Changelog
Every change to the ZyloPay public API, newest first.
Changes to the public API, newest first. Breaking changes ship only in a new dated version; see Versioning.
2026-09-28: API v1
The first public version of the ZyloPay API.
- API version
2026-09-28(the only dated version). - Resources: payment intents (create, retrieve, list, cancel), payments (retrieve, list), refunds (create, retrieve, list), terminals (retrieve, list), balance, events (30 days), webhook endpoints and deliveries.
- API keys:
zp_test_…(testnet sandbox) andzp_live_…(mainnet), scopes, IP allowlist, expiry, rotation with overlap, audit log. - Webhooks: 16 event types, signed with
ZyloPay-Signature(HMAC-SHA256), retried for 3 days, automatic disabling of failing endpoints, secret rotation with dual signatures, test events and resends. - Conventions:
Idempotency-Key(required for payment intents and refunds, 48-hour replay), cursor pagination, one error format with stable codes,Request-Id,RateLimit-*headers.
Known limitations
- The ZyloPay POS app picks up API-created payment intents from the release that adds intent pickup, which is rolling out. Terminal-started payments are fully visible through the API and webhooks.
- Withdrawals and payouts are not in the API. Use the dashboard.
- Publishable keys (
zp_…_pk_…) have no access yet. @zylopay/nodeis pre-release.