Developers · changelog
Versions, honestly dated
OMP v0.5.2 · platform sprints 12–14
June 2026- All 19 denial codes implemented — new: MD-103 (unsupported_vct), MD-305 (frequency_limit), MD-306 (geo + time_window), MD-503 (minVerificationLevel).
- API keys (mk_test_/mk_live_) mandatory on every verifier endpoint; the sandbox stays keyless.
- Rate limits per key with X-RateLimit headers; 429 with a reset time.
- Evidence export: integrity root, signed receipt, 24 h download, timestamp path.
- OAuth/RAR bridge: mandate-bound access tokens (RFC 9396) + live introspection (RFC 7662) — revocation voids tokens immediately.
- Correction: escalation is checked BEFORE the limit reservation; step-up approvals are single-use.
Platform sprints 7–11
June 2026- Supabase schema (006) with the evidence chain guard: append-only by trigger, 16 database validations.
- Auth: magic link, Google OAuth, enterprise SSO, TOTP 2FA with an AAL2 gate.
- Account lifecycle: GDPR export (Art. 20), deletion with anonymisation (the evidence chain remains).
- Automation: daily expiry sweep, mandate.expiring, limit.threshold at 80%.
- MCP server with 5 tools — the full lifecycle verified over stdio.
OMP v0.5 · platform sprints 1–6
June 2026- Verify engine with a deterministic check order, atomic limit reservation, timing-safe signatures.
- Issuance wizard (6 steps), kill switch, escalation flow end to end (600 s), four-eyes signing by database trigger.
- Evidence log (hash chain), webhooks (HMAC, retries, DLQ), verifier workspace with a rule editor.
- SEO foundation: action, glossary, and comparison clusters, llms.txt.