Changelog2025

New Applications No Longer Support `oidcLogin`

New applications should no longer use the oidcLogin endpoint to authenticate. This marks the beginning of a gradual deprecation of our legacy User API Key login flow, which uses OpenID Connect to exchange the resulting id_token to generate a BambooHR API key. While existing applications may continue using oidcLogin (with the required legacy.login scope), we strongly recommend reviewing your implementation and planning a full transition to OAuth 2.0 access tokens. This change improves overall security and aligns with industry standards for authorization and authentication.