---
title: "Recovery codes, confirmed alerts, and a key policy the verifier follows: Trooth changelog - Trooth"
description: "Accounts with two-factor authentication can make single-use recovery codes, profile alerts start only after the address confirms, the shared webhook key signs nothing from September 29, and a compromised signing key is treated as compromised whatever time a receipt carries."
canonical_url: "https://trooth.co/changelog/2026-09-28-recovery-codes-and-confirmed-alerts"
markdown_url: "https://trooth.co/changelog/2026-09-28-recovery-codes-and-confirmed-alerts.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

[Back to changelog](https://trooth.co/changelog)

Security

September 28, 20262 minute read

# Recovery codes, confirmed alerts, and a key policy the verifier follows

Accounts with two-factor authentication can make single-use recovery codes, profile alerts start only after the address confirms, the shared webhook key signs nothing from September 29, and a compromised signing key is treated as compromised whatever time a receipt carries.

## What changed

An account with two-factor authentication on can make ten recovery codes from Settings, Security, after entering a current authenticator code. Each signs you in once in place of the authenticator; making a new set stops the old ones; Trooth keeps only a keyed hash of each, and emails the account when a set is made or a code is used. Subscribing to a company's changes now sends a confirmation email first, and nothing else is sent until the link in it is followed; a webhook given there must answer a challenge before it is stored. Before moving the webhook dates, Trooth read every alert destination in production: none was a webhook or chat destination. So the shared signing key stopped signing on September 29 instead of October 5, and webhooks that have not proven ownership stop receiving the same day. The page for checking a receipt against its key now follows the key policy published with the keys: a key marked compromised, or revoked with no recorded reason, is not to be relied on for any signature, because a receipt's time is asserted by Trooth when it signs. The key list records when it first published each key from now on, and carries a list of retired and compromised keys. The older api.trooth.co/public/trust route gives one answer for a company's slug and its domain, and the developer documentation now leads with the supported lookup. A Stripe secret key is refused before it is stored.

## Why it changed

The audit of September 28, 2026 found no recovery path for a lost authenticator, a subscription that mailed any address without its consent, a shared-key window left open, and a verification page that disagreed with the published key policy.

## Who is affected

- **Affected:** Account holders using two-factor authentication, anyone subscribing to a company's changes, webhook receivers, and anyone checking a Trooth receipt against its key.
- **Availability:** Recovery codes: any account with two-factor authentication on. The rest: public.
- **Release stage:** Available.
- **Areas:** Company workspace, Webhooks, Platform.

## What to do

**No action required.** Nothing is required. If you use two-factor authentication, making a set of recovery codes in Settings, Security, and keeping them somewhere safe, is worth doing.

## Dates

- **Announced:** September 28, 2026, the day this entry was written. Entries are never backdated.
- **Released:** September 28, 2026.
- **Shared webhook key stops signing:** September 29, 2026.

## What this does not fix

Recovery codes are covered by route and unit tests, not yet by a browser test of sign-in. When a key's activation was never recorded, it stays unknown.

## Read more

- [Security settings](https://trooth.co/dashboard/settings/security)
- [Webhook reference](https://trooth.co/docs/webhooks)
- [Public Trust Profile API](https://trooth.co/docs/trust-profile-api)
- [Security controls](https://trooth.co/security/controls)

On this page

- What changed
- Why it changed
- Who is affected
- What to do
- Dates
- What this does not fix
- Read more

[Security](https://trooth.co/changelog?type=security)[Fix](https://trooth.co/changelog?type=fix)[Company workspace](https://trooth.co/changelog?area=workspace)[Webhooks](https://trooth.co/changelog?area=webhooks)[Platform](https://trooth.co/changelog?area=platform)

[Back to changelog](https://trooth.co/changelog)

## Related changes

- [SEP.28FixThe EU representative position, and Cloudflare's two permissionsLegal +1](https://trooth.co/changelog/2026-09-28-eu-representative-and-cloudflare-permissions)
- [SEP.28ImprovementRetention with an end, continuity powers made clear, and production watchedLegal +2](https://trooth.co/changelog/2026-09-28-retention-continuity-and-deploy-controls)
- [SEP.28FixCorrections from the September 28 audit: contract 1, one interface catalog, a complete bill of materialsAPI +5](https://trooth.co/changelog/2026-09-28-fresh-audit-corrections)
- [SEP.28FixA site-wide quality sweep: underlined legal links, keyboard-reachable code, readable small textPlatform +1](https://trooth.co/changelog/2026-09-28-site-wide-quality-sweep)
- [SEP.27MethodologyThe two Standards and the About page, rebuilt as referencesMethodology +1](https://trooth.co/changelog/2026-09-27-standards-and-about-page-as-references)
- [SEP.27NewA public feedback board, and a comparison you can start with any two companiesNetwork +1](https://trooth.co/changelog/2026-09-27-feedback-board-and-comparison)

## Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

## Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

Email address

[RSS](https://trooth.co/changelog/rss.xml)[Company workspace only](https://trooth.co/changelog/rss.xml?area=workspace)[Needs action](https://trooth.co/changelog/rss.xml?action=required)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current Machine-Readable Trust Profile per company, each fact labeled with its source. The part Trooth witnessed is a signed statement whose signature anyone can check later; the company's own declarations are not signed.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth now - it's free!",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://trooth.co/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Changelog",
      "item": "https://trooth.co/changelog"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "Recovery codes, confirmed alerts, and a key policy the verifier follows",
      "item": "https://trooth.co/changelog/2026-09-28-recovery-codes-and-confirmed-alerts"
    }
  ]
}
```
