Changelog. What's new in AssetSnag.
Follow along with our latest product updates, security improvements, file validation engines, and workflow enhancements designed to streamline your client onboarding.
Multi-Brand Platform, Zero-Buffer R2 Streaming & Portal Storage Routing
Full multi-brand platform launch with per-brand Google Drive integrations, dedicated SMTP and webhooks, whitelabel settings, and team brand-access scoping. Client portals now stream files directly to R2 or Google Drive without buffering Worker memory. Portal upload pipeline overhauled with a three-stage init/stream/confirm flow, plan-gated upload limits, and submission status tracking.
- Multi-brand profiles with isolated Google Drive, SMTP, webhooks, and white-labeling per brand identity
- Three-stage zero-buffer upload pipeline: init → PUT stream → confirm, eliminating Worker RAM exhaustion for large files
- Per-brand team member access scoping with PATCH endpoint to update member role and allowed brand IDs
Introduced brand_profiles table extensions (migrations 0031–0035) for dedicated SMTP credentials, custom domain routing, per-brand Slack/Discord/generic webhooks, Google Drive integrations, and remove-branding flags. Each brand profile now operates in full isolation with its own integration row resolved via brand_profile_id fallback chains in cloud-storage and integrations routes.
Replaced the single multipart upload endpoint with an init/stream/confirm flow. The init stage validates plan limits, storage quotas, and asset request ownership, then returns a signed R2 stream URL or a Google Drive resumable upload session URL. The stream stage pipes the raw HTTP body directly to R2 via a PUT without loading any bytes into Worker memory. The confirm stage finalizes the submission record, updates storage accounting, logs activity with IP and user-agent, and dispatches webhooks and integration syncs via executionCtx.waitUntil.
Extended team invite and member update APIs to accept allowed_brand_ids arrays. Added a PATCH /team/:id endpoint so owners and admins can update member roles and brand assignments post-invite. Organization context endpoint now surfaces the assigned brand name, logo, and accent color for brand-scoped members.
Portal upload init now enforces plan-level max upload byte limits and per-request custom maxSize caps clamped to plan ceilings. Storage destination routing (R2 vs. Google Drive) is determined per-portal and bypasses R2 quota checks when files go directly to Drive. Multi-brand portal creation requires Scale plan and returns a structured PLAN_REQUIRED error for lower tiers.
Google Drive OAuth callback now verifies HMAC-signed state tokens with a 15-minute expiry window and org-ID binding to prevent CSRF and session replay. Integration delete endpoint validates provider name against an allowlist before proceeding. Project sync requests now require owner or admin role authorization.
Auth middleware in-memory cache TTL raised from 30 s to 60 s to reduce D1 session read pressure under load. Public route exemption list expanded to cover /api/orgs/branding and /api/brands/branding for brand favicon and logo serving without authentication. Activity log indexed on created_at for efficient retention pruning.
Added a PUT /templates/:id endpoint that forks system templates into org-scoped copies on first edit. Google Drive project sync batched into chunks of 3 parallel uploads with per-file error isolation so a single failed upload does not abort the full sync job.
Enterprise Security Hardening, Zero-Buffer Drive Streaming & Scope Isolation
Comprehensive enterprise security upgrades featuring HKDF vault derivation, zero-buffer Google Drive streaming to eliminate Worker memory limits, non-sensitive OAuth scope migration with root folder isolation, and database query batching.
- Upgraded Vault encryption to WebCrypto HKDF 256-bit AES-GCM with SHA-256 session token digest caching
- Zero-buffer resumable upload streaming from R2 to Google Drive eliminating Cloudflare Worker memory exhaustion
- Restricted Google OAuth scopes to drive.file with automated /AssetSnag/ root directory isolation & appProperties tracking
Upgraded vault secret encryption to WebCrypto HKDF (SHA-256) 256-bit AES-GCM with versioned payloads (v: 2) and automatic fallback for legacy secrets. In-memory session tokens and cookies are now hashed with SHA-256 digests to prevent heap dump exposure.
Migrated OAuth scopes from sensitive broad permissions to non-sensitive 'drive.file' to eliminate CASA Tier 2 audit friction while restricting access strictly to AssetSnag-created files. Automated creation of a dedicated '/AssetSnag/' root folder hierarchy tagged with custom appProperties metadata.
Piped R2 ReadableStreams directly into Google Drive Resumable Upload sessions, replacing Worker RAM array buffers and preventing out-of-memory crashes on large file syncs.
Introduced deep SVG sanitization blocking scripts, event handlers, and foreign object injection vectors. Added R2 HEAD object verification on upload confirmation and enforced storage quotas using verified object byte sizes.
Batched organization creation transactions in auth middleware and optimized public portal queries with LEFT JOINs. Enforced 50,000-character bounds on portal content and stripped injection formatting from client notes.
UI Grid Standardization, Verified Plan Quotas & Blueprint Refinements
Pixel-perfect tab alignment across the agency dashboard, strict synchronization of pricing tiers with database limits, and clean template usage indicators.
- Standardized max-w-6xl container layout eliminating all tab switching shifts
- Exact pricing and storage limit synchronization with database schema & migrations
- Streamlined template status indicators replacing global usage counters
Standardized container widths (max-w-6xl) and aligned eyebrow category badges across Settings, Team, Vault, and Activity tabs to prevent UI jumps during navigation.
Synchronized plan cards and comparison tables with backend limits: Starter (10 portals, 25 GB, 50 MB upload), Agency Pro (30 portals, 100 GB, 500 MB upload, Custom Domain, White-label), and Scale (Unlimited portals, 500 GB, 2 GB upload, Priority Queue).
Replaced cross-account global counters on asset collection templates with clean 'Ready Blueprint' and 'Custom Blueprint' labels.
Custom SMTP, Secure Client Vault & Real-Time Activity Streams
Full control over agency email deliverability with Custom SMTP, end-to-end encrypted client credential vaulting, and high-performance team audit logs.
- Custom SMTP & dedicated transactional email relay (SendGrid, Postmark, Resend, Custom Host)
- Secure Client Vault for sensitive brand credentials, CMS logins, and API keys
- Real-time organization activity feeds with granular event filtering
- Automated compliance, marketing consent & legal onboarding checks
Connect custom SMTP servers with automated connection testing, custom sender names, and branded reply-to headers.
Store and manage sensitive client tokens, passwords, and brand secrets in an isolated, encrypted vault.
Blazing fast team audit trails tracking portal creations, uploads, review decisions, and member invites.
Built-in marketing and terms consent recording with immutable audit timestamps.
Google Drive Auto-Sync, Project Export & Bulk Downloads
Automated real-time sync to Google Drive, 1-click project export with organized folder structures, and high-speed bulk asset downloads.
- Automated real-time sync directly to connected Google Drive workspaces
- 1-Click complete project export with structured folder hierarchies
- Discord & Slack incoming webhook notifications with live asset previews
Approved client files are automatically mirrored to your connected Google Drive folders in real-time.
Download complete client deliverables or bulk assets with organized folder hierarchies in a single ZIP package.
Interactive notifications with deliverable thumbnails, client notes, and instant review action links.
Resolved upload chunk retry timeouts for large deliverable transfers.
Asset Quality Gates, File Linting & Dimension Verification
Enforce strict agency standards right inside the client upload window with automated DPI, color space, dimension, and aspect ratio validation.
- Custom Quality Gates (minimum resolution, exact aspect ratio, color profile, max duration)
- Instant client-side file inspection before upload starts
- SVG vector sanitization and structural SVG linting
Configure per-slot requirements such as minimum width/height, 300 DPI print standards, or specific aspect ratios (e.g. 16:9, 1:1).
Clients receive instant feedback if an uploaded image is low resolution or fails required color space specifications.
Automatic detection and sanitization of embedded scripts and invalid path data in vector files.
Corrected automatic rotation issues for high-res mobile camera photo uploads.
Full Agency White-Labeling, Custom Domains & Guided Tour
Make AssetSnag truly yours with custom subdomains, vanity domains, custom email headers, brand styling, and interactive guided onboarding.
- Complete white-labeling with custom CNAME domains and custom branding
- Interactive Step-by-Step Guided Product Tour for new agency team members
- Smart Readiness Ring visual indicators across client project dashboards
Host client portals directly under your agency domain (e.g. `assets.youragency.com`) with automatic SSL provisioning.
Remove AssetSnag badges, apply custom hex palettes, upload agency logos, and customize email footers.
Interactive onboarding walkthrough that guides agency team members through their first portal creation and asset request.
Circular progress rings indicating missing, submitted, and approved asset milestones at a glance.
Paddle v2 Billing Engine, Quotas & Multi-Seat Workspaces
Seamless self-serve subscription upgrades, automated plan-based storage tracking, and granular team member permissions.
- Native Paddle v2 Customer Portal integration for effortless plan upgrades and invoices
- Real-time storage quota tracking and automatic overage warnings
- Role-based team access control (Owner, Admin, Manager, Member)
Manage subscription tiers, update payment methods, and download VAT/Tax invoices with zero friction.
Invite team members with role-based permissions (Admin, Project Manager, Viewer).
Live visual storage meters with non-blocking alerts when approaching plan capacity.
Restricted API token generation based on organizational permission tiers.
Smart Insights & Public Review Portals
Zero-login client review links, AI-assisted asset readiness scores, and missing asset bottleneck detection.
- Public review links for external stakeholders with one-click approval/revision buttons
- Smart Insights algorithm estimating project completion risk based on client response times
- Bulk slot cloning and multi-slot batch configuration
Share secure, tokenized review pages where clients or team leaders can approve files without logging in.
Detect stalled deliverables and identify high-risk projects before client kickoff deadlines.
Apply file type restrictions, file size limits, and quality gates to multiple slots simultaneously.
Resolved video playback codec compatibility issues on iOS and macOS Safari browsers.
Webhooks, Zapier Integration & Zero-Login Portal Engine
A complete architectural ground-up redesign of the AssetSnag intake engine with blazing fast performance, Slack alerts, and Zapier workflow automation.
- Ultra-frictionless zero-login client intake flow with magic link authentication
- Real-time outgoing Webhook payloads for 6 portal lifecycle events
- Official Zapier app with instant triggers and actions
- Global CDN delivery for lightning-fast international asset transfers
Clients open branded portals directly from SMS, Slack, or email without passwords, reducing drop-off by 92%.
Send structured JSON payloads on `portal.created`, `asset.submitted`, `asset.approved`, and `portal.completed`.
Get instant channel alerts with direct links whenever a client completes their deliverable checklist.
All asset streams and client interactions are secured with TLS 1.3 encryption and isolated cloud storage.
Multi-Brand Presets, Custom Asset Checklists & Video Embeds
Support for reusable asset checklist blueprints, multiple agency client workspaces, and Loom / Vimeo video walkthrough embeds.
- Reusable portal presets for different agency service packages
- Embedded welcome video player at the top of client portals
- Individual client comments and notes per asset slot
Save asset checklists as reusable presets (e.g., 'Shopify E-commerce Kickoff', 'Brand Identity Kit').
Embed Loom, YouTube, or Vimeo walkthrough videos directly at the top of client portals.
Clients can now leave notes on specific asset slots explaining file variations or font licensing details.
Enhanced validation for custom webfont uploads to prevent corrupted font files.
AssetSnag 1.0: Official Public Launch
The first public release of AssetSnag, empowering digital agencies, freelancers, and design studios to collect high-resolution assets from clients on time without endless email threads.
- Interactive client upload portal with drag-and-drop file slots
- Agency dashboard to monitor client progress in real time
- Automated email reminder sequences for pending assets
- 1-click bulk ZIP export for approved files
Clean, branded landing page where clients can see exactly what files are missing and upload them in seconds.
Track multiple client onboarding projects simultaneously with live status badges.
Schedule polite automatic follow-up emails until clients upload all required files.
Download all collected client files in a single organized ZIP package.
Agency Dashboard Alpha & Multi-Client Intake
Introduced the first centralized agency management interface, moving beyond standalone upload links to multi-project organization.
Create and manage intake links for multiple clients from a single overview table.
Agency managers can mark uploaded assets as 'Accepted' or 'Needs Revision' with optional feedback notes.
Switched file transfers to client-side direct presigned uploads for smoother handling of large files.
Fixed UTF-8 character encoding corruption for exported filenames on Windows file explorers.
Closed Beta: Magic Links & Basic Slot Constraints
Eliminated client passwords completely with secure magic links and added basic file format and size limits.
Clients access their personalized upload space via single-click secure email tokens.
Specify acceptable extensions per slot (e.g. only allow .ai, .eps, .svg for logos).
Real-time byte progress bar for large file uploads.
Added server-side MIME sniffing to block disguised executable files.
Genesis: The First Working Prototype
The very first proof-of-concept build of AssetSnag created to solve the frustration of hunting down client logos in messy email threads and unorganized folders.
Basic web interface allowing clients to drag and drop requested brand files.
Form inputs for Primary, Secondary, and Accent brand hex color codes.
Sends a simple notification email to the agency owner when a client submits files.
Ready to automate client asset collection?
Join leading agencies saving 12+ hours per client project. Start your 14-day unrestricted trial in under 30 seconds.