> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Changelog

> Developer-visible changes to the Kyberis API, MCP server, and authentication, by production release date.

Each entry lists changes to the Kyberis API, MCP server, authentication, and
documentation that became available in production on the date shown (UTC). Entries
cover only behavior you can observe as a developer.

<Note>
  **Action required** at the top of an entry marks a change that may require you
  to update a client, integration, or automation. Filter entries by tag, or
  subscribe to this page with RSS at `/changelog/rss.xml`.
</Note>

<Update label="2026-09-23" description="ATT&CK detection traversal on relationships" tags={["API", "New"]} rss={{ title: "ATT&CK detection traversal on relationships" }}>
  ### New

  * **Traverse ATT\&CK detection knowledge.** `/v2/relationships` now links techniques to tactics, detection strategies, analytics, data components, and data sources. Use `relationship_types` for the related entity type, `predicates` for the link meaning, and `direction`, `platform`, and `include_inactive` to narrow results. See [Traverse ATT\&CK detection knowledge](/guides/pivot-relationships#traverse-att\&ck-detection-knowledge).
  * **Existing relationship requests are unchanged.** General actor, campaign, malware, IOC, sector, and country pivots keep their default behavior; ATT\&CK traversal applies only when you request an ATT\&CK predicate or target type. ATT\&CK cursors follow their own rules. See [ATT\&CK relationship responses](/responses/relationships#att\&ck-relationship-responses).
</Update>

<Update label="2026-09-22" description="Enterprise IoC feed" tags={["API", "New"]} rss={{ title: "Enterprise IoC feed" }}>
  ### New

  * **IoC feed for enterprise accounts.** `GET /v2/ioc-feed` keeps a local indicator dataset in sync: retrieve a paginated snapshot, then poll daily for additions, updates, and removals with the saved `next_cursor`. Kyberis must enable feed access for your account. See [IoC feed](/api-reference/endpoint/ioc-feed).
  * **Confidence intervals.** Set `min_confidence` and `max_confidence` on the first request to limit the feed to an interval of source confidence. See [Select a confidence interval](/api-reference/endpoint/ioc-feed#select-a-confidence-interval).
  * **Upsert-based credits.** Each page costs 10 credits per 1,000 upserts, rounded up; removals and empty responses are free. Cursors expire with retained feed history after seven days, so poll regularly. See [Access and credits](/api-reference/endpoint/ioc-feed#access-and-credits).
</Update>

<Update label="2026-09-15" description="Structured CVE inventory and exploitation-based confidence" tags={["API", "New", "Improved", "Breaking"]} rss={{ title: "Structured CVE inventory and exploitation-based confidence" }}>
  <Warning>
    **Action required**

    * **Check applicability before patching from `/v2/prioritize`.** CVE items now use `recommended_action_type: validate_exposure` with conditional remediation advice, or `monitor` for a conditional product exclusion. Automation that triggers a patch from `recommended_action_type` must perform the applicability check first. See [CVE inventory applicability](/responses/prioritize#cve-inventory-applicability).
    * **Review CVE confidence thresholds.** CVE assessment `confidence` now represents support for known exploitation, not confidence that your environment is vulnerable, and can be lower than before. If you filter or alert on `confidence`, read it together with `metadata.evidence_support` and `metadata.conditional_on`. See [CVE environment applicability](/responses/assessments#cve-environment-applicability).
  </Warning>

  ### New

  * **Structured inventory for environment assessments.** Send `environment_context.products` to `/v2/environment-assessments`, and set `inventory_complete: true` only when the list covers the entire environment. Read `metadata.applicability` for product-level `affected`, `unaffected`, or `unknown` status. See [CVE environment applicability](/responses/assessments#cve-environment-applicability).
  * **Product applicability on prioritized CVEs.** CVE items from `/v2/prioritize` include `product_match` and `applicability` without debug mode. See [CVE inventory applicability](/responses/prioritize#cve-inventory-applicability).

  ### Improved

  * **Consistent product matching.** Equivalent inventory and source product names now produce the same product applicability on `/v2/prioritize` and `/v2/environment-assessments`. Free-text `environment` is retained but not interpreted; the response reports `metadata.environment_text_evaluated: false`. See [CVE environment applicability](/responses/assessments#cve-environment-applicability).
</Update>

<Update label="2026-09-08" description="Enrichment-aware IoC scoring" tags={["API", "Improved"]} rss={{ title: "Enrichment-aware IoC scoring" }}>
  ### Improved

  * **IoC scores reflect enrichment context.** When Kyberis has indicator intelligence for an IOC, `/v2/ioc-assessments` adds a bounded enrichment boost, capped at 8 confidence points, for MITRE breadth, malware context, attribution, targeting, and source diversity. IOCs with richer context can now rank above sparser IOCs with similar base confidence. See [Enrichment-aware scoring](/guides/investigate-ioc#enrichment-aware-scoring).
  * **Inspect the enrichment contribution.** Read the total in `metadata.ioc_enrichment_boost`. With `options.include_debug: true` and the `debug:assessments` scope, `debug.signal_data.enrichment_boost_breakdown` returns the five component values. See [Enrichment scoring](/api-reference/endpoint/ioc-assessments#enrichment-scoring).
</Update>

<Update label="2026-08-21" description="Direct API-key auth for MCP and stable relationship pages" tags={["API", "MCP", "Authentication", "New", "Improved", "Breaking"]} rss={{ title: "Direct API-key auth for MCP and stable relationship pages" }}>
  <Warning>
    **Action required**

    * **Pass relationship cursors back unchanged.** `/v2/relationships` pagination now uses opaque snapshot cursors that expire after 10 minutes. Pass `next_cursor` back unchanged with the same request inputs, and do not build, parse, or modify cursors. See [General relationship pagination](/responses/relationships#general-relationship-pagination).
  </Warning>

  ### New

  * **Direct API-key authentication for MCP.** One-command MCP setup now installs `Authorization: ApiKey <key_id>:<secret>` in your MCP client, so tool calls use your API key directly. To switch a client you set up earlier, reconnect it from **API keys**. See [How MCP access works](/install/mcp#how-mcp-access-works).

  ### Improved

  * **Stable, larger relationship pages.** Paged traversal returns the same ordered results regardless of page size within a snapshot of up to 500 ranked results. `max_results` accepts 1–100. See [General relationship pagination](/responses/relationships#general-relationship-pagination).
</Update>
