Skip to content
Developer docs Changelog

Changelog

What changed in the API, webhooks, MCP server and command line, newest first.

Updated September 26, 2026

Webhook signatures cover the timestamp

  • Every webhook and REST hook delivery now carries x-commentgate-signature-v2: v2=<hex>, the HMAC-SHA256 of <timestamp>.<raw body> with x-commentgate-timestamp as the timestamp. Because the timestamp is signed, a captured delivery cannot be replayed later with a new one.
  • Verify x-commentgate-signature-v2 and reject any delivery whose timestamp is more than 5 minutes old. The Node.js, Express and Python samples do both.
  • Deprecated: x-commentgate-signature (sha256= over the body alone) is still sent for one release so existing receivers keep working. It is removed in the next release.

Settings that cover every account

  • A key whose creator is limited to some accounts now gets forbidden from guidance, protections and subscribing a hook, because each of those covers every account. Reading still works, within the creator's accounts.

Webhook comment status matches the API

  • Webhook and REST hook bodies now name a comment that was left up visible in comment.status, the same as the REST API. Before, they said allowed.
  • Deprecated: comment.legacy_status still carries the old name (allowed, hidden, deleted, review or pending) for one release so existing integrations keep working. Switch to comment.status; legacy_status is removed in the next release.

Developer docs

  • The developer docs moved to one page per topic. The endpoint, field, event, MCP tool and CLI references are now generated from the code, so they always match what runs. Old /developers#section links still lead to the right page.
  • The event catalogue lists every webhook event with an example body, including ad.health and insights.weekly.

API v1, webhooks, MCP server and command line