Skip to main content
Security

2 minute read

Recovery codes, confirmed alerts, and a key policy the verifier follows

Accounts with two-factor authentication can make single-use recovery codes, profile alerts start only after the address confirms, the shared webhook key signs nothing from September 29, and a compromised signing key is treated as compromised whatever time a receipt carries.

What changed

An account with two-factor authentication on can make ten recovery codes from Settings, Security, after entering a current authenticator code. Each signs you in once in place of the authenticator; making a new set stops the old ones; Trooth keeps only a keyed hash of each, and emails the account when a set is made or a code is used. Subscribing to a company's changes now sends a confirmation email first, and nothing else is sent until the link in it is followed; a webhook given there must answer a challenge before it is stored. Before moving the webhook dates, Trooth read every alert destination in production: none was a webhook or chat destination. So the shared signing key stopped signing on September 29 instead of October 5, and webhooks that have not proven ownership stop receiving the same day. The page for checking a receipt against its key now follows the key policy published with the keys: a key marked compromised, or revoked with no recorded reason, is not to be relied on for any signature, because a receipt's time is asserted by Trooth when it signs. The key list records when it first published each key from now on, and carries a list of retired and compromised keys. The older api.trooth.co/public/trust route gives one answer for a company's slug and its domain, and the developer documentation now leads with the supported lookup. A Stripe secret key is refused before it is stored.

Why it changed

The audit of September 28, 2026 found no recovery path for a lost authenticator, a subscription that mailed any address without its consent, a shared-key window left open, and a verification page that disagreed with the published key policy.

Who is affected

  • Affected: Account holders using two-factor authentication, anyone subscribing to a company's changes, webhook receivers, and anyone checking a Trooth receipt against its key.
  • Availability: Recovery codes: any account with two-factor authentication on. The rest: public.
  • Release stage: Available.
  • Areas: Company workspace, Webhooks, Platform.

What to do

No action required. Nothing is required. If you use two-factor authentication, making a set of recovery codes in Settings, Security, and keeping them somewhere safe, is worth doing.

Dates

  • Announced: September 28, 2026, the day this entry was written. Entries are never backdated.
  • Released: September 28, 2026.
  • Shared webhook key stops signing: September 29, 2026.

What this does not fix

Recovery codes are covered by route and unit tests, not yet by a browser test of sign-in. When a key's activation was never recorded, it stays unknown.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSCompany workspace onlyNeeds action

View as agent