{
    "version": "https://jsonfeed.org/version/1",
    "title": "Motorical: latest changes",
    "home_page_url": "https://docs.motorical.com/changelog",
    "description": "What changed in the Motorical API, dashboard and documentation.",
    "items": [
        {
            "id": "https://docs.motorical.com/changelog/backup-codes",
            "content_html": "<p>One set of backup codes covers every way you sign in, whether you use a passkey, an authenticator app, or both.</p>\n<ul>\n<li class=\"\"><strong>Regenerate backup codes</strong> is now available in <strong>Settings → Security</strong>, including for accounts that only use a passkey. Replacing the set invalidates the old codes immediately and needs a fresh confirmation from you.</li>\n<li class=\"\"><strong>Adding an authenticator app no longer replaces your codes.</strong> If your account already has backup codes, they stay valid and the setup screen says so. Before this change, enabling an authenticator app generated a new set and silently invalidated the one you had saved.</li>\n</ul>",
            "url": "https://docs.motorical.com/changelog/backup-codes",
            "title": "Backup codes: regenerate any time, and they survive adding an authenticator",
            "summary": "One set of backup codes covers every way you sign in, whether you use a passkey, an authenticator app, or both.",
            "date_modified": "2026-10-04T11:49:00.000Z",
            "tags": [
                "dashboard",
                "security"
            ]
        },
        {
            "id": "https://docs.motorical.com/changelog/one-password-rule",
            "content_html": "<p>Every place that sets a password now applies the same rule: <strong>at least 8 characters, including a lowercase letter, an uppercase letter and a number.</strong> A symbol is welcome but does not replace a number.</p>\n<ul>\n<li class=\"\">The sign-up, set-password, reset-password and change-password forms all check the rule before you submit, so a password the server would refuse can no longer look acceptable.</li>\n<li class=\"\">The API returns a single message for every violation: <em>\"Password must be at least 8 characters and include a lowercase letter, an uppercase letter and a number\"</em>.</li>\n<li class=\"\">If setting the password fails after your verification code was accepted, you can retry without requesting a new code.</li>\n<li class=\"\">The sign-up password form now includes your email as the username, so your browser's save-password prompt stores a complete login.</li>\n</ul>",
            "url": "https://docs.motorical.com/changelog/one-password-rule",
            "title": "One password rule everywhere",
            "summary": "Every place that sets a password now applies the same rule: at least 8 characters, including a lowercase letter, an uppercase letter and a number. A symbol is welcome but does not replace a number.",
            "date_modified": "2026-10-04T11:48:00.000Z",
            "tags": [
                "api",
                "dashboard",
                "authentication"
            ]
        },
        {
            "id": "https://docs.motorical.com/changelog/passkey-first-sign-in",
            "content_html": "<p>If your account has both a passkey and an authenticator app, signing in now offers the <strong>passkey first</strong>. Your browser's passkey prompt opens by itself; if you dismiss it you can try again, or choose <strong>Use a code instead</strong> to enter an authenticator or backup code.</p>\n<ul>\n<li class=\"\"><strong>Passkey only:</strong> the code box asks for a backup code, and says why.</li>\n<li class=\"\"><strong>Authenticator app only:</strong> nothing changes.</li>\n<li class=\"\"><strong>Settings → Security:</strong> you can now <strong>rename</strong> a passkey, so you can tell your devices apart.</li>\n</ul>\n<p>Also fixed: signing out after the page had been idle for a while could leave you signed in. Logout now ends the session reliably.</p>",
            "url": "https://docs.motorical.com/changelog/passkey-first-sign-in",
            "title": "Sign-in: passkey first, codes as a deliberate second choice",
            "summary": "If your account has both a passkey and an authenticator app, signing in now offers the passkey first. Your browser's passkey prompt opens by itself; if you dismiss it you can try again, or choose Use a code instead to enter an authenticator or backup code.",
            "date_modified": "2026-10-04T10:58:00.000Z",
            "tags": [
                "dashboard",
                "security"
            ]
        },
        {
            "id": "https://docs.motorical.com/changelog/signup-setup-token",
            "content_html": "<p><code>POST /api/auth/verify-code</code> (and the emailed verification link) now returns a single-use <strong><code>setupToken</code></strong>, valid for 30 minutes. It proves that the person setting the password owns the email address.</p>\n<p>Pass it to <code>POST /api/auth/set-password</code> together with the email and password:</p>\n<div class=\"language-json codeBlockContainer_Ckt0 theme-code-block\" style=\"--prism-color:#393A34;--prism-background-color:#f6f8fa\"><div class=\"codeBlockContent_QJqH\"><pre tabindex=\"0\" class=\"prism-code language-json codeBlock_bY9V thin-scrollbar\" style=\"color:#393A34;background-color:#f6f8fa\"><code class=\"codeBlockLines_e6Vv\"><div class=\"token-line\" style=\"color:#393A34\"><span class=\"token punctuation\" style=\"color:#393A34\">{</span><span class=\"token plain\"> </span><span class=\"token property\" style=\"color:#36acaa\">\"email\"</span><span class=\"token operator\" style=\"color:#393A34\">:</span><span class=\"token plain\"> </span><span class=\"token string\" style=\"color:#e3116c\">\"you@example.com\"</span><span class=\"token punctuation\" style=\"color:#393A34\">,</span><span class=\"token plain\"> </span><span class=\"token property\" style=\"color:#36acaa\">\"password\"</span><span class=\"token operator\" style=\"color:#393A34\">:</span><span class=\"token plain\"> </span><span class=\"token string\" style=\"color:#e3116c\">\"&lt;choose one&gt;\"</span><span class=\"token punctuation\" style=\"color:#393A34\">,</span><span class=\"token plain\"> </span><span class=\"token property\" style=\"color:#36acaa\">\"setupToken\"</span><span class=\"token operator\" style=\"color:#393A34\">:</span><span class=\"token plain\"> </span><span class=\"token string\" style=\"color:#e3116c\">\"&lt;from verify-code&gt;\"</span><span class=\"token plain\"> </span><span class=\"token punctuation\" style=\"color:#393A34\">}</span><br></div></code></pre></div></div>\n<p><strong>What you need to do.</strong> If you script or automate signup (agents, CLI-style flows), send the token from the verify step. Today a request without it still succeeds, so nothing breaks yet. We will require it after a notice period, and we will announce the date here.</p>\n<p>Accounts that sign in with Google or through the Gluo portal cannot have a password set through this endpoint.</p>\n<!-- -->\n<p>See <a class=\"\" href=\"https://docs.motorical.com/api-reference/authentication\">Authentication</a> and the <a class=\"\" href=\"https://docs.motorical.com/ai#developer-sandbox-agent-onboarding\">AI agent quickstart</a> for the updated flow. The OpenAPI document and Postman collection already include the new field.</p>",
            "url": "https://docs.motorical.com/changelog/signup-setup-token",
            "title": "Email signup: verify-code now returns a setupToken",
            "summary": "POST /api/auth/verify-code (and the emailed verification link) now returns a single-use setupToken, valid for 30 minutes. It proves that the person setting the password owns the email address.",
            "date_modified": "2026-10-04T10:56:00.000Z",
            "tags": [
                "api",
                "authentication"
            ]
        }
    ]
}