Release notes for the CompliAPI sanctions screening API, MCP server, and dashboard — every new endpoint, improvement, fix, and breaking change, grouped by release period with a permalink per release. Breaking changes follow the versioning and deprecation policy.
The Ethiopia-Related Sanctions program is now inactive and archived by OFAC, so CompliAPI no longer returns Ethiopia (ET) as a targeted country in sanctions screening results. All 23 OFAC country program pages have been re-verified as of September 27, 2026, ensuring your country-level compliance checks reflect the current regulatory reality.
CompliAPI's knowledge base is now searchable and indexable on compliapi.com, and the SDN search tool delivers cleaner structured data for better search engine visibility.
CompliAPI's help articles are now available directly at compliapi.com/knowledge-base, giving developers a fast, canonical reference for integration guides, compliance workflows, and API documentation. Articles are fully indexed by search engines, making it easier to find answers when you need them most.
The SDN search tool page now provides valid breadcrumb markup, ensuring search engines can correctly index and display the page in results. This keeps CompliAPI's compliance tools easy to discover when your team needs them.
CompliAPI is now listed on the Official MCP Registry, Smithery, Glama, and a public Postman workspace — making it easier for developers to discover and integrate compliance checks wherever they already work.
CompliAPI is now live on the Official MCP Registry, Smithery, Glama, and a public Postman workspace, so developers can discover and start integrating sanctions screening and geo-fencing checks directly from the tools they already use. Listings on Crunchbase and additional directories are also live, expanding visibility for teams evaluating compliance infrastructure.
No product-facing changes shipped this period — all commits this week were marketing site content, SEO copy, documentation, and internal pipeline tooling.
Paid plans can now register monitored entities — crypto addresses, emails, websites, and government IDs — and receive signed webhook events the moment a watched value is listed, delisted, or relisted on a sanctions list. Automatic retry with exponential backoff and SSRF-safe endpoint validation mean your compliance workflows stay current without polling.
Both the API and the dashboard search now support case-insensitive POSIX regular expressions, letting you match complex name patterns, identifiers, or address formats in a single query. Wrap any query in forward slashes — /pattern/ — to activate regex mode; the same syntax works in the free SDN search tool.
Sanctions name searches are now up to 10× faster and return more relevant results: typo-tolerant word-similarity matching means a query like "ivanof" surfaces "Vladimir Ivanov", while list metadata like chain labels no longer crowd out entity matches. All searches also carry a per-request statement timeout to keep responses consistently fast under load.
A new Monitor button on each search result and recently delisted row deep-links to the webhooks dashboard with the entity type, value, and label pre-filled — no manual copy-pasting required. Monitored-entity labels can also be edited inline without having to delete and re-add the entry.
The search typeahead now cancels superseded in-flight requests so results always reflect your latest query, surfaces rate-limit information with a clear message instead of a generic error, and caches results within your session to reduce redundant requests.
Self-serve account deletion, stronger password security, and expanded OFAC country data ship this week — plus new rate-limit headers and MCP resources for developers building compliance workflows.
You can now close your account from the Account settings page without contacting support — a short offboarding questionnaire and password confirmation are all it takes. Billing is cancelled automatically, and a confirmation email is sent when deletion is complete.
All metered API responses now include standard RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, and RateLimit-Policy headers so your application can monitor quota consumption in real time and back off gracefully before hitting a 429. Monthly quota errors also include a Retry-After header pointing to your next reset.
The MCP server for AI agents now advertises two always-available resources — a live sanctions lists reference and a usage guide — so agent clients get useful compliance context without needing an authenticated session or burning API quota.
The OFAC country designations dataset now includes Afghanistan, Mali, Somalia, and South Sudan, and reflects Syria's transition from the comprehensive Syria program to the successor PAARSS program. Country data is also kept in sync automatically at startup and on a daily schedule, so production always reflects the latest designations without any manual intervention.
The /screen/pep endpoint is now included in the full suite of endpoints activated through the project's x402 payment layer, so developers can start screening for politically exposed persons in the same seamless flow as other compliance checks.
A real-time strength indicator now guides you through meeting the project's password requirements — 12 or more characters with a mix of letters, numbers, and symbols — while creating or resetting your account. The same rules are enforced server-side, so you get clear, specific feedback rather than a generic error if a password doesn't qualify.
the project now publishes a formal API versioning policy: URL-based versioning, additive-only changes within a version, and a minimum 90-day notice window with Sunset and Deprecation headers before any breaking change. You can find the full policy in the API documentation.