v1.125 Sep 2026
Security: OAuth 2.0 access tokens (client credentials), IP allowlists, key expiry with a reminder email, the OpenAPI 3.1 document, RFC 6750 WWW-Authenticate answers, and stricter requests (credentials only in the Authorization header, JSON bodies only, a per-address limit on failed authentications).