Changelog

A chronological log of additions, changes, fixes, and deprecations to the SpireStock API and developer platform.

v1.3.0

Desktop Sign-In & Authentication Hardening

  • AddedDesktop sign-in handoff. POST /auth/desktop/code mints a single-use code for an already-authenticated session, and POST /auth/desktop/exchange trades that code plus the caller's own state value for a session. Codes are 256-bit, expire after two minutes, and are redeemed by a conditional UPDATE so a code can never be spent twice.
  • AddedGET /downloads/desktop/version and GET /downloads/desktop/mac report the current macOS build, read from the signed release manifest rather than a constant.
  • ChangedAccount lockout now applies to every authentication method. Five failed attempts locks the account for 30 minutes, and OTP, magic link and passkey all honour it — previously only password login checked, so a locked account could still be entered another way. A locked account returns 423.
  • ChangedPOST /auth/otp/request and POST /auth/magic-link/request are now rate limited, and every auth limiter is keyed on the target account rather than the caller's IP. Limits are shared across API instances, so they no longer reset on deploy.
  • ChangedPasskey login requires user verification (biometric or PIN), not just user presence, and rejects an authenticator whose signature counter goes backwards. Synced passkeys that report a permanent counter of zero are unaffected.
  • ChangedOTP verification returns one message for every failure. Previously “no OTP found” and “invalid OTP” were distinguishable, which revealed whether an address had a code outstanding.
  • FixedInvite and password-reset links are no longer redeemable at /auth/magic-link/verify for a full session. They now carry a purpose and are exchanged at POST /auth/magic-link/set-password/:token, which sets a password and returns no token.
  • FixedOne-time codes, OTPs and magic links are deleted seven days after they expire. Nothing previously removed them.
v1.2.1

API Key Notifications & Operator Roles

  • AddedWorkspace admins are emailed when an API key is created or revoked, so a key minted by one admin is visible to the rest.
  • ChangedPlatform operator routes are gated by role. Destructive operations require an explicit write role rather than any authenticated platform session.
  • FixedA workspace granted a plan by an operator no longer stays billing read-only, which had kept writes refused with 402 after the grant.
v1.2.0

MCP Server, Machine Access & Email Webhooks

  • Added@spirestock/mcp-server on npm — a Model Context Protocol server that connects Claude, Cursor and other AI tools directly to a workspace using an API key. See the MCP guide for the tool list and setup.
  • AddedResend email webhook with delivery tracking and an automatic suppression list, so hard bounces stop being retried.
  • AddedMulti-provider SMTP failover for platform email: a provider outage falls through to the next rather than dropping the message.
  • ChangedMachine access is plan-gated. A workspace on an active trial can use API keys; once the trial expires, key-authenticated requests return 402 with the same shape as the billing read-only response, including reads.
  • ChangedRepeated bad API keys from one address are throttled — 30 failures in 15 minutes returns 429 until the window clears.
  • FixedCorrected field mappings in the MCP account, product and master tools, and four defects found in an adversarial review of that surface.
v1.1.2

API Key Limits & Referral Endpoints

  • AddedReferral endpoints: GET /referral/lookup/:code and POST /referral/scan/:code are public and rate limited; GET /referral/me returns the calling workspace's own code and stats.
  • ChangedAn organization may hold at most 50 active API keys. Creating one beyond the cap returns 400 — revoke an unused key first.
  • FixedClosed two cases where a revoked or out-of-scope API key was still accepted.
v1.1.1

Session Integrity & Endpoint Fixes

  • FixedLogging out, changing your password, or signing in again now genuinely revokes the previous session token. This was already the documented behaviour but was not enforced, so older tokens kept working.
  • FixedEvery issued token is now unique. Two tokens minted for the same user within the same second used to be identical, so rotating a session in that window left the old token valid.
  • FixedValidation failures raised inside service layers now return their real status (usually 400) instead of 500 Internal Server Error.
  • FixedRepaired report, export and dashboard endpoints that returned 500 on every call, including the SKU sales, performance, product secondary, delivery challan, packing station, truck sheet and amount-to-be-paid exports.
v1.1.0

API Keys & Webhooks

  • AddedAPI key authentication via the X-API-Key header, with read/write and per-resource scopes. Keys skip the Turnstile and single-session constraints that apply to browser JWTs.
  • AddedCustomer webhooks for order.created, order.delivered and user.created, with HMAC-SHA256 signatures over {timestamp}.{body}.
  • AddedWebhook management endpoints under /developer: create, update, delete, rotate signing secret, send a test delivery, and read the delivery log.
  • AddedAutomatic delivery retries with exponential backoff, and an SSRF guard that rejects webhook URLs pointing at private, loopback or reserved addresses.
v1.0.0

Initial Release

  • AddedSpireStock REST API v1 with JWT authentication
  • AddedOrder management endpoints (CRUD + status flow)
  • AddedUser management (distributors, retailers, employees)
  • AddedProduct catalog with variants
  • AddedDashboard statistics and analytics
  • AddedExport endpoints (XLSX, PDF) for orders, users, sales, attendance
  • AddedWorkspace configuration and member management
  • AddedMulti-tenant architecture with organization scoping
  • AddedRate limiting (120 req/min general, 20/15min login)
  • AddedOpenAPI 3.0 specification with Swagger UI
  • AddedDeveloper portal with interactive documentation