## 0.76.0 - **A deployment now enrols with the fleet receiver instead of holding a token every deployment shared.** `ANCHORPOINT_FLEET_TOKEN`, the credential every client deployment's cron environment held identically, is gone: a token shipped inside a public installer bundle is a public token and was never one. `POST /heartbeat` authenticates a deployment by what it has already done instead. The first heartbeat for an unbound `deployment_id` carries no credential by construction, so the receiver mints one, binds it to that id, and returns it once; every heartbeat after presents it as a bearer token, and a bound id presenting no token or the wrong one is refused with a 401 and writes nothing. Tokens are stored hashed, never in the clear. The sender keeps its minted token in a file, `ANCHORPOINT_FLEET_TOKEN_FILE`, defaulting to `/app/fleet/token`, a new writable mount `deploy/compose.client.yml` and `deploy/docker-compose.server.yml` both add; a deployment that loses the file is refused until an operator clears its binding. - **`ANCHORPOINT_FLEET_READ_TOKEN` is renamed `ANCHORPOINT_FLEET_OPERATOR_TOKEN`**, because it now authorises a state change (clearing a binding) and not only a read. The old name is still read, as a deprecated fallback logged once at WARNING, and stops being read after the next release. - **An operator can clear a deployment's fleet enrolment from the console.** The Fleet screen gains `enrolled_at` and `last_seen_at` per row and a confirm-guarded "Clear enrolment" control, root-only and CSRF-checked, that calls the receiver's new `DELETE /deployments/{deployment_id}/binding`; the next heartbeat for that id enrols fresh. See `docs/TELEMETRY.md`, "The receiver", for the full protocol and its one remaining limit: an id chosen by hand at install is guessable and can be claimed before its real owner's first heartbeat, which generated ids are not exposed to. - **`install.py verify` no longer demands docker.** The installer's preflight checked Python, docker's compose plugin and `ssh-keygen` before any verb ran, so the one verb that runs no container was refused on a machine that has none. `docs/INSTALL.md` offers `verify` as the step a cautious reader takes before trusting a bundle enough to run anything from it, and an air-gapped boundary verifies on the machine that received the media rather than on the host it is about to install. The docker probe now runs for every verb except `verify`.