For AI agents: markdown of this page — /docs-content-en/changelog/keys-auth-oauth.md documentation index — /llms.txt
Change history: User authorization
← Changelog. Entries: 9.
- 2026-09-30 FIX-0930-14:
/v1/oauth/authorizerejectsstateprefixed withopen-app: - 2026-09-25 BC-0925-20: Bitrix24 events and automation rule callbacks arrive without Bitrix24 tokens under a Read-only key
- 2026-09-14 FIX-0914-15: OpenAPI now separates a personal key from an OAuth application key
- 2026-08-13 FIX-0813-8: The reauth refusal no longer advises OAuth to keys that have none
- 2026-07-29 BC-0729-4: the session in Authorization must belong to the app from X-Api-Key
- 2026-07-28 NEW-0728-1: an erased author's app no longer issues new user tokens
- 2026-07-05 FIX-0705-2: API key in the Authorization: Bearer header — a clear error instead of INVALID_SESSION
- 2026-06-30 NEW-0630-2: Self-hosted placement now receives a one-time authorization code on appUrl
- 2026-06-30 NEW-0630-3: New endpoint POST /v1/oauth/placement-session for self-hosted apps