All docs

Updating & rollback

Confirm work has stopped, replace packages together and preserve data before rollback.

Ophio isn’t released yet. These docs describe the development version; app downloads are not available.

Ophio does not update the Android app or companion automatically. Obtain new packages from the same trusted source as the installed versions. Its optional Claude Code and Codex updater is separate; it does not update Ophio itself.

Before updating

  1. Check Settings → Versions for app, computer and negotiated protocol versions.
  2. Finish or stop active work and confirm it stopped. Inspect the task’s Stop receipt, including Still running / unknown. A sent stop request is not enough.
  3. Stop Ophio on the computer.
  4. Back up configuration and data with the originals’ access protections.
  5. Replace both computer programs from the same archive.
  6. Start Ophio, check ophio doctor, then verify identity, devices and grants before new work.

On Linux, use the new archive’s install.sh and reinstall the user service from the graphical session. On the unqualified Windows preview, service uninstall stops Ophio and waits for it; replace both executables, then run service install from an ordinary-user PowerShell.

Install Android updates with the same signing key. A signature mismatch is not a reason to uninstall and lose local drafts. See Install on Android.

Compatibility and new features

A connection requires a protocol supported by both sides. Versions need not have identical numbers. An incompatible connection disables remote actions and preserves local drafts, Inbox items and downloads. Update the side named by the error.

A compatible older companion can still lack a new feature. An update-required message is separate from a permission denial. Updating does not grant device access. Closed-app alerts, launchers and other negotiated features may need a companion update.

Pending commands recovered after restart require review and are never automatically sent again. If an old stored command cannot be decoded, its unknown outcome must be reconciled against what actually happened. Do not retry with a new request identifier before checking.

Keep Claude Code and Codex up to date

This is opt-in during ophio setup or under Settings → Agents and accounts → Keep Claude Code and Codex up to date. Changing it requires Manage access and an online, compatible computer. Unsupported platforms show that limitation.

Ophio checks at startup and every six hours, only for agents already installed on the system. It downloads a platform binary from the agent’s official npm package, verifies its checksum and tests --version. Only a working copy is selected for future tasks. The settings show each agent’s version, check time and any problem; there is no separate Check now button.

Tasks and terminals started by Ophio use the selected copies. A running task keeps its version until it finishes. Ophio does not replace your system installation or change its accounts, settings or history. Claude Code’s own updater is disabled for the managed copy.

If a managed copy fails its health check, Ophio sets it aside and falls back to the system binary. Check agent readiness if that installation also cannot run. Downloads are kept in the computer data folder’s agents/ directory and can use about 1.5 GB.

Turning the setting off makes future tasks use the system installation again and removes managed copies, except a copy still needed by a running task. That copy is cleaned at a later check or restart. This is independent of app/database rollback below.

Database migrations

Before each schema migration the computer saves a SQLite backup beside its database, including committed WAL pages. A failed migration transaction does not leave a half-applied schema. Protect these backups because they contain sensitive records.

A database backup does not undo agent file edits, commands, delivered transfers or external actions.

Rollback

Read the full procedure first:

  1. Stop Ophio and confirm it is no longer running.
  2. Preserve the current database, its WAL/SHM files, configuration and migration backups together in protected storage.
  3. Reinstall the older package. Restore a backup from before the first migration it cannot read, using the original database filename. Never leave a newer WAL beside an older database.
  4. Start and check identity, grants and records before reconnecting devices. Keep backups until recovery is verified.

Older versions refuse newer schemas rather than downgrade them. Restoring loses later records and restores older pairing and revocation records. It does not roll back Android, phone drafts, downloads, native sign-ins or external work.

Earlier companion installs

The earlier program was named companion. On Linux, the new installer and ophio service install handle its managed service. On Windows, stop companion.exe yourself before any ophio.exe command; modern commands cannot reach the old process.

Ophio can rename earlier configuration and data folders. It never merges into or replaces an existing destination. A failed rename is reported and the old folder remains in use. Fix the cause rather than deleting either folder.

The current Android app has a different app ID from the earlier app. It installs alongside it and must be paired as a new device. Revoke the earlier device before removing the old app. Follow the package reference for rollback to the earlier program.