Changelog
What shipped, when. Everything here is deployed, not planned.
When an app is not connected or its sign-in expires, Passport now gives the AI client a secure Connect or Reconnect action for the right person. Clients with URL interaction support can show it natively; others receive a clear Passport link and retry guidance. Delegated agents can hand the link to their fixed human, while autonomous agents remain unable to create identity-ambiguous sign-ins.
Passport Desktop can now scan supported local AI-client configuration with explicit consent, group the MCPs it finds, capture owner-provided purpose, and guide safe migration behind Passport. Enterprise admins get a privacy-minimized action queue with reporting coverage, approval, migration, and removal decisions; members can execute requested removal locally with an exact backup and sibling-entry verification. Configured does not mean used: the product labels that distinction and retains findings through scan failures.
Free and Pro now open into a streamlined Apps, AI Clients, Activity, safety, and setup experience. Enterprise admins keep that same personal workflow and get a separate workspace control plane for catalog policy, people and teams, client fleet rules, guardrails, SSO, SCIM, and SIEM. Plan enforcement lives on the server, so a downgrade retains configuration without leaving Enterprise controls active.
Passport now publishes and consumes Client ID Metadata Documents for secretless OAuth client identity, while retaining Dynamic Client Registration and pre-registered client fallbacks. Redirects, metadata fetches, callback state, and plan/config changes are validated fail-closed before credentials or authorization codes leave Passport.
Newly connected MCPs start visible in every AI client, one switch changes an app atomically across current and future clients, and per-client edits no longer risk overwriting concurrent changes. Failed loads preserve the last confirmed state instead of appearing hidden, switch geometry is centered, and the low-value Connect all action is gone.
Terminal agents and CI now get a production CLI for login, namespaced discovery, governed calls, connections, resources, and prompts through the same policy and audit pipeline as MCP. The signed-in web app includes a four-step activation path and full CLI setup; doctor, shell completion, deterministic JSON, and verified package checks round out the operator experience.
Member and admin catalog cards now distinguish official-registry identity, dated point-in-time MCP verification, credential or vendor gates, reviewed permission examples, and observable definition scans. An offline registry canary validates every committed entry without pretending a weekly probe is continuous uptime.
Production deployments with email verification disabled are now provider-only: typing an address can never mint a session or workspace. CI enforces the auth and response-header posture, while scheduled drills exercise backup restoration, secret decryption, two-replica Postgres coherence, and concurrent gateway load.
The free tier now includes 5 members (up from 3) with the full core product: gateway, passes, audit trail, and the desktop app. The paid tiers are renamed Pro ($15 per member per month) and Enterprise ($30, adding SSO, SCIM, and SIEM streaming), both self-serve with a card and no sales call.
Passport auto-nominates connectors from the official MCP Registry: domain-verified vendor namespaces are probed live, tool schemas are scanned for injection text, and each toolset is hash-pinned so a silently changed server is caught by the weekly re-verify. New entries only ship when the vendor shows real adoption. The public catalog gained tier filters and per-category counts.
Claude, Claude Code, Cursor, VS Code, Codex, ChatGPT, and Claude.ai are all first-class. Five install with one click (config written natively, or through the client's own CLI); ChatGPT and Claude.ai get everything short of the paste: the connector address lands on your clipboard and one button opens the right settings page. Desktop v0.2.10.
Joining a workspace is now the workspace's decision: invite-only by default, with an opt-in company-domain policy. Emailed sign-in links are single-use and re-checked at redemption, so a link can never outrank the current policy.
Demo sandboxes are fully gated out of production deployments. Adding GitHub from the catalog connects the real GitHub MCP endpoint, never canned data. Covered by a dedicated end-to-end test in CI.
Verified email sign-in (a typed address is a claim, not an identity), two-phase workspace signup, transactional email, Stripe billing with a free tier, and this public site, including the browsable MCP catalog with per-connector pages.
A tiered brand-asset pipeline (curated marks → vendor-published icons → normalized favicons) gives every catalog entry a real mark, bundled offline into the desktop app and served static on the web. CI fails if any connector regresses to a bare-letter tile.
Cursor runs one bridge per window; all of them share a rotating single-use credential. Exchanges now serialize across processes and adopt a sibling's rotation instead of replaying it, fixing the 'phantom reconnect' loop.
Passport's gateway is a full OAuth 2.1 protected resource + authorization server: hosted clients connect by pasting one workspace URL, then approving in the browser. Grants are rotating and per-member; no static tokens to copy or leak.
The desktop app updates itself over a signed release feed (quiet in-app banner, one click). The bridge pushes toolset changes to running AI clients within ~15 seconds; no client restart when an admin approves a new MCP.
Prometheus metrics, gateway error-rate paging, a load baseline, an ops runbook with a rehearsed 99-second rollback, and a CI security gate (secret scanning, dependency audit, SAST) on every change.
Connectors carry their domain-verified reverse-DNS identity, source repository, version, and declared credential inputs from the official registry's server.json, matched by endpoint URL so identity can't be spoofed by republishers.
Deactivating a person signs them out everywhere and drops their connected-account grants. Encrypted-at-rest key rotation with a rekey tool, backup + tested restore drills, SSRF guards on every admin-supplied URL, and shared rate limits across the public surface.
Multi-tenant cloud on managed infrastructure: the governed gateway, per-member OAuth brokering (sign in once, brokered to every AI client), read-only passes, guardrails, audit trail, and the desktop app.