# DeployBeacon roadmap

> Generated from the capability catalogue that GET /api/v1/capabilities returns. Statuses are not promises of dates. Private beta.

## Available

- **Static ZIP hosting** (`available`): Inspect, publish, view release evidence and roll back.
- **REST API and CLI** (`available`): Scoped 30-day tokens, project and release operations.
- **Custom domains** (`available`): TXT ownership and DNS-only IPv4 routing checks activate HTTPS automatically, within the workspace’s recorded domain allowance.

## In private beta

- **Website file manager** (`private_beta`): Browse, search, download, edit, upload, rename and remove files in a new inspected version. No live-file overwrite. Browser sessions only; individual edits/downloads up to 512 KiB, 2 MiB of changes per save.
- **Private release previews** (`private_beta`): Prepare without changing the live site. Share an expiring bearer link, revoke it or publish the preview after checking it.
- **Recoverable release cleanup** (`private_beta`): Retire unused releases with seven-day recovery from Backups, REST, CLI or MCP release\_retire. Selected releases are protected; original ZIPs and audit history remain.
- **MCP tools** (`private_beta`): Bearer-token clients supported. Browser approval is required for agent publishing.
- **Domain forwarding and checks** (`private_beta`): Primary domain with optional alias redirects, HTTPS forwarding domains, registry expiry details and email DNS checks with suggested records. DNS records are not edited for you.
- **Public GitHub import** (`private_beta`): Commit-pinned public repository import with the same archive safety checks. Built static files only; no build execution, private repositories or automatic push deploys yet.
- **Static contact forms** (`private_beta`): Declared text and email fields from a published static website arrive in a private browser-session inbox with read, archive and CSV export. No file uploads or outgoing email.
- **Attention feed** (`private_beta`): Failed releases, blocked uploads, domain and HTTPS problems, pending approvals and usage above 80% in one list, plus unread message counts in the dashboard. REST, MCP and CLI; read-only.
- **Build plan** (`private_beta`): Framework, package manager, suggested build command and output folder from the latest inspection. Nothing is built or run on this host.
- **Direct assistant files** (`private_beta`): MCP, HTTPS API and CLI accept up to 50 built files / 512 KiB with archive, credential and quota checks. Stores a private inspection first; MCP publication still requires dashboard approval.
- **Security scanner** (`private_beta`): Known-vulnerable JavaScript libraries, miners, webshells, hidden frames and off-site password forms are checked at upload, on demand and daily for live releases. Signature checks; not proof of safety.
- **Original ZIP cleanup** (`private_beta`): Admin-confirmed unused-upload removal, seven-day recovery and live/retained-release protection. Storage is released after cleanup; history and prior encrypted backups are retained.
- **Visitor analytics** (`private_beta`): Cookie-free counts for live sites: daily unique visitors, page views, bandwidth, status codes, bot share, top pages and referrer hosts. No raw IP addresses or user agents are stored. Country from DB-IP Lite when installed. Owners can turn counting off per site.
- **Site access rules** (`private_beta`): Per-site password protection, IP allow and deny lists, hotlink protection, AI crawler policy, maintenance mode, directory listing, custom error pages and generated llms.txt. Private previews are unaffected.
- **Help and support requests** (`private_beta`): Learn more links on every dashboard panel, guide search over the guides and their Markdown twins, and support requests from the dashboard or an assistant hand-off. Request IDs, the project and recent findings are attached only with your consent. Replies appear in the dashboard.
- **OAuth assistant connections** (`private_beta`): PKCE sign-in, explicit workspace permissions, rotating tokens and revocation. Individual AI-client compatibility is being validated.
- **Workspace team access** (`private_beta`): Owner-issued 72-hour invitation links, role controls and revocation. Timed memberships and invitations remain controlled by owners. Optional account mail depends on verified addresses and configured outbound service.

## Partly available

- **Support replies by email** (`partial`): Optional verified-primary copies use the sealed Microsoft Graph mail queue when the provider and outbound dispatch are enabled. In-app replies remain available. Queued and accepted do not prove delivery.

## Planned

- **Dynamic Node/Python apps** (`planned`): Requires dedicated isolated workers before customer execution.
- **Managed databases and email** (`planned`): Provider setup, provisioning and backup testing remain.

## Waiting on an owner decision

- **Public status page** (`blocked`): Needs a status page hosted away from this server and an outside check location (owner choice). No same-server status is shown.
- **Paid subscriptions** (`blocked`): Billing provider account and prices require owner setup.

## Deprecated

None.

Generated 2026-10-04T06:55:39.947Z. Deprecation policy: https://deploybeacon.ai/docs/deprecation-policy
