Release v2.28.0
What's Changed
- Document tool approval toggle in MCPJam Agent panel by @mintlify[bot] in #3039
- fix(xaa): re-gate persona strip + registration surfaces behind xaa-registration flag by @chelojimenez in #3224
- Document mcpjam xaa run command and new flags by @mintlify[bot] in #3214
- fix(xaa): CIMD document fetch dies with ERR_INVALID_IP_ADDRESS on Node 20+ by @chelojimenez in #3232
- refactor(oauth): one resource-indicator decision — shared evaluator + per-surface enforcement by @chelojimenez in #3219
- docs(cli): XAA debugger guide page; fix unusable issuer example by @chelojimenez in #3237
- feat(xaa): OIDC/SAML identity-assertion toggle in the debugger header by @chelojimenez in #3234
- skill(mcp-inspector): add Cross-App Access (ID-JAG) coverage by @chelojimenez in #3238
- fix(xaa): mock the xaa-registration flag in the flow-tab suite (main is red) by @chelojimenez in #3241
- feat(xaa): confidential CIMD (private_key_jwt) in the debugger UI by @chelojimenez in #3216
- changesets by @ignaciojimenezr in #3243
Full Changelog: v2.27.0...v2.28.0