This private-preview batch closes the integration gaps uncovered while mapping a production-shaped Next.js and NestJS application onto Playstack’s identity and subscription boundaries.
Authentication and accounts
Auth can now authenticate an already normalized provider profile, inventory and individually revoke active sessions, select the response to refresh-token reuse, and run bounded credential cleanup. Browser applications hosted separately from their API can use an HTTP-only refresh cookie with an in-memory opaque bearer access token.
Accounts add member and invitation reads, account updates, self-service leaving, delivered ownership-transfer proposals, recoverable deletion, bounded purge cascades, and same-transaction account provisioning from user registration.
Billing and access
Subscription projections now isolate provider instances, reject stale webhook state, retain immutable revision history, expose current state, reconcile from the provider, and represent scheduled plan changes. Stripe invoice, dunning, cancellation, plan-change, and trial signals are normalized into Playstack events.
Plans can define no-card product trials and a smaller time-bounded grace grant set. Applications explicitly choose transactional or durable eventual entitlement projection. Entitlements add bulk resolution and complete snapshots for settings and administrative views.
Schema and audit composition
Prisma synchronization can apply package-declared model extensions before validating the complete relation graph, allowing the managed MFA artifact to add its required reverse relations to the managed Auth user model. Audit actor types remain safe built-ins while permitting application principals such as partners and services.