{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Changelog","siteUrl":"https://developer.flute.com","description":"Documentation and API reference for integrating Flute payment processing.","lang":"en-US","projectTitle":"Flute Payments API","jsonLd":{"@context":"https://schema.org","@type":"WebSite","name":"Flute Developer Portal","url":"https://developer.flute.com","description":"Documentation and API reference for integrating Flute payment processing."},"meta":[{"name":"og:type","content":"website"},{"name":"og:site_name","content":"Flute Payments API"},{"name":"twitter:card","content":"summary"}],"llmstxt":{"hide":false}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"changelog","__idx":0},"children":["Changelog"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2026-09-23","__idx":1},"children":["2026-09-23"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New features"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API"]},": Idempotency is now supported for all payment operations (sale, refund, capture, void, and more). Pass a unique idempotency key per request to guarantee that retries never create duplicate charges, even across network failures or timeouts. See the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/getting-started/idempotency"},"children":["Idempotency docs"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API"]},": Tax can now be configured on Payment Links and hosted Checkout pages, calculated inclusive or exclusive of the base amount and displayed as a clear subtotal/tax/total breakdown on the payer-facing page. See the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/online-payments/payment-links"},"children":["Payment Links docs"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Elements"]},": AVS fraud protection now includes full street address verification in addition to ZIP code. See the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/online-payments/flute-elements"},"children":["Elements docs"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Developer Portal"]},": A public status page is now available showing real-time health and 30-day rolling uptime for all core services ISVs integrate with. See the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/status"},"children":["status page"]},"."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2026-09-18","__idx":2},"children":["2026-09-18"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Bug fixes"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Checkout"]},": Fixed a validation gap where a payment session could be created with a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["referenceId"]}," exceeding 50 characters, only to fail with a cryptic error when the customer attempted to pay. The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["referenceId"]}," is now validated at session creation, returning a clear error upfront."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2026-09-14","__idx":3},"children":["2026-09-14"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New features"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCP"]},": Launched an open-source MCP server that lets AI coding assistants (Claude, Codex, Cursor) drive the full Flute payments platform through 47 typed tools covering transactions, ACH, customers, POS, terminals, settlements, subscriptions, and API token management. Production writes are disabled by default and credentials are stored in the OS keychain. Available via Homebrew or built from source (MIT license). See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://github.com/getflute/flute-cli-mcp"},"children":["GitHub"]},"."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2026-09-10","__idx":4},"children":["2026-09-10"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New features"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API v2: Settlement"]},": The Settlement resource is now available in the v2 API. See the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/api-reference/v2/settlements"},"children":["API reference"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Bug fixes"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["iOS SDK"]},": Fixed an issue where Tap to Pay and manual entry transactions could not be performed on sandbox merchant accounts in the iOS app, and the iPhone was not appearing in the Connected Devices list. Developers and QA teams can now fully test Tap to Pay flows in sandbox before going live."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Elements"]},": Fixed a bug where an already-spent Cloudflare Turnstile token was being reused across payment sessions, causing legitimate transactions to fail with a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["bot_challenge_failed"]}," error. The token is now refreshed on every payment attempt and auto-retried on challenge failure."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Breaking changes"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API v2: Settlements"]}," (",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/api-reference/v2/settlements"},"children":["API reference"]},"): As part of v2 beta API refinements, the following fields were updated to align with naming conventions and guidelines:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["status"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["batchStatus"]}," on list and response DTOs"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["orderBy"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sortBy"]}," on list requests"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["dateFrom"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["fromDate"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["dateTo"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["toDate"]}," on list requests"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["netAmount"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["salesAmount"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["refundsAmount"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["totalNetAmount"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["totalSalesAmount"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["totalRefundsAmount"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["batchDateTime"]}," removed"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["message"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["processorResponseCode"]}," removed from responses"]}]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2026-08-31","__idx":5},"children":["2026-08-31"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Bug fixes"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Elements"]},": Fixed a security gap where transactions were being approved despite a missing billing address when AVS was configured to Moderate or Strict. Both ZIP code and street address are now validated before authorizing a transaction."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2026-08-26","__idx":6},"children":["2026-08-26"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New features"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API"]},": Payment links can now be created and managed programmatically via the v2 API. Supports fixed amount, open amount, and standard checkout flows, with card and ACH/EFT, tipping, and merchant branding. See the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/online-payments/payment-links"},"children":["Payment Links docs"]}," and ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/api-reference/v2/payment-links"},"children":["API reference"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API"]},": The API now returns a clear ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["HTTP 401"]}," error when a sandbox API key is used against a production endpoint (or vice versa), preventing accidental real transactions during development."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Terminal SDK"]},": ISV apps can now initiate a payment by calling a single method, handing off to the Flute Terminal app via deeplink for card read and processing, and receiving a typed result callback (approval, decline, or error) that automatically resumes the ISV app. No cloud round-trips or custom middleware required. Supported on certified Sunmi and Verifone device families. See the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/sdk/flute-terminal-sdk"},"children":["Terminal SDK docs"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["iOS SDK"]},": Any compatible iPhone can now be used as a secure payment terminal, accepting contactless cards, digital wallets, and NFC-enabled devices without dedicated POS hardware. Ideal for integrations targeting mobile merchants, pop-ups, and field service providers. See the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/sdk/ios"},"children":["iOS SDK docs"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Bug fixes"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API"]},": Fixed a delay where the POS terminal status remained \"unavailable\" for approximately one minute after a transaction completed. The terminal now updates to \"available\" as soon as the home screen is shown."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2026-08-14","__idx":7},"children":["2026-08-14"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Bug fixes"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API"]},": Fixed an issue where batch settlement data was lost during settlement processing due to a shared database context across parallel operations. Settlement records now reflect correctly via the API."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2026-08-12","__idx":8},"children":["2026-08-12"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New features"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API v2"]},": Added Transactions, POS Transactions, Terminals, and Webhooks to the v2 API. See the API reference: ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/api-reference/v2/transactions"},"children":["Transactions"]}," · ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/api-reference/v2/pos-transactions"},"children":["POS Transactions"]}," · ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/api-reference/v2/terminals"},"children":["Terminals"]}," · ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/api-reference/v2/webhooks"},"children":["Webhooks"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Bug fixes"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API"]},": Fixed two AVS issues: transactions were being recorded with the wrong AVS response code, and the Strict AVS profile was incorrectly approving partial-match transactions that should have been declined."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Breaking changes"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API v2: Webhooks"]}," (",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/api-reference/v2/webhooks"},"children":["API reference"]},"): As part of v2 beta API refinements, the following fields were updated to align with naming conventions and guidelines:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["webhookName"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["endpointName"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["status"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["endpointStatus"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["createdAt"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["createdOn"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deliveryAttemptStatus"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deliveryLogStatus"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["success"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["isDelivered"]}," on ping/delivery responses"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["eventType"]}," changed from an enum to a string"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["eventTypeId"]}," removed from event types responses"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["List and event-types responses moved from a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["data"]}," envelope to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["items"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["List endpoints are now paginated"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API v2: Terminals"]}," (",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/api-reference/v2/terminals"},"children":["API reference"]},"): As part of v2 beta API refinements, the following fields were updated to align with naming conventions and guidelines:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["orderBy"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sortBy"]}," on list requests"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["asc"]}," (bool) renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sortOrder"]}," (string) on list requests"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["terminalPosStatus"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["terminalStatus"]}," on responses"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["lastSeenTimestamp"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["lastSeenOn"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["terminalVersion"]}," renamed to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["terminalAppVersion"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["availabilityStatus"]}," removed"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deliveryStatus"]}," removed"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deviceSoftwareDetails"]}," object removed"]}]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"2026-08-04","__idx":9},"children":["2026-08-04"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Bug fixes"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Terminal"]},": Fixed an issue where POS transactions would become stuck in a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["TransactionProcessing"]}," state without activating the terminal, blocking all subsequent payment attempts on that terminal with a \"Transaction is already in progress\" error and requiring manual cancellation via API as a workaround."]}]}]},"headings":[{"value":"Changelog","id":"changelog","depth":1},{"value":"2026-09-23","id":"2026-09-23","depth":2},{"value":"2026-09-18","id":"2026-09-18","depth":2},{"value":"2026-09-14","id":"2026-09-14","depth":2},{"value":"2026-09-10","id":"2026-09-10","depth":2},{"value":"2026-08-31","id":"2026-08-31","depth":2},{"value":"2026-08-26","id":"2026-08-26","depth":2},{"value":"2026-08-14","id":"2026-08-14","depth":2},{"value":"2026-08-12","id":"2026-08-12","depth":2},{"value":"2026-08-04","id":"2026-08-04","depth":2}],"frontmatter":{"title":"Changelog","description":"A record of notable changes to the Flute API and developer platform.","seo":{"title":"Changelog"}},"lastModified":"2026-09-23T22:36:33.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/docs/changelog","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}