- Introduces Enhanced Security Controls for third‑party applications, now generally available.
- Adds strict security mode, mandatory PKCE, explicit API authorization, default permissions, open‑redirect protection, and a curated allowlist to reduce attack surface.
- Existing third‑party apps keep working; a 6‑month migration window and guide are provided for adoption.