From 57eecee1de81601c0ad115c6af2cb28701e50f15 Mon Sep 17 00:00:00 2001 From: "mintlify[bot]" <109931778+mintlify[bot]@users.noreply.github.com> Date: Thu, 24 Sep 2026 20:07:06 +0000 Subject: [PATCH] docs: add Sep 24, 2026 changelog entry --- changelog.mdx | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/changelog.mdx b/changelog.mdx index 47c1347f0..6c313ba2f 100644 --- a/changelog.mdx +++ b/changelog.mdx @@ -7,6 +7,33 @@ keywords: ["changelog", "API updates", "release notes", "what's new", "API chang To subscribe to updates, please [**“Turn on notifications”**](https://help.x.com/en/managing-your-account/notifications-on-mobile-devices#:~:text=In%20the%20top%20menu,%20you,you%20would%20like%20to%20receive) for [**@API**](https://x.com/api). You can also follow this changelog in your feed reader via the [**RSS feed**](https://docs.x.com/changelog/rss.xml). + + ## New features + + ### Subscription expiration for X Activity API + + You can now pass an optional `expires_at` (RFC 3339 timestamp) when creating an [X Activity API](/x-api/activity/introduction) subscription. XAA deletes the subscription automatically at that time, so you no longer need to clean it up yourself. + + - To change the expiration, `POST` the same subscription again with a new `expires_at` + - Create, list, and update responses return `expires_at` when it is set + - Omit `expires_at` to keep the subscription active until you delete it + + See [Subscription expiration](/x-api/activity/introduction#subscription-expiration). + + ### OAuth 2.0 client secret for webhook signatures and CRC + + Webhooks can now be secured with your app's OAuth 2.0 client secret. X sends a new `X-Twitter-Webhooks-Signature-OAuth2` header, and you can generate the CRC `response_token` with the same secret. The legacy `X-Twitter-Webhooks-Signature` header (OAuth 1.0 consumer secret) is unchanged. + + See [Signature headers](/x-api/webhooks/introduction#signature-headers) and the [webhooks quickstart](/x-api/webhooks/quickstart). + + ## Updates + + - **`is_moderator` on `broadcast.chat` events:** [`broadcast.chat`](/x-api/activity/event-payloads#broadcast-chat) payloads now include an `is_moderator` boolean for the message author. The broadcast owner is reported as `false` in their own broadcast. + - **Broadcast scopes in OAuth 1.0a token exchange:** [Token exchange](/fundamentals/authentication/oauth-2-0/oauth-1-0a-token-exchange) now grants `broadcast.read` to Read apps and `broadcast.write` to Read and write apps. + - **Livestream API access:** The [Livestream API](/livestream-api/introduction) is now available by whitelist. Request access through the [Livestream API Access Form](/forms/livestream-api-access). + - **`source` Post field removed:** The deprecated `source` value is no longer available in `tweet.fields`. See [Post lookup fields](/x-api/posts/lookup/integrate). + + ### Migrate OAuth 1.0a user tokens to OAuth 2.0 with token exchange