Back to Home

Product

Changelog

Every change that affects how you build against gork.email, newest first. Endpoint names and behavior, not marketing.

Signed webhooks, replay-resistant console auth, and a fully documented API

A security pass across the internal auth boundary, plus the OpenAPI spec brought in line with what the API actually serves.

  • securityInternal console requests are now signed over method, path, organization, user, timestamp, and a SHA-256 hash of the body (v2 scheme). Previously the signature covered only org/user/timestamp, so a captured header could be replayed against any internal route for the length of the freshness window.
  • securityRemoved the DATABASE_URL fallback as an HMAC signing key. Internal requests now fail closed if INTERNAL_SYSTEM_SECRET is not configured, rather than silently signing with the database URL.
  • securityRemoved the legacy timestamp-only signature on the system-mail route, which had no rate limit and could be used as a spam relay from your own domain. That route is now rate limited per IP.
  • securityInbound SNS messages are signature-verified against the certificate named in the envelope, and the test-only unsigned bypass now requires an explicit environment flag read from worker bindings — never from the payload, so a sender cannot smuggle it in.
  • securityThe console sign-in surface refuses to start in production without its Turnstile secret, instead of running with CAPTCHA silently disabled.
  • addedDocumented 16 previously-undocumented endpoints, including all of /v1/drafts, GET /v1/attachments/{id}, GET /v1/analytics, GET /v1/inboxes/check, GET /v1/messages/{id}/raw, and the message/organization write routes. An OpenAPI parity test now fails if the spec and the real routers disagree in either direction.
  • addedEvery error code the API can emit is now a documented enum on the error envelope, so a client can branch on insufficient_credits vs limit_reached vs insufficient_scope instead of parsing messages.
  • addedgork_send_email and gork_reply_email accept an idempotencyKey on both the hosted MCP server and the @gork/sdk MCP server, so a retry after a timeout replays the original message instead of delivering a duplicate.
  • addedMCP tool errors now carry the machine-readable API error code to the model, so an agent can distinguish a quota reset from a top-up from a missing scope.
  • fixedThe OpenAPI spec served from the console is now kept in sync with the backend's copy; the two had drifted and nothing enforced parity.