What NangoHQ/nango shipped
Written by FoxPlug from public releases; not affiliated with Nango. An automatic summary of the public release, pull request and commit data of github.com/NangoHQ/nango. Nango did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Live catalog actions can now run as invocable actions through HTTP triggers and the dashboard. Pull request #7613
- Salesforce webhooks now require verification using a Nango webhook secret in the X-Nango-Webhook-Secret header. Pull request #7630
- Unsigned webhook providers (Affinity, Fillout, ShipStation) now require the webhookSecret stored in connection metadata. Pull request #7629
- All server events now carry account, environment, and
is_prodcontext automatically through middleware. Pull request #7627 - CLI now supports on-events trigger for functions, allowing functions to run when events occur. Pull request #7634
- Omnisend API-key authentication provider added to Nango Core. Pull request #7515
- MCP_OAUTH2_GENERIC integrations can now be created and managed through the public API. Pull request #7529
- Fixed inaccessible Upgrade links in tooltips by moving them outside tooltip triggers. Pull request #7467
- Removed SWR from webapp and migrated remaining hooks to react-query for consistent cache clearing. Pull request #7635
- Disabled autocapture events sent to PostHog, reducing ingestion by approximately 90%. Pull request #7655
Why it matters
Webhook security improvements across multiple providers now enforce signature verification. Live catalog actions bring new capabilities to function invocation. API improvements extend management functionality while webapp and event tracking changes improve reliability and reduce costs.
Changelog entry
- Live catalog actions can be invoked through HTTP triggers and the dashboard Pull request #7613
- Salesforce webhooks require X-Nango-Webhook-Secret header for verification Pull request #7630
- Unsigned webhooks (Affinity, Fillout, ShipStation) require webhookSecret in X-Nango-Webhook-Secret header or nangoWebhookSecret query param Pull request #7629
- All server events now carry account, environment, and
is_prodcontext through middleware Pull request #7627 - CLI supports on-events trigger for functions Pull request #7634
- MCP_OAUTH2_GENERIC integrations can be created and managed through the public API Pull request #7529
- Added Omnisend API-key provider Pull request #7515
- Added Tracify Analytics API-key provider Pull request #7507
- Added PostHog Capture provider Pull request #7645
- Added JobNimbus provider Pull request #7638
- Added eWay CRM provider Pull request #7637
- Added UKG Pro WFM CC provider Pull request #7636
- Fixed inaccessible Upgrade links in tooltips Pull request #7467
- Migrated remaining SWR hooks to react-query Pull request #7635
Webhooks now verify signatures for Salesforce, Affinity, Fillout, and ShipStation. Live catalog actions run as invocable functions. MCP integrations work through the public API. Six new provider integrations added.
This week brings webhook security enhancements across Salesforce and unsigned providers, requiring secrets for verification. Live catalog actions are now executable through HTTP triggers and the dashboard. MCP_OAUTH2_GENERIC integrations gain public API support. The CLI accepts on-events triggers for functions. Six new integrations added: Omnisend, Tracify, PostHog Capture, JobNimbus, eWay CRM, UKG Pro WFM. Webapp improvements reduce costs and fix accessibility issues.
Week of September 14, 2026
What shipped
- Scheduled functions now execute as the same entity type as regular functions, with optional logId and variant fields in the orchestrator payload. Pull request #7563
- Dashboard login and consent flow added to the OAuth server, with cookies on api.nango.dev to reuse existing session cookies. Pull request #7481
- Free plans now have a 10 GB monthly data-transfer cap enforced across proxy, webhooks, functions, and record reads. Pull request #7413
- Neon MCP added as a dynamically registered OAuth2 provider with read and write scopes. Pull request #7545
- Stripe App Sandbox appDomain moved from per-connection to per-integration configuration. Pull request #7227
- Hex MCP provider support added. Pull request #7578
- Autumn, a billing and subscription layer, added as an API key provider. Pull request #7576
- Linkly URL shortener added as an API key provider. Pull request #7516
- Dashboard redirects to the originally requested page after login instead of the home page. Pull request #7520
- Growth add-on management cron runs hourly to report, activate, and terminate add-ons. Pull request #7530
Why it matters
The week focused on integrations (five new providers added), billing features (data transfer cap and add-on scheduling), and platform improvements (scheduled functions, OAuth consent flow, billing deep links). These changes address both integration coverage and subscription management for growing deployments.
Changelog entry
- feat(integrations): add support for hex mcp Pull request #7578
- fix(webapp): land billing deep links on the right section Pull request #7567
- feat(providers): move stripe-app-sandbox appDomain to
integration_configPull request #7227 - refactor(records): share one helper for composite model names Pull request #7415
- fix(connect-ui): stop the theme flashing before the dialog loads Pull request #7497
- feat(integrations): add Autumn (API key) Pull request #7576
- feat: scheduled functions can execute Pull request #7563
- feat(oauth): add dashboard login and consent flow Pull request #7481
- feat(integrations): add Linkly (API key) Pull request #7516
- feat(auth): return to the requested page after login Pull request #7520
- feat(usage): cap free-plan data transfer at 10 GB monthly Pull request #7413
- feat(integrations): add Neon MCP support Pull request #7545
- feat(plans): growth add-on management cron Pull request #7530
This week: scheduled functions unified in orchestrator, Free plans now have 10GB monthly data transfer cap, Neon MCP added, plus Hex, Autumn, and Linkly integrations. Dashboard now returns you to your original page after login.
This week in Nango: scheduled functions unified in the orchestrator payload, Free plans now enforce a 10 GB monthly data-transfer cap, Neon MCP added as a dynamically registered provider. Three new integrations: Autumn (billing layer), Linkly (URL shortener), and Hex. Platform improvements include dashboard returning you to your originally requested page after login and Stripe App Sandbox configuration moving to the integration level.