# Todos for everyone, custom environment headers, and Slack in chat

> 6 updates: Chat can read and post to Slack, Custom HTTP headers for environments, Todos is now on for every organization, Store API keys as a dedicated…

Source: https://qa.tech/changelog/2026-09-04

---
6 updates shipped on September 4, 2026.

In this release

1.  01[Chat can read and post to Slack](#2026-09-04-chat-can-read-and-post-to-slack)Highlight
2.  02[Custom HTTP headers for environments](#2026-09-04-custom-http-headers-for-environments)Highlight
3.  03[Todos is now on for every organization](#2026-09-04-todos-for-every-organization)Highlight
4.  04[Store API keys as a dedicated config type](#2026-09-04-api-key-config-type)
5.  05[Copy assistant replies in chat](#2026-09-04-copy-assistant-replies-in-chat)
6.  06[Re-run the PR review agent on demand](#2026-09-04-rerun-the-post-merge-review-agent)

1.  Highlight
    
    Featured this release
    
    ## Chat can read and post to Slack
    
    Opt in and the agent can browse channels, read threads and post updates, screenshots included.
    
    Turn on "Enable Slack Tools in Chat" under the project's [Slack integration](https://docs.qa.tech/integrations/slack) and chat gains tools to list public channels, read messages and threads, and post rich updates with images and files attached.
    
    Off by default – existing Slack integrations are unaffected until you opt in. You may need to reconnect Slack to grant the additional permissions.
    
    More on this: the [Slack integration](https://qa.tech/product/integrations/slack).
    
    [\# Direct link](#2026-09-04-chat-can-read-and-post-to-slack)
    
2.  Highlight
    
    Featured this release
    
    ## Custom HTTP headers for environments
    
    Set per-environment header rules, like a preview protection-bypass token, and every run sends them.
    
    In environment settings, add name and value header rules scoped to a domain pattern, for example \*.preview.example.com. Matching requests from the browser, crawler and API sandbox include them automatically – handy for bypassing preview-deployment protection or attaching auth tokens.
    
    Rules can also be set from the Start Run API or a [GitHub Action](https://docs.qa.tech/integrations/github) configuration, and they persist across runs until explicitly cleared.
    
    More on this: [preview protection bypass](https://qa.tech/product/integrations/vercel-preview-protection) and [multi-environment testing](https://qa.tech/use-cases/multi-environment-testing).
    
    [\# Direct link](#2026-09-04-custom-http-headers-for-environments)
    
3.  Highlight
    
    Featured this release
    
    ## Todos is now on for every organization
    
    Todos leaves early access, splits into Focus and More, and each item leads with a way to solve it.
    
    Every organization now sees Todos in the project nav, chat and command palette – no invite needed.
    
    The list splits into two views with the same filter pills as Pull Requests: Focus holds todos that recurred four or more times in the last 30 days, More holds everything else recent, and hovering either pill explains the rule.
    
    Each todo's detail page now opens with a Recommended Next Step – Solve in Chat, or Complete With Cursor or Claude – instead of a generic settings link.
    
    More on this: [testing AI-generated code](https://qa.tech/use-cases/ai-generated-code-testing) and [how to audit your QA process](https://qa.tech/blog/how-to-audit-your-qa-process).
    
    [\# Direct link](#2026-09-04-todos-for-every-organization)
    
4.  Update 04 of 06
    
    ## Store API keys as a dedicated config type
    
    Configs now have an API Key type, masked everywhere in the UI and passed to tests as a variable.
    
    Under Settings → Configs → Add config, choose API Key to store a secret without folding it into Custom Fields. The value stays masked in the dashboard and in chat, and API tests can reference it as an environment variable.
    
    More on this: [API testing](https://qa.tech/product/api-testing) and [API contract testing](https://qa.tech/use-cases/api-contract-testing).
    
    [\# Direct link](#2026-09-04-api-key-config-type)
    
5.  Update 05 of 06
    
    ## Copy assistant replies in chat
    
    A copy icon appears under finished assistant messages so you can grab the text in one click.
    
    Once an assistant message finishes, a copy icon appears next to the feedback buttons. Click it to copy the reply's text – tool calls and reasoning are excluded – and the icon turns into a checkmark to confirm.
    
    More on this: [what QA.tech does](https://qa.tech/product).
    
    [\# Direct link](#2026-09-04-copy-assistant-replies-in-chat)
    
6.  Update 06 of 06
    
    ## Re-run the PR review agent on demand
    
    A menu action starts the post-merge review agent manually from any pull request.
    
    From a project's Pull Requests list, a pull request's detail page, its kebab menu or Cmd+K, choose "Run post-merge agent" to trigger a review on demand. Running it on a pull request that has not merged yet asks for confirmation first, and a toast with a "View conversation" link opens the chat thread the agent posts to.
    
    More on this: [pull request testing](https://qa.tech/product/pr-testing) and the [GitHub integration](https://qa.tech/product/integrations/github).
    
    [\# Direct link](#2026-09-04-rerun-the-post-merge-review-agent)
    

## Your team moves fast. Can your testing keep up?

QA.tech agents test your product autonomously, so moving fast never means shipping broken. See how it works in a 30-minute demo.

[Get a demo](https://qa.tech/demo)

[QA.tech](https://qa.tech/)

SOC 2 Type 2 compliant

![Sensiba SOC 2 Type 2 compliant](https://qa.tech/assets/soc2-type2-badge-DPb1j9VX.png)

### Product

-   [API Testing](https://qa.tech/product/api-testing)
-   [MCP](https://qa.tech/product/mcp)
-   [Mobile Testing](https://qa.tech/product/mobile-testing)
-   [PR Testing](https://qa.tech/product/pr-testing)
-   [Voice Testing](https://qa.tech/product/voice-testing)
-   [Web Testing](https://qa.tech/product/web-testing)

-   [AI QA testing guide](https://qa.tech/ai-qa-testing)
-   [Changelog](https://qa.tech/changelog)
-   [Integrations](https://qa.tech/product/integrations)
-   [Platform overview](https://qa.tech/product)
-   [Use cases](https://qa.tech/use-cases)

### Compare

-   [QA.tech vs Cypress](https://qa.tech/compare/qa-tech-vs-cypress)
-   [QA.tech vs Mabl](https://qa.tech/compare/qa-tech-vs-mabl)
-   [QA.tech vs Playwright](https://qa.tech/compare/qa-tech-vs-playwright)
-   [QA.tech vs QA Wolf](https://qa.tech/compare/qa-tech-vs-qa-wolf)

-   [B2B SaaS testing](https://qa.tech/saas)
-   [Ecommerce testing](https://qa.tech/industries/ecommerce)
-   [For CTOs](https://qa.tech/solutions/ctos)
-   [For QA teams](https://qa.tech/solutions/qa-testers)

### Resources

-   [Docs](https://docs.qa.tech/)
-   [Blog](https://qa.tech/blog)
-   [Events](https://qa.tech/events)
-   [Pricing](https://qa.tech/pricing)
-   [Case Studies](https://qa.tech/case-studies)

### Company

-   [About](https://qa.tech/about-us)
-   [Partnerships](https://qa.tech/partnerships)
-   [Press](https://qa.tech/press)
-   [Contact Us](https://qa.tech/contact)
-   [Privacy Policy](https://qa.tech/privacy-policy)
-   [Terms of Service](https://trust.qa.tech/resources?s=mb9w4yjb03i3t8bjsq4jx3&name=main-agreement.pdf)
-   [Security & Compliance](https://trust.qa.tech/)

### Social

-   [](https://www.linkedin.com/company/qa-tech-ai/)
-   [](https://x.com/getqatech)
-   [](https://www.instagram.com/getqatech/)

© 2026 QA.tech. All rights reserved
