Kensho released version 8.0.0 of kfinance, the Python library and proxy MCP server for the Kensho LLM ready API. The OAuth refresh token is now sent to /oauth2/refresh in a POST body instead of the URL query string, so it no longer appears in access logs or request logs, and the library replaces the requests and httpx clients with httpx2, which changes the exception types raised for HTTP and network errors.
Our readFirms pulling S&P Global data into AI workflows through kfinance or the proxy MCP server stop exposing long lived credentials in logs by upgrading. It is a breaking change, so engineering teams must update error handling and make any custom AUTH_REFRESH_URL accept POST before upgrading.