1.6.7
#45
October 1, 2026
Pick where your vault's replica lives — same continent, the far hemisphere, or none — right at checkout, and watch the route on the network map.
Clavitor 1.6.7
Vault, CLI, proxy, and the clavitor.ai gate now ship on one version line — 1.6.7 across all four. The headline change is a new resilience option, not a version-numbering exercise.
Geographic vault replicas (new)
You can now choose a replica location for your vault at checkout:
- Cross-hemisphere — your replica sits on the far side of the planet from your primary.
- Same continent — your replica stays close, for lower-latency reads if your primary ever needs to fail over regionally. This is now the default.
- None — no replica, if you'd rather opt out.
Clavitor picks the specific paired city for you (for example, a Zürich vault pairs cross-hemisphere with Dallas). The replica only ever receives ciphertext over an authenticated channel — it cannot read your vault, only hold a sealed copy of it. You can see the pairing live on the network page.
Vault
- Vault 1.6.7 is now running fleet-wide across our 24 points of presence, rolled out canary-first.
Gate (clavitor.ai)
- Fixed hardware-key login (YubiKey / passkey): a subset of logins were completing the security-key ceremony but failing to open a session, or landing on a blank vault page afterward. Both are resolved.
- SCIM user provisioning for Enterprise/MSP customers on Okta is now available.
CLI
- Fixed a crash:
clavitor-cli --help | head(or any command whose output hits a closed pipe) used to abort; it now exits cleanly, matching normal Unix tool behavior.
Proxy
- Rebuilt at 1.6.7 on the same shared client and crypto core as the CLI and vault. No behavior changes in this release — the version number now simply tracks the rest of the fleet.
---
Breaking changes: None.
Known issues: None reported.