Changelog
Version history, breaking changes, deprecations and migration
guides. Semver: breaking changes bump the major version.
v0.2.0
current2026-08-30
new
- API Key Management — per-key call counts and last-used tracking on the institution dashboard.
- Sandbox environment —
npm run sandbox(SANDBOX=1): in-memory DB, seeded demo actors,POST /api/sandbox/reset, daily auto-reset. - Public developer site — integration guides (Node, Python, PHP, Java, Flutter), pricing tiers and this changelog.
breaking
- Audit table columns renamed for PDPP Art. 28 pseudonymization:
consent_audits.user_id → user_hash,consent_audits.institution_id → inst_hash(same fordata_access_logs). Databases created before v0.2.0 have their audit ledger rebuilt on first boot. Queries that referenced the raw columns must switch to the digest columns.
v0.1.0
2026-08-29
- Core consent engine: request → approve → verify → revoke → expire.
- Signed, hash-chained, append-only audit ledger (Ed25519).
- AES-256-GCM token encryption at rest, LRU+TTL validation cache.
- Bilingual dashboards (user / institution / admin).
- SMS short-code consent (Amharic), HMAC webhooks, sovereign mode.
- PDPP compliance layer: erasure, unbundled consent, automation disclosure + objection, 72h breach pipeline.
Deprecation & migration policy
Endpoints are deprecated for at least two minor releases before removal and announced here. Migration guides accompany every breaking change. Subscribe to the RSS feed to track releases.