<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>OTPBox Changelog</title>
  <subtitle>Product updates and releases for OTPBox: disposable inboxes and OTP/verification-link extraction for test automation and AI agents.</subtitle>
  <link href="https://otpbox.io/changelog.xml" rel="self" type="application/atom+xml" />
  <link href="https://otpbox.io/changelog" rel="alternate" type="text/html" />
  <id>https://otpbox.io/changelog</id>
  <updated>2026-09-29T00:00:00Z</updated>

  <entry>
    <title>Status page: real uptime percentiles and an incidents list</title>
    <link href="https://otpbox.io/changelog#2026-09-29" />
    <id>https://otpbox.io/changelog#2026-09-29</id>
    <updated>2026-09-29T00:00:00Z</updated>
    <content type="html">The status page now tracks real uptime percentiles (24h / 7d / 30d / 90d) with response-time history and a recent-incidents list, instead of a fixed "all systems operational" badge.</content>
  </entry>

  <entry>
    <title>Organizations, pooled Pro plans, dashboard rebuild, and webhook management</title>
    <link href="https://otpbox.io/changelog#2026-09-28" />
    <id>https://otpbox.io/changelog#2026-09-28</id>
    <updated>2026-09-28T00:00:00Z</updated>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Organizations can subscribe to Pro ($9/month, 5,000 requests/month pooled across every key) from the dashboard; new pricing page at /pricing.&lt;/li&gt;
&lt;li&gt;Rebuilt customer dashboard: overview, projects &amp;amp; keys, usage, members, billing, activity, account settings, email invites, usage history charts.&lt;/li&gt;
&lt;li&gt;Full webhook management: create/edit/enable/disable/rotate secret/send test/redeliver, with a per-delivery log.&lt;/li&gt;
&lt;li&gt;MCP get_usage now matches REST GET /api/v1/usage; otpbox-sdk bumped to 0.2.0.&lt;/li&gt;
&lt;li&gt;ttlHours honoured on inbox/batch/identity creation; identity REST routes scope-gated; MCP webhooks accept usage.approaching/usage.exceeded.&lt;/li&gt;
&lt;li&gt;Usage-threshold (80%/100%) and billing lifecycle email/webhook notifications.&lt;/li&gt;
&lt;li&gt;Lost Premium keys can be recovered by email.&lt;/li&gt;
&lt;li&gt;Premium checkout live in production.&lt;/li&gt;
&lt;li&gt;Fixed a stale-PWA caching bug after deploys.&lt;/li&gt;
&lt;li&gt;Refund policy states an explicit 30-day window, in all 5 languages.&lt;/li&gt;
&lt;li&gt;Data retention clarified: message content kept 30 days after expiry for abuse prevention, then deleted permanently; privacy policy and terms updated to match.&lt;/li&gt;
&lt;/ul&gt;</content>
  </entry>

  <entry>
    <title>Phone field on the enterprise form; npm Trusted Publishing for otpbox-sdk</title>
    <link href="https://otpbox.io/changelog#2026-09-27" />
    <id>https://otpbox.io/changelog#2026-09-27</id>
    <updated>2026-09-27T00:00:00Z</updated>
    <content type="html">&lt;ul&gt;
&lt;li&gt;The enterprise contact form now also collects a phone number.&lt;/li&gt;
&lt;li&gt;otpbox-sdk releases now publish to npm via Trusted Publishing (OIDC) instead of a stored token.&lt;/li&gt;
&lt;/ul&gt;</content>
  </entry>

  <entry>
    <title>Full webhook lifecycle coverage; otpbox-sdk published to npm</title>
    <link href="https://otpbox.io/changelog#2026-09-26" />
    <id>https://otpbox.io/changelog#2026-09-26</id>
    <updated>2026-09-26T00:00:00Z</updated>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Webhooks now cover inbox.created/deleted/expired, identity.created/deleted, and link.detected - not just new messages.&lt;/li&gt;
&lt;li&gt;otpbox-sdk, the first-party TypeScript SDK, published to npm.&lt;/li&gt;
&lt;li&gt;Homepage repositioned to lead with AI-testing-agent use cases alongside free temp mail.&lt;/li&gt;
&lt;/ul&gt;</content>
  </entry>

  <entry>
    <title>MCP server, otpbox-sdk, otpbox-playwright, test identities, batches, webhooks, organizations</title>
    <link href="https://otpbox.io/changelog#2026-09-25" />
    <id>https://otpbox.io/changelog#2026-09-25</id>
    <updated>2026-09-25T00:00:00Z</updated>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Added a live "try it now" console to the docs, more CI/CD guides (GitHub Actions, GitLab CI, Jenkins, CircleCI), a public status page, and an enterprise contact form.&lt;/li&gt;
&lt;li&gt;Added idempotency keys, sandbox test-mode keys, usage-threshold webhooks, and MCP rate limiting.&lt;/li&gt;
&lt;li&gt;Added batch outcome states, automatic link classification, and scoped API keys.&lt;/li&gt;
&lt;li&gt;Released otpbox-playwright, a first-party Playwright fixture.&lt;/li&gt;
&lt;li&gt;Added synthetic test identities backed by a real inbox.&lt;/li&gt;
&lt;li&gt;Added a dashboard UI for batches and webhooks, and per-tool MCP call metrics.&lt;/li&gt;
&lt;li&gt;Released otpbox-sdk, the first-party TypeScript SDK.&lt;/li&gt;
&lt;li&gt;Added REST parity: DELETE /api/v1/inboxes/:id and GET /api/v1/usage.&lt;/li&gt;
&lt;li&gt;Shipped the batch API, webhooks, and the first MCP tools.&lt;/li&gt;
&lt;li&gt;Launched organizations: accounts, membership and roles.&lt;/li&gt;
&lt;li&gt;Added projects and org-scoped API keys.&lt;/li&gt;
&lt;li&gt;Improved OTP extraction to catch bare codes with no surrounding keyword.&lt;/li&gt;
&lt;li&gt;Removed the CAPTCHA step from minting a free API key.&lt;/li&gt;
&lt;li&gt;Launched the OTPBox MCP server for Claude, Cursor and other MCP clients.&lt;/li&gt;
&lt;li&gt;Fixed two mobile UX bugs.&lt;/li&gt;
&lt;li&gt;Translated the privacy policy and terms of service into Spanish, Portuguese, French and German.&lt;/li&gt;
&lt;/ul&gt;</content>
  </entry>
</feed>
