release log · version history

changelog & product updates.

Every release of WOTP Gateway, with the work that went into it. Real tag dates, and one version released so far — the project is new, and this page grows as it does.

releases

evolution of the gateway.

unreleased
on main

Deployment paths, and headlines in the instrument face

Deployment

  • ✓Dokploy: a Compose file that joins the platform network so Traefik routes to it, publishes nothing to the host, and names every environment variable instead of relying on an env file the platform never provides.
  • ✓Dokku: a dashboard image built against the repository root, because Dokku always uses the root as its build context and a Dockerfile written for a subdirectory cannot work there.
  • ✓Both paths are documented end to end, including the build-time variables that Next.js compiles into the browser bundle and which therefore need a rebuild rather than a restart.

Typography

  • ✓Headlines are now set in Geist Pixel. Body copy deliberately stays in Geist, because a dot-matrix face at 14-16px is hard to read across the long docs and legal pages.
  • ✓The face ships as a WOFF2 holding the full character set at 13.7 KB, replacing an 82.5 KB file that contained only digits and punctuation and could not set a single word.
  • ✓Letter spacing on headlines went from negative to normal, since the tightening suited a text serif and collided the pixel glyphs.
v0.1.0First Release
1 October 2026

The first release: two calls, your own WhatsApp and Telegram accounts

The API

  • ✓Two endpoints, POST /v1/otp/send and POST /v1/otp/verify. JSON in, JSON out, no SDK, no client library to keep current.
  • ✓An optional Idempotency-Key header that makes a retry safe, including the one case that matters: the provider accepted the message but the ledger write afterwards failed, where a naive retry would deliver twice.
  • ✓A documented error contract covering every code, every extra field, and the retry decision for each. Every 429 carries Retry-After, and validation errors never echo raw input back.
  • ✓Key management — issue, list, rotate and retire — with keys and OTP codes stored as SHA-256 digests only.

Channels

  • ✓WhatsApp over your own Meta Cloud API account: authentication templates with a copy-code button, signature-verified delivery callbacks, and per-message delivery status.
  • ✓Telegram over your own bot: no business verification, no card, no per-message cost, and never counted against the WhatsApp quota.
  • ✓One-tap Telegram contact linking that accepts a shared number only when it belongs to the person sharing it.

Dashboard

  • ✓Overview, API keys, a live OTP tester that generates copyable cURL commands, and a settings view.
  • ✓A seven-step first-run checklist derived from live readiness rather than asking you to judge your own setup.
  • ✓A playground that runs the real request and response bodies, the real status codes and the real Retry-After headers locally, with nothing sent anywhere.

Security

  • ✓Webhook payloads can no longer reach the control-plane query filter, closing an unauthenticated path from a request body into a query.
  • ✓Unauthenticated requests are rate-limited, and unknown API keys are cached so a bad key cannot be used to hit the database on every call.
  • ✓The plaintext API key is never persisted in the browser — it is shown once, and only its hash is stored. Phone numbers are masked in logs.
  • ✓Every published port is bound to loopback by default, so a default install is not reachable from the network by accident.

Reliability

  • ✓Sends are serialized per owner rather than per API key. One owner may hold five keys, so per-key locking let a single owner exceed the monthly cap several times over.
  • ✓Quota counts immutable usage, recorded once at send time. A counter that drops when messages later succeed is not a spend limit.
  • ✓In-process lock pools are bounded, so a stream of distinct numbers cannot grow them without limit.

Operations

  • ✓A three-container stack — API, PocketBase and dashboard — running as non-root, with one SQLite file to back up.
  • ✓Two health endpoints: liveness, and readiness that reports provider state by variable name and never by value, so it is safe to read in public.
  • ✓Retention pruning for OTP codes and audit rows, with a dry-run preview, plus request ids so a log line can be traced to the request that produced it.
  • ✓CI running the backend suite, the frontend checks, a full-history secret scan and dependency audits, against pinned dependencies.

Discoverability

  • ✓WhatsApp and Telegram landing pages, a sitemap, robots rules, OpenGraph and Twitter card images, schema markup and a PWA manifest.
  • ✓An instrument display face subset from 3.6 MB to 84 KB, on stat figures only — a dot-matrix face turns to mush below display size.
  • ✓Privacy, terms and disclaimer pages.

This page mirrors CHANGELOG.md, which is the canonical record.