Changelog
Every release, and what it costs to move to it.
This file is the summary. The reasoning behind a change lives in docs/decisions/.
Semantic versioning, and the public API is what docs/spec/public-api.md says it is. Adding to it is a minor release; changing it is a major one.
The format follows Keep a Changelog.
[1.0.0] - 2026-09-21
The first stable release. Against 1.0.0-rc.1, it carries what the first run against the live API found, with the standard schema now introspected rather than assembled.
Corporate and OAuth are experimental. Neither has run against Autentique: the Corporate endpoint needs the Corporate plan, and OAuth a registered application. Api\Corporate, Api\OAuth and what only they use are outside the semantic versioning promise until they have, and may change in a minor release (public API).
Changed
- Breaking against
1.0.0-rc.1:Api\Folders::create()no longer takes$type. The live API'screateFolderhas no such argument, and sending it failed. onlySandbox: trueondocuments()->list()andfolders()->documents()now lists only sandbox documents: Autentique ignores the flag, so the page is filtered by the package. The counts stay Autentique's.Api\Corporate::createWebhookEndpoint()acceptssignature.delivery_failedandsignature.biometric_reset, which the API's schema lists and the Corporate documentation left out.
Added
- Enum cases the live schema has and the documentation never mentions:
DocumentStatus::Rejected,EmailTemplateType::SignatureCompleted,PositionElement::Radio,PositionElement::SquareInitials,VerificationType::PfFacialMatch, withSecurityVerification::pfFacialMatch(). Data\Page::filter().Data\User::$group, the token owner's group, read frommebecause Autentique answers an organization'sgroupswith null.
Verified
- Webhooks against real deliveries: the signature, the payload shape (the resource at
event.data), the middleware, the controller and the event.
[1.0.0-rc.1] - 2026-09-21
The first release of lsnepomuceno/laravel-autentique, a new package replacing lsnepomuceno/laravel-autentique-v2. Nothing of the previous package's API survives; what it was and why it was replaced rather than upgraded is recorded in docs/history/from-laravel-autentique-v2.md, and UPGRADE.md maps every part of it.
A release candidate. Everything planned for 1.0.0 is here, and none of it has yet run against Autentique itself: the schemas the operations are validated against are assembled from the documentation, and a run against the sandbox needs a token this repository never holds. 1.0.0 follows that run, tracked in #48.
Added
- Documents:
Autentique::newDocument(), a fluent builder sendingcreateDocumentas a GraphQL multipart request, andAutentique::documents()to find, list, update, block, delete, sign, transfer and move them. - Signers: typed signers reached by email, WhatsApp, SMS or link, with positions, security verifications and a CPF; on an existing document,
Autentique::signers()adds, removes, resends, creates links and approves or rejects biometric checks. - Folders: create, rename, delete, share with people, groups or a link, and list their documents.
- Organizations and email templates.
- Webhooks: verified on the raw body with HMAC SHA-256 before anything runs, both payload shapes read, dispatched as
AutentiqueWebhookReceived, with an opt-in guard against duplicates. - Corporate: child organizations, their members and plans, login codes, webhook endpoints, custom plans and API usage, on the Corporate endpoint.
- OAuth 2.0 with PKCE, and
Autentique::withToken()for any other token. - Files from a path, an upload or a
Storagedisk, streamed in every case. - Errors as one exception per fault under
AutentiqueException; Autentique's documented codes as an enum, in English and Brazilian Portuguese. - Testing:
Autentique::fake(), answering every operation from what was sent, with assertions, andFakeWebhookfor signed webhook requests. - Commands:
autentique:checkandautentique:schema. Autentique::query(), the escape hatch for anything the package does not model.
Every operation is a .graphql file sent with variables only, and the suite validates each one against the API's schema.
The canonical file is CHANGELOG.md in the repository root.