API late September 2026 security update (1.7.0)
A security-focused API release that follows the mid September 2026 release.
- Changed (breaking) Two-Factor Authentication (2FA) for admin user login. 2FA on login is now enforced for every request API version, including the default
1.0.0used when noX-Spaaza-API-Versionheader is sent. Previously the passcode step only ran for requests with version1.5.8or higher, so older or version-less admin logins received a full session immediately and bypassed 2FA. Those clients now receive asession_passcode_keyandsession_passcode_expiry_dateinstead ofsession_info, and must complete the login by posting the emailed passcode to the session endpoint. Admin users withlogin_2fa_exemptset are unaffected and continue to receive an immediate session. See the versioning page for details.