2026-08-13 — Phase 84 Authenticator native build readiness and device qualification (no public API change)
- Hardened the standalone mobile Authenticator with time-limited transfer v2, bounded backup/import parsing, explicit HOTP advancement, deletion confirmation, secret-bearing deep-link removal, and an iOS privacy curtain.
- Added Android/iOS native CI and release-bound physical-device qualification tooling.
- No Authenticator seed/sync endpoint was introduced; the public contract remains
2026-08-08.3with 121 operations.
2026-08-13 — Phase 83 VettiGuard Authenticator secure offline core (no public API change)
- Added the separately versioned VettiGuard Authenticator mobile source product for generic standards-compatible TOTP/HOTP accounts.
- Added offline Android/iOS vaults, QR/manual enrolment, device-owner locking, encrypted
.vgauthbackup/import, and bounded attended transfer. - No Authenticator seed, OTP generation, sync, push, or recovery endpoint was added to the VettiGuard platform in this offline phase.
- No public
/v1route, request field, or response field changed; the contract remains2026-08-08.3with 121 operations.
2026-08-09 — Phase 79 automated recovery drills and off-site replication (no contract change)
- Added system-only encrypted-backup replication and fail-closed isolated recovery automation.
- Verified replica and measured restore results feed the existing Phase 78 recovery-evidence model.
- No public
/v1route, request field, or response field changed; the contract remains2026-08-08.3with 121 operations.
2026-08-09 — Phase 78 disaster recovery and recovery objectives (no contract change)
- Added system-only RPO/RTO governance, time-bounded isolated-restore/off-site/redeploy/failover/communications evidence, recovery posture snapshots, and a blocking Launch Readiness recovery gate.
- Backup archive-integrity verification remains separate from real isolated-restore evidence.
- No public
/v1route, request field, or response field changed; the contract remains2026-08-08.3with 121 operations.
2026-08-09 — Phase 77.2 public Rate Limiting documentation (no contract change)
- Added a first-class public
/developers/rate-limitingimplementation guide covering token buckets, fixed quotas, hierarchical scopes, adaptive cost, Observe/Throttle/Enforce semantics, server/mobile requests, SDK examples, retries, privacy, and production rollout. - Linked the guide from the Developer navigation, integration hub, footer, server SDK quickstarts, API guide, and mobile guide.
- Corrected traffic-control quickstart snippets to match the current PHP, Node.js, Python, and Go SDK interfaces.
- No public
/v1route, request field, or response field changed; the contract remains2026-08-08.3with 121 operations.
2026-08-09 — Phase 77 workspace envelope encryption and customer-managed keys (no contract change)
Phase 77 adds workspace-aware AES-256-GCM envelope encryption, versioned wrapping-key governance, customer-managed KMS-broker enforcement, and controlled ciphertext rewrap for a bounded set of application secrets. It does not add or modify a public /v1 operation. Contract remains 2026-08-08.3 with 121 operations.
2026-08-09 — Phase 76 data sovereignty and encryption-key governance (no contract change)
Phase 76 adds workspace/system control-plane governance for regional-data posture, key-provider evidence, cross-region approvals, and posture snapshots. It does not add or modify a public /v1 operation. Contract remains 2026-08-08.3 with 121 operations.
2026-08-09 — Phase 75 compliance assurance and public trust centre (no contract change)
- Added system-admin compliance assurance governance, expiring evidence metadata, policy versions, subprocessor reviews, integrity-stamped assurance snapshots, and an opt-in public
/trustpage. - Public assurance exposes only explicitly approved summaries and does not imply external certification from internal framework mappings.
- No public
/v1API operation changed; the contract remains2026-08-08.3with 121 operations.
2026-08-09 — Phase 74 post-launch reliability, SLOs and error budgets (no contract change)
- Added system-only reliability SLO/error-budget governance and post-Go-Live release-health evidence.
- Phase 73 production preflight can now block on breached release-gating SLOs.
- No
/v1or mobile API operation changed. Contract remains2026-08-08.3with 121 operations.
VettiGuard API Changelog
2026-08-09 — Phase 73 production deployment and Go-Live execution (no contract change)
- Added system-admin controlled production deployment execution, exact-release Phase 72 GO binding, rollback approval, production dependency gates, smoke validation, and final Go-Live recording.
- No public
v1route, request field, response field, or SDK contract changed. Contract remains2026-08-08.3with 121 operations.
2026-08-08 — Phase 72 launch validation and resilience certification (no contract change)
- Added system-admin launch-validation, resilience-evidence, bounded load-harness, and formal Go/No-Go release-certification capabilities.
- No public
v1route, request field, response field, or SDK contract changed. Contract remains2026-08-08.3with 121 operations.
2026-08-08 — Production Security & Performance Hardening (Phase 71; no public API change)
- Added bounded request-envelope validation, trusted-host support, session write-throttling, database connection timeouts, and targeted high-volume query indexes.
- Added web-server compression/static-cache guidance and expanded production performance/security readiness checks.
- No public
v1route, request field, or response field changed. - The public API contract remains
2026-08-08.3with 121 operations.
2026-08-08 — Console UI, Developer Portal & SDK Expansion (Phase 70; no public API change)
- Standardised shared console forms, toggles, traffic-service layouts, and text-only architecture flows.
- Added validated Python and Go SDK source distributions and expanded developer-portal guidance for Rate Limiting, Concurrency Control, and Dependency Resilience.
- No public
v1route, request field, or response field changed. - The public API contract remains
2026-08-08.3with 121 operations.
2026-08-08 — Customer Onboarding & Integration Readiness (Phase 69; no public API change)
- Added workspace-scoped Browser, Server/API, Native mobile, and Hybrid integration readiness profiles.
- Added automatic target-aware launch checks, readiness snapshots, and Observe-first production activation.
- No public
v1route, request field, response field, or SDK contract changed. - The public API contract remains
2026-08-08.3with 121 operations.
2026-08-08 — Phase 68.1 traffic-control console/readiness hotfix
- Repaired Rate Limiting, Concurrency Control, and Dependency Resilience summary dashboards and Redis-readiness presentation.
- Added safe Redis dependency-state classification and completed the environment template for Dependency Resilience.
- No public API change; contract remains
2026-08-08.3with 121 operations.
2026-08-08 — SCIM 2.0 & Enterprise SSO Hardening (Phase 68; no public API change)
Hardened the dedicated /scim/v2 and enterprise-authentication surfaces with scoped/expiring SCIM tokens, per-token SCIM self-protection, verified-domain identity-provider routing, generic discovery failures, and governed MFA-protected tenant recovery. The public /v1 API contract remains 2026-08-08.3 with 121 operations.
2026-08-08 — Enterprise Organisations & Policy Inheritance (Phase 67; no public API change)
- Added confirmed multi-workspace enterprise organisation hierarchy with delegated organisation roles.
- Added candidate-to-active central security baselines and per-workspace Enforced, Advisory, or Disabled inheritance.
- Added time-bounded policy-domain exceptions and privacy-safe governance events.
- Inherited controls are applied at policy-read time and can only make a workspace posture stricter; tenant data, credentials, billing, logs, and identity evidence remain workspace isolated.
- No customer-facing API operation was added or removed.
- The public API contract remains
2026-08-08.3with 121 operations.
2026-08-08 — Production Operations Centre (Phase 66; no public API change)
- Added a system-admin-only Production Operations Centre for platform health, provider/Redis/worker visibility, aggregate customer-impact correlation, and governed operational incidents.
- No customer-facing API operation was added or removed.
- The public API contract remains
2026-08-08.3with 121 operations.
2026-08-08 — Dependency Resilience & Circuit Breakers (contract 2026-08-08.3)
- Added
POST /v1/dependency-resilience/admitand/feedbackfor protected server integrations. - Added corresponding
/v1/mobile/dependency-resilience/*operations for registered native applications. - Added rolling failure-rate circuit breakers with closed, open, and half-open states.
- Added bounded recovery probes, retry budgets, dependency bulkheads, Observe simulation, and Enforce load shedding.
- Admission tokens are signed, expiring, context-bound, and persisted only as keyed hashes.
- Redis is the preferred distributed state backend with transactional MariaDB fallback and explicit fail-open/fail-closed options.
- The generated OpenAPI and Postman artifacts now contain 121 public operations.
2026-08-08 — Concurrency & Workload Admission Control (contract 2026-08-08.2)
- Added
POST /v1/concurrency/acquire,/renew, and/releasefor protected server integrations. - Added corresponding
/v1/mobile/concurrency/*operations for registered native applications. - Admission uses expiring signed leases and atomically satisfies all matching hierarchical capacity constraints.
- Added Observe, Wait, and Enforce modes, idempotent acquire retries, bounded retry guidance, renewal, explicit release, and TTL crash recovery.
- Redis is the preferred distributed state backend with transactional database fallback and configurable fail-open/fail-closed behaviour.
- The generated OpenAPI and Postman artifacts now contain 117 public operations.
2026-08-08 — Rate Limiting as a Service (contract 2026-08-08.1)
- Added
POST /v1/rate-limit/checkfor protected sites and server integrations. - Added
POST /v1/mobile/rate-limit/checkfor registered native applications. - Requests atomically check and consume all matching token-bucket and fixed-window quota policies.
- Added weighted token cost, optional adaptive cost from a fresh same-application API Protection
assessment_id, and hierarchical workspace/application/subject/device/route/custom scopes. - Added Observe, Throttle, and Enforce outcomes with policy inheritance from the workspace default.
- The generated OpenAPI and Postman artifacts now contain 111 public operations.
2026-08-07 — Search privacy, navigation, and contact hardening (no contract change)
- Excluded authentication and control-plane surfaces from search indexing and crawler discovery.
- Removed operator shell-command instructions from public and tenant-facing runtime pages.
- Added the system-admin branding/localisation route and grouped public Developer navigation.
- Repaired the historical
/demo/contact-formroute and tightened the VettiGuard-owned sample-origin exception. - No public
v1route, request field, response field, or SDK contract changed.
2026-08-07 — UI contrast and documentation refresh (no contract change)
- Standardised light and dark presentation across console, public, documentation, and user-guide surfaces.
- Refreshed browser documentation and the role-aware user guide.
- No public
v1route, request field, response field, or SDK contract changed.
2026-08-07 — Platform workspace protected sites (no contract change)
- Added super-admin protected-site management under the private
/system/protected-sitesconsole. - Added an explicit billing-exempt platform workspace.
- No public
v1route, request field, response field, or SDK contract changed.
2026-08-06 — Unified trust orchestration (contract 2026-08-06.8)
- Added server and mobile trust-orchestration decision operations.
- Added signed, context-bound decision-receipt verification and feedback operations.
- Added candidate-policy simulation and governed promotion in the private console.
- The generated OpenAPI and Postman artifacts contain 109 public operations.
2026-08-06 — Detection outcome feedback (contract 2026-08-06.1)
- Added
POST /v1/detection/feedbackfor site-bound server outcome annotations. - Added
POST /v1/mobile/detection/feedbackfor mobile-app-bound outcome annotations. - Successful verification responses may include the additive
assessment_idfield. - Added privacy-safe labels for legitimate activity, abuse, approved automation, false positives, and false negatives.
- Exact API retries within five minutes are de-duplicated.
The feedback endpoints accept bounded reason codes only. Clients must not submit raw device identifiers, passwords, tokens, identity evidence, or other sensitive content.
2026-08-05 — Developer sandbox (contract 2026-08-05.3)
- Added
GET /v1/sandbox/scenarios. - Added
POST /v1/sandbox/issue. - Added
POST /v1/sandbox/siteverify. - Sandbox tokens and responses are explicitly non-production and isolated from live verification state.
2026-08-05 — Branding presentation fields (contract 2026-08-05.2)
- Added an optional
brandingobject to browser challenge and adaptive step-up responses. - Added the public normalized logo resource
/v1/branding/{profile_id}/logo. - Added workspace and protected-site presentation settings for colours, localized copy, support/privacy/terms links, logos, and attribution.
- Browser SDK package metadata advanced to
0.26.0.
These are additive response fields. Verification clients must continue to ignore unknown fields and validate response tokens through /siteverify. Branding fields are presentation data, not verification evidence.
This changelog covers the public v1 API contract. Additions are non-breaking unless explicitly marked otherwise.
2026-08-05 — Contract and SDK distribution
- Added an OpenAPI 3.1 JSON contract at
/v1/openapi.json. - Added a generated Postman collection at
/v1/postman-collection.json. - Added a machine-readable changelog at
/v1/changelog.json. - Added package-ready Composer, npm, Swift Package Manager, and Android Maven metadata.
- Centralised known API route and method declarations so JSON
405handling and published contracts use one catalogue. - Added API and contract revision response headers.
No existing request or response field was removed or renamed.
2026-08-02 — Canonical API subdomain
- New integrations use
https://api.vettiguard.com/v1. https://vettiguard.com/api/v1remains operational for existing integrations.- Legacy responses carry migration headers that identify the canonical URL.
- No sunset date is currently assigned to the legacy base URL.
Compatibility policy
- New optional response fields may be added without a major API version change.
- Clients must ignore unknown response fields.
- Existing fields are not repurposed with a different meaning within
v1. - Breaking changes require a new versioned base path and a documented migration period.
- Deprecation notices are published in the changelog and response headers before removal.
2026-08-09 — Phase 80 UI/accessibility and release qualification (no contract change)
- Added internal cross-device/accessibility regression auditing and exact-package release qualification.
- Hardened shared responsive console, table, form, dialog, dropdown and keyboard-navigation behaviour.
- No public
v1route, request field, response field, or SDK contract changed; the public API remains at 121 operations.
2026-08-10 — Phase 81 final RC freeze and deployment package (no contract change)
- Added internal release-lock, migration-catalog, deployment-packet, and rollback-packet tooling for system operators.
- Added a blocking exact-RC identity gate to production release execution.
- No public
v1route, request field, response field, or SDK contract changed; the public API remains at 121 operations.
2026-08-10 — Phase 82 exact-release production evidence binder (no contract change)
Phase 82 changes only the system-admin release/launch control plane. New validation evidence is bound to the exact package version and manifest checksum, and System > Releases & upgrades can read/download a private production-evidence binder. No public /api/v1 route, request field, response field, SDK contract, or OpenAPI operation is added or changed. The public API remains at 121 operations with contract version 2026-08-08.3.
2026-08-11 — Phase 82.1
- Browser widget hotfix: routine challenge/token expiry now silently renews challenge state instead of rendering an expiry error card.
- Pending protected-form submissions are preserved and automatically resumed after fresh verification.
- Browser lifecycle state/events now distinguish ready, challenging, verified, stale, refreshing, and failed conditions.
- Built-in CAPTCHA chrome is merchant-neutral and shows only “Protected by VettiGuard”; effective branding responses neutralise account display name/logo for compatibility with older widget builds.
- No new public HTTP operation; contract remains
2026-08-08.3with 121 operations.
2026-08-11 — Phase 82.2
- Browser-only hotfix; public HTTP contract remains
2026-08-08.3with 121 operations. - Idle challenge/token expiry no longer creates continuous replacement-challenge traffic.
VettiGuard.getState(container)can reportchallenge_stale; fresh challenge state is obtained at interaction/protected-action time.- Successful widget chrome is reduced to a compact checked Verified state with no visitor-facing token implementation details.
- Phase 82.1 neutral identity remains unchanged: Protected by VettiGuard only.