For AI agents: markdown of this page — /docs-content-en/changelog/keys-auth.md documentation index — /llms.txt
Change history: Keys & Auth
← Changelog. Entries: 53.
- 2026-10-01 FIX-1001-9: Cowork key no longer refused to a box service account
- 2026-10-01 BC-1001-19: changing the mode of Cowork/Code seat keys through V1 and re-issuing a key wider than the caller are refused with 403
- 2026-09-30 BC-0930-31: Key revocation with a server outside its owner and Bitrix24 account scope
- 2026-09-26 BC-0926-1: the Cowork subscription key of an owner without a Bitrix24 account cannot be rotated, re-enabled or extended
- 2026-09-25 FIX-0925-9: Editing the scopes of a key whose webhook stayed on the previous Bitrix24 account address answers PORTAL_ADDRESS_CHANGED
- 2026-09-22 BC-0922-9: Retrying an unfinished key rotation requires recovery
- 2026-09-17 BC-0917-20: key mode errors point to an available switch
- 2026-09-17 FIX-0917-29: a bracket-form parameter gets 400 instead of 500
- 2026-09-16 FIX-0916-5: the COWORK_HARNESS_DISABLED code no longer arrives on Cowork subscription keys
- 2026-09-16 FIX-0916-17: POST /v1/keys/{id}/rotate accepts a blocked key
- 2026-09-09 FIX-0909-5: a self-hosted portal now issues a key that needs no webhook
- 2026-09-09 FIX-0909-6: replacing an application key no longer hands out an already-expired secret
- 2026-09-02 FIX-0902-13: the Bitrix24 plan refusal on key issuance and app installation now states its cause
- 2026-09-01 FIX-0901-3: rate limit descriptions now name the replica share, not just the total cap
- 2026-08-26 NEW-0826-10: the
vibe:infrascope is no longer granted on accounts with infrastructure disabled - 2026-08-22 BC-0822-2: the create and rotate responses now match the documented key shape
- 2026-08-22 BC-0822-3: key rotation now requires the same Bitrix24 plan as creation
- 2026-08-22 NEW-0822-4: a key now reports the channel it was issued through, and a refusal reports its exact cause
- 2026-08-22 FIX-0822-5: a rotation refused over scopes now reports the same code on every account
- 2026-08-22 BC-0822-8: rotating and bringing back platform-issued keys is closed
- 2026-08-22 NEW-0822-10: Reactivating a subscription key checks the issuance gates
- 2026-08-22 NEW-0822-11: Rotating a subscription key checks the issuance gates
- 2026-08-22 NEW-0822-12: POST /v1/keys rejects subscription billing
- 2026-08-20 FIX-0820-14: the account receives Bitrix24 scopes only, and a platform-only key no longer gains a webhook on rotate
- 2026-08-20 FIX-0820-18: revoking a key now closes the access links it issued
- 2026-08-11 NEW-0811-3: issuing a key with exactly the selected platform rights
- 2026-08-11 BC-0811-18: marking messages read now requires a key with write access
- 2026-08-11 FIX-0811-19: five more read operations stopped being rejected under a read-only key
- 2026-08-09 BC-0809-1: meta.total is no longer returned by default in lists
- 2026-08-07 FIX-0807-4: a body-less request reaches its handler instead of failing at parse time
- 2026-08-06 NEW-0806-13: the key-limit refusal now states the numbers
- 2026-08-06 FIX-0806-23: key issuance now checks platform access
- 2026-08-06 NEW-0806-24: a clear refusal when a personal key is left with only placement or entity
- 2026-08-05 FIX-0805-1: key rotation no longer strands the bot registered with it
- 2026-08-05 FIX-0805-2: a container on a shared host is no longer lost after key rotation
- 2026-08-05 FIX-0805-3: key rotation no longer disconnects the server and app bound to it
- 2026-08-05 FIX-0805-23: a personal key with no Bitrix24 webhook now says what it is missing
- 2026-07-29 NEW-0729-6: a management key whose owner account is pending erasure now returns 503
- 2026-07-29 NEW-0729-18: totalDefault — the meta.total default on the API key itself
- 2026-07-14 FIX-0714-35: placement bind for earlier-created apps is no longer rejected over the handler
- 2026-07-10 NEW-0710-13: placement.bind on a self-hosted Bitrix24 returns a clear SESSION_REQUIRES_ADMIN for a non-administrator
- 2026-07-10 FIX-0710-14: GET /v1/me capabilities now reflect read-only (READONLY) mode
- 2026-07-10 FIX-0710-15: the feedback author can reply to their own ticket again without the vibe:feedback scope
- 2026-07-05 FIX-0705-2: API key in the Authorization: Bearer header — a clear error instead of INVALID_SESSION
- 2026-07-03 NEW-0703-6: key deletion is blocked while an agent or bot is linked
- 2026-07-02 NEW-0702-7: Research price in the key self-description and the required top-up in the 402 body
- 2026-07-02 FIX-0702-18: a vibe:*-only key now issues instead of failing
- 2026-07-01 NEW-0701-4: Extended static field contract in /v1/guide and a schema-discovery pointer in /v1/me
- 2026-06-30 FIX-0630-4: PATCH on an OAuth application key's scopes: honest rejection instead of false access
- 2026-06-29 BC-0629-3: vibe-search provider slug removed
- 2026-06-28 FIX-0628-1: editing a key's scopes now applies them to the Bitrix24 webhook
- 2026-06-25 FIX-0625-6: /v1/me: storage supportedVisibilities are now uppercase
- 2026-06-23 BC-0623-4: API key creation is admin-only