v1.3 Changelog
Released: October 2026
The "REST API" release: everything you can do in the web app -- from to-dos and L10 meetings to organization and platform administration -- is now available to integrations through a documented REST API with personal API keys.
Highlights
- New REST API at
/api/v1for automation tools such as n8n or Zapier, reporting scripts, and your own apps - Personal API keys in Settings > API keys, with the scopes
read,write, andplatform - Full coverage of the app: team data, organization and team administration, and platform administration
- OpenAPI 3.1 description and an interactive reference at
/api/v1/docs, where you can try calls with your own key - Neutral resource names that read naturally to developers who do not know EOS --
tasks,goals,metrics,vision,org-chart,people-reviews - Scorecard values entered during an L10 meeting now appear in the Scorecard
Features
API Keys
- Every user creates and manages their own keys in Settings > API keys: a name, the access (Read only or Read & write), and the expiry (30 days, 90 days by default, 365 days, or Never).
- The full key is shown only once, right after it is created. EOS Hub stores only a hash of it, so a lost key cannot be shown again -- revoke it and create a new one.
- At most 10 active keys per user; expired and revoked keys do not count and stay in the list for reference.
- The list shows each key's visible beginning, permissions, last use, expiry, and status. Revoking a key stops every integration using it immediately.
- Platform keys: platform operators (
SUPERADMIN) can create keys with theplatformscope for platform administration. They are valid for at most 90 days and are marked with a red Platform badge. - In Platform > Users, the operator sees how many active keys each account has, can open a user's key list (details only, never the key itself), and can revoke a key that may have leaked.
See API Keys.
REST API
- Team data: to-dos, issues, Rocks with their milestones, Scorecard measurables with their weekly values, L10 meetings with ratings, segues, headlines, and cascading messages, the V/TO, the Accountability Chart, People Analyzer entries, and document links -- read and write, with the same rules as the web app.
- Organization administration for organization Owners and Admins: organization settings, members, teams, and team members.
- Platform administration for the platform operator: organizations (create, suspend, resume), accounts, users' API keys, and AI settings. Platform endpoints never return organization data.
- Weekly Scorecard values sent without
onTrackare judged against the measurable's goal. Numbers may use a decimal comma or dot (3,5and3.5), thousands groups, and a trailing%; a value that cannot be judged unambiguously needs an explicitonTrack. - Only managing your own API keys stays in the web app -- a key can never create or revoke keys.
See REST API.
API Conventions
- JSON with
camelCasefield names; the API version is part of the URL (/v1). - Cursor pagination: lists return
dataandnextCursor, withlimitfrom 1 to 200 (default 50). Pages stay stable while items are added or deleted. - Errors use standard HTTP status codes and a JSON body with a machine-readable
code(for exampleforbidden,notFound,orgSuspended,invalid); for format errors the response lists the problems field by field. Every response carries anX-Request-Idheader. - Rate limit: 120 requests per minute per key; above that
429 rateLimitedwith aRetry-Afterheader. - Calendar days -- due dates, meeting days, Scorecard weeks -- are plain
YYYY-MM-DDvalues that never shift between time zones. Instants are ISO 8601 in UTC.
Security
- A key has no permissions of its own: it acts with its owner's current organization and team roles, checked on every request. When someone is removed from an organization or a team, their keys lose access at once. A key's scopes can only narrow those rights.
platformkeys work only while their owner is a platform operator, and the operator's keys get no automatic access to customer data.- The full member list of an organization (
GET /orgs/{orgId}/members) is available to its Owners and Admins only, as in the web app; other members see the members of their own teams. /api/v1accepts only API keys -- a browser session cookie does not work there.- The interactive reference loads a single pinned script file with Subresource Integrity under a strict Content Security Policy.
Fixes
- Scorecard values entered during an L10 meeting now land in the week the Scorecard shows as current in your time zone. Before, they were stored at your browser's local midnight instead of the week the Scorecard uses, so they did not appear in it; existing values are moved by a data migration (see below). Sample data created during onboarding uses the right weeks as well.
- Documents: the Documents & Links page describes what it really does -- the team's shared list of links; EOS Hub does not upload files. The page's texts are translated, and the link buttons have accessible labels.
- V/TO: the page shows unusual stored items as text instead of failing.
Upgrade from v1.2
Back up first
Back up the database before upgrading.
Start the new version. The schema migration
api_keysadds the table for API keys. The Docker entrypoint applies it automatically on start (prisma migrate deploy); no manual step is needed. See Database Migrations.Run the data migration for Scorecard weeks. It moves every stored Scorecard value to the Monday of its week, so values entered during meetings appear in the Scorecard. When several values end up in the same week of a measurable, a value already on that Monday wins, otherwise the most recent one; the others are removed. The script is idempotent -- running it again changes nothing. Run it once from the repository against the application database, for example:
bashdocker compose exec -T postgres psql -U eoshub -d eoshub < scripts/data-migrations/2026-10-scorecard-weeks.sqlor with
psql "$DATABASE_URL" -f scripts/data-migrations/2026-10-scorecard-weeks.sql.
No new environment variables are needed. API keys use the existing database; the REST API is available at https://<your-host>/api/v1 as soon as the new version runs.