Skip to main content

Changelog

Changes to the Partner API, its authentication and webhooks, newest first.

2026-10-03​

  • Changed. Request a document upload link no longer takes fileName. The stored file is named from documentCategory and contentType, for example PASSPORT.jpg. A fileName you still send is ignored, so existing integrations keep working.
  • Changed. The same call takes uboId, the name the create response uses, instead of ownershipDetailId. ownershipDetailId is deprecated but still accepted; sending both with different values is 400 ValidationControl.Error.
  • Corrected (docs). The upload link page now says what the upload PUT needs and returns: the exact requested Content-Type, a 30-minute link, the storage errors for a wrong type or an expired link, and why each upload should finish before the next link with the same documentCategory.
  • Breaking. Partner API authentication moved to the Ryno identity service. Register an RSA X.509 certificate under API Credentials in the Partner Portal, then request tokens from your environment's token endpoint with grant_type=client_credentials and an RS256 private_key_jwt client assertion. See Authentication.
  • Removed. POST /auth/partner/v1/token, ES256 public keys, API Key IDs and the kid header. Credentials created that way no longer issue tokens.
  • Changed. Access tokens last 300 seconds instead of 3600, and responses use OAuth field names: access_token, expires_in, token_type, scope.
  • Changed. Your client ID is generated from your business name and partner ID, and replaces the partner ID as the assertion iss and sub.
  • Corrected (docs). API routes are served under /api: for example https://gateway.sandbox.rynopay.io/api/partner/v1/business-profiles. Earlier pages omitted the prefix.

2026-10-01​

  • Changed (breaking). phoneNumber on the business profile and phone on a business person must be E.164: a leading + then 7 to 15 digits. A number without + is rejected with 400 PhoneNumber.Invalid.

2026-09-27​

  • Changed (breaking). Each business person's identities are validated against the documents accepted for that person's country of residence, address.countryCode, including required dates and number formats. Failures are 400 ValidationControl.Error and nothing is written. See Accepted identity documents.
  • New. GET /customer/v1/onboarding/ubo-identity-requirements?countryCode=… lists the identity documents accepted from people living in a country.
  • Breaking. Every business person in businessPersonList — on Create Business Profile and Update Business Profile — now requires nationality, an ISO 3166-1 alpha-3 code (3 uppercase letters). A person without it is rejected with 400 ValidationControl.Error and nothing is created. People already on a customer are unaffected.
  • Corrected. idBackDocumentUploadId on an identity is accepted but not currently stored; the reference previously implied it was kept.

2026-09-26​

  • Changed. Every webhook is now sent by RynoPay's webhook delivery service with the contract in Webhooks: Ryno-* headers and Ryno-Signature with a rotation overlap, eventVersion and correlation in the body, 8 attempts over about three days, and endpoint health. Verify Ryno-Signature; the earlier X-Webhook-Signature scheme is not part of the contract.
  • Changed (dashboard). The delivery history, delivery detail and single-delivery replay come from that service: history statuses are Pending, Delivered, Exhausted, the history accepts from / to, the detail carries every attempt and the exact signed envelope, and a replay returns the new delivery's id. A bad status filter is 400 Webhook.StatusUnknown.
  • Removed (dashboard). secretPreview on GET and PUT /customer/v1/partner-profile/webhooks, and the ignored description field on registration. The secret is shown only when it is issued.

2026-09-22​

  • New. FinancialInstitution is accepted as a businessTypeCode, for banks, microfinance banks and other licensed financial services providers. Additive: no existing value changed.

2026-09-21​

  • Breaking. Webhook management left the Partner API. POST, GET and PUT /partner/v1/webhooks, POST /partner/v1/webhooks/rotate-secret, GET /partner/v1/webhooks/deliveries and POST /partner/v1/webhooks/deliveries/{deliveryId}/replay are withdrawn. Registering a URL, rotating the signing secret and reading the delivery log are now done by a signed-in person in the partner dashboard — see Managing your webhook. Your machine credential can no longer change where your events are delivered.
  • Unchanged: the signature scheme, the event catalogue and every event payload. Nothing you verify or parse on receipt is affected.
  • Breaking. GET /partner/v1/eco-partner/{customerId}, deprecated since 2026-09-14, is removed. Use GET /partner/v1/business-profiles/{customerId}/verification-status, which carries the same data in the standard envelope and reports real HTTP statuses on failure.

2026-09-19​

  • Breaking. The two error codes for partnerCustomerId are renamed to match it: Customer.PartnerReferenceRequired → Customer.PartnerCustomerIdRequired, and Customer.PartnerReferenceInvalid → Customer.PartnerCustomerIdInvalid. Branch on the new codes.
  • Breaking. GET /business-profiles/{customerId} and GET /business-profiles return partnerCustomerId instead of partnerReference, matching what create and update already returned.
  • The path parameter on GET /business-profiles/by-reference/{partnerCustomerId} is renamed to partnerCustomerId to match the request and response field. The URL is unchanged — a placeholder name is not part of it — so no caller needs to do anything.
  • New. GET /partner/v1/webhooks/deliveries lists your deliveries with their attempt history, and POST /partner/v1/webhooks/deliveries/{deliveryId}/replay retries one that was abandoned. (Both moved to the dashboard on 2026-09-21.)
  • New events. business.profile.created, business.profile.updated, business.person.added and business.document.confirmed. Every partner receives them automatically — ignore any event type you do not recognise rather than failing on it.
  • Webhook deliveries are now durable. A delivery that fails is retried with exponential backoff over roughly 24 hours instead of being dropped after one attempt. (Superseded on 2026-09-26.)
  • The webhook envelope is { id, type, specVersion, occurredAt, data }. id is stable across retries — use it to deduplicate. The X-Webhook-Signature and X-Webhook-Event headers are unchanged. (Superseded on 2026-09-26.)
  • PATCH /partner/v1/business-profiles/{customerId} now accepts incorporationCountryCode, which it previously had no field for — the country was inferred from the first entry of addresses. It also takes businessTypeCode and industry from the same vocabularies as create.
  • Breaking. businessTypeCode and industry are now validated against a fixed vocabulary and rejected with ValidationControl.Error when the value is not one of the listed names. industry was previously free text.
  • Breaking. The businessTypeCode names changed from underscored upper case to Pascal case: SOLE_PROPRIETOR → SoleProprietor, NON_PROFIT → NonProfit, and so on. Matching is case-insensitive, so LLC, Llc and llc all still work, but any name containing an underscore must be updated.
  • Breaking. POST /partner/v1/business-profiles/{customerId}/submit is removed. Creating a profile now queues the customer for compliance directly (verificationStatus becomes PendingVerification), and updating one leaves it queued. Uploaded documents are confirmed automatically when they land in storage, so there is nothing left for a submit step to do.
  • PATCH /partner/v1/business-profiles/{customerId} accepts businessPersonList, which appends business people — it never removes one. It is also how you respond to ChangesRequested.
  • Breaking. GET /partner/v1/onboarding-requirements is removed. The document categories and identity types this API accepts are listed in Reference tables.
  • Breaking. The deprecated alias POST /partner/v1/documents/onboarding-upload-link is removed. Use POST /partner/v1/business-profiles/{customerId}/documents/upload-link, which takes the same body.
  • Breaking. GET /partner/v1/business-profiles/{customerId}/onboarding-progress is removed. The profile is created in a single call, so there are no stages for a partner to poll through; use GET /business-profiles/{customerId}/verification-status for the outcome.
  • Breaking. The UBO endpoints are removed: POST, GET and DELETE on /partner/v1/business-profiles/{customerId}/ubos. Beneficial owners, directors and shareholders are now supplied only through businessPersonList on POST /partner/v1/business-profiles, which creates the customer and its people in one transaction.
  • POST /partner/v1/business-profiles accepts businessPersonList, creating the business customer and its people in one transaction. The response gains a ubos array listing what was created.
  • New PATCH /partner/v1/business-profiles/{customerId} — partial update of a business customer you own, and the place to confirm uploaded documents via businessDocumentIdList. Every field is optional; omitted fields are left unchanged. Rejected once an analyst owns the package.
  • Document ids confirmed there are checked against the customer that owns them; an unknown id or one belonging to another customer now fails the call (Document.NotFound / Document.AccessDenied).
  • Combined percentageShare above 100, and duplicate person emails within a single request, are now rejected with ValidationControl.Error before anything is written.
  • A failure anywhere in the call now leaves nothing behind. Previously the customer could be created and persisted while a later step failed, and onboarding-stage failures were swallowed entirely.
  • Documented the webhook management surface: POST /partner/v1/webhooks, GET /partner/v1/webhooks, PUT /partner/v1/webhooks, and POST /partner/v1/webhooks/rotate-secret. (All moved to the dashboard on 2026-09-21.)
  • Breaking: GET /partner/v1/webhooks no longer returns webhookSecret. It returns secretPreview instead — a masked hint such as whsec_****k9Qd. The secret is handed over only by the calls that issue it (on registration and on rotation); store it when you receive it, and rotate if you lose it.
  • Breaking: PUT /partner/v1/webhooks no longer regenerates the signing secret when webhookSecret is omitted — the live secret is kept, so changing a URL no longer breaks signature verification. The response carries webhookSecret only when the call actually set one, plus secretPreview either way.

2026-09-14​

  • Documented the partner business onboarding surface: POST /business-profiles, GET /business-profiles, GET /business-profiles/{customerId}, GET /business-profiles/by-reference/{partnerCustomerId}, POST /business-profiles/{customerId}/ubos, GET /business-profiles/{customerId}/ubos, DELETE /business-profiles/{customerId}/ubos/{uboId}, POST /business-profiles/{customerId}/documents/upload-link, POST /business-profiles/{customerId}/submit, GET /business-profiles/{customerId}/verification-status, and GET /onboarding-requirements.
  • Routes moved under /partner/v1/business-profiles/...; the prior route GET /partner/v1/eco-partner/{customerId} was kept as a deprecated alias (since removed).
  • Corrected the public businessTypeCode vocabulary to the values this API actually accepts (see Business type codes).