Changelog
Changes to the Partner API, its authentication and webhooks, newest first.
2026-10-03
- Changed. Request a document upload link no longer takes
fileName. The stored file is named fromdocumentCategoryandcontentType, for examplePASSPORT.jpg. AfileNameyou still send is ignored, so existing integrations keep working. - Changed. The same call takes
uboId, the name the create response uses, instead ofownershipDetailId.ownershipDetailIdis deprecated but still accepted; sending both with different values is400 ValidationControl.Error. - Corrected (docs). The upload link page now says what the upload
PUTneeds and returns: the exact requestedContent-Type, a 30-minute link, the storage errors for a wrong type or an expired link, and why each upload should finish before the next link with the samedocumentCategory. - Breaking. Partner API authentication moved to the Ryno identity service. Register an RSA X.509 certificate under API Credentials in the Partner Portal, then request tokens from your environment's token endpoint with
grant_type=client_credentialsand an RS256private_key_jwtclient assertion. See Authentication. - Removed.
POST /auth/partner/v1/token, ES256 public keys, API Key IDs and thekidheader. Credentials created that way no longer issue tokens. - Changed. Access tokens last 300 seconds instead of 3600, and responses use OAuth field names:
access_token,expires_in,token_type,scope. - Changed. Your client ID is generated from your business name and partner ID, and replaces the partner ID as the assertion
issandsub. - Corrected (docs). API routes are served under
/api: for examplehttps://gateway.sandbox.rynopay.io/api/partner/v1/business-profiles. Earlier pages omitted the prefix.
2026-10-01
- Changed (breaking).
phoneNumberon the business profile andphoneon a business person must be E.164: a leading+then 7 to 15 digits. A number without+is rejected with400 PhoneNumber.Invalid.
2026-09-27
- Changed (breaking). Each business person's
identitiesare validated against the documents accepted for that person's country of residence,address.countryCode, including required dates and number formats. Failures are400 ValidationControl.Errorand nothing is written. See Accepted identity documents. - New.
GET /customer/v1/onboarding/ubo-identity-requirements?countryCode=…lists the identity documents accepted from people living in a country. - Breaking. Every business person in
businessPersonList— on Create Business Profile and Update Business Profile — now requiresnationality, an ISO 3166-1 alpha-3 code (3 uppercase letters). A person without it is rejected with400 ValidationControl.Errorand nothing is created. People already on a customer are unaffected. - Corrected.
idBackDocumentUploadIdon an identity is accepted but not currently stored; the reference previously implied it was kept.
2026-09-26
- Changed. Every webhook is now sent by RynoPay's webhook delivery service with the contract in Webhooks:
Ryno-*headers andRyno-Signaturewith a rotation overlap,eventVersionandcorrelationin the body, 8 attempts over about three days, and endpoint health. VerifyRyno-Signature; the earlierX-Webhook-Signaturescheme is not part of the contract. - Changed (dashboard). The delivery history, delivery detail and single-delivery replay come from that service: history statuses are
Pending,Delivered,Exhausted, the history acceptsfrom/to, the detail carries every attempt and the exact signed envelope, and a replay returns the new delivery's id. A badstatusfilter is400 Webhook.StatusUnknown. - Removed (dashboard).
secretPreviewonGETandPUT /customer/v1/partner-profile/webhooks, and the ignoreddescriptionfield on registration. The secret is shown only when it is issued.
2026-09-22
- New.
FinancialInstitutionis accepted as abusinessTypeCode, for banks, microfinance banks and other licensed financial services providers. Additive: no existing value changed.
2026-09-21
- Breaking. Webhook management left the Partner API.
POST,GETandPUT /partner/v1/webhooks,POST /partner/v1/webhooks/rotate-secret,GET /partner/v1/webhooks/deliveriesandPOST /partner/v1/webhooks/deliveries/{deliveryId}/replayare withdrawn. Registering a URL, rotating the signing secret and reading the delivery log are now done by a signed-in person in the partner dashboard — see Managing your webhook. Your machine credential can no longer change where your events are delivered. - Unchanged: the signature scheme, the event catalogue and every event payload. Nothing you verify or parse on receipt is affected.
- Breaking.
GET /partner/v1/eco-partner/{customerId}, deprecated since 2026-09-14, is removed. UseGET /partner/v1/business-profiles/{customerId}/verification-status, which carries the same data in the standard envelope and reports real HTTP statuses on failure.
2026-09-19
- Breaking. The two error codes for
partnerCustomerIdare renamed to match it:Customer.PartnerReferenceRequired→Customer.PartnerCustomerIdRequired, andCustomer.PartnerReferenceInvalid→Customer.PartnerCustomerIdInvalid. Branch on the new codes. - Breaking.
GET /business-profiles/{customerId}andGET /business-profilesreturnpartnerCustomerIdinstead ofpartnerReference, matching what create and update already returned. - The path parameter on
GET /business-profiles/by-reference/{partnerCustomerId}is renamed topartnerCustomerIdto match the request and response field. The URL is unchanged — a placeholder name is not part of it — so no caller needs to do anything. - New.
GET /partner/v1/webhooks/deliverieslists your deliveries with their attempt history, andPOST /partner/v1/webhooks/deliveries/{deliveryId}/replayretries one that was abandoned. (Both moved to the dashboard on 2026-09-21.) - New events.
business.profile.created,business.profile.updated,business.person.addedandbusiness.document.confirmed. Every partner receives them automatically — ignore any event type you do not recognise rather than failing on it. - Webhook deliveries are now durable. A delivery that fails is retried with exponential backoff over roughly 24 hours instead of being dropped after one attempt. (Superseded on 2026-09-26.)
- The webhook envelope is
{ id, type, specVersion, occurredAt, data }.idis stable across retries — use it to deduplicate. TheX-Webhook-SignatureandX-Webhook-Eventheaders are unchanged. (Superseded on 2026-09-26.) PATCH /partner/v1/business-profiles/{customerId}now acceptsincorporationCountryCode, which it previously had no field for — the country was inferred from the first entry ofaddresses. It also takesbusinessTypeCodeandindustryfrom the same vocabularies as create.- Breaking.
businessTypeCodeandindustryare now validated against a fixed vocabulary and rejected withValidationControl.Errorwhen the value is not one of the listed names.industrywas previously free text. - Breaking. The
businessTypeCodenames changed from underscored upper case to Pascal case:SOLE_PROPRIETOR→SoleProprietor,NON_PROFIT→NonProfit, and so on. Matching is case-insensitive, soLLC,Llcandllcall still work, but any name containing an underscore must be updated. - Breaking.
POST /partner/v1/business-profiles/{customerId}/submitis removed. Creating a profile now queues the customer for compliance directly (verificationStatusbecomesPendingVerification), and updating one leaves it queued. Uploaded documents are confirmed automatically when they land in storage, so there is nothing left for a submit step to do. PATCH /partner/v1/business-profiles/{customerId}acceptsbusinessPersonList, which appends business people — it never removes one. It is also how you respond toChangesRequested.- Breaking.
GET /partner/v1/onboarding-requirementsis removed. The document categories and identity types this API accepts are listed in Reference tables. - Breaking. The deprecated alias
POST /partner/v1/documents/onboarding-upload-linkis removed. UsePOST /partner/v1/business-profiles/{customerId}/documents/upload-link, which takes the same body. - Breaking.
GET /partner/v1/business-profiles/{customerId}/onboarding-progressis removed. The profile is created in a single call, so there are no stages for a partner to poll through; useGET /business-profiles/{customerId}/verification-statusfor the outcome. - Breaking. The UBO endpoints are removed:
POST,GETandDELETEon/partner/v1/business-profiles/{customerId}/ubos. Beneficial owners, directors and shareholders are now supplied only throughbusinessPersonListonPOST /partner/v1/business-profiles, which creates the customer and its people in one transaction. POST /partner/v1/business-profilesacceptsbusinessPersonList, creating the business customer and its people in one transaction. The response gains aubosarray listing what was created.- New
PATCH /partner/v1/business-profiles/{customerId}— partial update of a business customer you own, and the place to confirm uploaded documents viabusinessDocumentIdList. Every field is optional; omitted fields are left unchanged. Rejected once an analyst owns the package. - Document ids confirmed there are checked against the customer that owns them; an unknown id or one belonging to another customer now fails the call (
Document.NotFound/Document.AccessDenied). - Combined
percentageShareabove 100, and duplicate person emails within a single request, are now rejected withValidationControl.Errorbefore anything is written. - A failure anywhere in the call now leaves nothing behind. Previously the customer could be created and persisted while a later step failed, and onboarding-stage failures were swallowed entirely.
- Documented the webhook management surface:
POST /partner/v1/webhooks,GET /partner/v1/webhooks,PUT /partner/v1/webhooks, andPOST /partner/v1/webhooks/rotate-secret. (All moved to the dashboard on 2026-09-21.) - Breaking:
GET /partner/v1/webhooksno longer returnswebhookSecret. It returnssecretPreviewinstead — a masked hint such aswhsec_****k9Qd. The secret is handed over only by the calls that issue it (on registration and on rotation); store it when you receive it, and rotate if you lose it. - Breaking:
PUT /partner/v1/webhooksno longer regenerates the signing secret whenwebhookSecretis omitted — the live secret is kept, so changing a URL no longer breaks signature verification. The response carrieswebhookSecretonly when the call actually set one, plussecretPrevieweither way.
2026-09-14
- Documented the partner business onboarding surface:
POST /business-profiles,GET /business-profiles,GET /business-profiles/{customerId},GET /business-profiles/by-reference/{partnerCustomerId},POST /business-profiles/{customerId}/ubos,GET /business-profiles/{customerId}/ubos,DELETE /business-profiles/{customerId}/ubos/{uboId},POST /business-profiles/{customerId}/documents/upload-link,POST /business-profiles/{customerId}/submit,GET /business-profiles/{customerId}/verification-status, andGET /onboarding-requirements. - Routes moved under
/partner/v1/business-profiles/...; the prior routeGET /partner/v1/eco-partner/{customerId}was kept as a deprecated alias (since removed). - Corrected the public
businessTypeCodevocabulary to the values this API actually accepts (see Business type codes).