Skip to content

Changelog

Phase 2: Web API, tokens and incoming webhooks (October 2026)

Section titled “Phase 2: Web API, tokens and incoming webhooks (October 2026)”

First public developer release.

  • Private Kits. Workspace admins create a Kit from a manifest (Admin → Connections → Create a private Kit) and install it. Private Kits can request bot scopes, user scopes, incoming webhooks and OAuth redirect URLs. Uploading the same slug with a higher version updates the Kit and its installation.
  • Web API v1 at https://api.ketvia.com/api/v1: auth, conversations, messages (with Blocks and Idempotency-Key), reactions, files, users, runs and installation. See the reference.
  • Bot tokens (kbot_…) created on the Kit’s API access page, with rotation (POST /auth/rotate) and immediate revocation.
  • User tokens (kusr_…) through the kit.access flow with PKCE, one-hour lifetime and single-use refresh tokens with reuse detection.
  • Client secrets (kcs_…) with a 24-hour overlap on rotation.
  • Incoming webhooks at https://hooks.ketvia.com/v1/….
  • Cluster-wide rate limits for reads, writes, files and webhooks.
  • OpenAPI 3.1 (JSON, YAML) and the manifest JSON Schema, generated from the same contracts the API uses.
  • SDK @ketvia/kit v0 and the ci-webhook sample.

Known limits in v1: Kit bots cannot add reactions or upload files (use a user token); interactive Blocks elements are removed from messages.

Events, interactivity, slash commands, assistant tools with approvals, the model data policy, the developer portal, and unlisted and directory distribution.