Skip to main content
Connect your client

Changelog

Releases, incidents, security advisories, and compliance notices for the gotcontext.ai platform, covering the public API, Web Dashboard, MCP Gateway, and SDKs. Every entry carries severity, affected components, and a clear customer-action flag.

Filters

Surface:
Type:

Latest releases

1.71.2 / Web 1.50.1permalink
ImprovementLowWebAPIAction required: No

More focused searches, clearer sources

Chat separates your research topic from formatting requests and presents source titles, domains and citations more clearly.

Show details ▾
  • Paper searches support quoted titles and arXiv identifiers, retain publication dates when available, and sort recent requests by submission date.
  • Source lists show domains and reference labels so similarly titled pages are easier to distinguish. Repeated links are read once.
  • Answers are guided to follow your requested format and place compact citations beside supported claims.
  • Current-news requests recognize common spellings of today and use the current date. Questions about available research tools receive capability guidance instead of an unrelated search.
1.71.1permalink
Bug fixLowAPIAction required: No

More complete research evidence

Chat retains complete source passages so shortened summaries do not hide the details needed to answer.

Show details ▾
  • Research keeps selected passages and opening context. When compression would lose usable evidence or increase its size, chat keeps the original excerpt.
  • Source receipts report the actual evidence sent, including when the original is retained.
1.71.0 / Web 1.50.0permalink
ImprovementLowWebAPIAction required: No

Web and paper research in chat

Search DuckDuckGo, find arXiv papers and read URLs with compressed evidence and saved source links.

Show details ▾
  • Choose Auto, Web, Papers, Read URLs or Off in chat tools. Auto recognizes common research and lookup requests.
  • Inspect source links, retrieval status and estimated evidence tokens in each answer. Sources remain available when reopening a conversation.
  • Search uses keyless services. Availability can vary; failed retrievals are reported explicitly.
Web 1.49.0permalink
ImprovementLowWebAction required: No

Your conversations, closer at hand

Start a chat and return to recent conversations from a simpler sidebar on desktop and mobile.

Show details ▾
  • New chat, chat search, Projects and Knowledge stay at the top. Find other destinations in More tools.
  • The mobile menu now includes saved conversations and their pin, rename and delete actions.
  • Search conversation history, load older chats and retry when a connection fails.
  • Switch projects in a searchable picker. Chat follows your selected project for knowledge and attachments.
  • Find profile, sign out, settings, billing and help together under Account.
Web 1.48.0permalink
ImprovementLowWebAction required: No

A simpler dashboard navigation

Find your workspace tools before recent chats, and preview notifications without leaving your page.

Show details ▾
  • Recent chats scroll separately from the main navigation. Secondary groups open when you need them.
  • Search, notifications, settings and your account share a quieter header with larger touch targets.
  • Settings and help brings language, billing, provider keys and product updates together.
  • Notification previews distinguish loading, an empty inbox and connection failures, with a retry action.
Web 1.48.0permalink
ImprovementLowWebAction required: No

Set up your AI in one place

Manage provider connections, image/video defaults, and spending controls together in AI settings.

Show details ▾
  • See saved provider connections first, with a compact form for adding or replacing keys.
  • Jump between Providers, Models, and Spending without leaving the page.
  • Keep unsaved model choices when a provider connection refreshes the model catalog.
  • Access subscription and invoices from the same settings hub.
1.70.0 / Web 1.47.0permalink
ImprovementLowAPIWebAction required: No

Choose your image and video models in chat

Ask for an image or video, choose an available model, and confirm the price before generation starts.

Show details ▾
  • Direct generation requests open a confirmation card while preserving your prompt.
  • Save personal and workspace defaults for video and image models, or choose each time.
  • Browse the connected provider’s media catalog, with explanations for unavailable models.
  • Recover interrupted submissions without intentionally starting a second generation.
Web 1.46.0permalink
Bug fixLowWebAction required: No

New chat opens a fresh conversation

Start a new chat after reading a reply, even when the message box is empty.

Show details ▾
  • New chat clears the previous transcript and conversation link.
  • New images and videos stay in view as they finish loading; scrolling into history keeps your place.
  • Escape closes enlarged images and returns keyboard focus to the image.
  • Unsent text is saved first. If saving fails, your draft stays in place.
1.69.0 / Web 1.46.0permalink
ImprovementLowAPIWebAction required: No

Create images and short videos in chat

Review a price, generate with your connected provider key, and return to saved results in the conversation.

Show details ▾
  • Create square images with supported OpenRouter or OpenAI models, and silent four-second videos with OpenRouter.
  • Enlarge images, play videos, and download private results directly from the conversation. Files are available for 30 days.
  • Queued generations can be cancelled. If saving fails, retry saving the completed result without generating again.
  • Generation uses your prompt; attached context is not included.
1.68.1permalink
Bug fixLowAPIWebAction required: No

Consistent text replies from connected models

Multi-part text replies appear as readable answers, including during streaming.

Show details ▾
  • OpenAI and OpenRouter replies combine their text sections without exposing raw response objects.
  • Reasoning, usage, and prompt-cache details remain available alongside the answer.
Web v1.45.1permalink
ImprovementLowWebAction required: No

A clearer chat workspace with more ways to start

Explore 30 editable prompts, read roomier answers, and keep the composer within reach as conversations grow.

Show details ▾
  • Search prompt examples across writing, coding, learning, analysis, planning, and context tasks. Choosing an example never sends it automatically.
  • The transcript scrolls independently, with responsive controls and readable tables and code on smaller screens.
  • Responses without a final answer show recovery guidance. Free OpenRouter models receive a larger output allowance.
  • Compression receipts appear when a turn has context to measure.
1.68.0permalink
Bug fixLowWebAction required: No

Workbench controls fit narrow screens

Compression inputs and results fit the available width. The tool tabs remain horizontally scrollable with a theme-aware scrollbar.

Show details ▾
  • Compression results link to your account plan
  • Result labels and buttons remain readable in light and dark themes
  • The dashboard account menu stays visible on small phones
1.68.0permalink
Bug fixLowWebAction required: No

Continue dashboard demos in your compression workspace

After a dashboard demo, continue in the compression workspace. Demo rate-limit messages no longer promise unlimited account usage.

Show details ▾
  • Public demo pages offer free sign-up
1.68.0permalink
ImprovementLowMCP GatewayAction required: No

Documentation search gains semantic reranking

Documentation search can rerank its lexical candidates with the configured embedding model and identifies the scoring method in its results. It retains lexical search when embeddings are unavailable.

Show details ▾
  • Interrupted code searches explicitly identify incomplete results
  • Improved quoted-path redaction and preservation of adjacent public URLs and routes
  • Connected feeds reserve document capacity before ingestion
1.68.0permalink
Bug fixLowWebAction required: No

Public pages stay readable in both themes

Pricing, documentation, changelog, legal pages and the homepage use theme-aware text and surfaces. The fixed navigation stays opaque over scrolled content.

Show details ▾
  • Code examples use readable syntax colors in each theme
  • Mobile, tablet and desktop layouts preserve contrast
  • Sign-in and sign-up expose their main content to assistive technology
1.68.0permalink
ImprovementLowWebAction required: No

Start a community post from the feed

Quick starters open a question or MCP tool and skill post, or take you to benchmark submission. Your headline stays empty until you write it.

Show details ▾
  • Starter controls work in light and dark themes and wrap on mobile
1.68.0permalink
FeatureMediumAPIWebClaude Code PluginAction required: No

Browser activation and safer session recovery

Connect a browser device through your signed-in account, and keep useful session context when tools recover interrupted work.

Show details ▾
  • Browser credentials stop working when the associated account is disabled or deleted
  • Release downloads check their size, integrity and expiration before activation
  • Repeated file reads remain independent across sessions, with full content retained when a baseline is unavailable
  • Recovery checkpoints retain explicit milestones without automatically saving submitted prompt text
1.68.0permalink
ImprovementLowAPIAction required: No

News administration gains audited requeue and pause controls

Administrators can requeue eligible news items with an explicit version and reason, while paused news pipelines refuse new intake, drafting, and publication. Authorized corrections, rejection, and withdrawal remain available.

Show details ▾
  • Requeue checks the expected version and records an editorial event; duplicate submissions preserve the same attempt generation
  • New intake, drafting, and publication require an available, unpaused pipeline control state; authorized safety edits remain available
1.68.0permalink
ImprovementMediumWebAPIAction required: No

Chat streams answers and preserves interrupted work

Answers and reasoning appear as they arrive. Stopping a response keeps the text already received and accounts conservatively for provider charges.

Show details ▾
  • Interrupted responses keep their partial answer
  • Missing final usage keeps the reserved cost until it can be reconciled
  • Slow providers start keepalive frames after a bounded initial wait; later refusals retain their status in an error event
1.44.26permalink
Bug fixMediumMCP GatewayAction required: No

MCP policy denials and session recovery report safe outcomes

Unavailable project policies deny execution, unknown tools are rejected, and quota-blocked summaries no longer suggest clearing a session.

Show details ▾
  • Empty project allowlists deny all tools and unavailable policy lookups refuse calls
  • Sensitive data is removed from malformed session errors
  • Explicit document searches distinguish missing documents from empty results
  • Capability listings match the tools available to your account
1.44.26permalink
FeatureMediumWebAPIAction required: No

Chat keeps every version of an answer and shows the model's thinking

Regenerating an answer or editing a message now adds a new version instead of replacing the old one, and reasoning models show their thinking in a collapsible panel beside the answer.

Show details ▾
  • Regenerate and edit create versions you can page through with the arrows under each turn
  • Edit a message in place; press Enter to send it as a new version, Escape to cancel
  • Reasoning from providers that report it appears as "Thought for N seconds", with a live timer while the model works
  • Code blocks are syntax highlighted, numbered and bulleted lists show their markers again, and answers can be read aloud
  • Keyboard shortcuts: Ctrl or Cmd + / lists them
  • Conversations you opened earlier in the session reopen instantly
1.44.25permalink
ImprovementLowMCP GatewayWebAction required: No

Jev guidance adds account and project controls

A limited hosted Pro pilot adds optional Jev guidance to document evidence tools. Knowledge Hub search and pre-flight guidance remain disabled; local results remain available if Jev fails.

Show details ▾
  • Account and project settings let owners turn Jev guidance off
  • Bounded questions and document node descriptions may be sent through OpenRouter to TypeSafe Jev
1.44.24permalink
Bug fixMediumWebAction required: No

Admin scroll no longer paints a stuck overlay

Scrolling the admin console (and the rest of the dashboard) keeps the topbar and sidebar pinned correctly instead of leaving a layered overlay while content moves underneath.

Show details ▾
  • html/body use overflow-x: clip so sticky chrome can pin to the real scrollport
  • Admin section nav stays in document flow — no sticky z-index band over the page
1.44.23permalink
ImprovementLowWebAction required: No

Admin overview becomes an operator command center

The admin overview now leads with attention queues, a full-width KPI row, secondary ops metrics, larger primary controls, and a live system pulse for compression threads and infra health.

Show details ▾
  • Needs-attention strip surfaces pending news drafts, open leads, and elevated churn
  • Operations tiles use SVG icons with larger primary actions beside the live system pulse
  • Refresh + PROD badge in the command header show when overview data was last loaded
1.44.22permalink
ImprovementLowWebAction required: No

Admin console gets a clearer operator shell

The admin overview and subpages share one sticky section nav, KPI cards, action tiles, and health meters so operators can see status and jump between tools faster.

Show details ▾
  • Sticky Admin subnav across Overview, Users, Trials, Scaling, Price audit, Moderation, Feedback, and News drafts
  • Overview KPIs sit in equal card treatment with live health bars for Postgres, Redis, email, and users
  • Quick links and form actions use the new admin button / tile primitives with clearer hover and focus states
1.44.21permalink
ImprovementLowWebAction required: No

Invite teammates right on the team page

Team owners and admins can invite someone directly on the team page: enter an email address, choose a role, and send. The dialog that used to stand in front of this is gone.

Show details ▾
  • The invite form now sits at the top of the Members tab
  • Pick the role before sending: admin, operator, or viewer
  • Success and error messages appear inline, just under the form
1.66.4permalink
ImprovementLowWebAction required: No

Chat is now a full-width canvas

Chat fills the window instead of sitting in a bordered box, so there is more room for your conversation and less surrounding chrome.

Show details ▾
  • The conversation area now fills the available space rather than sitting inside a card
  • Removed the breadcrumb and the status strip along the bottom; the tokens-saved figure is still shown at the top of the page
  • Suggested prompts are now a single row, with the rest under "More starters" alongside the example conversation
  • Conversation rows in the sidebar are taller, so they are easier to tap on a phone
1.44.21permalink
Bug fixMediumWebAction required: No

Attach chat files to the selected project

Chat now uses the project shown in the sidebar when you attach an image or text file.

Show details ▾
  • A temporary project lookup failure no longer blocks an attachment when a project is already selected
  • A project explicitly selected in the sidebar remains available to chat
  • Chat loads project and model choices once sign-in is ready
1.44.21permalink
ImprovementLowWebAction required: No

Find chat tools directly

The chat Tools menu now shows where to browse and run tools without hunting through another menu.

Show details ▾
  • Open the full tool catalog, Workbench, or batch queue directly from Tools
  • Chat settings have their own section below the tool actions
  • Add to conversation also links to the full tool catalog
1.44.20permalink
ImprovementLowWebAction required: No

Chat menus stay in place

Opening chat tools no longer moves your question or the starter cards around.

Show details ▾
  • Tools, Add, and Context open beside the composer without shifting the chat
  • Menus stay reachable on smaller screens and close with Escape or a click outside
  • Attached context remains available while you compose or retry a message
1.44.19permalink
ImprovementLowWebAction required: No

A clearer start to chat

Chat now puts your question first and makes starter tasks easier to understand before you choose one.

Show details ▾
  • The opening message explains how to ask across your files and knowledge
  • Starter cards include a short explanation of each task
  • On narrow screens, starter cards remain browsable without pushing the composer aside
  • Project initials in chat navigation are easier to read in light mode
  • The install-app action stays readable in the light dashboard theme
1.66.4permalink
ImprovementLowWebAction required: No

Redesigned sign-in and repaired the sign-up page theme

Signing in now uses a two-column layout, and both the sign-in and sign-up forms follow your light or dark theme instead of always rendering on a light card.

Show details ▾
  • The sign-in form sits in its own column beside a panel describing what the product does, matching the layout most developer tools use
  • Both forms now follow the site theme in light and dark mode
  • On sign-up in light mode, the Continue button no longer renders white text on bright cyan, which was too faint to read
  • Sign-up email and password fields are now visible against the card instead of blending into it
  • The marketing opt-in checkbox no longer renders as a white box in dark mode
  • The "last used" hint above the social sign-in buttons is no longer cut off
  • Fewer links at the foot of the sign-in page, with one clear path to create an account
1.66.4permalink
FeatureMediumAPIMCP GatewayAction required: No

Governed session-lesson distillation for agent plan proposals

Agents can now distill a session transcript into candidate lessons and submit them as a governed plan proposal in one call, instead of a manual write-up.

Show details ▾
  • A new MCP tool extracts durable, actionable lessons from a session transcript and submits them as a plan proposal against a target project
  • Falls back to a bounded local summary rather than a paid model call when the estimated cost is above a small threshold or no provider key is configured
  • Goes through the same scope-gated review flow as every other plan proposal
1.66.4permalink
FeatureMediumAPIAction required: No

Sandbox owner-stop and compute-budget guardrails

Sessions built on the sandbox runtime can now be stopped directly by their owner, and the platform can enforce daily/monthly compute-spend caps across a fleet before a new session starts.

Show details ▾
  • Owners can request destruction of their own sandbox session directly, with the platform confirming the underlying machine is actually gone before marking it stopped
  • A background sweep periodically reconciles session state against the real infrastructure so orphaned sessions do not sit indefinitely
  • Both the sandbox runtime and its compute-budget enforcement remain off by default while this rolls out
1.66.4permalink
FeatureMediumAPIMCP GatewayAction required: No

Two new MCP tools for self-hosted repo audits

Self-hosted and locally-attached MCP clients can now check which of their own files are undocumented, and pull a deterministic map of their repository, straight from an MCP call.

Show details ▾
  • A new tool lists source files your own project documentation never mentions, so drift between code and docs is a single call away
  • A companion tool returns a structured map of a repository — central files, entry points, and a symbol index
  • Both tools operate on a real local repository path, so they are available to self-hosted operators and locally-attached MCP clients, not the hosted SaaS gateway
1.44.18permalink
ImprovementMediumWebAction required: No

A clearer, more focused chat workspace

Chat now keeps conversations, model selection, context tools, and response actions easier to find while you work.

Show details ▾
  • Conversation navigation and chat actions stay organized across desktop and smaller screens
  • The composer gives prompts, attachments, tools, and model selection clearer focus states and grouping
  • Starter prompts and response actions remain close to the conversation without crowding the workspace
1.66.74permalink
Bug fixCriticalWebAction required: No

Chat now handles keyless accounts and assistive technology honestly

The chat composer no longer presents a working send action when no provider model is available, and streaming and command navigation expose their state to assistive technology.

Show details ▾
  • Keyless accounts get an inline OpenRouter connection path from the model picker
  • The transcript announces new responses and exposes generation progress
  • Example conversations are labelled and excluded from live savings totals
1.66.73permalink
FeatureMediumWebAction required: No

Create team-scoped webhooks from the dashboard

The webhooks page can stamp new endpoints with a team scope so VAL-CROSS-001 delivery filters apply.

Show details ▾
  • Optional Scope selector lists your active teams
  • createWebhook sends team_id when a team is selected
  • Team-scoped endpoints show a team badge in the list
1.66.72permalink
Bug fixMediumWebAction required: No

Webhook SDK types include team and project scope

The dashboard API client WebhookResponse type now exposes team_id and project_id, matching the REST API.

Show details ▾
  • WebhookResponse adds team_id and project_id (string | null)
  • createWebhook accepts optional teamId for team-scoped hooks
1.66.65permalink
Bug fixHighAPIAction required: No

Knowledge Hub get_item now returns items shared to your project

Items shared to a member project appeared in list and search but returned not found on detail fetch. get_item now uses the same membership UNION as list and query, and chunk counts use the owner project partition.

Show details ▾
  • Shared KB items visible in list_items/query are now retrievable via get_item
  • Chunk count on shared items uses the owner project_id partition
Showing 40 of 358 releases

Security advisories · incidents · compliance history

Web v1.45.0permalink
Security advisoryInformationalAPIWebAction required: No

Browser enrollment now has an explicit deny decision

You can deny a browser enrollment request, and a denied device code cannot later grant account access.

Show details ▾
  • The activation page confirms or denies the pending device request.
  • A denial is terminal for that device code; it does not create a credential.
  • Confirmation is bound to the signed-in account identity.
1.66.71permalink
Security advisoryMediumAPIMCP GatewayAction required: No

Free-tier compression quota now fails closed when usage cannot be measured

If Redis and the Postgres fallback both cannot determine monthly usage, free-tier compress and MCP calls return a retryable error instead of bypassing the monthly limit.

Show details ▾
  • Redis down + Postgres fallback exhausted on free plan -> HTTP 503 quota_unavailable
  • Postgres fallback uses the same billable UsageEvent filters as usage cache rebuild
  • Paid tiers remain fail-open when usage is unmeasured
1.66.70permalink
Security advisoryMediumAPIMCP GatewayAction required: No

API key auth refuses when Postgres cannot confirm enforcement state

If Redis authenticates a key but Postgres cannot confirm project binding or allowlists, the request is rejected (401 when the row is gone, 503 on DB outage) instead of serving possibly stale Redis enforcement fields.

Show details ▾
  • Deleted/revoked key with stale Redis blob -> HTTP 401
  • Postgres outage during enforcement lookup -> HTTP 503 auth_state_unavailable
  • Successful DB lookup still overwrites Redis-seeded state from Postgres
1.66.69permalink
Security advisoryHighAPIAction required: No

Polar subscription webhook processing failures now return 503

If a subscription lifecycle handler fails after signature verify, the webhook returns 503 so Svix retries instead of acknowledging with 200 and risking a dropped grant or downgrade.

Show details ▾
  • Lifecycle handler exceptions -> HTTP 503 Webhook processing failed
  • Unreadable discriminator after verify -> HTTP 503
  • Named-but-unhandled events still return 200
1.66.68permalink
Security advisoryMediumAPIAction required: No

Resend inbound webhooks now deduplicate Svix replays

Replayed Resend deliveries with the same svix-id short-circuit with 200 before re-running bounce/complaint suppression. Dedup failures return 503 so retries stay safe.

Show details ▾
  • dedup_inbound_event(provider=resend) after signature verify
  • Replay -> 200 ok without re-applying opt-out
  • Dedup DB error -> 503 dedup unavailable
1.66.67permalink
Security advisoryHighAPIAction required: No

Resend bounce suppression failures now return 503 (fail closed)

If bounce/complaint opt-out handling fails after signature verify, the webhook returns 503 so Resend retries instead of acknowledging with 200 and permanently skipping email suppression.

Show details ▾
  • Suppression-handler exceptions -> HTTP 503 suppression unavailable
  • Soft/ignored/success paths still return 200
  • Misconfig and bad signatures remain 400
1.66.66permalink
Security advisoryHighAPIAction required: No

Inbound webhook dedup failures now return 503 instead of re-processing

If the dedup ledger is unavailable after signature verification, Clerk, Polar, and GitHub webhooks return 503 and skip handlers. This prevents non-idempotent side effects from running twice when Svix retries, at the cost of a temporary delay until dedup recovers (GitHub needs a manual redeliver).

Show details ▾
  • Dedup DB errors fail closed with 503; handlers are not dispatched
  • Rollback after a dedup error is best-effort and cannot demote the 503 to a 500
  • GitHub log/detail includes the redeliver phrase for operator recovery
1.66.64permalink
Security advisoryHighAPIAction required: No

Offline migration scripts now include the RLS safety sweep

When you generate SQL with alembic upgrade --sql, the output now includes the same post-migration Row Level Security sweep that runs on every Fly deploy. Previously, applying offline-generated scripts could leave new public tables without RLS enabled.

Show details ▾
  • Offline Alembic runs on Postgres URLs emit lock_timeout + ENABLE ROW LEVEL SECURITY sweep SQL after migrations
  • Mirrors the every-deploy migration hook so air-gapped or reviewed SQL paths cannot skip tenant isolation hardening
1.66.20permalink
Security advisoryMediumAPIAction required: No

Accept-grant elevates to system before RLS-sensitive write

Preparing for RLS enablement: recording share acceptance now sets app.role=system for the accept UPDATE so it still works once policies are enforced.

Show details ▾
  • accept_grant elevates app.role mid-transaction before stamping accepted_at (0149 requires a service write, not a grantee UPDATE).
  • Does not flip RLS_GUC_ENABLED or change the production DB role; those remain CEO-gated (#514).
1.64.1permalink
Security advisoryMediumAPIAction required: No

Chat completions now has its own 60/min ceiling

POST /v1/chat/completions forwards each call to an upstream model provider on your own stored API key, so you are billed directly for it. It previously inherited the general per-plan request limit, which on the top tier allowed 500 calls a minute. It is now capped at 60 a minute -- one per second -- so a runaway loop or a leaked key costs far less before you notice. Normal interactive use is nowhere near this.

Show details ▾
  • The new ceiling applies only to POST /v1/chat/completions. Compression, knowledge and every other endpoint keep their existing per-plan limits.
  • Per-path ceilings can now only lower a limit, never raise one. Previously a path entry replaced the plan value outright, so an entry above your plan tier would have increased your allowance instead of capping it.
  • Responses continue to carry x-ratelimit-limit, x-ratelimit-remaining and x-ratelimit-reset, so a client can see the ceiling it is working against.
1.64.1permalink
Security advisoryMediumAPIAction required: No

Webhook signing secrets are now encrypted at rest

The secret your endpoint uses to verify the signature on our webhook deliveries is now encrypted in our database rather than stored as readable text. Nothing changes for you: the secret value itself is unchanged, so your existing verification keeps working and no reconfiguration is needed.

Show details ▾
  • New webhook secrets are encrypted before they are stored, using the same versioned key scheme already used for provider credentials.
  • The secret is still shown to you once, in full, when you create the webhook. It stays redacted everywhere else.
  • Delivery signatures are unchanged, so endpoints that already verify our signature continue to verify successfully.
1.62.0permalink
Security advisoryMediumAPIAction required: No

Signed A2A Agent Card for verifiable identity

Other AI agents that discover gotcontext through the Agent2Agent (A2A) protocol can now cryptographically verify that the Agent Card really came from gotcontext, before they trust or delegate to it. Our public Agent Card now carries a JWS signature that a standard A2A client can check against our published key.

Show details ▾
  • The Agent Card at the well-known A2A discovery path now includes a JWS signature (Ed25519) over the RFC 8785 canonical form of the card.
  • Verifiers can fetch the verification key from our published key set and reject a forged or tampered card.
  • The signature is additive and backward compatible: existing clients that ignore it keep working; self-hosted deployments without a signing key serve an unsigned card.
API v1.58.7permalink
Security advisoryHighMCP GatewayAction required: No

Restricted server-side-path tools on the hosted MCP service

A few Pro-tier MCP tools accept a server-side file path, which is only meaningful in a self-hosted deployment. On the hosted service they are now correctly hidden and blocked, since they do not apply there. Self-hosted deployments are unaffected and keep full access.

Show details ▾
  • Tools that take a server-side path are no longer discoverable or callable on the hosted MCP endpoint.
  • Added an automated release check so any future tool of this kind is caught before it ships.
  • Self-hosted operators keep these tools in full.
API v1.58.7permalink
Security advisoryHighAPIAction required: No

Upgraded a core web framework to clear published CVEs

Upgraded the API's underlying web framework to a new major version, clearing four high-severity published vulnerabilities, including authentication-bypass and request-forgery classes. No action is required on your side.

Show details ▾
  • Core web framework upgraded to its latest major release.
  • Four high-severity published vulnerabilities resolved.
  • No changes to your integration or request format.
API v1.58.7permalink
Security advisoryMediumAPIMCP GatewayAction required: No

Knowledge Base private items and sharing are now enforced

Items marked private are visible only to the API key that created them. Per-key sharing allowlists are enforced on every Knowledge Base operation: query, read, edit, delete, and diff, across both the MCP and REST surfaces.

Show details ▾
  • Private Knowledge Base items are accessible only to the API key that created them.
  • Sharing allowlists are checked on every operation (query, read, edit, delete, diff), not just on query.
  • Enforcement is consistent across the MCP gateway and the REST API.
Web v1.44.15permalink
Security advisoryMediumWebAction required: No

Web dependency security updates

Several transitive browser and server-runtime dependencies were updated to patched versions. No customer action is required.

Show details ▾
  • Updated affected transitive packages used by the web runtime and build toolchain.
  • Kept the update within compatible version ranges to avoid changing application behavior.
  • Hosted customers receive the fix automatically.
API v1.53.0permalink
Security advisoryHighAPIMCP GatewayAction required: No

Security and reliability fixes: filesystem filter, billing portal, cron cost, Docker pinning

Seven fixes from a proactive internal audit. The MCP search_code tool is now properly filtered in SaaS mode. Per-API-key tool restrictions now apply at discovery (tools/list) as well as dispatch. The billing portal returns a clear error instead of a misleading upgrade prompt when the database is briefly unavailable. GitHub Actions cron schedules were cut to reduce infrastructure cost. Docker base images are now digest-pinned for supply-chain stability. Hosted customers are auto-upgraded.

Show details ▾
  • The MCP search_code tool is now correctly restricted when running in hosted mode, preventing server-path access.
  • Per-API-key tool allowlists now filter tools/list (discovery) and tools/call (dispatch) consistently.
  • The billing portal returns a 503 with a clear message instead of a 404 "upgrade first" when the database is briefly unavailable.
  • The compression engine now rejects non-finite embeddings at ingest, preventing silent result corruption downstream.
  • Wire-shape contracts for the forum and social surfaces are now locked against future renames.
  • GitHub Actions cron schedules reduced by roughly 59% to cut infrastructure cost.
  • Docker base images are now digest-pinned so base-image changes arrive as reviewable pull requests.
API v1.52.3permalink
Security advisoryHighAPIMCP GatewayAction required: No

Security hardening: account deletion, billing, and webhook fixes

Five fixes from a proactive internal security audit. API keys are now revoked the moment their owner account is deleted; referral credits can only be earned once per referred user; the MCP proxy tool now blocks requests to internal network addresses; key revocation is reliable under concurrent requests; and usage-alert delivery is durable across server restarts. Hosted customers are auto-upgraded. No action required.

Show details ▾
  • Deleting an account now revokes all of its API keys before the account is removed.
  • Referral credit can only be earned once per referred user.
  • The MCP proxy tool no longer forwards requests to private or internal network addresses.
  • Key revocation is now reliable even under concurrent requests, so a revoked key is consistently rejected.
  • Usage-alert delivery is durable and is no longer dropped when a server instance restarts.
API v1.50.23permalink
Security advisoryMediumAPIAction required: No

Forum security: user silencing, safer username conflicts, link sanitization

Three forum hardening fixes: moderators can silence and unsilence users; username conflicts no longer reveal whether a name is already taken by another account; and unsafe links are stripped from comment content.

Show details ▾
  • Moderators can silence a user so they can no longer post comments, and reverse it.
  • Username conflicts are reported without revealing whether the name belongs to another account.
  • Unsafe links are stripped from comment content.
API v1.50.22permalink
Security advisoryMediumAPIAction required: No

Comment sanitizer hardened

The comment sanitizer was rebuilt to strip all HTML tags directly instead of relying on allowlisting, closing a class of HTML-entity edge cases and reducing the dependency surface.

Show details ▾
  • All HTML/XML tags are now stripped from comments; no HTML attributes survive.
  • Plain text and Markdown syntax is preserved.
API v1.50.16permalink
Security advisoryMediumAPIAction required: No

Payment-token audience enforcement

Skyfire payment tokens are now validated against the expected audience, so a token issued for a different service cannot be reused against this API. Agent payments remain off by default.

Show details ▾
  • Payment tokens whose audience does not match this service are rejected.
  • Operators enabling agent payments configure the expected audience as part of setup.
API v1.50.15permalink
Security advisoryHighAPIAction required: No

Secret encryption now fails closed in production

If the encryption key is not configured in production, secret-storage operations now fail safely instead of proceeding, preventing secrets from ever being written unencrypted. Local development behavior is unchanged.

Show details ▾
  • In production, a missing encryption key blocks the operation rather than storing unencrypted data.
  • Local development is unaffected for convenience.
  • Operators who rely on encryption should confirm the key is configured before deploying.
API v1.50.5 / Web v1.42.2permalink
Security advisoryLowAPIWebAction required: No

Hardened HTTP security-header baseline across the API and dashboard

Every API and dashboard response now carries a stronger set of browser security headers, defense-in-depth against clickjacking, MIME-type confusion, and referrer leakage. No customer action is required.

Show details ▾
  • Added X-Content-Type-Options (nosniff), X-Frame-Options (clickjacking protection), a stricter Referrer-Policy, and a Permissions-Policy denying unused device features.
  • Headers are only set when not already present, so nothing a route configures itself is overwritten.
  • A full Content-Security-Policy is being rolled out separately in report-only mode first, to avoid breaking sign-in or analytics.
  • No customer action is required.
API v1.50.4permalink
Security advisoryMediumAPIAction required: No

Per-plan request body-size limits now enforced reliably, including for streamed requests

Request body-size limits are now enforced reliably, including for streamed requests. Over-limit requests are rejected before any route handler processes the body.

Show details ▾
  • Identified through a proactive internal security audit and fixed server-side.
  • All upload styles (including streamed requests) are now subject to the same per-plan size limits.
  • Over-limit requests receive a deterministic 413 response before any route handler processes the body.
  • Within-limit uploads are unaffected.
  • No customer action is required.
Web v1.42.1permalink
Security advisoryMediumWebAction required: No

Dashboard notification rendering hardened against HTML injection

Notification links are now strictly escaped and URL-validated before rendering in the dashboard.

Show details ▾
  • Found through a proactive internal security audit; fixed in the rendering layer.
  • Notification links are now validated as http(s) URLs; invalid URLs render as plain text with no anchor element.
  • No customer action is required.
API v1.50.3permalink
Security advisoryHighAPIMCP GatewayAction required: No

Knowledge-base and tool access restrictions now fail closed on a database error

A database error during API key resolution could reset a key's knowledge-base and tool allowlists to unrestricted. Those restrictions now hold their seeded values when a database error occurs.

Show details ▾
  • Found through a proactive internal security audit as a follow-on to the v1.50.0 hardening.
  • Per-key knowledge-base and tool allowlists are now preserved correctly when a database error occurs during key resolution, rather than resetting to unrestricted.
  • Keys with no allowlist configured remain unrestricted. Existing behaviour is unchanged.
  • No customer action is required.
API v1.50.2permalink
Security advisoryMediumAPIAction required: No

GitHub tokens and webhook secrets now encrypted at rest

GitHub personal access tokens and webhook secrets stored for the GitHub integration were previously held as plaintext in the database. They are now encrypted with a server-side key; existing values are transparently upgraded.

Show details ▾
  • Found through a proactive internal security audit and fixed server-side.
  • Integration secrets are now stored as encrypted ciphertext; a database read or backup exposes ciphertext only.
  • Existing plaintext values were re-encrypted during the deployment. No manual step required.
  • Secret encryption now fails closed in production: if the encryption key is not configured, secret-storage operations fail safely instead of proceeding unencrypted.
  • No customer action is required.
API v1.50.1permalink
Security advisoryMediumAPIAction required: No

Outbound webhook URLs validated against internal-network access

User-configured webhook delivery URLs were not validated against internal network ranges, allowing delivery to private or cloud-metadata addresses. Webhook URLs are now checked at creation and re-validated immediately before each delivery.

Show details ▾
  • Found through a proactive internal security audit and fixed server-side.
  • Webhook creation now rejects URLs that resolve to private, loopback, link-local, or cloud-metadata addresses.
  • The delivery path re-validates the target address immediately before each outbound request.
  • HTTP redirects are no longer followed during delivery.
  • No customer action is required.
API v1.50.0permalink
Security advisoryHighAPIMCP GatewayAction required: No

Scoped API keys now strictly enforced; destructive-action confirmation locked to dashboard sign-in

Scoped API keys were accepted by the server but their scope constraints were not persisted or enforced. Every scoped key silently ran with full access. Scope restrictions are now applied end-to-end. Separately, the confirmation gate for destructive key operations now requires an active dashboard session.

Show details ▾
  • Found through a proactive internal security audit and fixed server-side.
  • Scope restrictions are now stored and enforced on every request. Previously they were accepted at creation but not applied.
  • Existing keys without explicit scopes are treated as legacy full-access keys. No behaviour change for current users.
  • A temporary backend outage during key resolution no longer causes a scoped key to fall back to full access.
  • The confirmation gate for destructive key operations now requires an active dashboard session.
  • No customer action is required.
API v1.45.xpermalink
Security advisoryMediumAPIAction required: No

Analytics CSV export hardened against spreadsheet formula injection

CSV cells beginning with formula-trigger characters (=, +, -, @) are now neutralized so exported files cannot execute formulas when opened in Excel or Google Sheets.

Show details ▾
  • Identified through a proactive internal security review and fixed server-side.
  • Cells that start with =, +, -, or @ are prefixed with a tab character before export, following standard CSV injection mitigation practice.
  • Numeric and date values are unaffected.
  • No customer action is required.
API v1.35.0permalink
Security advisoryHighAPIMCP GatewayAction required: No

Live key revocation across all API servers + outbound URL hardening

Revoked gc_ API keys are now invalidated promptly and reliably across all API servers. Separately, the document-fetch and Knowledge Hub ingest paths now block requests to private or internal network addresses across all known address encoding variants.

Fixed in:
API v1.35.0
Components:
API key lifecycle · MCP Gateway
Show details ▾
  • Revoked API keys are now invalidated promptly across all API servers. Revocation no longer requires waiting for a cache TTL to expire.
  • Server restarts no longer cause revocation events to be missed.
  • The document-fetch and Knowledge Hub ingest paths now block requests to private or internal network addresses.
  • Pairs with the v1.34.36 hotfix (cache-invalidation gap in the key confirmation flow) shipped the same day.
API v1.34.36permalink
Security advisoryHighAPIAction required: No

P0 hotfix: revoked confirm-tokens now invalidated promptly across all servers

A revoked key issued through the key-confirmation flow was not immediately invalidated in the shared cache, allowing it to continue authenticating on peer servers until the cache refreshed. The fix invalidates the cache immediately after revoking the key in the database.

Affected:
API v1.34.35
Fixed in:
API v1.34.36
Components:
API key lifecycle
Show details ▾
  • Cache invalidation is best-effort: a cache failure is logged and does not surface as an error to the caller.
Incident · resolved in API v1.23.12026-05-09 17:14 to 17:24 UTC (10 minutes)permalink
IncidentCriticalMCP GatewayAction required: No

MCP tools returned 500 for ~10 minutes

All MCP tool calls failed with HTTP 500 for approximately 10 minutes. No data was lost. Customers using MCP clients (Claude Code, Cursor, Codex CLI, Gemini CLI) saw tool calls fail and could retry after the window closed.

Affected:
API v1.22.4 to v1.23.0
Fixed in:
API v1.23.1
Components:
MCP Gateway · tools/call dispatch
Show details ▾
  • A routing change caused every tool call to reach a code path with a reference that had never existed. The defect was dormant in a prior release but only became reachable after the routing change landed.
  • Resolution: the broken reference was removed and deployed as API v1.23.1.
  • Hardening: automated checks were added to catch this entire class of defect before it ships.
Compliance notice · resolved in API v1.23.1permalink
Compliance noticeHighAPIAction required: No

Unsubscribe endpoint returned 401 for all requests

Between API v1.23.0 and v1.23.1, the `/v1/unsubscribe` endpoint (used for the CAN-SPAM/GDPR-required unsubscribe link in transactional emails) returned 401 Unauthorized for all requests. No unsubscribe records were lost. The endpoint returned a non-200 to clients, which retried or surfaced the error. No customer action required.

Affected:
API v1.23.0
Fixed in:
API v1.23.1
Components:
API · /v1/unsubscribe · transactional email footer
Show details ▾
  • The endpoint now correctly accepts unauthenticated requests as required for the unsubscribe use case.
  • No personal data was processed during the regression window. All requests during the window returned an explicit 401; retrying the unsubscribe link resolves the original opt-out.
Security advisory · resolved in API v1.22.6permalink
Security advisoryHighAPIMCP GatewayAction required: Yes

SSRF: outbound URL fetch paths now block requests to private and internal network addresses

Outbound URL fetches (used by webhook delivery, KB document ingestion, and a small number of MCP tools) could be tricked into reaching loopback or private addresses through address encoding techniques. The webhook/document-fetch paths now block requests to private or internal network addresses. Hosted customers received the fix automatically; self-hosted operators should upgrade to API ≥ v1.22.6.

Action required

Self-hosted operators: upgrade the API container to v1.22.6 or newer. No action required for customers on the hosted gotcontext.ai service.

Affected:
API ≤ v1.22.5
Fixed in:
API v1.22.6
CVE:
CVE pending assignment
CVSS:
7.5 (High), CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Components:
Webhook delivery · Knowledge Hub
Show details ▾
  • All outbound URL fetch paths now enforce private/internal network blocking at both validation time and connection time.
  • No active exploitation was observed in production traffic. The advisory is published preemptively.

Older releases are listed above on this page. Follow release announcements on GitHub for change notifications. Security advisories, incidents, and compliance notices are filed on this page; use the filters above to narrow by surface or type.

Citing a specific change? Use the permalink on each entry (/changelog#<entry-id>). To get notified when a security advisory or breaking change ships, subscribe via the Atom feed or create an account for email notifications.