Tickets API — Recent Changes

Customer-relevant changes to Tickets API endpoints and schemas from the past 6 months. Dates below are when each change was committed, not necessarily when it reached production — release to production may lag as it rolls through our int → uat → production pipeline.

DateVersionTypeChange
2026-09-151.29.0AddedAdded an optional tenant_code query parameter so a partner organization can call this API on behalf of a tenant it directly manages.
2026-09-141.28.0FixedCorrected the case state field description: Resolved cases can still be updated via PATCH and remain Resolved afterward -- only Closed and Cancelled cases can no longer be updated.
2026-09-141.28.0AddedAdded PATCH /v2/cases/{ticket_id} to update a case using the v2 schema, returning finding_details instead of threat_details.
2026-09-141.28.0DeprecatedPATCH /cases/{ticket_id} is deprecated; use PATCH /v2/cases/{ticket_id} instead.
2026-09-011.27.0FixedCorrected several Ticket/Contact/Comment/Email schema field descriptions, enum-value documentation, and deprecation cross-references to match actual API behavior.
2026-08-311.26.0AddedDocumented OAuth 2.0 client-credentials authentication as an additional supported auth method alongside the existing API key.
2026-08-311.26.0DeprecatedThe v1 case-detail, comments, and emails endpoints (GET /cases/{ticket_id}, /comments, /emails) are no longer documented in the public API reference; use their /v2/cases/{ticket_id} equivalents instead.
2026-08-311.26.0ChangedAPI documentation renamed from "Tickets Plugin API" to "Tickets API".
2026-08-211.26.0RemovedRemoved the finding_details.notification field from the v2 case schema.
2026-08-211.26.0ChangedClarified how detection_source, sensor_name, summary/description, and other alert/finding-derived fields are populated, including when they may be null or based on stale data.
2026-08-201.26.0AddedAdded GET /v2/cases/{ticket_id} to retrieve a single case using the v2 schema.
2026-08-201.26.0AddedGET /cases and GET /v2/cases now accept page/per_page as an alternative to limit/offset for pagination.
2026-08-201.25.0FixedCorrected threat_details/finding_details field types and nullability, and documented response_actions' actual fields in place of an earlier placeholder shape.
2026-08-171.24.0AddedDocumented the already-returned acknowledged/acknowledged_by fields and added a newly requestable resolution_notes field on the Ticket/TicketV2 schemas.
2026-08-071.23.0Changedthreat_details/finding_details are now included only for Alert-type cases; previously returned for every case type.
2026-08-071.22.0ChangedRestructured the v2 finding_details schema field names (summary, name, related_entities, event_created replacing activity_description, description, entities, alerted_at) and flattened its shape.
2026-08-071.22.0ChangedRenamed alert-details schemas: the v1 shape is now AlertDetails (previously FindingAlertDetails), and the v2 shape is now FindingAlertDetails (previously FindingAlertDetailsV2).
2026-08-071.22.0AddedAdded threat_details.investigation_id field.
2026-07-151.21.0AddedAdded GET /all_case_type_configs, returning every customer-visible case type configuration.
2026-07-151.20.0Deprecatedcase_source in case-creation requests is now deprecated; the field is still accepted but any supplied value is ignored.
2026-07-081.20.0RemovedRemoved the case_sub_subtype field from the Ticket/TicketV2 schemas.

← Back to Tickets API docs