Tickets API — Recent Changes
Customer-relevant changes to Tickets API endpoints and schemas from the past 6 months. Dates below are when each change was committed, not necessarily when it reached production — release to production may lag as it rolls through our int → uat → production pipeline.
| Date | Version | Type | Change |
|---|---|---|---|
| 2026-09-15 | 1.29.0 | Added | Added an optional tenant_code query parameter so a partner organization can call this API on behalf of a tenant it directly manages. |
| 2026-09-14 | 1.28.0 | Fixed | Corrected the case state field description: Resolved cases can still be updated via PATCH and remain Resolved afterward -- only Closed and Cancelled cases can no longer be updated. |
| 2026-09-14 | 1.28.0 | Added | Added PATCH /v2/cases/{ticket_id} to update a case using the v2 schema, returning finding_details instead of threat_details. |
| 2026-09-14 | 1.28.0 | Deprecated | PATCH /cases/{ticket_id} is deprecated; use PATCH /v2/cases/{ticket_id} instead. |
| 2026-09-01 | 1.27.0 | Fixed | Corrected several Ticket/Contact/Comment/Email schema field descriptions, enum-value documentation, and deprecation cross-references to match actual API behavior. |
| 2026-08-31 | 1.26.0 | Added | Documented OAuth 2.0 client-credentials authentication as an additional supported auth method alongside the existing API key. |
| 2026-08-31 | 1.26.0 | Deprecated | The v1 case-detail, comments, and emails endpoints (GET /cases/{ticket_id}, /comments, /emails) are no longer documented in the public API reference; use their /v2/cases/{ticket_id} equivalents instead. |
| 2026-08-31 | 1.26.0 | Changed | API documentation renamed from "Tickets Plugin API" to "Tickets API". |
| 2026-08-21 | 1.26.0 | Removed | Removed the finding_details.notification field from the v2 case schema. |
| 2026-08-21 | 1.26.0 | Changed | Clarified how detection_source, sensor_name, summary/description, and other alert/finding-derived fields are populated, including when they may be null or based on stale data. |
| 2026-08-20 | 1.26.0 | Added | Added GET /v2/cases/{ticket_id} to retrieve a single case using the v2 schema. |
| 2026-08-20 | 1.26.0 | Added | GET /cases and GET /v2/cases now accept page/per_page as an alternative to limit/offset for pagination. |
| 2026-08-20 | 1.25.0 | Fixed | Corrected threat_details/finding_details field types and nullability, and documented response_actions' actual fields in place of an earlier placeholder shape. |
| 2026-08-17 | 1.24.0 | Added | Documented the already-returned acknowledged/acknowledged_by fields and added a newly requestable resolution_notes field on the Ticket/TicketV2 schemas. |
| 2026-08-07 | 1.23.0 | Changed | threat_details/finding_details are now included only for Alert-type cases; previously returned for every case type. |
| 2026-08-07 | 1.22.0 | Changed | Restructured the v2 finding_details schema field names (summary, name, related_entities, event_created replacing activity_description, description, entities, alerted_at) and flattened its shape. |
| 2026-08-07 | 1.22.0 | Changed | Renamed alert-details schemas: the v1 shape is now AlertDetails (previously FindingAlertDetails), and the v2 shape is now FindingAlertDetails (previously FindingAlertDetailsV2). |
| 2026-08-07 | 1.22.0 | Added | Added threat_details.investigation_id field. |
| 2026-07-15 | 1.21.0 | Added | Added GET /all_case_type_configs, returning every customer-visible case type configuration. |
| 2026-07-15 | 1.20.0 | Deprecated | case_source in case-creation requests is now deprecated; the field is still accepted but any supplied value is ignored. |
| 2026-07-08 | 1.20.0 | Removed | Removed the case_sub_subtype field from the Ticket/TicketV2 schemas. |