Changelog
Developer-facing changes to the API, MCP server, webhooks, plugins and Telegram bots, newest first.
Last updated
Additive changes ship into v1 without notice: new endpoints, fields, events and enum values. Anything that changes existing behaviour is listed here.
3 October 2026#
- New: Telegram bots: instructions, people rules and your own plugins. Bot owners can set instructions (placed after our rules), welcome, help and support text, per-person blocks and daily limits, and switch on their own approved plugins per bot. New endpoints
/v1/telegram/userswith the new scopestelegram.users.readandtelegram.users.write(never inherited by older keys; changes need a live key). New webhookstelegram.end_user.first_seenandtelegram.end_user.blocked. - Fixed: Clearer bot token errors. Connecting a BotFather token now says when Telegram rejected the token, shows Telegram's own message for other errors, and only says it could not reach Telegram when the network actually failed.
- Improved: Developer console rebuilt. New overview, apps, keys, usage, settings, webhooks, plugins and playground screens. The Telegram tab is split into Overview, Behaviour, Access, Users, Limits, Integrations and Danger zone.
2 October 2026#
- New: Bring your own Telegram bot. Paste a BotFather token on your app and your bot runs on the Vidmoat editing agent, billed to you, with per-person and per-bot daily caps, access modes and feature switches. New webhooks
credits.low,credits.exhausted,app.suspendedandtelegram.end_user.limit_reached. See Telegram bots. - Changed: Rate limits fail closed; MCP batches capped. When the rate limiter cannot be reached,
/v1now refuses with503 unavailableandRetry-After: 30instead of letting requests through, and nothing runs or is charged. MCP JSON-RPC batches carry at most 10 messages, and eachtools/callafter the first counts against the limit. - Changed: Account suspension pauses apps. Suspending an account pauses its developer apps and their Telegram bots. A ban also revokes API keys and OAuth grants, and lifting it does not restore them.
- New: run_skill_script MCP tool. Runs a skill's bundled scripts against a project in a sandbox and returns the findings.
30 September 2026#
- Changed: MCP on every plan. Any plan can connect over MCP by signing in from the assistant. Personal API keys and live developer keys still need Studio. Per-tool plan gates and credit costs are unchanged.
- New: Creator Studio tools on MCP.
update_scheduled_post,cancel_scheduled_post,get_creator_overview,get_blueprint,rebuild_blueprintandget_challenges, for Creator Studio subscribers.
29 September 2026#
- Fixed: get_credits reports the next reset.
resetsAtis now the next reset (it was the previous one), andlastResetAtgives the previous one. Render slots are shared fairly so one account cannot hold them all. - Fixed: MCP tool fixes.
inject_html_animationacceptsstart,trackIndex,width,height,nameandclipId, and bad values are refused instead of silently replaced. Six other tool defects were fixed.
18 September 2026#
- New: Editor starter and embeddable player. A downloadable React editor starter with a hosted demo, and
/embed/player, the app compositor in an iframe driven bypostMessage. See video preview. - Improved: Endpoint explorer, MCP and webhook guides. The reference gained a searchable endpoint list, and the MCP and webhooks guides were added.
4 September 2026#
- Changed: Webhooks console moved to the developer portal. Webhook destinations are now managed at developer.vidmoat.com/developer/webhooks. The old address redirects there.
2 September 2026#
- New: Analysis tools on MCP. Twelve analysis tools, including
edit_readiness,analyze_structure,analyze_audio_kind,analyze_quality, dead air, faces and safe zones.
30 August 2026#
- New: Outbound webhooks. Signed POSTs when a render finishes, instead of polling. The signature covers the timestamp and the raw body, the event id stays the same across retries, and only timeouts,
5xx,408and429are retried. The delivery log keeps the receiver's response. See webhooks. - New: Workspaces.
/v1/workspaces,?workspace=on the project list,workspaceIdon create,PUT /v1/projects/{id}/workspace, and the MCP toolslist_workspaces,create_workspaceandmove_project_to_workspace. They use the existing projects scopes.
29 August 2026#
- Fixed: MCP host and list_projects.
api.vidmoat.comis the MCP host, andlist_projectsreturns the projects it was leaving out.
26 August 2026#
- New: report_issue and sample_clip_props.
report_issuelets an agent file a defect;sample_clip_propsreturns the property values the renderer will actually draw. - Fixed: Shared projects in more MCP tools.
preview_frame,preview_strip,bake_clips,get_bake_statusandgenerate_videowork on shared and handed-off projects.
21 August 2026#
- New: preview_strip and bake_clips.
preview_stripreturns up to 12 frames as one labelled contact sheet;bake_clipsflattens a selection of clips into one.
18 August 2026#
- Fixed: MCP 401 points at the authorization server. A
401from MCP carries aWWW-Authenticateheader withresource_metadata(RFC 9728), so clients can find where to sign in.
11 August 2026#
- New: OAuth plugins. Hosted MCP servers that need per-user OAuth can be plugins, with discovery, dynamic client registration and PKCE, or client credentials entered by hand.
- Changed: Marketplace plugins need a paid plan. Using marketplace plugins needs Creator or above. You can always use your own.
10 August 2026#
- New: Plugin platform. Publish an MCP server you host as a plugin. Its tools appear as
slug__toolover MCP and atPOST /v1/plugins/{slug}/{tool}. New scopeplugins.invoke, never inherited by older keys. Private, unlisted or public.
8 August 2026#
- New: Public REST API, v1. One wrapper for authentication, scopes, rate limits and errors on every endpoint. Video is billed per second and failed generations are refunded. Test keys return sample results and never spend credits.
- New: Developer portal and scoped keys. Register an app and mint
vmk_live_andvmk_test_keys with chosen scopes. Test keys are instant; live keys need the app approved in review. Keys minted before scopes keep their full access. - New: Sign in with Vidmoat. OAuth with scoped consent and revocable grants. Third-party access tokens last one hour; refresh tokens last 90 days and rotate.
- New: API playground. Run real
/v1calls from the console and see the results.
20 July 2026#
- New: Dynamic client registration for MCP.
POST /api/oauth/register(RFC 7591) lets any MCP client connect without pre-shared credentials.
16 July 2026#
- New: OAuth for Claude and ChatGPT connectors. PKCE,
client_secret_basicand OAuth discovery, so assistant connectors can sign in.
14 July 2026#
- New: MCP server and API keys. The first
/api/mcpendpoint andvmk_API keys, with tools for importing media, previewing frames, captions and stickers.