16 July 2026
All write endpoints: malformed request bodies are rejected
Request bodies used to be accepted silently when they carried fields the API did not recognise, or
the same field twice. Both now fail with 400 Bad Request and a code of InvalidRequestBody. This
is a breaking change to every POST, PUT and PATCH endpoint.
An unknown field, clientIdd for clientId, used to be ignored, so the value you thought you were
setting was quietly dropped. A body containing the same property twice used to keep the last one,
with no way to tell which had been applied. Both are now errors.
Field names are compared case-insensitively for the duplicate check, so clientId and ClientID in
one body is also rejected. Review any payload built by string concatenation, or merged from more than
one source.