Every shipped change that a caller can see: a new service in the catalogue, a data set the live hosts rolled to, a wave of frozen snapshot hosts, or a client library we now prove works. Newest first.
Watch it from your reader: the Atom feed. Nothing below is announced before it ships.
Every service's quickstart page gained a download row. The Postman v2.1 collection carries one request per served read endpoint, foldered by area, with that provider's own auth header set as the collection auth and baseUrl and apiKey as variables; beside it sits a minimal OpenAPI 3.1 file whose servers block is already our host. Both are generated from our own coverage manifest rather than from a vendor's spec, so they can only describe what we actually serve: 2,353 read requests across the 21 collections. A table on the docs index lists all 42 files.
A caller with a key can now ask any host for a failure on demand. Five faults: rate-limit, which answers with that provider's real over-limit response through the same code path a genuine refusal uses; server-error at 500, 502, 503 or 504 in the provider's documented error envelope; timeout; latency; and the read-only refusal, on a GET. An out-of-range value is refused with a 400 naming the grammar rather than quietly clamped, a substituted response costs no request budget, and every one of them carries an X-SandboxAPIs-Simulated header. Pinned hosts accept the header and stay byte-identical without it.
Three walkthroughs point a Python agent at a pinned GitHub, Jira or Slack host, have it answer one question about a real incident, and assert the answer in five lines of pytest. Every script on those pages is compiled and run by CI, so none of them can claim output nobody produced. The hosts are frozen snapshots, which is what makes an assertion in a test suite safe to keep.
Every one of the 21 services gained a frozen snapshot host on the newest data set, registered and frozen in the same change, taking the registry to 148 hosts with none left unfrozen. All 21 hosts serve one byte-identical artifact, so a Jira pin and a GitHub pin are two dialects of the same story rather than two data sets that happen to agree. Point CI at a -g12 host and it returns the same bytes in a year. The MCP package shipped as 0.3.13 carrying the new registry.
The live hosts cut over to hello-20, the largest single step the data set has taken. Thirteen domains landed together, among them package registries, repository rules, CI runners and CI policy, board configuration, watch graphs, billing periods, resource events and audit actors, alongside 199 rulings that closed rows the sandbox will deliberately never invent. Coverage across the fleet reached 97% of every published read surface, with ten services answering their whole read surface.
The quickstarts page carries snippets for ten real client libraries, each executed against the live hosts by a check that fails unless what it prints is the olympus-labs data set. Both Azure DevOps SDKs and the Jira board filter joined the same day, after the discovery request the official Python SDK sends was served and board filters were honoured. A snippet that stops working stops being published.
CI secret and variable NAMES became part of the data set, so GitHub Actions, Dependabot and Codespaces secrets, GitLab CI variables, Bitbucket pipeline variables and Devin organization secrets all list what a pipeline is given. No value is ever returned, because no secret exists to return. GitHub's coverage badge crossed into Deep for the first time on the back of it.
Four domains landed in one generation. Repository and organization webhooks on GitHub, GitLab and Bitbucket now carry the events they subscribe to, Jira filters and Azure DevOps saved queries answer along with WIQL by id, attachments hang off more parents than issues alone, and directory identities resolve on GitLab. Every stored query was proven to run on its own host before it was published.
The caller's keys and tokens, epic notes and discussions, approval rules, follows, issue links and relations, CODEOWNERS and the folder README, team grants and default reviewers all became part of the data set in one generation. GitLab, GitHub, Bitbucket, Linear, Jira and OpenAI each gained rows from it. This was the first of four cutovers in three days.
Twenty-one pinned snapshot hosts were registered on the newest data set and frozen in the same wave, leaving no unfrozen pin in the registry. Frozen means content-addressed: the artifact behind a pin is verified against a recorded sha before it is served, so a pinned host cannot quietly change under a test suite.
Organization and team memberships, invitations and a role catalog became part of the data set, along with 64 credentials whose last use and expiry derive from the event log rather than being invented. Sixteen vendor reference catalogs started serving from the artifact, covering licences, ignore templates, API versions, hosted runners, Jira project types and more. Every repository gained a LICENSE file, and the plan gained one level of depth plus a subgroup that owns no repository.
The canon-gap generation reached the live hosts: CI configuration, avatars and reactions, the founding order and the two subscription facts the generator had never produced. CircleCI and Buildkite answer their configuration surfaces from it, and reactions resolve on the git hosts and the trackers alike. Twenty-one pins were registered and frozen on it the same day, so every service had a snapshot host carrying the new data set within hours of it going live.
Statuspage serves the outage as customers were told about it: incidents, their updates, components and the page they were published on, all derived from the same incident canon Sentry and PagerDuty read. Its spec was published inside a documentation page rather than as a spec file, so it is pinned to bytes that hold still. Statuspage is the twenty-first read-only replica.
Two build services began serving over CI canon that had existed since the second generation, including a build's real job log rather than a description of one. CircleCI went on to answer its whole read surface three days later. Buildkite serves agents, builds and annotations, and refuses the vendor's own emoji catalogue rather than republishing somebody else's licensed data.
The outage finally reached the support queue. Zendesk serves the desk itself, with tickets, users, macros, views, triggers and an audit trail; HubSpot answers its whole read surface over the same CRM canon; Salesforce serves its sObject core with bounded SOQL that refuses an unsupported query by name instead of guessing at it. Salesforce is the thinnest service in the catalogue and the coverage page says so rather than hiding it.
The 0.3 line of @sandboxapis/mcp taught the published package every service and every pinned snapshot host, so an agent can pick a frozen universe without being told one. CI fails the build if the package's provider list or pin registry drifts from what the hosts actually serve, which is what stopped the published package advertising fewer services than the product had. Later releases in the line added the rate-limit budget to tool results and the orientation copy an agent reads first.
An incident domain landed, so the outage is derived from the event log rather than invented per service. Sentry serves issues and events whose stack traces point at files that exist in the repositories; PagerDuty serves the page that went off, who answered it, and what they did next. Both are about the same afternoon as the Slack thread, the Jira ticket and the pull request that fixed it.
A paid tier for one developer, at $5 a month or $50 a year. It buys rate limit and nothing else: every endpoint and every field is in the free tier, and anonymous access with no account stays free.
Channels, threads and messages became part of the data set, and two services render them. Slack's inverted dialect and the Microsoft Graph teamwork slice tell byte-identical stories, so the same incident thread reads correctly in either client. This is the hop that makes the four-vendor walk on the front page possible.
The OpenAI Platform organization surface arrived from the vendor's own published spec, followed the same day by Codex Analytics. Both project the same simulated engineering work the git hosts already serve, so a model's usage and the commits it helped produce are about one company rather than two unrelated fixtures.
The ninth service, built against the vendor's published v3 API, serving session and enterprise reads over the same engineering story the git hosts tell. Eight endpoints that would have needed invented data are refused by name instead, each with a reason on the coverage page.
The Anthropic Admin API surface, covering the organization, usage and cost reports and Claude Code analytics, plus Cursor's team admin, analytics, AI code tracking and cloud-agent reads. Both are derived from the same simulated engineering work the git hosts serve, so a usage report and the pull requests behind it agree.
A planning domain of sprints, epics and workflow transitions landed, and two trackers render it. Jira serves bounded JQL search, boards, sprints, changelogs and ADF comments; Linear serves a GraphQL schema subset with matching issue identifiers and branch names. The ticket a GitHub pull request closes is the same ticket in either tracker.
Two more git hosts, each in its own REST dialect. Bitbucket Cloud 2.0 serves workspaces, repositories, pull requests, pipelines, deployments and environments; Azure DevOps 7.1 serves git, pull requests, builds, graph identities and Boards including WIQL. The same commits at the same SHAs as GitHub and GitLab, because all four read one compiled artifact.
A Model Context Protocol server over the public API, published to npm as @sandboxapis/mcp and installed in one line. It gives an agent discovery and query tools instead of documentation to read. Calling orient first returns the hosts, the company, the entry points and how to pin a snapshot, so the next call is a correct one.
SandboxAPIs opened with GitHub's REST and GraphQL surface and GitLab's v4 REST and GraphQL surface, both served from one compiled data set. A pull request on GitHub and its merge request on GitLab are two renderings of the same object, down to the head SHA. Responses are validated against each vendor's own published spec on every CI run, and anything not covered answers a provider-shaped 404 rather than a made-up value.