<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Motorical: latest changes</title>
        <link>https://docs.motorical.com/changelog</link>
        <description>What changed in the Motorical API, dashboard and documentation.</description>
        <lastBuildDate>Sun, 04 Oct 2026 11:49:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <copyright>Copyright © 2026 Motorical.</copyright>
        <item>
            <title><![CDATA[Backup codes: regenerate any time, and they survive adding an authenticator]]></title>
            <link>https://docs.motorical.com/changelog/backup-codes</link>
            <guid>https://docs.motorical.com/changelog/backup-codes</guid>
            <pubDate>Sun, 04 Oct 2026 11:49:00 GMT</pubDate>
            <description><![CDATA[One set of backup codes covers every way you sign in, whether you use a passkey, an authenticator app, or both.]]></description>
            <content:encoded><![CDATA[<p>One set of backup codes covers every way you sign in, whether you use a passkey, an authenticator app, or both.</p>
<ul>
<li class=""><strong>Regenerate backup codes</strong> is now available in <strong>Settings → Security</strong>, including for accounts that only use a passkey. Replacing the set invalidates the old codes immediately and needs a fresh confirmation from you.</li>
<li class=""><strong>Adding an authenticator app no longer replaces your codes.</strong> If your account already has backup codes, they stay valid and the setup screen says so. Before this change, enabling an authenticator app generated a new set and silently invalidated the one you had saved.</li>
</ul>]]></content:encoded>
            <category>dashboard</category>
            <category>security</category>
        </item>
        <item>
            <title><![CDATA[One password rule everywhere]]></title>
            <link>https://docs.motorical.com/changelog/one-password-rule</link>
            <guid>https://docs.motorical.com/changelog/one-password-rule</guid>
            <pubDate>Sun, 04 Oct 2026 11:48:00 GMT</pubDate>
            <description><![CDATA[Every place that sets a password now applies the same rule: at least 8 characters, including a lowercase letter, an uppercase letter and a number. A symbol is welcome but does not replace a number.]]></description>
            <content:encoded><![CDATA[<p>Every place that sets a password now applies the same rule: <strong>at least 8 characters, including a lowercase letter, an uppercase letter and a number.</strong> A symbol is welcome but does not replace a number.</p>
<ul>
<li class="">The sign-up, set-password, reset-password and change-password forms all check the rule before you submit, so a password the server would refuse can no longer look acceptable.</li>
<li class="">The API returns a single message for every violation: <em>"Password must be at least 8 characters and include a lowercase letter, an uppercase letter and a number"</em>.</li>
<li class="">If setting the password fails after your verification code was accepted, you can retry without requesting a new code.</li>
<li class="">The sign-up password form now includes your email as the username, so your browser's save-password prompt stores a complete login.</li>
</ul>]]></content:encoded>
            <category>api</category>
            <category>dashboard</category>
            <category>authentication</category>
        </item>
        <item>
            <title><![CDATA[Sign-in: passkey first, codes as a deliberate second choice]]></title>
            <link>https://docs.motorical.com/changelog/passkey-first-sign-in</link>
            <guid>https://docs.motorical.com/changelog/passkey-first-sign-in</guid>
            <pubDate>Sun, 04 Oct 2026 10:58:00 GMT</pubDate>
            <description><![CDATA[If your account has both a passkey and an authenticator app, signing in now offers the passkey first. Your browser's passkey prompt opens by itself; if you dismiss it you can try again, or choose Use a code instead to enter an authenticator or backup code.]]></description>
            <content:encoded><![CDATA[<p>If your account has both a passkey and an authenticator app, signing in now offers the <strong>passkey first</strong>. Your browser's passkey prompt opens by itself; if you dismiss it you can try again, or choose <strong>Use a code instead</strong> to enter an authenticator or backup code.</p>
<ul>
<li class=""><strong>Passkey only:</strong> the code box asks for a backup code, and says why.</li>
<li class=""><strong>Authenticator app only:</strong> nothing changes.</li>
<li class=""><strong>Settings → Security:</strong> you can now <strong>rename</strong> a passkey, so you can tell your devices apart.</li>
</ul>
<p>Also fixed: signing out after the page had been idle for a while could leave you signed in. Logout now ends the session reliably.</p>]]></content:encoded>
            <category>dashboard</category>
            <category>security</category>
        </item>
        <item>
            <title><![CDATA[Email signup: verify-code now returns a setupToken]]></title>
            <link>https://docs.motorical.com/changelog/signup-setup-token</link>
            <guid>https://docs.motorical.com/changelog/signup-setup-token</guid>
            <pubDate>Sun, 04 Oct 2026 10:56:00 GMT</pubDate>
            <description><![CDATA[POST /api/auth/verify-code (and the emailed verification link) now returns a single-use setupToken, valid for 30 minutes. It proves that the person setting the password owns the email address.]]></description>
            <content:encoded><![CDATA[<p><code>POST /api/auth/verify-code</code> (and the emailed verification link) now returns a single-use <strong><code>setupToken</code></strong>, valid for 30 minutes. It proves that the person setting the password owns the email address.</p>
<p>Pass it to <code>POST /api/auth/set-password</code> together with the email and password:</p>
<div class="language-json codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-json codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token punctuation" style="color:#393A34">{</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"email"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"you@example.com"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"password"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"&lt;choose one&gt;"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"setupToken"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"&lt;from verify-code&gt;"</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">}</span><br></div></code></pre></div></div>
<p><strong>What you need to do.</strong> If you script or automate signup (agents, CLI-style flows), send the token from the verify step. Today a request without it still succeeds, so nothing breaks yet. We will require it after a notice period, and we will announce the date here.</p>
<p>Accounts that sign in with Google or through the Gluo portal cannot have a password set through this endpoint.</p>
<!-- -->
<p>See <a class="" href="https://docs.motorical.com/api-reference/authentication">Authentication</a> and the <a class="" href="https://docs.motorical.com/ai#developer-sandbox-agent-onboarding">AI agent quickstart</a> for the updated flow. The OpenAPI document and Postman collection already include the new field.</p>]]></content:encoded>
            <category>api</category>
            <category>authentication</category>
        </item>
    </channel>
</rss>