Changelog

Product updates and improvements.

FlareStarter Pro

v1.0.0

2026-08-23

Added

  • Organizations & RBAC — teams with email invitations and an accept-invitation landing page, owner/admin/member roles, and a single server-side guard behind every org route.
  • Seat billing — a Stripe quantity-model subscription per organization; seats sync as members join and leave, with the daily cron reconciling the count. Plan resolution falls back to the owner's personal entitlement.
  • API keys & rate limiting — org-scoped keys stored as SHA-256 hashes (the secret is shown once), KV sliding-window limits per plan, per-key daily usage, and a reference /api/v1/hello endpoint.
  • Credits metering — balance plus an append-only ledger; top-ups are idempotent by reference, so webhook replays are free, and spends use a conditional update that cannot over-draw under concurrency.
  • AI chat — streaming Workers AI metered per message: charged before the call, refunded when the upstream fails. Hidden entirely without the AI binding.
  • Growth kit — double-sided referral rewards at verification and first payment (with a cron settlement sweep), Stripe promotion codes with deep links and a read-only admin view, and D0/D3/D7 drip emails with HMAC-signed one-click unsubscribe.
  • Security pack — an append-only audit log over 20 sensitive event types with org and global views and a 180-day retention sweep, TOTP two-factor with backup codes and trusted devices, and admin impersonation that is logged start to finish.
  • Blog — an MDX content collection with per-locale variants, RSS, Article JSON-LD, and build-time OG images.
  • Solo mode — ORGS_MODE=solo hides organizations completely; a personal workspace carries credits, API keys and AI.
  • License & delivery — the commercial license is published at /license, and lifetime buyers assign GitHub seats themselves on the License page (Solo 1 / Team 4) with a profile preview before each invitation goes out.

Notes

  • Every slice ships with both test layers — pure logic in the node pool, real D1/KV in the workers pool.
  • The Apache 2.0 core stays open and complete; Pro is the commercial layer on top of it.