Hextner
VerifIPDetectBTPricingDocsSupport
Sign inStart free →
Changelog

Release notes 

Last updated: October 5, 2026

What changed in the VerifIP API, the DetectBT script, the console and this site, newest first. Each entry is dated the day the change went live. To hear about new entries, subscribe to the RSS feed. Every endpoint and field is described in the API documentation.

Website: Full-text pages and structured data

October 5, 2026

  • Every public page on hextner.com is now delivered as complete HTML, so tools that do not run JavaScript see the same text you do.
  • The sitemap now carries last-modified dates. New: llms.txt and llms-full.txt (a plain-text copy of the site for language models), and structured data that describes Hextner, VerifIP and DetectBT.

DetectBT 3.3.0: One billed evaluation per page load

October 5, 2026

  • The script checks each tab once when it loads. The page’s first getToken() or evaluate() without options now reuses that check, if its token is unused, under 4.5 minutes old and not a bot verdict. A page that loads the script and asks for one token on submit is billed one evaluation, not two.
  • A page that is prerendered but never opened is not evaluated: the automatic check waits until the page is shown.
  • Behaviour change: the script no longer evaluates automatically inside an iframe. Add data-allow-iframe="true" to the script tag to keep the old behaviour. Calls you make yourself inside a frame still work.
  • New data-debug="true" attribute on the script tag turns on debug logging.
  • The script is about 23 KB gzipped (64,784 bytes uncompressed).

VerifIP API 1.4.2: Quota refusals are free and say when to retry

October 4, 2026

  • A request refused by your quota (429 rate_limit_exceeded, the free daily cap or your monthly quota) is not billed: X-VerifIP-Units-Billed is 0, and X-RateLimit-Remaining no longer counts the refused request.
  • That 429 now also carries retry_after in the body: the seconds until your quota resets, the same value as the Retry-After header.
  • A batch body that is valid JSON but not an object (null, an array, a number or a string) now gets 400 invalid_request, not billed. null used to get a 500.
  • A 503 service_unavailable sent when the quota service cannot be reached now says when to retry: retry_after: 1 in the body and Retry-After: 1. It is still not billed.
  • GET /health now reports commit, the build of the API that answered.
  • OpenAPI description: email and phone batch entries list their invalid flag, and voip_known_provider is marked as not currently produced.

Docs: Burst limits are described as approximate

October 4, 2026

  • The per-plan burst rates are a soft brake, counted per Cloudflare location, so traffic spread over several connections can exceed them for a short time. Pace requests on your side. The monthly quota is the exact limit.
  • Only the descriptions changed: the plan numbers, headers, error codes and limiting behaviour are the same.

Console: Clearer account deletion

October 3, 2026

  • Deleting your account now tells you the date it will be permanently erased: 30 days after you delete it. A deleted account can no longer sign in.
  • Deleting an account ends any paid plan immediately, without refund for the unused period, and the console says so before you confirm. To use a plan until its period ends, cancel it first.
  • Within the 30 days, email contact@hextner.com to ask for the account back. Plans and API keys are not restored.

VerifIP API 1.4.0: WHOIS from the registries, real phone line types

September 26, 2026

  • /v1/whois asks the regional registry that holds the address directly. network_cidr is now real CIDR notation (several prefixes are joined with ", "), the registry’s own identifier moved to the new network_handle, and allocation_date is YYYY-MM-DD.
  • Phone line_type is classified with full numbering data, so ordinary mobiles answer mobile instead of unknown, and valid is a full pattern check.
  • ssl_status: valid no longer passes a certificate that fails validation.
  • New enum values: blocklisted in threat_categories, Unknown for connection_type, and rdns in enrichment_incomplete. Treat values you do not recognise as opaque.
  • The URL check echoes the URL exactly as you sent it.

VerifIP API 1.3.0: OpenAPI description and fairer billing

September 25, 2026

  • The API describes itself: GET /openapi.json and GET /openapi.yaml on verifip.hextner.com, with no key needed. Generate a typed client from it.
  • Not billed: requests refused as invalid (400), unknown endpoints (404), wrong methods (405), a batch on the Free plan (403 plan_required) and a publishable key used on the data API (403 public_key_not_allowed).
  • Browsers can read the rate-limit and billing headers in a cross-origin fetch().

VerifIP API: Official language SDKs retired

September 25, 2026

  • No new versions of the VerifIP language SDKs will be published. Installed versions keep working against the API, but they will not learn new fields.
  • For new code, call the HTTPS API directly with your language’s standard HTTP client, as the docs show, or generate a client from the OpenAPI description.

VerifIP API 1.2.0: IPv6 for every key

September 25, 2026

  • Public IPv6 addresses get a score instead of a 400 on /v1/check, batch, /v1/assess, /v1/whois and /v1/report.
  • Every IP answer carries ip_version (4 or 6). IPv6 answers list the sources that have no IPv6 data in signals_unavailable.
  • Every spelling of an IPv4-mapped IPv6 address is answered as the IPv4 address it carries.
Hextner

Adversarial traffic detection for teams that ship to the open internet.

Product

  • VerifIP
  • DetectBT
  • Pricing
  • Documentation

Company

  • Support
  • Release notes
  • Talk to sales
  • Get an API key
  • Console

Stay in the loop

Release notes (also as an RSS feed), new signals, and the occasional write-up on how detection actually gets evaded.

Create an account →

This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP blocklist data: The Spamhaus Project (DROP). Phishing data: PhishTank, CC BY-SA 2.5. Malware data: abuse.ch. Hextner uses the IP2Proxy LITE database for IP geolocation. Full notices: Data sources.

© 2026 Hextner. All rights reserved.
Privacy PolicyTerms of ServiceData sources