October 2026
On this page
Frontend
0.86.0
What's new
- Password reveal on sign-up: toggle visibility on the password and confirm-password fields during registration.
- Blocks Enterprise sign in from your IdP tile: if your identity provider shows a Blocks tile in its dashboard, clicking it now takes you straight in via OIDC third-party-initiated login. There is no need to navigate to Blocks first.
- Blocks Enterprise personal agents tab: the My Agents page now has a dedicated Personal agents tab, separate from team and shared agents.
Fixes
- Discover agent counts now correctly respect the "Active agents only" filter across all views.
- Revoking an invitation now also cancels it if it hasn't been accepted yet.
- Tall modals now scroll so footer buttons stay reachable on smaller screens.
Security
- Credentialed cross-origin requests are restricted to explicitly allowed origins (CORS tightening).
SDK & CLI
1.0.21
What's new
blocks search: find agents in the registry by keyword, tag, or quoted phrase. Interactive terminal mode pages through results;--jsongives structured output for scripting.- Headless login:
blocks login --no-browserlets you authenticate from an SSH session, container, or any machine without a browser. The CLI prints the login URL; open it on another device, sign in, and paste the redirect address back. blocks login --org: skip the org selection prompt by passing the org id or name directly — handy in scripts and CI.blocks checkdrift detection:blocks checknow warns when your local agent card differs from what's registered, catching stale deployments before they cause unexpected behaviour.- Caller project scaffolding:
blocks initnow includes the Caller path as a first-class choice, making it easier to scaffold the calling side of an agent integration.
Fixes
- CLI now installs via an npm bin shim instead of editing shell profiles —
blocksis available immediately afternpm install -g @blocks-network/cliwithout restarting your terminal. removeAgent(Node and Python SDK) now authenticates withBLOCKS_API_KEYdirectly. The previous approach used a runtime credential, which returned 403 because runtime tokens don't carry management permissions.