Changelog

The record
so far.

Provider integrations, risk intelligence, and alerts that are live in the product. Just shipped behavior and supported coverage.

7 entries
  1. alphaProviders

    Provider connections now enforce the permission boundary

    The connection screen is now a focused provider picker instead of a wall of credential forms. BeforeRed only offers new connections when the provider credential can be restricted against infrastructure changes.

    • One provider flow at a time, with the capability boundary shown before any credential input
    • Nine permission-restricted connection paths are implemented: five restricted-token paths and four OAuth paths
    • Railway OAuth is registered with project-viewer access and refresh support; Supabase, Vercel, and Neon remain provider-setup dependent
    • Legacy broad credentials are paused and can be removed without deleting prior usage history
  2. alphaProviders

    OAuth connection flow is now built into the alpha

    BeforeRed now supports the full OAuth handoff for providers that offer a safe authorization model: signed state and PKCE, callback validation, encrypted pending tokens, resource discovery, refresh-token rotation, and a final project or service selection before the first sync.

    • Railway uses project-viewer OAuth and never asks for a deploy token
    • Supabase is limited to organization and project discovery scopes
    • Vercel is limited to read-only integration scopes and does not request deployments, environment variables, billing, or write access
    • Neon is code-ready but remains disabled until Neon approves a commercial OAuth integration
  3. alphaProduct

    Know what your app will hit first

    BeforeRed now turns the latest usable signals from every connected provider into one deterministic app-level result. The overview leads with the limit that has the least room left, followed by the next closest signals.

    • One first-likely-limit result across all connected providers
    • Remaining allowance shown only when both usage and a valid limit are available
    • Runway appears only after enough history exists to support a forecast
    • Usage-only signals stay visible without being presented as safe or capped
  4. alphaProviders

    Fourteen provider adapters are now wired

    The runtime contains fourteen provider adapters for supported account, project, resource, and usage surfaces. Runtime wiring is tracked separately from certification and permission-safe user availability.

    • Upstash, Cloudflare Workers, Railway, Render, Neon, Netlify, MongoDB Atlas, and CockroachDB
    • Appwrite, Vercel, Supabase, Resend, Koyeb, and Fly.io
    • Each integration preserves unavailable usage as unknown instead of inventing a zero or a limit
    • Provider certification and safe user availability remain separate from runtime wiring
  5. alphaProviders

    Eight provider surfaces passed live reconciliation

    BeforeRed compared official provider responses with the matching provider dashboard before promoting these signals. Certification applies only to the tested metric surface, account, unit, and time window.

    • Upstash commands and storage
    • Cloudflare Workers requests, Railway project metrics, and Render outbound bandwidth
    • Neon branch storage, Netlify account credits, MongoDB Atlas Free-cluster capacity, and CockroachDB request units
    • Unsupported billing, cost, and quota fields remain unavailable
  6. alphaAlerts

    Scheduled sync now produces meaningful events

    Hourly syncs can now distinguish a material risk change from routine counter movement. BeforeRed records state transitions and deduplicates warning delivery so small usage changes do not become notification noise.

    • Safe, watch, urgent, and critical state changes
    • Recovery when an app returns to safe
    • Unusual usage acceleration and seven-day forecast crossings
    • Stale or unreachable provider connections
  7. alphaProduct

    Authenticated private alpha opened

    The first complete BeforeRed loop is available behind sign-in: connect a provider, store encrypted credentials, capture durable usage snapshots, and review the latest state from the app workspace.

    • Durable provider connections, resources, snapshots, and sync history
    • Manual sync plus an hourly scheduled sync boundary
    • Unknown and unsupported provider values remain explicit
Stay in the loop

New entries land here.

RSS works in any reader. We do not collect emails for this. No marketing, no "weekly digest". Just the same file you would hand to a human.

/changelog/rss.xml

Updated when entries ship. No tracking pixels.