Spinnable - Notice history

All systems operational

Notice history

Jun 2026

No notices reported this month

May 2026

Issues with worker tools from upstream provider
  • Postmortem
    Postmortem

    Composio security incident — May 21, 2026

    On May 21, 2026, Composio — one of the integration providers Spinnable uses to connect to third-party services — experienced a security incident. Composio's own analysis indicates the affected scope was small (around 0.3% of customer connections globally, concentrated in GitHub, which Spinnable does not route through Composio).

    Impact on Spinnable

    We have no indication that any Spinnable accounts have been impacted. The connections that route through Composio (Gmail, Outlook, Asana, and similar) are stored on Composio's infrastructure, not ours — so our exposure tracked theirs. Integrations Spinnable provides through other MCPs or directly are not part of this incident.

    We reviewed our access logs for activity from the attacker's known IP addresses across the incident window and found no evidence of unauthorized access to Spinnable systems.

    What we did

    Out of an abundance of caution, every affected connection in our project has been invalidated — either through Composio's own bulk-revocation effort, by per-connection revocation we ran through their API, or through direct credential rotation (X / Twitter) where Composio's revocation pathway was failing. Affected users were notified directly by email.

    Timeline (UTC)

    When

    Event

    May 21, 08:05–16:15

    Composio incident window

    May 23

    Composio published their public disclosure and began bulk revocation

    May 24

    Spinnable forensic snapshot, per-connection revocation for our project, X (Twitter) client-secret rotation

    May 26

    Post-mortem published; status page updated

    May 27

    Spinnable emailed the affected users directly

    What we've improved

    • Enabled 2FA on Spinnable's Composio dashboard account

    • Configured IP allowlisting on the Composio API key (a feature Composio rolled out as part of their incident response)

    • Reorganised our public status-page components to separate Spinnable services from subprocessors, so the same kind of upstream incident attributes correctly in future

    • Committed the response tooling (snapshot → resolve users → revoke → comms) to the Spinnable repo for faster future runs

    Looking forward

    For toolkits where token leakage would be high-impact, we're evaluating moving to bring-your-own OAuth credentials, which would give Spinnable a direct kill switch independent of subprocessor cooperation. We'll share updates as that work progresses.

    Reference

    Composio's full public disclosure: https://composio.dev/blog/composio-may-2026-security-incident

    Questions or concerns: security@spinnable.ai

  • Resolved
    Resolved

    This incident has been resolved. All tools should be working correctly after reconnection.

    We will notify users by email in the coming day with more details about the causes and measures taken.

  • Monitoring
    Monitoring

    We implemented a fix and are currently monitoring the result. We will email users individually to explain the actions taken and the disruption they saw with some of their connected accounts.

  • Investigating
    Investigating

    We are currently investigating an incident with an upstream provider of tools for workers.

Network restrictions preventing read replica communication
  • Resolved
    Resolved

    Communication between read replicas and their primaries for impacted projects has been restored. This incident is now resolved.

  • Monitoring
    Monitoring

    We have merged the fix and are monitoring for stability.

  • Update
    Update

    We have developed a fix and it is currently being validated. We will provide more updates soon.

  • Update
    Update

    Our team continues to work on implementing a fix for the issue. We will provide additional updates as progress is made.

  • Update
    Update

    Our team continues to work on implementing a fix for the issue. We are continuing to monitor the impact and will provide additional updates as progress is made.

  • Identified
    Identified

    We have identified the cause of the issue impacting read replica communication for projects. Our team is actively working on a fix and continuing to assess the impact to affected projects.

  • Update
    Update

    We are reviewing the impact of this issue, which is limited to projects with read replicas and network restrictions. We continue to both investigate mitigation options for the issue and identify projects that may be impacted.

  • Investigating
    Investigating

    Network restrictions are preventing read replicas from communicating with their primaries for a limited number of customer projects. We are actively investigating this issue.

Apr 2026

Some projects unavailable across multiple regions
  • Resolved
    Resolved

    This incident has been resolved.

  • Monitoring
    Monitoring

    We believe all users affected by this particular issue have been resolved. The team is going to keep an eye on these error rates to ensure we catch any that didn't originally appear, or that no new issues arise.

    We appreciate your patience as we worked through this issue.

  • Update
    Update

    The team is continuing their mitigation efforts. We've fixed and restarted most of the affected projects. We're continuously looking for any others that are affected so we can be sure to get them all fixed.

  • Update
    Update

    The team is still working to bring these back online, and have a fix under way.

    Many users can also resolve this on their own via a project restart. This can be performed from the dashboard for your own projects at any time. But for those who are still seeing issues after a restart, we will be pushing a fix soon.

  • Update
    Update

    We have identified this issue across multiple regions, not just eu-west-3 as originally suspected. We are expanding the scope of efforts to bring affected projects back online.

    Users can also resolve this, in most cases, on their own via a project restart. This can be performed from the dashboard for your own projects at any time.

  • Update
    Update

    The team is continuing to work through affected projects; however, a project restart is also effective. This can be performed from the dashboard for your own projects at any time.

  • Identified
    Identified

    We are seeing an increase in projects unavailable in eu-west-3 following an upstream issue with EC2 instances in the region. The team is working on restoring access to these projects

Increased Errors on HTTP Endpoints
  • Resolved
    Resolved

    All metrics have been nominal and stable for several hours now, and our upstream provider has resolved their incident.

  • Monitoring
    Monitoring

    We've received confirmation from our networking provider that there is recovery across all regions. We are able to corroborate this with our own metrics collections. We will continue to monitor for a bit, but we believe this to be resolved at this time.

    We apologize for the trouble, and we appreciate your patience.

  • Update
    Update

    We've seen a marked improvement in error rates across all regions in the last few minutes. We are still waiting on confirmation from our provider on status, but we believe things to be improved at the moment. We'll keep working on this until we have for sure reached a resolution.

  • Update
    Update

    We recognize that some of our users, especially in parts of North and South America, are continuing to experience DNS and 5XX errors when trying to connect to their projects. We have escalated this issue with our network provider and will work with them continuously until the problems are resolved.

  • Identified
    Identified

    Some users continue to experience errors. We are raising the issue with our provider.

  • Monitoring
    Monitoring

    Our upstream provider has reported their incident resolved. We will continue to monitor for any errors our customers may be experiencing for another 30 minutes.

  • Update
    Update

    The fix that our upstream provider implemented has taken effect. Service has significantly improved across all previously impacted regions. There are still residual elevated error rates in a handful of regions and we will continue to work with our provider to eliminate them.

  • Update
    Update

    Our upstream provider has rolled the fix out to most regions. While we are seeing improvement, we are still seeing increased error rates in Mexico and Brazil and are continuing to work with them until this is fully resolved.

  • Update
    Update

    Upstream provider mitigations are still under way, and we are seeing improvements incrementally as routing regions have the mitigations applied. We are still seeing particular impact in South America, but some users in North America may still be affected as well. We anticipate continued incremental improvements and will update as we get more information.

  • Update
    Update

    Our upstream networking provider has identified a fix and is currently implementing a fix. We are seeing preliminary improvements to error rates for users in North America, but are still following this issue closely with our provider.

  • Update
    Update

    Our upstream networking partner is continuing their investigation. We will continue to post regular updates as we have more information.

  • Identified
    Identified

    Our upstream networking provider has discovered an issue and has declared an incident on their side. They are currently working toward resolution. We are actively working with them and will provide updates on progress as more information is available.

  • Update
    Update

    We continue to have active lines of investigation going with our upstream network provider partners, and are still working toward a resolution.

    This issue affects the network-level access to projects. The projects themselves and the data in them are safe and unaffected.

    Users are seeing two separate symptoms of these networking issues:

    1. DNS Lookup failures for supabase project URLs
    2. 530 responses to HTTP requests to supabase project API Endpoints
  • Update
    Update

    We continue to work with partners and investigate.

  • Update
    Update

    We have further clarified the scope and impact of the issues currently affecting users. A subset of users across North and South America are experiencing DNS resolution failures and HTTP 530 errors.
    These symptoms indicate a networking-related issue impacting the availability of Supabase projects. We are actively working with both internal teams and external network providers to isolate the root cause and determine the most effective path to resolution.
    We will continue to provide updates as more information becomes available.

  • Update
    Update

    We are actively investigating this issue and working with relevant partner organizations. At this time, we do not believe this issue is specific to any particular network provider. A subset of users continue to be impacted in both South and North America.

  • Update
    Update

    We are currently investigating reports of users experiencing login issues when using Supabase Auth.

    At this time, the impact appears to be limited to a subset of users, primarily in North and South America.
    The exact cause and scope are still being determined.

    Our team is actively working to identify the root of the issue and will provide updates as more information becomes available.

    We appreciate your patience while we investigate.

  • Investigating
    Investigating

    We are currently investigating reports of users experiencing login issues when using Supabase Auth.

    At this time, the impact appears to be limited to a subset of users, primarily in South America.
    The exact cause and scope are still being determined.

    Our team is actively working to identify the root of the issue and will provide updates as more information becomes available.

    We appreciate your patience while we investigate.

Apr 2026 to Jun 2026

Next