Web Changelog
Release notes for the Web and API surfaces.
2026-07-31
Features
POST /experimental/tasks,GET /experimental/tasks/{id}, andGET /experimental/tasks/by-linkresponses now include alinks.webfield with the task's URL in the web app.
2026-07-24
Features
GET /v1/workspaces/{workspaceNameOrID}/skill-inventories/{id}/findingsnow returns arepoActivityfield (active,quiet, ordormant) reflecting how recently a finding's repositories were pushed to, and accepts arepoActivityquery parameter to filter results by one or more of these buckets.The canonical home banner on skill pages now shows a colored status badge (In sync, Stale, or Modified), plus when that status was last confirmed, matching the detail already shown in the "Also appears in" panel.
GET /experimental/tasks/{id}/runsresponses now include asummaryfield on completed runs when one is available, giving a short description of what the run did.The task timeline now shows a short summary of what a completed run did, alongside its existing status and links.
Bug Fixes
The Eval Runs pages no longer show an unrelated default-model notice banner at the top; pages now open directly with the heading and results table.
Eval run detail pages now show an "Activation Run" label above the run heading for runs that measure activation, and the Skills Activated column shows "None" when a solution completed with confirmed zero activations; previously this looked identical to a run still in progress.
The stale copy-state label on skill pages now reads "Last in sync {date}" instead of the contradictory "In sync until {date}", so the date shown accurately reflects when the copy last matched its source.
Skill listings on the registry now correctly hide skills whose current review failed, and no longer hide skills based on stale historical review results for identical content.
2026-07-17
Features
Connected GitHub App integrations now show separate Manage and Remove actions in integration settings, in place of a single Remove button: Manage opens the installation's settings on GitHub, and Remove opens a confirmation dialog before disconnecting.
Bug Fixes
The Ignored repos picker on the inventory scans page now searches your connected provider directly, so repositories beyond the first page of previously scanned repos can be found and ignored.
2026-07-09
Features
The eval runs list now shows a single Injected Context column in place of the separate Type and Subject columns, plus a new Scenarios column showing where each run's scenarios live.
Bug Fixes
Removed an inconsistent focus-ring outline from breadcrumb links; other interactive elements are unaffected.
2026-07-08
Features
The eval run detail view now labels variants "Baseline" and "With context" (replacing the misleading "Without context" label) and shows a new Injected Context panel describing exactly what fixture, plugin, directory, or commit a run injected.
2026-07-06
Bug Fixes
Skill-overload warnings no longer count skills sitting in plain source directories that no agent actually loads; only genuinely root-loaded skills count toward the threshold.
2026-07-03
Features
Billing settings now show the Team plan's monthly price inline: free organizations see it next to the Upgrade to Team button before checkout, and Team organizations see it next to their plan name.
GET /v1/orgs/{orgId}/billing/subscriptionnow includesmonthlyPriceUsdandupgradePriceUsdfields.monthlyPriceUsdis the current plan's monthly price (nullfor free or custom-priced plans);upgradePriceUsdis the Team plan's upgrade price (nullonce the org is already on a paid plan).Workspace member pages now support setting a default role that's automatically granted to every member of the workspace's organization, on top of any individual membership, useful for organizations that provision users via SSO.
PATCH /v1/workspaces/:idnow accepts anorgDefaultRolefield. When set, every member of the workspace's owning organization is granted that role on the workspace (capped atpublisher); omit it or set it tonullto remove the default.
Bug Fixes
The org billing page's credit usage display now matches the sidebar meter: over-limit usage reads "You've used your credit allowance" instead of a negative remaining figure, and fractional credit amounts are floored consistently.
2026-07-02
Features
New
DELETE /v1/projects/:projectIdendpoint soft-deletes a project: it's removed from normal reads and its name and source binding are freed for reuse, while eval-run and scenario-generation history is preserved.
Breaking Changes
GET /v1/orgs/{orgId}/creditsno longer returns thebundlesfield by default. Pass?include=bundlesto include the purchasable credit-bundle catalogue in the response, as before.
2026-07-01
Features
Claude Sonnet 5 (
claude-sonnet-5) is now available as an agent model for eval runs.The workspace Inventories Scans page has been rebuilt as a dashboard, with summary cards for estate growth, findings backlog, and scan health shown above the scans table.
2026-06-29
Features
Organizations can now subscribe to the Team plan and manage billing from organization settings: pay by card through a hosted checkout, get a monthly credit allowance, and buy additional credit bundles whenever you need them. Cancelling reverts the organization to the free plan at the end of the billing period.
Bug Fixes
Requests to
GET /v1/tiles/:workspaceName/:tileName/versions/:version/files/:filePathwith a malformed percent-encoded file path now return404instead of500. File paths containing a literal%are also served correctly.
2026-06-27
Breaking Changes
Review and fix runs that select a custom reviewer plugin or a non-default model now require a paid plan. An explicit reviewer or model override on
POST /experimental/review-runsorPOST /experimental/fix-runsnow returns403for an organization without the entitlement; previously such requests were accepted or silently fell back to the default. Free organizations continue to run against the default reviewer and model with no change.
2026-06-25
Features
Workspace members can now start skill reviews, security reviews, and review-fix runs. Previously these required the publisher role or higher; running a review is now available at the member level.
2026-06-19
Features
Org install policies now support a git source allowlist. Under Source restrictions, admins can configure which git hosts and repository path prefixes are permitted; installs from any unlisted git source are blocked at evaluation time. Sources are specified as
github.com/orgorgithub.com/org/repopatterns.The install policy
sourceRestrictionrule now accepts agitSourceAllowlistfield: an array of{ host, path }objects. When present, policy evaluation blocks any git-sourced install whose source does not match a listed host and path prefix.
2026-06-18
Features
Skill inventories can now be deleted from the inventory list. Workspace managers and owners see a delete action with a confirmation dialog; deleted inventories and their scans are immediately hidden but the workspace can be re-scanned at any time.
New
DELETE /v1/workspaces/:workspaceName/skill-inventories/:idendpoint removes a skill inventory and hides it and all associated scans. Requires themanage_integrationspermission.The inventory estate view now includes an Ignored repos panel for managing which repositories are excluded from future scans. Ignoring a repo purges its existing scan data and prevents it from being re-ingested on subsequent imports.
New
GET,POST, andDELETE /v1/workspaces/{workspaceName}/skill-inventories/{id}/ignored-reposendpoints let workspace admins manage which repositories are excluded from inventory scans. Ignoring a repo cascades a full data purge of its existing findings.The Inventories item now always appears in the workspace sidebar when the feature is enabled, even before any imports have been run. The empty state and failed-scan messages now show the
tessl inventory importcommand.Install, publish, and dependency policies can now be set and viewed at the org, workspace, and project levels from a unified policy editor. The editor shows the effective merged policy with per-field provenance badges indicating whether each value is set at the current level or inherited from a parent.
GET /v1/policies/{type}/{id}/effectivenow accepts a?provenance=truequery parameter. The response includes apolicySourcefield with per-field attribution showing which hierarchy level set each effective value.New users with pending org invitations are now shown them during sign-up, before a personal workspace is provisioned. Accepting an invite joins the invited org directly; skipping provisions a personal workspace as before.
Eval runs now default to
deepseek-v4-flashas the solver model (previouslyglm-5.1). Runs without an explicitmodeloverride pick up the new default; the scorer default remainsclaude-sonnet-4-6.
Bug Fixes
The plugin registry no longer shows stale installed-plugin content. Registry overview pages now always display the plugin's own declared skill documentation instead of falling back to vendored internal files.
The managed requirements search dropdown in the policy editor now overlays the page correctly instead of pushing the save button and other form content down.
Sending an org invitation now immediately refreshes the pending invitations list without requiring a page reload.
2026-06-17
Features
The inventory scan detail page now shows which first-party skills were added to or excluded from the index, with timestamps for added skills and reasons for excluded ones. A Re-index first-party skills button triggers a fresh indexing pass from the same page.
Bug Fixes
Skills submitted from repositories whose default branch is not
mainno longer get stuck in a sync error loop. The skill's source branch is now correctly recorded at submission time.
2026-06-11
Features
Review Runs now show what was reviewed: a registry-linked badge for tile skills, or the skill name for direct CLI review runs.
Review run objects now include a
subjectfield in their metadata:{ type: "tile_skill", tileRef, registryUrl }for tile-triggered reviews, or{ type: "skill", name }for CLI-initiated reviews. Runs created before this change omit the field.
Bug Fixes
Buttons rendered as links (navigation CTAs and similar) no longer show an underline on hover.
2026-06-04
Bug Fixes
Skill-name validation no longer rejects names containing
anthropicorclaudeas substrings. Skills such asclaude-apithat were previously blocked now validate and score correctly.tile quality scores now include completed review run results. Previously, review run scores were missing from the quality calculation.
2026-05-28
Features
File downloads for tile versions with failed, errored, or pending moderation now return
403with amoderation_hiddenerror code. Inline docs and steering are omitted from those version objects onGET /v1/tiles,GET /v1/tiles/:ws/:tile/versions, andGET /v1/tiles/:ws/:tile/versions/:version.tile pages now show a placeholder instead of inline docs and steering when a version is under moderation review, has failed moderation, or encountered a moderation error.
Public tiles now enforce a platform-level critical-severity security threshold: publishing a version with critical-severity findings blocks moderation and prevents the version from becoming available, regardless of workspace security policy settings.
Claude Opus 4.8 (
claude-opus-4-8) is now available as an agent model for eval runs.
Bug Fixes
Security severity levels in moderation failure messages now display as 'Critical', 'High', 'Medium', and 'Low' rather than internal identifiers.
Trend indicators on tile analytics now show 'New' when there is no baseline period to compare against, instead of an incorrect percentage.
2026-05-27
Bug Fixes
Eval-run detail pages now live under workspace-scoped URLs (
/workspaces/:workspace/eval-runs/:id), so the sidebar shows the correct workspace navigation. Existing/eval-runs/:idlinks redirect automatically for workspace members; public run links continue to work without authentication.
2026-05-22
Features
moderationStatusandmoderationErrorare now included in the version objects returned byGET /v1/tiles,GET /v1/tiles/:ws/:tile,GET /v1/tiles/:ws/:tile/versions, andGET /v1/tiles/:ws/:tile/versions/:version.moderationStatusis one ofpass,fail,error,pending, orskipped;moderationErrorcarries a safe, human-readable message when present. The deprecatedmoderationPassedboolean is unchanged;moderationStatusis the recommended replacement.The moderation status banner on tile pages now shows three distinct states: failed moderation (red), moderation error (orange), and review in progress (blue), each with copy tailored to the outcome.
2026-05-21
Features
Security review is now a required stage before a published tile version becomes available. After publishing, a version stays in
pendingmoderation state until the security scan completes; a failed or errored scan results in afailverdict and prevents the version from being accessible.tiles now show a pending moderation state immediately after publishing while security review runs; the version becomes available once review completes, and a failed scan keeps it offline.
Workspace member pages now include a short description explaining that org membership is required before a workspace role can be assigned, with a direct link to the org members page.
Bug Fixes
The error toast shown after a failed skill submission now displays a close button and auto-dismisses.
2026-05-14
Bug Fixes
Publishing to a workspace where you lack the publisher role now returns
401 Unauthorizedwith a message directing you to ask a workspace manager or owner (previously returned404 Not Found).
2026-05-13
Features
tiles and skills with no eval coverage now show an adjusted score: 80% of the review-based score at zero evals, ramping to full weight at three or more. Search ranking and score badges reflect this change.
2026-05-12
Features
The organization switcher has moved into the user menu with keyboard navigation. The workspace list now shows all workspaces across organizations, with an org badge when you belong to more than one.
Breaking Changes
The
allowUrlSourcesandallowFileSourcesfields have been removed from the managed-project policy;PUT /v1/workspaces/{workspaceId}/managed-project-policynow returns an error if either field is sent. Existing policies are migrated automatically.
Bug Fixes
The workspace selector in the 'Add member to organization' form now correctly requires a selection before submitting.
2026-05-11
Features
GET /v1/workspaces/:idnow accepts a workspace name in place of an ID.
2026-05-08
Features
Workspace settings now include toggles for public publishing, security reviews, and eval runs, accessible to workspace managers and above.
New
GET,PUT, andDELETE /v1/workspaces/{workspaceId}/managed-project-policyendpoints for managing workspace dependency-pinning policies.tiles in workspaces with security reviews disabled now show a disabled state instead of Pending on the security tab.
2026-05-07
Features
Starting an eval run or generating scenarios now returns 400 for workspaces with evals disabled.
Bug Fixes
Workspace created during onboarding now appears in the sidebar immediately without a page reload.
2026-05-06
Features
New /changelog page summarizing what shipped on Web and API each week.
Onboarding now captures role and use case during signup.
Bug Fixes
UUID validators relaxed to accept any valid hex format.
2026-05-05
Features
Refreshed copy on workspace and org role descriptions to make permissions easier to understand at a glance.
Creating a workspace now requires the org-admin permission.
Bug Fixes
Org and workspace selectors stay populated after a page refresh.
2026-05-01
Features
API endpoints are now tagged as
publicorexperimentalin the OpenAPI spec.
Breaking Changes
Editing workspace settings now requires the
edit_settingspermission (manager or higher).
2026-04-30
Features
Workspace Projects are now available to all customers.
Eval-result emails redesigned with a clearer score breakdown.
HTML files are now permitted in tile publishes.
2026-04-29
Breaking Changes
Legacy user-scoped API keys no longer accepted; switch to workspace- or org-level API keys.
Bug Fixes
Eval-run table rows are now real links so command-click opens them in a new tab.
2026-04-28
Features
Refreshed the favicon set across the web product.
2026-04-27
Features
Org admins can now change member roles.
Org admins can now remove members from the organization.
2026-04-24
Features
Pending org invitations can now be listed, resent, and revoked from the UI.
Related tiles and skills are back, now powered by semantic search.
Bug Fixes
Pending eval runs are now labeled "In Progress".
2026-04-23
Features
Added an organization switcher above the workspace selector.
Workspace owners can now delete empty workspaces.
Organizations can now be renamed directly from the UI.
A single invitation can now add a user to multiple workspaces in an organization.
Workspace managers can now browse organization members when adding workspace members.
Eval-run page now renders activation results from agent runs.
2026-04-21
Features
Eval-run progress now renders as a per-scenario segmented bar.
2026-04-16
Features
New workspace settings page with a Block Public Tiles toggle.
Email notifications are now sent on eval completion.
2026-04-15
Features
tile publishing now uses workspace-level API tokens.
2026-04-13
Features
tile lists can now be sorted by score, security, and impact.
API-key authentication now accepted on
GET /users/me.
2026-04-09
Features
Codex agent now available for eval runs.
2026-04-08
Features
Username now visible in the user dropdown menu.
Login and signup pages refreshed with a new tessellated logo background.
2026-04-07
Features
Improved the error messages when tile moderation fails.
Bug Fixes
tiles with no score now show a Pending badge instead of a 404.
2026-04-02
Features
Authentication-provider buttons now use a consistent "Continue with" label.
Removed the in-product tile-generation flow and the Request Docs CTAs.
2026-04-01
Features
Directory fixtures now supported in the V2 eval-run API.
2026-03-31
Features
Custom login and signup screens replace the previous hosted auth experience.
CLI device-auth flow added so
tessl loginworks from the terminal.
2026-03-30
Features
New API-key management UI rolled out.
Failed security reviews now appear in the UI.
Install CTA is now hidden on tiles and skills with critical-severity security findings.
Email invitations are now rate-limited.
Last updated

