# Changelog: October 2026

Changes to the API and to this documentation published in October 2026, newest first.

## 2026-10-04 – 1.63.0, client tokens: scan from an app without the key

[`POST /v1/client-tokens`](https://doc.cheap/docs/reference/endpoints/create-a-client-token) issues
a short-lived token with an API key. A browser or a mobile app sends
`POST /v1/scans` with that token, so the key stays on your server. A token
lives 300 seconds and allows one scan request by default, up to 900 seconds and
10 requests. It can call nothing but `POST /v1/scans`, its scans are billed and
stored exactly as the issuing key's, a sandbox key issues sandbox tokens, and
revoking or deleting the key ends its tokens.

Three error codes come with it: 401
[`client_token_expired`](https://doc.cheap/docs/errors/client_token_expired), 401
[`client_token_used_up`](https://doc.cheap/docs/errors/client_token_used_up) and 403
[`client_token_not_allowed`](https://doc.cheap/docs/errors/client_token_not_allowed).
[Read a passport in an Ionic app](https://doc.cheap/docs/guides/read-a-passport-in-an-ionic-app)
gains a second option built on it.

A `POST` sent with no body at all is now refused with 400
[`invalid_request`](https://doc.cheap/docs/errors/invalid_request) instead of 500 `internal_error`.
