Fundamentals — Authentication
New: OAuth 1.0a → OAuth 2.0 token exchange (/fundamentals/authentication/oauth-2-0/oauth-1-0a-token-exchange)
Added a full guide for migrating stored OAuth 1.0a user access tokens to OAuth 2.0 without re-consent. Covers prerequisites, the exchange request (grant_type=urn:ietf:params:oauth:grant-type:token-exchange on POST /2/oauth2/token), permission-to-scope mapping, success responses, retries/rotation, rate limits, errors, and FAQ.
Related updates:
OAuth 2.0 authorization code— grant types now include token exchange (RFC 8693) for existing OAuth 1.0a users.OAuth 1.0a overview— tip pointing apps with existing OAuth 1.0a users to the migration guide.
X API v2 — Webhooks
Introduction (/x-api/webhooks/introduction)
Documented dual signature headers for webhook POSTs:
X-Twitter-Webhooks-Signature-OAuth2(OAuth 2.0 client secret) — recommendedX-Twitter-Webhooks-Signature(OAuth 1.0 consumer secret) — legacy, still supported
CRC response_token generation follows the same secret rules. Clarified that the OAuth 2.0 App Only Bearer Token is not used for CRC or signature verification. Prerequisites now list OAuth 2.0 client secret (recommended) or OAuth 1.0 consumer secret.
Quickstart (/x-api/webhooks/quickstart)
CRC and signature examples updated to prefer the OAuth 2.0 client secret, with OAuth 1.0 consumer secret still valid for existing integrations. Added pseudocode, dual-header verification (prefer OAuth2, optional legacy fallback), constant-time comparison guidance, and refreshed Python/JavaScript/Flask samples.
X API v2 — Activity
Introduction (/x-api/activity/introduction)
New Subscription expiration section:
- Optional
expires_at(RFC 3339) on create; XAA deletes the subscription when it elapses - Without
expires_at, subscriptions remain until explicitDELETE /2/activity/subscriptions/:idor user OAuth revoke - Refresh expiration by POSTing the same subscription again with a new
expires_at(PUTupdatestag/webhook_idonly, not expiration)
Event payloads (/x-api/activity/event-payloads)
broadcast.chat payload now includes is_moderator. Docs note the broadcast owner is reported as is_moderator: false in their own broadcast.
Changelog
/changelog — Sep 21, 2026 entry for OAuth 1.0a → OAuth 2.0 token exchange via POST /2/oauth2/token, with link to the new migration guide.