diff --git a/devlog/_plan/260929_tokenlab_sponsor/000_roadmap.md b/devlog/_fin/260929_tokenlab_sponsor/000_roadmap.md
similarity index 100%
rename from devlog/_plan/260929_tokenlab_sponsor/000_roadmap.md
rename to devlog/_fin/260929_tokenlab_sponsor/000_roadmap.md
diff --git a/devlog/_plan/260929_tokenlab_sponsor/010_merge_6221.md b/devlog/_fin/260929_tokenlab_sponsor/010_merge_6221.md
similarity index 100%
rename from devlog/_plan/260929_tokenlab_sponsor/010_merge_6221.md
rename to devlog/_fin/260929_tokenlab_sponsor/010_merge_6221.md
diff --git a/devlog/_plan/260929_tokenlab_sponsor/020_sponsor_pr.md b/devlog/_fin/260929_tokenlab_sponsor/020_sponsor_pr.md
similarity index 100%
rename from devlog/_plan/260929_tokenlab_sponsor/020_sponsor_pr.md
rename to devlog/_fin/260929_tokenlab_sponsor/020_sponsor_pr.md
diff --git a/devlog/_fin/260930_release_2_72_0/000_plan.md b/devlog/_fin/260930_release_2_72_0/000_plan.md
new file mode 100644
index 0000000000..149e4c57f1
--- /dev/null
+++ b/devlog/_fin/260930_release_2_72_0/000_plan.md
@@ -0,0 +1,17 @@
+# 2.72.0 — TokenLab release
+
+Owner request (2026-09-30): merge the TokenLab sponsor PR, verify for regressions, release, check
+TokenLab's payment in the WORKS inbox through Aside, and have Aside email Vincent.
+
+Previous unit: `devlog/_fin/260929_tokenlab_sponsor/` merged #6221 (preset, `f6cddd7d69`) and opened
+#6240 (sponsor placement + CLI pinning, head `21cddd35c9`, 32/32 PR checks green). Release shape is
+2.71.0 (`devlog/_fin/260929_release_2_71_0/040_release.md`).
+
+| Doc | Work phase | Outcome |
+|-----|-----------|---------|
+| [010](./010_merge_6240.md) | wp2 | #6240 merged on full-lane CI (incl. windows 1–9) at its exact head |
+| [020](./020_release.md) | wp3 | npm latest 2.72.0, preview 2.72.0-preview.20260930, GitHub releases, gitHead |
+| [030](./030_payment_and_email.md) | wp4 | Payment/DocuSign status from WORKS; Vincent emailed by Aside exec; outcome recorded |
+
+Release content since v2.71.0: #6221 (TokenLab preset), #6240 (sponsor placement, CLI sponsor
+pinning), devlog-only commits.
diff --git a/devlog/_fin/260930_release_2_72_0/010_merge_6240.md b/devlog/_fin/260930_release_2_72_0/010_merge_6240.md
new file mode 100644
index 0000000000..ec33545400
--- /dev/null
+++ b/devlog/_fin/260930_release_2_72_0/010_merge_6240.md
@@ -0,0 +1,14 @@
+# 010 — Regression gate and merge #6240 (wp2)
+
+1. Dispatch full-lane Cross-platform CI on the PR head:
+ `gh workflow run ci.yml -R lidge-jun/opencodex --ref codex/tokenlab-sponsor -f lane=all`
+ (the pull_request event skips windows 1–9 and macOS control; 2.71.0 used the same dispatch).
+ Required: every job success, windows 1/9–9/9 present, on the final head `2b9295fea6` (the run on `21cddd35c9` was cancelled when the final sponsor copy landed; see 030).
+2. Local regression scope: the lanes' focused tests plus `test:changed`; the full local suite is
+ not runnable from a worktree under `~/.codex` (test home guard), so CI is the full-suite proof.
+3. `scripts/ci/assert-mergeable-review.sh --maintainer-integration 6240 lidge-jun/opencodex`, a PR
+ comment recording owner authorization, exact head and run IDs: PR-event Cross-platform CI,
+ Service lifecycle (triggered by `desktop/**` and `package.json`), and the `lane=all` dispatch.
+4. `gh pr merge 6240 --admin --squash --match-head-commit
`. C is that exact squash commit,
+ fixed before anything else lands on `dev`; assert `git show C:package.json` reads 2.72.0.
+ The `260929_tokenlab_sponsor` plan docs on the branch land inside the squash.
diff --git a/devlog/_fin/260930_release_2_72_0/011_wp2_execution.md b/devlog/_fin/260930_release_2_72_0/011_wp2_execution.md
new file mode 100644
index 0000000000..6105dfe65d
--- /dev/null
+++ b/devlog/_fin/260930_release_2_72_0/011_wp2_execution.md
@@ -0,0 +1,14 @@
+# 011 wp2 execution: regression gate and merge
+
+| Step | Evidence |
+|---|---|
+| Final copy | #6240 took TokenLab's final blurbs and referral link at `2b9295fea6` (030 findings); the `lane=all` run on `21cddd35c9` was cancelled |
+| PR-event CI on `2b9295fea6` | Cross-platform CI 36591071773, Service lifecycle 36591071699, React Doctor 36591071756: success; 32 pass, 5 path-skipped |
+| Full-lane gate | Cross-platform CI `lane=all` 36591083341: attempt 1 failed windows 7/9 (`cli-connect-readiness` installed-root probe, exit null at 18 s) and windows 8/9 (`main quota policy at native admission`, 32 s cases); neither loads a changed module (`init`, `provider-runtime` are lazy CLI imports). One rerun (attempt 2): both shards and `ci` success |
+| Review | Codex P2 and CodeRabbit sponsor-first-run fixed; CodeRabbit wording suggestion declined (verbatim sponsor copy, adapter chip visible, Responses-first pending) |
+| Policy | `assert-mergeable-review.sh --maintainer-integration 6240`: OK; decision comment 5894282491 |
+| Merge | `gh pr merge 6240 --admin --squash --match-head-commit 2b9295fea6` → dev `1cd9d25517` = C; `package.json` 2.72.0, version-sources check 2.72.0 passes |
+| Pre-move | #6243 (four version sources 2.72.0 → 2.73.0), `maintainer-sponsored` after review, merged → dev `73289d46ae` (2.73.0) |
+
+Local regression scope: focused sponsor/registry/README/GUI suites and `test:changed`; a full local run
+is not possible from a worktree under `~/.codex` (test home guard), so CI above is the full-suite proof.
diff --git a/devlog/_fin/260930_release_2_72_0/020_release.md b/devlog/_fin/260930_release_2_72_0/020_release.md
new file mode 100644
index 0000000000..98da49e340
--- /dev/null
+++ b/devlog/_fin/260930_release_2_72_0/020_release.md
@@ -0,0 +1,25 @@
+# 020 — Release 2.72.0 (wp3)
+
+Same procedure as `devlog/_fin/260929_release_2_71_0/041_wp4_execution.md`, with C = the #6240
+squash commit from 010 (never a later `dev` tip, which would carry 2.73.0).
+
+1. Pre-move: `gh workflow run dev-version-bump.yml -R lidge-jun/opencodex --ref main
+ -f intended-version=2.72.0 -f mode=pre-move` → PR moving exactly the four version sources to
+ 2.73.0; merge `--admin --squash --match-head-commit` after its CI.
+2. Preview: branch `codex/promote-preview-2.72.0` from C, `git merge -s ours origin/preview`,
+ `bun scripts/release-version-sources.ts sync 2.72.0-preview.20260930`, commit; diff vs C must be
+ exactly the four version sources, and `bun scripts/release-version-sources.ts` check mode passes.
+ PR to preview with the #6240 pr-assets screenshots, `gh pr merge --admin --merge --match-head-commit`.
+3. Main: branch `codex/promote-main-2.72.0` from C, `git merge -s ours origin/main`, tree equals C.
+ (`git diff --quiet C HEAD`). PR to main with the screenshots, merged the same way. enforce-target
+ flags promotion PRs as wrong base by design; it is not required on preview/main.
+4. Gate each promotion SHA: push-event Cross-platform CI and Service lifecycle `success`.
+5. Dispatch preview then stable:
+ `gh workflow run release.yml --ref preview -f version=2.72.0-preview.20260930 -f tag=preview
+ -f dry-run=false -f expected-sha=`, then `--ref main -f version=2.72.0 -f tag=latest
+ -f dry-run=false -f expected-sha=`. After an npm-acknowledged failure, resume with
+ `-f resume-after-npm-publish=true`; never republish.
+6. Verify dist-tags, `npm view @bitkyc08/opencodex@2.72.0 gitHead` = main sha, `gh release view v2.72.0`
+ (not prerelease, 25 assets as v2.71.0), preview release prerelease, latest.json 2.72.0 signed.
+
+The installed proxy/app on this machine is not updated (same as 2.70.0/2.71.0).
diff --git a/devlog/_fin/260930_release_2_72_0/021_wp3_execution.md b/devlog/_fin/260930_release_2_72_0/021_wp3_execution.md
new file mode 100644
index 0000000000..a268eb8e9e
--- /dev/null
+++ b/devlog/_fin/260930_release_2_72_0/021_wp3_execution.md
@@ -0,0 +1,29 @@
+# 021 wp3 execution: promotion and release
+
+| Step | Evidence |
+|---|---|
+| Candidate | C = dev `1cd9d25517` (#6240 squash), version sources 2.72.0 |
+| Pre-move | #6243 → dev `73289d46ae` (2.73.0), `maintainer-sponsored` after review |
+| Preview promotion | `codex/promote-preview-2.72.0`: `-s ours` merge of origin/preview + sync to 2.72.0-preview.20260930 (`14ccfe1a1a`); diff vs C = four version sources; PR #6245 merged (merge commit) → preview `4f9e3f0afb` |
+| Main promotion | `codex/promote-main-2.72.0`: `-s ours` merge of origin/main (`77cb00512f`), tree equals C; PR #6246 merged → main `5ab6d52b2a` |
+| Push-event gates | preview: Cross-platform CI 36597831993, Service lifecycle 36597831950; main: Cross-platform CI 36597841262, Service lifecycle 36597841450 |
+
+Dispatches (after both gates of a SHA succeed), preview first:
+
+```sh
+gh workflow run release.yml -R lidge-jun/opencodex --ref preview -f version=2.72.0-preview.20260930 -f tag=preview -f dry-run=false -f expected-sha=4f9e3f0afbbcf54a2b0421db8e962ec3d5682d5e
+gh workflow run release.yml -R lidge-jun/opencodex --ref main -f version=2.72.0 -f tag=latest -f dry-run=false -f expected-sha=5ab6d52b2a4da722d398e4ab50a6c621ac3ce087
+```
+
+## Results
+
+| Check | Evidence |
+|---|---|
+| Preview gates | Cross-platform CI 36597831993 success (push), Service lifecycle 36597831950 success |
+| Main gates | Service lifecycle 36597841450 success; Cross-platform CI 36597841262 attempt 1 failed only `test 2/4` (batch 10/48 hit the 120 s process bound; the attribution sweep reported every file passing alone, "the timeout lives in multi-file process state"); one rerun, attempt 2 success |
+| Preview release | release.yml 36602348988 success; npm `preview` = 2.72.0-preview.20260930, gitHead `4f9e3f0afb`, bins `ocx`/`opencodex` intact; GitHub release prerelease, 25 assets |
+| Stable release | release.yml 36603799783 success; npm `latest` = 2.72.0 (published 17:45 UTC, visible ~10 min later, as with 2.71.0), gitHead `5ab6d52b2a`, bins intact; GitHub release v2.72.0 not prerelease, 25 assets; latest.json 2.72.0 signed for darwin-aarch64, darwin-x86_64, linux-x86_64, linux-x86_64-deb, windows-x86_64 |
+
+npm printed `"bin[...]" script name bin/ocx.mjs was invalid and removed` during both publishes; 2.70.0 and
+2.71.0 printed the same, and the registry metadata keeps both bins (the `./` prefix is normalized).
+The installed proxy and desktop app on this machine were not updated.
diff --git a/devlog/_fin/260930_release_2_72_0/030_payment_and_email.md b/devlog/_fin/260930_release_2_72_0/030_payment_and_email.md
new file mode 100644
index 0000000000..c76199ee79
--- /dev/null
+++ b/devlog/_fin/260930_release_2_72_0/030_payment_and_email.md
@@ -0,0 +1,29 @@
+# 030 — Payment check and sponsor email (wp4)
+
+1. Aside exec, read-only, WORKS inbox: TokenLab messages since 2026-09-29 18:00 KST (payment
+ confirmation, transaction hash, amount), DocuSign completion status. Where a transaction hash is
+ given, confirm it read-only on the public chain explorer against the recipient addresses in the
+ agreement (1,200 USDT, TRC-20 or ERC-20).
+2. Only after npm `latest` reads 2.72.0 (the term starts at that release), Aside exec replies in the TokenLab thread from the maintainer mailbox, politely: payment received (only if confirmed), #6221/#6240 merged, released in
+ opencodex 2.72.0 (npm `@bitkyc08/opencodex`, release link), the 3-month term starts on that
+ release date per the agreement, README/picker placement live, the Responses-first proposal will be
+ evaluated separately. No attachments, no other recipients.
+3. Record 090_outcome.md; move this unit and `260929_tokenlab_sponsor` to `devlog/_fin/` through a
+ docs PR to dev.
+
+Wallet addresses and transaction hashes stay out of the repository; the outcome records only that
+payment was confirmed and when.
+
+## Findings (2026-09-30, before release)
+
+- WORKS inbox (Aside exec, read-only): Vincent wrote on 2026-09-29 23:08 KST that he signed the
+ agreement and paid 1,200 USDT on TRC-20, with a transaction hash, and sent final sponsor copy: a
+ longer English blurb, a Chinese blurb, and `https://tokenlab.sh/r/OPENCODEX` as the README and
+ picker link. A 23:13 message offers a USD 20 API-credit code for integration testing.
+- On-chain (Tronscan, read-only): the hash is a confirmed, successful transfer on the official
+ USDT contract of exactly 1,200.000000 USDT to the agreement's TRC-20 address, at 2026-09-29
+ 13:53 UTC; not flagged as risky.
+- DocuSign: the only DocuSign mail in WORKS is the 21:08 sender-verification notice. No completion notice reached the maintainer mailbox; status notices go to the envelope sender's address, which this
+ check did not cover. Signature completion stays unverified here.
+- Consequence for 010: #6240 takes the final copy and referral link (`2b9295fea6`) before the
+ regression gate; the earlier `lane=all` run on `21cddd35c9` was cancelled.
diff --git a/devlog/_fin/260930_release_2_72_0/090_outcome.md b/devlog/_fin/260930_release_2_72_0/090_outcome.md
new file mode 100644
index 0000000000..e8aedc57c7
--- /dev/null
+++ b/devlog/_fin/260930_release_2_72_0/090_outcome.md
@@ -0,0 +1,23 @@
+# 090 Outcome — 2.72.0 TokenLab release
+
+Closed 2026-09-30 (KST).
+
+| Criterion | Result |
+|---|---|
+| #6240 merged after full-lane CI on its exact head | Merged `1cd9d25517` from head `2b9295fea6`; lane=all 36591083341 success on attempt 2 (windows 7/9 and 8/9 reran once; neither loads a changed module) |
+| npm and GitHub releases | `latest` 2.72.0 (gitHead `5ab6d52b2a`, main via #6246), `preview` 2.72.0-preview.20260930 (gitHead `4f9e3f0afb`, preview via #6245); release.yml 36603799783 / 36602348988; v2.72.0 has 25 assets and a signed latest.json |
+| Payment and sponsor email | TokenLab's 1,200 USDT payment confirmed on-chain (2026-09-29 13:53 UTC). Reply sent from the maintainer mailbox through Aside exec at 2026-09-30 02:59 KST, confirming receipt, the 2.72.0 release, the placements and the term start |
+
+Release content since 2.71.0: #6221 (TokenLab preset, by @hedging8563), #6240 (sponsor placement,
+CLI sponsor pinning, final sponsor copy and referral link). #6243 moved `dev` to 2.73.0 after the
+candidate was pinned and is not part of 2.72.0.
+
+Per the agreement, the three-month sponsorship term starts with the 2.72.0 npm release
+(2026-09-29 17:45 UTC, 2026-09-30 KST).
+
+Open items, outside this unit:
+- DocuSign completion is not confirmed from the maintainer mailbox; TokenLab reports signing. Envelope
+ status goes to the sender account.
+- TokenLab's Responses-first preset proposal (`X-TokenLab-Delivery-Policy`) needs its own PR and evidence.
+- TokenLab offered a USD 20 API credit for integration testing; redeeming it is the maintainer's choice.
+- The installed proxy and desktop app on this machine were not updated.