The status page now tracks real uptime percentiles (24h / 7d / 30d / 90d) with response-time history and a recent-incidents list, instead of a fixed "all systems operational" badge.
Organizations can now subscribe to Pro ($9/month, 5,000 requests/month) from the dashboard, with the quota pooled across every key the organization mints. Added a dedicated pricing page.
Rebuilt the customer dashboard with dedicated sections for overview, projects & keys, usage, members, billing, activity and account settings, plus email invites for teammates and a usage history chart.
Full webhook management in the dashboard: create, edit, enable/disable, rotate the signing secret, send a test delivery, and redeliver any past delivery, each with its own delivery log.
The MCP get_usage tool now returns the exact same shape as GET /api/v1/usage; otpbox-sdk bumped to 0.2.0.
Inbox and batch creation now honor a custom ttlHours end to end; the test-identity REST routes enforce the same key scopes as their MCP equivalents; MCP webhook registration accepts the two usage-threshold events.
Added email and webhook notifications when an organization's usage crosses 80% or 100% of its monthly quota, and when a subscription is activated, renewed, goes past due, or is canceled.
Lost a Premium key? It can now be recovered by email instead of losing access for good.
Premium (ad-free temporary inbox) checkout went live in production.
Fixed a caching bug where a browser that had installed the PWA could get stuck showing a stale, broken copy of the app after a deploy.
The refund policy now states an explicit 30-day refund window, published in all 5 supported languages.
Clarified data retention: an inbox's messages are kept for 30 days after expiry purely for abuse prevention, then permanently deleted — the privacy policy and terms were corrected to state this plainly.
The enterprise "talk to us" form now also collects a phone number, so sales follow-up doesn't depend on email alone.
otpbox-sdk releases now publish to npm via Trusted Publishing (OIDC) instead of a stored token, for a more secure release pipeline.
Webhooks now cover the full inbox and identity lifecycle — inbox.created, inbox.deleted, inbox.expired, identity.created, identity.deleted — plus link.detected, not just new messages.
otpbox-sdk, the first-party TypeScript SDK, published to npm.
Repositioned the homepage to lead with AI-testing-agent use cases (the developer API and MCP server) alongside the existing free temp-mail inbox.
Added a live "try it now" console to the docs, more CI/CD integration guides (GitHub Actions, GitLab CI, Jenkins, CircleCI), a public status page, and an enterprise contact form.
Added idempotency keys for safe retries, sandbox test-mode keys for deterministic CI runs (no real mail delivery needed), usage-threshold webhooks, and MCP rate limiting.
Added batch outcome states, automatic link classification (verification / password-reset / magic-login / unsubscribe / tracking / general), and scoped API keys.
Released otpbox-playwright, a first-party Playwright fixture that creates an inbox, waits for the OTP or verification link, and cleans up automatically.
Added synthetic test identities — a realistic name, email and profile backed by a real inbox — for signup flows that need a believable persona rather than a bare address.
Added a dashboard UI for batches and webhooks, and per-tool MCP call metrics.
Released otpbox-sdk, the first-party TypeScript SDK, wrapping the REST API in a typed client.
Added REST parity routes: DELETE /api/v1/inboxes/:id and GET /api/v1/usage.
Shipped the batch-creation API, webhooks, and the first MCP tools on the backend.
Launched organizations — accounts, membership and roles — so a team can share projects and API keys instead of everyone holding a separate personal key.
Added projects and org-scoped API keys.
Improved OTP extraction to catch bare codes with no surrounding keyword like "code" or "OTP".
Removed the CAPTCHA step from minting a free API key — the monthly quota is the abuse control instead.
Launched the OTPBox MCP server, exposing the API as agent-callable tools for Claude, Cursor and other MCP clients.
Fixed two mobile UX bugs: a truncated inbox address and a dead-looking empty state.
Translated the privacy policy and terms of service into Spanish, Portuguese, French and German.