<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <id>https://docs.motorical.com/changelog</id>
    <title>Motorical: latest changes</title>
    <updated>2026-10-04T11:49:00.000Z</updated>
    <generator>https://github.com/jpmonette/feed</generator>
    <link rel="alternate" href="https://docs.motorical.com/changelog"/>
    <subtitle>What changed in the Motorical API, dashboard and documentation.</subtitle>
    <icon>https://docs.motorical.com/img/motorical-app-icon.svg</icon>
    <rights>Copyright © 2026 Motorical.</rights>
    <entry>
        <title type="html"><![CDATA[Backup codes: regenerate any time, and they survive adding an authenticator]]></title>
        <id>https://docs.motorical.com/changelog/backup-codes</id>
        <link href="https://docs.motorical.com/changelog/backup-codes"/>
        <updated>2026-10-04T11:49:00.000Z</updated>
        <summary type="html"><![CDATA[One set of backup codes covers every way you sign in, whether you use a passkey, an authenticator app, or both.]]></summary>
        <content type="html"><![CDATA[<p>One set of backup codes covers every way you sign in, whether you use a passkey, an authenticator app, or both.</p>
<ul>
<li class=""><strong>Regenerate backup codes</strong> is now available in <strong>Settings → Security</strong>, including for accounts that only use a passkey. Replacing the set invalidates the old codes immediately and needs a fresh confirmation from you.</li>
<li class=""><strong>Adding an authenticator app no longer replaces your codes.</strong> If your account already has backup codes, they stay valid and the setup screen says so. Before this change, enabling an authenticator app generated a new set and silently invalidated the one you had saved.</li>
</ul>]]></content>
        <category label="dashboard" term="dashboard"/>
        <category label="security" term="security"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[One password rule everywhere]]></title>
        <id>https://docs.motorical.com/changelog/one-password-rule</id>
        <link href="https://docs.motorical.com/changelog/one-password-rule"/>
        <updated>2026-10-04T11:48:00.000Z</updated>
        <summary type="html"><![CDATA[Every place that sets a password now applies the same rule: at least 8 characters, including a lowercase letter, an uppercase letter and a number. A symbol is welcome but does not replace a number.]]></summary>
        <content type="html"><![CDATA[<p>Every place that sets a password now applies the same rule: <strong>at least 8 characters, including a lowercase letter, an uppercase letter and a number.</strong> A symbol is welcome but does not replace a number.</p>
<ul>
<li class="">The sign-up, set-password, reset-password and change-password forms all check the rule before you submit, so a password the server would refuse can no longer look acceptable.</li>
<li class="">The API returns a single message for every violation: <em>"Password must be at least 8 characters and include a lowercase letter, an uppercase letter and a number"</em>.</li>
<li class="">If setting the password fails after your verification code was accepted, you can retry without requesting a new code.</li>
<li class="">The sign-up password form now includes your email as the username, so your browser's save-password prompt stores a complete login.</li>
</ul>]]></content>
        <category label="api" term="api"/>
        <category label="dashboard" term="dashboard"/>
        <category label="authentication" term="authentication"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Sign-in: passkey first, codes as a deliberate second choice]]></title>
        <id>https://docs.motorical.com/changelog/passkey-first-sign-in</id>
        <link href="https://docs.motorical.com/changelog/passkey-first-sign-in"/>
        <updated>2026-10-04T10:58:00.000Z</updated>
        <summary type="html"><![CDATA[If your account has both a passkey and an authenticator app, signing in now offers the passkey first. Your browser's passkey prompt opens by itself; if you dismiss it you can try again, or choose Use a code instead to enter an authenticator or backup code.]]></summary>
        <content type="html"><![CDATA[<p>If your account has both a passkey and an authenticator app, signing in now offers the <strong>passkey first</strong>. Your browser's passkey prompt opens by itself; if you dismiss it you can try again, or choose <strong>Use a code instead</strong> to enter an authenticator or backup code.</p>
<ul>
<li class=""><strong>Passkey only:</strong> the code box asks for a backup code, and says why.</li>
<li class=""><strong>Authenticator app only:</strong> nothing changes.</li>
<li class=""><strong>Settings → Security:</strong> you can now <strong>rename</strong> a passkey, so you can tell your devices apart.</li>
</ul>
<p>Also fixed: signing out after the page had been idle for a while could leave you signed in. Logout now ends the session reliably.</p>]]></content>
        <category label="dashboard" term="dashboard"/>
        <category label="security" term="security"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Email signup: verify-code now returns a setupToken]]></title>
        <id>https://docs.motorical.com/changelog/signup-setup-token</id>
        <link href="https://docs.motorical.com/changelog/signup-setup-token"/>
        <updated>2026-10-04T10:56:00.000Z</updated>
        <summary type="html"><![CDATA[POST /api/auth/verify-code (and the emailed verification link) now returns a single-use setupToken, valid for 30 minutes. It proves that the person setting the password owns the email address.]]></summary>
        <content type="html"><![CDATA[<p><code>POST /api/auth/verify-code</code> (and the emailed verification link) now returns a single-use <strong><code>setupToken</code></strong>, valid for 30 minutes. It proves that the person setting the password owns the email address.</p>
<p>Pass it to <code>POST /api/auth/set-password</code> together with the email and password:</p>
<div class="language-json codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-json codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token punctuation" style="color:#393A34">{</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"email"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"you@example.com"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"password"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"&lt;choose one&gt;"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"setupToken"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"&lt;from verify-code&gt;"</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">}</span><br></div></code></pre></div></div>
<p><strong>What you need to do.</strong> If you script or automate signup (agents, CLI-style flows), send the token from the verify step. Today a request without it still succeeds, so nothing breaks yet. We will require it after a notice period, and we will announce the date here.</p>
<p>Accounts that sign in with Google or through the Gluo portal cannot have a password set through this endpoint.</p>
<!-- -->
<p>See <a class="" href="https://docs.motorical.com/api-reference/authentication">Authentication</a> and the <a class="" href="https://docs.motorical.com/ai#developer-sandbox-agent-onboarding">AI agent quickstart</a> for the updated flow. The OpenAPI document and Postman collection already include the new field.</p>]]></content>
        <category label="api" term="api"/>
        <category label="authentication" term="authentication"/>
    </entry>
</feed>