Docs

Developer changelog

Developer Platform contract, security, documentation, and compatibility changes.

The release entries below are generated from repository-backed release changes and reviewed with the API, SDK, and event contracts. They are Private Preview release notes, not an assertion of public package publication. For the current package manifest versions, see SDKs.

Release-note contract

Every entry that changes a public integration surface records the affected REST path major, SDK package and version, event schema impact, migration requirement, and compatibility window. The documentation generator reads package manifest metadata and npm run docs:verify fails when that metadata is stale. A release entry never replaces the governed OpenAPI, capability, or ABI checks.

27 JUL 2026

  • Made Developer Platform documentation publicly readable while retaining controlled Developer Preview access for credentials, sandbox admission, production scopes, and the Developer Console.
  • Added public reference pages for availability, networks and deployment provenance, errors and rate limits, and safe testing.
  • Added shared webhook network-address validation that rejects private IPv4-in-IPv6 mapped targets.
  • Added bounded public GraphQL body, field, depth, alias, and fragment-cycle enforcement.
  • Updated Python workflow execution to re-fetch and verify canonical prepared intents before a signer is invoked.
  • Disabled Java, Kotlin, and Swift raw-intent signer helpers until native canonical workflow executors are available.
  • Added browser-safe authenticated-read inspection, ephemeral redacted request history, generated snippets, local event envelope inspection, and a fixed non-production HMAC verification vector.
  • Corrected hosted sandbox documentation: the current standard fixture-set selector is persisted, but named market, vault, position, and balance fixtures are not yet part of the public API contract.

24 JUL 2026

  • Added the machine-readable capability registry and public-launch coverage gate.
  • Added the OpenAPI 3.1 v1 contract.
  • Added hashed application keys, origin-bound publishable keys, wallet sessions, and scoped workflow authentication.
  • Added canonical resource adapters and typed non-custodial Agent Credit workflows.
  • Added the transactional event outbox, signed webhook contract, replay history, and stream cursors.
  • Added TypeScript, React, Python, JVM, Swift, and active-contract package sources.
  • Completed active-V2 ABI provenance across the governed contract inventory.
  • Kept Start Building in controlled preview while the governed internal penetration assessment, public-GA certification, and release-owner approval remain open.

On this page