Changelog

Changelog

What we have shipped, newest first.

September 2026 OpenAPI spec + message search/filter

A machine-readable OpenAPI 3.1 contract (/docs/openapi.yaml) validated in CI, plus shared message filtering — has_otp, subject_contains and from — across the REST API and the dashboard.

September 2026 API-key cap

API-key minting is now bounded: a maximum of 20 active keys per account, with an hourly create rate limit, so leaked-key hygiene stays manageable.

September 2026 Public docs + quickstart

The public quickstart and this reference set, plus a copy-paste Playwright example (examples/playwright/otp-signup.spec.ts) that awaits an OTP over the wait endpoint.

September 2026 Onboarding

Post-signup activation: a first inbox and welcome message are provisioned automatically, with a one-click API key and ready-to-run code snippets on the dashboard.

September 2026 Wedge 4 — OTP-first landing

The landing page now leads with the OTP wedge: "Wait for the OTP. One API call.", with a live curl and Python sample for the wait endpoint.

September 2026 Wedge 3 — REST API v1

Bearer-authenticated REST API: inboxes, message listing and retrieval, cursor pagination, per-key rate limits, and the wait-for-OTP/magic-link long-poll primitive.

September 2026 Wedge 2 — signed webhooks

DB-backed webhooks with SSRF-pinned HTTPS delivery and per-webhook HMAC signatures.

September 2026 Wedge 1 — inbound email

The no-loss inbound path: Postfix accepts and durably stores mail, then a bounded parser extracts OTPs and magic links. Mail is deferred, never lost, when the app is down.