{"asOf":"2026-10-02T00:00:00.000Z","changes":[{"changeId":"chg_0c2a31dbe8f14a019452c709a762bd30","slug":"stripe-mcp-agent-keys-october-2026","title":"Stripe MCP requires Agent Keys or OAuth by October 31","summary":"Starting October 31, 2026, Stripe MCP will reject full-access secret keys and restricted keys without the Agent tag with HTTP 401. OAuth remains available.","action":"For bearer-token connections, create a least-privilege Agent Key, test it in a sandbox, then expire the old key. Interactive clients can reconnect with OAuth. Keep human confirmation enabled.","severity":"ACTION_REQUIRED","affectedClientSlugs":[],"affectedToolSlugs":["stripe"],"factChanges":[{"field":"caveats","before":["Stripe administrators must enable MCP access separately for sandbox and live environments.","Stripe strongly recommends restricted API keys for bearer-token sessions and human confirmation before tools run.","Connected-account access requires a Stripe-Account header and is not available through OAuth."],"after":["Stripe administrators must enable MCP access separately for sandbox and live environments.","From October 31, 2026, Stripe MCP rejects full-access secret keys and restricted keys without the Agent tag; migrate to Agent Keys or OAuth. Keep human confirmation enabled.","Connected-account access requires a Stripe-Account header and is not available through OAuth."]}],"source":{"label":"Stripe: Model Context Protocol","url":"https://docs.stripe.com/mcp"},"observedAt":"2026-10-02T00:00:00.000Z","effectiveAt":"2026-10-31T00:00:00.000Z","publishedAt":"2026-10-02T00:00:00.000Z","isRetrospective":false},{"changeId":"chg_4f1a9c2e7b3d6f805a1c9e2b7d4f6083","slug":"figma-mcp-catalog-adds-windsurf-and-chatgpt-web","title":"Figma MCP catalog added Windsurf and ChatGPT web","summary":"Figma's MCP catalog now lists Windsurf and ChatGPT, expanding the reviewed Figma client allowlist to include Windsurf and the ChatGPT web surface.","action":"No action is needed to keep existing integrations; newly listed clients can now connect.","severity":"INFORMATIONAL","affectedClientSlugs":["chatgpt-web","windsurf"],"affectedToolSlugs":["figma"],"factChanges":[{"field":"allowedClientSlugs","before":["claude-code","codex","cursor","vs-code"],"after":["chatgpt-web","claude-code","codex","cursor","vs-code","windsurf"]}],"source":{"label":"Figma: MCP catalog","url":"https://www.figma.com/mcp-catalog/"},"observedAt":"2026-07-16T00:00:00.000Z","effectiveAt":null,"publishedAt":"2026-07-16T00:00:00.000Z","isRetrospective":false},{"changeId":"chg_6e7f4d1a2b3c4d5e8f9012a3b4c5d6e7","slug":"atlassian-legacy-sse-retirement-2026","title":"Atlassian Rovo MCP retired its legacy SSE endpoint","summary":"Atlassian now requires Streamable HTTP for Rovo MCP connections after retiring its legacy SSE endpoint on June 30, 2026.","action":"Verify that the client uses the current Streamable HTTP endpoint and remove legacy SSE configuration before reconnecting.","severity":"BREAKING","affectedClientSlugs":["claude-code","cursor","gemini-cli"],"affectedToolSlugs":["atlassian"],"factChanges":[{"field":"transports","before":["SSE","STREAMABLE_HTTP"],"after":["STREAMABLE_HTTP"]}],"source":{"label":"Atlassian: Getting started with Rovo MCP","url":"https://support.atlassian.com/atlassian-rovo-mcp-server/docs/getting-started-with-the-atlassian-remote-mcp-server/"},"observedAt":"2026-07-11T00:00:00.000Z","effectiveAt":"2026-06-30T00:00:00.000Z","publishedAt":"2026-07-11T00:00:00.000Z","isRetrospective":true}],"nextCursor":null}