Changelog
What shipped, and when.
Every release, newest first. Security work is listed alongside features rather than kept quiet - including the times something was found to have never worked, which is the half of a changelog most products leave out.
Last updated August 30, 2026.
August 30, 2026
2 changes
A public documentation hub, AI discovery index, and corrected API examples.
- Added
Documentation hub and discovery index
A public /docs entry point now links the Lua, C# and HTTP API references, the complete Markdown guide, and the changelog. llms.txt and the sitemap point people and AI search tools at the same canonical documentation.
- Fixed
Canonical API examples
Public loader and API examples now consistently use api.arcticauth.com. The key lifecycle description now separates optional machine binding and place policy from executor telemetry.
August 25, 2026
1 change
Import from the Junkie Key System, in beta.
- Added
Import from Junkie Key System (Beta)
Pulls a service’s keys through Junkie’s v2 REST API - key value, HWID, Discord ID, expiry, invalidated state - into a new ArcticAuth service, with the same 15-day Ice grant a Luarmor import gets. The project id field is Junkie’s numeric service id. Marked Beta because Junkie has no HWID-reset timestamp to carry across, so a migrated key’s self-serve reset cooldown starts fresh rather than picking up where the source left off.
August 22, 2026
11 changes
Migration from PandaAuth, plans you can actually buy, and a trust-list toggle that had never been read.
- Added
Migration from PandaAuth
A wizard that copies either one PandaAuth service’s keys or up to five Kryptic Vault scripts across. You sign in on PandaAuth in a new tab and approve a consent screen; ArcticAuth only ever receives a single-use code, traded server-side for a grant that lives 45 minutes and is never stored. It is a copy - PandaAuth is left as it was unless you ask, at the end, for the migrated content to be cleared. One migration per account at a time, and 15 days between completed runs.
- Added
Plans are buyable
The per-service plan picker starts a real PayPal order instead of reporting that the checkout was not wired. A redirect checkout, so PayPal’s script never enters the dashboard. A fixed 30-day window rather than a subscription: nothing stores a payment method, so a plan ends rather than renewing silently, and buying again extends it rather than replacing it.
- Added
Unknown Obfuscator
The vault can record a script whose obfuscator this product does not run. Moonveil, wYnFuscator and the rest arrive from a migration with their build served exactly as it was, and re-hardening unavailable - rather than being filed under a provider nothing here can reproduce.
- Security
The vault reads the trust list
The per-script Trust list toggle was stored, shown in the dashboard, and never consulted at delivery - so a blocked machine still got the script unless that script happened to take a script_key. It is now checked on every loader pull that asks for it, ahead of the key gate, because a ban is not a fact about a key.
- Changed
Open registration
The invitation code is optional for everyone by default. A code that resolves is kept as the referral that brought the account in; one that does not is ignored rather than refusing the sign-up. A deployment can close the door again with one setting.
- Changed
Import switched on
Provider imports, and the migration promo that rides on them, default to enabled rather than answering 503.
- Added
Vault Users screen
Who has been executing your scripts: date, player, machine, game, executor, script and region, with a one-click blacklist and one search box over all of it. It is a delivery log rather than a session list - the vault knows when it handed a script over and nothing after that. Rows are deleted after two days, because every one of them names a real person’s machine, account and location.
- Security
Trust list entries can name a player
Previously a machine only, which fell to anyone willing to spoof one. An entry now names a machine or a Roblox account, the loader checks both, and a Block on either wins - so a banned machine is not rescued by a whitelisted account, and a banned account is not rescued by a whitelisted machine.
- Added
Loader benchmark
Time your own load: fetch, compile, handshake, pull, decrypt and load, plus one real end-to-end run. Served unobfuscated so the method can be checked - a benchmark nobody can read is a marketing number, and we wrote both the tool and the thing it measures. It reports every sample with no trimming, keeps the cold first fetch separate from the warm ones, never retries a throttled sample into a good timing, and reads the Lockdown state off the payload so two runs cannot be mislabelled.
- Added
A public changelog
This page. Previously the release history existed only as a section of a documentation file somebody had to download first.
- Changed
One crown for the staff view
The admin header carried a mode pill beside a separate Admin link - a badge narrating a state nobody needed narrated, and two presses to get anywhere. It is now a single crown: press it for the admin screens, press it again to come back to your dashboard as an ordinary account sees it. Filled while the admin screens are showing, and it works on a phone, where the labelled pill was hidden.
August 18, 2026
10 changes
Vault throttling per machine, a PIN in front of every vault, captcha, and a first-run setup wizard.
- Changed
Simultaneous runs on one address
Vault throttling is budgeted per declared machine rather than per address, with a per-address ceiling and an hourly cap on distinct machines over it. Throttled callers get an answer they can parse instead of an empty body, and the loader retries with jittered backoff.
- Security
Vault PIN
A four-digit gate in front of every service vault, set at sign-up or in Account Settings and password-confirmed both ways. One unlock lasts 12 hours per session, dies at sign-out, and locks out after five wrong attempts. Enforced on every vault endpoint, not just in the UI.
- Security
One account per device
A browser that registers an account is held to it for a week; a second registration inside that window is refused with the date the lock lifts. Sign-ins are never refused - a browser signing into an account it did not open is counted and surfaced to staff instead.
- Security
hCaptcha
Credentials on the admin Integrations screen, with independent switches for the key page, registration and sign-in. Fails open when hCaptcha is unreachable, because a challenge nobody can solve is an outage rather than a defence.
- Added
First-run setup wizard
Service, then revenue, then configuration, ending with how to implement the loadstring. Skippable at every step.
- Added
Configurable key prefix
Per service, letters and numbers, defaulting to artic_. Applies to keys minted from then on - keys already issued keep the name they were issued under, because the string is the key.
- Changed
ArcticAuth Documentation
Renamed, made public and prerendered, given in-page word search with match highlighting and syntax colouring in every code block, and offered as a downloadable Markdown file.
- Changed
Dormant accounts are removed
After 90 days with no sign-in. Staff and service owners are exempt by default.
- Fixed
Specific payment-credential errors
The settings screen names the missing field - “PayPal secret key” - instead of reporting a generic misconfiguration.
- Fixed
Layout
The admin Integrations screen uses its right-hand column instead of leaving it empty, and the service settings panels scroll inside their own bounds rather than dragging the grid’s hairline out of line.

