Free
$0forever
For one small product with a couple of services.
- Up to 2 connected repos



api · web · mobile · infra → one release
Your company ships one release out of four repositories. Muster reads the PRs merged since the last one, writes the changelog for the people who use your product — not for the people who wrote it — and waits for a human to approve. It never publishes on its own.
Each item carries its PR numbers and a literal excerpt copied out of the PR. So “is this hallucinated?” stops being a judgment call and becomes a substring check: the number is in the input set, the quote matches character for character.
Reads from GitHub · publishes to your site, Slack and email
Offline receipts sync when signal returns
mobile#1204api#4412infra#302
“Queues unsent receipts in a local outbox and flushes it on the first successful heartbeat.”
Invite teammates by email domain
web#2871api#4398
“Anyone with a verified company domain can be auto-added to the workspace on first login.”
THE REVIEW SCREEN — four repos merged into one draft, still unpublished


THE SCREEN THAT MATTERS
Every PR in the input set has to land somewhere: an item, or the ignore list with a stated reason. That's what catches the failure nobody catches — omission.
release 2.14 · 4 repos · since 2.13 (11 days)
“Queues unsent receipts in a local outbox and flushes it on the first successful heartbeat.”
substring match · mobile#1204
“Anyone with a verified company domain can be auto-added to the workspace on first login.”
substring match · web#2871
“Removes the hard LIMIT 1000 on the CSV export path and streams the cursor instead.”
substring match · api#4405
“Moves the summary aggregation behind a cached endpoint; median first paint drops from 2.9s to 0.9s.”
substring match · infra#298
38 in = 31 items + 7 ignored · no PR unaccounted for
If your release is four merges in four places, a per-repo feed is four changelogs your users have to assemble themselves.
| Axis | One-repo changelog tools | Muster |
|---|---|---|
| Scope | One repository in, one changelog out. | Every repo that ships in the same release, merged into one entry. |
| Input accounting | Picks whatever commits it finds interesting. | Each input PR appears as an item or in the ignore list with a reason. Coverage is a number. |
| Evidence | Prose you have to take on faith. | PR numbers from the input set plus a literal excerpt, checked by exact substring match. |
| Failure it catches | Wrong claims, if you happen to notice. | Omission — the one nobody catches, because nothing is counting. |
| Publishing | Auto-posts on merge or tag. | Drafts and waits. A human approves, always. |
| Written for | Developers reading commit subjects. | The person using your product, in their words. |
Start free with two repos. Approval is always manual, on every plan.
$0forever
For one small product with a couple of services.
$29per connected repo / month
8 connected repos, the cap on this plan, comes to $232.
For a company shipping api, web, mobile and infra as one release.
$19per connected repo / month
Your bill is this price times the number of repos you connect.
For several products shipping out of the same account.
The plan sets how many repos you can connect. It does not gate what Muster does.
Manual approval
A named person approves every release. No setting turns it off.
Coverage enforcement
Publishing is blocked while any input PR has no destination.
Verified excerpts
Every quote is checked by exact substring against the PR it came from.
Immutable audit log
Every approval and later edit is kept, and exports as CSV.
Approval roles
Owner, approver and reviewer. Only the first two publish.
Tenant isolation
Postgres row-level security on every table, not a filter in app code.
Hosted changelog
A public page at your Muster address, with RSS and JSON feeds.
Release notices
Slack and email, with one row per delivery attempt.
Generation cost
What the model charged, shown apart from the plan price.
Paid through Stripe checkout · idempotent webhooks · cancel or delete your account and tenant data from settings.