September 2026
security(ai): stop one guest's booking reference reaching another guest through the knowledge base (vanio-feedback#903)
We've fixed a security issue where booking references and guest portal links could occasionally appear in AI-generated knowledge base articles. These articles are only visible to your team, not to guests, and we've now added an extra safeguard to prevent guest information from being stored in shared articles going forward.
admin toggle for permission to enter, so providers see the real answer (vanio-feedback#931)
Property managers can now manually override the "Permission to Enter" status on maintenance tasks, ensuring service providers see the correct access level regardless of guest check-in status. Simply toggle between "Awaiting guest" and "Guest approved" on any task, and your team will see who made the change and when it was set.
re-land the guest-reply recovery and voice code pacing (vanio-feedback#930, #932)
Guest replies that include booking links are now properly delivered instead of disappearing silently. Additionally, access codes shared during voice calls are now spoken one digit at a time, making them easier for guests to hear and write down.
correct the portal-auth import alias that broke the build
We've fixed a critical issue that was preventing Vanio from loading properly. Your platform is now fully operational again.
security(owner-portal): the Host header is not an identity — onboarding resume + listing photos (vanio-feedback#899)
We've fixed a security issue that could have allowed unauthorized access to onboarding information and listing photos when using custom domain names. Your property details and photos are now properly protected, regardless of which domain is used to access your account.
read access codes one digit at a time so a guest at the door can catch them (vanio-feedback#932)
Vanio AI now reads access codes and PIN numbers one digit at a time with pauses between them — so guests at your door can actually hear and write down the code without asking you to repeat it.
a reply the platform refuses for containing a link now reaches the guest (vanio-feedback#930)
Guest messages that contain links or contact details are now delivered to guests instead of being silently dropped. When Airbnb blocks these messages for safety reasons, Vanio automatically removes the problematic content and sends the message through—so your guests always receive your replies, just without the link or phone number.
read Airbnb pricing settings under the key they are written with (vanio-feedback#901)
Property prices now display correctly on your booking websites—587 listings that were showing "from $100" will now show their actual nightly rates, and price sorting in searches will work properly again.
security(seam): record whether the lock webhook's signature check would pass, before enforcing it (vanio-feedback#929)
We've strengthened security for smart lock integrations by adding signature verification to incoming lock events. This ensures that lock status updates actually come from Seam and not from unauthorized sources. For now, we're monitoring these checks without blocking any events, giving us confidence before we enforce them fully.
calendar sync asked a per-listing column a per-link question (vanio-feedback#894, #900)
Vanio now correctly syncs your Airbnb calendar when a property is connected under multiple Airbnb accounts, and properly reports when calendar syncing discovers nothing instead of silently marking it as successful.
security(airbnb): stop shipping a working key to the Airbnb token store in the source (vanio-feedback#862, vanio-feedback#895)
We've removed hardcoded connection details that were accidentally stored in our codebase and could have allowed unauthorized access to your Airbnb token storage. These details are no longer active, but we've updated how we manage them to prevent similar issues in the future. Your synced Airbnb listings continue to work without any changes needed on your end.
watch whether guest messages ARRIVE, not just whether they go unanswered (vanio-feedback#912)
Vanio now monitors whether guest messages actually arrive, not just whether you've answered them. If a message gets stuck in delivery or never reaches your inbox, you'll get alerted instead of having it disappear silently. We've also added visibility into outbound messages that fail to send to guests, so you can catch and fix delivery problems before guests think you're ignoring them.
security(websites): one genuine payment could be replayed into unlimited bookings (vanio-feedback#915)
We fixed a critical security issue where a guest's legitimate payment could be fraudulently reused to create multiple bookings on the same property. Your bookings are now protected by a verification system that ensures each payment can only complete one booking.
re-land #917's next check-in fix, in a shape Turbopack can build
We've fixed an issue that was affecting how check-in tasks identify the correct reservation. Your system will now properly skip next check-in pointers and find the right guest arrival date, even when reservations are spread across a longer timeframe.
"I'm transferring you to the team now" transferred nobody, for five months (vanio-feedback#921)
When guests called to reach your team, Vanio's voice assistant would say "I'm transferring you to the team now" but then disconnect the call instead of completing the transfer. This has been fixed, and guest calls will now properly connect to your team as intended.
the component wrapping the whole dashboard was named ErrorBoundary but wasn't one
If the dashboard encounters a problem, you'll now see a friendly error message with options to try again or reload, instead of a blank page. We've also improved how we track these issues so our team can fix them faster next time.
the management type and fee level came back to every staff role's thumbnails (vanio-feedback#922)
Staff members at your properties can now see the management type (Managed/Leased) and fee level on property thumbnails throughout the platform, making it easier to find operational details while managing tasks and reservations. This information displays consistently across the property picker, task filters, and task details for maintenance, cleaning, roaming, team lead, and inspector roles.
every recurring task was created already overdue (vanio-feedback#910)
Recurring tasks will now be created with future due dates instead of appearing already overdue. Tasks generated from your recurring task templates will arrive on your team's list with time to complete them, rather than showing as late from the moment they're created.
operations workspaces had no Calendar in the desktop menu (vanio-feedback#927)
Operations workspace users can now access the Calendar from the desktop menu. Previously, only staff members (cleaners, maintenance, inspectors) could see it, while owners, admins, and other roles were missing this option—even though the Calendar worked fine on mobile and the feature was already available to them.
service providers were told the wrong next check-in (vanio-feedback#917)
We've fixed an issue where service providers were shown incorrect upcoming check-in details on their tasks. Cleaners and other team members will now see the right guest arriving next, with accurate confirmation codes and arrival dates—no more confusion from outdated or duplicate booking information on a single task.
early/late chips fired on 96% of jobs — execution card ignored the listing's own turnover times (vanio-feedback#918)
Early and late check-in/check-out warning indicators now respect each listing's actual turnover times instead of showing false alarms for properties that run on different schedules. Service providers will see these yellow flags only when checkouts and check-ins genuinely fall outside their assigned listing's standard times.
an instant 0k charge looked identical to the recharge setting (vanio-feedback#909)
We've made it clearer when you're adding credits right now versus setting up automatic recharges. The "Add credits" section now shows a warning before you charge your card, and the amount options are styled differently so they can't be confused with your recharge settings—preventing accidental large charges like the one reported in this issue.
auto-recharge billed the configured amount once per deduction, not once per threshold breach (vanio-feedback#909)
We fixed a billing issue where auto-recharge was charging multiple times whenever your balance dropped below the threshold, instead of just once per breach. Your account will now respect your configured recharge amount and won't get paused due to rapid repeated charges.
date-change timeline posts showed the day before (vanio-feedback#916)
Fixed an issue where date changes in your reservation timeline were displaying one day earlier than they actually occurred. If a guest's check-in date changed from September 7th to September 6th, it was incorrectly showing as September 6th to 5th — this is now corrected and you'll see the accurate dates in your timeline history.
single-listing import created no platform link, so every push silently pushed nothing
We've fixed a bug where individually imported Airbnb listings appeared connected but failed to push availability updates without any error message. Your calendar syncs to Airbnb will now work correctly for all listings, and you'll get a clear alert if a connection issue prevents a push from going through.
the overview page was waiting on a market read nothing displays (vanio-feedback#774)
The listings overview page now loads 4–6 times faster, especially when navigating between properties. We removed unnecessary background calculations that were slowing down the page without providing any visible benefit, and streamlined how property data loads when you first open Vanio.
no way out of the consent screen when signed in as the wrong user
If you accidentally reach the OAuth connection screen signed in as the wrong account, you can now sign out directly from that screen without losing your place in the flow. After signing back in as the correct user, you'll be guided to restart the connection—nothing gets approved by mistake, and you'll know exactly where you are.
wire the OAuth access-token validator to the real authorization server
OAuth login for Vanio's MCP server now works properly—access tokens are validated against our authorization server instead of being rejected outright. Property managers using OAuth credentials to connect third-party tools will no longer encounter authentication failures.
advertise how to authenticate, and accept OAuth access tokens
Vanio's AI integration now works seamlessly with Claude and other AI assistants—they can automatically discover how to connect to your account and authenticate securely. Your existing API keys continue to work exactly as before, while AI tools can now use your Vanio login credentials instead.
OAuth 2.1 authorization server so the MCP server connects with a login
Connect your Vanio account to Claude directly—just paste a link into the Claude app, log in, and approve. No API keys or technical setup required.