What changed.

Released changes to the Assetlib SDKs, the audit, and the hosted console, newest first. Each entry names the versions it affects, where to get them, and what they do not cover yet. Which SDK version supports what is in the table at the end.

Only released work is listed: a tagged release, a version on npm, or a change live on the hosted console. The SDKs are developer previews published as GitHub releases and tags, not on npm or Maven Central. Planned work, such as experiment and analytics connectors, hosted MCP tools, and usage billing, appears here when it ships. Dates are US Eastern time. Full release notes: JavaScript and Expo, Swift, and Android.

Tintable icons

A placement can declare that its artwork is a single-color icon. Assetlib delivers the shape, and your app supplies the color when it draws it, from its theme, a selected state, or dark mode.

  • Declare "rendering": "template" on a placement in assetlib.catalog.json and regenerate its reference. Placements without the field are unchanged.
  • Upload the icon as an SVG. One that uses currentColor is ready as it is; one drawn in a single fixed color is converted, and the console says so. An SVG with more than one color is rejected as a tintable icon.
  • A tintable placement accepts only tintable icons, and other placements never receive one. Tintable icon placements do not count toward the placements meter.
  • Expo apps pass tintColor, which colors the bundled and the downloaded icon alike. In SwiftUI the SDK applies template rendering and the app sets foregroundStyle; in Compose the app draws the returned bitmap with Icon and its tint.
  • When an SDK finds published artwork whose rendering differs from the placement's, it downloads nothing and keeps showing compatible cached artwork or the bundled icon.
  • @assetlib/cli 0.2.0 also counts Swift call sites such as artwork.travel.coast as references in assetlib sync --references.
  • Hosted consoleLiveconsole.assetlib.dev
  • JavaScript and Expo SDK0.5.0-preview.1Developer preview. Tarballs on the GitHub release, not npm. Includes @assetlib/cli 0.2.0.
  • Swift SDK0.4.0-preview.1Developer preview. Swift Package Manager, exact version.
  • Android SDK0.4.0-preview.1Developer preview. AAR and SHA256SUMS on the GitHub release, not Maven Central.

Limits. In-app icons only: launcher icons and launch screens stay in the app binary. Sources must be SVG; PNG and multi-color icons are not supported. Android apps must recompile when they move to the new AAR. Checked with unit and shared contract tests; no iOS simulator, Android emulator, or device run of a tintable icon is claimed.

Placements as an outline and per platform

The Placements page gains a List, Outline, and Platforms switch. The choice is kept in the page address, so a link or a reload opens the same view.

  • Outline opens each placement into its state and variant images and counts the required images still missing.
  • Platforms sets each placement against iOS, Android, Expo, and web: the screen and build that each platform's newest build declares, its displays in the last 30 days, and a warning when a platform's newest build no longer declares the placement.
  • The SDK configuration the console exports stays within the limits the SDK patch releases below enforce: at most 16 signing keys and 4096 bytes.
  • Hosted consoleLiveconsole.assetlib.dev

Limits. The platform columns come from builds registered with assetlib sync, a developer preview. Displays come only from apps that turn on the JavaScript SDK's opt-in usage reporting; the Swift and Kotlin SDKs report nothing.

One public configuration contract across the three SDKs

Patch releases that make the JavaScript, Swift, and Kotlin SDKs accept and reject the same public SDK configurations.

  • A configuration pins a single signing key, a set of 1 to 16 distinct Ed25519 public keys of at most 256 bytes each, or both; a single key given with a set must belong to it. Swift now accepts a configuration with only a key set.
  • A configuration over 4096 UTF-8 bytes is rejected, unknown fields included. The Android SDK's previous limit was 8192 bytes.
  • Explicit nulls in known fields, a keyId without an explicit single key, and keyIds that do not match the keys in length and order are rejected.
  • The JavaScript SDK also accepts the configuration as a raw JSON string. @assetlib/cli 0.1.1 changes only its README, which now installs the CLI from the release tarball.
  • JavaScript and Expo SDK0.4.1-preview.1Developer preview. Tarballs on the GitHub release, not npm. Includes @assetlib/cli 0.1.1.
  • Swift SDK0.3.1-preview.1Developer preview. Swift Package Manager, exact version.
  • Android SDK0.3.1-preview.1Developer preview. AAR and SHA256SUMS on the GitHub release, not Maven Central.

Limits. Configurations from the hosted console are unaffected. These patches were checked with unit and shared contract tests; no iOS simulator, Android emulator, or device run is claimed for them.

Insert Assetlib artwork into Figma

The console now serves a workspace's prepared images to the Figma plugin's Insert tab, read with a draft token.

  • Insert lists the workspace's images and the artwork on each placement, and places one in the Figma file as an image-filled frame.
  • Inserted artwork stays linked to its placement, so the plugin can send an edited frame back to that placement as a draft. Publishing stays in the console.
  • Only prepared sizes are served, privately and uncached. Originals are never served to the plugin.
  • Hosted consoleLiveconsole.assetlib.dev
  • Figma pluginFrom sourceDevelopment preview. Build from source and import into Figma desktop.

Limits. The Figma plugin is not listed in Figma Community and has no tagged release. Images uploaded before prepared sizes were introduced on October 7, 2026 show “Re-upload needed” and cannot be inserted.

Members, invitations, settings, and an audit log

  • Invite people by email and role. The owner copies a one-time link that works once, for the invited address only, for seven days.
  • Owners change roles in the members table. A workspace always keeps at least one owner.
  • Settings have their own sidebar: Profile and Sessions for your account; General, Members, and Activity for the workspace; Connect, Tokens, and Integrations for developers; Approvals for releases.
  • Activity is the owner's audit log of publications, promotions, restores, approvals, members, tokens, and integrations, with filters and CSV export.
  • A command menu opens with ⌘K or Ctrl+K.
  • Hosted consoleLiveconsole.assetlib.dev

Limits. Assetlib does not send invitation email yet. SSO, custom roles, and self-service workspace deletion are not available; deletion is by request.

The console moves to console.assetlib.dev, with a new layout

  • Sign in with GitHub at console.assetlib.dev.
  • A top bar with the workspace switcher, a sidebar with Settings at the bottom, an address for each section, an Overview page, a page for each placement and image, and filter bars on the lists.
  • Hosted consoleLiveconsole.assetlib.dev

Limits. Delivery and SDK configurations that name the previous console address keep working there, and delivery never redirects. Sign-in moved to the new address.

Staging, and light, dark, and experiment variants

Each SDK can follow a staging environment and resolve appearance and experiment-arm variants of a placement.

  • A staging environment in the public configuration, with its own manifest path.
  • Appearance and arm cells resolve in a fixed order: arm and appearance, arm only, appearance only, then the plain image. An arm never borrows another arm's image. Expo components follow the system appearance.
  • An optional decide callback supplies the arm from the experiment tool the app already uses, with a bounded wait.
  • A pinned signing key set in the public configuration, and cache storage that survives key-set changes, with a one-time migration of the existing cache.
  • JavaScript and Expo only: opt-in usage reporting of resolve, display, and fallback events, off by default. This is also the first JavaScript release with named state sets, paginated catalogs, image-retention policies, and verified Lottie JSON for the app's own player in browsers.
  • Swift and Kotlin include the image descriptions first released in 0.2.1-preview.1.
  • JavaScript and Expo SDK0.4.0-preview.1Developer preview. Tarballs on the GitHub release, not npm.
  • Swift SDK0.3.0-preview.1Developer preview. Swift Package Manager, exact version.
  • Android SDK0.3.0-preview.1Developer preview. AAR and SHA256SUMS on the GitHub release, not Maven Central.

Limits. Assignment comes from the app's own experiment tool. Experiment and analytics connectors are planned, and Assetlib collects no experiment results. The Swift and Kotlin SDKs report no usage, do not resolve named state sets or catalogs, and show an animation's still poster.

Build sync from CI, a developer preview

  • assetlib sync registers a build and its placement catalog with the console over HTTPS, from CI or a terminal.
  • assetlib check compares the generated TypeScript references with the catalog, assetlib hash prints the catalog's canonical hash, and assetlib adopt previews turning bundled Expo image call sites into declared placements; it is a dry run by default.
  • JavaScript and Expo SDK@assetlib/cli 0.1.0Developer preview. CLI tarball on the v0.4.0-preview.1 GitHub release, not npm.

Limits. Sync sends the catalog, the build and CI details, and path:line references to placement keys, never source contents or image bytes. References are literal matches, so a missing one is not evidence that a placement is unused. The current CLI is 0.1.1, on the v0.4.1-preview.1 release; it is not published to npm.

Staging and production, approvals, app tokens, builds, and webhooks

  • Publish to staging, promote to production, and restore each environment on its own. Production can require an approval that applies only to the exact release reviewed.
  • App tokens with declare and draft scopes, for CI and tools.
  • Builds registered with assetlib sync bring their declared placements and the code references behind them, so each placement shows where it is used.
  • Placements can hold appearance and arm variants. Artwork sent from the Figma plugin arrives as a draft image, optionally bound to a placement in the draft.
  • Placements show the displays reported by apps that turn on the JavaScript SDK's usage reporting.
  • Signed webhooks and Slack incoming webhooks for publication, approval, build, and archive events.
  • The public SDK configuration includes the workspace's signing key set, and the API is described in OpenAPI.
  • Hosted consoleLiveconsole.assetlib.dev

Limits. Build sync is a developer preview and the Figma plugin a development preview. Swift and Kotlin apps report no displays.

Lottie animations, named states, and dynamic catalogs in the console

  • Upload Lottie animations. Each one carries a still poster for apps that do not play it.
  • A placement can hold named visual states, one image per state.
  • A dynamic catalog publishes a list of images with paginated, signed delivery.
  • Placements are grouped by screen, and a release is reviewed against what is published before it ships.
  • An account can create more than one workspace.
  • Hosted consoleLiveconsole.assetlib.dev

Limits. Named states and catalogs reach apps through the JavaScript SDK from 0.4.0-preview.1, which also resolves Lottie JSON in browsers for the app's own player. Swift and Kotlin apps show a placement's plain image and an animation's still poster.

The artwork audit on npm, and as an agent plugin

  • npx -y @assetlib/audit@0.1.0 <app-root> --assets assets --references src inventories an app's PNG, JPEG, and WebP files: measured bytes, exact duplicates, dimension candidates, and optional reference hints.
  • It runs on your machine with no account. It uploads nothing and changes no files; npm fetches the package on first run.
  • The assetlib-audit plugin runs the same pinned version in Claude Code and Codex, explains the evidence, and proposes at most a few placements for a first migration, keeping bundled fallbacks.

Limits. No reference found is a review candidate, never proof that an image is unused. The audit never deletes, uploads, or publishes.

Image descriptions that follow the artwork

  • Optional localized descriptions travel with the signed image, so a cached or restored image keeps its own description, and bundled artwork carries its own declared ones.
  • Lookup tries the exact language tag, then less specific tags, then the declared default.
  • Apps choose descriptive or decorative use for each image and keep their own control labels.
  • The console edits each image's descriptions by locale, with a default language.
  • JavaScript and Expo SDK0.2.1-preview.1Developer preview. Tarballs on the GitHub release, not npm.
  • Swift SDK0.2.1-preview.1Developer preview. Swift Package Manager, exact version.
  • Android SDK0.2.1-preview.1Developer preview. AAR and SHA256SUMS on the GitHub release, not Maven Central.
  • Hosted consoleLiveconsole.assetlib.dev

Limits. These releases were tagged from a separate branch; JavaScript 0.4.0-preview.1 and Swift and Kotlin 0.3.0-preview.1 carry the same changes. Android apps must recompile when they replace the AAR. VoiceOver and TalkBack listening and physical-device acceptance have not been run.

PNG, prepared sizes, and SVG in browsers

  • The console keeps each new upload's exact original privately and prepares delivery sizes from it: lossless PNG and WebP for artwork, compressed WebP for photos. A restricted static SVG becomes a normalized browser vector plus native rasters.
  • The SDKs choose a signed PNG or WebP size for the pixel size the app requests (the placement's size by default) and check its type, hash, and dimensions. When a candidate fails they try the next one, then the legacy WebP, then cached history, then the bundled image.
  • The JavaScript SDK's browser adapter can opt into the normalized SVG.
  • JavaScript and Expo SDK0.2.0-preview.1Developer preview. Tarballs on the GitHub release, not npm.
  • Swift SDK0.2.0-preview.1Developer preview. Swift Package Manager, exact version.
  • Android SDK0.2.0-preview.1Developer preview. AAR and SHA256SUMS on the GitHub release, not Maven Central.
  • Hosted consoleLiveconsole.assetlib.dev

Limits. No native SVG rendering; Swift and Kotlin use the prepared rasters. Images uploaded earlier are labelled original not retained. An Android app with its own image decoder must update it: the decoder now returns AssetImageInfo?.

First SDK developer previews

  • Signed artwork delivery into typed placements: pinned Ed25519 signatures, app-scoped manifests, SHA-256 image checks, release sequence checks, a bounded verified cache, and bundled fallbacks.
  • A TypeScript core with an Expo adapter for iOS, Android, and web; SwiftUI Image accessors for iOS 17 and macOS 14; Android bitmaps and Compose images for Android 8 (API 26) and later.
  • JavaScript and Expo SDK0.1.0-preview.1Developer preview. Tarballs on the GitHub release, not npm.
  • Swift SDK0.1.0-preview.2Developer preview. Swift Package Manager, exact version.
  • Android SDK0.1.0-preview.1Developer preview. AAR and SHA256SUMS on the GitHub release, not Maven Central.

Limits. Still WebP artwork only. Swift 0.1.0-preview.1, tagged the same evening, is superseded by 0.1.0-preview.2, which fixes Swift 6 actor isolation in generated image accessors.

Compatibility

Each SDK has its own version numbers and follows one signed release contract. A cell names the first released version of that SDK with the feature, and later versions keep it. Every version is a developer preview.

First SDK version that supports each feature
FeatureJavaScript and ExpoSwiftAndroid
Signed releasesschemaVersion: 1Ed25519 signatures checked against pinned keys, release numbers that never go backwards, SHA-256 image checks, a verified cache, and bundled fallbacks. Still WebP images.0.1.0-preview.10.1.0-preview.20.1.0-preview.1
Placement catalog and generated referencesA checked-in catalog of placements, turned into typed references offline.0.1.0-preview.10.1.0-preview.20.1.0-preview.1
PNG and WebP sizesrenditionSchemaVersion: 1The SDK picks a signed size for the pixel size the app asks for.0.2.0-preview.1Also SVG in browsers, opt-in.0.2.0-preview.1No SVG; uses the prepared rasters.0.2.0-preview.1No SVG; uses the prepared rasters.
Image descriptionsaccessibilityLocalized descriptions that stay with the image they describe. 0.2.1 was tagged from a separate branch; JavaScript 0.4.0 and Swift and Android 0.3.0 carry it.0.2.1-preview.10.2.1-preview.10.2.1-preview.1
Staging environmentenvironment: "staging"0.4.0-preview.10.3.0-preview.10.3.0-preview.1
Signing key setpinnedPublicKeys1 to 16 trusted keys in the public configuration. The three SDKs accept and reject the same configurations from JavaScript 0.4.1 and Swift and Android 0.3.1.0.4.0-preview.10.3.0-preview.1A key set without a single key from 0.3.1-preview.1.0.3.0-preview.1
Light and dark variantsvariantSchemaVersion: 10.4.0-preview.10.3.0-preview.10.3.0-preview.1
Experiment armsvariantSchemaVersion: 1Arm variants, with an optional decide callback that takes the arm from the app's own experiment tool.0.4.0-preview.10.3.0-preview.10.3.0-preview.1
Named state setsstateSchemaVersion: 10.4.0-preview.1Not supportedShows the placement's default image.Not supportedShows the placement's default image.
Dynamic catalogscatalogSchemaVersion: 1Signed, paginated lists of images.0.4.0-preview.1Not supportedNot supported
Lottie animationsanimationSchemaVersion: 10.4.0-preview.1Verified Lottie JSON for a player the app supplies.PlannedPlayback. Shows the still poster today.PlannedPlayback. Shows the still poster today.
Usage reportingOpt-in counts of resolved, displayed, and fallback images. Off by default.0.4.0-preview.1PlannedSends no reports today.PlannedSends no reports today.
Tintable iconsrendering: "template"Single-color icons the app colors when it draws them. When a placement and its published artwork disagree, the SDK downloads nothing and keeps compatible cached artwork or the bundled icon.0.5.0-preview.1Expo passes tintColor to the bundled and the downloaded icon.0.4.0-preview.1Template rendering; the app sets foregroundStyle.0.4.0-preview.1The app tints the returned bitmap.

Oldest supported clients. JavaScript and Expo 0.1.0-preview.1, Swift 0.1.0-preview.2, and Android 0.1.0-preview.1. Every release still gives each placement a signed WebP image in the first contract’s format, and these versions ignore the fields they do not know, so an app that shipped with one keeps showing still images from current releases, without the newer features. Swift 0.1.0-preview.1 is superseded by 0.1.0-preview.2.