Changes that affect API clients are listed here, newest first. Additions that do not change existing behaviour (a new optional field, a new endpoint) are listed too, so you can see what became available.
2026-10-03
- Malformed list queries are rejected with
422and a cleardetailinstead of500: a condition without 3 or 4 elements, afilterselement that is neither an array nor an object, a group object with no key or several keys, anAND/ORgroup whose value is not a non-empty array, groups nested deeper than 32 levels, a negativelimit_from, and alimit_tolower thanlimit_from. 429responses of the rate limiter have the body{"detail": "Too many requests"}like every other error (thereasonkey is gone);Retry-Afteris unchanged.- A missing API key scope is answered with
401API key is invalideverywhere. .../getand.../deleteendpoints also accept the id in a JSON body{"id": "<uuid>"}; theentity_idquery parameter still works. Neither, or two different ids, gives422. A body sent to them must be JSON.- New
POST /user_credit/get_selfandPOST /version(GET still works and shares the rate limit);/versionis rate limited on the static tier (1,200 requests a minute). POST /ai_tool/get_allno longer returns hidden or deprecated tools.- New
POST /conversation/count(scopeayeto.conversation, same body as/conversation/find). - Conversation cost (
POST /usage/cost/conversation) is the sum of the credits actually charged, not a repricing at current prices; it includes the text tokens of image models and no longer fails with404for models removed since. - Chat with a model that cannot stream stores the answer and returns it (before, the answer was lost and the response returned the user's message).
- Chat attachments are checked and stored before anything else: an attachment refused
with
422(file is too large, a storage quota, invalid data) no longer leaves the user message behind. Malformed base64 returns422invalid base64 data in attachment '<filename>'(orinvalid data URI in attachment '<filename>') instead of500. Thesizefield of attachments is no longer required and is ignored. - A chat follow-up to a conversation created in an organization runs in that
organization when the request names none (charged there, membership required);
naming a different organization returns
422the conversation belongs to another organization. Another user's conversation is refused with403before any attachment is stored. - The structured chat stream (
runner_version"2") no longer sends the unusediterationfield. - Booster database: creating a record with a key that already exists returns
422a record with key '<key>' already existsinstead of500;limit_fromwithoutlimit_toreturns up to 100 records fromlimit_from(limit_frommust be lower than1000); malformedAND/ORfilters return422instead of500. - Data loader: unsupported file types return
422unsupported file type '<mime>'and are not charged. - Workflows: a file named by its id in the run input stays the user's and is no longer deleted with the run (files sent as base64 still belong to the run).
2026-10-02
- Booster database collection rules apply only to panels in public database mode; in private mode they are ignored. Users a panel is shared with read-only can now write its records and take locks (in both modes).
POST /tts/mp3requires the newayeto.ttsscope andPOST /data-loader/loadthe newayeto.data_loaderscope. Existing API keys were given both scopes; keys created by pairing a desktop client (ayeto.connectoronly) can no longer call these endpoints.POST /tts/mp3andPOST /data-loader/loadaccept an optionalorganization_id: the request runs in the organization and is charged to the user's credit there (admins and members only; guests and non-members get403).POST /tts/mp3returns422withnot enough user credit/not enough organization creditwhen the credit runs out, instead of500Failed to generate audio.- Chat refuses a model switched off by the administrators (requested directly or as the
assistant's model) with
422model is disabled, and an automatic model with no available model with422model is not available;model is deprecatedis returned before the conversation is touched. - Reading another user's conversation with
/conversation/get(refused with404) no longer updates itsaccessedfield. - The
languageheader of an API request no longer changes the user's preferred language in the AYETO app (before, every request saved it, and a request without the header reset it to English). POST /assistant/avatar/getaccepts API keys with the newayeto.assistantscope, which can now be selected when creating a key (it also covers/assistant/find).- New documentation of API v3, replacing the earlier beta notes.
- Workflows are available on the API: reading, running, streaming runs, approvals,
editing, publishing, export and import (
ayeto.workflow,ayeto.workflow.write). - Private booster database API with its own scopes (
ayeto.booster.database,ayeto.booster.database.write).