Baselayer replaced GET /autocomplete with a session based Autocomplete API: the backend mints a short lived session with POST /autocomplete/sessions and the browser calls GET /autocomplete/businesses on each keystroke, so the API key never reaches the client. Each suggestion now describes a canonical business with its officers, registered agents, addresses and liens, and carries a token valid for 15 minutes that is redeemed as business_token on POST /searches. A JavaScript/TypeScript SDK with a ready made typeahead component handles session refresh and retries, and the old route was set to stop working on 25 September.
Our readOnboarding flows that use business typeahead had one day of notice to migrate, and the new token ties the KYB search to exactly the business the applicant picked, which cuts mismatched entity searches. Keeping the API key server side also removes a credential exposure risk in client side integrations.