Ship privacy-first analytics with a 10-second install.
Back to resources
Changelog

v1.1.0 — API-key auth, per-project CORS, Geo-IP

Aug 20263 min read

v1.1.0 closes the security gap that mattered most: every ingestion and metrics request now requires a per-project Bearer API key. Unauthenticated requests receive 401; a key from one project reading another project returns 403.

CORS is now enforced per project. Each project defines its allowed_origins, and the server rejects any origin outside the allowlist at the browser preflight. The wildcard header is gone from production responses entirely.

Geo-IP moves to CDN headers where available: CF-IPCountry and X-Vercel-IP-Country are read server-side, with a client-side provider race as fallback. Server-side values always take precedence over anything a client sends.

Finally, the internal cost dashboard is now exposed at /internals/cost behind the admin scope, so operators can watch cost per event in real time.

Turn every signal into your next decision.

Start with a lightweight tracker. Grow into agent-readable product intelligence.

No cookies. No third-party ad tracking. Your telemetry stays yours.