What's New

Recent changes across Manzano and Grove. Breaking changes are called out explicitly — check the "Action Required" section first if you're upgrading an existing project.


Action Required

If you're carrying a project forward from before April 2026, three changes may require edits before manzano test or manzano deploy will succeed:

  1. kind "xxx" is now required on every root record. Add kind "..." as the first item inside every record { ... } block. 2-5 lowercase ASCII letters, not starting with mz. See Declarations — The kind declaration and checker error E0112.
  2. grove.toml uses project_id at the top level. The old [project] name = "..." version = "..." table is no longer what the CLI reads or writes. Move to:
    project_id = "my-app"
    
    See Configuration Reference.
  3. Anonymous route calls are now truly anonymous. If your Cedar policies or authorize hooks relied on the old synthetic "route" principal fallback, update them to either require authentication or to permit Role::"__anonymous" explicitly. See Per-Project Cedar Policy.

April 2026

Authentication — new top-level section

Identity now has a dedicated section separate from authorization. Four pages cover the end-to-end story:

security/authorization.md picks up a "Where ctx.principal comes from" cross-link and retains the authorize hook model it always had.

Language

CLI — manzano 0.4.x

Authorization

Runtime and Database

Workflows — two new subsystems documented

Web and HTTP

Running the server

Errors and limits


See Also