Everything shipped and a few things we decided not to build. Looking ahead? See the roadmap.
LegendShippedPivotReconsideredWon't build
October 2026
Reliability
Fixed
Replaying a processed event now runs it again
Replay on the Events page is there to run a purchase or cancellation through a second time, for example after you add a mapping that was missing, or to re-apply a cancellation that an older version did not finish. Until now a replay of an event that already showed as processed did nothing: our duplicate protection treated it as a repeat delivery from the provider, skipped it, and the page showed processed again, so the no-op looked exactly like a real run. A replay now overrides that protection for the one run you asked for, and Ghost is updated. Repeat deliveries from a provider are still dropped, and they now show as skipped with the reason instead of as processed. Reported by one of our beta publishers, who traced it through the code and filed it as an issue. Thank you.
Replay of a processed event runs it again and updates Ghost
A provider redelivery shows as skipped with the reason "duplicate delivery", no longer as processed
Cancellations now end access on Ghost sites with Stripe connected
On a Ghost site with Stripe connected, PayGlue marks a buyer as comped, and Ghost represents that as a zero-amount complimentary subscription. When the provider reported a cancellation, PayGlue switched the comped flag off and relied on Ghost to end that subscription. Ghost does not do that on an API edit, so the member kept the tier and the access while the event showed as processed. PayGlue now cancels the complimentary subscription itself through Ghost's Admin API, and the member drops back to free. Verified against a live Ghost 6.68 site. Two smaller fixes shipped with it: readers whose address contains a + were not found in Ghost and the purchase failed with Member already exists, and a retried event replaced its real error with a signature timestamp message. Found by one of our beta publishers who ran a full subscription lifecycle in their Paddle sandbox and sent us every event id. Thank you.
A cancellation, pause or refund cancels the complimentary subscription in Ghost; the member drops to free and the label switches to payglue-ended
Addresses with a + are found in Ghost, for purchases and for the paywall check
A retried event keeps the error of its first attempt instead of a timestamp message
A Ghost site with Stripe connected needs at least one paid tier, see the troubleshooting docs
Paddle subscriptions: activation and cancellation now reach Ghost
A Paddle purchase created the Ghost member, but the subscription events that followed failed. Paddle sends subscription notifications with a customer id only, and PayGlue expected the email to be in the notification itself. The purchase looked fine, so a cancelled subscription left the member with access. Reported by one of our beta publishers testing in the Paddle sandbox, with the event ids and the right diagnosis already in the mail. Fixed the same morning, thank you. PayGlue now looks the email up through the Paddle API for subscription events, the same way it already did for purchases. Your Paddle API key needs read access to Customers, which it already has if purchases were working.
subscription.activated, canceled, paused and resumed resolve the customer email through the Paddle API
Failed subscription events can be replayed from the Events page, in order: activated, then canceled
Maintenance: security updates across the stack, three PayGlue-OS releases
We went through every library PayGlue is built on and brought it up to date, in the hosted product first and then in the open source edition. That closed all open security advisories in both repositories. Most of them concerned code paths PayGlue does not use, or tools that only run in our test suite. The hosted product now runs on Django 6.1.1 and gunicorn 26, and the open source edition runs the same versions, so there is one stack to test instead of two. Nothing changes for you and there is nothing you need to do.
All open security advisories closed, in the hosted product and in PayGlue-OS
Django 6.1.1, gunicorn 26.2 and current versions of the other libraries
The open source edition runs the same versions as the hosted product
PayGlue-OS v0.9.0: test purchases are labelled, delivery alerts are retried
September 2026
Reliability
Fixed
Failure alerts are recorded first and retried until they reach you
Since 13 September PayGlue mails you the moment a purchase ends in a permanent failure. That mail is sent by our background worker, and the worker was missing its mail configuration, so the alert did not go out. We found it on 30 September while looking at a publication whose provider events had failed, and we had not been told either, because an incident was only recorded after a successful send. Both are fixed. The configuration is in place, and the alert now writes the incident down before it tries to mail. If the mail cannot go out, the reason is stored and the nightly job sends it. A publication that has not connected Ghost yet is alerted too.
The worker can send mail again, and checks for it at every start
An alert that cannot be sent stays open and is retried every night
After 48 hours we get one internal notice, also when you could not be reached
Alerts no longer depend on a Ghost connection being set up
September 2026
v0.46
Product
Shipped
Test purchases are labelled, so you can tell them apart
When you test a purchase in your provider's sandbox or test mode, PayGlue creates the Ghost member exactly as it would for a reader, access, newsletter and emails as your rule says, because a test is there to show you the real flow. What is new: PayGlue knows it was a test. The member gets a fifth label, payglue-test, and its note reads Test purchase. PayGlue reads the provider's own signal for this: Creem's test mode, Lemon Squeezy's test mode, Gumroad's test flag, a Paddle or PayPal connection set to sandbox, a Polar sandbox token. The email address plays no part, so a real reader with a throwaway address is a real member. To clean up after testing, filter your Ghost members by the label and delete the selection.
Fifth label payglue-test on members created by sandbox or test-mode purchases
Newsletter and emails follow your rule, so you see what a reader would see
Detected from the provider's own test signal, never from the address
Pricing table: choose how you sell, see the table while you build it
The pricing table editor now asks one question first: how do you sell? One price per tier gives every column its own price, period and product, which is the right answer when your monthly and yearly plans are separate products at your provider, or when you sell a single plan. The monthly / yearly toggle is for several plans that each exist in both periods; a toggled tier now carries a monthly and a yearly product, and the button follows the toggle, so a visitor who picks yearly lands in the yearly checkout. A live preview under the question is rendered by the same script your readers load, so it shows exactly what they will see, as you type. The tier type sits at the top of every tier card, a table starts with a free tier, and the feature list gained a cross for what a tier does not include. Existing tables keep their settings; a tier that has only one of the two prices now shows it in both views instead of going blank.
How do you sell? One price per tier, or a monthly / yearly toggle
Toggled tiers have a monthly and a yearly product, the button follows the toggle
Live preview in the editor, rendered by the real embed script
Tier type first in every card, new tables start with a free tier
Cross symbol in the feature list
A tier with only one price shows it in both views, with the right suffix
Clicking the nav item or breadcrumb of the page you are on returns to its overview
Paywall box follows your alignment, colour, radius and width
The paywall editor has offered alignment, button text colour, corner radius and button width for a while, showed them in its preview and saved them. The box on your site never read them, so headline, text and button stayed left and the button kept one look. Fixed: the box now aligns as you chose and the button takes its colour, radius and width. If you set any of these earlier, your paywall changes to what you configured. The pricing table opened from the paywall button also shows the billing period next to each price now.
Alignment applies to headline, text and button
Button colour, radius and full width apply
The pricing table overlay shows / mo and / yr and follows the toggle
September 2026
Reliability
Fixed
Signature headers from Creem, Paddle, Gumroad and Patreon now reach verification
PayGlue stores an incoming webhook first and verifies it a moment later from the queue. The queue kept only a fixed list of headers, and that list still dated from the first three providers. For Creem this meant every delivery to a publication failed verification with a missing signature header while the provider saw a normal 200. Fixed on 13 September. The list now carries every header an adapter reads, and a test compares it against the adapter code so a future provider cannot ship without its header. If you connected Creem before this date and a purchase did not unlock a reader, the event is in your event log with a failed status. Replay it, or reply to any of our mails and we do it for you.
Creem deliveries to publications failed verification before 13 September, the provider saw a 200
The header list is now checked against the adapters in CI
Failed events from before the fix can be replayed from the event log
September 2026
v0.44
Reliability
Shipped
You hear about a stuck purchase the minute it happens
When a purchase reaches PayGlue but cannot be delivered to Ghost, the owner of the publication now gets one email right away, not a nightly digest that needed three failures in a day before it would say anything. The mail names the cause. If PayGlue could not write to your Ghost site, it points at the Ghost connection page. If your payment provider's webhook could not be verified, it points at that provider's connection page and asks you to compare the webhook secret. Either way the failed events stay in your event log and can be replayed once the cause is fixed, so no purchase is lost. You get one mail per incident; the next delivery that goes through resets it. Both texts can be read and edited in the admin like every other PayGlue email.
One email on the first failed delivery, sent from the worker, not from a nightly job
Two texts: Ghost connection failing, or provider webhooks being rejected
Failed events stay in the event log and can be replayed after the fix
We are not copied on your mail. If nothing has changed after two days, we get one internal note and may ask how things are going
September 2026
Providers
Won't build
Steady membership platform
Several of you asked for Steady, the membership platform many German-speaking publishers and podcasters use. We went through their API and wrote to their support twice. The answer is the same both times: Steady has no webhooks. A new member, a cancellation or an expired subscription reach the outside world only as Zapier triggers. Everything PayGlue does starts with the provider telling us that something happened, so the only ways around it would be polling Steady's subscription list or asking every reader to log in with Steady at the paywall. Neither is something we want to run or want to ask of your readers. Same conclusion as with Mollie: a solid API, built for a different job. If Steady publishes a webhook endpoint, we will pick this up again.
No webhooks at Steady, subscription events exist only as Zapier triggers
Polling or a Steady login at the paywall were the alternatives, we want neither
Patreon stays the reference for a membership platform with an open event API
A call with the founder, and what the Ghost key is really for
Not sure whether PayGlue fits your setup? There is a button in the founder card on the landing page now: grab 30 minutes with André, no pitch, no obligation. Bring your questions, or just watch him click through the dashboard. And the question people ask first, why PayGlue needs a Ghost Admin API key, has its own page in the docs: every call we make with it, what we never do with it, and why the payment provider key is optional. The Security Manifest links to it. Two smaller things: prices on the site now say excl. VAT, because a few people were surprised at checkout. We do not collect tax ourselves, our payment provider adds it depending on your country, and the site should say so plainly. And support mails go to support@payglue.io.
Book a 30-minute call from the founder card on the landing page
Polar signs webhooks differently from 8 September, and we verify both ways
Polar changed how new webhook secrets are derived: secrets created from 8 September 2026 follow the Standard Webhooks specification, older ones do not. Our adapter used to guess which of the two it was looking at from the shape of the secret. It now verifies against both derivations and accepts whichever matches, so a Polar connection made before or after the change keeps working without you touching anything. Polar also started asking which API version a webhook should use. We checked both against the five events we read: they are identical for our purposes, and the docs now say which one to pick. Thanks to one of our founding members, whose question about Polar's new API version picker is how we spotted the change in the first place.
Both Polar signing schemes are verified, old and new secrets keep working
Nothing to change on your side, existing connections are unaffected
The whole product in 30 seconds, on the landing page
There is now a play button on the dashboard preview at the top of the landing page. It opens a 30-second video: a purchase at your payment provider, a member in Ghost, that is the whole product. The video is hosted by Tella and loads only after you allow it, through a new category in the cookie banner, so nothing from a third party is fetched just because you opened the page. The same video sits on our new YouTube channel and in the README of the open source repo.
Play button on the hero, video in an overlay, closes with Escape or a click outside
Embedded videos are a consent category of their own; nothing loads before you say yes
PayGlue has a YouTube channel now, linked from the footer and the setup wizard
Privacy policy updated with a section on embedded videos
September 2026
v0.40
Billing
Pivot
A failed payment is not the end of your account
We changed our mind on this one. Until now an account whose subscription had ended was deleted after 30 days, which sounded tidy and was the wrong ending: cards expire, banks block things, and sometimes a month is just rough. None of that should cost you your setup, so the deletion is gone and a grace period took its place. If a payment for your PayGlue plan fails, you hear from us while your provider retries the card, and nothing else changes. If the subscription ends, you keep full access for 30 days, with a reminder halfway through and a last note the day before. Only then are your workspaces paused, and paused means paused: your connections, mappings, paywalls and buttons stay exactly where they are, and picking a plan brings everything back. A paused account is kept for three months before it is deleted, and you get a notice with the date a week ahead. The same principle for your own readers: An Expired Card Is Not a Cancellation.
Before: deletion 30 days after the subscription ended. Now: a pause you can undo
Failed payment: a mail while your provider retries, nothing else changes
Subscription ended: 30 days of full access, then the pause
Three months of pause before deletion, with a week's notice
Every page here now carries an accessibility toolbar, the marketing pages and the blog alike, and your choices stay in your own browser rather than being sent to us. We did not build it: it is Sienna by Benny Luk, released under the MIT licence, and it is better than anything we would have written ourselves. Thank you for making it open source. We serve it from our own domain instead of a CDN, so opening it hands your IP address to nobody and sets no cookies.
Contrast and saturation, text size, line and letter spacing, and a dyslexia-friendly font
Screen reader, reading guide, larger cursor, and an option to stop animations
Settings live in your browser only. No cookies, and nothing reaches us
The favicon, the dashboard, every transactional email, this blog, the public docs and the open-source repo all carry a new icon now. Nothing else changed: same name, same pricing, same eight providers. Found a real bug while rolling it out everywhere at once, the icon used to carry its own dark background square inline, which disappeared on already-dark surfaces like the dashboard sidebar. Fixed by dropping the background everywhere the icon sits inline, keeping it only for standalone app icon files. Longer version, including why the icon accidentally ended up describing the product: A Light Rebrand I Didn't Plan to Do.
New icon across favicons, the dashboard, transactional emails, the blog and the docs
Fixed the icon disappearing on dark backgrounds where it used to carry its own dark frame
No change to the name, pricing, or product
August 2026
v0.37
Reliability
Shipped
A late payment no longer costs your reader their access
If you sell through Paddle, a reader whose card expired lost access the moment Paddle reported the payment overdue. That was the only provider where this happened, so the same situation had two different outcomes depending on which provider you had chosen. Overdue is not an ending: the provider is still emailing the customer and retrying the card, and the customer has not decided anything yet. There is now one rule everywhere.
An overdue or failed payment leaves access exactly as it was
A cancellation, pause, suspension or expiry still removes it, as before
The same behaviour across all eight providers instead of one exception
Found while checking the facts for an article, not from somebody it happened to
August 2026
v0.36
Security
Shipped
A patched admin, and a framework we can keep moving
Django shipped a security release on 4 August, and one of its four issues reaches anyone running their own copy: the admin turned stored URL values into clickable links without checking the scheme first, so a value saved by a customer could run code in the session of whoever opened the list. We are on the patched release, with a test that fails if anyone steps back below it. The framework itself moved to 6.1 along the way, and the one package holding it back turned out to be switched off and no longer needed.
On the patched Django release, with the admin link fix in place
The upgrade needed no code changes and no database migration
A dependency that had been dormant since the switch to slug-based separation is gone, so future upgrades are not blocked by it
Nothing changes for hosted publications; this matters if you run PayGlue yourself
August 2026
v0.35
Payments
Shipped
Subscriptions that start on time, and end when they should
Providers announce a subscription differently than they announce a one-off sale, and we were listening for only one of the two. A subscription could be paid for and unlock nothing, and a cancellation could go through without the access ever being taken back. Both directions now work, and a member you look at months later says what happened to them.
A subscription unlocks access the same way a purchase does, whichever wording the provider uses
Cancelling really removes access, so your paywall closes again
Cancelling at the end of the paid period keeps access running until that date, as it should
A cancelled member is now labelled as ended and keeps the provider, with the purchase and end dates in the note
August 2026
v0.34
Support
Shipped
Support requests you can actually follow
Writing in from the dashboard now gives you a subject line of your own, a reference you can quote, and a status that moves on its own as we work on it. You can also change the address we reply to, which used to look like a choice and quietly was not.
Name your request yourself instead of us guessing from the first line
The reply address is yours to change, and it is checked before you send
Status follows the ticket, so you see Active or Closed without asking
Provider cards say Connected when the connection is fine, and only ask for attention when a delivery really needs you
August 2026
v0.33
Reliability
Shipped
One product, one outcome, whichever button they clicked
A payment tells us which product was bought. It never tells us which buy button, paywall or pricing column it was bought from, because that is not in the webhook. So there can only be one answer to the question "what happens in Ghost when somebody buys this". Until today the same product could carry a different answer for each widget it appeared in, and a purchase applied all of them in the order they happened to be stored. Nobody lost access, everybody got that, but whether the buyer was subscribed to your newsletter and which label they were given depended on which widget you had saved last. That is now impossible rather than merely avoided: the database refuses a second answer for the same product. The rule is also written by the server as part of saving the widget, so a widget that takes money without granting anything is no longer a state that can exist.
One rule per product, enforced by the database rather than by whichever editor happens to be saving
Saving a widget writes its rule in the same step, so the two can never disagree
Product Mapping now says what a purchase does, in a sentence, and lists every widget offering that product
The check for the paywall script now confirms the script belongs to your publication, instead of accepting any PayGlue script it finds
Blog articles no longer scroll sideways on a phone, and one article can no longer end up with a different text size than the rest
August 2026
v0.32
Website
Shipped
What's new is written once now, and published without a release
This page and the bell in the dashboard were two lists typed into the source code, unaware of each other. Every announcement was written twice, in two voices that drifted, and shipping one meant releasing the whole application. The unread dot had the same problem in miniature: it meant "the list is not empty", which is always true, so after the first look it told nobody anything. Both read one table now. A line is published by saving it, and the dot means what it says. Each item in the bell links to its own entry down this page instead of dropping you at the top of forty-five of them.
The changelog page and the dashboard bell read the same source, so they cannot say different things
The unread dot compares against the last entry this browser has seen, and clears when the bell is opened
The bell shows the four newest and links here for the rest, enforced in code rather than by remembering to delete the oldest
Every entry has its own address on this page, so a link can point at one thing
The page keeps a generated copy of itself, so a backend outage cannot leave you with an empty changelog that still reports success
August 2026
v0.31
Website
Shipped
Every page now arrives as a page, not as an empty shell
Until today this site was one application that drew itself in your browser after the fact. That works for a dashboard behind a login. It is a poor answer for a page somebody found through a search: what a search engine received was the same empty file for eighteen different addresses, with the same title and the same seventy-eight words, and whatever it made of that came later, if at all. The changelog you are reading was the clearest case, months of entries that were invisible to anybody who did not run JavaScript. Every marketing page is now built to finished HTML: the landing page went from nothing to just under three thousand words, this page to over four and a half thousand. The dashboard is untouched, it stays the application it should be.
The landing page, the comparisons, the roadmap, this changelog, the security manifest, the legal pages, both forms and the founding page ship as HTML
Each of them carries its own title, its own description and its own canonical address
An address that does not exist now answers with a real 404 instead of a page that claims to exist
One sitemap instead of two, generated from the pages that were actually built rather than maintained by hand
The price on the landing page no longer waits on two hundred kilobytes of JavaScript before it appears
Every internal link is checked against the built site before a release goes out, so a link to a page that was never generated fails the build
August 2026
v0.30
Open source
Shipped
Run it yourself without signing up for anything first
Until this release, starting your own copy of PayGlue began with creating an account at a hosted identity service. Not as a recommendation: the dashboard threw an error at startup without it, so the software would not boot at all. That is a strange thing to ask of somebody who wanted twenty minutes to decide whether the tool was worth their time. An installation can now keep its accounts in its own database, and a setup wizard walks through the first account instead of showing a sign-in page you have no key for. A hosted provider stays fully supported and still brings what only it can, magic links, sign-in with Google or GitHub, and authenticator apps. Where those do not exist, the screens for them are left out rather than shown and broken. Then we followed our own setup guide on a clean laptop, and it broke on step one. Both bugs it found are fixed here.
Accounts can live in the installation itself, so nothing has to be signed up for elsewhere
A two-step setup wizard on first run, which closes for good once an account exists
The first account is settled by a database constraint, so two simultaneous requests cannot both become the administrator
The password rules the form shows are the rules the server enforces, and nothing else
The example environment file no longer overrides a working default with a placeholder that stops the app from starting
Host ports come from the environment, so an install works on a machine that already runs Postgres
August 2026
v0.29
Open source
Shipped
The open-source build stopped pointing at our servers
PayGlue is source-available, and anyone can run it themselves. Until this release, an install that did so was quietly tied to ours. The snippet you copied out of your own dashboard carried our address, so your readers' browsers talked to our server instead of yours. The check that tells you whether the paywall is installed compared your site against our hostname, so it said no matter how correctly you had set it up. Your checkout could not finish, because the list of allowed return addresses was ours. And the welcome mail going to your customers was signed with our name. None of that was a decision, it was what happens when a product and its open-source build grow out of the same code without anybody checking which one a value belongs to. It is fixed, and this is the release where running PayGlue yourself actually means running it yourself.
Embedded scripts work out their own backend from the tag they were loaded from, so nothing has to be configured and it stays right behind any proxy
The installed check looks at the path, not at whose domain it is
Checkout accepts your own dashboard as a return address
Seeded emails carry no name and no links, and arrive switched off so you read them before your customers do
No product analytics at all: no package, no key, nothing sent anywhere
Six security advisories closed, none left open
August 2026
v0.28
Reliability
Shipped
A purchase that grants nothing no longer looks like a success
A product without a mapping takes the payment, gets accepted, and grants nobody anything. That is the intended behaviour, and until now three separate parts of the dashboard reported it as fine: the editor saved without complaint, the badge saying it was unmapped sat in grey, and the event log marked it processed in green. Somebody paid, nothing happened, and there was no red anywhere. Each of the three now says what it means, and the event can be run again once the mapping exists.
A mapping that fails to save says so, instead of the widget reporting success anyway
Not mapped is a red warning rather than a grey aside, in the Buy Button, Paywall and Pricing Table editors
Processed events can be replayed, so adding a missing mapping no longer means granting access by hand
Replay asks first and says what it will do, including that an existing member is left unchanged and nothing is charged again
The paywall recognises your existing Stripe subscribers, so moving a post onto it keeps the people who have been paying longest
Switching publication reloads the page you are on, instead of showing the previous one until you refresh
August 2026
v0.27
Content
Pivot
The blog moved onto the product domain, and the old one became the demo
Running the blog on a Ghost site at blog.payglue.io was the obvious choice, since we sell to Ghost publishers. It also meant every article we wrote was building a subdomain instead of the domain people actually buy from. A search engine treats those as two different places, so the work was landing in the wrong account. The blog now sits at payglue.io/blog, which is where it should have been from the start. And the Ghost site does not get switched off, it gets a better job: it is the live demo, running the real paywall, buttons and pricing table against a real provider.
payglue.io/blog: 36 articles on the product domain, where the traffic is worth something
Every old article redirects to its new home, so nothing that was already ranking gets dropped
blog.payglue.io stays live as the demo you can walk into rather than an archive nobody visits
Articles that a model helped draft say so, in the byline, on the article
July 2026
v0.26
Growth
Shipped
Get paid for the recommendations you were making anyway
Most of the people who find PayGlue were told about it by somebody else. There was never a way for that somebody to get anything out of it. There is now, and the page shows you what a handful of referrals is actually worth instead of asking you to take a number on faith.
Settings, Affiliate: join the programme in one click, no application to write
40% of every payment your referrals make, for as long as they stay
30 day cookie window, nothing to pay to join, and no minimum payout
A calculator built on the real plan prices, so pick a plan, drag the slider, see the year
July 2026
v0.25
Support
Shipped
The docs sit next to the contact form now
Support looked like a wall: one narrow form, and a support PIN sitting above it as though everybody needed one. Most questions are answered in the docs faster than we can reply, and almost nobody needs the PIN, so the page now says both of those things out loud.
Pick a topic before you write, or skip it, the cards are a shortcut and not a gate
The docs, changelog, roadmap and status page sit beside the form, each with a line on when it is the better stop
The support PIN is marked clearly as something you only need when we ask for it
A help menu in the dashboard header, replacing the single docs button
July 2026
v0.24
Security
Shipped
Confirming something serious no longer means logging out
Handing over a publication or closing an account used to bounce you out of the dashboard and make you sign in again, which is a strange thing to ask of somebody who is already signed in. A confirmation window now opens where you are: your authenticator app if you have one set up, otherwise a code by email.
Step-up confirmation for ownership transfers and account deletion, in an overlay rather than a logout
Uses your authenticator app when you have one, and falls back to a one-time code by email
Each confirmation is good for one action only, so an approval cannot be reused later
Deleting your account now really deletes it, with a confirmation email and a page explaining what is gone
July 2026
v0.23
Team
Shipped
Nobody gets removed from a team quietly
Removing a teammate was a change only the person clicking the button ever saw. That is fine when it is routine and bad when it is not, so the same email now goes to everybody with a reason to know about it.
The removed member is told they no longer have access
The owner and the admins are told who was removed and by whom
Each email goes out separately, so nobody sees anybody else's address
July 2026
Access
Pivot
The waitlist is gone, PayGlue is in open beta
Collecting addresses and letting them wait made sense while there was nothing to hand people. There is now, so the waitlist and the third-party tool behind it are both retired. You can sign up and connect a provider today.
Sign up directly, no invitation needed and no queue to join
The Prefinery waitlist and every mention of it are removed, including from the privacy policy
Founding member pricing is still available at payglue.io/founding while it lasts
July 2026
Trust
Pivot
Your DPA, and a list of everyone who touches your data
If you have ever had to answer a GDPR question about a tool you use, you know the drill: hunt for the data processing agreement, then try to find out which sub-processors are actually involved. Both are now one click away, and they stay that way.
Settings, Documents: download the signed Data Processing Agreement any time
A public sub-processor list at payglue.io/subprocessors, with what each one does and where it runs
New sub-processors are announced there at least 30 days before they go live, with a dated history so you can check
Spelled out on the page: your payment providers are not our sub-processors, you engage them directly
July 2026
v0.22
Team
Fixed
Everyone hears how an ownership transfer ended
Handing a publication to a teammate only ever emailed one person: the current owner, asking them to confirm. The person being handed the publication was never told, and nobody found out how it ended. Fixed.
The proposed owner is told when they are nominated
Everyone involved gets a confirmation when the transfer completes
Everyone involved is told when it is rejected or cancelled
Each email goes out separately, so nobody sees anybody else's address
July 2026
v0.21
Reliability
Shipped
Test any connection without a real purchase
You no longer have to wait for a real sale to find out whether a provider connection actually works. Each mapping now has a "Send test" button that runs a real event through the full pipeline against a test email you control, and tells you straight away whether the member was granted in Ghost, or exactly what went wrong.
One click per mapping, from the Product Mapping page
Runs the real resolver and Ghost sync, so it catches wrong API keys and broken mappings before your customers do
Clear result: member granted, or the concrete error
Works for every provider, including Patreon
July 2026
v0.20
Providers
Shipped
Patreon support
Patreon joins our supported providers. Connect your Patreon campaign and an active pledge automatically grants the Ghost access you mapped it to. A cancelled pledge revokes it, no manual CSV exports or Zapier workflows to maintain.
Map each Patreon tier to the Ghost access it unlocks, right from the dashboard
Active patrons get access automatically; cancelled pledges lose it automatically
Your tiers load into the Buy Button, Paywall, and Pricing Table editors
Signed webhooks, set up once in the Patreon developer portal
July 2026
Providers
Won't build
Mollie payment provider
We looked closely at adding Mollie, a popular European provider several of you asked for. After working through their API, we've decided to hold off for now. Mollie is built primarily for one-off e-commerce payments. Its recurring model asks each creator to build and run their own subscription integration, which doesn't fit PayGlue's "share a link, we handle the rest" approach. Only one-time payments would map cleanly today, and for that narrow slice the effort isn't justified yet. It's back on the backlog, not off the table. If enough of you need Mollie for one-time sales, we'll revisit.
Subscriptions at Mollie are API only, there is no hosted checkout link for a membership
One-time sales via Payment Links would work, but that slice alone does not carry an adapter
Grace periods for downgrades and cancellations, plus reminder emails
Changing your mind about a plan shouldn't mean losing access overnight. Downgrading to a lower plan or canceling your subscription now comes with a clear grace period before anything actually changes, with a few reminder emails along the way so nothing catches you off guard.
Downgrading to a lower plan: full access continues for 30 days before any workspace over your new limit is paused
Canceling your subscription: nothing is removed right away: you get a 30-day window, with a heads-up email at the start and reminders as it winds down
Paused or soon-to-expire workspaces are clearly marked in your dashboard so you always know where you stand
July 2026
v0.18
Dashboard
Shipped
Creem payment provider, reworked navigation with quick search
Creem.io joins our supported payment providers, and it's now the default for PayGlue's own billing too, so your subscription, invoice history, and plan details all read from Creem. The dashboard navigation also got a rework: sections expand in place instead of jumping to a separate tab row, and a quick search (⌘K) jumps straight to any page.
Creem connection: buy buttons, paywalls, and pricing tables all support it end to end
Billing page now shows your real plan name, next payment date, and invoice history from Creem
Expandable sidebar sections with a clearer breadcrumb
Press ⌘K (or click search) to jump to any page instantly
Same navigation on mobile as on desktop
July 2026
v0.17
Account
Shipped
Sign in with Google or GitHub
By popular request, you can now sign in with your Google or GitHub account instead of (or alongside) a magic link email. Both can be connected from your account settings at any time.
One-click sign in with Google or GitHub on the login page
Connect or disconnect either provider anytime from Preferences
Magic link email sign-in still works exactly as before
July 2026
v0.16
Dashboard
Shipped
Redesigned dashboard navigation, Ko-fi support
The dashboard navigation got a cleaner, Finder-style layout: a slim icon rail for the main sections, with a workspace switcher and tabs up top instead of a deep sidebar tree. We also added Ko-fi as a payment provider, popular with the Ghost community for tips and memberships.
New breadcrumb + tabs navigation across the whole dashboard
Ko-fi connection: sync donations and memberships to Ghost access
Six payment providers now supported end to end
July 2026
v0.14
Security
Shipped
Per-tenant webhook secrets
Every account now gets its own unique, randomly generated secret embedded in its webhook URL. Not every payment provider reliably signs its webhook payloads, so we'd rather not rely on that alone. A per-tenant secret keeps each account's webhook delivery isolated regardless of what a given provider does or doesn't verify on their end.
Unique webhook secret generated automatically for every account
Already-configured webhook URLs keep working, nothing to update on your end
Applies across all five supported payment providers
July 2026
v0.13
Providers
Shipped
Paddle support
Paddle joins Polar, Lemon Squeezy, PayPal, and Gumroad as a fully supported payment provider. Connect it, sync member access on completed transactions and subscription changes, and pull your product list straight into the Buy Button dashboard.
New Paddle connection: API key + webhook secret, sandbox auto-detected
Paddle products load automatically in the Buy Button dashboard
Webhook delivery confirmed against a real live purchase
July 2026
v0.12
Providers
Shipped
Gumroad support + live system status page
Gumroad joins Polar, Lemon Squeezy, and PayPal as a fully supported payment provider. Connect it, sync member access on sales, and pull your product list straight into the Buy Button dashboard. Alongside that, our infrastructure status is now public and monitored in real time.
New Gumroad connection: application credentials + webhook sync for sale and subscription events
Gumroad products load automatically in the Buy Button dashboard, checkout links included
status.payglue.io is live: real-time monitoring for the website, backend, database, cache, and background workers
Live status badge added to the site footer
July 2026
v0.11
Infrastructure
Shipped
Automated dependency security scanning + CI pipeline
Added automated dependency security scanning (Dependabot) and a CI pipeline with test coverage across both the open-source and production codebase.
Dependabot now watches every dependency in both repos and opens weekly update PRs
CI runs the full build and test suite on every pull request before it can merge
Backend tests run against a real Postgres instance, matching production
June 2026
v0.10
Open Source
PivotStrategic decision · Impact: community
PayGlue goes open source
After months of building in closed beta, we made the full codebase public. This was not a planned milestone from day one. It became the obvious next step once the closed beta validated that the product works and people genuinely need it. Open sourcing is how we earn trust beyond what any privacy page can say.
Full codebase published at github.com/PayGlue/PayGlue-OS under BUSL 1.1 (converts to Apache 2.0 in 2030)
Self-hosting is free: run PayGlue on your own infrastructure with no license fee
SETUP.md: complete setup guide for Ghost, Polar, Lemon Squeezy, PayPal, and Cloudflare Workers
Thank you to every beta tester, waitlist member, and early adopter who shaped this product, you made this possible
Hosted version remains in closed beta at payglue.io/waitlist
June 2026
v0.10
Integration
Shipped
PayPal: Connect as a payment provider
PayPal is now a fully supported payment provider. Subscribers who purchase through a PayPal subscription plan automatically receive Ghost membership access via the same mapping system used for Polar and Lemon Squeezy.
Webhook handler: OAuth 2.0 signature verification via PayPal's verify-webhook-signature API
Event mapping: BILLING.SUBSCRIPTION.ACTIVATED/CANCELLED/EXPIRED/SUSPENDED translate to Ghost membership actions
Dashboard connection page: step-by-step setup guide for Client ID, Client Secret, and Webhook ID
Product picker: loads active PayPal subscription plans directly from your account in Buy Button, Paywall, and Pricing Table editors
Checkout link: subscription plans link to PayPal's hosted checkout page, where buyers log in with their PayPal account
Setup docs: full guide published at docs.payglue.io/providers/paypal
June 2026
v0.9
Integration
Shipped
Lemon Squeezy: Connect as a payment provider
Lemon Squeezy is now a fully supported payment provider. Purchases made through Lemon Squeezy automatically create Ghost members, assign labels, and send welcome emails via the same mapping system used for Polar.
Webhook handler: HMAC-SHA256 signature verification via X-Signature header
Event mapping: order_created and subscription events translate to Ghost membership actions
Dashboard connection page: step-by-step setup guide for webhook URL and signing secret
Product picker: loads Lemon Squeezy products from your store, including test-mode products
Analytics: webhook events and product mappings visible in the Analytics section
June 2026
v0.9
Dashboard
Shipped
Analytics: Webhook Events and Product Mapping as dedicated pages
The Analytics section is restructured. Webhook Events and Product Mapping are now separate pages accessible from an expandable sidebar section, making it easier to monitor activity and review your configuration at a glance.
Webhook Events: inbound delivery log with status filter, error details, and replay for failed events
Product Mapping: read-only table showing all active mappings with their trigger, newsletter, and email settings
Mobile navigation: icons added to section headers for faster orientation
June 2026
v0.8
Feature
Shipped
Pricing Table: Free, one-time, and subscription tiers in one table
Ghost cannot mix a free tier, a one-time payment, and a subscription into a single coherent pricing table. This embed does exactly that. Paste one script tag into a Ghost HTML card and a fully styled table appears.
Up to 3 tiers per table: free sign-up (opens Ghost portal), one-time payment, or recurring subscription
Monthly/yearly toggle with separate pricing per tier
Embed inline in a Ghost HTML card, and full-bleed width breaks out of Ghost's content column automatically
Or use the overlay button: one button opens the table in a full-screen modal overlay
Customizable accent color for buttons, toggle, ribbon badge, and highlighted card
June 2026
v0.7
Feature
Shipped
Buy Button: Link any Polar product from Ghost content
A lightweight embed that places a branded buy button anywhere in Ghost content. Select a product from your Polar catalog and the checkout URL fills automatically.
One script tag in a Ghost HTML card, no theme edits required
Opens Polar checkout in a new tab or same tab, configurable per button
Customizable label, color, and border radius from the dashboard
Sandbox mode shows test products so you can validate your setup before going live
June 2026
v0.6
Feature
Shipped
JS Paywall: Content gating without Stripe
Ghost blogs without a Stripe connection can now gate content using a lightweight JavaScript snippet. PayGlue checks member access on every page load and shows a fully customizable overlay to non-paying visitors.
One script tag in your Ghost theme header, no database changes, no theme forks
Access check verifies Ghost member status via comped flag or payglue-active label
Overlay is fully customizable: headline, body text, button label, color, and URL
Paywall Config in dashboard: pick a Polar product or use a custom link
Live overlay preview updates as you type
June 2026
v0.5
Integration
Shipped
Polar End-to-End: Payments trigger Ghost membership and welcome email
The first full payment-to-membership flow is live. A Polar purchase now reliably creates a Ghost member with the correct plan, labels, and a welcome email, without any manual steps.
Polar order.paid webhook: Ghost member created automatically with comped plan and PayGlue labels
Welcome email delivered via Ghost Admin API. Magic link is the recommended default for payment flows
Email type selector in mapping settings: choose between magic link, confirmation, or no email
Unsupported event types are silently acknowledged and never stored, keeping the event log clean
June 2026
v0.5
Docs
Shipped
Documentation launched at docs.payglue.io
Based on beta tester feedback, we launched public documentation. Every core workflow now has a dedicated article.
Get started guide: connect Ghost and run your first payment in minutes
Ghost integration: Admin API key setup, Stripe requirement explained
Providers: Polar setup guide, with Lemon Squeezy and Stripe coming soon
Troubleshooting: Ghost Stripe cancellation notice explained, member access checklist
Security overview: encryption, EU infrastructure, zero-knowledge credential storage
June 2026
v0.4
Feedback
PivotTriggered by user feedback · Impact: trust
Security Manifest
Early users asked the same question: "What exactly does PayGlue see from my customers?" We decided the right answer was not a FAQ bullet. It was a dedicated page with verifiable claims, backed by the actual source code.
New /security page: a public record of what PayGlue never sees and exactly what it does see
HMAC-SHA256 signature verification on every webhook with a 5-minute replay-attack window
Credentials stored encrypted in the EU, never logged
Full codebase is public so anyone can audit the claims independently
June 2026
v0.4
Product
PivotPhase: completed · Impact: major
Rebranding: GhostGlue → PayGlue
We proactively reached out to the Ghost Foundation to clarify trademark policy before a wider launch. Their guidelines do not permit using "Ghost" in third-party product names. We rebranded to PayGlue and moved to payglue.io. The product, the team, and the mission stay exactly the same.
New brand: PayGlue at payglue.io
ghostglue.io redirects to payglue.io via Cloudflare
All infrastructure migrated: app.payglue.io, api.payglue.io
Existing beta testers informed and accounts migrated
The sidebar is rebuilt from scratch, settings are reorganized, and organizations can now be renamed or deleted directly in the app.
Sidebar org switcher: dropdown showing all organizations with "Add organization" at the bottom
Integrations renamed to Connection, so Ghost CMS and each payment provider have their own page
New Organization settings: edit your org slug with a warning about webhook URL changes
Danger Zone: delete your organization with slug confirmation (owner only)
June 2026
v0.3
Infrastructure
Reconsidered
Per-tenant PostgreSQL Schemas
We initially planned to give every organization its own database schema for hard data isolation. After reviewing our actual threat model and operational complexity, we decided against it.
June 2026
v0.3
Infrastructure
Shipped
Infrastructure: API Proxy, Railway Backend, Secrets
All API traffic now runs through our own domain. Django backend live on Railway with a real database and encrypted credential storage.
Cloudflare Worker on api.payglue.io proxies all requests
API backend with managed cloud database on EU infrastructure
Encrypted credential storage for Ghost API keys and payment provider tokens
Polar integration: step-by-step webhook setup guide in the integrations page
Ghost health check: green "Connection established" or red "Connection failed"
Session persists across page reloads, no more login loop on reload
May 2026
v0.2
Product
Live
Founding Member Beta Launch
PayGlue is live in closed beta. Founding Members purchase a spot and get auto-provisioned access to the full webhook relay pipeline.
Post-checkout auto-login: purchase on Polar, land directly in your account
Polar production checkout with verified webhook delivery
Organization onboarding: create org, connect Ghost blog, enter dashboard
May 2026
v0.2
Product
Shipped
Waitlist Opens + Landing Page
The first public version of payglue.io goes live. Visitors can join the waitlist and lock in their Founding Member rate.
Landing page with feature overview, pricing tiers, and FAQ
Waitlist signup with email confirmation
Five founding member tiers with automatic tier advancement
April 2026
v0.2
Feature
Shipped
Dashboard & Tenant Architecture
The core dashboard is built. Users can create organizations, manage their Ghost connection, and view payment mappings and event logs.
Multi-tenant architecture: one account, multiple Ghost blogs
Role-based access: owner, admin, member
Event log: every incoming webhook with processing status
March 2026
v0.1
Infrastructure
Shipped
Webhook Relay Engine
The core engine receives payment provider webhooks and translates them into Ghost membership actions.
Webhook receiver with provider-specific signature verification
Automatic retry with exponential backoff on failed deliveries
Dead-letter queue for manual replay
Ghost Admin API integration: grant, revoke, and update membership tiers
January 2026
v0.1
Product
Foundation
Initial Idea and Architecture
PayGlue starts as a personal project. Ghost CMS only supports Stripe natively, but many creators use Polar, PayPal, or other providers.
Problem validated with multiple Ghost publishers
Architecture decision: webhook relay as a non-invasive layer, never touching the Ghost database directly
Core principle: PayGlue is not a payment processor and never sees transaction data
Won't build
Feature
Won't build
Native Ghost Theme Integration
We looked at injecting PayGlue logic directly into Ghost themes via custom code injection. It would have created tight coupling between a user's theme and our infrastructure, making upgrades fragile and debugging nearly impossible. Webhooks are the clean boundary. We stay on our side of it.
Reconsidered
Product
Reconsidered
Free Tier
We explored offering a free tier to lower the entry barrier. We decided against it: free tiers require monetizing at scale through ads, data, or aggressive upsells. PayGlue is built to last as a small, focused tool. A 30-day trial at public launch will be the entry point instead.