Accounts with two-factor authentication can make single-use recovery codes, profile alerts start only after the address confirms, the shared webhook key signs nothing from September 29, and a compromised signing key is treated as compromised whatever time a receipt carries.
What changed
An account with two-factor authentication on can make ten recovery codes from Settings, Security, after entering a current authenticator code. Each signs you in once in place of the authenticator; making a new set stops the old ones; Trooth keeps only a keyed hash of each, and emails the account when a set is made or a code is used. Subscribing to a company's changes now sends a confirmation email first, and nothing else is sent until the link in it is followed; a webhook given there must answer a challenge before it is stored. Before moving the webhook dates, Trooth read every alert destination in production: none was a webhook or chat destination. So the shared signing key stopped signing on September 29 instead of October 5, and webhooks that have not proven ownership stop receiving the same day. The page for checking a receipt against its key now follows the key policy published with the keys: a key marked compromised, or revoked with no recorded reason, is not to be relied on for any signature, because a receipt's time is asserted by Trooth when it signs. The key list records when it first published each key from now on, and carries a list of retired and compromised keys. The older api.trooth.co/public/trust route gives one answer for a company's slug and its domain, and the developer documentation now leads with the supported lookup. A Stripe secret key is refused before it is stored.
Why it changed
The audit of September 28, 2026 found no recovery path for a lost authenticator, a subscription that mailed any address without its consent, a shared-key window left open, and a verification page that disagreed with the published key policy.
Who is affected
- Affected: Account holders using two-factor authentication, anyone subscribing to a company's changes, webhook receivers, and anyone checking a Trooth receipt against its key.
- Availability: Recovery codes: any account with two-factor authentication on. The rest: public.
- Release stage: Available.
- Areas: Company workspace, Webhooks, Platform.
What to do
No action required. Nothing is required. If you use two-factor authentication, making a set of recovery codes in Settings, Security, and keeping them somewhere safe, is worth doing.
Dates
- Announced: September 28, 2026, the day this entry was written. Entries are never backdated.
- Released: September 28, 2026.
- Shared webhook key stops signing: September 29, 2026.
What this does not fix
Recovery codes are covered by route and unit tests, not yet by a browser test of sign-in. When a key's activation was never recorded, it stays unknown.