July 2026
8 min
rate limiting for new identifier creation release date july 30, 2026 when an identifier is created or its parameters are modified, past events are evaluated and matching events are added to the events feed a new per tenant limit of 250k events per hour now caps the total volume of past events matched across all new identifiers in a tenant within a given hour this protects the tenant from being overloaded when many identifiers are created or imported in a short span the limit resets every hour this is in addition to the previously in place per identifier limit of 50k events per data source category together, these limits ensure the volume of past events remains manageable when new identifiers are created learn more docid\ i7enux9t9ne6o67sr7no5 leaked credential event categories release date july 23, 2026 leaked credential events in the tenant feed now include four distinct categories, giving you greater granularity into the validation status of credentials affecting your organization all credentials all credentials discovered by flare valid credentials credentials confirmed to have a correct leaked password, helping you identify and prioritize active exposures invalid credentials credentials confirmed to have an incorrect leaked password, helping you quickly rule out inactive exposures mitigated credentials credentials confirmed to have a correct password, but where mitigation actions have since been taken learn more docid\ us0ed0th0wgzrquhgvxp4 flare mcp server (beta) release date july 22, 2026 the flare mcp (model context protocol) https //api docs flare io/sdk/api mcp server provides ai agents access to flare's tenant/global search and platform apis, allowing them to query flare's threat intelligence dataset and inspect tenant events without writing code using the rest api the following tools are available global search executes a query against the entire flare threat intelligence dataset tenant search executes a query scoped to events matching your monitored identifiers event lookup returns the full event payload for a single event by uid event type reference returns documentation and searchable fields for a given event type learn more https //api docs flare io/event types v2/overview profile returns the current user's profile, including tenants, permissions, and feature flags see the api documentation https //api docs flare io/sdk/api mcp for setup instructions and supported mcp clients please note that this is a beta release and is subject to change password attributes for leaked credential events release date july 8, 2026 leaked credential events can now be filtered by a set of password attributes that describe the leaked password, including its length and the counts of lowercase, uppercase, numeric, and special characters these attributes are available when searching for events in the events feed or global search and in identifier matching policies learn more docid 8ykwptlf5d76xqwa1fwyv identifier discovery policies release date july 6, 2026 identifier discovery policies are now enabled by default for all users these policies control which subdomains are automatically discovered and created as identifiers, helping you focus monitoring on the subdomains that matter and filter out noise with identifier discovery policies, you can define ignore patterns to exclude specific subdomains from automatic discovery reduce noise in your events feed by preventing irrelevant identifiers from being created automatically learn more docid 016efxn7tjf eer7lryd7 astp api updates release date july 6, 2026 two new updates have been made to the astp public api credentials/ search endpoint this endpoint now supports including urls as part of the response, giving you richer context alongside credential results learn more https //api docs flare io/api reference/astp/endpoints/post credentials search urls by credential hash endpoint a new endpoint that allows you to query which urls a particular credential hash is valid for, making it easier to assess the scope of a compromised credential learn more https //api docs flare io/api reference/astp/endpoints/post urls by credential hash