NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #2357 most downloaded on pub.dev
A library of Dart and Flutter utility classes that are used across other components of the atPlatform.
Last release today
07 Oct 2026
Release timing varies
gaps range from 8 days to 3 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
6 years old
118 releases · first in 2020
feat: AtConstants.atTelemetrySigningPrivateKey (privatekey:at_telemetry_signing_privatekey) and AtConstants.atTelemetrySigningPublicKey (public:_at_te
AtConstants.atTelemetrySigningPrivateKey
(privatekey:at_telemetry_signing_privatekey) and
AtConstants.atTelemetrySigningPublicKey
(public:_at_telemetry_signing_publickey.__atserver) are reserved keys.
Both are marked @experimental while telemetry signing is in early stages.feat: a notification can carry its own expiry (eAtn) instead of ttln, and an update can be marked ephemeral (eph), which no atServer persists. Send th
eAtn) instead of ttln,
and an update can be marked ephemeral (eph), which no atServer persists.
Send them only to an atServer whose info lists notify.eAtn and
notify.eph.InfoFeatures reads the features an atServer lists in its info
reply, with InfoFeature and InfoFeatureStatus naming them: a feature
counts unless it is Retired, and one that is not GA warns once.One column per quarter.
feat: StoppedException, thrown by the work of a stopped AtClient and by a call on a closed at_lookup connection. It is not an AtException, so a catch
StoppedException, thrown by the work of a stopped AtClient and by
a call on a closed at_lookup connection. It is not an AtException, so a
catch that falls back on an ordinary failure does not take a stop for one.Atsign(String) constructs an atSign the same way toAtsign() does,
so Atsign('@alice') reads as it looks; the two routes cannot disagree.EnrollmentConstants.primaryEnrollmentId (primary) names the
enrollment an atSign's own credential authenticates as: the flat keyfile
material with no enrollment record of its own. PkamVerbBuilder keeps it off
the wire, emitting the bare pkam: a released atServer expects for that
credential, so a client can carry one name for every credential it holds.fix: EnrollmentConstants.regexForPerEnrollmentNamespaces anchors the enrollment id at the start of a key or after a colon as well as after a dot. Anch
fix: EnrollmentConstants.regexForPerEnrollmentNamespaces anchors the
enrollment id at the start of a key or after a colon as well as after a dot.
Anchoring on a dot alone let a key whose name IS the reserved namespace slip
past — abc.a.__e@alice, the shared @bob:abc.a.__e@alice and the cached
cached:@bob:x.r.__e@alice all escaped it. The atServer matches on this
constant to refuse a write into another enrollment's reserved namespace, so
those spellings were unguarded. The named group EnId is unchanged, and
every key that matched before matches now with the same id.
docs: the four __manage constants say what they are. They describe records
that live only on the atServer and never reach a client, which is worth
saying because they read like a sync filter waiting to be wired.
feat: enroll:infons:<namespace> — "info about a namespace". A read verb
alongside enroll:listns, taking the same authorisation, returning a JSON
map of facts about the namespace rather than a list of its members. Its
first member is lastRevokedAt: the latest moment a revocation touched an
enrollment granted that namespace, or null. enroll:listns is unchanged.
fix: Metadata.fromJson preserves a null ttl/ttb/ttr instead of
reading it as 0, so the toJson/fromJson round trip is lossless.
toJson always writes the three, so an unset one goes out as
"ttl": null and used to come back as 0 — leaving a reader unable to
tell "this request said nothing about it" from an explicit 0, which is a
different request: ttl:0 clears a record's expiry and ttr:0 means do
not cache. An explicit 0 still round trips as 0, and a numeric string is
still parsed. The atServer's update:json handling is the caller this
affects; it now agrees with the metadata-fragment form of the same
request, which has always left an unmentioned relative null.
feat: add AtNetworkTimeouts.defaultResponseBudget (90s) — the overall budget for one complete response, as distinct from defaultTimeout, which bounds
feat: add AtNetworkTimeouts.defaultResponseBudget (90s) — the overall budget
for one complete response, as distinct from defaultTimeout, which bounds the
wait for the next bytes and restarts every time a chunk arrives. A large
response is many such waits in a row, and only this budget bounds their sum, so
a peer that trickles bytes indefinitely is caught by this and by nothing else.
Deliberately not passed through cap: it bounds an aggregate rather than a
single operation, and its own default already exceeds the 60s ceiling. Nothing
reads it yet.
docs: signingAlgo says plainly that it names the APKAM authentication
key's algorithm — the key that signs the from: challenge — and not the
algorithm an enrollment signs documents with. The name invites the second
reading and the two are deliberately different algorithms from rollout 1
onward. Stated on EnrollParams, EnrollVerbBuilder and PkamVerbBuilder,
which all declare the field and previously said this in two forms and none.
feat: add EnrollVerbBuilder.apkamPublicKeySignature, threading the existing
EnrollParams.apkamPublicKeySignature through to the built command. The field
had no route to the wire, so an enroll:update could not carry the proof of
possession the atServer requires before it installs a new apkamPublicKey —
which made the rotation the field exists for unsendable.
feat: add Metadata.copy() — a field-for-field copy, so callers handing
metadata from one object to another stop hand-rolling the field list. A
hand-rolled copier silently drops any field added to Metadata later: the
value still round-trips and only the missing field is absent at the far end,
which is how immutable and appMetadata went astray on several paths in
at_client. A caller that must not carry a field clears it after copying, so
the exception is written where it applies rather than being the default.
feat: add EnrollVerbBuilder.apsk, threading the existing EnrollParams.apsk through to the built command. The field had no route to the wire, so nothin
EnrollVerbBuilder.apsk, threading the existing
EnrollParams.apsk through to the built command. The field had no route to
the wire, so nothing could send the value the atServer publishes verbatim.EnrollParams.apskLegacy and the matching EnrollVerbBuilder
field, carrying the bare RSA _apsk string an enrollment publishes
verbatim. Every deployed _apsk consumer base64-decodes the value as an RSA
key, so a plain-legacy enrollment must be able to publish that shape through
the same verb every other enrollment uses. A separate field rather than
widening apsk to two types, which would have been source-breaking on a
published field. The atServer writes it as-is — not JSON-encoded, since a
quoted string is not what a bare-RSA parser reads — and refuses a request
carrying both fields, which would disagree about one record with no basis for
choosing between them.EnrollParams.apsk's entry status is active or retired, not
verifyOnly as 5.14.0 documented, and the entry carries a kid like every
other key entry in the protocol. retired is use-neutral — "retained, not
for new operations" — because use already names the operation a key serves:
a retired signing key still verifies old envelopes, and a retired
encapsulation key still opens records already sealed to it. Documentation
only; the atServer stores the value verbatim, so no record carries either
spelling.feat: add EnrollParams.apsk — the value a client composes for its own public:_apsk. .a.__e@ signing key, carried on enroll:request and stored verbatim
feat: add EnrollParams.apsk — the value a client composes for its own
public:_apsk.<enrollmentId>.a.__e@<atSign> signing key, carried on
enroll:request and stored verbatim on the enrollment record. A
Map<String, dynamic> like metadata, opaque to the atServer, capped there
at 20KB encoded.
It exists so the atServer can stop composing that value from
(apkamPublicKey, signingAlgo). PKAM verification is record-authoritative
and reads the enrollment record, so _apsk is a client-side artefact the
server has no use for and no business knowing the format of — it was
publishing one only because the record's rightful writer, the enrollee, does
not exist yet at approval. Sending the value moves the format back to the
side that owns it, and a new signing-key shape stops needing a server
release. Absent means no _apsk is published at all.
The form the client composes is a versioned array of signing keys —
{"v":1,"keys":[{"use","alg","pub","status"}]} — spelled as KeyPackage's
keys are, so one vocabulary covers every "list of keys with algorithms" in
the protocol. An entry whose status is verifyOnly has stopped signing but
is retained: envelopes are stored durably and re-verified later, so removing
a key would retroactively unverify everything ever signed with it.
feat: add EnrollOperationEnum.update and the matching enroll:update
alternation in the enroll grammar — an approved enrollment amending its own
record's apkamPublicKey, signingAlgo, apsk and metadata. Self-only:
the connection's enrollment id must equal the target's. It never reaches
namespaces or the approval state, because an operation an enrollment can
invoke on itself must not be able to widen its own grant.
This is what lets an enrollment replace its APKAM authentication keypair while keeping its id, rather than the replacement being a new enrollment.
feat: add EnrollParams.apkamPublicKeySignature — base64 of a signature by
the new APKAM private key over
<enrollmentId>|<apkamPublicKey>|<signingAlgo>, required on an
enroll:update that changes apkamPublicKey.
The connection proves possession of the enrollment's current key and nothing else proves possession of the new one, so without this a compromised-but-authenticated client can install a public key whose private half is held by someone else — locking out the legitimate holder while the record still looks valid.
feat: add AtNetworkTimeouts — the process-wide network-timeout policy: defaultTimeout (30s, the per-attempt default), maxAllowed (60s hard cap on any
AtNetworkTimeouts — the process-wide network-timeout policy:
defaultTimeout (30s, the per-attempt default), maxAllowed (60s hard cap on
any single network operation), defaultOnboardingTimeout (5 min — the poll
budget for waiting on a newly-registered atSign to be provisioned, deliberately
longer than the per-op cap), and cap(). The single place to set the SDK's
network timeouts (#1909).SecureSocketConfig.connectTimeout so a connect deadline can be
threaded through to SecureSocket.connect.feat: add the enroll:listns: operation to the enroll verb grammar (the gated per-namespace enrollment-discovery verb), ordered before list in the oper
enroll:listns:<listNamespace> operation to the enroll verb
grammar (the gated per-namespace enrollment-discovery verb), ordered before
list in the operation alternation so it is not prefix-shadowed.EnrollParams.metadata (opaque Map<String, dynamic>, stored
verbatim on the enrollment record and returned from discovery) and
EnrollParams.signingAlgo (rsa2048 | mldsa65), with the matching
EnrollVerbBuilder fields; an empty metadata map is dropped from the
built command.pkam verb signingAlgo literal to accept mldsa65
(post-quantum ML-DSA APKAM authentication).feat: add Metadata.appMetadata (AppMetadata{providerId, additional}), emitted on the wire as :appMetadata: (base64-encoded JSON) on the update, update
Metadata.appMetadata (AppMetadata{providerId, additional}),
emitted on the wire as :appMetadata: (base64-encoded JSON) on the
update, update:meta and notify verbs and parsed back by the verb
builders. providerId routes pluggable-crypto decryption; additional
is provider-owned opaque metadata. providerId must be a non-empty
string (a FormatException is thrown otherwise).feat: add :cl flag to the scan verb syntax, plus ScanVerbBuilder.commitLog
:cl flag to the scan verb syntax, plus
ScanVerbBuilder.commitLog:nc (no-commit) flag to the update, update:meta, update:json
and delete verb syntaxes, plus UpdateVerbBuilder.noCommit and
DeleteVerbBuilder.noCommit:dAt (deletedAt) timestamp to the delete verb syntax, plus
DeleteVerbBuilder.deletedAtMetadata.createdAt / updatedAt / expiresAt / availableAt on
the wire as :cAt: / :uAt: / :eAt: / :aAt: (used by update,
update:meta and notify)2026-05-05T11:59:44.123456Z; helper at VerbUtil.formatIso8601Microsfeat: add AtKey.fullKey getter — key name including its namespace
AtKey.fullKey getter — key name including its namespaceAtKey.fullKeyAndOwner getter — fullKey combined with the owning atSignAtBytesfeat: add AtBytes supporting hardware acceleration in at_chops
AtBytes supporting hardware acceleration in at_chopsfeat: extend syntax of info verb, adding info:mtls and info:mtlsbrief
info verb, adding info:mtls and info:mtlsbriefchore: remove @experimental annotation from EnrollVerbBuilder.otp
@experimental annotation from EnrollVerbBuilder.otpchore: fix lint from the new strict_top_level_inference rule
strict_top_level_inference rulefeat: add AtRootDomain with basic parsing including proxy.
AtRootDomain with basic parsing including proxy.chore(deps): bump uuid to "^4.0.0"
fix: NotifyVerbBuilder.buildCommand() uses AtKey.toString() instead of doing its own thing.
NotifyVerbBuilder.buildCommand() uses AtKey.toString() instead of
doing its own thing.feat: add EnrollmentConstants. Contains various patterns and regular expressions for enrollment-related data
EnrollmentConstants. Contains various patterns and regular
expressions for enrollment-related datafeat: add immutable flag to Metadata and force flag to the DeleteVerbBuilder. Immutable records may not be updated once the immutable flag has been se
immutable flag to Metadata and force flag to the
DeleteVerbBuilder. Immutable records may not be updated once the immutable
flag has been set, and may not be deleted unless the force flag has been
set in the delete command.feat: add Atsign string extensions
fix: remove isPaginated check in SyncVerbBuilder and always set from: and limit: since sync:from verb expects these params to be set.
fix: Introduce IV params for apkam enrollment flow
feat: Introduce skipDeletesUntil for sync:from verb
fix: Add "publicKeyHash" and "hashingAlgo" type to metadata.
- fix: export regex utils class
[Breaking Change]feat: Emit the isEncrypted value in the metadata if it is false
feat: Add "expiry" enroll params to support apkam keys to auto expiry after specified time duration
feat: Add "delete" operation to the enroll verb to allow deletion of denied enrollments
feat: Add "unrevoke" operation to the enroll verb to restore revoked APKAM keys
chore: deprecate MessageTypeEnum.text
fix: Deprecate apkam in PkamAuthMode enum
feat: enroll verb syntax change for enrollforce and added new exception AtEnrollmentRevokeException
fix: Add shared_key.atsign@atsign to reservedKey regex
fix: Add fetch operation to enroll verb to get the enrollment details
fix: max key length validation changes
feat: Enhance enroll:list to enable filtering based on enrollment status
Nothing published for this version
fix: "toJson()" invoked on "pubKeyHash" leads to NullPointerException.
feat: changes to replace md5 checksum - deprecated pubKeyCS in AtKey and introduced new class PublicKeyHash
fix: Add "InvalidPinException" which is thrown when an invalid Semi Permanent Passcode is submitted.
[Breaking Change] fix: Updated regex for Reserved keys (Internal keys used by the server)
fix: Deprecate encryptedDefaultEncryptedPrivateKey in EnrollParams and introduce encryptedDefaultEncryptedPrivateKey for readability
feat: Introduced TTL(Time to Live) for OTP verb to configure OTP expiry
chore: Deprecated all variables in src/at_constants.dart, use AtConstants. instead
src/at_constants.dart, use AtConstants.<variable-name> insteadfeat: Introduce "AtThrottleLimitExceeded" exception which is thrown when enrollment request exceeds the limit
fix: Modify "totp" verb regex to include alphanumeric characters
build(deps): bump github/codeql-action from 2.1.37 to 2.1.38 by @dependabot in #881
Full Changelog: v3.0.51...v3.0.53
fix: Add revoke and list operations to "enroll" verb
fix: git#865 - fixes notifying the switch atSign event multiple times by @sitaram-kalluri in #867
Full Changelog: v3.0.50...v3.0.51
feat: initial commit for at_chops uptake by @murali-shris in #809
feat: added syntax and verb builder for keys verb
feat: totp support in enroll verb
fix: Enhance stats verb to allow regex for stats:15
fix: Modify emoji list to allow variation selector Unicode
fix: Add constants for AtClientParticulars
feat: introduce enum for pkam authentication mode
feat: Enhanced the monitor verb syntax
strict flag to allow client to request that only regex-matching notifications are sent -
e.g. do not send other 'control' type notifications like the 'statsNotifications'multiplexed flag to allow client to indicate that
this socket is also being used for request-response interactionsfix: Tightened the validation of 'public' key names. Keys like this: public:@bob:foo.bar@alice will now correctly be identified as not being valid.
public:@bob:foo.bar@alice will now correctly be identified as not being valid.Your coding agent can read these notes before it upgrades. Set up the MCP server →