Platform updates, September 2026
Created
🆕
Shipped in September.
September started with the MCP, CLI and API release. The rest of the month went into the API around it, a batch of dashboard fixes, updated legal documents, a website that pulls its prices and limits from one place, and a Safe Browsing listing that took our test domains down with it.
MCP, CLI and API
Our big feature pack finally landed: an MCP server for coding agents, a CLI for the terminal and pipelines, and the public API underneath both. There is a whole post on it: MCP, CLI and API are here.
Since then:
- Scoped API tokens — a token gets a set of permissions when it is created. Combinations that make no sense are rejected.
- Build and post-deploy commands — can be read and set through the API.
- PHP version — can be changed through the API.
- First deployment on request — creating an environment through the API or MCP no longer deploys right away unless asked to.
- Environment variables — handling and validation fixed.
- Codex login —
codex mcp login fortrabbitfailed with an error page. Fixed. - Software presets — the MCP tool listing software presets no longer fails on a preset without versions.
- OAuth-only accounts — accounts that sign in only with GitHub, GitLab or Google got a 401 from the API and the MCP server. Fixed.
- MCP registry — the server is listed in the official MCP registry as
com.fortrabbit/mcp.
Platform and infra
- GitHub token format — GitHub changed the format of its access tokens, which broke some deployments. Fixed.
- More software detected — Grav 2, HydePHP and Jigsaw are now recognized when creating an app.
- Minutely cron jobs — jobs scheduled
* * * * *no longer all start at second zero. Each environment gets a fixed delay of up to 49 seconds, so the load spreads over the minute.
Safe Browsing warning on frbit.app
On the 18th, Chrome, Safari and Brave started showing "Deceptive site ahead" on frbit.app URLs. A client told us. We keep trying fortrabbit easy and low on friction. Some see that as an open door for abuse.
Google Safe Browsing had listed the apex domain frbit.app. Safe Browsing walks host suffixes, so a listing on the root hits every {environment}.{region}.frbit.app address below it, including apps that had nothing to do with the cause. In all the years on our old app domain frb.io, with the same kind of abuse, this never happened.
Google lifted the listing on the 19th, a day after the report. It is an arms race, and we have tightened our measures once more. frbit.app is now a verified property in Google Search Console, so we get warned early. Other measures we keep to ourselves.
Test domains are meant for testing. A production site belongs on a domain of its own, see external domain setup.
Legal document changes
The terms, privacy statement, data processing agreement and sub-processor list were updated to match the 2026 legal requirements in the EU and Germany. The highlights:
- Data export and switching — the terms describe how to take data along (Git, SSH, SFTP, database access, API), with 30-day transition and retrieval periods and no switching fees. That is the EU Data Act.
- Liability — rewritten to the German-law standard.
- Reporting illegal content — how to report it and how reports are handled, as the Digital Services Act asks.
- Sub-processors — Better Stack, Urlbox, Anthropic and the OAuth sign-in providers added, seven services we no longer use removed.
- Ads — we are trying paid ads. The privacy statement and cookie policy say what gets measured and where. A Google Ads remarketing tag runs on www, docs and blog, except for visitors in the EEA, UK, Switzerland, Brazil and Quebec.
Each change is a single commit, so the history is readable: see the legal repository on GitHub. The documents themselves are under legal.
Smaller improvements
- Back to where you started — booking a component now returns to the page it was started from.
- Unbooked components — settings for components that are not booked are marked as such on the environment.
- Payment methods listed once — the picker for connecting a payment method to a team showed some methods twice.
- Account deletion — deleting an account also deletes its contact in Intercom, our support chat. Contacts left over from earlier deletions are gone too.
- Deep links — anchor links on pages with a logged-in footer no longer scroll to the wrong spot.
- Deployment author — deployments not started by a fortrabbit user, from a bot for example, show the Git author, in the dashboard, the API and the MCP server. Before, the line with author, target and transport was missing entirely.
Website and docs
- One source for prices and limits — the website, the docs and the API now read plans, prices and limits from the same definitions. Big internal project.
- Pricing in your currency — the pricing page renders on the server and software pages show prices in the currency picked.
- Alternatives pages — the pages comparing fortrabbit to other hosts got shorter and more opinionated, see alternatives.
- Faster pages — docs search loads on demand, and CSS ships in one bundle.
- For machines — an API catalog and the OpenAPI document are served on the website, so agents can find the API and the MCP server without reading the docs first.
- Related articles — docs and blog articles link to others on the same topic at the end.
From the blog
- On TUI design patterns — every AI coding tool in the terminal invents its own UI. A pitch for shared idioms.
Kirby Konf 2026
I attended the Kirby CMS conference in Mainz. It was good to meet real people in real life again. A bit odd, though: the crowd was mostly middle-aged white men.

Bastian built his own presentation layer for his talks, sponsor slide included.

Yours truly, trying hard to explain the world. Photo by René Henrich via Bsky.
Outlook
- Metrics — the first version is running on our staging cluster. We took a round of internal feedback and are working it in. Monthly traffic is now counted from the collected history. Last big gap before general availability.
- Deployment config file — a
.fortrabbit/deploy.ymlin the repository to define deployment settings next to the code. Running on the staging cluster, a first round of feedback is in. - Performance — still load testing and tuning.
- Key-value store — next on the list.
- First migrations — a small first batch of apps from the old platform, mostly in the US region. More details follow, the plan is in the migration program.
The new platform is still in BETA. The badge comes off soon, and we are working towards general availability. If something breaks, tell us and we will get on it.