[{"slug":"ZV-2026-1963","server_name":"api.proof.holdings","severity":"breaking","title":"api.proof.holdings: Enum value onboarding removed from action_type on create_user_request.","summary":"[risky] Description of create_user_request changed (25% word delta). [breaking] Enum value onboarding removed from action_type on create_user_request. [breaking] Enum value compliance removed from action_type on create_user_request. [risky] Enum value 2fa added to action_type on create_user_request. [risky] Enum value login added to action_type on create_user_request. [risky] Enum value custom added to action_type on create_user_request. [risky] Enum value confirmation added to action_type on create_user_request. [risky] Enum value authorization added to action_type on create_user_request. [breaking] Type of action_context on create_user_request changed string → object. [safe] Description of get_api_key_usage changed (9% word delta). [safe] Description of regenerate_api_key changed (22% word delta).","changes":[{"kind":"description_changed","tool":"create_user_request","after":"Create a new verification request to ask another user to share verified assets. Each asset is an object naming its type, e.g. { \"type\": \"email\" }.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), or sign in with start_login — a session opens this tool — then call this tool again.","before":"Create a new verification request to ask another user to share verified assets.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), or sign in with start_login — a session opens this tool — then call this tool again.","detail":"Description of `create_user_request` changed (25% word delta).","severity":"risky","descriptionDelta":0.25},{"kind":"enum_value_removed","path":"inputSchema.properties.action_type","tool":"create_user_request","before":"onboarding","detail":"Enum value `onboarding` removed from `action_type` on `create_user_request`.","severity":"breaking"},{"kind":"enum_value_removed","path":"inputSchema.properties.action_type","tool":"create_user_request","before":"compliance","detail":"Enum value `compliance` removed from `action_type` on `create_user_request`.","severity":"breaking"},{"kind":"enum_value_added","path":"inputSchema.properties.action_type","tool":"create_user_request","after":"2fa","detail":"Enum value `2fa` added to `action_type` on `create_user_request`.","severity":"risky"},{"kind":"enum_value_added","path":"inputSchema.properties.action_type","tool":"create_user_request","after":"login","detail":"Enum value `login` added to `action_type` on `create_user_request`.","severity":"risky"},{"kind":"enum_value_added","path":"inputSchema.properties.action_type","tool":"create_user_request","after":"custom","detail":"Enum value `custom` added to `action_type` on `create_user_request`.","severity":"risky"},{"kind":"enum_value_added","path":"inputSchema.properties.action_type","tool":"create_user_request","after":"confirmation","detail":"Enum value `confirmation` added to `action_type` on `create_user_request`.","severity":"risky"},{"kind":"enum_value_added","path":"inputSchema.properties.action_type","tool":"create_user_request","after":"authorization","detail":"Enum value `authorization` added to `action_type` on `create_user_request`.","severity":"risky"},{"kind":"input_type_changed","path":"inputSchema.properties.action_context","tool":"create_user_request","after":"object","before":"string","detail":"Type of `action_context` on `create_user_request` changed string → object.","severity":"breaking"},{"kind":"description_changed","tool":"get_api_key_usage","after":"Get per-API-key usage for a given key id: verification counts by type/channel/status, plus verification-request/confirmation/authorization totals, and attribution context (attribution_cutoff_at, attributed_fraction). The counts cover the key and every key it replaced (api_key.replaced_key_ids). Counts only — no recipient identifiers. Scoped to the authenticated account; an API-key caller may read only its own key.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), or sign in with start_login — a session opens this tool — then call this tool again.","before":"Get per-API-key usage for a given key id: verification counts by type/channel/status, plus verification-request/confirmation/authorization totals, and attribution context (attribution_cutoff_at, attributed_fraction). Counts only — no recipient identifiers. Scoped to the authenticated account; an API-key caller may read only its own key.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), or sign in with start_login — a session opens this tool — then call this tool again.","detail":"Description of `get_api_key_usage` changed (9% word delta).","severity":"safe","descriptionDelta":0.09090909090909094},{"kind":"description_changed","tool":"regenerate_api_key","after":"Regenerate an API key: issues a new key (a new id and secret) with the same name, environment, scopes and project. The old key stops working immediately; use the id in this response from now on. The new key lists the old one in replaced_key_ids, so its requests and usage stay with it. The new secret is returned ONLY in this response. Note: the secret will be visible in the AI conversation context.\n\nAgent usage: This operation requires 2FA. Before calling, complete the 2FA flow: (1) call start_2fa with action_type \"api_key_regenerate\", (2) wait for user to verify the code, (3) poll get_2fa_status until \"verified\", (4) then call regenerate_api_key.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), or sign in with start_login — a session opens this tool — then call this tool again.","before":"Regenerate an API key, issuing a new secret while keeping the same ID and settings. The old key stops working immediately. The new secret is returned ONLY in this response. Note: the secret will be visible in the AI conversation context.\n\nAgent usage: This operation requires 2FA. Before calling, complete the 2FA flow: (1) call start_2fa with action_type \"api_key_regenerate\", (2) wait for user to verify the code, (3) poll get_2fa_status until \"verified\", (4) then call regenerate_api_key.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), or sign in with start_login — a session opens this tool — then call this tool again.","detail":"Description of `regenerate_api_key` changed (22% word delta).","severity":"safe","descriptionDelta":0.22340425531914898}],"published_at":"2026-10-08T10:46:17.645Z"},{"slug":"ZV-2026-1676","server_name":"api.proof.holdings","severity":"breaking","title":"api.proof.holdings: Tool add_challenger was removed.","summary":"[breaking] Tool add_challenger was removed. [breaking] Tool invite_challenger was removed. [breaking] Tool list_challengers was removed. [breaking] Tool remove_challenger was removed. [breaking] Tool trigger_drill was removed. [safe] Description of create_identity_challenge changed (20% word delta). [breaking] Field hitl_id was removed from create_identity_challenge input; consumers still sending it may be rejected or silently ignored. [breaking] Field challenger_id was removed from create_identity_challenge input; consumers still sending it may be rejected or silently ignored. [breaking] New required field circle_id on create_identity_challenge; requests without it will fail. [breaking] New required field member_id on create_identity_challenge; requests without it will fail. [risky] Description of get_current_user changed (38% word delta). [risky] Description of get_identity_challenge changed (26% word delta).","changes":[{"kind":"tool_removed","tool":"add_challenger","detail":"Tool `add_challenger` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"invite_challenger","detail":"Tool `invite_challenger` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"list_challengers","detail":"Tool `list_challengers` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"remove_challenger","detail":"Tool `remove_challenger` was removed.","severity":"breaking"},{"kind":"tool_removed","tool":"trigger_drill","detail":"Tool `trigger_drill` was removed.","severity":"breaking"},{"kind":"description_changed","tool":"create_identity_challenge","after":"Create a Proof-Me cross-channel identity challenge (CONFIRM) for an enrolled Circle member. The account holder approves/denies on a channel different from the one the suspicious contact reached the member on.\n\nAgent usage: poll get_identity_challenge with the returned ID until it leaves pending (confirmed, denied, cancelled, failed, expired or revoked).\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), then call this tool again. start_login does NOT open this tool.","before":"Create a Proof-Me cross-channel identity challenge (CONFIRM) for an enrolled challenger. The account holder approves/denies on a channel different from the one the suspicious contact reached the challenger on.\n\nAgent usage: poll get_identity_challenge with the returned ID until it reaches a terminal state (active = confirmed, denied, expired).\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), then call this tool again. start_login does NOT open this tool.","detail":"Description of `create_identity_challenge` changed (20% word delta).","severity":"safe","descriptionDelta":0.19999999999999996},{"kind":"input_property_removed","path":"inputSchema.properties.hitl_id","tool":"create_identity_challenge","before":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":"HITL config that holds the challenger"},"detail":"Field `hitl_id` was removed from `create_identity_challenge` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"input_property_removed","path":"inputSchema.properties.challenger_id","tool":"create_identity_challenge","before":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":"Enrolled challenger initiating the check"},"detail":"Field `challenger_id` was removed from `create_identity_challenge` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"input_required_added","path":"inputSchema.properties.circle_id","tool":"create_identity_challenge","after":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":"Circle that holds the member"},"detail":"New required field `circle_id` on `create_identity_challenge`; requests without it will fail.","severity":"breaking"},{"kind":"input_required_added","path":"inputSchema.properties.member_id","tool":"create_identity_challenge","after":{"type":"string","pattern":"^[0-9a-fA-F]{24}$","description":"Enrolled Circle member initiating the check"},"detail":"New required field `member_id` on `create_identity_challenge`; requests without it will fail.","severity":"breaking"},{"kind":"description_changed","tool":"get_current_user","after":"Get the signed-in user's account details, plan and settings. Needs a login session: call start_login, then wait_for_login until it reports success. An API key alone cannot read this — for the key's own account use get_self_api_key or get_settings.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), or sign in with start_login — a session opens this tool — then call this tool again.","before":"Get the current authenticated user. Returns account details, plan, and settings for the API key owner.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), or sign in with start_login — a session opens this tool — then call this tool again.","detail":"Description of `get_current_user` changed (38% word delta).","severity":"risky","descriptionDelta":0.3846153846153846},{"kind":"description_changed","tool":"get_identity_challenge","after":"Get a Proof-Me identity challenge by ID. Returns its status (pending, confirmed, denied, cancelled, failed, expired, revoked or suspended), the channel the CONFIRM ran on, and — once the person being checked decided — the proof token and its proof_id. Poll this for resolution.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), then call this tool again. start_login does NOT open this tool.","before":"Get a Proof-Me identity challenge by ID. Returns status, the channel the CONFIRM ran on, and the proof token once confirmed. Poll this for resolution.\n\nACCESS: needs a Proof account. Authenticate this client (Claude Code: /mcp → Authenticate), then call this tool again. start_login does NOT open this tool.","detail":"Description of `get_identity_challenge` changed (26% word delta).","severity":"risky","descriptionDelta":0.26415094339622647}],"published_at":"2026-10-01T17:27:18.389Z"}]