Skip to main content

Release — v0.9.11

Date: August 12, 2026 Version: 0.9.11 Category: Release
← Back to Changelog

Overview

Release v0.9.11 turns the REST API into a metered product. Requests are now priced in API credits weighted by what an endpoint actually costs to run, Specialist and Industrial Pro carry a monthly included allowance, and past that allowance a prepaid, opt-in overage takes over with a spend cap and a hard ceiling behind it. It also ships a prepaid credit ledger, an API console on the dashboard, a new /v1/science and /v1/tokens surface, live usage feeds, and a site-wide screen, tab, region and canvas recorder. Industrial Pro's previously unlimited API allowance becomes finite in this release — subscriptions started before 12 August 2026 are grandfathered, and that is covered in full below.

Table of Contents

  1. 1. Highlights
  2. 2. Tokens and API credits are two different things
  3. 3. The metered API
  4. 4. Prepaid overage, spend caps, and ceilings
  5. 5. Industrial Pro: unlimited becomes finite
  6. 6. The API console
  7. 7. New API endpoints
  8. 8. Screen, tab, region and canvas recorder
  9. 9. Full change list
  10. 10. Technical Notes
  11. 11. Testing & Quality
  12. 12. How to Report Issues

1. Highlights

+
  • The REST API is now metered in credits: one credit is one standard request, and heavier endpoints cost more because they cost more to run.
  • Specialist includes 1,000,000 credits a month; Industrial Pro includes 10,000,000. Both refresh at the start of each billing month.
  • Overage is prepaid and off until you turn it on. It can only ever spend credits already bought, at $1.00 (₹85) per 100,000 credits. There is no invoice after the fact.
  • Two independent safety nets: a monthly spend cap you set, and a hard ceiling of ten times your included allowance that applies regardless.
  • Industrial Pro's unlimited API allowance is now a finite 10,000,000 credits a month. Subscriptions started before 12 August 2026 keep the old allowance.
  • Added an API console to the dashboard's API Keys tab: burn-down, end-of-period projection, usage chart, per-endpoint spend, credit balance, spend cap, overage toggle, and a live call feed.
  • Added a prepaid credit ledger in the auth worker. Debits and top-ups are idempotent on their reference, so a retried call or a repeated webhook can only ever move money once.
  • Added new API surface: /v1/science/* (63 colour spaces, delta-E, correlated colour temperature), /v1/tokens/* (design tokens with ten export targets), /v1/catalog, and the /v1/usage/live and /v1/usage/stream feeds.
  • Added a site-wide recorder for screen, tab, region and canvas capture, with video, animated GIF, PNG frame and poster export.
  • Cut usage-analytics writes by 99.6% in measurement by coalescing them, which is what makes allowances this size affordable.
  • API access is now sold from Specialist upward. Plans without it get an explicit upgrade response instead of a confusing empty quota.

2. Tokens and API credits are two different things

+

This release introduces a second meter, so it is worth being blunt about what each one is. They are separate balances, bought separately, spent on different things, and neither pays for the other.

  Tokens API credits
What they pay for Tool work that runs on our servers — full-site accessibility crawls and batch jobs. Anything that runs in your browser is free and unmetered. REST API calls to /v1/*, and nothing else.
What one unit is Roughly $0.10 of metered work — the reference rate allowances are sized against. One standard request. Heavier endpoints cost more credits.
What plans include Apprentice 100 once (a starter balance, it does not renew); Artisan 250, Specialist 1,000, Industrial Pro 2,500 — per billing month. Apprentice and Artisan none; Specialist 1,000,000, Industrial Pro 10,000,000 — per billing month.
Where they live Pricing → Tokens, and the token bar on the Analyzer. Pricing → API credits, and the API console on the dashboard.

The two are roughly a thousand times apart in unit value, which is the main reason to keep them apart in your head: a thousand API credits is under a rupee's worth of API traffic, whereas a thousand tokens is an entire month of a Specialist plan's tool allowance. Nothing in this release converts one into the other, and we have not merged them.

A third, unrelated use of the word. The new /v1/tokens/* endpoints generate design tokens — CSS custom properties, Sass variables, Tailwind theme config and so on. They have nothing to do with the site's token currency, and calling them spends API credits like any other endpoint.

3. The metered API

+

The monthly quota is denominated in credits rather than calls. One credit is one unit of standard work; endpoints are weighted by what they actually consume, so a caller doing simple colour maths is not subsidising one rendering images. Every response carries an x-credits-cost header stating what that call consumed.

Credits What it buys
1 Standard work — /v1/color/convert, /v1/color/contrast, /v1/science/convert, /v1/science/spaces, /v1/accessibility/check, /v1/accessibility/recommend, /v1/vision/simulate, polling a job with /v1/jobs/id/, and any endpoint nobody has weighted yet
2–4 Generators and multi-step maths — /v1/palette/generate, /v1/palette/evaluate, /v1/harmony/generate, /v1/gradient/generate, /v1/shade/scale, /v1/graphql, /v1/tokens/export (2); /v1/science/delta-e (2); /v1/ishihara/plate and /v1/science/temperature (3); /v1/tokens/generate (4)
5 /v1/science/dossier, which walks all 63 colour spaces plus a locus search in one call; and /v1/usage/stream, charged once when the stream opens — the events themselves are free
10–12 Rendered pixels — /v1/palette/png, /v1/gradient/png, /v1/ishihara/png (10); /v1/vision/simulate-image, /v1/palette/from-image, /v1/accessibility/from-image (12)
25 Async jobs — POST /v1/jobs/{type}, which does batch work on our clock

What each plan includes. Specialist includes 1,000,000 credits a month and Industrial Pro 10,000,000, both refreshing at the start of the billing month. Credits are pooled per account, not per key — ten keys draw on one allowance, so splitting traffic across keys buys nothing. Sustained around the clock those allowances work out at roughly 22 and 224 credits a minute, against per-minute rate limits of 300 and 3,000: on a plan running flat out it is the monthly allowance you meet first, not the rate limit. They are sized for normal use.

API access is now a paid feature. It is included from Specialist upward, matching what the pricing page has always sold. A key created on Apprentice or Artisan still authenticates — so the dashboard can manage it — but metered endpoints refuse it with a 402 PLAN_UPGRADE_REQUIRED naming the plan and the upgrade path, rather than the previous behaviour of reporting a quota of zero as exhausted. Discovery stays open to everyone: /v1, /v1/catalog, /v1/health, /v1/tiers and the docs need no key, so you can read the whole catalogue before deciding whether to buy.

4. Prepaid overage, spend caps, and ceilings

+

By default, running out means stopping. Past your included allowance you get a 429 telling you the allowance is used up and when it resets. Nothing is billed, and nothing changes about that unless you deliberately change it.

If you want calls to keep working, overage is opt-in and prepaid. Two conditions, both of which must hold, and the second is the important one:

  • You have turned overage on. It ships off, and the only way it turns on is you turning it on in the dashboard.
  • You have a prepaid credit balance that covers the call. Overage spends credits bought in advance at $1.00 (₹85) per 100,000 credits. If the balance will not cover a call, the call is refused with a 402 rather than served on account.

That is the whole design: nothing in the metering path can produce an invoice. There is no bill after the fact, ever — not for a runaway retry loop, not for a leaked key, not for a traffic spike you did not expect. The worst case is refused requests, which is a problem you can see and fix, rather than a charge you discover later.

Credit top-ups are self-serve. Buy a pack from Dashboard → API keys → Add credits. The order is priced server-side from the pack you pick — the client never names a price — and purchased credits do not expire at period end. Overage can only ever spend a balance you have already bought, so a call past your allowance is refused rather than billed after the fact. For volume beyond the largest pack, a custom rate limit, or a contract, tell us what you need.

Two safety nets, independent of each other. You can set a monthly spend cap in the dashboard (up to $10,000) and overage stops there. Separately, and regardless of anything you configure or how large your balance is, every account has a hard ceiling of ten times its included allowance in one month — a backstop so a runaway client cannot drain a balance overnight. Support can raise it per key if you genuinely need it lifted.

Each refusal says which of these stopped you, so the fix is never a guessing game: allowance exhausted and the plan cannot buy more, allowance exhausted but opting in would fix it, your own spend cap, the hard ceiling, or an insufficient balance.

5. Industrial Pro: unlimited becomes finite

+

Industrial Pro was previously sold with an unlimited API allowance. As of this release it includes 10,000,000 credits per billing month, with prepaid overage past that on the same terms as every other paid tier. We are stating that plainly rather than leaving it to be discovered in a rate-limit response.

The reason for the change is that "unlimited" is not something anyone can actually operate: it cannot be capacity-planned, it cannot be metered, and a single leaked key can burn the margin on an entire tier. A finite number that nobody reaches in normal use is more honest than an infinite one we would have had to police informally.

If you subscribed to Industrial Pro before 12 August 2026, you keep what you bought. Subscriptions created before 12 August 2026, 00:00 UTC are grandfathered onto an allowance a hundred times the new quota — not reachable inside a month at the tier's 3,000 requests per minute. You do not need to do anything, and there is nothing to opt into. The finite 10,000,000 allowance applies to Industrial Pro subscriptions started on or after that date.

Grandfathering is decided from the subscription's creation date rather than a maintained list of accounts, so it cannot go stale or miss anyone. It is deliberately a very large finite number rather than infinity: that honours the promise in every practical sense while still leaving a bound in the system, which is the difference between honouring a promise and having no safety net at all.

6. The API console

+

The dashboard's API Keys tab gained a console for the meter, in four panels:

  • Usage & cost — a burn-down of credits used against credits included, an end-of-period projection with whether you are running ahead of or inside your allowance, days left in the period, overage credits and their cost, and a usage chart drawn as SVG against the site's theme tokens.
  • Where the credits went — the same daily rows aggregated per endpoint, so an unexpected burn can be traced to the call responsible.
  • Credits & spend — your prepaid balance, the overage toggle, the monthly spend cap, and a statement of recent ledger transactions.
  • Live usage — individual calls as they happen, streamed over server-sent events from /v1/usage/stream.

The figures come from the API, and the API authenticates with an API key — there is deliberately no session-authenticated route to a meter. The console therefore asks you to paste a key, holds it in sessionStorage only (gone when the tab closes; never localStorage, never a cookie), and uses it for both the polled figures and the stream. Declining costs you the usage figures and nothing else: the balance and the spend controls are session-authenticated and work without a key, because you must always be able to turn paid usage off without producing one.

7. New API endpoints

+
  • Colour science — /v1/science/spaces and /v1/science/spaces/{key} expose the registry of 63 colour spaces with full provenance (primaries, white point, transfer curve, gamut coverage, the standard that defines it); /v1/science/convert converts between them; /v1/science/dossier returns a colour in all of them at once; /v1/science/delta-e computes CIE76, CIE94, CIEDE2000 and CMC; /v1/science/temperature does correlated colour temperature both ways; /v1/science/illuminants and /v1/science/metrics list the reference data.
  • Design tokens — /v1/tokens/generate builds a token set with gamut fitting and contrast checking, /v1/tokens/export renders it, and /v1/tokens/formats lists the ten export targets: CSS custom properties, Sass, Less, W3C Design Tokens JSON, Tailwind theme config, modern CSS (OKLCH with light-dark()), Android colors.xml, SwiftUI, Flutter ThemeData, and Jetpack Compose.
  • Catalogue — /v1/catalog returns the whole endpoint catalogue as JSON, grouped, with common errors and response headers. It needs no key, so tooling can discover the API before anyone has bought anything.
  • Usage feeds — /v1/usage/live polls the recent tail of individual calls with a cursor, and /v1/usage/stream streams them over server-sent events. These sit alongside the existing /v1/usage daily history rather than replacing it.

The science endpoints drive the same space engine the browser tool uses rather than reimplementing any of it, so the API and the UI cannot disagree about a conversion.

8. Screen, tab, region and canvas recorder

+

Added a recorder available site-wide, covering four capture surfaces: a whole screen or window you pick, this tab without the picker, a region of the current page, and a tool's own canvas — the last of which is pixel-exact and independent of what is on screen, so scrolling cannot spoil a take.

A finished recording can be saved as a video file (MP4 where the browser supports it, WebM otherwise), an animated GIF, a folder of PNG frames, a poster still, or a trimmed clip. Recordings are held in the browser's own storage; nothing is uploaded.

9. Full change list

+
  1. Weighted credit meter — Added per-endpoint credit weighting, included monthly allowances, and a single pure decision function that authorises or refuses every metered request.
  2. Prepaid, opt-in overage — Added pay-as-you-go past the included allowance at $1.00 (₹85) per 100,000 credits, off by default and payable only from a balance bought in advance.
  3. Spend caps — Added a customer-set monthly overage cap, enforced against the month's total overage rather than a single request.
  4. Hard ceilings — Added an absolute monthly ceiling of ten times the included allowance, independent of any customer setting, liftable per key by support.
  5. Industrial Pro allowance — Replaced the unlimited API allowance with 10,000,000 credits per billing month.
  6. Grandfathering — Industrial Pro subscriptions created before 12 August 2026 keep an allowance a hundred times the new quota, decided from the subscription date rather than a maintained list.
  7. Plan gate — Restricted API access to Specialist and above. Plans without it now receive an explicit upgrade response; the free tier's API quota is zero.
  8. Prepaid credit ledger — Added credit accounts and a transaction statement to the auth worker, with balances that cannot go negative and every change recorded with the balance it produced.
  9. Idempotent money movement — Made metered debits idempotent on the request id and top-ups idempotent on the order id, so a retried call and a webhook delivered twice each move money exactly once.
  10. Billing adapter — Added the API worker's client for the ledger, which fails closed on every error path: an outage refuses paid traffic rather than giving it away.
  11. API console — Added burn-down, projection, usage chart, per-endpoint spend, credit balance, spend cap, overage toggle and a live call feed to the dashboard's API Keys tab.
  12. Colour science endpoints — Added /v1/science/*: 63 colour spaces with provenance, conversion, a full dossier, four delta-E metrics, and correlated colour temperature.
  13. Design token endpoints — Added /v1/tokens/*: token generation with gamut fitting and contrast checking, plus export to ten targets.
  14. Catalogue endpoint — Added /v1/catalog, the machine-readable endpoint catalogue, open without a key.
  15. Live usage — Added /v1/usage/live polling and /v1/usage/stream server-sent events alongside the existing daily history.
  16. Usage write coalescing — Coalesced usage-analytics writes by identity, day, endpoint and status, measured at 99.6% fewer writes in tests.
  17. Recorder — Added a site-wide screen, tab, region and canvas recorder with video, GIF, PNG frame, poster and trim export.

10. Technical Notes

+
  • Money is counted exactly; telemetry is counted cheaply. Quota and overage are counted transactionally, per request, in a Durable Object. The coalesced usage buffer is analytics only — what a dashboard draws. Losing a few seconds of it to an evicted isolate costs a slightly short chart, never a wrong charge.
  • Why the writes were worth coalescing. Usage bookkeeping was around 90% of the marginal cost of serving a request, because a per-request usage cell meant a read and a write each time. Requests sharing an identity, day, endpoint and status land in one cell, so a thousand of them become one write. Cells accumulate rather than overwrite, so totals survive the optimisation intact.
  • Metering is per account, not per key. Every dashboard-issued key on an account resolves to the same identity, so the allowance, the ceiling and the credit balance are shared across all of them.
  • The ledger fails closed. If the credit ledger is unreachable, the API treats the account as having no overage allowance and no balance. That refuses a handful of paid requests during an outage rather than serving traffic that is never paid for; included-quota traffic is untouched, because billing is only consulted once a request is past its allowance.
  • Debits are not retried blindly. A debit that times out may already have committed, so it is only replayed because the ledger is idempotent on the request id. Every charge carries that id, which makes a charge reconcilable and refundable by lookup rather than by investigation.
  • The recorder is lazy. Only a small shim loads on a normal page view; the engine, UI, GIF encoder and exporters are pulled in the first time someone actually records. The Analyzer route has under 2 KB of headroom, so a recorder that loaded eagerly could not have shipped at all.
  • The GIF encoder is ours. Encoding is hand-written JavaScript with frame diffing — no ffmpeg, no WebAssembly — so a re-encode costs roughly real time and reports progress while it works.
  • New endpoints are never free by accident. An endpoint nobody has weighted yet bills as standard work, which is the safe direction to get wrong.

11. Testing & Quality

+

The metering path carries dedicated suites: the pricing decision function, overage and refusal reasons, the plan gate, the credit ledger and its seam with the API, quota enforcement, and the usage buffer — alongside the existing unit, integration, contract, OpenAPI and webhook-security suites. Because the decision function is pure and synchronous, every branch that can spend money is exercised directly. The buffer's tests measure the thing that costs money — writes reaching the store — and then prove the totals survive coalescing exactly, because a cheaper counter that counts wrong is worthless. A separate mirror test keeps the browser console's copy of the credit weights honest against the server's.

12. How to Report Issues

+

When filing an issue, please include: steps to reproduce, browser/OS, affected page, tool or endpoint, screenshots or recordings, console logs where available, and whether the issue relates to API metering, credits and overage, the API console, a specific /v1 endpoint, or the recorder. For an API problem, the x-request-id header from the response is the fastest way for us to find the call — and for anything involving a charge, it is the reference the ledger records, so quote it.