# Platform updates, September 2026

Source: https://blog.fortrabbit.com/platform-updates-september-2026
Created: 2026-09-28
Author: Frank Lämmer
Tags: changelog

> MCP, CLI and API released, scoped API tokens, Grav 2, HydePHP and Jigsaw detection, a GitHub token fix, a Safe Browsing listing on our test domains, updated legal documents and a pricing page that renders on the server.


## MCP, CLI and API

Our big feature pack finally landed: an MCP server for coding agents, a CLI for the terminal and pipelines, and the public API underneath both. There is a whole post on it: [MCP, CLI and API are here](/mcp-cli-and-api-launched).

Since then:

- **Scoped API tokens** — a token gets a set of permissions when it is created. Combinations that make no sense are rejected.
- **Build and post-deploy commands** — can be read and set through the API.
- **PHP version** — can be changed through the API.
- **First deployment on request** — creating an environment through the API or MCP no longer deploys right away unless asked to.
- **Environment variables** — handling and validation fixed.
- **Codex login** — `codex mcp login fortrabbit` failed with an error page. Fixed.
- **Software presets** — the MCP tool listing software presets no longer fails on a preset without versions.
- **OAuth-only accounts** — accounts that sign in only with GitHub, GitLab or Google got a 401 from the API and the MCP server. Fixed.
- **MCP registry** — the server is listed in the official MCP registry as `com.fortrabbit/mcp`.

## Platform and infra

- **GitHub token format** — GitHub changed the format of its access tokens, which broke some deployments. Fixed.
- **More software detected** — Grav 2, HydePHP and Jigsaw are now recognized when creating an app.
- **Minutely cron jobs** — jobs scheduled `* * * * *` no longer all start at second zero. Each environment gets a fixed delay of up to 49 seconds, so the load spreads over the minute.

## Safe Browsing warning on frbit.app

On the 18th, Chrome, Safari and Brave started showing "Deceptive site ahead" on `frbit.app` URLs. A client told us. We keep trying fortrabbit easy and low on friction. Some see that as an open door for abuse.

Google Safe Browsing had listed the apex domain `frbit.app`. Safe Browsing walks host suffixes, so a listing on the root hits every `{environment}.{region}.frbit.app` address below it, including apps that had nothing to do with the cause. In all the years on our old app domain `frb.io`, with the same kind of abuse, this never happened.

Google lifted the listing on the 19th, a day after the report. It is an arms race, and we have tightened our measures once more. `frbit.app` is now a verified property in Google Search Console, so we get warned early. Other measures we keep to ourselves.

Test domains are meant for testing. A production site belongs on a domain of its own, see .

## Legal document changes

The terms, privacy statement, data processing agreement and sub-processor list were updated to match the 2026 legal requirements in the EU and Germany. The highlights:

- **Data export and switching** — the terms describe how to take data along (Git, SSH, SFTP, database access, API), with 30-day transition and retrieval periods and no switching fees. That is the EU Data Act.
- **Liability** — rewritten to the German-law standard.
- **Reporting illegal content** — how to report it and how reports are handled, as the Digital Services Act asks.
- **Sub-processors** — Better Stack, Urlbox, Anthropic and the OAuth sign-in providers added, seven services we no longer use removed.
- **Ads** — we are trying paid ads. The privacy statement and cookie policy say what gets measured and where. A Google Ads remarketing tag runs on www, docs and blog, except for visitors in the EEA, UK, Switzerland, Brazil and Quebec.

Each change is a single commit, so the history is readable: see the [legal repository on GitHub](https://github.com/fortrabbit/legal/commits/main). The documents themselves are under .

## Smaller improvements

- **Back to where you started** — booking a component now returns to the page it was started from.
- **Unbooked components** — settings for components that are not booked are marked as such on the environment.
- **Payment methods listed once** — the picker for connecting a payment method to a team showed some methods twice.
- **Account deletion** — deleting an account also deletes its contact in Intercom, our support chat. Contacts left over from earlier deletions are gone too.
- **Deep links** — anchor links on pages with a logged-in footer no longer scroll to the wrong spot.
- **Deployment author** — deployments not started by a fortrabbit user, from a bot for example, show the Git author, in the dashboard, the API and the MCP server. Before, the line with author, target and transport was missing entirely.

## Website and docs

- **One source for prices and limits** — the website, the docs and the API now read plans, prices and limits from the same definitions. Big internal project.
- **Pricing in your currency** — the  renders on the server and software pages show prices in the currency picked.
- **Alternatives pages** — the pages comparing fortrabbit to other hosts got shorter and more opinionated, see .
- **Faster pages** — docs search loads on demand, and CSS ships in one bundle.
- **For machines** — an API catalog and the OpenAPI document are served on the website, so agents can find the API and the MCP server without reading the docs first.
- **Related articles** — docs and blog articles link to others on the same topic at the end.

## From the blog

- [On TUI design patterns](/tui-design-patterns) — every AI coding tool in the terminal invents its own UI. A pitch for shared idioms.

## Kirby Konf 2026

I attended the Kirby CMS conference in Mainz. It was good to meet real people in real life again. A bit odd, though: the crowd was mostly middle-aged white men.

![Bastian Allgeier's sponsor slide](/images/kirby-konf.jpg)

Bastian built his own presentation layer for his talks, sponsor slide included.

![Frank talking to other developers](/images/frank-at-kirby-konf.jpg)

Yours truly, trying hard to explain the world. Photo by René Henrich [via Bsky](https://bsky.app/profile/renehenrich.norden.social.ap.brid.gy/post/3mwg3334bep72).

## Outlook

- **Metrics** — the first version is running on our staging cluster. We took a round of internal feedback and are working it in. Monthly traffic is now counted from the collected history. Last big gap before general availability.
- **Deployment config file** — a `.fortrabbit/deploy.yml` in the repository to define deployment settings next to the code. Running on the staging cluster, a first round of feedback is in.
- **Performance** — still load testing and tuning.
- **Key-value store** — next on the list.
- **First migrations** — a small first batch of apps from the old platform, mostly in the US region. More details follow, the plan is in the .

The new platform is still in BETA. The badge comes off soon, and we are working towards general availability. If something breaks, tell us and we will get on it.
