# API changes: June 28, 2026

[← Changelog](/docs/changelog) · [June 2026](/docs/changelog/2026-06)

### FIX-0628-1: editing a key's scopes now applies them to the Bitrix24 webhook

**Before**

`PATCH /v1/keys/:id` with a `scopes` array saved the new set in Vibecode but, on self-hosted Bitrix24 portals, did not propagate it to the Bitrix24 webhook. The webhook kept its old scope set, so a call to a freshly added scope was rejected by Bitrix24 (403) even though Vibecode already reported the key as carrying it.

**After**

A `scopes` change is now applied to the Bitrix24 webhook in the same request. If the sync cannot be performed, the key is not updated (Vibecode and Bitrix24 stay on the previous set) and the response carries an error code: `INVALID_SCOPES` (400) — Bitrix24 does not grant one of the requested scopes, `STALE_DEVELOPER_KEY` (410) or `RECOVERY_FAILED` (502) — the developer key is invalid, `BOX_NO_DEVELOPER_KEY` (400) — the key owner has no developer key, `DEVKEY_SCOPE_SYNC_FAILED` (502) — any other Bitrix24 rejection.

**Impact on integrators**

No action needed — scopes added via `PATCH /v1/keys/:id` now take effect immediately. If the response returns one of the codes above, the scope set was left unchanged: fix the cause and retry.
