Added

30 September 2026

🚀 New APIs

Compliance API

  1. New attestation_validation_status_changed webhook. The event type is sent with the compliance_review category. You no longer need to poll attestation status while attestation validations are running. See the event types reference for more information.

Accounts API

  1. Set a pay-in settlement strategy at account creation. POST /api/accounts takes an optional payinsSettlementStrategies array, USD only for now: [{ "type": "usd", "settlementStrategy": { "type": "holdInFiat" } }]. An unpermitted strategy fails at creation rather than after the account exists.

⭐ Enhancements

Payouts API

  1. Target-amount payout requests now support USD and EUR.
  2. USD payout transfer rail validation. USD payouts and payout methods now check the transfer type. A transferType (ACH or WIRE) that isn't available returns a 400 listing the supported types.
  3. Developer fee percentage validation. The developer's fee percentage is now validated as 0 to 100 on both the payout and withdrawal paths, and the minimum / maximum appear on the field in the OpenAPI spec. A negative percentage previously passed validation and inflated the payout; it now returns 400.
  4. Fee quote endpoints accept on-behalf-of. POST /api/payouts/fees/token-to-fiat and POST /api/payouts/fees/fiat-to-token now honor the on-behalf-of header, so a quote can be taken for a child organization the same way the payout itself is.
  5. Configured Bre-B keys are validated before a payout method is saved and before a payout runs. A Bre-B key is now checked at creation and at payout time instead of failing later in execution. An invalid key returns 400 with the validation message.
  6. USD PAY is advertised for chains reachable by bridging. The currency capabilities an organization reports now list PAY for USD on chains that bridging can reach. If you branch on the advertised operations to decide whether a source chain can pay out in USD, more chains now qualify.
  7. Cross-chain USDT payouts to Tron. A Tron-destination payout can now be routed from another chain. Enabled upon request, reach out to [email protected].

Compliance API

  1. Expanded attestation submission validations. Proof of address, source of funds, formation documents, UBO ownership, and flow of funds now run through document verification when you upload a supporting document attestation. See uploadAttestations for more information.
  2. Unresolvable state and province codes are rejected on upload. An ISO 3166-2 subdivision that does not resolve for its country now returns 400 at attestation upload, on both review and associated-person attestations, instead of being forwarded to the KYC provider and failing downstream. The error names the attestation type at fault.

Sandbox

  1. Payouts and pay-ins can be driven to a chosen outcome. Reserved account numbers set the result of a sandbox payout for ARS, BOB, COP, MXN, PEN, and USD: failure with a specific error code, a payout that stays pending, or one that settles slowly. Reserved deposit amounts do the same for pay-ins on USD (ACH, WIRE), MXN (SPEI), BRL (PIX), and ARS (CVU). The reserved values are listed in Simulated Payments.

🐛 Bug Fixes

Accounts API

  1. Unknown or deleted account ids return 404, not 500. Reading transactions or payouts for an account id that does not exist now returns 404.
  2. Setting a settlement strategy before pay-in details exist returns 412, not 500. PUT /api/accounts/{id}/set-settlement-strategy on an account whose deposit details are still being provisioned now returns 412 instead of an internal server error.

Payouts API

  1. Plasma payouts report their token as USDT. A payout sourced from USDT0 on Plasma returned USDT0, which is not in the published TokenSymbol enum, so a strict client could not parse it. Every symbol field now reads USDT, matching details.token. Plasma is also now listed among the supported payout blockchains.

Payins API

  1. A pay-in whose fees consume the whole deposit now fails. Previously it settled a zero-value credit. It now fails before any provider settles, so no fee is taken, and the funds are returned to the sender.

Compliance API

  1. Document attestations no longer stay pending forever. A document the verification provider rejects now resolves to failed with a reason and emits an attestation_validation_status_changed webhook event.
  2. An attestation referencing a document that never finished uploading is rejected. Uploading an attestation that names a documentId whose file has not landed in storage now returns 400. Previously the attestation was accepted and failed later with nothing to point at.