[{"slug":"ZV-2026-1344","server_name":"popdot.ai","severity":"breaking","title":"popdot.ai: Field requestSponsorUrl was removed from upgrade_trial input; consumers still sending it may be rejected or silently ignored.","summary":"[risky] Optional field publicKey was added to answer_trial_canary; may shift model behaviour. [risky] Field claimError was added to answer_trial_canary output. [risky] Field sigil was added to answer_trial_canary output. [risky] Field sigilId was added to answer_trial_canary output. [risky] Optional field publicKey was added to try_domain; may shift model behaviour. [risky] Field claimError was added to try_domain output. [risky] Field sigil was added to try_domain output. [risky] Field sigilId was added to try_domain output. [risky] Description of upgrade_trial changed (46% word delta). [breaking] Field requestSponsorUrl was removed from upgrade_trial input; consumers still sending it may be rejected or silently ignored. [breaking] New required field sigilId on upgrade_trial; requests without it will fail. [breaking] New required field signature on upgrade_trial; requests without it will fail. [breaking] New required field timestamp on upgrade_trial; requests without it will fail. [breaking] Field humanSponsorUrl was removed from upgrade_trial output; consumers reading it will break.","changes":[{"kind":"input_property_added","path":"inputSchema.properties.publicKey","tool":"answer_trial_canary","after":{"type":"string","description":"Optional, on the call that goes live. Your Ed25519 public key (standard padded base64 of the raw 32 bytes) to claim your agent identity in the same call. Requires headers X-Popdot-Timestamp (Unix seconds) and X-Popdot-Signature: an Ed25519 signature by this key over {timestamp}\\nPOST\\n/api/mcp\\n{sha256 hex of the raw request body}. Omit it to receive a claim token for upgrade_trial instead."},"detail":"Optional field `publicKey` was added to `answer_trial_canary`; may shift model behaviour.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.claimError","tool":"answer_trial_canary","after":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}}},"detail":"Field `claimError` was added to `answer_trial_canary` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.sigil","tool":"answer_trial_canary","after":{"type":"object","required":["sigilId","publicKey","mandateId"],"properties":{"sigilId":{"type":"string"},"agentName":{"type":"string"},"mandateId":{"type":"string"},"publicKey":{"type":"string"}}},"detail":"Field `sigil` was added to `answer_trial_canary` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.sigilId","tool":"answer_trial_canary","after":{"type":"string"},"detail":"Field `sigilId` was added to `answer_trial_canary` output.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.publicKey","tool":"try_domain","after":{"type":"string","description":"Optional, on the call that goes live. Your Ed25519 public key (standard padded base64 of the raw 32 bytes) to claim your agent identity in the same call. Requires headers X-Popdot-Timestamp (Unix seconds) and X-Popdot-Signature: an Ed25519 signature by this key over {timestamp}\\nPOST\\n/api/mcp\\n{sha256 hex of the raw request body}. Omit it to receive a claim token for upgrade_trial instead."},"detail":"Optional field `publicKey` was added to `try_domain`; may shift model behaviour.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.claimError","tool":"try_domain","after":{"type":"object","properties":{"code":{"type":"string"},"message":{"type":"string"}}},"detail":"Field `claimError` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.sigil","tool":"try_domain","after":{"type":"object","required":["sigilId","publicKey","mandateId"],"properties":{"sigilId":{"type":"string"},"agentName":{"type":"string"},"mandateId":{"type":"string"},"publicKey":{"type":"string"}}},"detail":"Field `sigil` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.sigilId","tool":"try_domain","after":{"type":"string"},"detail":"Field `sigilId` was added to `try_domain` output.","severity":"risky"},{"kind":"description_changed","tool":"upgrade_trial","after":"Turn a free trial into your own paid, persistent address in one call, no human required. Claim the agent identity your trial created (a Nascent Sigil, its sigilId came back when the trial went live) by proving you hold your Ed25519 key: send the one-time claimToken, the sigilId, your publicKey, a Unix timestamp and a signature by your key over popdot-claim/1\\n{timestamp}\\n{sigilId}\\n{sha256 hex of claimToken}\\n{publicKey}. The claim token works until 30 days after the trial ends. If you supply a wallet, this also returns the exact USDC-on-Base (x402) challenge to keep the trial's exact URL live on a paid rental. No wallet yet? You still get your identity; fund a USDC wallet on Base later and pay it yourself.","before":"Turn a free trial into your own paid, persistent address in one call, no human required. Redeem the one-time claimToken from try_domain with your BYO Ed25519 publicKey: this mints your unanchored agent identity (a Nascent Sigil) and, if you supply a wallet, returns the exact USDC-on-Base (x402) challenge to keep the trial's exact URL live on a paid rental. No wallet yet? You still get your identity plus an optional URL a human can use to sponsor the upgrade; fund a USDC wallet on Base later and pay it yourself.","detail":"Description of `upgrade_trial` changed (46% word delta).","severity":"risky","descriptionDelta":0.4639175257731959},{"kind":"input_property_removed","path":"inputSchema.properties.requestSponsorUrl","tool":"upgrade_trial","before":{"type":"boolean","description":"Set true to also receive an optional URL a human can use to sponsor the upgrade."},"detail":"Field `requestSponsorUrl` was removed from `upgrade_trial` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"input_required_added","path":"inputSchema.properties.sigilId","tool":"upgrade_trial","after":{"type":"string","description":"The sigilId returned with the claim token. It must match the identity the token belongs to."},"detail":"New required field `sigilId` on `upgrade_trial`; requests without it will fail.","severity":"breaking"},{"kind":"input_required_added","path":"inputSchema.properties.signature","tool":"upgrade_trial","after":{"type":"string","description":"Standard padded base64 of the 64-byte Ed25519 signature over the popdot-claim/1 message."},"detail":"New required field `signature` on `upgrade_trial`; requests without it will fail.","severity":"breaking"},{"kind":"input_required_added","path":"inputSchema.properties.timestamp","tool":"upgrade_trial","after":{"type":"string","description":"Integer Unix seconds, no leading zeros, within 300 seconds of now. Part of the signed message."},"detail":"New required field `timestamp` on `upgrade_trial`; requests without it will fail.","severity":"breaking"},{"kind":"output_property_removed","path":"outputSchema.properties.humanSponsorUrl","tool":"upgrade_trial","before":{"type":"string"},"detail":"Field `humanSponsorUrl` was removed from `upgrade_trial` output; consumers reading it will break.","severity":"breaking"}],"published_at":"2026-09-23T06:57:17.017Z"},{"slug":"ZV-2026-0440","server_name":"popdot.ai","severity":"breaking","title":"popdot.ai: Field steps was removed from rent_domain output; consumers reading it will break.","summary":"[safe] Tool answer_trial_canary was added. [safe] Tool upgrade_trial was added. [risky] Description of rent_domain changed (46% word delta). [risky] Optional field fromAddress was added to rent_domain; may shift model behaviour. [risky] Optional field payerAddress was added to rent_domain; may shift model behaviour. [risky] Optional field payerProof was added to rent_domain; may shift model behaviour. [risky] Optional field payerProofIssuedAt was added to rent_domain; may shift model behaviour. [risky] Optional field paymentId was added to rent_domain; may shift model behaviour. [risky] Optional field txHash was added to rent_domain; may shift model behaviour. [breaking] Field steps was removed from rent_domain output; consumers reading it will break. [breaking] Field message was renamed to credential on rent_domain. [breaking] Field documentation was renamed to next on rent_domain. [breaking] Field estimatedPrice was renamed to payment on rent_domain. [risky] Field provisioning was added to rent_domain output. [risky] Field reason was added to rent_domain output. [risky] Field rental was added to rent_domain output. [risky] Field rentalId was added to rent_domain output. [risky] Description of try_domain changed (64% word delta). [risky] Optional field analyticsConsent was added to try_domain; may shift model behaviour. [risky] Optional field autoSelect was added to try_domain; may shift model behaviour. [risky] Optional field desiredEmotion was added to try_domain; may shift model behaviour. [breaking] New required field goal on try_domain; requests without it will fail. [risky] Optional field inputResponses was added to try_domain; may shift model behaviour. [risky] Optional field preferredSubdomain was added to try_domain; may shift model behaviour. [risky] Optional field target was added to try_domain; may shift model behaviour. [risky] Optional field trialHandle was added to try_domain; may shift model behaviour. [breaking] Field auth was renamed to candidateI","changes":[{"kind":"tool_added","tool":"answer_trial_canary","detail":"Tool `answer_trial_canary` was added.","severity":"safe"},{"kind":"tool_added","tool":"upgrade_trial","detail":"Tool `upgrade_trial` was added.","severity":"safe"},{"kind":"description_changed","tool":"rent_domain","after":"Rent a subdomain, paying per-transaction with USDC on Base (x402). No funded account or stored balance: each rental is a single on-chain payment. Requires agent authentication. Two phases: call once with intentMandateId, domainId, subdomain, and duration (plus payerAddress + payerProof if your wallet is not sigil-bound) to get the exact x402 payment challenge; pay it on Base; then call again with paymentId, txHash, and fromAddress to settle and receive the live rental plus a Web Identity Credential. Request an x402 payment challenge to rent a subdomain. Durations PT1H, PT4H, P1D, P7D, P30D. Returns the exact USDC amount and recipient on Base.","before":"Rent a subdomain, paying per-transaction with USDC on Base (x402). No funded account or stored balance: each rental is a single on-chain payment. Requires agent authentication. Validates the request, then returns the exact HTTP 402 challenge/settle REST sequence to complete the paid rental (payment happens on-chain between the two calls, so it runs over REST). Request an x402 payment challenge to rent a subdomain. Durations PT1H, PT4H, P1D, P7D, P30D. Returns the exact USDC amount and recipient on Base.","detail":"Description of `rent_domain` changed (46% word delta).","severity":"risky","descriptionDelta":0.45882352941176474},{"kind":"input_property_added","path":"inputSchema.properties.fromAddress","tool":"rent_domain","after":{"type":"string","description":"(phase 2) The wallet you paid from (must match the challenge's bound payer)."},"detail":"Optional field `fromAddress` was added to `rent_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.payerAddress","tool":"rent_domain","after":{"type":"string","description":"(phase 1, optional) The 0x wallet you will pay from. Required only when your Sigil has no bound x402 wallet."},"detail":"Optional field `payerAddress` was added to `rent_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.payerProof","tool":"rent_domain","after":{"type":"string","description":"(phase 1, optional) EIP-191 personal_sign signature proving control of payerAddress. Required with payerAddress when no wallet is sigil-bound."},"detail":"Optional field `payerProof` was added to `rent_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.payerProofIssuedAt","tool":"rent_domain","after":{"type":"string","description":"(phase 1, optional) ISO 8601 timestamp of the payerProof, within 5 minutes of the request."},"detail":"Optional field `payerProofIssuedAt` was added to `rent_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.paymentId","tool":"rent_domain","after":{"type":"string","description":"(phase 2) The paymentId returned by the phase-1 challenge."},"detail":"Optional field `paymentId` was added to `rent_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.txHash","tool":"rent_domain","after":{"type":"string","description":"(phase 2) The on-chain transaction hash of your USDC payment on Base."},"detail":"Optional field `txHash` was added to `rent_domain`; may shift model behaviour.","severity":"risky"},{"kind":"output_property_removed","path":"outputSchema.properties.steps","tool":"rent_domain","before":{"type":"array","items":{"type":"object"}},"detail":"Field `steps` was removed from `rent_domain` output; consumers reading it will break.","severity":"breaking"},{"kind":"output_property_renamed","path":"outputSchema.properties.message","tool":"rent_domain","after":"credential","before":"message","detail":"Field `message` was renamed to `credential` on `rent_domain`.","severity":"breaking"},{"kind":"output_property_renamed","path":"outputSchema.properties.documentation","tool":"rent_domain","after":"next","before":"documentation","detail":"Field `documentation` was renamed to `next` on `rent_domain`.","severity":"breaking"},{"kind":"output_property_renamed","path":"outputSchema.properties.estimatedPrice","tool":"rent_domain","after":"payment","before":"estimatedPrice","detail":"Field `estimatedPrice` was renamed to `payment` on `rent_domain`.","severity":"breaking"},{"kind":"output_property_added","path":"outputSchema.properties.provisioning","tool":"rent_domain","after":{"type":"object"},"detail":"Field `provisioning` was added to `rent_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.reason","tool":"rent_domain","after":{"type":"string"},"detail":"Field `reason` was added to `rent_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.rental","tool":"rent_domain","after":{"type":"object"},"detail":"Field `rental` was added to `rent_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.rentalId","tool":"rent_domain","after":{"type":"string"},"detail":"Field `rentalId` was added to `rent_domain` output.","severity":"risky"},{"kind":"description_changed","tool":"try_domain","after":"Launch a memorable public URL for something you built. Free for 24 hours, no signup and no wallet required. Tell it your goal and an https target to point the address at; it opens a trial, asks a short safety question or two, and on a clean pass returns a live subdomain plus a one-time claim token you can redeem for your own agent identity. Use it to demo a deployment with a real address before a paid rental. One trial per agent. Expires in 24 hours.","before":"Get a trial API key. Entry point for new agents: no payment, no human signup. Leads to a free 24-hour trial subdomain after a short screening interview.\n\nProvision a free 24-hour trial subdomain. Two-phase: initiate, answer the screening questions, complete. Returns a live HTTPS URL you control for 24 hours.\n\nCall this with your email and you'll get back the exact step-by-step REST sequence to claim a live trial subdomain (the screening interview is interactive, so it runs over REST). Use it when you need a temporary web address, want to test a deployment with a real URL, or want to show your operator a live demo before a paid rental. One trial per agent. Expires in 24 hours.","detail":"Description of `try_domain` changed (64% word delta).","severity":"risky","descriptionDelta":0.6448598130841121},{"kind":"input_property_added","path":"inputSchema.properties.analyticsConsent","tool":"try_domain","after":{"type":"boolean","description":"Record operator consent to trial analytics for this address."},"detail":"Optional field `analyticsConsent` was added to `try_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.autoSelect","tool":"try_domain","after":{"type":"boolean","description":"Let Popdot AI pick an available subdomain from your goal when you do not provide preferredSubdomain."},"detail":"Optional field `autoSelect` was added to `try_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.desiredEmotion","tool":"try_domain","after":{"enum":["comedy","absurd","playful","edgy","wholesome","professional","trustworthy"],"type":"string","description":"Preferred vibe of the parent domain: comedy, absurd, playful, edgy, wholesome, professional, trustworthy. Unknown values are ignored."},"detail":"Optional field `desiredEmotion` was added to `try_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_required_added","path":"inputSchema.properties.goal","tool":"try_domain","after":{"type":"string","description":"What you built and want to put online, in a sentence (used to name and describe the address)."},"detail":"New required field `goal` on `try_domain`; requests without it will fail.","severity":"breaking"},{"kind":"input_property_added","path":"inputSchema.properties.inputResponses","tool":"try_domain","after":{"type":"array","items":{"type":"object"},"description":"(retry only) Your answers to the safety questions, one { id, response } per requested input."},"detail":"Optional field `inputResponses` was added to `try_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.preferredSubdomain","tool":"try_domain","after":{"type":"string","description":"The subdomain label you want (e.g. 'mydemo'). Omit and set autoSelect:true to have one picked for you."},"detail":"Optional field `preferredSubdomain` was added to `try_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.target","tool":"try_domain","after":{"type":"string","description":"An https URL to point the address at. Content hosting is not yet available, so a live external target is required."},"detail":"Optional field `target` was added to `try_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.trialHandle","tool":"try_domain","after":{"type":"string","description":"(retry only) The trialHandle returned by the first call. Echo it back with your answers."},"detail":"Optional field `trialHandle` was added to `try_domain`; may shift model behaviour.","severity":"risky"},{"kind":"output_property_renamed","path":"outputSchema.properties.auth","tool":"try_domain","after":"candidateId","before":"auth","detail":"Field `auth` was renamed to `candidateId` on `try_domain`.","severity":"breaking"},{"kind":"output_property_renamed","path":"outputSchema.properties.status","tool":"try_domain","after":"claimToken","before":"status","detail":"Field `status` was renamed to `claimToken` on `try_domain`.","severity":"breaking"},{"kind":"output_property_renamed","path":"outputSchema.properties.message","tool":"try_domain","after":"claimTokenExpiresAt","before":"message","detail":"Field `message` was renamed to `claimTokenExpiresAt` on `try_domain`.","severity":"breaking"},{"kind":"output_property_renamed","path":"outputSchema.properties.documentation","tool":"try_domain","after":"domain","before":"documentation","detail":"Field `documentation` was renamed to `domain` on `try_domain`.","severity":"breaking"},{"kind":"output_property_added","path":"outputSchema.properties.expiresAt","tool":"try_domain","after":{"type":"string"},"detail":"Field `expiresAt` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.next","tool":"try_domain","after":{"type":"string"},"detail":"Field `next` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_renamed","path":"outputSchema.properties.steps","tool":"try_domain","after":"questions","before":"steps","detail":"Field `steps` was renamed to `questions` on `try_domain`.","severity":"breaking"},{"kind":"output_property_added","path":"outputSchema.properties.shareMessage","tool":"try_domain","after":{"type":"string"},"detail":"Field `shareMessage` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.subdomain","tool":"try_domain","after":{"type":"string"},"detail":"Field `subdomain` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.trialHandle","tool":"try_domain","after":{"type":"string"},"detail":"Field `trialHandle` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.trialId","tool":"try_domain","after":{"type":"string"},"detail":"Field `trialId` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.trustReceipt","tool":"try_domain","after":{"type":"object"},"detail":"Field `trustReceipt` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.upgrade","tool":"try_domain","after":{"type":"object"},"detail":"Field `upgrade` was added to `try_domain` output.","severity":"risky"},{"kind":"output_property_added","path":"outputSchema.properties.url","tool":"try_domain","after":{"type":"string"},"detail":"Field `url` was added to `try_domain` output.","severity":"risky"}],"published_at":"2026-08-26T22:57:14.618Z"},{"slug":"ZV-2026-0434","server_name":"popdot.ai","severity":"breaking","title":"popdot.ai: Resource popdot://rentals/{agentId} was removed, consumers reading it will break.","summary":"[risky] Optional field emotion was added to search_domains; may shift model behaviour. [breaking] Resource popdot://rentals/{agentId} was removed, consumers reading it will break.","changes":[{"kind":"input_property_added","path":"inputSchema.properties.emotion","tool":"search_domains","after":{"enum":["comedy","absurd","playful","edgy","wholesome","professional","trustworthy"],"type":"string","description":"Filter by the reaction the domain is built to elicit: comedy, absurd, playful, edgy, wholesome, professional, trustworthy. Unknown values are ignored."},"detail":"Optional field `emotion` was added to `search_domains`; may shift model behaviour.","severity":"risky"},{"kind":"resource_removed","tool":"popdot://rentals/{agentId}","before":"popdot://rentals/{agentId}","detail":"Resource `popdot://rentals/{agentId}` was removed, consumers reading it will break.","severity":"breaking"}],"published_at":"2026-08-26T19:49:15.274Z"}]