- Added multiple agent‑vault capabilities (members/available endpoint, ungranted member picker, access‑bundle variables, session logs) and introduced token‑auth credential expiry with alerts.
- Implemented security hardening: redacted auth headers/JWTs, added OCSP responder for internal CAs, enforced conditional forbid rules, and refined secret‑scanning endpoint handling.
- Updated UI/UX across the app (inline combobox creation, sticky table header, revamped secret sharing and reference tree) and refreshed documentation and style guides.