Skip to content

Changelog

All notable changes to Moveris API (v2) will be documented here.

In plain terms

This page lists new features, changes, deprecations, and fixes. Check it when upgrading your integration or troubleshooting unexpected behavior.


2026

[2.13.0] - 2026-07-15

Added

  • Meeting Liveness Botframe quality gating — Before frames enter the accumulator, the bot runs a gate-and-reset quality pipeline (blur, brightness, and optionally face geometry / pose). A rejected frame resets that participant's buffer so the model still receives consecutive frames. The session SSE stream adds frame-quality-rejected (throttled to about once per second per participant) with participantId, participantName, reason, framesCollected, and framesRequired so M2M clients can surface interviewer guidance. See Integration Guide — Frame quality gating and API Reference — Session Events.

  • Meeting Liveness Bot — background segmentation — Optional bgSegmentation on POST /api/sessions replaces each participant's background with neutral grey before frames are sent to fast-check. Defaults to the deployment setting configured by Moveris. When enabled, requests include bg_segmentation: true in the analysis payload. See Integration Guide — Background segmentation.

Changed

  • React SDK (@moveris/react 3.22.0, @moveris/shared 3.22.0) — Adaptive blur and brightness gates are now platform-aware. detectPlatform() classifies 'ios' | 'android' | 'harmonyos' | 'desktop' | 'other', and PLATFORM_BLUR_PARAMS tunes fraction, top percentile, and window size per platform (for example Android uses a more lenient blur curve than iOS). Existing blurThreshold / brightnessThreshold floors still apply. See Hooks and Types & Constants.

Fixed

  • React SDK (@moveris/react 3.22.4)useSmartFrameCapture adds requireLandmarks (default false). When true, isDetectorReady also waits for the FaceLandmarker before capture starts, so short live-check sessions do not finish with empty landmarks while the ~25MB model is still loading. Leave unset for fast-check / fast-check-crops. See Live Check and Hooks.

  • React SDK (@moveris/react 3.22.3, @moveris/shared 3.22.3)CameraStabilizer retries once by default after a failed 4s cold-start window (auto-exposure still converging), reducing capture starts on an unstable camera. Configurable via StabilizerConfig.maxRetries.

  • WebRTC transport (@moveris/webrtc 3.22.2) — Observer config fetch now appends ?model=<alias> so clients route to the correct model shard. Upgrade @moveris/webrtc (and @moveris/react if you use useWebRTCLiveness) to 3.22.2+.

  • Meeting Liveness Bot — stale session cleanup — When a session expires, the bot now leaves the meeting (stopBot), broadcasts session-status with fatal, and unlocks the client form. SSE onerror that receives 404 for the session also marks the session fatal so the UI does not stay stuck in scanning.

[2.12.0] - 2026-06-26

Added

  • Mixed V3.1.1 models — New mixed-10-v3_1_1, mixed-30-v3_1_1, mixed-60-v3_1_1, mixed-90-v3_1_1, and mixed-120-v3_1_1 aliases. V3.1.1 is a clean retrain of the V3.1 temporal-physio family on canonical RGB inputs, with thresholds recalibrated on the real-world holdout set (equal error rate drops to roughly 5–9% on that set). Select a model with the model body field or with X-Model-Version: v3_1_1 plus frame_count (10, 30, 60, 90, or 120). The 90-frame model (mixed-90-v3_1_1) is the recommended ship configuration. See Models overview and Model Versioning & Frames.

  • React SDK (@moveris/shared / @moveris/react / @moveris/react-native / @moveris/webrtc 3.21.0) — Registered the V3.1.1 models in the SDK type and config layer: mixed-{10,30,60,90,120}-v3_1_1 added to the FastCheckModel union, v3_1_1 added to ModelVersion, and matching MODEL_CONFIGS entries (per-frame minFrames / recommendedFrames). Additive; mirrors the existing V3.1 entries.

  • Meeting Liveness Bot — V3.1.1 models — The interviewer scanner and verification history now support the mixed-*-v3_1_1 aliases, so meeting sessions can target the latest model generation.

Changed

  • Meeting Liveness Bot — H.264 video pipeline — The bot now ingests each participant's video as an H.264 stream (the web_4_core meeting-provider variant) and extracts frames with FFmpeg, instead of receiving one PNG per frame. End-to-end verdict latency drops from roughly 20 seconds to about 9 seconds. Frames are now delivered at native capture resolution (no forced 640×480 downscale, so face proportions are preserved) and as consecutive frames (no frame skipping), matching how the liveness models are trained. No API changes — session endpoints, server-sent event (SSE) streams, and webhook payloads are unchanged.

  • WebRTC observer reliability — The observer deployment adds a WebSocket heartbeat and a liveness watchdog that detect dead or half-open KVS connections and recover automatically, plus separate liveness and readiness health checks so the service is not marked unhealthy while models are still warming up. No API changes for WebRTC integrators.

[2.11.0] - 2026-06-22

Added

  • Meeting Liveness Bot — targeted participant scanningPOST /api/sessions now accepts optional targetParticipantNames and excludeParticipantNames (arrays of display names). When targetParticipantNames is set, the bot scans only matched participants; excludeParticipantNames skips named people (for example interviewers or hosts). Name matching is two-tier: fast fuzzy matching for clear cases, with an optional LLM confirmation step (configured by Moveris on the bot deployment) for ambiguous names. Matched participants are pinned and analyzed during active speech, so frames are captured while the subject is live on camera. The SSE stream adds participant-stage and participant-matched events for real-time UI. See Integration Guide — Targeted participant scanning.

Fixed

  • WebRTC transport (@moveris/webrtc 3.20.2, @moveris/react 3.20.2) — Fixed connection failures that prevented any WebRTC liveness session from completing. The client now reads the channel-specific signaling endpoint (wssEndpoint) from the observer config instead of falling back to the generic regional URL, handles the KVS SignalingClient SDP answer and ICE candidate event shape correctly, drains the DataChannel send buffer between chunks for larger frame counts (30+ frames), and includes a generated session_id in the start message so the observer returns a verdict instead of timing out. No API changes — upgrade @moveris/webrtc and @moveris/react to 3.20.2.

[2.10.0] - 2026-06-18

Added

  • WebRTC transport (@moveris/webrtc 3.20.0, @moveris/react 3.20.0) — New @moveris/webrtc package with WebRTCLivenessClient for framework-agnostic liveness over a single AWS KVS WebRTC DataChannel (frames sent in 16 KB PNG chunks; verdict returned on the same channel). @moveris/react adds useWebRTCLiveness for React state management. Requires an observer deployment that exposes /kvs/config (separate from the standard REST base URL). See WebRTC Quick Start and WebRTC Client Reference.

  • Meeting Liveness Bot — Slack notifications — Optional Slack alerts on the bot deployment post formatted liveness verdicts (environment label, participant name, score, model, session ID). Configured by Moveris; leave disabled by default. See Integration Guide — Slack notifications.

Security

  • React SDK (@moveris/react 3.20.0, @moveris/webrtc 3.20.0) — Dependency patches for shell-quote, form-data, vite, and ws.

  • Meeting Liveness Bot — Dependency overrides updated for react-router, vite, and ws audit findings.

[2.9.0] - 2026-06-11

Changed

  • React SDK (@moveris/react 3.19.0, @moveris/shared 3.19.0)useSmartFrameCapture now uses adaptive blur and brightness thresholds that calibrate to each user's camera and lighting. A rolling 30-frame window derives a threshold from the top-10% mean, so low-quality cameras and dim rooms can still pass sharp, well-lit frames. The existing blurThreshold and brightnessThreshold props act as floors for the adaptive computation (not fixed gates). Hard floors (MIN_BLUR_FLOOR=20, MIN_BRIGHTNESS_FLOOR=30) still reject unusable frames. After five consecutive blur or brightness rejections, persistent advisory feedback takes priority over generic "hold still" copy. New exports: computeAdaptiveBlurThreshold, computeAdaptiveBrightnessThreshold, sampleBlurVariance, and related constants — see Hooks and Types & Constants.

Fixed

  • React SDK (@moveris/react 3.19.0) — Blur rejection now resets the captured frame buffer (same as face-loss) so V3+ models receive fully consecutive frames with uniform temporal spacing. The blur gate runs pre-capture against sampleBlurVariance values, fixing a scale mismatch that rejected every frame when adaptive mode was enabled.

Security

  • Hosted Verification UI — Dependency upgrades (react-router, vitest, ws, and related packages) and nginx hardening for current security advisories.

[2.8.0] - 2026-06-08

Added

  • v2 upload-first pipeline — New POST /api/v2/upload, POST /api/v2/fast-check, and POST /api/v2/live-check endpoints. Upload frames (or a video file) during capture, then run inference by session_id without resending pixels. Additive to v1; existing /api/v1/* endpoints are unchanged. See V2 Upload-First Pipeline.

  • Live Check (POST /api/v1/live-check) — V3-only batch path that accepts SDK-supplied MediaPipe Face Mesh landmarks (≥468 points) per frame so the server can skip its own face-mesh pass and preserve temporal-physio signal quality. SDK: LivenessClient.liveCheck(), useLiveness with endpoint: 'live-check'. See Live Check.

  • React SDK (@moveris/react 3.15.0, @moveris/shared 3.15.0)useLivenessV2 hook and LivenessView pipeline="v2" prop for the upload-first flow (v2Uploadv2FastCheck / v2LiveCheck).

  • Embeddable Cognito widgets (@moveris/cognito-check 0.3.1, @moveris/cognito-check-react 2.0.1) — Added Mixed V3 (10/30/60f) and Mixed V3.1 (10/30/60/90f) model entries and the v3 / v3_1 model versions, so the embeddable widget can target the latest model generations.

  • Meeting Liveness Bot — Concurrent sessions (isolated per-session FrameHandler with scoped WebSocket routing); manual per-participant scan in the interviewer UI (explicit trigger instead of auto-accumulation); full mixed-*-v3_1 model support in scanner and history filters.

Changed

  • React SDK (@moveris/react 3.14.0)useSmartFrameCapture uses VideoFrameSync (requestVideoFrameCallback) on Chrome/Safari to eliminate timer-induced duplicate and skipped frames that corrupt V3+ temporal signals. Falls back to setInterval on Firefox and non-browser environments.

  • React SDK (@moveris/react 3.17.0) — Frame encoding uses fast-png (level 1) instead of canvas.toDataURL, roughly doubling realized capture cadence (~6 fps → ~12 fps) with unchanged pixel data. New optional brightnessThreshold prop on useSmartFrameCapture overrides minimum brightness for frame acceptance.

  • SDK (@moveris/shared 3.18.0)LivenessResult now exposes realScore (the raw real_score from the API, 0.0–1.0). Previously this value was dropped when building the result. Use realScore for decision-making; confidence remains reserved for future use.

  • Idempotency (fast-check family) — Session cache is now model-aware. Reusing a session_id with a different model returns 409 (session_model_mismatch) instead of replaying another model's verdict. Cached responses report the executed model. fast-check-stream pins the model at session creation and rejects mid-stream model switches.

  • Webhook metadata — Fast-check webhook payloads now forward client metadata as tenant_metadata consistently.

Fixed

  • POST /api/v1/verify — Corrected inverted verdict and real_score direction for spatial-feature models; abstains instead of fabricating a verdict when both heart-rate/baseline and spatial feature extraction fail entirely.

  • Hybrid modelshybrid-v2-* and legacy hybrid-50 / hybrid-150 / hybrid-check requests now run the selected hybrid checkpoint instead of silently scoring with the 10-frame anti-spoofing model.

  • Meeting Liveness Bot — Fresh Moveris session_id on re-scan to avoid API cache hits; bot_session_id in request metadata for webhook clustering.

Security

[2.7.0] - 2026-05-14

Changed

  • React SDK (@moveris/react 3.10.1) — Canvas contexts used for capture and quality analysis pin colorSpace: 'srgb' and willReadFrequently: true, reducing pixel drift on Display P3 / wide-gamut displays that previously skewed blur, brightness, and encoded frame data. The default full-frame capture cap moves from 640×480 to 1280×720 to align with the V3.1 training resolution path.

  • React SDK capture format (@moveris/react 3.10.x) — Frame utilities emit PNG base64 only. The previous 'raw' RGBA option and the jpeg-js encoding path were removed from captureVideoFrame and useSmartFrameCapture. Breaking change for advanced integrations: if you relied on 'raw' output or deterministic jpeg-js JPEG, migrate to the returned PNG or encode JPEG yourself outside the helper.

Fixed

  • Containerized inference (MediaPipe) — Docker images ship updated OpenGL libraries and a MediaPipe compatibility shim so face-detection workloads keep running against current upstream library expectations.

[2.6.1] - 2026-05-11

Security

  • Developer Portal APIBackend dependencies updated to address known security advisories.

  • Hosted Verification UI — Dependency upgrades clear current audit findings for the hosted verification web application.

  • Moveris MCP server — Dependency overrides updated so self-hosted MCP installs pick up upstream security fixes.

[2.6.0] - 2026-05-06

Changed

  • React/Shared SDK (@moveris/react and @moveris/shared 3.8.6) — Face-crop generation now matches the server/training pipeline (20% frame-based margin, bounded non-square crop, then resize to 224×224). This reduces false fake outcomes caused by crop mismatch in custom integrations that build their own crops with calculateFaceCropRegion.

  • Breaking change for custom crop pipelines: calculateFaceCropRegion now returns { x, y, width, height } instead of { x, y, size }, and calculateAdaptiveCropMultiplier was removed.

  • React SDK capture pipeline (@moveris/react 3.8.2 – 3.8.5) — Frame encoding is now deterministic across browsers (jpeg-js instead of canvas.toDataURL) and the SDK exposes an optional raw RGBA capture format on useSmartFrameCapture / captureVideoFrame for advanced integrations that need consistent pixel data and to bypass browser JPEG variance.

Security

  • Integration runtime hardening — Additional dependency security fixes shipped across SDK and MCP surfaces, reducing vulnerability exposure for pinned and self-hosted integrator builds.

[2.5.1] - 2026-04-23

Fixed

  • Social login account linking (Developer Portal auth) — When a user signs in with Google or GitHub and the email already exists, the backend now auto-links the social provider to that existing account instead of forcing password login. This removes avoidable login failures for teams using social auth.

[2.5.0] - 2026-04-23

Added

  • Embeddable Cognito widgets (@moveris/cognito-check and @moveris/cognito-check-react 0.1.0) — New SDK packages provide a hosted checkbox-style verification entrypoint for teams that want a lightweight, embeddable verification trigger in web apps.
  • Portal admin cache refresh action — Admins can now trigger allowed-host cache refreshes from the backend tooling, reducing propagation delays when CORS allowlists are updated.

Changed

  • Developer Portal authentication and authorization — Portal-facing endpoints now use JWT auth with role-based access control (RBAC) and organization scoping more consistently, improving tenant isolation for multi-org teams integrating through the portal.
  • Cognito widget UX behavior — Verification checkbox state now locks after success, applies a 30s timeout guard, and standardizes camera preview to a 4:3 aspect ratio to reduce webcam cropping issues.

Fixed

  • API key revocation handling — Revoked API keys now raise a dedicated backend error path and return clearer auth failures for clients, making key-rotation incidents easier to diagnose.

Security

  • Dependency hardening across integration surfaces — Additional vulnerability patches were released across MCP/server tooling and SDK build dependencies, reducing exposure for pinned deployments.

[2.4.1] - 2026-04-22

Changed

  • Verification UI (0.4.0) — Hosted verification flow now forwards camera capability context in crop submissions, improving downstream auditability for integrators using the hosted experience.
  • Developer portal backend reliability — Admin detection listings were optimized to reduce N+1 query overhead in large datasets. This improves performance for teams reviewing verification activity.

Security

  • Runtime dependency hardening — Security updates were shipped across SDK/Verification UI/MCP tooling, reducing known vulnerability exposure for pinned integrations.

[2.4.0] - 2026-04-15

Added

  • Async Video Detect idempotencyPOST /api/v1/{tenant_slug}/video/detect now supports the Idempotency-Key header. Reusing the same key with the same API key returns the original submission_id instead of creating duplicate async jobs, which helps integrators retry safely after network interruptions.
  • React SDK (@moveris/react 3.7.0) — Added LivenessCaptureProvider context plus brightness sampling utilities (sampleCenterBrightness, sampleFaceBrightness) for advanced custom overlays and capture-feedback UIs without prop threading.

Changed

  • React SDK (@moveris/react 3.6.3) — Capture pacing can now be tuned with both captureIntervalMs and minCaptureDelay; the previous hard floor that limited effective capture rate has been removed when you set a lower delay explicitly.
  • Verification UI — Updated to SDK @moveris/react 3.6.3 and aligned capture throttling values for more consistent frame cadence during hosted verification sessions.
  • Developer Portal integration layer — Portal API calls now consistently target the unified /api/v1 paths with Bearer-authenticated requests and envelope-unwrapped responses, improving compatibility with API v2 response handling in portal workflows.

Fixed

  • Async video processing (portrait videos) — Frame extraction now correctly applies OpenCV rotation metadata for portrait MP4 uploads, preventing incorrect orientation during inference.
  • React SDK (@moveris/react 3.6.3) — Camera and detection loops stop as soon as frame collection enters uploading, avoiding unnecessary camera activity while waiting for the API response.

Security

  • Dependency vulnerability updates were shipped across API, MCP, and Verification UI runtimes to reduce exposure for integrators running self-hosted or pinned builds.

[2.3.1] - 2026-04-02

Fixed

  • React SDK (@moveris/react / @moveris/react-native / @moveris/shared 3.6.2) — When the API returns HTTP success but the JSON body has no verdict field, LivenessClient now maps the result to verdict inconclusive instead of throwing LivenessApiError. Responses that include an error or failed success still throw as before.

Changed

  • Developer Portal — transactional emails — Signup, billing, and payment-related notifications use a shared base layout with refreshed copy; payment_failed template binding is corrected.

[2.3.0] - 2026-04-02

Added

  • Developer Portal — organization video settings — Organization admins can set the tenant slug (used in POST/GET /api/v1/{tenant_slug}/video/detect) and an optional video metadata schema (JSON Schema) so metadata on async video submissions is validated consistently. Configure both under Settings in the Developer Portal.
  • Webhook delivery logs — payload echo and filters — Delivery log API responses now include request_body (the JSON body Moveris attempted to deliver). You can filter logs by event_type (e.g. verification.completed, verification.failed) and by model (resolved model in the payload). The Portal Webhook / delivery views add filtering and a detail drawer for each attempt; event labels use the verification.* names.

Changed

  • React SDK (@moveris/react / @moveris/react-native / @moveris/shared 3.6.1) — The “Find better lighting” advisory appears in more real-world lighting conditions (lower dynamic-range threshold), while remaining non-blocking — capture is not stopped.

Security

  • Moveris MCP server — Dependency update to address a reported denial-of-service issue.

[2.2.0] - 2026-04-01

Added

  • verification.failed webhook — In the Developer Portal you can subscribe to a second event type. Moveris sends it when ML inference or async video processing fails after authentication and request validation (covers fast-check, fast-check-crops, fast-check-stream, and tenant video/detect). The JSON body keeps the same top-level shape as verification.completed (event, session_id, timestamp, data); for failures, data includes error, model, input_source, processing_ms, and frames_processed (no verdict). The X-Webhook-Event header is verification.failed. Configure which events each webhook receives in the Portal (completed only, failed only, or both). Signing with your webhook secret works the same as for completed events.
  • React SDK (@moveris/react / @moveris/react-native 3.5.0) — Clearer camera permission denied messaging and built-in denied UI on LivenessCamera.

Changed

  • @moveris/shared (LivenessClient) — Unwraps the API v2 standard JSON envelope (data, success, message) and maps the structured errors array format. Use a @moveris/shared release that includes this behavior together with API v2; upgrade @moveris/react / @moveris/react-native to pick up the matching dependency range.
  • Default model in deployment templates — Example and Fly/Docker configuration defaults now align on mixed-10-v2 where a single default model alias is set (adjust MODELS_* / worker settings for your environment).
  • Developer Portal (backend)Proxies to API v2 unwrap the standard response envelope (e.g. models list for the Portal UI).
  • Moveris MCP server — Consumes API v2 response envelopes; dependency updates for reported vulnerabilities (e.g. path-to-regexp).
  • Verification UI — End-to-end handling of API v2 standard responses.

Fixed

  • Webhook delivery logging — Failure-path deliveries no longer hit invalid null constraints or missing session linkage when emitting verification.failed (delivery logs and MCP session stubs behave consistently).
  • Developer Portal (web UI) — Dependency updates (including pinned axios) to address npm audit findings.

[2.1.0] - 2026-03-30

Added

  • Standard response envelope on all endpoints — Every JSON response is now wrapped in { "data": ..., "success": true/false, "message": "..." }. Error responses include an errors array with error-code-keyed messages. Webhook payloads are not affected (they keep the { event, session_id, timestamp, data } format). See Errors.
  • Async tenant-scoped video detection endpoints — New endpoints for pre-recorded video processing:
  • POST /api/v1/{tenant_slug}/video/detect to submit a video file (or URL) and get a submission_id
  • GET /api/v1/{tenant_slug}/video/detect/{submission_id} to poll status and retrieve results when complete Supports tenant metadata validation, tenant/org access checks, and async queue processing.
  • React SDK camera capability inspection@moveris/react / @moveris/shared (3.4.0) now expose camera capability helpers (getCameraCapabilities, validateCameraRequirements, getOptimalConstraints) plus useCamera capability fields and LivenessView onCapabilities callback for device diagnostics.

Changed

  • Response format (breaking) — All API responses now use the standard envelope. Clients must read response.data for the payload instead of the top-level body. Errors use success: false with errors array instead of the previous flat { "error": "...", "message": "..." } format. Validation errors return 400 (previously 422).
  • React SDK capture quality signals — Recent SDK releases improve real-time capture guidance with matrix-based roll detection and dynamic-range soft warnings ("Find better lighting"), while keeping capture non-blocking for advisory-only conditions.
  • Verification UI capture flow — Verification UI now uses crop-based submission aligned with fast-check-crops and supports alias-based model resolution in requests, improving compatibility with API v2 model versioning.

Fixed

  • Verification UI crop payload shape — Crop submissions now send { index, pixels } objects to match the fast-check-crops schema.
  • Portal/API edge networking for integrators — Upstream platform now forwards Fly-Client-IP through Nginx, improving real client IP visibility for integrations relying on network telemetry.

[2.0.1] - 2026-03-23

Added

  • React SDK: Face area quality gateuseSmartFrameCapture now rejects faces that occupy less than 4% of the frame area. Helps avoid low-quality captures when the user is too far from the camera.
  • React SDK: captureIntervalMs and onEyeWarninguseSmartFrameCapture gains captureIntervalMs (default 100 ms) to tune capture rate (e.g. 50 ms for ~20 FPS). useDetectionPipeline gains onEyeWarning callback for real-time eye quality feedback ("Eyes are in shadow", "Glare detected", etc.) just before onRestartNeeded fires.
  • MCP: frame_count parameterverify-human-presence tool accepts optional frame_count (10, 30, 60, 90, 120) to override the default derived from risk_level.

Changed

  • React SDK: Default endpointLivenessView and useLiveness now default to fast-check-crops instead of fast-check-stream. Pass endpoint="fast-check-stream" to preserve previous behavior.
  • MCP: Alias-based model resolutionverify-human-presence tool uses API v2 alias resolution. Response model field now returns frame count string (e.g. "10", "30"); new model_version and frame_count fields added. Risk levels map to { modelVersion: "latest", frameCount } tuples.

[2.0.0] - 2026-03-20

Added

  • Model versioning (v2 flow) — New frame_count body parameter and X-Model-Version request header for alias-based model resolution. Send X-Model-Version: latest (or v1, v2, fast, etc.) with frame_count: 10|30|60|90|120 to resolve the concrete model. See Model Versioning & Frames.
  • Deprecation response headers — When using a deprecated model, responses include Deprecation: true, Sunset, X-Moveris-Deprecated-Model, and X-Moveris-Suggested-Model. All responses include X-Moveris-Model-Resolved with the resolved model ID.
  • Billing suspension guard — Suspended accounts receive 402 with error: "account_suspended" (distinct from insufficient_credits). Credit pre-check runs before processing; usage logs persist for audit.

Changed

  • CORSX-Model-Version header is now allowed in CORS preflight. Deprecation response headers are exposed to clients.
  • Request schema — When X-Model-Version header is present, the model body field is ignored; resolution uses (version, frame_count) instead.

[1.12.0] - 2026-03-19

Added

  • Fast Check Crops: bg_segmentation — Optional request field to indicate whether background segmentation was applied to crops before sending. Stored in session metadata for A/B analytics comparing model accuracy with vs. without segmentation.

[1.11.3] - 2026-03-17

Security

  • Backend dependency vulnerability fixes to address known security advisories.

[1.11.2] - 2026-03-14

Added

  • React SDK: useDetectionPipeline hook for gaze + eye-region gating, exposing detectionGate and getWarnings() for session warnings at submit time.

Changed

  • React SDK: useSmartFrameCapture now supports external detectionGate and adds restart() for blocking conditions (e.g. hidden/shadowed eyes). Glasses detection is non-blocking and forwarded as a warning.
  • Documentation: API key scopes and frame capture requirements documentation updated (including clarification for capture behavior by endpoint).

[1.11.1] - 2026-03-12

Added

  • AI-readable documentationllms.txt and llms-full.txt added for AI assistant integration (Claude Code, ChatGPT, Cursor). Enables AI tools to discover and use the API documentation during integration.
  • SDK documentation updatesSession ID (sessionId) prop documented for LivenessView, LivenessModal, and useLiveness (React and React Native). CapturedFrame type clarified (timestampMs in SDK, timestamp_ms in API payload).

[1.11.0] - 2026-03-12

Added

  • Capture warnings in fast-check responses — Optional warnings field in request and response for Fast Check, Fast Check Stream, and Fast Check Crops. Frontends can report capture conditions (e.g. "Low light detected", "Face not centered"); the API echoes aggregated warnings in the response for debugging and UX improvement.

Changed

  • Basic Auth for documentation — Optional authentication for documentation endpoints when DOCS_BASIC_AUTH is configured. Protects staging docs from public access.

[1.10.0] - 2026-03-11

Added

  • API key scopes — API keys can be restricted by scope: detection:write, detection:read, session:write, session:read, session:audit, keys:read, keys:write, usage:read, credits:read, webhooks:read, webhooks:write, hosts:read, hosts:write. Create scoped keys in the Developer Portal for least-privilege access. Keys with empty scopes retain full access (backward compatible).

Changed

  • Endpoints now enforce scope requirements. Requests with keys that lack the required scope return 403 with error: "insufficient_scope" and required_scope in the response.

[1.9.1] - 2026-03-10

Fixed

  • Mixed model credit costs — Corrected credit deduction for mixed-v2 models (e.g. mixed-10-v2, mixed-30-v2, mixed-90-v2, mixed-120-v2). Requests using these models now deduct the correct number of credits per model config.

[1.9.0] - 2026-03-10

Added

  • Models registry endpoint — GET /api/v1/models returns the list of available models with id, label, description, min_frames, and deprecated status. Authenticated via shared app-to-app Bearer token. Used by the Developer Portal and SDK useModels hook for dynamic model selection.
  • React SDK useModels hook — Fetch available models from the API and build dynamic model selectors with deprecated-flag support. Integrations can show model descriptions and warn when using deprecated models.

[1.8.0] - 2026-03-10

Added

  • Mixed V2 models — New model family trained on 6,486 videos across 9 attack types. Includes mixed-10-v2, mixed-30-v2, mixed-60-v2, mixed-90-v2, mixed-120-v2 with improved accuracy and per-model EER thresholds. See Models overview.

Deprecated

  • Legacy mixed modelsmixed-10, mixed-30, mixed-60, mixed-90, mixed-120, mixed-150, and mixed-250 are deprecated. Migrate to the corresponding mixed-N-v2 variants.

[1.7.0] - 2026-03-06

Changed

  • Dynamic CORS — CORS allowed origins are now managed via the Developer Portal (AllowedHost entries) instead of a fixed configuration. Organizations can add and manage allowed hosts (e.g. for Qualtrics, Pavlovia, custom domains) without code changes.

[1.6.0] - 2026-03-04

Fixed

  • Documentation — Added missing CLAUDE.md.txt download for AI integration and Claude Code workflows.

[1.5.0] - 2026-03-04

Added

  • Session endpoints for verification landing page — GET /api/v1/sessions/{session_id} returns session context; PATCH /api/v1/sessions/{session_id}/audit records audit events. Enables the verification UI to display session metadata and track user interactions.
  • HMAC verification token authentication — MCP verification flows can use short-lived tokens (in URL or X-API-Key header) instead of API keys. Tokens are HMAC-signed server-side and include an expiration claim.

Changed

  • CORS support for verification landing page — Added verify.moveris.com and dev.verify.moveris.com to allowed origins so the verification UI can call the API without CORS errors.

Fixed

  • React SDK: Eliminated LivenessCamera flickering caused by unstable callback dependencies.
  • React SDK: Injectable sessionId support for liveness detection components.

[1.4.0] - 2026-02-26

Added

  • MCP (Model Context Protocol)AI agents can now verify human presence before high-stakes actions. Integrate Moveris with Cursor, Claude Desktop, ChatGPT, Microsoft Copilot, Meta AI, and other MCP hosts. Documentation includes step-by-step agent configurations.
  • CORS support for Qualtrics and Pavlovia — Embed the liveness flow in Qualtrics and Pavlovia survey subdomains without CORS errors.

Changed

  • Documentation site updated with glossary improvements and MCP reference pages.

[1.3.0] - 2026-02-24

Added

  • Webhook delivery logs — View delivery history and status of webhooks in the Developer Portal. Helps debug failed deliveries and monitor verification callbacks.
  • MCP verification sessions — Create and manage verification sessions for AI agents. Sessions can be tracked and cleaned up automatically.

[1.2.0] - 2026-02-13

Added

  • Fast Check Stream endpoint — New endpoint for high-concurrency frame uploads. Ideal when many users verify in parallel or when you prefer streaming over batch uploads.
  • Organization name and code — API responses can include organization details for multi-tenant integrations.
  • Model cards — Public documentation for each liveness model (Fast, Balanced, Thorough) with use cases and performance characteristics.
  • Documentation portal — Central docs site at documentation.moveris.com with API reference, SDK guides, examples, and best practices.

Changed

  • Improved liveness detection when using mixed frame counts across models.
  • React and React Native SDK documentation expanded with component usage and examples.

[1.1.0] - 2026-02-09

Added

  • Organization invitations — Invite users to your organization via invitation codes in the Developer Portal. Supports email/password and social login flows.
  • Streaming liveness in React — React SDK components now support streaming options for smoother capture flows and lower latency.

Fixed

  • Face-crops endpoint behavior corrected for pre-cropped image submissions.
  • Organization mapping and invitation code validation in the Developer Portal.

How to Read This Changelog

  • Added - New features
  • Changed - Changes to existing functionality
  • Deprecated - Features that will be removed in future versions
  • Removed - Features that have been removed
  • Fixed - Bug fixes
  • Security - Security-related changes