proofable/sdk, proofable/mcp, and proofable/docs.
Published APIs and verifier schemas may change between minor versions. Breaking changes are listed in each entry and in the repo changelogs.
Delegated mounts fail closed without an allow-list
@proofable/sdk@0.1.4 makes an empty or missing allowedActions list grant nothing for a delegated permission, matching the hosted contract. A delegated host action is denied with ACTION_NOT_ALLOWED; controller-owned mounts keep their existing behavior. See Run your first guarded action.Checks are free
Checking an existing proof now costs 0 credits. You pay only when you create a new proof.GETandPOST /api/v1/proofs/checkare free. Rate limits per plan are the only control.- Per-request surcharges for verifier count, query complexity, time window, and result limit are removed.
/api/v1/proofs/checkis no longer an x402 pay-per-call resource. Proof creation and share grants still are.- Access grants are a flat 2 credits. Duration tiers (
perHour,maxDurationBonus) were removed; the grant’s own duration limit is enforced where the grant is created.
Canonical delegation actions
An agent’s authority is what its delegation lists, not a scope string.allowedActions minus deniedActions is the grant, and an empty allow-list grants nothing.- Delegations require
allowedActionsand only accept canonical action names. - Spend authority is bounded:
make_paymentneedsallowedPaymentTypesandmaxSpendtogether. - App agents list the web origins they may act from in
allowedOrigins, or"*"for servers. - Revoked, superseded, and expired delegations grant nothing.
Builder path without a listing
Define the checks in your app. Check the visitor by account. Reuse a current proof. Verify only what is missing.defineGate+gateCheck({ gate, subject })does not create a Proofable profile.POST /api/v1/proofs/checktakes the same x402 pay-per-call rail asGET.- MCP sign-in stays OAuth. Machine API calls stay x402, sponsor, or credits.
gateCheck({ gateId })still works for published listings.
One description per public surface
GitHub, npm, the MCP Registry, and product pages no longer repeat the product line. Each surface now carries its own description, so search and directories show what that surface is instead of one slogan everywhere.- MCP package and registry: Give AI agents identity, scoped access, trusted context, and verifiable actions through MCP.
- SDK package: SDK and CLI for verification gates, reusable proof, and agent permissions.
- Docs: Docs for verification, gates, proofs, agents, and MCP.
- The category stays the remembered brand: The trust harness for AI.
- Release notes now summarize the predecessor
@neusreleases in one readable history section.
First Proofable release
Connect your AI client once. Carry agent identity, limits, and current proof into the next client or app.- Connect context, tools, and authority to your profile.
- Reuse a current proof instead of repeating the check.
- Give each agent an identity, a spend limit, and permissions you can revoke.
- Require current proof before access or a protected action.
@neus packages, see the migration guide.Breaking changes
@neus/sdkis now@proofable/sdk.@neus/mcp-serveris now@proofable/mcp.- The CLI binary is
proofable(wasneus). Runnpx -y @proofable/sdk setup. - MCP tools are named
proofable_*.tools/listadvertises only these names. - The MCP config key is
proofable. The token store moved from~/.neus/to~/.proofable/, so sign in once.
History
Before the Proofable packages, the same product shipped as@neus/sdk and @neus/mcp-server. The notes below are the highlights of each predecessor release. The complete record stays with those packages on npm and in the archived source at proofable/network under the neus-final tag. To move an @neus install to Proofable, see the migration guide.