← All API release notes

API v4 Release Notes — September 24, 2026

New

  • Download file contents from object_files — POST /{profile}/user/v4/object_files/{id}/download returns a short-lived, single-use link in meta.data (url, expires_in, expires_at, filename, content_type, size). Fetch it with a plain GET within 10 seconds; the link needs no Authorization header and always downloads as an attachment. It requires the same access as reading the file (Customer Files or Lead Files) plus access to the customer or lead. See the Object Files reference for resuming with Range and for the 404 returned by an expired, used, or revoked link.

Changed

  • Empty wallet is checked before the rate limit — A company with no tokens left now gets 402 rather than a 429 from per-token rate limiting, so the response says why the request was refused.
  • invoice_line_items ordering — Lines render in SecurityTrax, on the emailed invoice, and on the PDF in sort ascending order, then id. A line with no sort goes last. When a user saves an invoice in SecurityTrax, every line's sort is renumbered 1..N to match the on-screen order, replacing values set through the API.
  • customer_credit_checks TransUnion results — A TransUnion security freeze, suppressed file, minor, or disputed file now returns 422 credit_report_failed with a detail explaining the cause. These results won't change on retry until the consumer acts.

Fixed

  • Wrong HTTP method on a valid path — A request using a method a path doesn't support now returns 405 method_not_allowed with an Allow header listing the supported methods, instead of 500 internal.
  • Usage metering — Some API requests and MCP tools/call requests incorrectly weren't always recorded as usage; they now are. Customer and lead intake requests remain free.
  • Error handling guidance — The Requests and Responses reference now correctly recommends that clients fall back on the HTTP status for any code they don't recognize: don't retry a 4xx without changing the request, and retry a 5xx later.

Never miss an API change

Get an email when new API release notes are published, or follow the RSS feed.