General availability
The GA cut of the fail-closed, opaque authorization gateway. It gathers every additive, backward-compatible wave shipped since 2.1.0 behind one version — no removed or renamed API, no breaking change. The authorization hot path, the payload lock, and the WORM epoch-header signed bytes are byte-for-byte unchanged.
- Standards interop: an AuthZEN / COAZ decision surface, OAuth 2.1 Resource-Server metadata + issuer pinning, RFC 8693 delegation chains, and the MCP MRT step-up transport.
- A2A task connector — a seventh provider dialect normalized at the gate, byte-identical to the other six.
- Author-your-own community skills with reviewer approval, plus a deny-only community-gate seam.
- Read-only compliance-evidence bundle generated from the real audit record and cross-walked to SOC 2, the EU AI Act, ISO 42001, DORA, and NIST 800-53.
- Portable WORM attestation endpoint + SLSA build provenance for externally-checkable proof.
- Opt-in, privacy-bounded vendor telemetry and off-hot-path license refresh — both default-OFF and fail-safe.
- ReBAC relation-tuple projection for the operator knowledge graph, and off-hot-path JWKS key-set rotation that never goes empty.