- Added Annotations with chart markers and management UI, and introduced Model Context Protocol (MCP) for read‑only analytics assistants with API key authentication.
- Released a typed TypeScript @umami/api client generated from OpenAPI, added API key management, and enabled session‑property filters in segments.
- Implemented security hardening (reject partial 2FA tokens, bind sessions to password fingerprints, secret scanning) and fixed various bugs including timezone inconsistencies, PostgreSQL query optimizations, and mobile UI issues.