Skip to content
Tech Dev Notes
Apps

Every tracked app, its developer, and a lookup for any other app.

  • App directoryTracked apps on iOS and Android, by category
  • Find any appLive App Store and Google Play lookup
  • DevelopersPublishers and their apps
  • Compare appsHead to head ratings, ranks, versions
Charts

Live store charts, tracked app standings, and this week's movers.

  • App Store chartsLive top free, paid, grossing on iPhone
  • Google Play chartsLive top charts on Android
  • Tracked rankingsTracked apps across markets
  • MoversBiggest rises and drops this week
Screens

Real in-app screens, store listing screenshots, and launcher icons.

  • In-app screensReal-device iOS and Android UI
  • Store screenshotsApp Store and Google Play listings
  • App iconsAdaptive, monochrome, themed
Tech stacks

SDKs, frameworks and APIs detected in shipped app builds.

  • Tech stacks by appAnalyzed iOS and Android builds
  • TechnologiesEvery detected SDK and framework
AI tools

Changelogs for Claude Code, Codex, Cursor, Grok and more.

  • AI tool releasesLatest versions across tools
Notes

Articles and xAI side projects.

  • BlogArticles and guides
  • X feature flagsFeature switches in X web
  • Grok companionsAni, Mika, Rudi, Valentine
  • GrokipediaRandom article and index
Apps
  • App directory
  • Find any app
  • Developers
  • Compare apps
Charts
  • App Store charts
  • Google Play charts
  • Tracked rankings
  • Movers
Screens and icons
  • In-app screens
  • Store screenshots
  • App icons
Tech stacks
  • Tech stacks by app
  • Technologies
AI tool releases
  • AI tool releases
Notes
  • Blog
  • X feature flags
  • Grok companions
  • Grokipedia

Tech Dev Notes © 2026

RSSAboutPublic APIStatusSecurityPrivacyTermsSite map@techdevnotes
X Docs

· Docs

X Docs

September 23, 2026 at 2:40 AM UTC

Added a full guide for migrating stored OAuth 1.0a user access tokens to OAuth 2.0 without re-consent. Covers prerequisites, the exchange request (grant_type=urn:ietf:params:oauth:grant-type:token-exchange on POST /2/oauth2/token), permi…

Changelog

Fundamentals — Authentication

New: OAuth 1.0a → OAuth 2.0 token exchange (/fundamentals/authentication/oauth-2-0/oauth-1-0a-token-exchange)

Added a full guide for migrating stored OAuth 1.0a user access tokens to OAuth 2.0 without re-consent. Covers prerequisites, the exchange request (grant_type=urn:ietf:params:oauth:grant-type:token-exchange on POST /2/oauth2/token), permission-to-scope mapping, success responses, retries/rotation, rate limits, errors, and FAQ.

Related updates:

  • OAuth 2.0 authorization code — grant types now include token exchange (RFC 8693) for existing OAuth 1.0a users.
  • OAuth 1.0a overview — tip pointing apps with existing OAuth 1.0a users to the migration guide.

X API v2 — Webhooks

Introduction (/x-api/webhooks/introduction)

Documented dual signature headers for webhook POSTs:

  • X-Twitter-Webhooks-Signature-OAuth2 (OAuth 2.0 client secret) — recommended
  • X-Twitter-Webhooks-Signature (OAuth 1.0 consumer secret) — legacy, still supported

CRC response_token generation follows the same secret rules. Clarified that the OAuth 2.0 App Only Bearer Token is not used for CRC or signature verification. Prerequisites now list OAuth 2.0 client secret (recommended) or OAuth 1.0 consumer secret.

Quickstart (/x-api/webhooks/quickstart)

CRC and signature examples updated to prefer the OAuth 2.0 client secret, with OAuth 1.0 consumer secret still valid for existing integrations. Added pseudocode, dual-header verification (prefer OAuth2, optional legacy fallback), constant-time comparison guidance, and refreshed Python/JavaScript/Flask samples.

X API v2 — Activity

Introduction (/x-api/activity/introduction)

New Subscription expiration section:

  • Optional expires_at (RFC 3339) on create; XAA deletes the subscription when it elapses
  • Without expires_at, subscriptions remain until explicit DELETE /2/activity/subscriptions/:id or user OAuth revoke
  • Refresh expiration by POSTing the same subscription again with a new expires_at (PUT updates tag/webhook_id only, not expiration)

Event payloads (/x-api/activity/event-payloads)

broadcast.chat payload now includes is_moderator. Docs note the broadcast owner is reported as is_moderator: false in their own broadcast.

Changelog

/changelog — Sep 21, 2026 entry for OAuth 1.0a → OAuth 2.0 token exchange via POST /2/oauth2/token, with link to the new migration guide.

Older release← Sep 22, 03:03 UTCNewer release→ Sep 24, 02:39 UTC
All X Docs releases →