0806 | Product launches: StepGrab, BackEngine MCP, Capacity Desktop, Wispr Flow Notetaker

||Download

Show notes

Mia:Hello and welcome back to ProductHunt Daily.

This episode is produced by Bri. Bri uses advanced AI technology to turn the feeds you care about into podcasts made for listening. Contact us at hi@bri.so.

Transcript

Mia: Hello and welcome back to ProductHunt Daily. I'm Mia, and as always, I'm joined by my co-host Milo.

Milo: Hey everyone, Milo here. We've got a packed lineup of new launches for you today, so let's dive right in.

Mia: We're kicking things off with StepGrab, a native Mac app that turns any task into a step-by-step guide, plus a smart new launch called BackEngine MCP.

Milo: And that's just the start — we'll also be covering a free Mac app that turns plain English into real apps, meeting notes that get the details right, and much more.

Mia: StepGrab is a new Mac app that turns any task into a step-by-step guide. The idea is simple: you record yourself doing something once, and it rebuilds every click as an annotated screenshot, with a numbered arrow and a step description written by a model that runs entirely on your Mac.

Milo: And the pitch is aimed at people who document workflows — whether that's for a colleague, a support ticket, onboarding material, standard operating procedures, tutorials, or a bug report. The maker positions it as an alternative to tools like Scribe or Tango, which they call genuinely good, but web-first and subscription-only.

Mia: StepGrab's pitch is that it captures every app on the Mac, not just the browser, and it runs fully offline — no account required, and nothing gets uploaded. It needs macOS 14.0 or later on Apple Silicon or Intel, it's built with Apple's native StoreKit, and the maker claims there are no third-party analytics or ad SDKs tucked in.

Milo: Pricing is worth noting because it's flexible. There's a free tier covering up to five guides with ten steps each — no account or credit card needed. Then Pro comes in at 2.99 a month, 12.99 a year, or a one-time lifetime purchase of 44.99. There's even a launch code that drops the lifetime to 34.99, though the maker notes that code only works on Apple accounts that have never bought anything in the app before — and that's an Apple rule, not theirs.

Mia: Before you export, you can review the steps, delete the ones you don't want, undo the last capture, and pick your arrow color, size, and style. Worth a fair caveat, though — the maker's own materials don't fully agree on what formats you can export. The launch description lists GIF, PDF, MP4, clickable HTML, Markdown, and vertical video, while the product site's features and FAQ describe PDF, animated GIF, and MP4 as three ways to export. So if you care about a specific export format, that's worth checking first.

Mia: BackEngine MCP launched with the tagline "Make private company knowledge usable for AI." The maker's diagnosis: most companies plug Claude or ChatGPT into Slack, email, calls, tickets, and their CRM through a single MCP — which they call raw pipes into scattered systems. The model reads a slice and guesses the rest.

Milo: BackEngine connects to those same tools, but the claim is that it reads everything first, joins it into one permissioned record per account, and keeps it current — so Claude and ChatGPT work from the whole picture, not just fragments. In a reported head-to-head against direct connectors, the maker claims 67% fewer errors, 2.4 times more key facts, and 65% fewer tokens.

Mia: Founder Eli frames the goal as the opposite of Google's indexing problem — making private company knowledge safe and usable for AI, with the mission that every piece of truth about a customer relationship should be instantly accessible to the person who needs it, at the moment they need it. On launch day, he walked through his own workflow in Claude: a quick summary of missed email and Slack with drafted replies, a list of site visitors matching his ideal customer profile with emails ready, a live view of what had shipped and which tickets were active, and a seven-day spend summary that flagged a possible billing mistake.

Milo: But the discussion raised some genuinely open questions. One commenter asks what "permissioned" actually covers — the record tracks which customer's data it is, not which employees may see which parts. And support history is full of notes that are true but shouldn't travel: "do not give this account another refund," a one-off pricing exception, a comment written on a bad day. Their concern is that a reply drafted from all of that could surface something nobody intended to share.

Mia: Capacity Desktop is a free Mac app that turns plain English into real apps, built and stored locally — as the makers put it, on your machine, not someone else's servers. Baptiste and Samuel position it as an alternative to Lovable and Bolt: they wanted the same magic without the rent — no marked-up AI credits, no code sitting in a cloud workspace, and no export button treated as an afterthought.

Milo: The stated capabilities are broad. You start from more than eighty hand-picked design templates, or import an existing repo. You bring your own AI key — Claude, GPT, Gemini, Grok, Kimi, DeepSeek all mentioned — billed at cost with a built-in spend dashboard. Every change becomes a restorable version with one-click rollback. A publish tab connects GitHub and Vercel, preflights your environment variables, and deploys in one click. And there's a zero-terminal setup that detects and installs dev tools like Git and Node.

Mia: Projects stay normal folders and git repos you can open in any editor. Right now it's free during beta with no sign-up, and the makers say a future paid plan would be a one-time license — never a subscription, never credit markups. It's macOS on Apple Silicon only for now, with Windows and Linux on the roadmap.

Milo: There's a note of inconsistency worth flagging. The product website's FAQ, which describes Capacity more broadly, says paid plans use credits that never expire — which is a different pricing description from the desktop launch post.

Mia: Community discussion is interesting too. One commenter compared it to Glaze by Raycast, noting Capacity seems focused on web-distributed apps, and asked whether the desktop apps are native or Electron. Another commenter, Gero, a solo founder with no development background, stood out in the thread as well.

Mia: Wispr Flow Notetaker launched today with the tagline "meeting notes that get the details right," from the team behind the Wispr Flow voice-dictation product. It's on Mac, English only for now, and free to try — the maker says the goal is to get the core right before rolling out to other languages and platforms.

Milo: The design bet, per Wispr's Tanay, is that almost nobody reads a raw transcript even though everything downstream builds on it — and a single wrong name or acronym travels everywhere. So before the meeting, it checks the calendar invite so names are spelled correctly, brings in terminology you've already taught Wispr Flow, and captures your microphone and everything you hear as two separate streams, so your words never get mixed up with someone else's.

Mia: Transcripts use real names rather than "Speaker 1" and "Speaker 2," and a fix you make after the fact applies across the whole transcript. Around that core: a brief before each meeting, one-click catch-up if you miss something mid-meeting, summaries that call out decisions and next steps, one-tap capture for calls that were never on the calendar, and MCP support to pull any meeting into Claude or ChatGPT without copy-pasting.

Milo: It's aimed at people who live in back-to-back meetings and depend on notes for action items. The company's Head of Growth describes his own problem as transcript drift — other people were getting his things to do, and he was getting theirs. And one of his GTM teammates calls it the first note-taker they've used that consistently nails diarization, with action items landing with the right people — and says they now trust it enough to rely on it.

Mia: Let's start with a new open-source project called Aegisora, which just launched on Product Hunt. It's positioned as a "narrow control plane" for AI agent tool calls and API calls, with an MIT license, and it's aimed at application security and engineering teams. The maker frames the core problem as a runtime security blind spot as companies move from simple chat interfaces to fully autonomous agents.

Milo: So essentially a security layer for when AI agents are actually executing things in production, rather than just answering questions.

Mia: Right. Aegisora is described as a zero-latency proxy that sits between agents and their tools. The maker claims it intercepts malicious AI actions, enforces least-privilege access to APIs, masks personally identifiable information on the fly, and produces readable audit logs, all without heavy middleware. Time to pause here — these are the maker's own claims, not independently verified results.

Milo: What does it actually claim to block?

Mia: A few categories: semantic prompt injections, unauthorized API calls, and PII leaks. Under the hood it says it actively intercepts payloads and has a dedicated PII masking engine tied to GDPR and HIPAA data redaction. It also defaults to fail-closed during proxy or network disruptions, meaning traffic stops rather than passing through unprotected. And it generates immutable, human-readable audit trails aimed at SOC 2 and ISO compliance reviews.

Milo: Where would teams actually run something like this?

Mia: It's designed as a lightweight sidecar proxy inside your own VPC, and the maker says raw payloads and PII never touch external third-party infrastructure. Listed integrations include OpenAI, Anthropic, Azure AI, AWS Bedrock, GitHub, Slack, and Vercel. There are three tiers: a Developer Sandbox that's open source and described as free forever with local monitoring and rule-based blocking; a Design Partner tier with limited spots for cloud-managed runtime governance and PII masking; and an Enterprise VPC tier with dedicated proxy clusters, single sign-on, and a compliance suite. One caveat worth flagging — the product site lists a SOC 2 Type II and ISO 27001 compliance story, but those are self-presented and not verified in what's been published so far.

Milo: Next on today's list is ngrok AI Gateway, or ngrok.ai — a hosted gateway that puts public providers, custom endpoints, and self-hosted models behind a single URL and a single access key.

Mia: This one comes from a product manager at ngrok named Niji, who says the team built it after running into familiar AI-infrastructure pain themselves: juggling multiple gateways and SDKs, sharing provider keys across config files, checking usage across several dashboards, maintaining fallback logic, and accidentally exposing models meant to stay private.

Milo: What's the setup workflow like?

Mia: The idea is you point your OpenAI, Anthropic, or Vercel AI SDK at the gateway URL, swap in a single API key, and route without rebuilding your integrations. The documentation's example routes first to a self-hosted model, with hosted models as fallbacks. It's aimed at two kinds of teams: those experimenting across providers, and those running models on private infrastructure.

Milo: And the private-model support is the big differentiator, right?

Mia: Exactly — that's the most cited piece. Local LLMs connect through ngrok's own network, so they work alongside hosted providers without public IPs, inbound ports, or exposure to the public internet. One commenter who runs models on their own infrastructure called that the thing that solves a real security headache. Another described internal compliance cases where every gateway they'd tried assumed everything sat behind a public API.

Milo: What about the provider keys and access control?

Mia: The product site lists bring-your-own-key, so you can use your current OpenAI, Anthropic, or custom provider keys and keep your existing rates, and there are scoped access keys per team or use case. So the near-term tradeoff is more centralization in one gateway, but in exchange you get private-model routing and fewer keys floating around.

Milo: Next up, Cloudflare Wallets — a new programmable wallet layer for the "agentic internet," announced on the Cloudflare Blog as part of the company's Agents Week. The headline frames it as a programmable wallet, built for a future where AI agents discover, use, and pay for services autonomously, giving agents a secure way to transact with APIs, content, and digital services.

Mia: So what are the named capabilities?

Milo: Virtual wallets, spending controls, and machine-friendly payments. Cloudflare frames the product as financial infrastructure for the next generation of AI applications. And it's worth noting these are all the maker's own descriptions — nothing here is independently verified, and the supplied evidence includes no pricing, no availability date, no technical architecture, and no deployment details.

Mia: What did the community make of it on Product Hunt?

Milo: The discussion is fairly limited. One commenter said they were excited and had already claimed their username. Another wrote, "finally, no need to approve payments," which implies the wallet removes a manual approval step. A third person — a self-described long-time Cloudflare user — praised the company's CDN as incredibly fast and the setup as seamless, though that comment is really about Cloudflare generally rather than Wallets specifically. And a fourth commenter asked what problem Cloudflare most often saw in websites or apps that led it to build Wallets this way.

Mia: So a big announcement, but with a lot still to be filled in about how it actually works and when it ships.

Mia: Finally, Dover MCP — a new integration from Dover, the startup-recruiting marketplace, introduced by founder George. It connects Dover's free applicant tracking system to ChatGPT, Claude, Cursor, and other AI tools through the Model Context Protocol. It's available today as part of Dover's free ATS for startups, which Dover says covers scheduling, sourcing, job board integrations, and pipeline tracking.

Milo: And the target user is a startup already on Dover who wants to run hiring tasks from an AI chat?

Mia: Exactly. Per the launch description, users can review the strongest applicants across open roles, schedule and prepare for interviews, add notes, update candidate stages, and identify which pipelines need more sourcing. The maker's example workflow: ask Claude to find a candidate, schedule an interview, prepare the hiring manager, add debrief notes, move the candidate forward, and draft the follow-up email. And Cursor, Codex, and other MCP clients can connect using a generic HTTP configuration with the Dover MCP server address.

Milo: What about the built-in AI features Dover describes?

Mia: Application review and scoring against job-specific criteria, an AI interview notetaker that transcribes video interviews and pre-fills scorecards, and concise interview synopses that highlight strengths, concerns, and next steps. All maker claims, not verified results. On the privacy side, Dover says the connection uses OAuth scopes you choose — read access covers jobs, applications, candidates, and interviews. So the takeaway: for a startup already running Dover, this is a way to pull hiring operations into a conversational AI workflow without a separate recruiting stack, though the actual performance of those AI features still needs to be tested in practice. And that wraps this part of the briefing.

Mia: There's a new macOS app called Keytones, and it's built around a very specific frustration: realizing you've left Caps Lock on or missed a Shift key before you've already typed several sentences in a row. Its maker, Stefan Keller, says he built it after repeatedly catching himself typing all in capitals without noticing.

Milo: So instead of trying to imitate a mechanical keyboard with typewriter sounds, Keytones gives each key group its own distinct tone. Uppercase, lowercase, the space bar, and modifier keys each sound different, so you can actually hear the difference between a capital and a lowercase letter as you type.

Mia: And each of those groups has its own controls for pitch, length, damping, and volume. You can mix the built-in sounds or drag in your own audio files, which the app checks when you import them. There's also a visual option that pulses a glowing border along the bottom of your screen with every keystroke, and the color and size change depending on the key group. That mode can run on its own without any sound, which is handy in a quiet room or if your audio device has too much latency.

Milo: There are a few other practical touches as well. You can set up a per-app list of allowed or blocked apps and toggle it from the menu bar, triple-tap a configurable modifier key to mute instantly, and control everything with Siri or Shortcuts. Keytones even remembers separate volume levels for each output device, so your headphones don't get the volume you'd set for your MacBook speakers. And the maker says the sound engine stays clear even when you swap headphones mid-sentence.

Mia: He also stresses that it's fully private. Keytones requests Accessibility access just to detect key presses, and it says it never reads, logs, or stores anything you type. The app is at version 1.0, released in July 2026, and it's available on Subclassed.

Milo: Before we wrap up, let's do a quick sweep of everything that landed today. StepGrab is a menu-bar app that turns any Mac task into a step-by-step guide. BackEngine opened up private company knowledge to AI through its new MCP integration. And Capacity Desktop lets you describe an app in plain English and have it built locally, all for free.

Mia: We also covered Wispr Flow Notetaker, which promises meeting notes that get the details right, and the open-source Aegisora, built to control AI agent tool and API calls. Plus a deep dive on ngrok's AI Gateway, Cloudflare's new programmable wallet layer, and Dover's MCP connecting recruiters' tools. That's it for today—thanks for listening!