What's new in Tender (2026)

Updated 09 Oct, 2026 10:14 AM in Getting Started

If you've used Tender for a while, this page is for you: what changed in 2026, and the few things you need to do. Each item links to the article with the details.

What you need to do

Only if you use the Tender API:

  • Sign in with a personal API token. Logging in to the API with your email and password (HTTP Basic) no longer works. Make a token under Profile › API tokens and send it as Authorization: Bearer <token>. See Authentication.
  • Replace your old API key before 27 September 2027. API keys from your profile page keep working until then (or until the expiry they already had), but you can no longer see or reset them. A personal token is a drop-in replacement: make one, swap it into your scripts, and you're done.
  • Use the Authorization header. The X-Tender-Auth header and the ?auth= parameter still work for now, but new code should send Authorization: Bearer.
  • Use a supporter's token. Only your support staff can use the API. Requests made as a customer get 401 or 403.

Nothing else needs action: everything below is either automatic or optional.

A new look

  • The dashboard has a new design. Menus and pages are where they were.
  • A modern design for your site. New sites start with a responsive design that works on phones. If your site still uses the classic design, write to us and we'll move it over. Your theme comes along: its CSS moves into Settings › Appearance & Text › Custom CSS, where you can edit it, with the classic CSS kept in a comment in case you want it back.
  • Dark mode. Everyone can choose Light, Dark or Automatic (follow the device) under Profile › Appearance. Your site follows the same choice for visitors once you tick Allow dark mode in Settings › Appearance & Text. Leave it off if your custom CSS assumes a light background.
  • Logos and a header banner. Upload your logo, a version for dark mode, and a banner image for the top of your site in Settings › Appearance & Text.

Answering customers

  • Add KB articles to replies. The Add KB button in the reply form finds articles by section or by searching, and can link straight to a heading inside one. Use the keyboard to pick one without leaving the reply.
  • Links to headings. Every heading in a KB article has a # link next to it, so you can share a link to the exact paragraph.
  • Queue and category pickers in the discussion toolbar move a discussion without opening its settings.
  • GitHub repositories per queue or category. Pick which repository a queue's or category's tickets go to, instead of one per site. (Basecamp is no longer offered as a tracker.)
  • Who an email is from. Tender uses the From address to decide who wrote an email. When a message's Reply-To is a different address, staff see both. Quoted text from earlier messages is folded away behind Show quoted content.
  • Emoji in discussions, comments and articles are kept exactly as typed.

Your knowledge base

  • Feedback becomes a conversation. When a reader rates an article and leaves a comment, Tender can start a private discussion from it, in the category and queue you choose, so you can reply. Turn it on in Settings › Knowledge Base Feedback.
  • Spam in KB ratings is caught automatically, and the ratings list has Spam, Not spam and Delete for the rest.

Fighting spam

Tender's spam filter stops a large amount of spam every day. This year's work is about its mistakes: the real messages it hides by accident, and the spam that slips through.

  • Your clicks teach it. Every time someone on your team marks a comment as spam, or restores one the filter hid, Tender now keeps that decision as a label, along with what the filter knew at the time.
  • A new model, learned from those labels. We built a new spam model from comments that support teams specifically marked as spam or restored as real, not from the filter's own guesses. It weighs the words in a message together with how it was sent, and busy sites get a version tuned to their own conversations.
  • Tested on the past before it decides anything. We ran the model against years of past comments whose outcome we already know, and it now scores new comments alongside the current filter, without changing what you see. Once it has proven itself on live traffic, it will start releasing real messages the filter would have hidden, so fewer of your customers' messages need rescuing from the spam folder.

Nothing to set up: keep using Spam and Not spam as you always have, and every click makes the filter better.

Customers and security

  • Activation emails on request. People who sign up on your site get their activation email when they ask for it from the welcome page, rather than automatically. This keeps fake sign-ups from sending email in your name.
  • Large files on public discussions (audio, video, archives and programs) are only available to your support staff, and on a site that requires login, to signed-in members. Images, PDFs and documents work as before.
  • HTTPS on your own domain. If your site uses its own domain (support.yourcompany.com), we can now give it a free certificate. Write to us to set it up.

For developers

  • Personal API tokens with read-only or read-and-write access and an expiry date: Authentication.
  • OAuth 2.1 for apps that act on behalf of your staff, with dynamic client registration and PKCE: OAuth for applications.
  • Connect an AI assistant. Tender works with AI assistants that support MCP, such as Claude: they can read and search your discussions and knowledge base, and draft replies and KB articles as you. It's off until you ask us to turn it on for your site: Connecting an AI assistant (MCP).
  • The whole API reference has been rewritten, with examples you can paste.

Questions about any of this? Start a discussion and we'll help.

More from the knowledge base