# Changelog

Every developer-facing change to Layout, newest first. Feed: https://developer.layout.link/changelog/feed.xml

- 2026-09-22 [Card-free sandbox builds](https://developer.layout.link/changelog/card-free-sandbox-builds.md) (Sandbox): Sandbox builds never ask for a card. Each application has its own daily sandbox allowance, and a new Usage page shows what you have used and lets you ask for more.
- 2026-09-22 [Week of September 21](https://developer.layout.link/changelog/week-of-september-21.md) (Console): Reset a forgotten console password from the sign-in page, and a one-screen Quickstart in the top navigation.
- 2026-09-21 [Orders in the console](https://developer.layout.link/changelog/orders-in-the-console.md) (Console): A new Orders page lists every order your keys caused in the selected environment, with the outcome in words and the reason when one did not complete.
- 2026-09-15 [Week of September 14](https://developer.layout.link/changelog/week-of-september-14.md) (Console): A disconnected person can be invited again, the console sends the right link to the right person and explains what it did, console search matches the docs, and four guides were corrected.
- 2026-09-13 [A signing secret per environment](https://developer.layout.link/changelog/a-signing-secret-per-environment.md) (Webhooks, breaking): Sandbox and production deliveries are now signed with different secrets, and every delivery says which environment it came from. Production verification needs the new production secret.
- 2026-09-13 [Check readiness with whoami](https://developer.layout.link/changelog/check-readiness-with-whoami.md) (API): GET /v1/whoami says which application and environment a key opens and whether production is approved, so going live is a check instead of a 403.
- 2026-09-13 [Connections that last](https://developer.layout.link/changelog/connections-that-last.md) (API): A person's connection to your app now survives them signing in to Layout. People who already have Layout can connect by approving you, and Layout texts them the approval link itself.
- 2026-09-13 [Headless phone verification](https://developer.layout.link/changelog/headless-phone-verification.md) (API): Two new calls let a provisioned person prove their phone without opening a Layout page. Layout texts them a code, they read it to you, and you pass it back.
- 2026-09-13 [Ordering moves to MCP](https://developer.layout.link/changelog/ordering-moves-to-mcp.md) (MCP, breaking): POST /v1/orders is retired and answers 410. Carts are built over MCP with a build grant, and a build grant session now lists only the three tools it can use.
- 2026-09-13 [Week of September 7](https://developer.layout.link/changelog/week-of-september-7.md) (Console): Webhook subscriptions open in a side drawer, logo uploads go through, the sandbox test phone cannot be mistyped, and the guides cover cardless builds and connections.
- 2026-09-12 [Builds before a card](https://developer.layout.link/changelog/builds-before-a-card.md) (API): Someone you just provisioned can see a real, priced cart before they have a card on file, up to a daily allowance set for your application. When a card is needed, Layout's card page names your app.
- 2026-09-12 [Docs for people and agents](https://developer.layout.link/changelog/docs-for-people-and-agents.md) (Docs): Search that reads every page, an endpoint reference, three new guides, and the whole reference as llms.txt, Markdown twins and an OpenAPI 3.1 file.
- 2026-09-12 [Keys you can read again](https://developer.layout.link/changelog/keys-you-can-read-again.md) (Console): Client secrets can be revealed on demand instead of once at creation, the console says plainly what your approval status allows, and logos upload as files.
- 2026-09-12 [Send a test webhook](https://developer.layout.link/changelog/send-a-test-webhook.md) (Webhooks): Send test event fires a real, signed delivery at your endpoint, so you can prove the whole path before a single order exists.
- 2026-09-12 [Why a key was refused](https://developer.layout.link/changelog/why-a-key-was-refused.md) (Console): The API still answers every refused key with the same sentence. Your console now shows the real reason, which key it was, how many times, and when it last happened.
- 2026-09-11 [Layout for Developers opens](https://developer.layout.link/changelog/developer-platform-opens.md) (API): Sign up, create an application and build against sandbox the same day. Provision a person, build a real cart for them, and follow every order on signed webhooks.
- 2026-09-04 [Your logo on consent](https://developer.layout.link/changelog/your-logo-on-consent.md) (MCP): When a person connects an MCP client to Layout through OAuth, the consent screen shows that client's logo beside the Layout mark, drawn from the host its redirect URI points at.
