diff --git a/changelog.mdx b/changelog.mdx index 47c1347f0..17271d235 100644 --- a/changelog.mdx +++ b/changelog.mdx @@ -7,6 +7,25 @@ keywords: ["changelog", "API updates", "release notes", "what's new", "API chang To subscribe to updates, please [**“Turn on notifications”**](https://help.x.com/en/managing-your-account/notifications-on-mobile-devices#:~:text=In%20the%20top%20menu,%20you,you%20would%20like%20to%20receive) for [**@API**](https://x.com/api). You can also follow this changelog in your feed reader via the [**RSS feed**](https://docs.x.com/changelog/rss.xml). + + ### New features + + - **Expiring X Activity API subscriptions:** Pass an optional `expires_at` (RFC 3339) when you create a subscription, and X deletes it automatically at that time. To change it, send the same `POST /2/activity/subscriptions` request again with a new value. See [Subscription expiration](/x-api/activity/introduction#subscription-expiration). + - **OAuth 2.0 client secret for webhooks:** You can now use your app's OAuth 2.0 client secret for CRC responses and signature verification. Apps with a client secret configured receive the new `X-Twitter-Webhooks-Signature-OAuth2` header. The legacy `X-Twitter-Webhooks-Signature` header is unchanged. See [Signature headers](/x-api/webhooks/introduction#signature-headers). + - **`is_moderator` on `broadcast.chat` events:** The [`broadcast.chat`](/x-api/activity/event-payloads) payload now shows whether the sender is a chat moderator. The broadcast owner is reported as `is_moderator: false`. + + ### Updates + + - **Broadcast scopes in token exchange:** When you [exchange OAuth 1.0a tokens for OAuth 2.0](/fundamentals/authentication/oauth-2-0/oauth-1-0a-token-exchange), Read permission now includes `broadcast.read`, and Read and write permission now includes `broadcast.write`. + - **Approve Chat join requests:** [Adding a user to a Chat group](/x-api/chat/add-members-to-a-chat-group-conversation) who has a pending join request now approves that request. Use the same key-rotation body you use to add any member. + - **Livestream API access:** The Livestream API is available to approved (whitelisted) apps and no longer requires an Enterprise plan. Request access with the [Livestream API Access Form](/forms/livestream-api-access). + + ### Bug fixes + + - **Batch compliance upload limit:** The correct upload limit is **128 MB** (about 6.5 million IDs). Larger uploads return `413`. See [Uploads](/x-api/compliance/batch-compliance/integrate#uploads). + - **`source` removed from `tweet.fields`:** The deprecated `source` field is no longer listed as an available [Post field](/x-api/posts/lookup/integrate#available-fields), matching its removal from X API v2. + + ### Migrate OAuth 1.0a user tokens to OAuth 2.0 with token exchange