> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jojapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# September 2026 Changelog

## Deployments with their own URLs

Every save of an API on the edge gateway is now an immutable **deployment** with its own URL (`https://{api}--{id}.jojapi.dev`), and `https://{api}--preview.jojapi.dev` follows the latest one. See [Deployments](/studio/deployments).

* **Every save is a preview first**: the template, code, variables, secrets and storage bindings all go to a preview deployment that you can test before consumers see it. A bar on the Worker tab shows how many changes production is behind, with **Deploy to production** and **Discard**. **Save and deploy** puts a variable into production at once (for example to rotate a leaked key) without your other pending changes; `jojapi deploy --prod` still deploys code straight away. Removed storage is deleted once no active deployment uses it, so a rollback still finds it. See [Deployments](/studio/deployments#every-save-is-a-preview-first).
* **Test from the playground**: on your API's marketplace page, **Send requests to** sends your playground requests to the latest preview or to one deployment instead of your public host, and each request shows where it ran (`Preview · #8 bhsmu1w6`). Only you see the choice; the requests are billed like production on your own subscription. See [Deployments](/studio/deployments#test-a-deployment-from-the-playground).
* **Promote and roll back in seconds**: nothing is rebuilt; a rollback restores the variables and bindings the deployment had.
* **Release notes**: promotions and their notes appear as **Releases** on the API's public page.
* **Pinned versions**: make a deployment **Public** and share its URL; any subscriber can call it, billed as usual. Owner-only deployments answer only your own keys.
* **Active deployments in compute usage**: three per API are included; older ones are archived automatically unless you keep them active. Beyond three, \$0.02 per deployment per month (informational, like the rest of compute usage).
* **CLI**: `jojapi deploy [--prod] [--message] [--json]`, `jojapi deployments`, `jojapi promote <id> [--note]`, `jojapi rollback`. Each deployment records its commit, branch and pull request.
* **Deploy from GitHub**: the `jojapicom/deploy-action` GitHub Action deploys a preview for every pull request (and comments its URL) and production on every merge. A first deploy from the CLI or GitHub switches an API in template mode to code mode, as a preview. See [Deploy from GitHub](/studio/github-actions).

## Edge gateway: your API as a Cloudflare Worker

APIs are moving to a new **edge gateway** where every API runs as its own Worker close to the consumer. For APIs already moved, the Target tab became the **Worker** tab:

* **Template**: origins with failover, header and query changes, consumer context headers, timeout and a proxy — the Worker is generated from it on every save, and **View generated code** shows exactly what runs. See [API targeting](/studio/api-targeting).
* **Code**: **Edit code** turns the generated files into yours. A plain Worker (`export default { fetch }`), several files with relative imports, JSON and text modules, a Monaco editor in the browser. The gateway talks to it over documented `x-jojapi-*` headers; no SDK. See [Worker code](/studio/custom-code).
* **Variables**: named values bound to the Worker (`env.NAME`); secrets are encrypted at rest and write-only. Credential-looking headers of moved APIs became secret variables automatically.
* **Storage and queues**: a key-value store, SQL database, object storage, queue or stateful object class created for your API alone and bound to its Worker.
* **Runtime errors and console**: unreachable origins, timeouts, exceptions and `x-jojapi-error` reports grouped by message with recent occurrences; `console.*` output when console logging is on.
* **Usage sources**: metered billing reads a response header, a header key or a JSON field with an optional default instead of a template. See [Billable objects](/studio/billable-objects#usage-sources-on-the-edge-gateway).
* **Management API**: two new scopes, `code:read` and `code:write`, for the template, files, variables, storage and settings.
* **My APIs list**: a **Gateway** badge per API — **Classic** (not moved yet), **Template** or **Code** — with a filter, the API host, endpoint counts and quick links to the Worker, analytics and request logs.

APIs still on the classic gateway keep the previous form and template expressions until they are moved.

## Shared resources between APIs

A stateful object, key-value store, SQL database, object storage or queue of one API can now be bound by other APIs, so two listings can use one store or one pool of stateful objects. See [Shared resources](/studio/shared-resources).

* **Your own APIs**: share a resource and it is bound into the other API right away.
* **Another account's API**: name it by its slug; the other account accepts the invitation on that API's **Bindings** and binds the resource under its own name. They see your API and account name, never your code or variables.
* **Stateful objects** run in the owner's production Worker; the other API calls their public methods. Stores and databases are shared read and write; queues for sending only.
* **Revoke** re-releases the other API without the binding at once. A resource in use cannot be deleted, and production keeps every shared class.
* Usage stays on the owner's compute; each listing bills its own consumers as before. Up to 10 APIs per resource.

## Agent payments (x402 + MPP)

AI agents can now buy access to any API on the marketplace without an account — the paying wallet is the customer:

* **Pay per request**: providers price endpoints in USD; keyless calls answer an HTTP 402 offer over x402 (USDC on Base) and MPP, the gateway verifies the payment, forwards the call and settles only when the API answered. Upstream errors are never charged.
* **Plans for agents**: every paid USD plan of an unlisted or public API is purchasable by an agent (free plans and private APIs stay closed to agents) at `https://{api}.jojapi.net/_jojapi/agent/subscribe/{plan}`. The purchase issues a fresh API key bound to a prepaid period; renewals are offered, never auto-charged. An agent may hold several plans of one API, each with its own key.
* **Pay-as-you-go balance**: wallet top-ups fund an account-wide balance; the usual metering, tiers and formulas apply.
* **Identity**: one wallet = one account (chain-agnostic on EVM); more wallets only by double signature. Sign-In-With-X gates `me`, key rotation and wallet linking.
* **Discovery**: every API host serves `/.well-known/x402`, an annotated `/openapi.json` (`x-payment-info`) and its logo at `/favicon.ico`, and `https://agents.jojapi.net` lists all agent-payable APIs, so x402 directories can index endpoints and plans.
* **Studio**: an Agent payments switch per API, an Agent price per endpoint (single or bulk), and agents shown as customers with a badge in Subscriptions and Transactions. See [Sell to AI agents](/studio/agent-payments) and [Pay as an AI agent](/consumers/agents).

## Verified Publishers

Organizations can now carry a verified tick next to their name — on marketplace cards, API pages and their publisher profile — so consumers can tell an official provider from a lookalike:

* **Domain verification**: prove you control your website's domain by publishing a DNS TXT record (`_jojapi.your-domain.com`) from **Settings → Account → Verified publisher badge**. The record is checked on demand and re-checked regularly afterwards.
* **Review**: once the domain is verified, apply with one click. Our team checks that the website, the profile and the published APIs present the same organization, and emails the decision. Declined applications show the reasons and can be resubmitted after 14 days.
* **Provider byline on cards**: every marketplace card now names its publisher ("by …") under the API name, linking the brand to the publisher profile — verified ones with the tick.
* **Bound to the domain**: the badge lapses automatically if the TXT record stays missing for 30 days or the profile website moves to another domain. See [Verified publishers](/studio/verified-publishers).

## Automatic crypto payouts

Provider payouts in crypto are now sent automatically — **USDC on Polygon**, from the 15th of the month, with the transaction link in Studio and in the payout email:

* **Address confirmation**: a new or changed payout address receives a small test deposit (\$0.10–0.99 USDC, deducted from the next payout) once a payout is ready; enter the amount you received in **Studio → Payouts** to confirm it. Payouts to a new address start 72 hours after the change, and the change email carries a one-click link that freezes payouts if it was not you.
* **Addresses already paid to** stay confirmed; nothing changes for existing providers.
* PayPal payouts continue to be processed by hand. See [Provider earnings](/studio/provider-earnings).

## Management API

Providers can now drive the Studio from scripts, CI and agents with **management tokens** — scoped credentials that stand in for the login on the Studio's own routes:

* **Separate from API keys**: a `jm_` token acts on your listings and can never reach payments, payouts, your account or your API keys. Create them in **Studio → Management API**, one per script or agent, with an expiry; revoke in one click.
* **Five scopes**: `listings:read`, `listings:write`, `plans:write`, `analytics:read`, `subscriptions:read` — an agent that only publishes documentation never needs to see pricing.
* **Publish from your OpenAPI**: `import/preview` shows what would change, `import/apply` writes it in one transaction, without touching blocked/hidden flags, groups or plans.
* **Audited**: every token request is logged with its outcome for 90 days, and each token shows when it was last used. See [Management API](/studio/management-api).

## Hide JoJ API headers on a key

For keys another platform calls APIs with — a bridge that lists an API elsewhere, or a reseller that passes responses on to its own customers — **Workspace → API Keys** has a per-key switch (row menu → **JoJ API headers**). With it on, responses to that key carry none of the gateway's headers: usage and quota, balance, the deployment that answered and the gateway-response marker. The API's own headers and CORS stay; usage, billing and request logs are unchanged. See [Hiding JoJ API headers](/consumers/api-keys#hiding-joj-api-headers).

## Duplicate an endpoint

The Studio **Endpoints** page can copy an endpoint under a new method and URL path (row menu → **Duplicate…**). The copy carries the documentation, parameters, responses and examples, the billing spec, the agent price and the target membership; only its statistics start empty. Handy for offering a path with and without a trailing slash.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.