What changed
What changed, 1 October 2026
Admin
A blog manager role, and the operator's screens behind their own gate.
AI assistants and search engines
Llms.txt, the docs as text, an IndexNow key.
Auth
Decide where a sign-in lands by resolving it, not by its prefix.
Where a sign-in lands has to be a path on this site.
Blog
A post names the ones out before and after it.
Import posts from a spreadsheet.
Act on many posts at once, and a schedule never unpublishes.
A post cannot take an address the blog's own pages use.
Posts, the image library, scheduling and the public API.
A blog manager role, and the cleaner every post goes through.
Authors in the sitemap, and each list dated by its newest post.
Previous and next under each post, and related posts called that.
The import screen.
A content security policy for the blog and changelog, report-only.
The newest posts on the home page, and a page's own on each tool.
The link dialog finds our own posts and pages.
The posts list filters, pages and acts on many at once.
The blog manager's screens -- posts, the editor, images, calendar.
The public blog at /blog.
Changelog
Drafted from each deploy, public once a person approves it.
The public page at /changelog.
The approval screens.
Consent
A stale factor, and one person in two workspaces.
A lapsed session signs in again, and a new account comes back.
A page that connects an app, and copy that no longer says "local".
The banner reads the cookies without setting state in an effect.
Ask where the law says to, and remember where a visit came from.
Copy
The MCP server offers seventeen tools, not sixteen.
Crawl
A wall answering the not-found probe is not learned as the not-found page.
Destinations
A one-off crawl or scrape writes where it names.
Legal
The policy says what the site actually does.
Newsletter
The list, with double opt-in.
The subscribers screen.
The sign-up, and the pages its emails open.
OAuth
An idle TTL of zero or less keeps the month; the doc says what revoke ends.
A key appears when the app connects, and the log says what happened.
Revoking the key in Settings ends the connection, and the deploy works.
One approval, one ordinary API key.
OAuth and scrape follow-ups
Polling reports the destination, keys record use.
Playground
An extraction may name a destination too.
Send the result to a destination, not only to the screen.
Proxy
A file upload passes through as bytes, and the API skips the page gate.
Rate limits
Count the address Cloudflare saw, not the one a client claims.
safeNext
Refuse a path that dot segments turn into another host.
Share cards
Every tool, use case and comparison has its own.
Sign-up
An account remembers where it came from.
Other
Max tier auto, the plan as the ceiling everywhere, and climbs bounded by the credits left.
Sign-in keeps an app's consent link, and CI type-checks with route types.
Max tier auto in the app, its docs, and billing screens that say what the plan allows.
Fix(web): send /signed-out to /login on the public host, not localhost.