Changelog
Phase 2: Web API, tokens and incoming webhooks (October 2026)
Section titled “Phase 2: Web API, tokens and incoming webhooks (October 2026)”First public developer release.
- Private Kits. Workspace admins create a Kit from a manifest (Admin → Connections → Create a private Kit) and install it. Private Kits can request bot scopes, user scopes, incoming webhooks and OAuth redirect URLs. Uploading the same slug with a higher version updates the Kit and its installation.
- Web API v1 at
https://api.ketvia.com/api/v1: auth, conversations, messages (with Blocks andIdempotency-Key), reactions, files, users, runs and installation. See the reference. - Bot tokens (
kbot_…) created on the Kit’s API access page, with rotation (POST /auth/rotate) and immediate revocation. - User tokens (
kusr_…) through thekit.accessflow with PKCE, one-hour lifetime and single-use refresh tokens with reuse detection. - Client secrets (
kcs_…) with a 24-hour overlap on rotation. - Incoming webhooks at
https://hooks.ketvia.com/v1/…. - Cluster-wide rate limits for reads, writes, files and webhooks.
- OpenAPI 3.1 (JSON, YAML) and the manifest JSON Schema, generated from the same contracts the API uses.
- SDK
@ketvia/kitv0 and theci-webhooksample.
Known limits in v1: Kit bots cannot add reactions or upload files (use a user token); interactive Blocks elements are removed from messages.
Coming next
Section titled “Coming next”Events, interactivity, slash commands, assistant tools with approvals, the model data policy, the developer portal, and unlisted and directory distribution.