# What's new in 1.2

The latest Mobile SDK is **1.2.1**, released 2026-08-03 on iOS and Android in lockstep. 1.2.1 is a security hotfix on top of 1.2.0, and 1.2.0 was a feature release on top of 1.1.0. This page covers the whole 1.1 to 1.2.1 span, so an app upgrading from 1.1 sees everything that changed.

:::caution[Upgrade to 1.2.1]

Versions 1.0.0, 1.1.0, and 1.2.0 are deprecated for security reasons. Their release artifacts have been removed from the GitHub release pages, and from the Maven repo on Android, so a build pinned to one of them no longer resolves. Pin 1.2.1 or later.

:::

## Upgrade

iOS (Swift Package Manager):

```swift
.package(url: "https://github.com/octetproof/octet-sdk-ios", exact: "1.2.1")
```

Android (Gradle):

```kotlin
implementation("com.octetproof:sdk:1.2.1")
```

The proof wire format, proof semantics, trust levels, and verdict codes are unchanged across 1.2. A 1.2.1 proof means what a 1.1 proof means, and every verifier keeps working. The one thing that needs a newer verifier is enforcing the new session binding, which requires `octet-verify` 1.2.0 or later.

## New API

- **Session-binding.** `isWithin`, `isOutside`, and `contains` take an optional `sessionNonce` (1 to 512 bytes). The SDK commits a hash of the nonce inside the signed proof, so your verifier can confirm the proof was made for a specific login. An empty or over-cap nonce returns `INVALID_SESSION_NONCE`. See [Session-binding](/docs/concepts/session-binding/) and [Predicates](/docs/api-reference/predicates/).
- **`Octet.attestationEnrolmentBundle()`.** Returns this device key's attestation evidence, so a verifier can establish the device's hardware root before the first proof arrives. See [`attestationEnrolmentBundle()`](/docs/api-reference/octet-start/) and [Device Attestation](/docs/concepts/device-attestation/).
- **SDK version gating.** The SDK reports its version and platform on every backend request. `Octet.start(...)` can throw `LicenseError.upgradeRequired(...)`, and `LicenseStatus` gains `upgradeRecommended` and `minSupportedVersion`. Both paths are inert in 1.2, because the backend gates no version yet. See [License Types](/docs/api-reference/license-types/).

## Changed

- **Rolling license-token persistence.** The SDK persists the refreshed license token from a lease response, so a device carries a fresh token across restarts within the offline-grace window. See [License & Activation](/docs/concepts/license-activation/).
- **Android background location is now opt-in.** The SDK's Android manifest declares only the permissions the foreground proof flow uses, so it no longer bundles `ACCESS_BACKGROUND_LOCATION`. To generate proofs while the app is backgrounded, declare `ACCESS_BACKGROUND_LOCATION` in your own manifest. See [Prerequisites](/docs/getting-started/prerequisites/).
- **Android public API surface narrowed.** Several internal `com.octetproof.sdk.model` types that were public by default on Android are now `internal`, matching iOS. `Position` and `GeoBounds` stay public. If you referenced an undocumented type, switch to the public `Octet` API.

## Fixed (Android)

- **Device-key security level carried on the wire.** A 1.1 serialization bug dropped `device_attestation.security_level` from the proof, so a verifier gating on a hardware tier could reject a healthy TEE or StrongBox device. A 1.2 proof reports the true tier.
- **Attestation key re-attested before its chain expires.** The key-attestation chain's intermediate is short-lived (about 14 days). The SDK now regenerates the key before the chain ages out, rather than presenting an aged-out chain about two weeks after enrolment.

## Privacy and distribution

- **iOS privacy manifest.** The xcframework bundles `PrivacyInfo.xcprivacy`, declaring the data types it handles and its required-reason API use. Xcode folds it into your app's privacy report.
- **Android data-collection disclosure.** The SDK's `INTEGRATION.md` gains a section describing what the SDK handles, by purpose, to help you complete the Play Console Data Safety form.
- **Android 16 KB page-size support.** The native libraries are aligned for the 16 KB memory-page devices that Android 15 introduces. No action needed.
- **Signed, verifiable downloads.** Each release publishes a SHA-256 checksum, SLSA build provenance, an SBOM (software bill of materials), and a keyless cosign signature for the binary. See "Verifying the download" in each repository's `INTEGRATION.md`.

## Full changelogs

- [`octet-sdk-ios` CHANGELOG](https://github.com/octetproof/octet-sdk-ios/blob/main/CHANGELOG.md)
- [`octet-sdk-android` CHANGELOG](https://github.com/octetproof/octet-sdk-android/blob/main/CHANGELOG.md)
