All articles
macOS 1.4.0 Release 7 October 2026

Cutouts, marks, and an assistant on your terms: Verbinal for macOS 1.4.0

The largest Mac release since the Cube Viewer. 1.4.0 brings over what Windows 1.4.1 shipped — cutouts, marks on images and cubes, figures with the marks on them, Remote Compute — and goes further with the AI assistant: you allow each session, decide kind by kind what it may do without asking, read why it proposes every change, and keep a log of everything it did.

The last time this blog covered the Mac was 1.3.0, the release that brought the Cube Viewer. Three quieter releases followed over the summer: 1.3.1 added Settings ▸ Endpoints and the FITS Viewer's own figure export, 1.3.2 added Workflows and French for every string in the app, and 1.3.3 was a reliability pass on Storage. Meanwhile the Windows app moved ahead, and Windows 1.4.1 became the measure: Mac 1.4.0 began as a plan to catch up with it, item by item.

Then came two full test passes, run by an AI assistant driving the app through its own tools, case by case, with a person watching the screen. They found more than the plan did — wrong pixels, wrong positions, wrong answers to the assistant — and much of this release is what they found, put right. If you are new to Verbinal for macOS, the 1.3.0 post is still a good tour of the app; this one is about what is new.

Cutouts: only the part of a file you need

A MegaPipe tile is 1.6 GB. If what you want is one galaxy in a corner of it, the whole tile is most of an afternoon's download and a good share of your disk. 1.4.0 adds cutouts, and there are two ways to make one.

Cut by CADC. Where the archive offers its SODA cutout service, CADC cuts the region on its side and sends only that: a few megabytes, at full resolution. Cut Out…, in an observation's detail in Search and in Research, opens an editor on the file's footprint: a circle or a box, RA and Dec in degrees or sexagesimal, sizes in arcminutes, and for a cube a wavelength range in nanometres. It starts from what your search asked for, checks as you type — off the file, partly off, the wrong shape for this file — and tells you the size it will be before you commit. And Search's Spatial cutout and Spectral cutout boxes, as on CADC's own search page, make Download fetch only the part of a file within the search's circle, or its wavelengths.

Cut on this Mac. Once an observation's file is downloaded, you can cut it locally: at once, offline, as often as you like — and it is the only way for files CADC will not cut. A local cutout is meant to be handed to other tools without apology:

  • The pixels are copied, not converted — the same BITPIX, the same scaling.
  • The header is rewritten so the same sky lands on the same pixel: CRPIX moved, LTV/LTM recording where the cut sits in its parent, SIP distortion kept valid, a HISTORY line saying where it came from, and a fresh CHECKSUM and DATASUM.
  • Mosaics keep the images you choose, and cubes are cut to the channels of a wavelength range, whether the axis is frequency, wavelength, wavenumber or velocity.
  • fpack files compressed with RICE_1 are cut by decoding only the tiles the region touches, and the cutout is written uncompressed.
  • Weight maps come along. A MegaPipe tile's weight map can be cut beside it with the very same box, once Verbinal has checked that the two lie on the same pixels. A file on another grid is offered greyed out, with the reason.

A cutout is kept in Research beside its observation, marked with what it was cut from and where, with a way back to the complete observation; downloading it again cuts it again.

The Cut Out sheet on the M31 MegaPipe u-band tile: the file MegaPipe.016.263.U.MP9301.fits, on this computer; a 4.2-arcminute circle drawn on the tile's footprint; and the size, about 29.5 MB of 400 MB. Two numbered hints explain Cut by and the size.
The cutout editor on the M31 MegaPipe u-band tile: a 4.2′ circle, about 29.5 MB of a 400 MB file, cut on this Mac from the copy already downloaded. The numbered hints in this post's screenshots were put up by an AI assistant through Verbinal's own tools.

A few megabytes of a 1.6 GB tile, at full resolution — cut where the data lives, or on your own Mac from the file you already have.

Marks on images and cubes

You can now draw on your data. Turn on Draw in the FITS Viewer's new Marks panel, click the image — or drag to size the mark — and type its label: a circle or a box around a source, a callout with a leader line to its label, or a label alone. Drag a mark to move it, a corner grip to resize it, double-click to rename it. Right-click it to copy its position in the form the Search box reads, centre on it, search there, export a figure around it, or delete it.

When the image has a WCS, marks are pinned to the sky, so a mark finds the same place in another image of the field. They keep their size on the subject as you zoom, turn with the view, and are kept with the file and its extension — however its path is spelled — so they are there when you open it again. The panel lists them with a filter, and sets colour, bold, label size and outline. They export as a DS9 region file (sky in fk5 with sizes in arcseconds, pixels counted from 1 as DS9 counts them) or as JSON.

Cubes have marks too. A cube mark lives on a channel: it is drawn on the slice showing that channel, Centre on Mark takes you there, and the volume shows every channel's marks where they sit in the cube. Your assistant can draw marks as well, and its marks say so.

The Verbinal for macOS FITS Viewer with a JWST NIRISS F356W image of the galaxy cluster field RXC J2211 in the inferno colormap with an asinh stretch. Four marks sit on the image — a callout to a star reading 'Star: JWST diffraction spikes', a box labelled 'Galaxy chain', a circle labelled 'Galaxy group', and a callout reading 'Peak ≈ 3.34 MJy/sr' — and the Marks panel lists all four as by the assistant. Numbered hints point at Draw, the marks' Export menu and Export Figure.
Marks on a JWST NIRISS image of the cluster field RXC J2211. All four were drawn by an AI assistant — the panel says by the assistant — and the peak is the value it read from the file with a pixel probe. The bubbles are its hints on Draw, the marks' Export menu and Export Figure…

Figures, and spectra that open as spectra

Export Figure in the FITS Viewer now draws the image's marks and labels — a Marks toggle turns them off — and shows either the whole image or the view on screen, as PNG at 2× or 4×, or as PDF. A mark's menu has Export Figure Around Mark…. The legend gives the figure's own centre and field of view; its “Center” used to be the WCS reference point, which is often not the middle of the image at all. The Cube Viewer's figures draw the cube's marks too: on a slice, those of the channel shown; in the volume, where they sit.

A FITS file whose data is a table used to open as a blank image a row of bytes tall — HST's _x1d spectra came out 38946×1. Now a spectrum opens as a spectrum: flux against wavelength, in the units the file gives, each echelle order its own line, the error as a band. A table that holds no spectrum says so and lists its columns. And a spectrum exports as a figure of its own, titled by the object (TARGNAME) and the instrument, with its axis units and error band, and a note of how large the error is — a high-S/N spectrum's band can be thinner than its line.

The FITS Viewer showing an HST STIS x1d file of SN 2023ixf as a spectrum: titled SN2023IXF, HST · STIS · 2023-05-22, flux in 10^-14 erg/s/cm²/Å against wavelength from about 5,300 to 10,200 Å, with the note that the ±1σ band from ERROR is a median 0.76% of the flux, narrower than the line. Numbered hints point at the title, the error note and Export Figure.
An HST STIS _x1d of SN 2023ixf, which used to open as a blank image one row tall. It now plots as a spectrum, titled by its target, and says its error band is narrower than the line.

Your assistant, on your terms

Verbinal's built-in MCP server lets Claude Desktop, Claude Code or any other MCP client work in the app with you, through about two hundred tools. Until now, the rules for that were one switch: Auto-apply, on or off. 1.4.0 replaces the switch with decisions you make in the open.

You allow each session. An assistant now starts by saying who it is and what it is here for, and Verbinal comes forward with a window: the client and its connection, the assistant's own description of itself — its own words, which Verbinal cannot check — and the instructions it will be given for this session, up to 250 words, filled from Settings ▸ AI Agent ▸ Session Instructions. Allow, and it receives your instructions word for word. Deny, and it is told to ask you first. Until you allow a session, no tool works but start_session and describe_app.

You decide what it may do without asking, kind by kind. Settings ▸ AI Agent lists every kind of change an assistant can make, each Allowed — it applies at once, with its reason in the session log — or Ask me, when it waits in Pending for you. What adds or changes is kept apart from what removes, replaces or stops, so allowing an assistant to tidy up what it made does not let it delete your files. By default notes, saved things, files, uploads, sessions, batch jobs and removing what an assistant itself made go ahead; sharing and every other removal ask. Your old Auto-apply choice carries over.

One kind always asks: what every later assistant is told. Adding or changing an AI Guide tool, or rewriting a tool's description, changes the instructions of every assistant after this one — so an assistant, or text planted in a file it happened to read, could quietly steer the next. Those changes now always wait for you, as deletions do.

Every change says why. Each write takes a one-sentence reason, and Pending shows it under the change — or “No reason given” — so you read why a delete is wanted before you apply it. Pending's History says who applied each change: you, auto-apply, or the assistant's background start. A proposal nobody applies expires after three hours instead of waiting, as one did for six days, to be applied to a world that had moved on. A change that fails says why. And the robot that opens Pending is now in every toolbar, always, with its count.

Settings, AI Agent section: kinds of change an assistant can make, each with an Allowed / Ask me switch — files saved on this Mac, adding to CANFAR storage, using the CANFAR allocation for sessions and compute or for batch jobs, sharing — then 'What every assistant is told', marked Always asks, and the start of 'What removes, replaces or stops'. Three numbered hints explain them.
Settings ▸ AI Agent: each kind of change Allowed or Ask me, what every later assistant is told always asking, and what removes, replaces or stops kept in a list of its own.

A log that explains itself. Session Logs, also in Settings ▸ AI Agent, keep each assistant session: every change with who made it and why, the app's own decisions and the rule behind each, every call with the CADC and CANFAR requests it made and what their outcomes mean, and services failing and recovering. Read it session by session, export it as text or JSON Lines, or delete closed ones; it is kept for ten days on your Mac.

The Session Logs sheet. The selected session, claude-code-blog-screenshots/1.0, is open; its log reads: the assistant connected to Verbinal 1.4.0; the person allowed the session of Claude, as the assistant presents itself, to set up screens and hints and capture them for the verbinal.com blog post, with the instructions 'Use only Verbinal and its tools for this work: no other apps, and no network connections outside Verbinal. Ask before anything destructive.'; then each call — start_session, get_current_view, capture_view, list_ui_targets, show_ui_hints — with how long it took.
The log of the session that took these screenshots. The assistant said who it was and what it was for; the session was allowed, with the instructions from Settings given to it word for word; and every call after is written out in plain words.

Answers within 45 seconds. An assistant's client can give up on a call after a minute, while some of Verbinal's waited two. Every call now answers within 45 seconds; work that takes longer — a 1.6 GB download, a ten-minute image probe — carries on, on a new activity bar along the bottom of the window, which says what is running, who started it (you, your assistant, or Verbinal itself), and why anything failed. Two short sound cues, the ones Windows and Linux play, mark when an assistant starts working and when it has gone quiet.

A bridge that survives restarts. An assistant started before Verbinal used to fail its handshake and give up for the whole session; one connected when Verbinal quit lost its tools until reconnected by hand. The bridge an assistant launches now answers the handshake itself, tells the assistant Verbinal is not running and what to turn on, and connects when Verbinal starts. It speaks every MCP version, the newest (2026-07-28) included.

An assistant that can see, point, and keep its hands off

An assistant can now look. capture_view gives it a picture of Verbinal's front window — whatever screen, sheet or Settings section is showing, with no Screen Recording permission, since the window is Verbinal's own. get_fits_image and get_cube_image return the viewers as you see them, with the map from a point in the picture back to the file's pixel, so mark the brightest source is something it can check against the picture.

And it can point. Verbinal reads its own windows the way VoiceOver does, so every control on every screen, sheet and Settings section can be pointed at, down to each entry of a list. show_ui_hints puts up rings and bubbles with the assistant's words — a numbered tour, or the rest of the window dimmed — placed by rules: bubbles never overlap each other, never cover what they point at, stay in the window and keep off images. An assistant can open a folded section or a sheet, select a tab, and close a sheet as Esc would. It never presses a button that acts, and never changes your settings: open_settings opens the right section, and you do the setting.

The Verbinal for macOS home screen at 1.4.0 with a numbered tour of three hints: 1, Remote Compute, ringed on its tile; 2, Pending, on the robot button in the toolbar; 3, the activity bar along the bottom of the window.
A numbered tour on the home screen, put up by an assistant with show_ui_hints: the new Remote Compute tile, Pending in the toolbar, and the activity bar. The home screen now runs in the same order as on Windows — Portal, Remote Compute and Storage first.

Any MCP client can connect. AGENTS.md, in the repository, is written for the assistant to follow: the command (Verbinal.app/Contents/MacOS/Verbinal mcp), the server name verbinal-canfar, and the entry for Claude Code, Claude Desktop, Codex, Cursor, Gemini, Windsurf and VS Code.

Remote Compute: the code your assistant runs, in view

An assistant could already run code on CANFAR with run_code, and the app showed no trace of it. Remote Compute is the screen for it, with its own tile on the home screen: the compute session's state, size and uptime, Start Session and Stop Session, every run — the assistant's and your own — with its code, output and errors and Run Again, and a box to run a Python or Bash snippet yourself. It uses your own CANFAR allocation, and until you choose a compute image it explains what it takes, with a link to the verbinal-execution watcher image.

Every run is remembered, with who sent it, when and how it ended, and is watched until its result arrives, whether or not anyone asks. A run survives signing out and quitting the app: after you sign in, every run still out is looked at again. A session whose image CANFAR could not pull shows Not ready with the reason, instead of “Starting” for ever. A session that no longer matches Settings says how it differs, with Restart with New Settings. And the screen tells you something worth knowing before you size a pool of workers: on CANFAR, os.cpu_count() counts the whole node — 192 — not the cores your session may use. Those are set by its CPU quota, in /sys/fs/cgroup/cpu.max, and the screen says how to read it.

The Remote Compute screen: the session running, with Start Session, Stop Session, Settings and Open Folder in Storage; a banner saying the session differs from Settings, with Restart with New Settings; the list of runs, all sent by the assistant; and the newest run's Python code and output — os.cpu_count(): 192, cores in the quota: 1.0. Three numbered hints point at the run, the output and the restart button.
Remote Compute after a run an assistant sent: its code, and an output that makes the point — Python counts 192 cores, the session's quota is one. Above, the session says it no longer matches Settings, with Restart with New Settings.

The Portal, Batch Jobs and Storage

  • The Portal is laid out as on Linux and Windows: platform load, storage and batch jobs across the top, active sessions the full width, then CANFAR images beside recent launches — one column in a narrow window. Launch Session opens the form in a sheet, the progress window closes by itself once the launch goes through, and a launch that fails keeps the form to put right.
  • Session cards show CPU and RAM for every session. A flexible session used to say only “FLEX”; it now shows what it uses, and a fixed one what it was given.
  • CANFAR images by type and by project, as chips with counts. Find in Registry… searches the registry behind the platform for a colleague's build or a tag the catalogue has not picked up, and Add keeps it among your images. Long lists in the launch form — projects, images — open a panel you can type into.
  • Batch Jobs keeps up with thousands of jobs. With ten thousand jobs, opening the list took two seconds and every check froze it again. It now shows the newest 500 with Show More, a filter on every tab, and a History tab that remembers finished jobs — and why one failed — after CANFAR has forgotten them.
  • Notifications for a session that comes up or fails to start, and polling that follows what is happening: about five seconds after a change, easing off while nothing moves.
  • Storage warns when a file that usually holds secrets is public. A real CANFAR home had .token, .config and .bashrc readable by anyone, and nothing said so. Such a file is now marked, with Make Private. A folder deletes with everything in it, and a 200 GB quota reads as 200 GB, counted as Finder counts.

Search and Research, day to day

  • A Radius field. A cone search looked within 1′ of the target unless you knew to type a radius after it. The Spatial section now has a Radius — degrees, 5' or 30 arcsec — kept with saved and recent searches.
  • ADQL checked as you type against CADC's own schema: each problem underlined and listed, Execute off until the query can run — LIMIT where ADQL writes SELECT TOP n, a column the archive does not have (with the name that exists), a column two joined tables share. Nothing it cannot be sure of is flagged.
  • Cancel a long search, on the form and in the ADQL editor (Esc); the results already shown stay. With CADC's archive down, a search now says so after two minutes instead of spinning for four.
  • Each calibration level is its own result, so opening one row no longer lands on another, and a transient is found however it is written: AT 2023ixf, 2023ixf or SN 2023ixf.
  • Copy anything. Right-click a result to copy a value, the observation's details, a row or the page, as tab-separated text that pastes into a spreadsheet; the Search box now reads a pasted 00:42:44.3 +41:16:09.
  • Research without the file. Save to Research keeps an observation and a place for notes without downloading it; Remove File… frees the disk and keeps the notes. A record now describes the file it actually holds, from the archive's details for its own plane — one had said g band for a u-band file.

What testing found

Some of what the test passes found were rough edges. Others were wrong answers, and those are worth saying plainly:

  • Distortion was ignored. On images with SIP distortion — HST's calibrated frames, many ground-based pipelines — the crosshair, Go To, bookmarks, blink alignment and the assistant's sky readouts were up to about 8 pixels (0.3″) out toward the corners of a WFC3 frame. The polynomial now applies both ways and agrees with astropy to 10−9° and 10−6 px.
  • Rotation on modern headers. Headers that give the rotation as a PC matrix beside CDELT — JWST's i2d images among them — had it ignored. And the value under the cursor came from the vertically mirrored row: the RA and Dec were right, the number was not, except on data symmetric top to bottom.
  • Every CFHT .fz frame was unviewable. A Rice block that fpack stores raw — noise, cosmic rays, anything busy — was read as Rice codes, and the rest of the tile came out as horizontal streaks, in the viewer and in local cutouts. The decoder now follows cfitsio block for block, is checked value for value against files cfitsio wrote, and reads 8- and 32-bit images as well as 16-bit.
  • Viridis was not viridis. Both viewers drew a teal-to-orange approximation, and figures went out labelled VIRIDIS; inferno, magma and plasma were 9-point approximations up to 17/255 off. All four are now matplotlib's own 256-entry tables.
  • Very large images over 4 GB, or 500 million pixels, were refused whatever the Mac had free. Now the free memory decides: a MegaPipe tile opens, drawn from a block average so stars a pixel across survive, while the readout, WCS, marks and Go To still read every pixel.
  • A Mac set to another calendar — the Buddhist one, say — showed dates in the year 2569 and asked the archive for the wrong release date. Dates sent to CADC are now always Gregorian.
  • Positions just under a whole minute printed as 23h59m60.00s, and Go To on a French Mac refused 10,68. Both read and write positions as the rest of the app does now.
  • Downloads that held nothing — a 0-byte package, a tar of 1024 zero bytes — were recorded as downloaded, and a download that took over five minutes failed however steadily it arrived. An empty download is refused now, a record whose file is missing says so with Download Again, and only a five-minute stall ends a download.
  • A delete that did nothing said it had. CANFAR answers a delete of a session it does not have with success, so a bulk delete of one real and one made-up id said “Deleted 2 of 2”. Verbinal now checks the ids first, and asks the platform afterwards whether the session is really gone.
  • An assistant's download replaced your file. Downloading from your storage into Downloads deleted a file of the same name already there. Yours is kept now, and the download takes a timestamp in its name.

Privacy, source, and how to get it

The privacy posture has not moved. No analytics, no telemetry, no third-party services; your credentials stay in the macOS Keychain, and traffic goes directly to CANFAR and CADC over HTTPS. Session logs and the archive details Research keeps stay on your Mac. The one new thing to know is small: a cutout by CADC sends CADC the region you asked for, which is how it knows what to cut. A cutout on your Mac sends nothing at all.

Verbinal for macOS is free and open source under the Mozilla Public License 2.0, with the full source at github.com/szautkin/canfar-macos. It runs on macOS 14 (Sonoma) or newer, in English and French, with VoiceOver naming every control — a test now fails on any that has no name. Search and both viewers work without signing in; Portal, Remote Compute and Storage need a free CADC account. It is on the Mac App Store, and the release page on GitHub has an unsigned .dmg and .zip with SHA-256 checksums.

Get Verbinal for macOS 1.4.0

Free and open source under MPL-2.0. macOS 14 or later and a free CANFAR account. Search and the viewers work without signing in — and your data stays on your Mac.

Download on the Mac App Store Source Code