diff --git a/changelog.mdx b/changelog.mdx
index 8ebdc835..57a2837e 100644
--- a/changelog.mdx
+++ b/changelog.mdx
@@ -9,6 +9,41 @@ import { YouTubeVideo } from '/snippets/youtube-video.mdx';
For API library updates, see the [Node SDK](https://github.com/onkernel/kernel-node-sdk/blob/main/CHANGELOG.md), [Python SDK](https://github.com/onkernel/kernel-python-sdk/blob/next/CHANGELOG.md), and [Go SDK](https://github.com/onkernel/kernel-go-sdk/blob/main/CHANGELOG.md) changelogs.
+
+## Product updates
+
+### Auth
+
+- Added **[1Password Agentic Autofill](/vaults/1password)** (preview). Your end users can approve access to logins that stay in their own 1Password account. Once your organization has preview access, connect accounts through the CLI, MCP server, or dashboard.
+- The MCP server’s vault tools now return the API’s error codes and messages.
+- Added managed auth [reauthentication](/auth/configuration) controls to the dashboard: a **Health checks** switch and a separate toggle for automatic reauthentication. Both were already available through the API and CLI.
+- The dashboard now shows **Unverified** for managed auth connections whose health check was skipped because no check URL is set.
+
+### Payments
+
+- Added **[MPP browser purchases](/info/mpp)**. Agents can buy a stealth, headful browser session through the Machine Payments Protocol without a Kernel account or API key.
+- Added optional `checkout_origin` to the [AgentCard](/integrations/wallets/agentcard) card spec for autopilot rule matching. Supported in the MCP server.
+- Vault provider configs now include the Link publishable key.
+
+### Browsers
+
+- Extended `memory` to [browser pools](/browsers/pools). Create or update a pool with `16GiB` instead of the default `8GiB`. Updates apply to newly created browsers; existing browsers keep their original allocation.
+- [WebMCP](/browsers/webmcp) listings now include tools registered through a `navigator.modelContext` polyfill, so you can discover and invoke them like native page tools.
+- Added common Ubuntu desktop fonts to the headful browser image, making the fonts a page can detect more typical of a Linux desktop.
+- Launched browser-first onboarding in the dashboard.
+
+## Documentation updates
+
+- Added a [1Password Agentic Autofill](/vaults/1password) guide covering setup, credential collection as a fallback, and private vault and passkey limitations.
+- Added [Export Telemetry](/browsers/telemetry/export) for sending session events to your OpenTelemetry backend over OTLP.
+- Added [Buy a Browser with MPP](/info/mpp), covering the `402` payment flow.
+- Added [Code Mode with Browser REPL and WebMCP](/browsers/code-mode-webmcp) and a Browser REPL page in the MCP reference.
+- Added cookbooks for [e2e Web Testing](/cookbooks/e2e-kernel) and [Personal Shopper with Link and Eve](/cookbooks/personal-shopper).
+- Rewrote [Web Bot Auth](/browsers/bot-detection/web-bot-auth) around opt-in access to Kernel’s WBA token for Startup and Enterprise plans. Added links from the bot anti-detection overview and stealth guide, and moved Bot Anti-Detection to the start of the Intermediate section.
+- Documented [browser pool](/browsers/pools) memory options.
+- Split cookbooks into common patterns and harnesses & models, and updated the skills docs to recommend the `kernel` CLI.
+
+
## Product updates