> ## Documentation Index
> Fetch the complete documentation index at: https://docs.proofable.me/llms.txt
> Use this file to discover all available pages before exploring further.

# Changelog

> Every Proofable release, what changed across MCP, SDK, and docs, and the upgrade steps you need for each.

Each entry is a product release: MCP, the SDK, and these docs, plus the upgrade steps for that cut. The [predecessor releases](#history) are summarized at the bottom.

Package records: [`proofable/sdk`](https://github.com/proofable/sdk/blob/main/CHANGELOG.md), [`proofable/mcp`](https://github.com/proofable/mcp/blob/main/CHANGELOG.md), and [`proofable/docs`](https://github.com/proofable/docs/blob/main/CHANGELOG.md).

<Note>
  Published APIs and verifier schemas may change between minor versions. Breaking changes are listed in each entry and in the repo changelogs.
</Note>

<Update
  label="October 5, 2026"
  description="v0.1.4"
  tags={["SDK", "Docs", "Agents"]}
  rss={{
title: "Proofable SDK v0.1.4",
description: "Delegated runtime mounts fail closed when the permission carries no explicit allow-list."
}}
>
  ## Delegated mounts fail closed without an allow-list

  `@proofable/sdk@0.1.4` makes an empty or missing `allowedActions` list grant nothing for a delegated permission, matching the hosted contract. A delegated host action is denied with `ACTION_NOT_ALLOWED`; controller-owned mounts keep their existing behavior. See [Run your first guarded action](/mcp/guarded-action).

  ```bash theme={"system"}
  npm install @proofable/sdk@0.1.4
  ```
</Update>

<Update
  label="September 25, 2026"
  description="Checking a proof is free"
  tags={["API", "Docs", "Pricing"]}
  rss={{
title: "Checking a proof is free",
description: "Checks against an existing proof no longer cost credits. You pay only to create a proof."
}}
>
  ## Checks are free

  Checking an existing proof now costs **0 credits**. You pay only when you create a new proof.

  * `GET` and `POST /api/v1/proofs/check` are free. Rate limits per plan are the only control.
  * Per-request surcharges for verifier count, query complexity, time window, and result limit are removed.
  * `/api/v1/proofs/check` is no longer an x402 pay-per-call resource. Proof creation and share grants still are.
  * Access grants are a flat 2 credits. Duration tiers (`perHour`, `maxDurationBonus`) were removed; the grant's own duration limit is enforced where the grant is created.

  Reuse is the point of a portable proof, so checking one is free and rate-limited rather than metered. See [Pricing](/pricing) and [Reuse verification](/use-cases/reuse-verification).
</Update>

<Update
  label="September 24, 2026"
  description="v0.1.2"
  tags={["SDK", "API", "Docs", "MCP", "Agents"]}
  rss={{
title: "Proofable v0.1.2",
description: "Agent delegation follows the canonical action contract. Explicit allow-lists, bounded spend, and origin limits replace scopes."
}}
>
  ## Canonical delegation actions

  An agent's authority is what its delegation lists, not a scope string. `allowedActions` minus `deniedActions` is the grant, and an empty allow-list grants nothing.

  * Delegations require `allowedActions` and only accept canonical action names.
  * Spend authority is bounded: `make_payment` needs `allowedPaymentTypes` and `maxSpend` together.
  * App agents list the web origins they may act from in `allowedOrigins`, or `"*"` for servers.
  * Revoked, superseded, and expired delegations grant nothing.

  ```bash theme={"system"}
  npm install @proofable/sdk@0.1.2
  ```
</Update>

<Update
  label="September 13, 2026"
  description="v0.1.1"
  tags={["SDK", "API", "Docs", "MCP"]}
  rss={{
title: "Proofable v0.1.1",
description: "Inline Gate Policy, subject reuse without a profile, one description per public surface, and x402 on POST /proofs/check."
}}
>
  ## Builder path without a listing

  Define the checks in your app. Check the visitor by account. Reuse a current proof. Verify only what is missing.

  * `defineGate` + `gateCheck({ gate, subject })` does not create a Proofable profile.
  * `POST /api/v1/proofs/check` takes the same x402 pay-per-call rail as `GET`.
  * MCP sign-in stays OAuth. Machine API calls stay x402, sponsor, or credits.
  * `gateCheck({ gateId })` still works for published listings.

  ## One description per public surface

  GitHub, npm, the MCP Registry, and product pages no longer repeat the product line. Each surface now carries its own description, so search and directories show what that surface is instead of one slogan everywhere.

  * MCP package and registry: Give AI agents identity, scoped access, trusted context, and verifiable actions through MCP.
  * SDK package: SDK and CLI for verification gates, reusable proof, and agent permissions.
  * Docs: Docs for verification, gates, proofs, agents, and MCP.
  * The category stays the remembered brand: The trust harness for AI.
  * Release notes now summarize the predecessor `@neus` releases in one readable [history section](#history).

  ```bash theme={"system"}
  npm install @proofable/sdk@0.1.1
  ```
</Update>

<Update
  label="September 6, 2026"
  description="v0.1.0"
  tags={["MCP", "SDK", "Docs", "Agents"]}
  rss={{
title: "Proofable v0.1.0",
description: "First Proofable release. Connect once. Carry identity, limits, and proof across AI clients and apps."
}}
>
  ## First Proofable release

  Connect your AI client once. Carry agent identity, limits, and current proof into the next client or app.

  * Connect context, tools, and authority to your profile.
  * Reuse a current proof instead of repeating the check.
  * Give each agent an identity, a spend limit, and permissions you can revoke.
  * Require current proof before access or a protected action.

  If you are upgrading from the earlier `@neus` packages, see the [migration guide](/migrate).

  ### Breaking changes

  * `@neus/sdk` is now `@proofable/sdk`. `@neus/mcp-server` is now `@proofable/mcp`.
  * The CLI binary is `proofable` (was `neus`). Run `npx -y @proofable/sdk setup`.
  * MCP tools are named `proofable_*`. `tools/list` advertises only these names.
  * The MCP config key is `proofable`. The token store moved from `~/.neus/` to `~/.proofable/`, so sign in once.

  Full rename mapping and fix steps: [Migration guide](/migrate).
</Update>

## History

Before the Proofable packages, the same product shipped as `@neus/sdk` and `@neus/mcp-server`. The notes below are the highlights of each predecessor release. The complete record stays with those packages on npm and in the archived source at [proofable/network](https://github.com/proofable/network) under the `neus-final` tag. To move an `@neus` install to Proofable, see the [migration guide](/migrate).

| Release | Date | Highlights |
| - | - | - |
| 1.3.9 | 2026-08-13 | OAuth browser command-injection sink removed; registry scanning scoped to the MCP package; retired `neus` import/export/revoke aliases; trust-workflow skill restored in the plugin bundle. |
| 1.3.8 | 2026-07-30 | RFC 9207 issuer validation in `neus setup` and `neus auth`; retired `neus-trust` plugin fallback probe. |
| 1.3.7 | 2026-07-30 | One-click marketplace install restored in Cursor; RFC 8707 `resource` normalization fixes `invalid_target`. |
| 1.3.6 | 2026-07-30 | Cursor plugin owns MCP registration, CLI defers when present; trust-workflow skill moved into the package as its single home. |
| 1.3.5 | 2026-07-21 | Optional ZKPassport dependency aligned to 0.16.1. |
| 1.3.4 | 2026-07-21 | Offline portable-proof verification (EIP-191, Ed25519, EIP-1271) with strict canonical JSON and a CAIP-380 interoperability fixture. |
| 1.3.0 | 2026-07-08 | `llms.txt` and `pricing.txt` for AI search; docs opened to AI crawlers; Codex plugin metadata; public SDK surface tightened. |
| 1.2.0 | 2026-06-18 | Agent context mount: `neus mount <agentId>` for any runtime; `neus_agent_mount` in-session; runtime-mount SDK modules. |
| 1.1.0 | 2026-05-26 | First public MCP release: OAuth-first setup, `@neus/mcp-server` on npm, public tools including encrypted Vault secrets, Claude Code marketplace plugin. |
| 1.0.12 | 2026-05-26 | First `@neus/sdk` release with the hosted MCP CLI and OAuth browser flow. |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.