Revocable workspace API keys, live outside-in reads on unclaimed profiles, a dispute path for anything Trooth publishes, and /verify.
What changed
Revocable tenant API keys (secret shown once, hash-only storage) now authenticate every /v1 endpoint. Unclaimed Trust Profiles read Transport Layer Security (TLS), security headers, and security.txt live on every view instead of showing placeholders. Anything Trooth publishes can now be disputed at /network/dispute, and /verify collects every independent check in one place. This release also shipped a planning tool built around the 0-100 figure, which was deleted on 2026-09-04 along with the figure itself.
Who is affected
- Affected: Company workspaces using the /v1 endpoints, and readers of unclaimed Trust Profiles.
- Availability: API keys: company workspaces. Everything else: public.
- Release stage: Available.
- Areas: API, Company workspace, Trust Profiles.
What to do
Action not assessed. Recorded before entries stated whether a reader had to act.
Dates
- Announced: July 24, 2026, the day this entry was written. Entries are never backdated.
Corrections and later changes
- Later: The planning tool this release shipped was deleted on 2026-09-04, with the figure it was built around. Read that change.