Changelog

What shipped.

New capabilities and improvements across the Instaship console, CLI, API, and MCP server.

New

OAuth-secured MCP server

Instaship lifecycle and app-management capabilities are now available through MCP. OAuth clients get PKCE, rotating refresh tokens, and a consent screen for action, app, and environment scopes. MCP can inspect environment variable names and secret classifications but never returns their values; scoped API keys remain available for trusted headless clients.

New

Scoped app management

API keys can now receive app-management authority to create apps and update default provider manifests without gaining access to unrelated apps or bypassing workspace roles.

Improved

Mint credits at $0.25

Every new environment now costs $0.25 USD. Reuse and cleanup remain free, with no seat charge for people, agents, or CI.

New

Scoped API keys

Keys now carry explicit access rules for actions, apps, and environment types. The server enforces the same policy for the console, CLI, CI, and agents.

Custody

Workspace-level handoff

Custody now has a dedicated workspace surface. One bundle returns every provider credential and permanently ends Instaship access.

New

Apps as first-class context

Environments, minting, and provider defaults now follow the selected app. Keys, custody, usage, and credits remain workspace-wide.

Improved

Checkpoint auto-resume

Runs pause when a provider needs browser approval and resume from the parked step after approval. No second mint is required.

Improved

Vercel variable sync

Environment variables can sync directly to a selected Vercel target as an opt-in step during minting.

New

Evidence on every step

Provisioning records ordered status, errors, workflow references, duration, and evidence for each provider step.