
Hello Codecks people! 👋
Over the last few years we’ve stretched Codecks to cover more and more ground, from community management to vision boards to complex sprint management, and plenty more.
Now we’re turning some of that energy inward. That means polishing what’s there, sharpening the rough edges, and prioritising the quality-of-life stuff you’ve been asking us for.
This release is a big step in that direction. We overhauled our API, which had been in a wonky state for years, and shipped a stack of QoL improvements straight from your requests. Plenty more where that came from, expect your everyday Codecks to keep getting smoother, snappier, and more intuitive in the releases ahead.

API & Integrations
Our old API solution was quite limited and dependent on fishing into your cookies to extract the access token and offered no rights management. No more! Codecks now offers a full blown API token system so that you can manage your access in a better way. Wire Codecks into Zapier or n8n, build your own Discord or Slack bot, or feed your cards to an AI assistant: it’s all straightforward now. We also made our other integrations more secure while we were at it.
- Organization API tokens: owners and admins can create tokens under Organization Settings → Integrations → API Tokens. Each token has a permission tier (Admin, Producer, Read, Read & write) and a set of projects it may touch.
- Personal API tokens: no more sharing one all-powerful token across the team. Create tokens that act as you under Your Profile → API Tokens, each limited to a role below your tier or even read-only, and revoke a single one without affecting anyone else. Organizations can turn personal tokens off entirely.
- We’re retiring the old browser-login credential. The
X-Auth-Token header is deprecated and stops working on 2026-12-31, and you can no longer pass the token as an ?auth-token= URL parameter at all. Please move your scripts to an API token before then.
- Graph API: if you build against our API, you know the pain of a query failing with an opaque server error and no hint why. Now a malformed query returns a
400 that tells you the error code, a message, and exactly where in the query it broke (all documented in the manual). count and exist queries also work on fkAsArray relations now.
- Your GitHub, GitLab, Bitbucket and Slack webhooks are now verified, so nobody can spoof events into your board. You can list and remove your GitLab and Bitbucket webhook urls yourself, each comes with its own secret, and existing GitHub hooks are migrated automatically.
- Discord: clearer error message when the Decky bot lost access to a server.
Two-Factor Authentication
We’ve improved the security for your access and since security should be important to everybody we’re making it available for all plans as well as free users.
- Added a new Security tab in Your Profile (replacing the Password tab) where you can add passkeys or hardware security keys as a second factor.
- Adding the first key turns two-factor authentication on, generates 8 recovery codes and logs out all other sessions. Recovery codes can be regenerated.
- Login, password reset and email verification ask for the security key (or a recovery code) when two-factor authentication is on.
- Sensitive actions like adding or deleting a key ask you to confirm it’s you (via password, security key, or Google/Discord login).
Journeys
We know you love our unique journeys feature. We implement a few more quality of life features for these.
- No more jumping up to the hero card first. You can now apply a journey right from any sub card where you’re already working.
- Journey steps can use
%PARENT_TITLE% in their content, replaced with the Hero Card’s title when the journey is applied. So a step titled “Design the level for %PARENT_TITLE%” becomes “Design the level for Boss Fight” automatically.
- You can Shift-click to select a range of journey steps in the journey editor.
- Added a tag selection menu when having multiple journey steps selected.
- Fixed “Create Dependency Chain” linking steps in the wrong order.
- Fixed journey step dependencies getting dropped when picking a target deck for a step.
Improvements & Bug Fixes
And that’s not all. Here are more improvements and fixes.
- Ever excluded both “done” and “in review” cards from a search and still saw some? That’s fixed: excluding two statuses in the same category now correctly hides both, and it just works, nothing new to configure. You can also open any result in a new tab with Ctrl/Cmd-click or Ctrl/Cmd-Return.
- Conversations can now be snoozed “Forever”. Until now a snooze would bump the thread back to you at least every two weeks. “Forever” is for the conversations where those reminders just aren’t useful anymore, so use it wisely. A new reply from someone else still brings the thread back. We also gave closed conversations and comment previews a fresh look.
- You can now pick between a 24-hour and a 12-hour (am/pm) time format in your profile settings.
- Hand overlay: use “Add team member” to add a lane for a teammate and see their hand.
- Run Configs: define a custom default label for Runs using
%RUN_NR% and %CALENDAR_WEEK% placeholders.
- New keyboard shortcut
Shift + V toggles between table view and mini card view.
- CSV importer now supports importing tags. Migrating from another tool or a spreadsheet? Your existing tags come across, and any it doesn’t recognise are created as project tags automatically.
- Export cards: added a “Card link” option.
- Checkboxes in a card got a new look and behaviour. We also fixed a race condition where quickly toggling several would revert earlier toggles.
- Text Editor: the mention picker no longer shows stale suggestions after switching cards or projects.
- Denied actions now show an inline message instead of sending you to a “forbidden” page.
- Timeline: prevent accidental text selection when panning.
- Fixed re-enabled observers gaining access to all open projects instead of just the ones they are listed in.
- Cards that were force-synced into someone’s hand can now be discarded by other people too.
- Fixed cloning projects with attached files.