliberately left as plain JavaScript — compiling it would require turning off the renderer's OS sandbox, and the preload holds nothing but a list of IPC channel names.
Free vs Pro licensing (Fase 2.2): Catenary now has a plan. A Pro key is verified offline with Ed25519 — no server call, no phone-home, and the app stays fully functional without a network.
The 7-day Pro trial is claimed, not granted: a fresh install runs on Free from the first second, and the clock only starts when you ask for it — from the invitation that appears when you meet a free limit, or from Settings → License. No card, once per machine. Because it can only ever be started once and there is no way back, asking for it opens a confirmation that names the date the trial would end before you spend it, rather than starting the clock on a single click. That way the days are spent while you are actually pushing against something, instead of draining during a week you never opened the app.
Day 8 is a screen rather than a silence. If the trial left more projects open than Free allows, Catenary reopens the one you were last in and closes the rest — closed, never deleted: they wait under Recent, the screen names them, and every file, canvas, branch and worktree is untouched. From there you work one project at a time, or get Pro to keep them side by side. The same reconciliation runs whenever the app starts over its limit, so a plan is never enforced in one direction only, and a Recent entry you cannot open right now says so with a lock instead of failing on the click.
The free plan is the whole product, in small: canvas, terminals, editor, browser, git and wires between agents are unlimited on every plan. What Pro buys is scale — more projects open at once, more tasks running in parallel, bigger teams. On Free one agent commands at most two helpers, and that single rule is the same number everywhere it shows up: two Maestro recruits, and a three-node squad (a leader plus two). Four of the five built-in squads fit under it; the five-agent Enterprise squad carries a PRO badge, shown only to users who are actually on the free plan.
Meeting a limit opens an invitation that names what just happened rather than a generic upsell, and never interrupts work in progress. It offers three doors in the order they cost: Get Pro is the button, I have a key sits beside it, and the trial is a quiet link off to the side — an offer, not the answer the wall volunteers first.
Changing plan is a moment, not a relabelled row: activating a key or claiming the trial dims the room, and the mark arrives with a shockwave, the trial naming the date it ends and a purchase naming the person it was sold to.
Which plan you are on is always visible: a small tag sits beside the version in the sidebar foot — FREE, PRO TRIAL · 3d, or PRO — so the trial countdown runs somewhere you actually walk past, instead of only inside Settings. Clicking it opens a plain comparison: what every plan gets unlimited (canvas, terminals, editor, browser, git, and the wires between agents) stated first and without columns, then the five places Free and Pro genuinely differ. Those five rows are generated from the same numbers the app enforces, so the table cannot drift from docs/legal/PLAN-LIMITS.md. A Pro user clicking their own tag gets their licence, not a sales table.
License… sits in the app menu, the command palette and its own Settings section, where the plan is a card — what you have, what it comes with, and, on a trial, how much of it is left as a bar. A paid plan can also raise the Maestro ceiling (2–10) there. That ceiling exists on Pro too and is not a paywall: a maestro opens agents on its own initiative, each one spending your API credits, so it stands alongside the approval card and the action throttle as a cost brake.
Plan limits are documented in docs/legal/PLAN-LIMITS.md, which EULA clause 4.1 now incorporates by reference.
1-Click Agent Task (worktree automation): a ⚡ New Agent Task pill now leads the canvas toolbar (Cmd/Ctrl+Shift+N, also in the command palette). It opens a prompt-first modal: you describe what the AI should do, and the branch name writes itself from that description — "Criar modal de login" becomes feature/login-modal, "Faça a Issue #42" becomes fix/issue-42. The branch field is always visible and always editable, and it stops following the prompt the moment you touch it.
Confirming creates an isolated git worktree, pans the canvas to a clear patch, draws the task's own territory there, and starts the chosen workforce inside it — a single agent (Claude Code, Codex, …), a plain terminal, or a whole Squad, picked through the real Squads dialog rather than a smaller copy of it. The prompt is delivered once the agent CLI is actually listening, so it reaches the agent instead of the shell it booted from — and the delivery is verified against the terminal's own screen rather than assumed, then re-sent until the text is really in the composer. A CLI that takes five seconds to attach its input reader (Antigravity on Windows) used to swallow the prompt silently and leave an empty > behind; now the Enter is only pressed once the words are there. A squad leader gets its role prompt in front of the goal, in the same single message.
Setup rápido (on by default) makes the new checkout usable in about a second: node_modules is linked from the source checkout, the .env family is copied (copied, not linked — a task branch must not rewrite your main checkout's secrets), and the repo's own .catenary/setup.sh runs if the team committed one. All three are best-effort: none of them can fail the worktree.
Autonomous agent terminals: the New Agent Terminal picker gained an "Agente autônomo" checkbox, and the recruit approval card a matching one. A terminal created with it ticked launches its agent CLI with permission prompts bypassed, so the agent edits files and runs commands without someone accepting each one. The picker's command footer rewrites itself as you tick the box, so the flag is always read rather than promised.
Autonomy is chosen at creation and nowhere else: a CLI fixes its permission mode when it starts, so a switch offered afterwards could only mark something invisible until a future restart. A node whose terminal is autonomous shows a badge beside the Maestro one — an indicator, not a control.
The mark survives an app restart (and a session resume) via the machine-local session.json, deliberately not the committed workspace.json, so cloning a project never inherits someone else's bypass.
Per-agent flags: --dangerously-skip-permissions for Claude Code and Antigravity (read from the installed CLIs), plus --dangerously-bypass-approvals-and-sandbox (Codex), --always-approve (Grok), --auto (OpenCode) and --force (Cursor) from each project's docs.