{"schema":"obelisk-public-changelog-v1","service":"Obelisk","title":"What's new","updatedMonth":"2026-07","servedCommit":"f7906e9ff2c8e92d80d03183694fe35c2d72213b","self":"https://obeliskgate.com/changelog?format=json","human":"https://obeliskgate.com/changelog","entries":[{"id":"mobile-parity-and-isolated-release","releasedMonth":"2026-07","title":"A sturdier mobile experience and safer release path","summary":"Navigation now stays contained at every screen size, public controls meet a 44-pixel touch target, and contact links remain intact behind edge protections. An isolated staging environment proves the exact release before production, while runtime dependency updates are validated and swapped atomically with rollback to the prior service state.","category":"experience","link":{"href":"https://obeliskgate.com/status","label":"See the release posture →"}},{"id":"verifiable-release-history","releasedMonth":"2026-07","title":"Release history you — and your agents — can verify","summary":"What's New now comes from one structured, public-safety-checked source. The same release history is available as JSON, carries stable entry identifiers, and is bound to the revision actually serving it.","category":"transparency","link":{"href":"https://obeliskgate.com/changelog?format=json","label":"Open the release document →"}},{"id":"exact-revision-release-proof","releasedMonth":"2026-07","title":"Every deployment now proves the code it ships","summary":"A production release must now have a successful continuous-integration result for the exact revision being deployed. The release boundary rejects missing, stale, malformed, still-running, or failed proof before it changes production.","category":"assurance","link":{"href":"https://obeliskgate.com/status","label":"See the resilience posture →"}},{"id":"evidence-provenance","releasedMonth":"2026-07","title":"Security evidence now carries its provenance","summary":"Receipts and integrity evidence now distinguish interactive operators, trusted automation, and runtime environments without guessing. That closes a class of reports that looked authoritative while describing the wrong actor or source.","category":"assurance","link":{"href":"https://obeliskgate.com/trust","label":"How verification works →"}},{"id":"weighted-trust-evidence","releasedMonth":"2026-07","title":"Trust scores now respect evidence strength","summary":"Security evidence is now weighted by authority and freshness, so a weak or old signal cannot silently carry the same confidence as a current, direct measurement.","category":"rating","link":{"href":"https://obeliskgate.com/trust","label":"Explore the trust model →"}},{"id":"checks-prove-they-can-fail","releasedMonth":"2026-07","title":"Safety checks now prove they can catch a defect","summary":"Critical checks are tested through the same arguments and wiring used in real operation. A check cannot be reported healthy merely because its underlying detector works in isolation.","category":"assurance","link":{"href":"https://obeliskgate.com/security","label":"Read the security model →"}},{"id":"production-revision-truth","releasedMonth":"2026-07","title":"Production status now follows the revision actually running","summary":"Deployment-currency signals now compare the code serving production with the intended release, rather than treating unrelated repository files as runtime drift.","category":"reliability","link":{"href":"https://obeliskgate.com/status","label":"View status and resilience →"}},{"id":"committed-evidence-plane","releasedMonth":"2026-07","title":"Integrity reports identify the tree they measured","summary":"Repository security evidence now states whether it measured committed code or a working copy. This prevents an uncommitted local change from being mistaken for production evidence.","category":"transparency","link":{"href":"https://obeliskgate.com/security","label":"Review the security posture →"}},{"id":"unknown-is-not-healthy","releasedMonth":"2026-07","title":"Unknown is no longer reported as healthy","summary":"When a dependency or identity provider cannot be measured, Obelisk preserves that result as unknown instead of turning missing evidence into a green status.","category":"transparency","link":{"href":"https://obeliskgate.com/status","label":"See how status is reported →"}},{"id":"website-current","releasedMonth":"2026-07","title":"The website, brought fully current","summary":"Sender-bound tokens are now documented for customers and developers, the API manifest covers federation and verification surfaces, every page carries the brand mark, and connector claims derive from one catalogue.","category":"documentation","link":{"href":"https://obeliskgate.com/api","label":"Explore the API manifest →"}},{"id":"account-control","releasedMonth":"2026-07","title":"Security alerts, API keys and full account control","summary":"Your account now includes a security-alert timeline, scoped expiring API keys for agents, security-habit badges, and a direct account-deletion control.","category":"account","link":{"href":"https://obeliskgate.com/account","label":"Open your account →"}},{"id":"live-website-roster","releasedMonth":"2026-07","title":"Live website roster","summary":"Organization dashboards now show linked websites with live probe-backed status, response latency, and an uptime sparkline rather than a cached availability claim.","category":"organizations"},{"id":"persistent-accessibility","releasedMonth":"2026-07","title":"Theme and accessibility preferences that stick","summary":"Light and dark themes now carry into browser chrome, while higher contrast, reduced motion, larger text, and other accessibility preferences are applied across the product.","category":"experience"},{"id":"account-shield","releasedMonth":"2026-07","title":"Account Shield","summary":"Every account now has a live security score, tier, trend, sign-in streak, and a concrete next action that can improve its posture.","category":"rating"},{"id":"verified-seal","releasedMonth":"2026-06","title":"The verified “Secured by Obelisk Gate” seal","summary":"Protected sites can embed a live seal that reflects their measured security band and links to a public verification page — proof of protection rather than a static badge.","category":"verification","link":{"href":"https://obeliskgate.com/developers/seal","label":"Get the seal →"}},{"id":"saml-identity-provider","releasedMonth":"2026-06","title":"SAML 2.0 identity provider","summary":"Obelisk can issue signed Security Assertion Markup Language assertions to downstream applications, making one passkey-first identity usable across compatible business tools.","category":"federation","link":{"href":"https://obeliskgate.com/docs/saml","label":"Set it up →"}},{"id":"off-box-recovery","releasedMonth":"2026-06","title":"Off-box recovery and a self-healing watchdog","summary":"Encrypted backups are integrity-checked away from the primary service, and the health watchdog can restart an unhealthy process. The documented total-loss recovery objective is about fifteen minutes.","category":"reliability","link":{"href":"https://obeliskgate.com/status","label":"Resilience posture →"}},{"id":"integrations-catalogue","releasedMonth":"2026-06","title":"Integrations catalogue","summary":"A single catalogue now shows where Obelisk can serve as the identity provider over OpenID Connect or Security Assertion Markup Language.","category":"federation","link":{"href":"https://obeliskgate.com/integrations","label":"Browse connectors →"}},{"id":"credential-transparency","releasedMonth":"2026-06","title":"Verify-it-yourself credential transparency","summary":"Session issuance and passkey changes are recorded in a tamper-evident account log, so you can verify that each sign-in and credential change was yours.","category":"transparency"},{"id":"assurance-bound-sessions","releasedMonth":"2026-06","title":"Assurance-bound sessions","summary":"Sessions carry how identity was proven. Passkey-backed sessions can perform sensitive changes; lower-assurance recovery sessions remain restricted.","category":"identity"},{"id":"obelisk-rating","releasedMonth":"2026-05","title":"The Obelisk Rating, 0–100","summary":"A live security score distills measured account or organization signals into one rating with visible coverage and improvement levers.","category":"rating"},{"id":"organizations-and-scan","releasedMonth":"2026-05","title":"Organizations, teams and website scan","summary":"Register an organization, invite role-scoped team members, and measure a public website to produce a security rating with concrete improvement levers.","category":"organizations"},{"id":"one-identity-every-project","releasedMonth":"2026-05","title":"One identity, every project","summary":"A universal Obelisk account now carries cleanly separated per-project profiles, allowing one passkey-first identity to work across the ecosystem.","category":"identity"},{"id":"passkey-first-sign-in","releasedMonth":"2026-04","title":"Passkey-first usernameless sign-in","summary":"One-tap, phishing-resistant sign-in works without typing a username, with controlled recovery paths available when needed.","category":"identity"},{"id":"tamper-evident-receipts","releasedMonth":"2026-04","title":"Tamper-evident receipts","summary":"Consequential identity and authorization actions emit signed, hash-chained receipts so the audit trail cannot be silently rewritten.","category":"assurance"}]}