1.2.0-rc.1 / Release and assurance
Release status
Implemented capabilities, package identities and deployment limits.
Odexa v1.2 RC1 is an implementation candidate, released on 21 September 2026. Its specification, source, schemas and reference package are available for implementer evaluation. It is not a stable production standard or external certification. The previous developer preview, 1.2.0-draft.2, remains available separately.
Release identities
| Layer | Exact identity |
|---|---|
| Candidate edition | 1.2.0-rc.1 |
| Native policy | 1.2.0-draft.1 |
| Current service, authority and asset envelopes | 1.2.0-draft.3 |
| Python reference package | 0.0.0.dev3 |
| Historical service and command | 1.2.0-draft.2 / odexa-reference |
Use odexa-current for the current operator path. The edition label does not rewrite signed message versions, schema constants or historical receipts. Selected payment, storage, asset and archive profiles remain explicit; see schemas and profiles.
Implemented reference capabilities
- Static policy publication and deterministic scope, action, purpose and obligation evaluation.
- Direct free agreements without a Foundation, provider or payment account; explicit delegation when an origin chooses another service.
- Exact assent and durable receipts, separate access tokens, current authorization, revocation and retained key history.
- Optional fixed quotes, separate payer mandates, authenticated read-only payment verification and durable financial/access states.
- Native asset versions, representation and source closure; selected continuing-storage reports with inherited deadlines.
- Gateway observations, signed participant reports, known reporting denominators and explicit unknown/conflicting outcomes.
- Selected free/paid/storage/asset archives with independent trust, inert import and fresh-agreement provider handover.
The installed Python commands demonstrate one bounded resource and ordinary free or paid retrieval/reporting/archive flows. Native-asset and continuing-storage capabilities have their own APIs and clients; the command does not silently select them. Synthetic payment examples do not debit, refund or transfer money. See the quickstart and validation evidence.
Security contact and deployment limits
The integrated technical review and corrections are complete. The frozen package retains the tested implementation and approved licences. The project owner has confirmed receipt and monitoring of private security reports at hello@odexa.org; no response deadline is promised. The release record supersedes earlier operational status notes retained in historical evidence.
Production deployments must supply ingress controls, monitoring, backup/recovery, valid certificates, credential provisioning and explicit authority renewal. The reference does not provide a general website proxy, hosted administration or automatic certificate/key renewal. The generated local policy/authority expires after 24 hours and its TLS certificate after two days. No external security certification is claimed.
Inspect the candidate
Download the reference source and evidence or Python wheel, and check the file inventory. Keep historical draft-2 material and state directories separate. Upgrade guidance explains why imported evidence does not transfer live credentials or agreements.