Changelog: October 2026

Changes to the API and to this documentation published in October 2026, newest first.

2026-10-04 – 1.63.0, client tokens: scan from an app without the key

POST /v1/client-tokens issues a short-lived token with an API key. A browser or a mobile app sends POST /v1/scans with that token, so the key stays on your server. A token lives 300 seconds and allows one scan request by default, up to 900 seconds and 10 requests. It can call nothing but POST /v1/scans, its scans are billed and stored exactly as the issuing key's, a sandbox key issues sandbox tokens, and revoking or deleting the key ends its tokens.

Three error codes come with it: 401 client_token_expired, 401 client_token_used_up and 403 client_token_not_allowed. Read a passport in an Ionic app gains a second option built on it.

A POST sent with no body at all is now refused with 400 invalid_request instead of 500 internal_error.