October 2026 — Direct attachment transfers
Added checksum-bound PUT uploads and authorized streaming downloads, with SDK uploadFile/downloadFile and continued small-file JSON compatibility. New unused uploads become eligible for asynchronous cleanup after 24 hours.
October 2026 — First-release contract corrections
Replay and attachment uploads now enforce the Idempotency-Key required by the initial specification. Preview clients must pass that header; the SDK replay method requires its options argument and adds attachments.upload/download. Responses and accepted mutations commit together. Repeated requests retain the original delivery result or attachment ID; conflicting requests return 409. Replay invalidates results from previous workers.
July 2026 — Developer platform preview
Introduced tenant-scoped service credentials, mailbox and message APIs, idempotent sending, canonical events, signed webhooks, replay, the TypeScript SDK, and the integrations portal.
- Plan-controlled per-minute and daily request limits
- HMAC-SHA256 signatures and five-minute replay tolerance
- At-least-once delivery with retry and reconciliation
- Versioned OpenAPI 3.1 contract
Compatibility policy
New optional fields, resources, event types, and enum values can be added within v1. Consumers should ignore unknown fields and handle unknown event types safely.