What has shipped.
Platform changes, SDK releases and security work, newest first.
Newest first.
- 0.1.1
The API has its own address, api.measura.dev, and the SDK uses it by default.
- ChangedSDKThe default endpoint is https://api.measura.dev/v1/ingest. Apps on 0.1.0 keep working unchanged.
- ChangedDocumentationThe API reference uses https://api.measura.dev/v1/{function}.
- 0.1.0
The Android SDK is on Maven Central as dev.measura:measura-sdk.
- AddedSDKAdd implementation 'dev.measura:measura-sdk:0.1.0' to your app. No more emailed AAR.
- AddedDocumentationThe install guide explains the Advertising ID permission and how apps for children remove it.
- Build milestone
Campaign ROAS in the dashboard, revenue that nets out refunds, a dashboard that works on a phone, and a contact page.
- AddedRevenueCampaign ROAS: attributed installs, purchase revenue and spend per campaign, with spend entered in the dashboard or pulled from a connected network.
- FixedRevenueRefunds, chargebacks and disputes are now subtracted from revenue. They were previously added to it. Revenue reports gross, refunded and net per currency.
- AddedDashboardThe developer dashboard works on phones: the sidebar opens as a drawer, and page headers and forms fit narrow screens. On desktop the sidebar collapses to icons.
- AddedWebsiteA contact page with a form, routed to the team, replacing an email link.
- ChangedDocumentationThe API reference was checked against the code and corrected: status codes, response shapes, plan-gated resources, team and invitation procedures, and the deferred link endpoint.
- Build milestone
The Help assistant answers without an AI model, the Android SDK passed its publish checks on real devices, and the blog was rebuilt.
- AddedHelpThe in-dashboard assistant answers from the documentation and your own workspace data with no AI model required, and hands a conversation to a person when it cannot resolve it.
- FixedAndroid SDKNo crash on Android 5.x, an offline queue that drains in batches the server accepts, key resolution that retries, and Wi-Fi-only and low-battery settings honoured on every send. Verified on Android 5.0 and 11 against staging.
- AddedAndroid SDKhandleDeepLink records a re-engagement when a Measura link opens an app that is already installed, and returns the in-app path.
- ChangedBlogRedesigned blog with cover images and topics.
- FixedWebsiteThe methodology page no longer collapses to a narrow column on phones.
- Build milestone
Integrations were rebuilt around a full webhook lifecycle, and attribution and fraud gained detail views.
- AddedIntegrationsPayment webhooks can be revoked, reactivated and deleted, and every integration is configured from one tabbed page.
- AddedDashboardAttribution and fraud tables open a detail view with the full decision behind each row.
- AddedAndroid SDKCollects the Google advertising ID when the user allows it; configurable with collectAdvertisingId.
- FixedSign-inRefreshed sessions survive redirects, and Google and GitHub always show their account picker.
- Build milestone
All three apps moved to Cloudflare Workers, and a security review was closed out.
- ChangedHostingThe website and both dashboards now run on Cloudflare Workers.
- SecurityAPISix findings from a security review closed, including stricter checks in the edge functions and on confirmed email claims.
- FixedAndroid SDKA blank API key logs an error instead of crashing, and no queued event is dropped on flush.
- ChangedDashboardDialogs trap keyboard focus, and admin tools are limited by staff tier.
- Build milestone
Plans and billing, account closure, and an in-dashboard Help Center.
- AddedHelpHelp Center in the dashboard: support conversations with the team, attachments, and feedback.
- AddedBillingPaid plans with limits enforced on the server, upgrades, scheduled downgrades and usage tracking.
- AddedAccountAccount closure with a 30 day recovery window, data erasure, and a full account export.
- AddedSign-inWorking sign-up, and separate sign-in for customers and staff.
- Build milestone
Revenue outside Play billing is attributed, and conversions are sent back to ad networks in their own formats.
- AddedRevenuePayment webhooks for Paystack, Flutterwave, Stripe and any gateway, with a revenue page showing each payment matched to the install that produced it.
- AddedPostbacksConversion postbacks in Meta, Google, Snapchat and TikTok formats, or Measura’s own JSON to any URL, with retries.
- AddedAndroid SDKServer-controlled SDK settings with a remote kill switch, low battery fallback, uninstall detection through push tokens, and opt-in diagnostics.
- AddedAttributionA later, stronger match now supersedes an earlier attribution instead of being discarded.
- AddedDocumentationDocumentation search and machine-readable copies of the docs for AI tools.
- Build milestone
The Android SDK gained a size budget that the build enforces, so the figure published in the docs cannot drift from what ships.
- AddedAndroid SDKSize budget enforced on every build. The release archive is measured and the build fails if it exceeds the figure published in the docs.
- FixedMarketing siteDuplicate import in the navigation component, and the Gradle version pinned to 8.7 for reproducible builds.
- AddedDeploymentStaging deploy workflow, dormant until a staging project reference is configured.
- Build milestone
Attribution gained a full decision trace, the Android SDK was hardened, and the dashboards were locked down.
- AddedAttributionOrdered matching hierarchy: install referrer, then click identifier, then advertising identifier, then fingerprint, then organic. The first match wins.
- AddedAttributionEvery attribution now stores the signals used, a written reason, and the candidate clicks that were rejected, so a decision can be audited after the fact.
- AddedAttributionAtomic resolution with a uniqueness constraint per install plus an hourly reconciliation pass for orphaned records.
- AddedAndroid SDKPlay Install Referrer integration, which gives deterministic attribution through the store install.
- ChangedAndroid SDKReliability pass covering offline queueing, retry backoff and scheduler resilience.
- SecurityDashboardsContent Security Policy plus a full security header set on both the admin and developer dashboards.
- SecurityAPISigned request replay window narrowed to ten minutes, and tenant identity now read only from server controlled token claims.
- AddedAdminAppend only audit log recording every administrative change with its previous and new values.
- AddedMigrationImporter acceptance tests end to end, including historical attribution rows.
- ChangedData retentionPartition drop path verified and unblocked, giving raw events a working ninety day window.
- Build milestone
First hardening pass after an internal production readiness audit, covering ingestion, metering and rate limiting.
- AddedIngestionBatched event ingestion with per event signature verification and idempotency keys for deduplication.
- AddedBillingMonthly event metering with per plan caps enforced at ingest time.
- AddedAPIDurable rate limiting on the deep link redirector and the key resolution endpoint.
- AddedSecurityAPI keys stored as hashes only, with the plaintext value shown once at creation.
- AddedAttributionRetrying postback delivery to configured advertising networks.
- AddedDatabaseComposite indexes on the hot attribution paths, and correct handling of the all zero advertising identifier that signals a user opted out.
