Changelog
September 27, 2026
The agent flow: connect over MCP, search, run a job, get the result, fall back to the next provider, and see provider counts per category. The CLI stays on looot 1.1.0; no CLI update is needed for this release.
For agents
- Run a job, not a provider:
endpointId: "job:people.email.verify". looot picks the provider and says why inrequestedJob. - Common field names work on job runs:
email,url,domain,name,first_name,last_name,company,linkedin_url,phone(camelCase too). looot maps them to each provider’s own schema. - Fallback:
fallback: truemoves to the next provider of the same job on a miss. Every attempt, the provider that served it (servedEndpointId) and the exact prices are on the run. - A
normalizedblock on completed runs: the same field names whatever provider answered (email verify, email find, scrape, company enrich; 20 endpoints so far). - A bad email, URL, domain or phone on a job run is refused before any provider runs, at $0.
- Providers that have actually run rank above untried ones.
catalog_overviewreports providers and endpoints per category and job.
Money
- 24 endpoints no longer charge when the provider reports a failure inside an otherwise successful response.
- One company-lookup-by-email endpoint now settles on the provider’s own reported cost, so a miss is $0.
- A live test of 50 providers (202 runs) reconciled every checked run on the ledger.
Catalog data
- 171 raw provider job names were merged into standard job ids, cutting the “other” bucket from 68% of jobs to 10%.
- Output examples use values from saved provider answers, and prices for one large provider now come from its own published price list.
September 26, 2026
npm install -g looot now installs 1.1.0.
A change you may need to make
looot token prints your secret to stdout, so it now needs --reveal, on a terminal and in a
pipe alike. Before this release it printed into any pipe, and an agent’s shell is always a pipe,
so an agent’s token could land in its own logs.
If your shell profile has:
export LOOOT_TOKEN="$(looot token)"
change it to:
export LOOOT_TOKEN="$(looot token --reveal 2>/dev/null)"
With the old line, LOOOT_TOKEN is empty after upgrading. looot doctor flags this. The CLI
itself keeps working from your saved login either way.
Fixed
- Signed-out
looot catalog endpointsfollows the paging cursor to the end (it used to repeat page 1), and says when your--limitwas capped. --waitis validated before sending:--wait=abcor a value outside 0 to 60 whole seconds now gets a clear message. It used to get a generic error or a silent cap.looot searchwith no text says it needs search text, with an example.looot runs evidenceshows evidence fields (an input fingerprint, ledger references), separate fromruns attempts.
Better results, no upgrade needed
These landed on the gateway, so they apply to every CLI version:
- For a job the catalog doesn’t cover, search says “no provider does this job yet”. It used to list unrelated endpoints.
- Filtering by a job name search already recognizes returns that job’s endpoints.
- The cheapest reliable provider ranks first for phone lookup, scraping to markdown and backlinks.
- Validation errors name the field that failed.
- Run results never include a provider account’s own remaining credits.
September 25, 2026
The first public release. npm install -g looot installs looot 1.0.0: browser sign-in with
nothing to copy by hand, browsing the catalog with no account, one-line errors, typed errors on
MCP, catalog listings that only offer what can actually run, and this documentation site.
Verified with a fresh, unassisted customer test. Full details are in the
v1.0.1 notes, released the same day from that test’s findings.
September 25, 2026
The public CLI release. Since the last internal build (2026-09-22):
For customers
loooton npm. One command, zero dependencies, no source code shipped. The old install script and package name are gone.- Browse before signing up.
looot search "<task>"andlooot inspect <id>work with no account, from the public catalog, with full endpoint ids and prices. - Sign in without copying a secret.
looot loginprints a link and a code and opens the approve page on looot.ai. You check the code, machine and organization, choose a label, scopes and an expiry, and approve. Only a one-way digest of the token ever leaves your machine. The token then appears in Settings, Agent tokens, as “CLI on <machine>”.looot logoutrevokes it on the server, verified dead within seconds. - Safer agent setup.
looot initwrites a reference to your token, never the secret itself;init --dry-runshows only looot’s own entry, never another tool’s configuration. - Clearer errors. One line, exit code 1, no stack trace. Unknown commands say so.
- Catalog truth. Endpoints looot’s platform keys can’t actually serve are no longer offered as runnable.
Fixed the same day, from the first customer test
- Clicking Deny in the browser now stops the terminal by itself. It used to leave it waiting.
looot loginandlooot whoamishow the organization’s name and the token’s expiry date.- Every customer-facing surface (docs, dashboard, the plain-text agent docs, the MCP tool descriptions, the npm page) says looot consistently.
- The money rule is stated everywhere: browsing needs no account, running needs sign-in and a funded balance (no trial credit). The insufficient-balance message shows one short link to pay.
runs listshows $0 or “pending” where it used to show a broken number; receipts no longer show an internal placeholder value.
How it was verified
Four rounds of a fresh, unassisted customer test: install from npm, browse, sign in with a human
approving in the browser, one paid call, sign out, and confirm the token is revoked. Round 1
found 8 problems; round 2 found a secret leaking into init --dry-run’s JSON and a broken install
link in the docs; round 3 found an endpoint the platform key couldn’t actually serve. All were
fixed. The verdict on the published 1.0.0 build: yes, install, browse, sign-in, a paid call with
an exact balance change, sign-out and revocation all worked. On 1.0.1: yes again, with Deny
stopping the CLI on its own, the organization name and token expiry showing, a paid call
reconciling to the cent, and sign-out revoking the token.
September 22, 2026
- A slow read no longer freezes a request for the platform’s own database: it now times out at a few seconds and the caller gets a retryable error, not a long stall.
- You only see endpoints that can actually run for your workspace, whether through a platform key
or your own connection. Pass
includeUnavailableto see the rest. - Running out of balance answers with a clear 402 and a Stripe Checkout link, a suggested amount,
and a plain-English message;
GET /v1/balancecarries the same link. - Stripe went live: top-ups now take card payments.
- Failure handling improved on five providers so a failed call is reliably charged $0.
September 21, 2026
- Numeric fields sent as either a number or a numeric string are both accepted.
- A run’s hold is now sized from the largest volume signal in the input (a limit, a page size, a batch array). It used to assume the smallest case.
- A 200 response that actually reports a failure inside its body now fails the run and charges $0, on endpoints where that check is defined.
- Maximum sizes were added to 134 volume and cost inputs across the catalog, and worst-case prices were corrected on 131 endpoints from two providers.
- Failure-detection rules were added to 182 endpoints across six providers, so more failed calls settle at $0. An empty or error result is not charged.
Every change here was independently reviewed and proven with paid calls checked against the ledger.
September 20, 2026
A dashboard-only release: the gateway itself didn’t change.
Nobody waits
- Every signed-in page now paints its frame in 0.3 to 0.4 seconds. Four pages used to wait for the gateway before showing anything.
- Every click gives feedback in under 100 ms: a progress bar and the clicked item highlight right away.
- Coming back to a page within 20 seconds costs no extra server round trip.
- Fewer round trips per page: dashboard overview 4 (was 6), run list 2 (was 5), usage 7 (was 9), settings 7 (was 11), connections 14 (was 18).
- Nine “Refresh” buttons that silently did nothing now actually refresh, with a pending state; ten forms now stay busy until the new data is on screen.
Nothing big to load
- Every list (catalog, platforms, providers, organizations, settings, connections) now pages through one shared component, including server-side search over the largest platform’s more than 1,200 rows.
- The catalog page’s HTML is 0.3 MB, down from 4.6 MB; the operations page is 0.4 MB, down from 1.2 MB.
Correct numbers
- “Runs this week”, “Spent this week” and “Success rate” are now computed exactly. They used to be estimated from your last 50 runs.
Under the hood
- The session cache is now keyed by user and active organization, closing a gap an independent review found.
- Every number above was measured in a browser against production. Page size and server timers were not used as evidence.
September 20, 2026
- Sessions are now cached by token kind, which made the dashboard noticeably faster:
/connectionsloads in 1.25 seconds (was 2.1) and/usagein under 1 second (was about 1.7), measured in a browser. GET /v1/connectionsnow carries each connection’s latest test receipt.
September 20, 2026
- The run list and five other lists in the dashboard now page on the server. They no longer load everything at once.
- Fixed the mobile footer and the phone header layout.
- A bigger footer wordmark and header links that show earlier on larger screens.
September 20, 2026
- Your ledger list now sorts correctly past 9,999 entries; it used to stop counting there.
- Sign in with Google or GitHub, with a hardened check on where you’re sent back to afterward.
September 19, 2026
Speed
- A paid call that waits for its result now takes 2.2 to 2.5 seconds. It took 3.8 to 4.3 seconds before, and 5 to 13 seconds under load.
- Listing your connected OAuth providers takes 0.3 seconds, down from 6.5.
- The dashboard overview, usage, settings and operations pages now read in parallel and load a lighter catalog directory.
Reliability
- A brief database outage no longer causes the gateway to spin; it retries within a fixed budget.
- A busy database now answers with a retryable error, not a generic server failure.
- Your run list tolerates clock differences. One bad run is set aside and the rest of the page still loads.
Product
- No looot fee for now: a platform-key call is charged the provider’s price only.
- Search now matches common phrasing, for example “ip geolocation” finds the right endpoints.
- The
loootCLI shipped, with an installer.
Known, and next
- One internal record grew large from a day of test runs; the growth on the run path is stopped and cleanup is next.
- A large number of endpoints are labeled as needing your own key although they in fact run on looot’s platform keys; correcting the label from run evidence is next.
September 18, 2026
The first OAuth provider proven live: a live Google Analytics connection from the Connections page, with two Analytics calls completing through the gateway at $0.
Fixed
- Calls on a connected account (not a platform key) were being routed to the wrong internal path and failing before they reached the provider. This was the root cause of every failed Google Analytics run.
- Connection-based call failures now carry a proper error type, the provider’s HTTP status, and a redacted provider message.
- The “consent expiring soon” warning now only shows when there’s genuinely no refresh token, and reconnecting clears earlier warnings.
September 18, 2026
- Connect Google Calendar, Gmail, Sheets and Drive with one click; Google Analytics and Search Console now request offline access so your connection keeps working after the first token expires.
- You can see which OAuth apps are set up for each provider from your own session.
- Every connect, save and revoke button now shows a pending state (“Connecting…”, “Saving…”, “Revoking…”) while it works.
Verified live against Gmail labels and messages, Search Console sites, and Analytics accounts and summaries.
September 17, 2026
- Long-running async jobs that don’t finish in time now park and get rechecked on a backoff schedule for up to 24 hours. A result that comes back empty, or never comes back, is not charged.
- Eight providers joined the catalog on the connect-your-own-account track: Instantly, lemlist, Smartlead, HubSpot, Pipedrive, Attio, Apollo (sequences) and Notion.
- The Connections page now lists “Connect your account” providers separately.
- A feedback button was added to every page.
- The public site grew pricing, how-it-works, agent-client and legal pages, and a Markdown mirror of the catalog for agents to read directly.
Known gaps at this point: one provider (basic-auth) wasn’t yet offered on Connections, the eight new providers showed placeholder tiles until logos were added, and calls made with your own key were $0 until pricing for that case was decided.
September 17, 2026
- Providers can now be connected by OAuth, with credentials stored per provider so a provider can offer more than one way to connect.
- If a worker crashes mid-call on a long-running job, the job now resumes automatically instead of needing operator attention.
- Slack, Google Analytics and Search Console joined the catalog on the connect-your-own-account track.
- The Connections page grew “Connect with Google Analytics” and “Connect with Search Console” buttons, a reconnect option for revoked connections, and setup help for providers that use a pasted key (HubSpot, Notion, Slack, Instantly, Smartlead, Pipedrive, Attio, Apollo).
Not in this release: a platform fee on calls made with your own key (still $0), and looot as an OAuth provider for ChatGPT- and claude.ai-style connectors.