Changelog

What shipped, and when.

Every release, newest first. Security work is listed alongside features rather than kept quiet - including the times something was found to have never worked, which is the half of a changelog most products leave out.

Last updated August 30, 2026.

  1. August 30, 2026

    2 changes

    A public documentation hub, AI discovery index, and corrected API examples.

    • Added

      Documentation hub and discovery index

      A public /docs entry point now links the Lua, C# and HTTP API references, the complete Markdown guide, and the changelog. llms.txt and the sitemap point people and AI search tools at the same canonical documentation.

    • Fixed

      Canonical API examples

      Public loader and API examples now consistently use api.arcticauth.com. The key lifecycle description now separates optional machine binding and place policy from executor telemetry.

  2. August 25, 2026

    1 change

    Import from the Junkie Key System, in beta.

    • Added

      Import from Junkie Key System (Beta)

      Pulls a service’s keys through Junkie’s v2 REST API - key value, HWID, Discord ID, expiry, invalidated state - into a new ArcticAuth service, with the same 15-day Ice grant a Luarmor import gets. The project id field is Junkie’s numeric service id. Marked Beta because Junkie has no HWID-reset timestamp to carry across, so a migrated key’s self-serve reset cooldown starts fresh rather than picking up where the source left off.

  3. August 22, 2026

    11 changes

    Migration from PandaAuth, plans you can actually buy, and a trust-list toggle that had never been read.

    • Added

      Migration from PandaAuth

      A wizard that copies either one PandaAuth service’s keys or up to five Kryptic Vault scripts across. You sign in on PandaAuth in a new tab and approve a consent screen; ArcticAuth only ever receives a single-use code, traded server-side for a grant that lives 45 minutes and is never stored. It is a copy - PandaAuth is left as it was unless you ask, at the end, for the migrated content to be cleared. One migration per account at a time, and 15 days between completed runs.

    • Added

      Plans are buyable

      The per-service plan picker starts a real PayPal order instead of reporting that the checkout was not wired. A redirect checkout, so PayPal’s script never enters the dashboard. A fixed 30-day window rather than a subscription: nothing stores a payment method, so a plan ends rather than renewing silently, and buying again extends it rather than replacing it.

    • Added

      Unknown Obfuscator

      The vault can record a script whose obfuscator this product does not run. Moonveil, wYnFuscator and the rest arrive from a migration with their build served exactly as it was, and re-hardening unavailable - rather than being filed under a provider nothing here can reproduce.

    • Security

      The vault reads the trust list

      The per-script Trust list toggle was stored, shown in the dashboard, and never consulted at delivery - so a blocked machine still got the script unless that script happened to take a script_key. It is now checked on every loader pull that asks for it, ahead of the key gate, because a ban is not a fact about a key.

    • Changed

      Open registration

      The invitation code is optional for everyone by default. A code that resolves is kept as the referral that brought the account in; one that does not is ignored rather than refusing the sign-up. A deployment can close the door again with one setting.

    • Changed

      Import switched on

      Provider imports, and the migration promo that rides on them, default to enabled rather than answering 503.

    • Added

      Vault Users screen

      Who has been executing your scripts: date, player, machine, game, executor, script and region, with a one-click blacklist and one search box over all of it. It is a delivery log rather than a session list - the vault knows when it handed a script over and nothing after that. Rows are deleted after two days, because every one of them names a real person’s machine, account and location.

    • Security

      Trust list entries can name a player

      Previously a machine only, which fell to anyone willing to spoof one. An entry now names a machine or a Roblox account, the loader checks both, and a Block on either wins - so a banned machine is not rescued by a whitelisted account, and a banned account is not rescued by a whitelisted machine.

    • Added

      Loader benchmark

      Time your own load: fetch, compile, handshake, pull, decrypt and load, plus one real end-to-end run. Served unobfuscated so the method can be checked - a benchmark nobody can read is a marketing number, and we wrote both the tool and the thing it measures. It reports every sample with no trimming, keeps the cold first fetch separate from the warm ones, never retries a throttled sample into a good timing, and reads the Lockdown state off the payload so two runs cannot be mislabelled.

    • Added

      A public changelog

      This page. Previously the release history existed only as a section of a documentation file somebody had to download first.

    • Changed

      One crown for the staff view

      The admin header carried a mode pill beside a separate Admin link - a badge narrating a state nobody needed narrated, and two presses to get anywhere. It is now a single crown: press it for the admin screens, press it again to come back to your dashboard as an ordinary account sees it. Filled while the admin screens are showing, and it works on a phone, where the labelled pill was hidden.

  4. August 18, 2026

    10 changes

    Vault throttling per machine, a PIN in front of every vault, captcha, and a first-run setup wizard.

    • Changed

      Simultaneous runs on one address

      Vault throttling is budgeted per declared machine rather than per address, with a per-address ceiling and an hourly cap on distinct machines over it. Throttled callers get an answer they can parse instead of an empty body, and the loader retries with jittered backoff.

    • Security

      Vault PIN

      A four-digit gate in front of every service vault, set at sign-up or in Account Settings and password-confirmed both ways. One unlock lasts 12 hours per session, dies at sign-out, and locks out after five wrong attempts. Enforced on every vault endpoint, not just in the UI.

    • Security

      One account per device

      A browser that registers an account is held to it for a week; a second registration inside that window is refused with the date the lock lifts. Sign-ins are never refused - a browser signing into an account it did not open is counted and surfaced to staff instead.

    • Security

      hCaptcha

      Credentials on the admin Integrations screen, with independent switches for the key page, registration and sign-in. Fails open when hCaptcha is unreachable, because a challenge nobody can solve is an outage rather than a defence.

    • Added

      First-run setup wizard

      Service, then revenue, then configuration, ending with how to implement the loadstring. Skippable at every step.

    • Added

      Configurable key prefix

      Per service, letters and numbers, defaulting to artic_. Applies to keys minted from then on - keys already issued keep the name they were issued under, because the string is the key.

    • Changed

      ArcticAuth Documentation

      Renamed, made public and prerendered, given in-page word search with match highlighting and syntax colouring in every code block, and offered as a downloadable Markdown file.

    • Changed

      Dormant accounts are removed

      After 90 days with no sign-in. Staff and service owners are exempt by default.

    • Fixed

      Specific payment-credential errors

      The settings screen names the missing field - “PayPal secret key” - instead of reporting a generic misconfiguration.

    • Fixed

      Layout

      The admin Integrations screen uses its right-hand column instead of leaving it empty, and the service settings panels scroll inside their own bounds rather than dragging the grid’s hairline out of line.