From 659adc95507fef81221fc3a3c9d1d58da4083c1b Mon Sep 17 00:00:00 2001
From: "mintlify[bot]" <109931778+mintlify[bot]@users.noreply.github.com>
Date: Thu, 24 Sep 2026 17:09:00 +0000
Subject: [PATCH] docs: add Sep 24, 2026 changelog entry
---
changelog.mdx | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/changelog.mdx b/changelog.mdx
index 47c1347f0..66c590388 100644
--- a/changelog.mdx
+++ b/changelog.mdx
@@ -7,6 +7,23 @@ keywords: ["changelog", "API updates", "release notes", "what's new", "API chang
To subscribe to updates, please [**“Turn on notifications”**](https://help.x.com/en/managing-your-account/notifications-on-mobile-devices#:~:text=In%20the%20top%20menu,%20you,you%20would%20like%20to%20receive) for [**@API**](https://x.com/api). You can also follow this changelog in your feed reader via the [**RSS feed**](https://docs.x.com/changelog/rss.xml).
+
+ ### New features
+
+ - **OAuth 2.0 webhook signatures.** Webhook POSTs now carry an `X-Twitter-Webhooks-Signature-OAuth2` header signed with your app's OAuth 2.0 client secret. You can also compute CRC responses with the client secret. The legacy `X-Twitter-Webhooks-Signature` header and OAuth 1.0 consumer secret keep working. See [Webhook security](/x-api/webhooks/introduction#signature-headers) and the [webhooks quickstart](/x-api/webhooks/quickstart).
+ - **Expiring X Activity API subscriptions.** Pass an optional `expires_at` timestamp when you create a subscription, and X deletes it automatically at that time. To change the expiration, send the same subscription again with a new `expires_at`. See [Subscription expiration](/x-api/activity/introduction#subscription-expiration).
+
+ ### Updates
+
+ - **Moderator flag on broadcast chat events.** `broadcast.chat` payloads now include an `is_moderator` boolean. See [event payloads](/x-api/activity/event-payloads).
+ - **Broadcast scopes in token exchange.** [OAuth 1.0a to OAuth 2.0 token exchange](/fundamentals/authentication/oauth-2-0/oauth-1-0a-token-exchange) now grants `broadcast.read` for Read apps and `broadcast.read` plus `broadcast.write` for Read and write apps.
+ - **Livestream API access.** Livestream API endpoints are now available by allowlist. To request access, fill out the [contact form](/forms/enterprise-api-interest). See the [Livestream API](/livestream-api/introduction).
+
+ ### Bug fixes
+
+ - **Removed `source` from `tweet.fields`.** The OpenAPI spec no longer lists the deprecated `source` field, which X API v2 does not return. Field pickers in tools such as Postman no longer offer it. See [Post lookup fields](/x-api/posts/lookup/integrate).
+
+
### Migrate OAuth 1.0a user tokens to OAuth 2.0 with token exchange