[{"slug":"ZV-2026-1387","server_name":"mcp.victano.com","severity":"breaking","title":"mcp.victano.com: Type of code on connect_verify changed string → unset.","summary":"[risky] Description of connect_start changed (54% word delta). [risky] Optional field language was added to connect_start; may shift model behaviour. [risky] Description of connect_verify changed (83% word delta). [safe] Field code on connect_verify is no longer required. [breaking] Type of code on connect_verify changed string → unset. [risky] Default of code on connect_verify changed unset → null. [risky] Optional field session was added to get_opportunity; may shift model behaviour. [risky] Optional field session was added to get_workflow; may shift model behaviour. [safe] Description of list_workflows changed (9% word delta). [risky] Optional field session was added to list_workflows; may shift model behaviour. [risky] Optional field session was added to search_opportunities; may shift model behaviour. [risky] Optional field session was added to whoami; may shift model behaviour. [safe] Prompt job-bid-ready-pack was added. [safe] Prompt job-grant-match was added. [safe] Prompt job-monday-pipeline was added.","changes":[{"kind":"description_changed","tool":"connect_start","after":"Begin authentication. Send the user's work email and your conversation's language ('lt', 'en'…); Victano mails a confirm link and a code. Then call connect_verify(request_id) at once: it waits for the click. No card needed.","before":"Begin authentication. Send the user's work email; Victano mails them a six-digit code valid for 15 minutes and returns a request_id. Ask the user for the code, then call connect_verify with both. Nothing is charged and no card is needed.","detail":"Description of `connect_start` changed (54% word delta).","severity":"risky","descriptionDelta":0.5434782608695652},{"kind":"input_property_added","path":"inputSchema.properties.language","tool":"connect_start","after":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Language","default":null},"detail":"Optional field `language` was added to `connect_start`; may shift model behaviour.","severity":"risky"},{"kind":"description_changed","tool":"connect_verify","after":"Finish signing in: call right after connect_start with no code; it waits for the Confirm click (if it returns waiting, call again; never ask the user). Or pass the code they read you. Returns an api_key (shown once) and, without a connection session, a `session` to pass on every later call.","before":"Complete authentication with the request_id from connect_start and the six-digit code the user received. On success this session is authenticated immediately, with no reconnect, and the full toolset appears. Save the returned api_key into this client's MCP config as an Authorization: Bearer header so future conversations start connected. The key is shown once and cannot be recovered.","detail":"Description of `connect_verify` changed (83% word delta).","severity":"risky","descriptionDelta":0.8311688311688312},{"kind":"input_required_removed","path":"inputSchema.required.code","tool":"connect_verify","detail":"Field `code` on `connect_verify` is no longer required.","severity":"safe"},{"kind":"input_type_changed","path":"inputSchema.properties.code","tool":"connect_verify","after":"unset","before":"string","detail":"Type of `code` on `connect_verify` changed string → unset.","severity":"breaking"},{"kind":"default_changed","path":"inputSchema.properties.code","tool":"connect_verify","after":null,"detail":"Default of `code` on `connect_verify` changed unset → null.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.session","tool":"get_opportunity","after":{"type":"string","description":"The `session` value connect_verify returned, when this client keeps no connection session. Pass it on every Victano call in this conversation; omit it when the user connected with Sign in (OAuth) or a key."},"detail":"Optional field `session` was added to `get_opportunity`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.session","tool":"get_workflow","after":{"type":"string","description":"The `session` value connect_verify returned, when this client keeps no connection session. Pass it on every Victano call in this conversation; omit it when the user connected with Sign in (OAuth) or a key."},"detail":"Optional field `session` was added to `get_workflow`; may shift model behaviour.","severity":"risky"},{"kind":"description_changed","tool":"list_workflows","after":"The playbook library: how bid professionals actually run this work, from the weekly scan through qualification, eligibility screening, reading a specification, clarification questions, and the proposal skeleton. READ A WORKFLOW BEFORE IMPROVISING A PROCESS. Whole jobs (`jobs`) come first. Pass persona='consultant' to see the multi-client ones. Follow with get_workflow.","before":"The playbook library: how bid professionals actually run this work, from the weekly scan through qualification, eligibility screening, reading a specification, clarification questions, and the proposal skeleton. READ A WORKFLOW BEFORE IMPROVISING A PROCESS. Pass persona='consultant' to see the multi-client ones. Follow with get_workflow.","detail":"Description of `list_workflows` changed (9% word delta).","severity":"safe","descriptionDelta":0.0888888888888889},{"kind":"input_property_added","path":"inputSchema.properties.session","tool":"list_workflows","after":{"type":"string","description":"The `session` value connect_verify returned, when this client keeps no connection session. Pass it on every Victano call in this conversation; omit it when the user connected with Sign in (OAuth) or a key."},"detail":"Optional field `session` was added to `list_workflows`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.session","tool":"search_opportunities","after":{"type":"string","description":"The `session` value connect_verify returned, when this client keeps no connection session. Pass it on every Victano call in this conversation; omit it when the user connected with Sign in (OAuth) or a key."},"detail":"Optional field `session` was added to `search_opportunities`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.session","tool":"whoami","after":{"type":"string","description":"The `session` value connect_verify returned, when this client keeps no connection session. Pass it on every Victano call in this conversation; omit it when the user connected with Sign in (OAuth) or a key."},"detail":"Optional field `session` was added to `whoami`; may shift model behaviour.","severity":"risky"},{"kind":"prompt_added","tool":"job-bid-ready-pack","after":"job-bid-ready-pack","detail":"Prompt `job-bid-ready-pack` was added.","severity":"safe"},{"kind":"prompt_added","tool":"job-grant-match","after":"job-grant-match","detail":"Prompt `job-grant-match` was added.","severity":"safe"},{"kind":"prompt_added","tool":"job-monday-pipeline","after":"job-monday-pipeline","detail":"Prompt `job-monday-pipeline` was added.","severity":"safe"}],"published_at":"2026-09-24T09:44:17.219Z"}]