Skip to content

Changelog

Gateway

2026-04-29 — Wave 19 + Fortune-500 ops surface

  • Receipt verifier now public (no API key required) at /api/v1/receipts/verify.
  • OpenAPI spec auto-generated on every deploy and served at https://docs.cloakapi.io/openapi.json and .yaml.
  • New documentation surface at docs.cloakapi.io (Astro Starlight).
  • New API reference at docs.cloakapi.io/api-reference/ (Redoc).
  • Internal observability: GlitchTip 4.0.12, OpenObserve, Uptime Kuma.
  • Customer transparency: status page, signed-receipt verifier in browser.
  • OWUI demo wired to the gateway via OIDC. (Demo surface retired 2026-07-25.)

2026-04-15 — Wave 18

  • Stripe webhook handler refactored.
  • Per-org cost cap middleware.
  • Spatie permissions / RBAC roll-out.

2026-03-30 — Wave 16

  • RBAC permission middleware alias rbac.
  • Tenant scope middleware now opts out of payload logging.

SDKs

  • openai-python: any version 1.x — point base_url at https://api.cloakapi.io/api/v1.
  • openai-node: any version 4.x — same.
  • anthropic-sdk-python / anthropic-sdk-typescript: any version — point base_url at https://api.cloakapi.io/api/v1.

Browser extension

  • 0.1.58 (Chrome tip, measured 2026-09-26) — unversioned cloakapi-extension-chrome.zip and versioned cloakapi-extension-chrome-0.1.58.zip are byte-identical (sha256 cc4151794b9235c35c1bcf8ca496252d006b0076502bf242eabcd69b29619a82, both HTTP 200). Superseded versioned zips …-0.1.57.zip and …-0.1.56.zip answer HTTP 410. No Firefox build is served: the unversioned .xpi link answers HTTP 410. Tip version, sha256 and signing status are always the ones on the downloads page and the release-integrity register. The extension has also been on the Chrome Web Store since 2026-09-29.
  • 0.1.31 (Chrome, served build, measured 2026-09-20) — then-current tip; superseded. Historic note only — do not treat as tip. Earlier versioned zips …-0.1.23.zip through …-0.1.30.zip (including 0.1.24) answer HTTP 410.
  • 0.1.24 (Chrome, served 2026-09-09, withdrawn by 2026-09-20) — cloakapi-extension-chrome-0.1.24.zip and the unversioned cloakapi-extension-chrome.zip then shared sha256 197da5c5… (both HTTP 200 on that date). The versioned zip now answers HTTP 410.
  • 0.1.23 (Chrome, served 2026-09-05, withdrawn by 2026-09-09) — cloakapi-extension-chrome-0.1.23.zip, sha256 d4c04176…, an unsigned developer build. The 2026-09-05 measurement stands; the file now answers HTTP 410.
  • Earlier entries on this page described 0.2.x–0.4.x features (partner attribution, Syncthing audit sync, tokenise-and-inspect preview). No served build carries those version numbers; the entries were removed 2026-09-05 rather than left next to the measured version.

Desktop

  • 1.2.6 — current desktop tip on the register and downloads page (Windows setup/MSI/portable + Linux AppImage/deb). See Desktop app. Builds are unsigned; verify SHA-256 before run. Withdrawn 1.0.0 installers answer HTTP 410. Older 1.1.0–1.2.5 packages may still be listed as non-tip archives.