Improved multipart forms and better security This release brings cleaner multipart form handling, better deep-linking from API Reference, and hardened security across the board. Nested object properties in multipart forms now expand into individual editable rows and serialize as clean JSON parts Opening the client from API Reference now lands you directly on the selected operation Response previews are now protected against XSS and referrer leakage Pre-request and post-response scripts run in an isolated sandbox, removing unsafe-eval from the main app Web client now defaults to proxy.scalar.co