Changelog: October 2026¶
Changes to the API and to this documentation published in October 2026, newest first.
2026-10-04 – 1.63.0, client tokens: scan from an app without the key¶
POST /v1/client-tokens issues
a short-lived token with an API key. A browser or a mobile app sends
POST /v1/scans with that token, so the key stays on your server. A token
lives 300 seconds and allows one scan request by default, up to 900 seconds and
10 requests. It can call nothing but POST /v1/scans, its scans are billed and
stored exactly as the issuing key's, a sandbox key issues sandbox tokens, and
revoking or deleting the key ends its tokens.
Three error codes come with it: 401
client_token_expired, 401
client_token_used_up and 403
client_token_not_allowed.
Read a passport in an Ionic app
gains a second option built on it.
A POST sent with no body at all is now refused with 400
invalid_request instead of 500 internal_error.