Changelog and versioning
How the CRM API evolves without breaking your integration, and what changed on each date.
Versioning
The version is part of the URL (/v1). Within a version only compatible changes ship: a new route, a new response field, a new optional parameter, a new value in a response enum, a new event. Removing or renaming a route or field, changing a type or making an optional parameter required only happens in a new version. Ignore fields you don't know.
Deprecation
A deprecated route or field keeps working for at least 90 days after it is announced here. A previous version stays up for at least 12 months after the next one launches. Security fixes may change behavior immediately and always appear here.
Availability
There is no public CRM status page yet. To monitor from your side, a lightweight authenticated call (such as GET /v1/contacts?pageSize=1) once a minute is enough.
History
2026-10-01
- Fix An API key works with just
X-API-Key(it used to also requireX-Tenant-Slugand responded 400); the tenant comes from the credential. A key from another tenant and a call without credentials respond401. - New Webhooks: all 12 events now fire (
contact.updated,deal.created,survey.responded,campaign.completed,journey.enrolled,journey.completedwere accepted but never sent),score.rule_firedcan be subscribed to, the payload gains anidand theX-AllyOne-Eventheader carries the event type. - Security Rate limit per user (session) or per IP — no longer depends on a client-sent header. The webhook list shows the
secretmasked. - Docs New pages: Webhooks, Errors and limits and this Changelog. Fixed the Embedded Signup path (
/v1/waba-accounts/...) and the data location (European Union).
2026-09-28
- Security Login lockout per email + IP after wrong attempts; passwords found in public breaches are rejected.
2026-09-24
- New Per-channel consent and unsubscribe in forms and in the unsubscribe link.
- Change LGPD erasure of a contact propagates to AllyOneMail and deletes media; the data subject export includes conversations, messages, tickets, notes and orders.
2026-09-21 to 23
- Security SSRF and DNS-rebinding protection in webhook delivery and
send_webhookactions; redirects are no longer followed. Contact data export now requires thelgpd.*permission.
2026-09-22
- New WhatsApp through third-party BSPs (360dialog, Infobip, Gupshup, Blip), in addition to the Cloud API.
2026-09-16
- Change All CRM email sending goes through AllyOneMail (the CRM no longer speaks SMTP directly).
2026-09-09
- New
agentrole (an agent only sees conversations assigned to them), automatic assignment and conversation priority; Instagram DMs, comments and mentions in Chat Flow.
