Introducing Claude Opus 5.5, the first model in our new Claude 5.5 family.
It performs at the level of Claude Fable 5.1 for most tasks, and costs 40% less to run than Opus 5.
Please welcome GPT-6 Sol and GPT-6 Luna to the GPT-6 universe.
GPT-6 Sol and Luna build on the advances behind GPT-6 Astra, bringing much of its strengths into faster and more affordable models to support work at scale.
We’ve also made caching and inference more efficient, and we’re passing the savings directly to you: 50% lower API prices for Sol and Luna compared with GPT‑5.6 promotional pricing.
the recurring theme from the last PassControl security review was funny:
most of the refusals were correct. the wording around them wasn't.
a cache failure isn't a credential rotation. a missing key doesn't prove a forged receipt.
truth claims are part of security too.
rewrote the README around one question: "how do i make my first governed call?"
realized the docs were technically complete but still made you work too hard to understand the product.
correct documentation != useful documentation
spent time fixing something hilariously non-security related today:
the Fleet Actions menu was literally getting clipped by its own section if you only had 1-2 agents.
backend can be perfect and one stupid dropdown will still make the product feel broken
passcontrol passport import now takes the secret through a hidden prompt and puts it in Keychain / Secret Service / DPAPI.
no key in shell history. no key in process args.
small UX thing, massive difference for a security product.
found a nasty rollback bug in passport import.
under one failure path, replacing a key could delete the same key it was supposed to preserve.
0.9.4 fixes it. this is exactly why i keep doing stupid amounts of testing before calling this thing done.
one thing i really hate in infra dashboards: a number with no explanation behind it.
PassControl's spend view now literally explains the total: durable charges + operator adjustments + any remaining difference.
money should be auditable.
fun bug: receipts were permanent until you rotated the signing key enough times and old ones just stopped verifying.
fixed that in 0.9.2. retired public keys can now stay in history so old receipts remain verifiable.
security software gets weird when the safest answer is also the least satisfying one.
if PassControl can't read spend/state, it now says unavailable. not 0.
"I don't know" is a feature when the alternative is lying.
nothing humbles you like CI failing every build because it's trying to run a test file that literally does not exist in the repo.
that was PassControl for a bit lol
fixed the generator so the workflow can't reference DB tests the public tree doesn't actually carry.
AI agents shouldn’t hold your raw API keys.
I built PassControl to put an authorization layer between agents and LLM providers - per-agent identities, scoped permissions, budgets, revocation and audit trails.
Self-hostable. Looking for the first people willing to break it.
@byaarav I literally polished the fuck out of my software just to avoid distribution which i cant now avoid. OpenAI released the AgentsAPI which at least validated my market but forced me to start distributing because otherwise it will remain a dead repo with 0 stars
@VitaliiRel Yeah, definitely. Especially when you’re sitting anywhere near credentials, trust has to be earned before the product can really scale. That’s something I’ll have to tackle as PassControl grows.