Added
- Delete a workspace — with 30 days to change your mind. Deleting an organization is a scheduled operation. A pre-check states what stands in the way before the dialog opens (an active subscription is cancelled first; one that is already cancelled but still running does not block), the dialog names the member count and what is kept, and asks you to type the workspace name. Every member is signed out immediately, and the owner receives a mail with a restore link that works for 30 days without signing in — it brings the workspace back at its original address, with all memberships intact. After the 30 days a daily run removes the workspace across all 13 modules, including published portals and their custom domains. Where there is an invoice history, the accounting records and their anonymous anchor are kept for the statutory retention period; where there is none, nothing remains.
- Delete your account, yourself. A new Delete account card sits below the data cards on your profile. A pre-check says what would happen: a sole owner of an organization with other members transfers ownership first, an active subscription is cancelled first, and a sole owner without other members takes the workspace along — the dialog says so in as many words. Accounts managed through SSO or SCIM point to their identity provider instead: that lifecycle belongs to the IdP. The dialog lists what is deleted and what is kept, and asks you to type your own email address. The confirmation mail carries a one-time "Keep my account" link that reverses everything for 30 days — account reactivated, a co-deleted workspace restored at its original address.
- Download a complete copy of your personal data. A new Your data card on the profile page hands you everything tied to you as JSON: profile, memberships, chat history with messages, personal variables and their values, notifications, preferences and usage data (AI runs, credits, review activity). This covers the right to data portability (GDPR Art. 20). Workspace content such as specs and tests belongs to the organization and stays out — the regular export functions cover that. It also works without signing in: the farewell mail after leaving an organization carries a download button with a one-time link, valid for 30 days.
- A verified domain belongs to the organization that verified it. Anyone whose address sits under a domain an existing organization has verified (
max@acme.comwhile Acme Corp has verifiedacme.com) joins that organization through an invitation from its administrator. Only verified domains bind — listing a domain without the DNS proof binds nobody. Domain management now has its own page under Settings → Domains, visible on every plan; the SSO page itself remains Enterprise. - Assign a security scheme to every endpoint of a spec in one go. The action "Assign to endpoints…" now sits on the security scheme itself. Pick the endpoints in one of four ways — all, by folder, by tag, or hand-picked with search — and the dialog states what you are about to do before it happens: "38 endpoints selected · 3 already have BearerAuth". It is repeatable: a second run over the same selection skips what already carries the scheme instead of duplicating it, and reports both numbers. And it is reversible: the same selection can be cleared again with "Remove from selected". Locked versions — published or deprecated — are left untouched, and the action is hidden from anyone without write access to specs.
add_security_schemeassigns to several endpoints at once over MCP. The tool takesendpointIds(comma-separated) together withversionIdand returns how many assignments were created, how many were skipped, and how many of the given ids do not exist in that version. The single-endpoint call is unchanged.- A new style-guide rule finds paths that collide.
/languages/{id}and/languages/{languageId}look different but are the same route in OpenAPI — a placeholder's name is documentation, not part of the address, and the same goes for a trailing slash. "Paths must be unique" names each pair and the endpoint on the other side; its severity is configurable per organization and per project like any rule. The create dialog says it up front, too: it names the endpoint already holding that route and keeps "Create" disabled. See the style guide.
Improved
- Code samples send the authentication the endpoint actually declares. All nine languages now follow the security scheme in the spec: API key in the header, in the query string or as a cookie (under its declared name), Basic in the form each language has for it (
curl -u,http -a,requests(auth=…),SetBasicAuth,basic_auth), Bearer, and OAuth2 / OpenID Connect as bearer tokens; an HTTP scheme that is none of these is named rather than guessed, and an endpoint declaring several schemes carries all of them. The Copy button in the API Designer resolves exactly the same way as the published docs, and the Markdown form of an endpoint page names the mechanism ("X-Api-Key header") rather than just the scheme. The playground follows: it now handles Basic and query-string API keys alongside bearer and header keys, and pre-fills type, parameter name and location from the endpoint's scheme instead of having you type them. - Code samples carry the full production URL. When no environment is released to the playground, the portal falls back to the environment with the "Feeds the public docs" role — its base URL describes precisely the contract these docs document — and appends the spec's base path (
/v3), read live from the spec at build time, so a correction takes effect with the next portal build without republishing the doc version. The OpenAPI export, and with it Postman and Insomnia, now writes the base path into theserversURL, where OpenAPI 3 expects it. - Schema aliases stay aliases, end to end. A component written as a pure reference to another (
ErrorResponse: { $ref: … ProblemDetails }) is imported as an alias rather than a copy, exported back under the name the file used, and shown in the editor with the target's fields and both names in the table header —ErrorResponse › ProblemDetails, both clickable. Chains across several intermediate names are followed. Editing stays at the target, and the JSON view still shows the reference as stored. - The endpoint editor always shows the Security row. With no scheme defined yet it reads "No security schemes defined" and offers Add security scheme, which creates one straight from the endpoint editor — and assigns it to the endpoint you have open.
Changed
- Team events now reach the people who manage members. An invitation, a removal, a role change go to owners, admins and any custom role holding
org:manage-members— the same permission you need to invite someone in the first place. The invitation mail to the invited person is unaffected and arrives as before, and webhooks fire unchanged. In personal notification settings the Team category is hidden for anyone without that permission. See roles & permissions. - Leaving, removal and workspace deletion run through one offboarding path. The Auth0 session is ended server-side; if the address sits on a verified domain of the organization being left, the account is suspended as well — the address belongs to the company. Private addresses and external consultants under a foreign domain are never suspended. The person receives a neutral mail naming the concrete date their account is removed if they do not join an organization again: 30 days. Every way back stops the clock — a new invitation lifts the suspension, and otherwise joining or signing in is enough. SCIM deactivation (
active=false) deliberately stays out of this: it is reversible — parental leave, a sabbatical — and does not end a membership. - The 14-day Pro trial is granted once per person rather than once per workspace. Registration itself stays open; only the one-time welcome trial is affected.