WardenAuthAgent Security
PricingDocsCompareBlogLearnChangelog
Sign inGet started free
What's new

Changelog

Every release, shipped. Updates are pushed regularly — check back for the latest.

v2.1.0

2026-07-14

Agent Security monitoring dashboard, CloudWatch alarms, and comprehensive documentation.

  • NewCloudWatch Dashboard — 10 widgets for API Gateway, Lambda, DynamoDB, and SQS DLQ monitoring
  • NewNew alarms: DynamoDB throttle detection, Cognito auth failure, Stripe webhook errors, billing overage alerts
  • NewFull Docusaurus documentation site — 20 pages covering Agent Security, RBAC, and Tutorials
  • ImprovedPost-registration redirects to dashboard instead of onboarding wizard
  • ImprovedLogin redirect respects last-used mode (Agent or RBAC)
  • FixBilling tier resolver correctly reads Data.tier from subscription records
  • FixgetTupleLimit now resolves tier-aware limits instead of always returning free tier

v2.0.0

2026-07-01

Agent Security platform — MCP gateway, HITL approvals, Web Push, and PWA.

  • NewMCP Gateway — aggregate multiple MCP servers behind one connection with namespaced tool routing
  • NewTwo-level HITL: self-approval and admin-approval with SoD enforcement
  • NewWeb Push notifications for HITL approvals — instant alerts even when the app is closed
  • NewPWA support — install the dashboard on mobile for approval management anywhere
  • NewPortal proxy service with parallel fan-out and per-server partial failure isolation
  • NewServer-side drift detection — alerts when upstream MCP servers add or change tools
  • NewCryptographic receipts — signed JWT for every allow/deny decision, independently verifiable
  • NewResource constraints — ABAC fallback for shared-credential MCP servers
  • NewVelocity policy per grant, per server, and per tool with user-configurable budgets
  • NewApproval history — full accountability record: who approved/denied what, when, and why
  • NewDeny with reason — reviewers can provide feedback when rejecting an agent action
  • NewAuto-reject timeout — stale HITL requests expire after 1 hour and open a fresh request
  • NewAgent gateway (Go SDK) — self-hosted MCP proxy with local enforcement
  • NewMCP OAuth — register OAuth apps for GitHub, Asana, Linear, Notion, and more
  • NewMcpHitlService — extracted approval lifecycle management from consent service
  • NewBillingTierResolver — consolidated tier resolution from scope hierarchy into a single DDD service

v1.6.0

2025-01-15

Cursor-based pagination, webhook endpoints, and TypeScript SDK.

  • NewCursor-based pagination on all list endpoints (scopes, permissions, roles, access policies, API keys, resource types, webhooks, audit)
  • NewWebhook endpoints: subscribe to RBAC events via HTTP POST delivery
  • NewResource types: categorize resources for better policy organization
  • NewTypeScript SDK (@ecarrizo2/wardenauthz-js) published to npm with full type safety
  • NewOpenAPI spec updated with resource-types and webhooks path definitions
  • ImprovedPaginated dashboard UI for all resource lists
  • Improvedsitemap.xml and robots.txt added for SEO

v1.5.0

2024-12-20

Enterprise tier with SAML SSO, SCIM provisioning, and audit log.

  • NewSAML 2.0 SSO integration — connect your IdP (Okta, Azure AD, Google Workspace)
  • NewSCIM 2.0 automatic user provisioning and deprovisioning
  • NewAudit log — immutable event trail with actor, resource, action, and timestamp
  • NewEnterprise tier: custom contracts, SLA, dedicated infrastructure
  • NewTeam member management: invite, assign roles, remove members
  • ImprovedDashboard: Enterprise settings page for SSO and SCIM configuration
  • ImprovedDashboard: dark mode and accent color theming

v1.4.0

2024-11-10

API key management, bulk access checks, and improved billing.

  • NewScoped API keys: create, rotate, and revoke keys with per-key permission scopes
  • NewBulk access check: evaluate up to 25 decisions in a single HTTP call
  • NewStripe billing integration: upgrade, downgrade, and manage subscriptions in-dashboard
  • ImprovedUsage dashboard: real-time check counts and quota visualization
  • ImprovedAPI key hashing with PBKDF2 — keys are never stored in plaintext
  • FixFixed race condition in concurrent access policy updates

v1.3.0

2024-10-01

Wildcard permissions and deny-wins semantics.

  • NewWildcard permissions: resource:* (all actions on resource) and *:* (all access)
  • NewDeny-wins semantics: explicit deny overrides any allow — no ambiguous results
  • NewWorkspace scopes: nest workspaces under an organization scope
  • ImprovedPermission evaluation now short-circuits on first explicit deny
  • ImprovedRole model refactored to support up to 200 permissions per role

v1.2.0

2024-08-22

Multi-tenant scopes and role-based access control foundation.

  • NewScopes: fully isolated RBAC namespaces per tenant
  • NewPermissions: fine-grained resource+action definitions with allow/deny effects
  • NewRoles: named bundles of permissions, assignable via access policies
  • NewAccess policies: bind a subject to one or more roles in a scope
  • NewPOST /v1/access/check: the core authorization API
  • ImprovedSingle-table DynamoDB design — sub-millisecond reads at any scale

v1.0.0

2024-07-01

Initial release — org registration and core API.

  • NewOrganization registration with Cognito-backed authentication
  • NewManagement dashboard for visual RBAC administration
  • NewREST API with API key authentication
  • NewAWS serverless infrastructure: Lambda + DynamoDB + API Gateway

Have a feature request or spotted a bug?

Send feedbackContact us
© 2026 ecarrizo. All rights reserved.
PricingDocsCompareBlogLearnChangelogStatusGlossaryContactTermsPrivacy