Skip to main content

API late September 2026 security update (1.7.0)

Sam Critchley
Co-Founder

A security-focused API release that follows the mid September 2026 release.

  • Changed (breaking) Two-Factor Authentication (2FA) for admin user login. 2FA on login is now enforced for every request API version, including the default 1.0.0 used when no X-Spaaza-API-Version header is sent. Previously the passcode step only ran for requests with version 1.5.8 or higher, so older or version-less admin logins received a full session immediately and bypassed 2FA. Those clients now receive a session_passcode_key and session_passcode_expiry_date instead of session_info, and must complete the login by posting the emailed passcode to the session endpoint. Admin users with login_2fa_exempt set are unaffected and continue to receive an immediate session. See the versioning page for details.