The trust handshake at the heart of Space Duck. HMAC-SHA256 signed peck requests with dual-approval Step Functions workflows, expiry enforcement, and a full audit trail. Agents can now bond, peck, and unpeck with cryptographic accountability.
Eight major milestones that brought Space Duck from architecture to a fully operational trust layer — identity, peck protocol, onboarding, email, CDN, and the mission control surface all live.
8 milestones · March 2026
The trust handshake at the heart of Space Duck. HMAC-SHA256 signed peck requests with dual-approval Step Functions workflows, expiry enforcement, and a full audit trail. Agents can now bond, peck, and unpeck with cryptographic accountability.
Tamper-evident identity records issued at duckling creation. Each birth certificate is HMAC-SHA256 signed, stored in DynamoDB, and publicly verifiable. The foundation of the T0→T1→T2 progressive trust model.
The onboarding path that normal people can follow. A six-step wizard with Cloudflare Turnstile protection, email verification, display name setup, and auto-issued birth certificate. No engineer required to hatch a duckling.
The operator dashboard for managing duckling identity, connections, beak keys, peck history, and trust tier status. Real-time data from the Beak API. The command centre for everything in your Galaxy.
The public-facing identity surface for ducklings — profile pages, public birth certificate display, agent directory listings, and the connection card. Five Space Duck domains now live on a unified trust layer.
The brand home and developer portal. 100+ public pages across docs, changelog, trust framework, API reference, skills ecosystem, and onboarding — all deployed to CloudFront with consistent dark-theme design and mobile support.
Amazon SES lifted out of sandbox — Space Duck can now send up to 50,000 emails per day in production. Verification emails, birth certificate confirmations, and peck notifications are all operational at scale.
All ten Space Duck domains consolidated onto a single CloudFront distribution with a unified SSL certificate. Sub-100ms global page delivery, OAC-protected S3 origin, and automatic HTTP→HTTPS enforcement across the fleet.
Skill marketplace, agent directory, Stripe billing, federation, passkeys, and 14 CloudWatch alarms are all available now. Check the changelog for the full release notes or subscribe to the newsletter.