Changelog
Product updates and improvements.
FlareStarter Pro
v1.0.02026-08-23
Added
- Organizations & RBAC — teams with email invitations and an accept-invitation landing page, owner/admin/member roles, and a single server-side guard behind every org route.
- Seat billing — a Stripe quantity-model subscription per organization; seats sync as members join and leave, with the daily cron reconciling the count. Plan resolution falls back to the owner's personal entitlement.
- API keys & rate limiting — org-scoped keys stored as SHA-256 hashes (the secret is shown once), KV sliding-window limits per plan, per-key daily usage, and a reference
/api/v1/helloendpoint. - Credits metering — balance plus an append-only ledger; top-ups are idempotent by reference, so webhook replays are free, and spends use a conditional update that cannot over-draw under concurrency.
- AI chat — streaming Workers AI metered per message: charged before the call, refunded when the upstream fails. Hidden entirely without the AI binding.
- Growth kit — double-sided referral rewards at verification and first payment (with a cron settlement sweep), Stripe promotion codes with deep links and a read-only admin view, and D0/D3/D7 drip emails with HMAC-signed one-click unsubscribe.
- Security pack — an append-only audit log over 20 sensitive event types with org and global views and a 180-day retention sweep, TOTP two-factor with backup codes and trusted devices, and admin impersonation that is logged start to finish.
- Blog — an MDX content collection with per-locale variants, RSS, Article JSON-LD, and build-time OG images.
- Solo mode —
ORGS_MODE=solohides organizations completely; a personal workspace carries credits, API keys and AI. - License & delivery — the commercial license is published at
/license, and lifetime buyers assign GitHub seats themselves on the License page (Solo 1 / Team 4) with a profile preview before each invitation goes out.
Notes
- Every slice ships with both test layers — pure logic in the node pool, real D1/KV in the workers pool.
- The Apache 2.0 core stays open and complete; Pro is the commercial layer on top of it.