Product updates
QuestAPIs changelog
A transparent record of shipped foundations, security changes, and known limitations. Planned work is not presented as complete.
Eight-quest Academy and reliable account return
The complete beginner route is now represented in the app and database, with clearer saved progress and a hardened email-verification return flow.
Added
- Seven new playable beginner quests covering HTTP, JSON, endpoints, API-key safety, webhooks, status codes, and project planning
- Published curriculum records, answer validation, and one-time XP/gold reward rules for all eight Academy regions
- Dashboard progress based on completed lessons rather than an XP estimate
Changed
- Every map region now opens its own interactive lesson instead of showing a coming-later notice
- Successful password sign-in now performs a full navigation so the server immediately receives the new session cookie
- Verification callbacks now surface expired or malformed link errors and safely support both authorization codes and email token hashes
- Expanded Help and FAQ guidance for available quests, cross-browser verification, and the planned branded support sender
Security
- Callback destinations are restricted to local paths to prevent external redirect abuse
- Lesson rewards remain server-validated, idempotent, and available only to authenticated users
Known limitation
- A custom support@questapis.dev sender still requires a hosted mailbox plus verified SMTP configuration
- Opening a verification link on a different device cannot transfer that browser session; the verified user can sign in normally
Public launch foundation
The rebuilt QuestAPIs experience is live on the primary domain with production accounts and saved Academy progress, while the Journal and closed-beta notice run as separate deployments.
Added
- Installable Academy experience with web-app metadata, branded icons, standalone display, and a conservative offline learning shell
- Production profiles, onboarding, saved lesson completion, XP/gold rewards, cosmetics, and developer-key storage
- QuestAPIs Journal with three launch articles, RSS, sitemap, robots policy, and security headers
- Home-screen installation guidance for iPhone, iPad, Android, and supported desktop browsers
Changed
- Published the rebuilt v2 website to questapis.dev
- Connected questapis.blog and verified HTTPS delivery
- Replaced the beta application page with a clear applications-closed notice
- Improved signup routing so immediately confirmed accounts continue into onboarding
Security
- Activated 27 row-security policies and server-authoritative Academy transactions
- Preserved incompatible legacy API-key and shop tables by giving the v2 models distinct names
- Kept the legacy production branch untouched while publishing the rebuild from the isolated v2-staging branch
- The offline worker excludes authentication and API routes from its cache
Known limitation
- Some offline lesson actions still require a network connection to validate answers and save rewards
- Email confirmation is required before a new account can sign in
- Paid plans remain unavailable until verified Stripe test-mode work is complete
Phase 1.5 authority and transaction hardening
The v2 codebase now has atomic server-authoritative paths for its first persistent Academy, economy, and developer-key flows, ready for isolated staging verification.
Added
- Atomic lesson validation, idempotent XP/gold awards, and persistent dashboard balances
- Atomic cosmetic purchase and equipment transactions using server-owned prices and locked balances
- One-time API-key reveal, hash-only storage, owner-scoped revocation, hourly quota accounting, and usage records
- Default-deny RLS coverage, profile provisioning, supporting indexes, staging seeds, structured redacted logs, and admin catalog operations
- Backup, rollback, monitoring, and validation runbooks
- A redesigned, application-free beta landing page and matching closed-beta state
Changed
- Starter Grove completion now calls the authoritative server flow when staging auth is available
- Dashboard values now come from the authenticated profile and API-key records
- The header uses a 33 KB WebP logo derivative instead of requesting the 2.4 MB source PNG
Security
- Client sessions cannot directly mutate currency, rewards, inventory, roles, entitlements, subscriptions, or metering
- Repeated completions and purchases use unique database constraints inside transactions; shop prices never come from the browser
Known limitation
- Live auth, email, cross-user, load, backup/restore, and rollback rehearsals require the isolated staging services
- No production or legacy infrastructure has been changed
Phase 1 platform foundation
The isolated QuestAPIs v2 foundation now supports both the beginner Academy experience and the developer platform surface.
Added
- Responsive public website and dual-path homepage
- Eight-region Academy atlas with a mobile quest trail
- Introductory lesson, quiz, dashboard, achievements, streak, and cosmetic-shop foundations
- Grove development API, documentation, catalog, and interactive playground
- Supabase account, email verification callback, and password-recovery integration
- PostgreSQL migration for curriculum, rewards, entitlements, API keys, metering, billing, notifications, and RLS
- Pricing, onboarding, status, feedback, admin, Help Center, FAQ, and changelog surfaces
Changed
- Upgraded Next.js to 16.3.6 and the test runner to a patched release
- Replaced unverified legacy API readiness claims with explicit development or planned states
- Added security headers, canonical metadata, sitemap entries, and reduced-motion handling
Security
- API-key comparison uses a configured SHA-256 digest and timing-safe equality
- Authority-bearing database tables expose self-read policies but no browser mutation policies
- Production dependency audit reports zero known vulnerabilities
Known limitation
- Staging deployment requires a valid Vercel login
- Persistent accounts and progress require a new Supabase staging project
- Stripe remains test-ready architecture only
Discovery and visual direction
Established preservation boundaries, audited the public legacy reference, and defined the Adventure Atlas visual system.
Added
- Legacy technical assessment
- Academy persistence and authorization contract
- Dark evergreen, navy, cyan, ivory, and gold visual foundation
- Starter Grove public learning preview