changelog

What changed

What we ship to MeshArc, as it ships: new features, fixes and changes to the API, the app and the crawler.

What changed, 1 October 2026

Admin

  • A blog manager role, and the operator's screens behind their own gate.

AI assistants and search engines

  • Llms.txt, the docs as text, an IndexNow key.

Auth

  • Decide where a sign-in lands by resolving it, not by its prefix.

  • Where a sign-in lands has to be a path on this site.

Blog

  • A post names the ones out before and after it.

  • Import posts from a spreadsheet.

  • Act on many posts at once, and a schedule never unpublishes.

  • A post cannot take an address the blog's own pages use.

  • Posts, the image library, scheduling and the public API.

  • A blog manager role, and the cleaner every post goes through.

  • Authors in the sitemap, and each list dated by its newest post.

  • Previous and next under each post, and related posts called that.

  • The import screen.

  • A content security policy for the blog and changelog, report-only.

  • The newest posts on the home page, and a page's own on each tool.

  • The link dialog finds our own posts and pages.

  • The posts list filters, pages and acts on many at once.

  • The blog manager's screens -- posts, the editor, images, calendar.

  • The public blog at /blog.

Changelog

  • Drafted from each deploy, public once a person approves it.

  • The public page at /changelog.

  • The approval screens.

  • A stale factor, and one person in two workspaces.

  • A lapsed session signs in again, and a new account comes back.

  • A page that connects an app, and copy that no longer says "local".

  • The banner reads the cookies without setting state in an effect.

  • Ask where the law says to, and remember where a visit came from.

Copy

  • The MCP server offers seventeen tools, not sixteen.

Crawl

  • A wall answering the not-found probe is not learned as the not-found page.

Destinations

  • A one-off crawl or scrape writes where it names.

  • The policy says what the site actually does.

Newsletter

  • The list, with double opt-in.

  • The subscribers screen.

  • The sign-up, and the pages its emails open.

OAuth

  • An idle TTL of zero or less keeps the month; the doc says what revoke ends.

  • A key appears when the app connects, and the log says what happened.

  • Revoking the key in Settings ends the connection, and the deploy works.

  • One approval, one ordinary API key.

OAuth and scrape follow-ups

  • Polling reports the destination, keys record use.

Playground

  • An extraction may name a destination too.

  • Send the result to a destination, not only to the screen.

Proxy

  • A file upload passes through as bytes, and the API skips the page gate.

Rate limits

  • Count the address Cloudflare saw, not the one a client claims.

safeNext

  • Refuse a path that dot segments turn into another host.

Share cards

  • Every tool, use case and comparison has its own.

Sign-up

  • An account remembers where it came from.

Other

  • Max tier auto, the plan as the ceiling everywhere, and climbs bounded by the credits left.

  • Sign-in keeps an app's consent link, and CI type-checks with route types.

  • Max tier auto in the app, its docs, and billing screens that say what the plan allows.

  • Fix(web): send /signed-out to /login on the public host, not localhost.

The MeshArc newsletter

New posts and what changed, at most twice a month.