Rotated secrets, Tailscale integration & Kubernetes Operator v2.0
We've added support for automated secret rotation, along with several other platform updates and improvements. We also rewrote the Kubernetes Secrets Operator in Go (2.0), overhauled the secret deployment pipeline so references stay in sync across apps, added self-hosting on Tailscale, and shipped rotation support across the CLI, SDK, and REST API.
Teams, SCIM, Platform APIs & Audit Logs
A wave of access control and platform upgrades — Teams with team-owned service accounts and role overrides, SCIM v2 provisioning to drive the user lifecycle from your identity provider, the full management REST API for Apps, Environments, Roles, Service Accounts, and Members, and a new org-wide audit log that captures every management action across your organization. Here's the full recap.
March 2026
March was a major release month. We rewrote the CLI from Python to Go — shipping a single binary across 16 platform targets that's 75-90% smaller. We introduced Secret Types with sealed write-only secrets, added Azure as a second external identity provider, launched Azure Key Vault sync, released Go SDK 2.0 with pure-Go cryptography, and shipped native AI agent integration. Here's everything.
Improved Cross-Environment Secret Management & More
The Console has been updated with new features and UX improvements to make managing secrets across environments easier and more intuitive. We've also shipped several performance optimizations, bugfixes, and improved secret handling for self-hosted users.
Keep your secrets
Self-host or start on fully managed Cloud in under a minute.
Run Phase on your own infrastructure. Free and open source.