# What's new in 2.0

2.0 is a major release. It changes how the SDK is licensed, adds on-device proof verification, and gives the session an explicit teardown. Full history is in the [`octet-sdk-ios`](https://github.com/octetproof/octet-sdk-ios/blob/main/CHANGELOG.md) and [`octet-sdk-android`](https://github.com/octetproof/octet-sdk-android/blob/main/CHANGELOG.md) changelogs.

Upgrading from 1.x? Read [Migrating from 1.x](/docs/v2.0/getting-started/migrating-from-1x/). The 1.x docs stay at [/docs/v1.2/](/docs/v1.2/).

## Attested bootstrap

The SDK no longer carries an embedded license key. It proves the app's identity at first launch with a platform attestation (Apple App Attest, Android key attestation) and the backend mints the license. You register your app once against your Octet account at `sdk.octetproof.com/apps` (see [Prerequisites](/docs/v2.0/getting-started/prerequisites/)). See [Attested bootstrap](/docs/v2.0/concepts/attested-bootstrap/).

## On-device verification

`Octet.verify` verifies a proof on the device, offline, running the same checks and the same tri-state verdict as the `octet-verify` service. Use it as a fast local gate. The service still owns the backend-only checks (replay-uniqueness, revocation). See [On-device Verification](/docs/v2.0/concepts/on-device-verification/) and the [`Octet.verify` reference](/docs/v2.0/api-reference/octet-verify/).

## Session lifecycle

`OctetSdk.close()` ends the session and stops all background work, including the Android location foreground service (whose notification is now the neutral "Location active"). Call it when your proof flow finishes. See [Session Lifecycle](/docs/v2.0/concepts/lifecycle/).

## Proof binding and freshness

The predicates gain two optional controls alongside `sessionNonce`: `decisionRef` binds an uploaded proof to one authorization decision, and `forceFresh` mints a proof for the call with no binding. See [Proof Binding](/docs/v2.0/concepts/proof-binding/).

## Metrics

The SDK's metrics collection is documented on the [Metrics](/docs/v2.0/concepts/metrics/) page. It carries no location data and is disabled with `telemetryEnabled = false`.

## Breaking changes

- **iOS: `confidence.flags` JSON values are now `UPPER_SNAKE`** (`VPN_ACTIVE`, not `vpnActive`), matching Android. Affects only code parsing `toJson()` on iOS. See [Serialization](/docs/v2.0/api-reference/serialization/).
- **New reason code `regionUnresolved`.** A country or subdivision predicate that cannot resolve the region returns `INDETERMINATE / REGION_UNRESOLVED` instead of coarsening silently. See [Verdicts](/docs/v2.0/concepts/verdicts/).

## Other changes

- **Semantic-binding v2** is the default proof emission: proofs now bind city and earth geometry and a location verdict. Verify with `octet-verify` 1.3.0 or later, or on-device with `Octet.verify`.
- **New adversarial reason codes** `spoofingDetected` and `tampering`, distinct from the benign "couldn't measure" reasons. See the [reason-code taxonomy](/docs/v2.0/concepts/verdicts/).
- **`regionFromJson`** decodes an `OctetRegion` from its JSON form. See [`OctetRegion`](/docs/v2.0/api-reference/octet-region/).

## React Native

A React Native wrapper is in progress and not yet published. See [React Native](/docs/v2.0/getting-started/react-native/).
