Skip to main content
Improvement

2 minute read

Search that finds products, standard errors, and a keyboard that reaches everything

Directory search now matches product names and domains on the live page, errors can be read as standard problem details, every response carries a request id, sign-in uses PKCE where the provider supports it, webhooks carry Standard Webhooks headers, and seven keyboard and focus defects are fixed.

What changed

The directory search box now reads Search a company, product or domain, and it matches product names and domains as well as names and descriptions; each result says why it matched, and two companies with the same name show their domains. A comparison now opens a question in place to show where each answer came from, keeps the scope you set in its link and export, and names the version of each company's record it compared. On the public API, an error comes back as RFC 9457 problem details when the request asks for application/problem+json, with the previous body unchanged otherwise, and every response carries an X-Request-Id and a W3C traceparent header. A Trust Profile read through the API answers If-None-Match with 304 Not Modified. Signed exports carry who they are about, when they were made and how, inside the signed bytes, and the verifier reports integrity and freshness as two separate answers. A copied profile link notes the save it came from, and the page says when the record has changed since. Sign-in with Google, GitHub and Microsoft now uses PKCE, and Apple sign-in a nonce. Webhook deliveries add the Standard Webhooks headers beside the existing signatures. The MCP endpoint's tool list is sorted, paged and identified by a digest, and each answer says when it was given and from which source. A browser pass over every page found seven places where keyboard focus could land under the cookie panel, the phone menu or a sticky header, or lose its outline; all seven are fixed.

Why it changed

Trooth closed 160 more of its open launch requirements on September 29, 2026, and found that one change announced the day before had been made to a component the directory page does not use. This release puts it on the live page and adds a check that fails the build if that happens again.

Who is affected

  • Affected: Anyone searching the directory or comparing companies, developers calling the public application programming interface (API) or the Model Context Protocol (MCP) endpoint, webhook receivers, people signing in with Google, GitHub, Microsoft or Apple, and anyone using the site from a keyboard or a phone.
  • Availability: Public, except the import and research-project changes, which are in the workspaces.
  • Release stage: Available.
  • Areas: Network, API, Trust Profiles, Webhooks, Company workspace, Platform.

What to do

No action required. Nothing is required. Developers who want machine-readable errors can send Accept: application/problem+json; webhook receivers can keep checking the signatures they check today.

Dates

  • Announced: September 29, 2026, the day this entry was written. Entries are never backdated.
  • Released: September 29, 2026.

What this does not fix

With a phone held sideways and the on-screen keyboard open, the cookie panel can still cover a field on the records request form; closing the panel reveals it. The record-history tables that versioned reads depend on are ready and will be switched on after review.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSNetwork onlyNeeds action

View as agent