§ Changelog · release notes

What we shipped.

A running record of the platform work that matters to agent builders and cohort users — newest first.

Each release block lists what changed and why. Releases that ship a new SDK version get their own permalink at /changelog/<slug> with version chips linking to the npm or PyPI page; in-page anchors stay reachable as #r-<date>. Every PR with user- or builder-visible impact lands a Fixed / Added / Changed / Security / Infrastructure entry here — enforced by CI.

Updated


  1. A transitive advisory pinned out of the frontend build

    • Security

      Pinned source-map-js to 1.2.2 through an override. The advisory (GHSA-68fv-2mgg-jv7q, an indexed source-map can stall the event loop) landed against the version Vite pulls in transitively, which turned the CI dependency audit red on commits that were green when they were cut.

  2. Page counts from our own CDN logs

    • Changed

      agentdraft.io's CDN request logs now feed a daily page count to VectraSEO, our SEO analytics service. Raw logs stay in a private bucket for 7 days; only aggregates leave it — path, referring site, browser or crawler name, status category and utm_* tags, with any referrer, country, browser, campaign tag or non-existent page address seen fewer than 3 times a day grouped as "other". No IPs, cookies or other URL parameters are sent, and sign-in, onboarding and dashboard pages are never included. The privacy policy's "Cookies and analytics" and "Sharing" sections describe it.

  3. Opt-in visit analytics on the public site

    • Added

      The marketing site now asks before loading Google Analytics 4. Declining, or sending a Global Privacy Control signal, means the script is never fetched. If you accept, page views record only the path and utm_* tags. GA4 is switched off at the router before any navigation into sign-in, onboarding, or the dashboard, so authenticated pages are never reported. Google signals and ad personalization are off, and "Cookie settings" in the footer changes your choice at any time.

  4. The paragraphs were always there — now the markup says so

    • Fixed

      Nine posts shipped their body copy as bare text between headings. Browsers collapsed the whitespace into readable paragraphs, but anything reading <p> elements — including VectraSEO's answer-structure check — saw only headings and stray citation notes, which is why those posts kept failing the check even after they had a real answer block. Both the API renderer and the static build now wrap top-level text in paragraphs, and the FAQ answers those posts already carried get their <p> too.

    • Fixed

      Dead OWASP links across nine posts now point at the projects' current hosts — top10.owasp.org for the Top 10 and genai.owasp.org for the LLM Top 10 and the prompt-injection entry. The old owasp.org/www-project-* URLs 404 for some crawlers mid-migration. Like the earlier OpenAI fix, the rewrite is applied when a body is rendered, so it also survives a republish from VectraSEO.

    • Fixed

      /docs no longer nominates a .lede element in its speakable JSON-LD. The page has no such element, so the scope resolved to nothing; it now lists the selectors the docs page actually renders.

    • Fixed

      Expired holds stopped blocking the calendar. A hold reserves a slot for 30 seconds, and the conflict engine already lets a new booking take the slot once that window passes — but availability, the A2A availability skill, the dashboard booking list, and the calendar audit kept treating the stale row as live until DynamoDB's lazy TTL cleanup ran, which can take hours. All four readers now check the hold's own TTL before counting it.

  5. Every post now answers its own question

    • Added

      119 blog posts now open with a direct answer block — 40 to 85 words that answer the question the post is titled after, before the post starts explaining it. Eleven posts already had one; the rest opened straight into prose, so an answer engine asking "what is agentic calendar conflict resolution" had to infer an answer from the whole article. Every indexed post now carries one, which is 130 of them.

    • Changed

      The 16 posts held out of the search index deliberately did not get a block, and a test now keeps it that way. The block exists to be extracted — the page nominates .answer-block as its speakable passage — and a noindex page is not going to be extracted, so an entry there is two maps to keep in sync forever in exchange for nothing.

    • Fixed

      /email now redirects to the mailbox docs instead of returning a 404. Posts describing "AgentDraft's Email box for Agents" linked there, but only the /calendar side of that redirect family was ever filled in — so a page ranking in search sent readers to a dead end. /email-box and /email-for-agents are covered too, and a test now fails the build if either family loses an alias or points at a route that no longer exists.

    • Added

      New integration page at /integrations/crewai, plus a worked examples/crewai_quickstart.py — the ~20-line crewai.tools.BaseTool subclass that gives a Crew race-free availability and booking tools over the agentdraft SDK. Google has been probing a CrewAI scheduling slug under eight different URL prefixes for a page that didn't exist, and CrewAI was the one major agent framework without its own page.

    • Fixed

      Corrected a compatibility claim we had been repeating everywhere: **CrewAI cannot consume the agentdraft-langchain tools.** CrewAI validates Agent(tools=…) against its own crewai.tools.BaseTool and raises a Pydantic ValidationError on a langchain_core tool, and Tool.from_langchain() doesn't bridge it either — it requires a callable .func that a hand-written BaseTool subclass doesn't have. Verified against crewai 1.15.20 and langchain-core 1.6.2; the AutoGen half of the same sentence does work and is unchanged. The claim is corrected on every page, in both PyPI READMEs, and in the module docstrings, and a test now fails the build if it comes back.

  6. What the page says when you take the tags off

    • Fixed

      Three headlines were running their words together for anything that reads the page as text. The home page announced itself as "Turn meeting requestsinto bookings.Keep your agentsin sync.", the pilot page as "Move your scheduling agentfrom demo to production.", and pricing as "Pricing should beboring infrastructure." All three looked correct on screen: the line breaks were doing the spacing, and the template compiler had removed the whitespace around them. The site nominates its h1 as the passage answer engines should quote and voice assistants should read aloud, so that was the sentence being handed to them.

    • Changed

      /docs was titled "The AgentDraft protocol specification" — which is /spec's subject, not its own. It is the API reference: quick start, endpoints, error codes, audit log. Two pages claiming the same identity left them competing for the same searches.

    • Changed

      Four page titles said only what section of the site you had landed in. "Blog", "Docs", "Security", and "Pricing" now say what is on the page, which is the only thing a search result has to work with. Pricing's summary also stopped at the $25 plan and omitted Scale, implying $25 was the ceiling for self-serve.

  7. The pages nobody could reach

    • Fixed

      The Enterprise button on /pricing is now a real link. It always went to /pilot, but through a click handler rather than an href — so it couldn't be opened in a new tab, and search engines never saw the edge at all. /pricing is linked from every page on the site, which made this one of the few strong paths to the pilot page; without it, /pilot had two inbound links in total. The four paid plans are unchanged: those buttons start a checkout rather than navigating.

    • Added

      Six pages that could only be reached from an index now have links from the pages that actually discuss them. The webhooks guide links to the payload-debugging and latency deep dives and to the Nightlamp writeup; email-flow monitoring links to that writeup too, having previously named Nightlamp while linking only off-site; the calendar API links to the Alaska Road Trip study; the coordination layer and negotiation pages link to their respective guides.

    • Fixed

      A blog post no longer links to a retired OpenAI documentation page. The URL redirected to a page that 404s, which is easy to miss because the first hop looks healthy. Post bodies are authored upstream and can't be edited through that API, so known-dead outbound links are now repointed as the post is ingested — which also means a republish can't bring the dead link back.

    • Infrastructure

      Deploys now verify that a nonexistent URL returns 404, that the app subdomain redirects the apex's sitemap.xml, rss.xml, changelog.rss, and llms.txt, and that its robots.txt still resolves. These behaviours live in the CDN configuration rather than the site bundle, so no test suite could see them and a regression would only have surfaced in Search Console weeks later.

  8. Dead URLs stop pretending to be the home page

    • Fixed

      A URL that doesn't exist now answers 404. Every missing object used to return 200 with the home page's HTML — its title, its canonical — so any invented path became a live page. Search Console had logged the result as soft 404s, with one slug that was never published crawled under seven different path prefixes (/blog/, /posts/, /articles/, /news/, …), and the apex was advertising an unbounded set of duplicates of itself. Real routes are unaffected: each one is pre-rendered to its own file, so a missing object was already proof the route wasn't real.

    • Fixed

      Blog posts no longer print their own summary twice. The header rendered the lede, then rendered it again as the page's "direct answer" whenever the post had no hand-written one — which was 139 of 146 posts. Because the page's speakable structured data points at that element, every one of those posts was nominating a marketing teaser as the passage answer engines should read aloud. Seven posts covering CRM sync, email threading, calendar conflict resolution, draft management, error handling, and event metadata gained a real answer block instead.

    • Fixed

      app.agentdraft.io stopped serving the apex's sitemap.xml, rss.xml, changelog.rss, and llms.txt. They were byte-identical objects in the same bucket, so Google — whose property covers every subdomain — crawled the whole marketing site a second time under the app host and logged 28 blog URLs as "Page with redirect". They now redirect to the apex.

    • Added

      /pilot carries a visible "Updated" line and a dateModified in its structured data. The highest-intent page on the site had no page-level entity at all, so answer engines had nothing to date it by.

    • Added

      Internal links from /audit to the audit-trail and human-approval deep dives, and from /vs/agentmail to the AgentMail alternatives page. Footer-linked pages carry a link from all 176 URLs; everything else had exactly one. The three pages that earn the site's highest-intent search impressions were all in the second group.

  9. A plan between Team and a sales call

    • Added

      **Scale** — $99/month for 25 users, 25 mailboxes, unlimited agents, and 100,000 bookings a month. Team's five-mailbox ceiling was the first wall most workspaces hit, and the only thing above it was a $5k–$20k annual pilot. Scale is self-serve: upgrade from the billing page, no conversation required. Every metered limit moves with the mailbox count, so you don't clear one ceiling and meet another.

    • Added

      Plans granted outside Stripe can now be locked. A manually set tier used to survive only until the next subscription event carrying that workspace's id — a cancellation reset it to the free tier, a renewal repriced it back to whatever the old subscription was billing for, and both happened silently. A locked plan is refused by the billing webhook at the storage layer, and a failed charge on an unrelated invoice can no longer start a countdown against it.

    • Fixed

      The billing page told free workspaces they had a dedicated CSM and 7-year audit — the plan summary fell through to the Enterprise description for any tier without an explicit case. Each plan now carries its own.

    • Fixed

      The pricing page's structured data caught up with the page itself. Search engines were told the booking allowance stopped at Team's 10,000, and never saw the question explaining what to do after the fifth mailbox — the FAQ is authored once for readers and once for crawlers, and only the first copy had learned about Scale. The two are now checked against each other, and /pricing and /changelog report the date they were actually last edited.

  10. A direct path to production pilots

    • Added

      Teams can request a scoped production pilot without an account, with a saved inquiry, team inbox notification, and clear commercial expectations.

    • Changed

      Homepage and pricing calls to action connect production buyers to pilot scoping and clarify separate booking and mailbox limits.

    • Fixed

      Pilot submissions preserve the submitted contact address, allow retries after stalled requests, and keep form details out of URLs before JavaScript loads.

    • Fixed

      The mobile navigation and booking-conflict walkthrough fit narrow phone screens.

  11. Two priced limits start applying

    • Added

      calendars_per_seat is enforced. Developer and Individual connect 1 calendar, Team 3 per seat, Enterprise unlimited — the numbers that have been on the pricing page all along. Connecting past the cap returns 402 quota_exceeded from every path (Google OAuth, Folio, ICS), and the count is held in a conditional counter committed in the same TransactWriteItems as the connection row, so two concurrent connects can't both slip through. Reconnecting a calendar you already have refreshes its tokens without spending a slot, and disconnecting frees one immediately.

    • Added

      audit_retention_days is enforced. GET /v1/dashboard/audit no longer returns events older than your plan keeps — 7 days on Developer, 30 on Individual, 1 year on Team, 7 years on Enterprise — and reports retention_days so the dashboard can say so instead of looking empty. Audit rows now carry a DynamoDB TTL derived from the tier at write time; upgrading lengthens retention for events written after the upgrade, not before.

    • Changed

      The audit page names your retention window in its header and, when a range filter reaches past it, says which days it is showing and why.

    • Fixed

      The ICS 5-feed limit and the calendar cap are now separate limits with separate messages. The feed limit bounds what one provider can cost us regardless of plan; the calendar cap is the entitlement, and on every plan below Enterprise it binds first.

  12. The homepage stops contradicting the pricing page

    • Fixed

      The homepage said the free Developer tier gives 1 agent. It gives 3, and has since the tier was widened so a free workspace can actually watch two agents collide. /pricing was corrected at the time; the homepage card was missed, so the two pages disagreed about what signing up gets you. Both now read from the same tier table, checked on every build.

    • Fixed

      Multi-agent priority resolution is no longer sold as the Team unlock. It was never gated — every tier runs the same conflict engine, and the free tier's three agents exist specifically so priority resolution can be tried before paying. The claim was removed from /pricing once already; it survived on the homepage and in the dashboard's billing panel, which reported a Multi-agent priority: yes/no line driven by a flag no code ever read. The flag is deleted.

    • Changed

      Tier attributes now have to gate something to exist. A new check fails the build when an entitlement is declared and displayed but never consulted — the exact shape of the defect above — with the two remaining unbacked attributes listed explicitly rather than left to be rediscovered.

    • Changed

      The TypeScript SDK is now npm install agentdraft, matching pip install agentdraft exactly. It shipped as @agentdraftio/sdk because the @agentdraft scope is held by an inactive account — but the unscoped name was free the whole time, and guessing the install command is the first thing anyone tries. The old package stays on npm, deprecated with a pointer to the new one.

    • Fixed

      agentdraft-mcp on PyPI advertised its source, issue tracker, and changelog under github.com/GipsyChef/agentdraft — an org that no longer exists, so all three links 404'd. PyPI release metadata cannot be edited after upload, so this is fixed by releasing 0.1.1. The Python SDK's 0.1.1 shipped with no repository link at all; 0.1.2 adds one.

    • Fixed

      The script that generates the published install commands had a hardcoded @agentdraft/sdk — a package this project does not own — that would have overwritten the correct commands on the next site build. It now reads every package name from the manifest it releases from, so the docs cannot advertise a package that isn't ours.

    • Added

      The MCP server carries a server.json for the official MCP Registry and a smithery.yaml for Smithery, so agentdraft-mcp can be listed where developers shop for agent tooling rather than only found by name on PyPI.

    • Added

      agentdraft-mcp now has a public source repository at ryabinski-labs/agentdraft-mcp. The MCP registry, Smithery, PulseMCP and Glama all resolve a server through a public GitHub repo, and AgentDraft's application repo is private — so the server's directory is published as a mirror. Its Repository link on PyPI now opens, and you can read the code before you install it.

    • Fixed

      Structured data on every page and blog post listed a github.com/ryabinski-labs/agentdraft-engine-reference repository that returns 404, and linked an npm organization page instead of the package. Both are corrected.

  13. Sixteen blog posts step out of the way of the homepage

    • Fixed

      Searching for agentdraft returned a blog post about AI adoption trends, with agentdraft.io itself nowhere on the first page. 125 posts share one domain and the ones written for an executive audience were outranking the product they were meant to sell. Sixteen posts — thirteen written for a buyer rather than a builder, three about capabilities AgentDraft doesn't ship — now carry noindex, follow and are left out of the sitemap. They stay published, stay linked from /blog, and keep passing link equity onward; they just stop competing with the pages a developer is actually looking for.

    • Changed

      The noindex directive can now be follow as well as nofollow, so a page can be withheld from search without also cutting off the links it sends to the rest of the site. Private app routes are unaffected and still emit noindex, nofollow.

Older releases

  1. Analytics stops following you past the marketing site
  2. Blog ingest accepts updates and deletes, not just creates
  3. One redirect path for a stored paid-tier signup
  4. Free tier now representable in the billing client
  5. Free tier can now run multiple agents
  6. Retired marketing URLs now resolve cleanly
  7. Approvals — a human sign-off gate for any agent action
  8. Cookieless marketing analytics goes live
  9. Answer-engine polish and a shorter path to an API key
  10. The blog claim guard checks claims, not keywords
  11. No more dead citation links on the blog
  12. Every published blog post is back in the sitemap
  13. Answer-engine remediation pass
  14. DNSCove authoritative DNS cutover
  15. Blog ingest API returns the real post URL
  16. Free calendar collision audit, right from the comparison pages
  17. Try the API with no signup
  18. Instant API key, plus a code fallback for magic links
  19. A faster path from CTA to API key
  20. Alternatives guides, glossary expansion, and benchmark census
  21. Trust pages, SEO metadata, and production API tuning
  22. Billing correctness and an open-source collision benchmark
  23. A guided setup checklist and a clearer, more accessible dashboard
  24. Send feedback from the dashboard, plus blog & security SEO fixes
  25. Checkout now collects tax and accepts promo codes
  26. Calendar list no longer breaks after disconnecting a feed
  27. Webmail calendar connector is now Folio
  28. Calendar connect surfaces real errors; local dev boots again
  29. Billing webhook resolves the correct plan
  30. Private app routes are easier for crawlers to retire
  31. Google user data disclosures
  32. Launch-readiness proof is easier to audit
  33. Dashboard sessions last through the workday
  34. Publish and webhook setup feedback is clearer
  35. Mailbox webhooks can target one agent
  36. Email-flow monitoring with AgentDraft mailboxes
  37. Block out your vacations
  38. Counter-proposals documented, plus API reference fixes
  39. Webhooks are now documented
  40. Booking notes and the video link now land on the calendar event
  41. The timezone picker is now searchable
  42. Set your timezone — the one that actually gates bookings
  43. SDKs speak title, invitee, and timezone
  44. Scheduling rules are actually enforced
  45. Working hours read in your own timezone
  46. Pricing answers its own questions
  47. Bookings know who they're for
  48. One canonical URL per marketing page
  49. Connected calendars resync themselves
  50. The glossary doubles in size
  51. Integration pages for n8n and the OpenAI Agents SDK
  52. A sharper share card and a more legible masthead
  53. The free Developer tier reaches the homepage
  54. A free Developer tier, a mobile nav, and a clearer homepage
  55. Blog posts published via the ingestion API render cleanly
  56. Recurring ICS events with a non-UTC UNTIL now expand fully
  57. Permanently delete revoked agents
  58. Lowercase-safe agent mailbox routing
  59. Mid-run human consent for high-impact agent actions
  60. Marketing claim audit and pricing copy alignment
  61. Conferencing links, Calendar Audit, ChatGPT App, coordination-layer pillar
  62. Dashboard Webhooks page
  63. P1 differentiation moat — multi-agent negotiation + OSS engine reference
  64. P0 distribution oxygen — A2A protocol, two more /vs pages, Vercel AI + Mastra adapters, Claude skill
  65. Footer composition + Field notes in masthead nav
  66. Launch wave 1 — collision benchmark, vs/temporal-cortex, newsletter capture
  67. SEO landing pages + outbound mail fix
  68. Launch-week polish
  69. Passkeys
  70. A real changelog
  71. Launch readiness — SDKs, packages, and discovery
  72. Calendar connectors, agent key lifecycle, mailbox API
  73. Agent mailboxes, onboarding, dashboard hardening
  74. Production architecture and deploy pipeline
  75. Initial AgentDraft platform

Frequently asked

What gets a changelog entry?

Anything users or agent builders can observe — new endpoints, breaking changes, dashboard UX, fixed bugs, security patches, infrastructure work that touches the public plane. Internal-only refactors and tests opt out with the skip-changelog label. CI fails any other PR that doesn't touch this changelog file.

How do per-release permalinks work?

Releases that ship a new SDK version get a dedicated /changelog/<slug> permalink with a short summary, version chips, and SoftwareApplication JSON-LD. In-page anchors stay reachable at #r-<date> for releases without a permalink — if multiple un-slugged releases share a date, the second and later get a numeric suffix.