diff --git a/.gitignore b/.gitignore
index dd915994..5eca79d4 100644
--- a/.gitignore
+++ b/.gitignore
@@ -112,4 +112,8 @@ markdown-help/**
## downloaded assets models
-*.mdsp.assetmodel/**
\ No newline at end of file
+*.mdsp.assetmodel/**
+
+url-migration-review.md
+
+.DS_Store
diff --git a/.npmignore b/.npmignore
index ac6b8f75..b2d14cb7 100644
--- a/.npmignore
+++ b/.npmignore
@@ -6,9 +6,9 @@
agentconfig*.json
images/
docs/
-src/
-test/
-templates/
+/src/
+/test/
+/templates/
.dockerignore
Dockerfile
tsconfig.json
@@ -32,6 +32,8 @@ report.xml
.github
.prettier*
+url-migration-review.md
+
bulkupload*
bulkdownload*
eventdownload*
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 1cc90e50..daf3ee23 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,20 @@
# Changelog
+## 4.0.0 - Stormy Vienna - September 2026
+
+- BREAKING CHANGE: Insights Hub URLs are migrating from the `mindsphere.io` domain to the new `siemens.app` scheme. Version 4.0.0+ only works with the new `siemens.app` URLs - use the `3.x` release line if your tenant/gateway still uses `mindsphere.io` URLs.
+- SDK, CLI: added support for the Xcelerator `coreTenantId`/`customerTenantId` (OAuth/PIAM identity zone id) so the SDK can build correct `siemens.app` URLs
+- SDK: separated application vs. technical user credential forms in the config web server, renamed "service credentials" to "technical user credentials", and clarified core/customer tenant id field descriptions
+- Fixed file upload hitting the wrong gateway host on Xcelerator agents
+- Fixed cookie/browser auth path resolution for Xcelerator tenants, including sending the `gw_session` cookie (renamed from `mindsphere_session`) for borrowed-cookie auth
+- Fixed jku host validation and an Application Credentials UI bug
+- Fixed broken Asset Manager, Operations Insight, and Settings app links on Xcelerator tenants (they now correctly use `