v0.1.6
[0.1.6] - 2026-08-01
Changed
-
platformnow reports the operating system, not the JavaScript runtime.
It previously sentnode/deno/bun/web, which meant every Electron
app reportednodeno matter which OS it ran on — so a dashboard could not
tell a Windows install base from a macOS one, and the breakdown was not
comparable with the Swift, Rust, C++ and C# SDKs, all of which report the OS.
It now sends the same canonical tokens they do:macos,windows,linux
(and an unmappedprocess.platformvalue verbatim, e.g.freebsd).Where there is genuinely no host OS to report — a page in a browser, an
isolate on the edge — the runtime token is still the honest answer and is
kept:web,workers,unknown. The SDK deliberately does not read
navigator.userAgentData.platformto guess a browser's OS; it is
Chromium-only and a fingerprinting surface, and this SDK avoids the
User-Agent for the same reason it avoids it ininstance_name.No app code changes. If you have been reading the platform breakdown, expect
nodeto stop growing andmacos/windows/linuxto start; historical
rows keep their old token.
Added
sdkfield identifying this SDK on activate/validate/keyless calls.
Sendsjs. Keylight used to work out which SDK a device ran from the shape
of itsplatformtoken — feasible only while each SDK had its own
vocabulary, which the change above ends. Exported asSDK_ID. Requires no
action from you; older SDK versions keep working, and the server falls back to
the previous inference when the field is absent.
Added
activeRevalidate()— forced, 60 s-debounced revalidation for active use.
Call it when the user brings the app forward (window focus, popover open,
route change) so a dashboard revoke lands within a minute instead of waiting
for the next launch. It bypassesrefreshIfNeeded's staleness gates
(5 min / 6 h / 24 h) and sharescheckOnLaunch's reconciliation: a definitive
server rejection downgrades immediately, a network blip never downgrades a
live session, and it never throws. The debounce is held in memory only, so a
process restart or page reload always revalidates. Mirrors the Swift SDK's
activeRevalidate().
Fixed
- The
activeRevalidate()debounce no longer follows the wall clock. It now
measures elapsed time withperformance.now(). Because the debounce
suppresses revalidation, a system clock moved backwards previously
suppressed revocation enforcement for the size of the jump — indefinitely, if
the clock stayed back. Falls back to the previous behaviour only where
performanceis unavailable.