🏷️ v3.2.0 — 2026-09-14
🚀 New features
Open Banking API
Added sandbox support for Finsim bill payments.
Added a new field (
balanceOfPaymentCode) to support Eurobank non-SEPA payments.
Payhub API
The payment request ID is now automatically appended to merchant return redirect URLs.
Payment requests now support optional custom metadata fields.
A new endpoint is available to retrieve registration details including webhook configuration.
Merchants can now configure a return URL flow for payment links.
A new endpoint is available to retrieve payment request details by ID.
Paygate API
Users who have not yet activated their account can now set up a password through the welcome flow.
Inactive users are now supported in the password reset welcome flow.
Merchant details responses now include rejection-related information.
The merchant entity now stores rejection info fields for future reference.
✨ Improvements
Paygate API
Merchant lookups during authorization are now cached to improve performance.
🐛 Bug fixes
Open Banking API
Bill payment accounts are now resolved through the dedicated bill-payment backend.
Payhub API
Removed duplicate form field names and stabilised end-to-end checkout tests for DIAS and Worldline.
Paygate API
Partner certificate paths are now derived on the server side rather than supplied by the client.
Removed an obsolete application key field from the merchant details response.
Fixed a bug that could cause the total paid amount to be calculated using stale data.
Moved merchant adaptor application key generation to the organisation activation step.
Fixed transaction handling in the easy onboarding flow.
Increased the maximum allowed length for the adaptor application key.
Aligned terminal status transaction matching and fixed an IRIS logo lookup issue.
Fixed a race condition that could cause payment response order statuses to be processed out of order.
Corrected the description of the delete bank holiday endpoint to avoid a false-positive security alert.
Order and payment request updates are now wrapped in a single transaction, and a duplicate callback has been removed.
Payment status reporting is now restricted to the owning merchant.
Fixed an incorrect partial payment status being returned.
Fixed unexpected behaviour in the terminal payment request endpoint.
Reverted an unintended change to the payment status response format.
Fixed an incorrect cancellation status being returned for v1 payments.
Fixed incorrect response mapping for the v1 post-payment status endpoint.
Resolved a transaction boundary issue and a cancellation bug in the merchant send-for-approval flow.
Aligned the not-found payment request response with the expected legacy format.
Fixed the Eurobank easy registration flow.
Database transactions are now wrapped in a retry-compatible execution strategy to prevent failures under transient errors.
Fixed incorrect serialisation of the ultimate creditor info response.
Added explicit database transactions to prevent orphaned records when external service calls fail.
Fixed a typo in the terminal payment status consumer.
Fixed errors occurring during terminal payment status transactions.
Financing
Fixed an issue that could cause duplicate consent acceptance events to be recorded.
🔒 Security
Open Banking API
Sensitive data is now redacted from exception logs, and build and audit warnings have been resolved.
Test redirect URIs have been replaced with approved whitelisted domain values.
Sensitive HTTP headers are no longer included in global exception handler logs.
Swagger UI is now only accessible in development and local environments.
Payhub API
Worldline callback digest verification has been added, and the onboarding callback has been hardened.
Page scripts are now restricted to same-origin relative modules to tighten content security.
The subscription service token has been moved to Key Vault for secure storage.
DTD processing has been disabled in the Worldline XML canonicalizer to prevent XML injection.
Fixed a duplicate organisation code submission that could break DIAS registration.
Paygate API
OpenAPI and log4net vulnerabilities have been patched and build warnings cleared.
Admin accounts are now locked out after a configurable number of failed login attempts.
Callback configuration secrets are no longer exposed in the get-partner response.
Payment request redirect URLs are now validated before use.
Sensitive partner credentials are masked in the get-partner-by-ID response.
Secret values are no longer written to logs in the Key Vault service.
Payment request redirect and callback URLs are now validated on creation.
Registration callbacks are now bound to a one-time nonce to prevent replay.
The minimum allowed length for JWT signing keys is now enforced in configuration.
Dynamic content in email HTML is now sanitised to prevent injection attacks.
Sensitive data has been removed from Eurobank refund consumer logs.
The ALTCHA challenge search space has been increased to prevent brute-force bypass.
HTML content in the email generator is now sanitised to prevent injection attacks.
Merchant application key comparisons now use constant-time logic to prevent timing attacks.
Registration status lookups are now scoped to the authenticated partner.
Payment status requests are now scoped to the requesting merchant.
Application key generation now uses a cryptographically secure random source.
Terminal payment status processing now validates order ownership and the DIAS transaction ID.
OAuth tokens are no longer written to logs.
Unauthorised access to payment orders is now prevented.
OData queries against Azure Table Storage are now protected against injection.
An upper bound has been added to the batch size parameter for file-based orders and refunds.
Financing
The event grid webhook endpoint now validates the
X-API-KEYheader on all incoming requests.
Other changes
OpenBank redirect URIs are now validated, and CORS origins are sourced from the operations whitelist.