Changelog

  • Removed the waitlist "secret key" from the Credentials tab — it was never used to authenticate anything, so it's gone rather than left sitting around
  • Added standard security headers (HSTS, no-sniff, referrer policy, and a frame-ancestors policy that blocks the app from being embedded elsewhere) to every response
  • Emails to your waitlist now come from a Waitlists sending address, with replies going to you
  • Recipients are always the entry's own address
  • Sending is rate-limited
  • Charts now run on Recharts 3
  • Refreshed the icon set
  • Zero known vulnerabilities in dependencies
  • The landing page sign-up form now joins the real Waitlists waitlist
  • Generated embed code — from the credentials tab and the MCP get_embed_snippet tool — now renders textarea, radio, and multi-select fields correctly, and keeps field labels as written
  • Submitted entries record the email from the form's email field
  • Switching tabs on a waitlist page (Responses, Analytics, Form Editor, Credentials) is now instant — no re-fetch of the page underneath
  • Dashboard, waitlists, waitlist detail, tokens, and feedback pages show a loading placeholder shaped like the real page instead of a blank flash
  • Paging, searching, and filtering responses keeps the current rows on screen (dimmed, with a small spinner) instead of clearing the table while it loads
  • Every button that saves, deletes, or sends something now shows a busy state and can't be clicked twice
  • Deleting an entry or changing its status updates the table immediately, and reverts with a message if it fails
  • Sign-in now runs through devsforfun ID instead of Supabase Auth
  • Database moved to Postgres via Drizzle, deployed on Neon
  • Upgraded to Next.js 16, React 19, and Tailwind 4
  • Added new field types to the form editor
  • Compose and send email to waitlist entries, individually or in bulk
  • Track entry status (new, contacted, sent an email, closed)
  • Drag-and-drop field reordering in the form editor
  • Edit an existing waitlist's name and allowed origins
  • Create a waitlist and generate an embeddable HTML form
  • Public submit API keyed by per-waitlist API key, with origin checks
  • Responses tab to review entries