Skip to main content
Notable changes per release. For the full commit-level history, see the GitHub releases.
October 9, 2026
Fixes
  • The docs page escapes the spec URL in its inline script. A specEndpoint value with </script> can no longer close the script tag. The UI configuration values now also escape >, &, U+2028 and U+2029.
October 8, 2026
Fixes
  • The package entry points point to dist again. 0.2.1 was published with entry points that point to src, which is not in the package, so it cannot be imported. Use 0.2.2 instead.
October 8, 2026
Fixes
  • POST /api/<slug>/unlock is documented for every auth collection, as Payload mounts it.
  • Login, forgot-password and unlock bodies follow loginWithUsername: email by default, username when email login is off, email or username with allowEmailLogin.
  • OpenAPI 3.0 output is valid with an empty required list and with fields that allow several types, such as json fields. 3.0 and 3.1 output no longer keep the 3.2 tag fields summary, kind and parent.
  • The internal payload-kv and payload-query-presets collections are hidden unless includeSystem is on.
  • Create, update, delete and duplicate list the query params Payload reads for them, and the global update too. Bulk update also lists limit and sort. Write operations list autosave, publishAllLocales, unpublishAllLocales, overrideLock and selectedLocales[] where Payload reads them.
  • Collection create is documented with status 201. The global update response is { message, result } and a restored global version is { doc, message }.
  • Relationships and uploads inside groups, named tabs, arrays and blocks are written as IDs in create and update bodies. A polymorphic relationship is written as { relationTo, value }, and an optional relationship accepts null.
July 13, 2026
New features
  • Per-operation security marking derived from your access functions: each operation is probed as an anonymous request and marked public or secured accordingly.
  • Overrides for the detected marking: custom.openapi.security per collection or global, and the securityWhen option across the whole document.
June 14, 2026
Initial release.