Skip to content
Version 2Active developmentInfrastructure completeDesktop application under constructionV5 closed beta cleared (Windows, trusted testers)
All posts
ReleaseSeptember 20, 20268 min read

V5: an in-game overlay, a Verse Catalog, and one honest action system — cleared for closed beta

Written by The LynxDock Team, Engineering, LynxDock

LynxDock is lightweight communication for communities that want control — and for Star Citizen organizations, control means the moment of the operation itself: the medic request, the rearm call, the 'arrived' press while your hands are on the flight controls. V5 is the line of work that takes the quick actions out of the chat window and puts them where the pilot is, without touching the game. This post is the closure record in plain language: what is in the build, how it was qualified, and the list of things we know are not perfect.

Start with the rule that shaped everything: the overlay is not allowed to touch the game. No process injection, no DirectX or DLL hooks, no reading of game memory, no synthetic input, nothing an anti-cheat could reasonably object to. The overlay is an ordinary transparent, always-on-top window that is click-through and non-focusable while passive, so Star Citizen keeps the keyboard and mouse. Activation uses Windows Raw Input in observation-only mode — LynxDock sees which control you pressed and never blocks or alters it on the way to the game, which is why the settings page tells you plainly to pick a key or spare mouse button the game does not use. Escape is reserved: it always means 'give input back', from every state, and it cannot be bound to anything else.

Two controls, two jobs. A Quick Action control fires your current primary action with no focus hand-off and no cursor. A Pointer / Menu control deliberately takes the mouse so you can click the deck; keys 1–8 press it in the order shown. They are separate on purpose — one physical control has one meaning, so its behaviour never depends on state the pilot cannot see while flying. Micro mode is one line; Compact shows status and the deck. Per-monitor and per-game profiles remember position, size, scale, opacity and mode, a Move overlay mode lets you drag the card exactly where you want it, and placement, moves and restarts were qualified at 100 % and 150 % display scaling.

Underneath the overlay is the part that matters more: one canonical action system. Every quick action — order receipts, participation, requests, mission progress, logistics adjustments, deliveries mapped onto the transfer lifecycle — is derived on the server from canonical state, your role, the current revision and the surface asking. Surfaces never decide what is legal. Every mutation carries an expected revision and an idempotency key, so a repeated press or a retry after a dropped connection is replayed rather than applied twice, and a stale press is refused with a readable reason (out of date, conflict, not allowed) instead of silently overwriting newer state. The idempotency records are durable and crash-consistent. The overlay, the main app and any paired device go through exactly the same path; nothing on the overlay can bypass a permission or a confirmation.

The overlay talks to the app over a local Control Surface Bridge — the one door future devices will use too. It binds to 127.0.0.1 only, every client authenticates, pairing uses a six-digit one-time code that expires in two minutes, credentials are stored as digests, scopes are least-privilege and enforced per action, per-device rate limits and an Origin allowlist apply, and revoking a device disconnects it immediately. A Connected devices page shows the bridge state and every paired device with its scopes, state and last-seen time. The typed SDK and its security model are documented so a third party can build a safe read-only surface.

The Verse Catalog is the reference half of the operations layer: a patch-aware catalog of ships, vehicles, locations, commodities, missions and related entities, deliberately separate from live operational truth so reference data can never overwrite what is actually happening in an operation. It has full-text search with facets, a dense table, per-field provenance, a compare view, patch-to-patch diffs and a coverage dashboard that shows counts rather than claiming 'all data'. Unknown values stay unknown — a missing SCU renders as unknown, never as zero, and cargo-grid fit is never inferred from headline SCU. Catalog pickers sit inside the surfaces that need them. One honest caveat: the Star Citizen Wiki provider ships disabled and is switched on by the server owner, who runs the import server-side; at qualification time no full provider run had been performed, and we do not describe coverage we have not measured. Since then a full run has been performed and recorded (below).

How it was qualified. The candidate is a single frozen executable — commit 5a53bff, build 0.1.0+5a53bff — built in a clean clone with the web assets embedded (no dev server) and clean-checkout verified with 989 Rust tests plus the desktop suite. It was then driven on the live rig against Star Citizen in borderless mode: the game kept keyboard and mouse while the overlay was passive, a deck press reached the server, a click on dead space passed through and restored the game to the foreground, a live request action from the overlay succeeded, second-monitor placement and restart held, and the focus counters matched an external sampler with the foreground-restoration failure counter at zero throughout. Along the way the campaign closed a run of findings the hard way — a fresh-process window that briefly came up without its passive style, a destroyed-prior-window recovery, a second-monitor placement bug — each with a root cause, a bounded fix and a re-qualification, not a hope. One thing did change after that clearance: an ordinary member could see only the provider id on catalog entries, with the Star Citizen Wiki attribution visible just to administrators. That was not acceptable to ship, so a second candidate — build 0.1.0+2ca6589, commit 2ca6589 — was built on 2026-09-21 from the same tree plus that one client-only change (attribution, source link and CC BY-SA 4.0 licence link on the catalog page, every entity card and every catalog picker), verified with a plain member account against an isolated server holding the full Wiki import, the client suite and the same clean-clone gate; the overlay and live-game qualification carries forward because none of that code differs.

What we are not claiming. Every requirement in the V5 pack was classified — 454 rows, zero unclassified — and only 76 are marked shipped: implemented, tested and measured live with no contradicting finding. Sixty-five more are foundation: built and tested, with their named live measurement still owed (most of them the catalog rows waiting on that full Wiki run). Tactical and Radar overlay modes, mobile, Stream Deck, GameGlass, Steam Deck and end-to-end encryption are later waves and are not in this cut. Exclusive fullscreen is not supported, because Windows draws nothing over it. And one residual stays open by name: when the window under the overlay vanishes during a hand-off, Windows can briefly re-activate the passive overlay; a watchdog yields within a fraction of a second and click-through is preserved, but whether a key pressed inside that moment reaches the game could not be measured despite repeated controlled attempts. The disposition records it as unmeasured — not as absent — and it is the first thing we are asking testers to watch for.

So the closed beta is exactly that: a frozen, hashed, unsigned portable build handed directly to a small number of trusted testers, with its known issues written down next to the download rather than discovered afterwards. Public downloads stay closed until a signed build and the wider beta. The whole platform remains what it set out to be — chat, voice, a tactical board and now the operations layer, in one deployable unit, on hardware your community owns.

What it looks like. The home page now carries a gallery of this exact build running a staged convoy-escort operation on an isolated demo server: a fictional organisation of 32 simulated members, seeded through the product's own RPCs, on the tactical board, in Operations, My Dock, Missions, Logistics, comms, the Verse Catalog and the overlay. The catalog in those captures was populated by a full Star Citizen Wiki provider run against that demo server — 132 requests, 17,029 entities for patch 4.10.0-LIVE, CC BY-SA 4.0 — which is why we can now show it. Measured on that run: 24,058 of 24,058 provider records fetched for the patch observed at the time, 688 skipped by the normaliser, 286 rejected with reasons, 0 conflicts — provider-relative completeness, never 'all Star Citizen data', and mission-universe coverage still unknown. The provider still ships disabled in the beta build itself; the server owner enables it. Every capture is the application's own window, and nothing in it is live game telemetry.

Related reading