Operational trust readiness - UAT/demo disclosure

API changelog

Public Billie API release notes grouped by breaking changes, non-breaking changes, and security updates for partner readiness review.

Breaking changes

Breaking

API v1 contract freeze

2026-06-20

Public API consumers should use /api/v1 paths. Future incompatible changes will be announced before activation and grouped under a new versioned route.

Non-breaking changes

Non-breaking

Public trust routes published

2026-06-24

Added webhook documentation, operational status, changelog, vulnerability disclosure, security.txt, and data request route disclosure for UAT review.

Non-breaking

Webhook catalogue expanded

2026-06-22

Published payment, payout, refund, and bill event examples with signature headers, retry timing, replay guidance, and idempotent handling expectations.

Security updates

Security

Webhook signing posture documented

2026-06-23

Clarified HMAC-SHA256 signature verification, timestamp tolerance, duplicate event rejection, and endpoint secret rotation expectations.

Security

Secret handling guidance reinforced

2026-06-21

Public pages now state that secrets must stay out of email, logs, source control, browser storage, and support tickets.