# Change history: User authorization

[← Changelog](/docs/changelog). Entries: 9.

- 2026-09-30 [FIX-0930-14: `/v1/oauth/authorize` rejects `state` prefixed with `open-app:`](/docs/changelog/2026-09-30#fix-0930-14-v1-oauth-authorize-rejects-state-prefixed-with-open-app)
- 2026-09-25 [BC-0925-20: Bitrix24 events and automation rule callbacks arrive without Bitrix24 tokens under a Read-only key](/docs/changelog/2026-09-25#bc-0925-20-bitrix24-events-and-automation-rule-callbacks-arrive-without-bitrix24-tokens-under-a-read-only-key)
- 2026-09-14 [FIX-0914-15: OpenAPI now separates a personal key from an OAuth application key](/docs/changelog/2026-09-14#fix-0914-15-openapi-now-separates-a-personal-key-from-an-oauth-application-key)
- 2026-08-13 [FIX-0813-8: The reauth refusal no longer advises OAuth to keys that have none](/docs/changelog/2026-08-13#fix-0813-8-the-reauth-refusal-no-longer-advises-oauth-to-keys-that-have-none)
- 2026-07-29 [BC-0729-4: the session in Authorization must belong to the app from X-Api-Key](/docs/changelog/2026-07-29#bc-0729-4-the-session-in-authorization-must-belong-to-the-app-from-x-api-key)
- 2026-07-28 [NEW-0728-1: an erased author's app no longer issues new user tokens](/docs/changelog/2026-07-28#new-0728-1-an-erased-author-s-app-no-longer-issues-new-user-tokens)
- 2026-07-05 [FIX-0705-2: API key in the Authorization: Bearer header — a clear error instead of INVALID_SESSION](/docs/changelog/2026-07-05#fix-0705-2-api-key-in-the-authorization-bearer-header-a-clear-error-instead-of-invalid_session)
- 2026-06-30 [NEW-0630-2: Self-hosted placement now receives a one-time authorization code on appUrl](/docs/changelog/2026-06-30#new-0630-2-self-hosted-placement-now-receives-a-one-time-authorization-code-on-appurl)
- 2026-06-30 [NEW-0630-3: New endpoint POST /v1/oauth/placement-session for self-hosted apps](/docs/changelog/2026-06-30#new-0630-3-new-endpoint-post-v1-oauth-placement-session-for-self-hosted-apps)
