$ CHANGELOG
Track every update to the SDK and platform. New features, bug fixes, and improvements -- all in one place. Auto-generated from GitHub Releases.
Added
- Fix weekly release version bump: base on package.json, skip existing tags
- Remove scheduled sync from public repo workflow
- add homepage evidence flow diagram (#106)
- Merge pull request #101 from vinay-lgtm-code/vinay-lgtm-code/feature-sections
- Merge branch 'vinay-lgtm-code/feature-sections' of https://github.com/vinay-lgtm-code/kontext_verify into vinay-lgtm-code/feature-sections
- add Compliance Officer Time section to homepage (#96)
- code cleanup & reinforcement — 11 features, 6 migrations, 1201 tests
- add enforcement modes, GDPR PII vault, and AI narrator sections (#94)
- add enforcement modes, GDPR PII vault, and AI narrator sections
- evidence-first website messaging + sample packet PDF (#91)
- Merge pull request #90 from vinay-lgtm-code/vinay-lgtm-code/fix-vercel-workflow-root
- Merge pull request #89 from vinay-lgtm-code/vinay-lgtm-code/add-vercel-analytics
- add vercel analytics to web app
- Merge pull request #88 from vinay-lgtm-code/vinay-lgtm-code/update-governance-headline
- Merge pull request #87 from vinay-lgtm-code/vinay-lgtm-code/update-hero-headline
- Merge pull request #85 from vinay-lgtm-code/vinay-lgtm-code/compliance-first-site-reposition
- reposition website for compliance-first buyers
- Merge pull request #84 from vinay-lgtm-code/vinay-lgtm-code/fix-ci-lint
- Merge pull request #83 from vinay-lgtm-code/vinay-lgtm-code/website-fixes
- Merge pull request #82 from vinay-lgtm-code/vinay-lgtm-code/fix-ci-lint
- Merge pull request #81 from vinay-lgtm-code/vinay-lgtm-code/circle-integration-audit
- add x402 payment protocol, implement circle-compliance/cctp/x402 integrations, rename tiers to startup/growth/enterprise
- Merge pull request #80 from vinay-lgtm-code/vinay-lgtm-code/fix-stripe-tests
- Merge pull request #79 from vinay-lgtm-code/vinay-lgtm-code/fix-ofac-sync-cli
- Merge pull request #78 from vinay-lgtm-code/vinay-lgtm-code/website-fixes
- add Why Kontext section to homepage
- Merge pull request #77 from vinay-lgtm-code/vinay-lgtm-code/website-fixes
- rebuild assessment into payment review readiness simulator
- Merge pull request #76 from vinay-lgtm-code/vinay-lgtm-code/weekly-release-cicd
- weekly release CI/CD for npm, PyPI, CLI + website changelog
- Merge pull request #75 from vinay-lgtm-code/vinay-lgtm-code/fix-daily-release-ci
- Merge pull request #74 from vinay-lgtm-code/vinay-lgtm-code/website-fixes
- website overhaul + AI agent secondary focus
- Merge pull request #73 from vinay-lgtm-code/vinay-lgtm-code/evaluate-site-value
- Merge pull request #72 from vinay-lgtm-code/vinay-lgtm-code/evaluate-site-value
- Merge pull request #71 from vinay-lgtm-code/vinay-lgtm-code/evaluate-site-value
- Merge pull request #70 from vinay-lgtm-code/vinay-lgtm-code/evaluate-site-value
- L-R question flow, results polish, and email share
- Merge pull request #69 from vinay-lgtm-code/vinay-lgtm-code/evaluate-site-value
- Merge pull request #68 from vinay-lgtm-code/vinay-lgtm-code/evaluate-site-value
- switch assessment AI summary to Vertex AI (GCP)
- Merge pull request #67 from vinay-lgtm-code/vinay-lgtm-code/evaluate-site-value
- add Payment Evidence Gap Assessment to landing page
- Merge pull request #66 from vinay-lgtm-code/vinay-lgtm-code/bump-v0.13.0
- Merge pull request #65 from vinay-lgtm-code/vinay-lgtm-code/website-vs-sdk-gap-audit
- website-SDK gap audit — intent hashing, SAR/CTR reports, case packets, approval policies
- Merge pull request #64 from vinay-lgtm-code/vinay-lgtm-code/landing-page-rebrand-v1
- Merge pull request #63 from vinay-lgtm-code/vinay-lgtm-code/landing-page-rebrand-v1
- multi-rail integration tabs, remove patent numbers and hero badge
- Merge pull request #62 from vinay-lgtm-code/vinay-lgtm-code/kontext-email-outreach-campaign
- add Vercel cron job for scheduled email sending
- Merge pull request #61 from vinay-lgtm-code/vinay-lgtm-code/landing-page-rebrand-v1
- Merge pull request #60 from vinay-lgtm-code/vinay-lgtm-code/landing-page-rebrand-v1
- rebrand landing page for compliance/risk/audit buyer positioning
- Merge pull request #59 from vinay-lgtm-code/vinay-lgtm-code/oss-removal-analysis
- ACH compliance, multi-rail funding sources, OSS de-emphasis
- Merge pull request #58 from vinay-lgtm-code/vinay-lgtm-code/cookie-popup
- add GDPR cookie consent popup with vanilla-cookieconsent v3
- Merge pull request #57 from vinay-lgtm-code/vinay-lgtm-code/docs-v012-update
- Merge pull request #56 from vinay-lgtm-code/vinay-lgtm-code/docs-v012-update
- Merge pull request #55 from vinay-lgtm-code/vinay-lgtm-code/reserve-logging-section
- Merge pull request #54 from vinay-lgtm-code/vinay-lgtm-code/reserve-logging-section
- add reserve monitoring section to landing page
- Merge pull request #53 from vinay-lgtm-code/vinay-lgtm-code/website-redesign
- website redesign — hero toggle, how-it-works, security reframe, 3 blog posts
- RBAC — admin / staff-dev / staff-risk roles (#52)
- CLI auth, named agents/payments, policy config in init wizard
- reserve reconciliation logging + dashboard demo (v0.12.0)
- Merge pull request #47 from vinay-lgtm-code/vinay-lgtm-code/add-clarity-tracking
- Merge pull request #46 from vinay-lgtm-code/vinay-lgtm-code/add-clarity-tracking
- server v0.11.1 — postgres persistence, multi-rail billing, CI/CD fixes
- Merge pull request #45 from vinay-lgtm-code/vinay-lgtm-code/add-clarity-tracking
- add Microsoft Clarity analytics tracking to marketing site
- Merge pull request #44 from vinay-lgtm-code/fix/remove-duplicate-dashboard
- Merge pull request #43 from vinay-lgtm-code/vinay-lgtm-code/enterprise-pivot-v1
- update hero subtitle to verifiability layer positioning
- remove trust strip panel from landing page
- move founder bio to dedicated /team page, add footer link
- unified payment instrument abstraction — Tokens Are Tokens (#42)
- Merge pull request #41 from vinay-lgtm-code/vinay-lgtm-code/enterprise-pivot-v1
- enterprise landing page with CSS/JS animations, route restructuring
- KontextAnchor Base mainnet deploy + source verification (#40)
- Merge pull request #39 from vinay-lgtm-code/vinay-lgtm-code/casablanca-v1
- Merge pull request #38 from vinay-lgtm-code/vinay-lgtm-code/casablanca-v1
- GCP sanctions screening service, CLI wizard overhaul, BYOK providers
- Merge pull request #37 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- Merge pull request #36 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- Merge pull request #35 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- Merge pull request #34 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- CLI-first onboarding + hybrid viem auto-instrumentation (v0.10.0)
- Merge pull request #33 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- Merge pull request #32 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- bump all packages to v0.9.0 — pluggable sanctions screening
- Merge pull request #31 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- airport flipboard effect on hero currency text
- Merge pull request #30 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- split-view hero — code left, interactive playground right
- Merge pull request #29 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- unified playground — crypto + fiat screening with entity name support (Phase D)
- Merge pull request #28 from vinay-lgtm-code/vinay-lgtm-code/calgary-v2
- website redesign + pluggable sanctions screening architecture (Phases A-C)
- Merge pull request #27 from vinay-lgtm-code/feat/python-client
- add Python thin client wrapping Kontext REST API
- Merge pull request #26 from vinay-lgtm-code/refine-product-plan-v1
- proof-of-compliance reframing, Fira Code font, copy fixes, integrations restructure
- complete Terminal Noir redesign — unified dark aesthetic across all pages (#17)
- add ERC-8021 transaction attribution integration
- agent forensics SDK wiring + website promotion (#15)
- agent provenance, on-chain anchoring, CLI package, and web redesign (#14)
- on-chain digest anchoring + A2A attestation (#13)
- Merge pull request #11 from vinay-lgtm-code/vinay-lgtm-code/minsk-v1
- extract CLI into standalone @kontext-sdk/cli package
- Add KYA module, Treasury SDN provider, screening notifications, and FAQ updates
- Remove BlocklistManager from open-source main branch
- Add custom blocklist/allowlist to Pro tier on pricing page and FAQs
Fixed
- PIIVault constructor + ApprovalService rename (deploy fixes)
- pass pool to PIIVault constructor (fixes server crash)
- rename ApprovalChain to ApprovalService (fixes deploy)
- regenerate lockfile for @opentelemetry/api in sdk (#97)
- revert hero headline to "The governance layer for programmable payments" (#92)
- remove duplicate Vercel working directory
- update homepage governance headline
- update homepage hero headline
- update feature-flag component plan types from free/pro to startup/growth
- update feature list copy in JSON-LD structured data
- add missing gitignored integration files and remove unused imports
- align stripe tests with current startup plan config
- use correct CLI package path in OFAC sync workflow
- create missing webhooks.ts and add typecheck to CI
- update Resend sender to send.getkontext.com
- update Resend sender to getlegaci.com domain
- switch assessment email share from Gmail OAuth to Resend API
- resolve Vertex AI SDK type error and credential loading
- replace per-character flip with whole-word slide to prevent clipping
- resolve merge conflicts with main (framer-motion + googleapis)
- logo strip — use explicit white fill instead of currentColor
- consistent logo strip branding — all 6 logos as uniform SVGs
- add Microsoft Clarity to static HTML pages
- enterprise form — use native Web3Forms submit with redirect (#48)
- remove duplicate dashboard routes causing Vercel build failure
- correct ERC-8021 suffix marker and byte order to match spec (#16)
- use workspace:* for kontext-sdk dependency
- remove duplicate keyword and fix JSON in sdk package.json
- prevent checkout credential override on sync-public push (#12)
- explicitly disable npm provenance in release workflow (#10)
- drop --provenance from npm publish (#9)
- skip CodeQL on public repo (no Advanced Security license) (#7)
- add actions:read to CodeQL + repo guards (#6)
- skip private-repo workflows when running on public repo (#5)
- handle diverged histories in sync-public workflow (#4)
- server and SDK builds for free-tier CI (#2)
- unblock CI pipeline and enable public repo sync (#1)
Changed
- add Reserve Reconciliation, Screening Providers, Payment Compliance sections
- add v0.11.1 changelog entry
- update FAQs and Docs with trust layer positioning
- rewrite READMEs — trust layer positioning, CLI-first onboarding
- add auto-instrumentation section to docs, update to v0.10.0
- add Python client documentation and fix CLI version
Added
- **Intent hashing**: `IntentContext` type and SHA-256 intent hash computation in `verify()`. Binds payment purpose, scope, and limits to a cryptographic hash stored in the transaction record.
- **SAR report templates**: `generateSARReport()` — FinCEN Form 111-aligned suspicious activity report with auto-generated narrative from anomaly data and digest proof.
- **CTR report templates**: `generateCTRReport()` — FinCEN Form 112-aligned currency transaction report with $10K threshold detection and daily aggregation for structuring analysis.
- **Case packet export**: `exportCasePacket(txId)` — per-transaction evidence bundle with transaction record, reasoning entries, anomalies, trust score, related tasks, and digest proof.
- **Approval policies**: `setApprovalPolicies()` — configurable multi-trigger approval evaluation (`amount-threshold`, `low-trust-score`, `anomaly-detected`, `new-destination`) with `require-approval`, `block`, or `flag` actions.
- **Evidence retention**: `retention.days` config option and `KontextStore.cleanup(retentionDays)` for TTL-based record eviction.
- **Webhook lifecycle events**: `WebhookManager` now emits `task.created`, `task.confirmed`, and anomaly events automatically.
- **RBAC display names**: Human-readable role labels (`Administrator`, `Platform Engineering`, `Compliance & Risk`).
Fixed
- Website pricing page code snippet now uses actual `VerifyResult` shape (`compliant`, `checks`, `riskLevel`) instead of non-existent `decision`/`auditBundleId`.
- Website SDK tab code snippet now uses actual `VerifyInput` fields (`token`, `agentId`, `paymentMethod`, `paymentReference`) instead of non-existent `rail`/`initiator`/`fundingSource`/`txRef`.
- Removed SEPA from command center subtitle (no SEPA module exists).
Added
- **Reserve reconciliation logging**: `logReserveSnapshot()` queries on-chain `totalSupply()` via raw JSON-RPC and logs a tamper-evident snapshot (supply, block number, block hash) into the digest chain
- `ReserveReconciler` static utility class for on-chain supply verification — zero dependencies, same pattern as `UsdcCompliance`
- `verify()` integration: optional `reserveSnapshot` flag auto-captures stablecoin supply alongside every payment
- Tolerance alerting: `reserveDiscrepancy` anomaly fires on `onAnomaly()` callbacks when supply/reserve delta exceeds threshold
- `generateComplianceCertificate()` now includes a `reserveReconciliation` section summarizing snapshot history, discrepancy count, and latest status
- Dashboard "Reserve State at Time of Payment" evidence drawer panel — LED indicator, block hash proof, delta display
- CLI `kontext reconcile` command — queries on-chain supply and prints human-readable reconciliation output
- Python client `log_reserve_snapshot()` (sync + async) and `ReserveSnapshot` Pydantic model
- Landing page "Reserve reconciliation" section with code example and live evidence card
- All 8 chains available from day one — no plan gate, no cumulative spend requirement
Changed
- `AnomalyRuleType` union extended with `'reserveDiscrepancy'`
- `AnomalyDetector` gains public `reportAnomaly()` method for integration-driven anomaly events
Added
- PostgreSQL persistence with migration runner (auto-runs on startup)
- Multi-rail billing: Stripe (fiat), Circle Programmable Wallets (USDC/EURC/USDT), direct Base wallet transfers
- Subscriptions and API key management tables (migration 004)
- Billing status endpoint (`GET /v1/billing/status`)
- Circle/Base wallet payment verification endpoint (`POST /v1/billing/verify-payment`)
- Server version centralized in `version.ts` (single source of truth)
- Startup banner shows storage mode (PostgreSQL vs In-memory)
- Cloud SQL instance attachment in CI/CD deploy pipeline
- GCP Cloud Monitoring uptime check and alerting
Changed
- Pricing updated: Pro ($449/mo) → Startup ($2,000/mo, invite-only)
- Server version bumped to 0.11.1
- npm publish auth fixed in release workflow (was deleting auth token)
- `pg` added to tsup externals for proper bundling
Added
- Wallet provider configuration for Circle Programmable Wallets, Coinbase Developer Platform (CDP), and MetaMask Embedded Wallets
- `CircleWalletManager`, `CoinbaseWalletManager`, `MetaMaskWalletManager` classes (enterprise-gated)
- CLI wizard prompts for wallet provider setup with API key scope guidance, credential validation, and secrets storage (`.env`, GCP Secret Manager, AWS Secrets Manager, HashiCorp Vault)
- Plan gating for `coinbase-wallets` and `metamask-wallets` features
Added
- CLI-first onboarding via `npx kontext init` interactive wizard
- `kontext.config.json` configuration file for zero-arg `Kontext.init()`
- Hybrid viem auto-instrumentation: `withKontextCompliance()` wraps `sendTransaction`/`writeContract`
- On-chain wallet monitoring via `WalletMonitor` for ERC-20 Transfer events
- `ConfigLoader` for walking directory tree to find config files
Changed
- README rewritten with trust layer positioning and CLI-first onboarding flow
Added
- Pluggable sanctions screening architecture with `ScreeningProvider` interface
- `ScreeningAggregator` for multi-provider consensus screening
- `OFACAddressProvider` (built-in, free), `OpenSanctionsProvider`, `ChainalysisFreeAPIProvider`
- `TreasurySDNProvider` for Treasury SDN list sync
- `ScreeningNotificationManager` for webhook/SMTP alerts on flagged addresses
- Website redesign: split-view hero, interactive playground, airport flipboard currency effect
Added
- ERC-8021 transaction attribution integration for builder identification
- Agent forensics SDK wiring: identity registry, wallet clustering, behavioral fingerprint, cross-session linker, confidence scorer
- Terminal Noir website redesign with unified dark aesthetic
Added
- On-chain digest anchoring on Base via `anchorDigest()`, `verifyAnchor()`, `getAnchor()`
- `KontextAnchor` Solidity contract deployed to Base Sepolia
- `OnChainExporter` for automatic digest anchoring at batch boundaries
- A2A compliance attestation exchange via `exchangeAttestation()`
- Agent provenance with delegated sessions and checkpoints
- CLI extracted into standalone `@kontext-sdk/cli` package
- Python thin client wrapping Kontext REST API
Added
- KYA module: agent identity registry, wallet clustering, behavioral fingerprint, cross-session linking, confidence scoring (enterprise-gated, feature-flagged)
- `TreasurySDNProvider` for built-in OFAC SDN screening
- Screening notification manager for compliance alerts
Fixed
- CI pipeline fixes: public repo sync, server/SDK builds for free-tier CI, TypeScript alignment
Added
- Standalone `@kontext-sdk/cli` package with `check`, `verify`, `reason`, `cert`, `audit`, `sync`, `mcp` commands
- MCP server exposing compliance tools for AI coding assistants (Claude Code, Cursor, Windsurf)
- Custom blocklist/allowlist manager (pro-gated)
Fixed
- CI/CD: npm provenance, CodeQL workflow, sync-public credential handling
Added
- `verify()` convenience method: logs a transaction and runs USDC compliance checks in one call, returning a `VerifyResult` with compliance status, risk level, checks, recommendations, and the logged `TransactionRecord`
- `VerifyInput` and `VerifyResult` types exported from the SDK
Changed
- Phase 1 cleanup: removed all Milestone 2–4 source files from git tracking (trust scoring, anomaly detection, SAR/CTR reports, compliance certificates, agent reasoning, approval manager, KYA module, CCTP, Circle Wallets, Circle Compliance, Gas Station, CFTC, screening aggregator/providers, Vercel AI integration, webhooks). All removed code is preserved locally and excluded from the TypeScript compile and test runs.
- Removed `HttpExporter`, `KontextCloudExporter`, and `MultiExporter` from the public SDK surface (Phase 2)
- Removed `sar` and `ctr` from `ReportType`; removed approval-related types from `KontextConfig`
- Updated `tsconfig.json` to explicitly exclude non-Phase-1 source paths from compilation
Removed
- Non-Phase-1 exports: KYA, CCTP, Circle Wallets/Compliance, Gas Station, CFTC, Webhooks, Vercel AI integration, screening providers, approval manager, Http/Cloud/Multi exporters, trust scoring types, anomaly config types, reasoning types, certificate types, approval types
Added
- Gate BlocklistManager behind Pro plan (not available on free tier)
Added
- Fix approval.ts index signature TypeScript errors blocking CI build
- Update website copy and plan gating for unified screening
- Add unified screening provider architecture with 4 pluggable providers
- Fix payment-flows.md inaccuracies and add 96 tests for full coverage
- Move Changelog from header nav to footer Product section
- Document all payment flows and add plan gating integration tests
- Add ApprovalManager for human-in-the-loop action approval
- Fix changelog: prebuild script fetches CHANGELOG.md from GitHub
- Fix changelog on Vercel: fetch CHANGELOG.md from GitHub at build time
- log changelog path resolution on Vercel
- Fix changelog: inject content via env var at config time
- Fix changelog on Vercel: set outputFileTracingRoot to monorepo root
- Fix changelog page on Vercel: copy CHANGELOG.md at build time
- Add plan gating to SDK and align marketing copy with actual features
Changed
- Switched npm publish to trusted publishing via GitHub Actions OIDC (no tokens needed)
Fixed
- TypeScript strict mode errors in OFAC sanctions DTS build
- pnpm lockfile sync and demo workspace reference
- Release workflow: pnpm version conflict, gitignored file handling
Added
- Full-stack feature flag system with Firestore backend, plan-aware targeting (Free/Pro/Enterprise), and stale-while-revalidate caching across SDK, server, and website
- `FeatureFlagManager` class in SDK for synchronous `isEnabled()` checks
- `<FeatureFlag>` React server component for conditional rendering
- `GET /v1/flags` and `GET /v1/flags/:name` API endpoints
- `requireFlag()` middleware for gating server routes behind feature flags
- CI/CD pipelines: test/build on push, Cloud Run deploy, Vercel deploy
- Renovate for automated dependency management
- Changelog tracking (public + internal)
Fixed
- Stripe test mock using arrow function instead of constructor function
Added
- Pluggable `EventExporter` interface with 6 built-in implementations (Noop, Console, JsonFile, HTTP, KontextCloud, Multi)
- CFTC 26-05 compliance module for FCM digital asset margin requirements
- Per-user pricing: $449/seat/mo with per-seat event limits
- Stripe Checkout integration with subscription billing
- Comprehensive OFAC sanctions screening with SDN list support
- Circle Programmable Wallets integration
- Circle Compliance Engine integration
- Gas Station sponsorship manager
- CCTP V2 cross-chain transfer support with hooks
- Vercel AI SDK middleware integration
- Webhook manager with retry logic
- Agent reasoning and compliance certificates
- Tamper-evident digest chain with SHA-256 rolling hashes
- Trust scoring and anomaly detection
Changed
- SDK now uses plan-based event metering (Free: 20K, Pro: 100K/seat, Enterprise: unlimited)
Added
- Initial SDK release with action logging, task confirmation, and audit export
- Support for Ethereum, Base, Polygon, Arbitrum, Optimism, Avalanche, Solana
- USDC compliance checks
- JSON and CSV export formats
- Local and cloud operating modes