- OAuth apps can now be marked as confidential, requiring both Client ID and Client Secret for token requests (except implicit grant flow).
- Manage confidentiality status from the Applications page in the user profile.
- Applies to Web App and Content Management API, enhancing security for custom integrations.
