Potential Breaking Change: Upcoming Changes to View-Based API Update Behavior (API)
Heads up: Starting October 7, 2026, view-based API requests will be required to follow the editing settings configured in your app.
This change affects how the Knack API authorizes update requests made through a view.
What’s Changing
Views must be configured for editing. Requests that update a record through a view will only succeed when that view allows editing, such as a Form view or a view with inline editing turned on. Views set up for display only will reject update requests with a 400 error.
Field-level edit settings will be enforced. If a field is set as not editable in a view, requests through that view can no longer update that field, even when other fields in the view are editable. The view will also no longer return editing options for that field, such as available choices for a connection field.
Who May Be Affected
Most apps won’t be affected. You may need to take action if you have custom code, an external integration, or an automated workflow that updates records through a view and either:
-
Sends updates to a view that is set up for display only, or
-
Writes to a field that is set as not editable in that view.
What To Do
If you rely on either pattern, update your setup to use one of these supported options:
-
Make the view or field editable, if users should be able to change it
-
Send the update through a Form view that includes the field (this can be a form hidden from users)
-
Use object-based API requests for secure server-side integrations
Potential Breaking Change: Improved Security for Filtered Connection Pickers (API)
Also arriving in week 41 (October 7, 2026): significant security improvements to connection field lookups.
Specifically, the undocumented endpoint GET /v1/scenes/scene_NN/views/view_NN/connections/field_NN is changing substantially. If you have a custom integration or process that uses this endpoint, we recommend migrating to a view-based API call to a table or search view that has access to the desired data. Documentation for view-based GET requests can be found here.
This change only affects the shape of the payload sent to Knack. The shape of the response from this endpoint does not change. Any code that reads the result of a connection picker lookup is not affected.
New: Restrict POST for View-Based API (Settings → Security)
New: A new security setting is coming in week 41 (October 7, 2026) under Settings → Security that controls whether new records can be created through views designed for editing, such as Edit Record forms and search views with inline editing enabled.
Toggle Restrict POST for View-based API on or off to control whether your edit-intended views can be used to create new records via the API.
Built-In Rules
Behavior varies depending on when your app or account was created:
-
Existing apps: The setting defaults to OFF, so there is no change to your app’s current behavior. You can enable it at any time.
-
New apps: The setting defaults to ON, blocking record creation through edit-intended views out of the box.
-
New accounts after Oct 7: The restriction is always enforced and no toggle is available.
This setting gives you more control over how your app’s API behaves, helping prevent unintended record creation through views that weren’t designed for it.