Changelog
What changed for integrators, newest first. The API is at version 1.0.0.
The API's version is in the API reference; a breaking change gets a new major version. Additions (new fields, new endpoints, new webhook event types) can arrive at any time: ignore fields and event types you do not know.
2026-10-08
- Tillsafe is the product's name, and these docs live at
docs.tillsafe.com. The documented API base ishttps://api.tillsafe.com(early access: keys are issued on request). - New pages: how payments are matched, the security model, USDT on TRON and BNB Chain and testing with simulate_payment, whose commands the test suite runs like the quickstart's.
2026-10-07
Added
- USDC and USDT on Solana (
USDC@solana:devnetin test mode;USDC@solana:mainnetandUSDT@solana:mainnetlive), credited atfinalized.
Changed
- Payment links: opening a link reserves a unit, so concurrent payers can no
longer pay for more than
quantity_limit(quantity_reserved,409 payment_link_fully_reserved). A link invoice gets its deposit address only when the payer picks a network (POST /v1/checkout/invoices/{id}/payment_option), within 30 minutes. Open unpaid link invoices are capped (409 payment_link_busy).
2026-09-30
- Developer docs: this site. The quickstart and every webhook snippet are executed against the API by the test suite, and the API reference is generated from the OpenAPI description at build time.
2026-09-29 to 2026-09-30
Added
- Payment links:
POST /v1/payment_linksand friends, a landing screen on the checkout, andpayment_link.created,payment_link.updated,payment_link.deactivatedwebhooks. Invoices created from a link carrypayment_link. - Subscriptions: plans, customers and invoice-based renewals, with reminders,
retries and prepaid credit. Eight
subscription.*webhooks. - Connected wallet payments (EIP-6963 wallets and TronLink):
POST /v1/checkout/invoices/{id}/wallet_binding. - USDC on Base, Arbitrum and Polygon, and USDT on Arbitrum and Polygon; Bitcoin in test mode with your own xpub.
GET /v1/reconciliation/balances; the checkout'scapabilities.receipt_email.
Changed
- An excess under 0.01 of a stablecoin is kept and no longer makes an invoice
overpaid. - Refund emails to payers no longer carry the claim link: send it yourself.
- The checkout view of a BTC option no longer includes the xpub (its derivation is
bip32).
2026-09-29
Added
POST /v1/invoices/{id}/cancelandPOST /v1/invoices/{id}/resolve_review, with theinvoice.review_resolvedandinvoice.cancelledwebhooks (reviews).- Reconciliation:
GET /v1/reconciliationand a CSV export (GET /v1/reconciliation/export). - The embed loader, and payer receipts by email
(
POST /v1/checkout/invoices/{id}/notify). - Checkout languages: Spanish, Brazilian Portuguese, Turkish and Indonesian.
- Live merchants with their own deposit addresses.
Changed
- An invoice under review no longer expires while it waits.
- In live mode, an API key can only accept size holds; other holds need the dashboard.
2026-09-28
Added
- Refunds:
POST /v1/invoices/{id}/refunds, payer claim links and screening,refund.claimed. GET /v1/checkout/invoices/{id}/lookup(the payer's "find my payment") andGET /v1/checkout/exchanges.- Webhooks
invoice.payment_reversed,invoice.wrong_assetandinvoice.late_payment; every invoice event has a top-levelinvoice_id. POST /v1/test_helpers/invoices/{id}/simulate_paymentis part of the documented API.- Dashboard sign-in with passkeys, team roles, and API keys on the Developers page.
Changed (breaking)
- In live mode,
webhook_urland the webhook secret can only be changed on the dashboard (403 live_change_requires_dashboardfor API keys).
2026-09-27
- First version of the API: invoices, payments, webhook deliveries and replay, merchant settings, the
checkout endpoints and live status events; signed
invoice.*webhooks; the hosted checkout in English, Russian and Vietnamese; test helpers.