diff --git a/changelog.mdx b/changelog.mdx
index 47c1347f0..17271d235 100644
--- a/changelog.mdx
+++ b/changelog.mdx
@@ -7,6 +7,25 @@ keywords: ["changelog", "API updates", "release notes", "what's new", "API chang
To subscribe to updates, please [**“Turn on notifications”**](https://help.x.com/en/managing-your-account/notifications-on-mobile-devices#:~:text=In%20the%20top%20menu,%20you,you%20would%20like%20to%20receive) for [**@API**](https://x.com/api). You can also follow this changelog in your feed reader via the [**RSS feed**](https://docs.x.com/changelog/rss.xml).
+
+ ### New features
+
+ - **Expiring X Activity API subscriptions:** Pass an optional `expires_at` (RFC 3339) when you create a subscription, and X deletes it automatically at that time. To change it, send the same `POST /2/activity/subscriptions` request again with a new value. See [Subscription expiration](/x-api/activity/introduction#subscription-expiration).
+ - **OAuth 2.0 client secret for webhooks:** You can now use your app's OAuth 2.0 client secret for CRC responses and signature verification. Apps with a client secret configured receive the new `X-Twitter-Webhooks-Signature-OAuth2` header. The legacy `X-Twitter-Webhooks-Signature` header is unchanged. See [Signature headers](/x-api/webhooks/introduction#signature-headers).
+ - **`is_moderator` on `broadcast.chat` events:** The [`broadcast.chat`](/x-api/activity/event-payloads) payload now shows whether the sender is a chat moderator. The broadcast owner is reported as `is_moderator: false`.
+
+ ### Updates
+
+ - **Broadcast scopes in token exchange:** When you [exchange OAuth 1.0a tokens for OAuth 2.0](/fundamentals/authentication/oauth-2-0/oauth-1-0a-token-exchange), Read permission now includes `broadcast.read`, and Read and write permission now includes `broadcast.write`.
+ - **Approve Chat join requests:** [Adding a user to a Chat group](/x-api/chat/add-members-to-a-chat-group-conversation) who has a pending join request now approves that request. Use the same key-rotation body you use to add any member.
+ - **Livestream API access:** The Livestream API is available to approved (whitelisted) apps and no longer requires an Enterprise plan. Request access with the [Livestream API Access Form](/forms/livestream-api-access).
+
+ ### Bug fixes
+
+ - **Batch compliance upload limit:** The correct upload limit is **128 MB** (about 6.5 million IDs). Larger uploads return `413`. See [Uploads](/x-api/compliance/batch-compliance/integrate#uploads).
+ - **`source` removed from `tweet.fields`:** The deprecated `source` field is no longer listed as an available [Post field](/x-api/posts/lookup/integrate#available-fields), matching its removal from X API v2.
+
+
### Migrate OAuth 1.0a user tokens to OAuth 2.0 with token exchange