[{"slug":"ZV-2026-1038","server_name":"kairossignal.com","severity":"breaking","title":"kairossignal.com: amount on topup_credits narrowed to a closed enum (20, 99); previously valid values may now be rejected.","summary":"[risky] Description of topup_credits changed (54% word delta). [breaking] amount on topup_credits narrowed to a closed enum (20, 99); previously valid values may now be rejected.","changes":[{"kind":"description_changed","tool":"topup_credits","after":"Add credits. Card (one call): {\"method\": \"stripe\", \"amount\": N} where N is $20 or $99 — returns a Stripe checkout_url already bound to your api_key, and credits post automatically once Stripe confirms payment at $1 = 1 credit. No human step and no wallet needed. USDC on Base ({\"method\": \"usdc\"}) is also accepted but requires more work: verify your sender first via POST /v1/credits/crypto/challenge and /verify with X-API-Key, sign the returned challenge with your own EOA, then pass the verified from_address and send only after a successful quote — credit requires finalized Base evidence. Instructions: https://kairossignal.com/docs/crypto.html","before":"Request a USDC quote only after verifying the sender through POST /v1/credits/crypto/challenge and /verify with X-API-Key. Sign the returned challenge using your own EOA wallet. Instructions: https://kairossignal.com/docs/crypto.html. Supply the verified from_address; send only after a successful quote. Credit requires finalized Base evidence. Alternatively, obtain a Stripe checkout link.","detail":"Description of `topup_credits` changed (54% word delta).","severity":"risky","descriptionDelta":0.5402298850574713},{"kind":"enum_narrowed","path":"inputSchema.properties.amount","tool":"topup_credits","after":"enum[20,99]","before":"open","detail":"`amount` on `topup_credits` narrowed to a closed enum (20, 99); previously valid values may now be rejected.","severity":"breaking"}],"published_at":"2026-09-14T03:00:15.857Z"},{"slug":"ZV-2026-0975","server_name":"kairossignal.com","severity":"breaking","title":"kairossignal.com: Tool get_zk_provenance was removed.","summary":"[breaking] Tool get_zk_provenance was removed.","changes":[{"kind":"tool_removed","tool":"get_zk_provenance","detail":"Tool `get_zk_provenance` was removed.","severity":"breaking"}],"published_at":"2026-09-11T13:12:14.309Z"},{"slug":"ZV-2026-0756","server_name":"kairossignal.com","severity":"breaking","title":"kairossignal.com: Field record_id was removed from verify_footprint input; consumers still sending it may be rejected or silently ignored.","summary":"[risky] Description of verify_footprint changed (97% word delta). [breaking] Field record_id was removed from verify_footprint input; consumers still sending it may be rejected or silently ignored. [breaking] New required field expected_row_sha256 on verify_footprint; requests without it will fail. [breaking] New required field leaf_index on verify_footprint; requests without it will fail. [breaking] New required field stamp_day on verify_footprint; requests without it will fail. [breaking] dataset on verify_footprint narrowed to a closed enum (depin_onchain); previously valid values may now be rejected.","changes":[{"kind":"description_changed","tool":"verify_footprint","after":"Retained Merkle-membership check for one depin_onchain observation: stamp_day (YYYYMMDD), leaf_index (0-based row in /attestations/batch_<day>.tsv), expected_row_sha256. verified=true ONLY when the row at that index hashes to expected_row_sha256 AND its inclusion path reaches that day's manifest merkle_root. Says nothing about Bitcoin status or upstream accuracy. Other datasets: unsupported (no retained proof).","before":"Return SHA-256 cryptographic verification for a dataset or record","detail":"Description of `verify_footprint` changed (97% word delta).","severity":"risky","descriptionDelta":0.9661016949152542},{"kind":"input_property_removed","path":"inputSchema.properties.record_id","tool":"verify_footprint","before":{"type":"integer","description":"Record ID to verify"},"detail":"Field `record_id` was removed from `verify_footprint` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"input_required_added","path":"inputSchema.properties.expected_row_sha256","tool":"verify_footprint","after":{"type":"string","pattern":"^[0-9a-f]{64}$"},"detail":"New required field `expected_row_sha256` on `verify_footprint`; requests without it will fail.","severity":"breaking"},{"kind":"input_required_added","path":"inputSchema.properties.leaf_index","tool":"verify_footprint","after":{"type":"integer","minimum":0},"detail":"New required field `leaf_index` on `verify_footprint`; requests without it will fail.","severity":"breaking"},{"kind":"input_required_added","path":"inputSchema.properties.stamp_day","tool":"verify_footprint","after":{"type":"string"},"detail":"New required field `stamp_day` on `verify_footprint`; requests without it will fail.","severity":"breaking"},{"kind":"enum_narrowed","path":"inputSchema.properties.dataset","tool":"verify_footprint","after":"enum[depin_onchain]","before":"open","detail":"`dataset` on `verify_footprint` narrowed to a closed enum (depin_onchain); previously valid values may now be rejected.","severity":"breaking"}],"published_at":"2026-09-06T04:39:17.246Z"}]