Skip to content
routebase

Changelog

Earlier releases

1.4.0

Added

  • Delete a workspace — with 30 days to change your mind. Deleting an organization is a scheduled operation. A pre-check states what stands in the way before the dialog opens (an active subscription is cancelled first; one that is already cancelled but still running does not block), the dialog names the member count and what is kept, and asks you to type the workspace name. Every member is signed out immediately, and the owner receives a mail with a restore link that works for 30 days without signing in — it brings the workspace back at its original address, with all memberships intact. After the 30 days a daily run removes the workspace across all 13 modules, including published portals and their custom domains. Where there is an invoice history, the accounting records and their anonymous anchor are kept for the statutory retention period; where there is none, nothing remains.
  • Delete your account, yourself. A new Delete account card sits below the data cards on your profile. A pre-check says what would happen: a sole owner of an organization with other members transfers ownership first, an active subscription is cancelled first, and a sole owner without other members takes the workspace along — the dialog says so in as many words. Accounts managed through SSO or SCIM point to their identity provider instead: that lifecycle belongs to the IdP. The dialog lists what is deleted and what is kept, and asks you to type your own email address. The confirmation mail carries a one-time "Keep my account" link that reverses everything for 30 days — account reactivated, a co-deleted workspace restored at its original address.
  • Download a complete copy of your personal data. A new Your data card on the profile page hands you everything tied to you as JSON: profile, memberships, chat history with messages, personal variables and their values, notifications, preferences and usage data (AI runs, credits, review activity). This covers the right to data portability (GDPR Art. 20). Workspace content such as specs and tests belongs to the organization and stays out — the regular export functions cover that. It also works without signing in: the farewell mail after leaving an organization carries a download button with a one-time link, valid for 30 days.
  • A verified domain belongs to the organization that verified it. Anyone whose address sits under a domain an existing organization has verified (max@acme.com while Acme Corp has verified acme.com) joins that organization through an invitation from its administrator. Only verified domains bind — listing a domain without the DNS proof binds nobody. Domain management now has its own page under Settings → Domains, visible on every plan; the SSO page itself remains Enterprise.
  • Assign a security scheme to every endpoint of a spec in one go. The action "Assign to endpoints…" now sits on the security scheme itself. Pick the endpoints in one of four ways — all, by folder, by tag, or hand-picked with search — and the dialog states what you are about to do before it happens: "38 endpoints selected · 3 already have BearerAuth". It is repeatable: a second run over the same selection skips what already carries the scheme instead of duplicating it, and reports both numbers. And it is reversible: the same selection can be cleared again with "Remove from selected". Locked versions — published or deprecated — are left untouched, and the action is hidden from anyone without write access to specs.
  • add_security_scheme assigns to several endpoints at once over MCP. The tool takes endpointIds (comma-separated) together with versionId and returns how many assignments were created, how many were skipped, and how many of the given ids do not exist in that version. The single-endpoint call is unchanged.
  • A new style-guide rule finds paths that collide. /languages/{id} and /languages/{languageId} look different but are the same route in OpenAPI — a placeholder's name is documentation, not part of the address, and the same goes for a trailing slash. "Paths must be unique" names each pair and the endpoint on the other side; its severity is configurable per organization and per project like any rule. The create dialog says it up front, too: it names the endpoint already holding that route and keeps "Create" disabled. See the style guide.

Improved

  • Code samples send the authentication the endpoint actually declares. All nine languages now follow the security scheme in the spec: API key in the header, in the query string or as a cookie (under its declared name), Basic in the form each language has for it (curl -u, http -a, requests(auth=…), SetBasicAuth, basic_auth), Bearer, and OAuth2 / OpenID Connect as bearer tokens; an HTTP scheme that is none of these is named rather than guessed, and an endpoint declaring several schemes carries all of them. The Copy button in the API Designer resolves exactly the same way as the published docs, and the Markdown form of an endpoint page names the mechanism ("X-Api-Key header") rather than just the scheme. The playground follows: it now handles Basic and query-string API keys alongside bearer and header keys, and pre-fills type, parameter name and location from the endpoint's scheme instead of having you type them.
  • Code samples carry the full production URL. When no environment is released to the playground, the portal falls back to the environment with the "Feeds the public docs" role — its base URL describes precisely the contract these docs document — and appends the spec's base path (/v3), read live from the spec at build time, so a correction takes effect with the next portal build without republishing the doc version. The OpenAPI export, and with it Postman and Insomnia, now writes the base path into the servers URL, where OpenAPI 3 expects it.
  • Schema aliases stay aliases, end to end. A component written as a pure reference to another (ErrorResponse: { $ref: … ProblemDetails }) is imported as an alias rather than a copy, exported back under the name the file used, and shown in the editor with the target's fields and both names in the table header — ErrorResponse › ProblemDetails, both clickable. Chains across several intermediate names are followed. Editing stays at the target, and the JSON view still shows the reference as stored.
  • The endpoint editor always shows the Security row. With no scheme defined yet it reads "No security schemes defined" and offers Add security scheme, which creates one straight from the endpoint editor — and assigns it to the endpoint you have open.

Changed

  • Team events now reach the people who manage members. An invitation, a removal, a role change go to owners, admins and any custom role holding org:manage-members — the same permission you need to invite someone in the first place. The invitation mail to the invited person is unaffected and arrives as before, and webhooks fire unchanged. In personal notification settings the Team category is hidden for anyone without that permission. See roles & permissions.
  • Leaving, removal and workspace deletion run through one offboarding path. The Auth0 session is ended server-side; if the address sits on a verified domain of the organization being left, the account is suspended as well — the address belongs to the company. Private addresses and external consultants under a foreign domain are never suspended. The person receives a neutral mail naming the concrete date their account is removed if they do not join an organization again: 30 days. Every way back stops the clock — a new invitation lifts the suspension, and otherwise joining or signing in is enough. SCIM deactivation (active=false) deliberately stays out of this: it is reversible — parental leave, a sabbatical — and does not end a membership.
  • The 14-day Pro trial is granted once per person rather than once per workspace. Registration itself stays open; only the one-time welcome trial is affected.

1.3.0

Added

  • Test runs validate against the spec version deployed in the environment under test. A run against staging is judged by the contract staging actually serves, not by whichever version the test case happens to link to. A failed schema assertion names the version it checked against, and a test whose endpoint link has gone stale says so explicitly.
  • Scenario steps open in a dialog that shows which variables they need. Clicking a step name reveals what it is made of and which variables are unresolved before you run it.
  • Doc portals: the navigation sidebar is resizable. Readers can drag it between 180 and 520 px, double-click to reset it to the portal's own width, or nudge it with the arrow keys. The width is remembered per browser and applies on the next visit without the layout jumping on load.
  • Doc portals: every navigation row with content below it now collapses. Previously a plain grouping folder had a chevron while a folder with its own page did not — and showed its subfolders permanently but its endpoints only while you stood on it. Every row now behaves the same, with two targets: clicking the name opens the folder's page, clicking the chevron expands it, as in any file tree.
  • Doc portals: long navigation labels are truncated instead of wrapping, so every row keeps the same height, and hovering reveals the full title in a tooltip styled like the rest of the portal — same type, colours and border, and it follows light and dark mode. The portal's own tooltips replace the browser's grey boxes throughout the navigation and the API reference.
  • Doc portals: the header can be lifted off the top edge. A new Top margin dial under "Header" in the design settings turns the bar into a free-floating pill together with the existing horizontal inset and corner radius. The margin survives scrolling, and everything that sticks below the header — navigation, table of contents, the endpoint bar and pinned code samples — moves with it.
  • API reference: hovering a property scrolls the matching line of the code sample into view. Highlighting the line only helped when it happened to be visible; in a longer sample it was off-screen and you had to find it by hand. It now scrolls there — but only when the line is actually out of view, and after a short pause, so the sample does not twitch as you move down the property list.

1.2.0

Added

  • MCP server — the full platform is now driveable by an agent. The server now covers the full feature set of the product across 31 toolsets. Monitoring, Security, Projects, Variables, Mock Server and the testing workshop went from partial to complete: an agent can now create a project, manage variables, reorder and regenerate mock rules, set up test schedules and data-driven test tables, triage security findings, acknowledge incidents, and schedule maintenance windows. Alongside the tools there are now 12 resources and 13 guided workflows, including incident triage, security finding triage, and walking a deprecation to its end. Deliberately read-only: billing, plan limits, roles and team assignments are readable so an agent can explain why something is blocked — but it cannot switch a plan, buy seats, grant a role, or add anyone to a team. See the MCP quickstart.
  • A dedicated address for the MCP server. It is now https://mcp.routebase.dev — the address you paste into Claude or your IDE no longer carries a path. The previous address keeps working.
  • Review mode in the API Designer. A "Changes" toggle shows what has changed since a chosen baseline — the last published version by default. Changed and added endpoints and schemas are marked with a dot in the tree, folders carry a rollup count, and removed entities are listed in a popover since they no longer have a row. Inside a schema, property rows show the diff directly: added rows in green, changed rows in amber with the old type struck through, and removed properties as a read-only ghost row. Request and response bodies are marked too, including bodies that resolve through a $ref.
  • Project-wide endpoint and schema overview, with duplicate detection. One surface across every spec in the project — the scale at which redundancy actually appears, and where per-spec lists cannot help. It finds exact duplicates across spec boundaries — schemas by a documentation-insensitive structure hash, so it catches Address in one spec and PostalAddress in another with identical structure, which a name search never finds. Duplicate endpoints (same method, same normalized path template) are flagged in red rather than blue: they are a potential gateway routing conflict, not redundancy.
  • The style guide's path naming convention is configurable. Kebab-case is one legitimate convention among several — a .NET-style API with /AccountManagers paths is not a style violation. Pick the convention per organization and per project (kebab-case, camelCase, PascalCase, lowercase); quick fixes follow the setting, so you keep the consistency check without rewriting a single path. See the style guide.
  • A new style-guide rule finds dangling references. no-dangling-refs catches a $ref that points at no schema in the spec — at design time, rather than when a test hits it at runtime. It is the counterpart to no-unused-components and carries Warning severity, so it shows in the score without blocking a publish.
  • Test cases can be renamed. Rename, duplicate and delete now live in one context menu, reachable by right-click or the hover menu on the sidebar row and from the card. Double-clicking a row renames it inline.
  • Mock server: delete a folder with all rules under it. The confirmation names the folder and count up front and lists the affected rules. See mock server.
  • Try It: save the response body to a file. The raw body the server returned, named from request path, status code and date, with the extension following the Content-Type. The desktop app opens a native save dialog.
  • Tag autocomplete in the API Designer and Testing. Typing a tag now suggests from the version's tag catalog and from the tags used on other endpoints, suites and scenarios — so Users and users stop drifting apart. Free text still wins: Enter creates what you typed unless you arrow into a suggestion.
  • Undo and Redo in the designer toolbar. Both sit next to the spec title with a tooltip naming the exact action ("Undo Schema change"), and are mirrored in the command palette. They cover response status codes, content types and descriptions, schema link and unlink, and parameter edits and ordering. The endpoint tree is now fully keyboard-navigable with the arrow keys.
  • "Copy From" can copy authentication when creating an environment. Auth type, all non-secret fields and {{VAR}} references come along and resolve against the variables copied beside them. See environments.
  • Link an existing schema to a response, and an existing component to a request body. Attaching ErrorResponse to a 400 is now a searchable picker on the response itself, with an unlink action beside it. Dropping a schema from the sidebar links it rather than copying it, so one shared definition stays one definition.
  • Desktop app 1.0.0 for macOS and Windows.
  • MCP CLI 1.0.4 — routebase-mcp init now asks for your region, so US-region accounts no longer have to know about ROUTEBASE_REGION up front. See the CLI reference.

Improved

  • OpenAPI import and export carry the full contract. Operation-level security requirements now survive an import and stay linked to their operations, with OpenAPI inheritance applied correctly: an operation without its own entry inherits the document-wide default, and an explicit security: [] remains an opt-out. Validation constraints — minLength, maximum, pattern, multipleOf and the rest of the schema editor's set — round-trip on both sides.
  • Version comparison sees the whole schema. Changes nested below a schema's top level are now detected, as are changes to enum values alone — removing an allowed value is a breaking change for everyone who sends it, and it now surfaces as one. Fields typed as "string or null" (the OpenAPI 3.1 form MCP-created schemas use for nullable fields) are read correctly, and request body changes appear in the diff alongside responses. This is what the review mode above builds on.
  • Export fidelity. $refs inside array items and composition members resolve to the full referenced schema, and fully qualified generic .NET type names shorten to a readable form (FilterFieldDtoOfSchedulerEventType) instead of being cut at the wrong boundary.

1.1.0

Added

  • Doc portals: nested folder navigation. The portal sidebar now mirrors the folder hierarchy from the API Designer instead of flattening it.
  • "Watch this API for drift" — drift monitoring for a whole spec in two clicks. Previously this meant creating monitors endpoint by endpoint. See schema drift.
  • Slack and Teams alerts, properly formatted. "Add to Slack" connects a channel in one click instead of a two-minute manual setup. Incident, monitoring, security and drift messages are formatted with Block Kit and Adaptive Cards rather than raw payloads, and a security scan arrives as one message instead of one per finding. Slack and Teams integrations now have their own Messaging page in settings.
  • Components overview as a triage surface. Clicking the "Schemas" or "Shared" sidebar header opens an overview in the main panel. See shared library.
  • Callouts, tabs and mermaid diagrams in endpoint descriptions, via slash commands in the description editor.
  • A dialog warns about tag divergence when you move an endpoint into a folder whose name disagrees with the endpoint's tags; for nested folders, the nearest folder wins.

Changed

  • Contract violations in array items are now classified as errors. Previously they were reported at a lower severity, which understated a real contract break.

1.0.0

Routebase brings the full API lifecycle under one roof:

New to Routebase? Start with Getting Started.

← Latest releases

Ready to ship on it?

Routebase is live. Design your API once — docs, mocks, tests, and monitoring all follow from the same source.

14-day Pro trial — no credit card required.