# Changelog

## Unreleased (staged)

- Keys accepted in the `X-API-Key` header and as `Authorization: Bearer`; `?api_key=` unchanged.
- Every error body carries `error.code` / `error.message` / `error.docs_url` next to the legacy `message`.
- Per-minute limits are now counted per account (previously clients of a plan could share one counter).
- `429` responses for the per-minute limit include `Retry-After`.
- OpenAPI 3.1 description published at `/openapi.json`; this documentation at `/developers/`; API section in `/llms.txt`.

## Planned

- Real HTTP statuses for errors (`401/403/404/400/405/429/500`) after a 30-day notice here and by email to API customers.
- `Deprecation` header on responses to the `?api_key=` form (the form itself stays).
- Remote MCP server.