October 9, 2026
Fixes
- The docs page escapes the spec URL in its inline script. A
specEndpointvalue with</script>can no longer close the script tag. The UIconfigurationvalues now also escape>,&, U+2028 and U+2029.
October 8, 2026
Fixes
- The package entry points point to
distagain.0.2.1was published with entry points that point tosrc, which is not in the package, so it cannot be imported. Use0.2.2instead.
October 8, 2026
Fixes
POST /api/<slug>/unlockis documented for every auth collection, as Payload mounts it.- Login, forgot-password and unlock bodies follow
loginWithUsername:emailby default,usernamewhen email login is off,emailorusernamewithallowEmailLogin. - OpenAPI 3.0 output is valid with an empty
requiredlist and with fields that allow several types, such asjsonfields. 3.0 and 3.1 output no longer keep the 3.2 tag fieldssummary,kindandparent. - The internal
payload-kvandpayload-query-presetscollections are hidden unlessincludeSystemis on. - Create, update, delete and duplicate list the query params Payload reads for them, and the global update too. Bulk update also lists
limitandsort. Write operations listautosave,publishAllLocales,unpublishAllLocales,overrideLockandselectedLocales[]where Payload reads them. - Collection create is documented with status
201. The global update response is{ message, result }and a restored global version is{ doc, message }. - Relationships and uploads inside groups, named tabs, arrays and blocks are written as IDs in create and update bodies. A polymorphic relationship is written as
{ relationTo, value }, and an optional relationship acceptsnull.
July 13, 2026
New features
- Per-operation security marking derived from your access functions: each operation is probed as an anonymous request and marked public or secured accordingly.
- Overrides for the detected marking:
custom.openapi.securityper collection or global, and thesecurityWhenoption across the whole document.
June 14, 2026
Initial release.
- OpenAPI 3.0/3.1/3.2 document built from the sanitized Payload config — collections, globals, auth, versions, and jobs.
- Scalar and Swagger UI renderers.
- Custom endpoint and field metadata via
custom.openapi. - Filters, interactive auth, extensions, and caching.
openapi:generateCLI for writing the spec to a file.- UI translations for 44 locales.