Changelog and versioning
How the AllyOneMail API evolves without breaking your integration, and what changed on each date.
Versioning
The version is part of the URL (/api/v1, /api/v2). Within a version only compatible changes ship: a new route, a new response field, a new optional parameter, a new value in a response enum, a new event. Removing or renaming a route or field, changing a type or making an optional parameter required only happens in a new version. Ignore fields you don't know.
Deprecation
A deprecated route or field keeps working for at least 90 days after it is announced here. A previous version stays up for at least 12 months after the next one launches. Security fixes may change behavior immediately and always appear here.
Availability
Component availability, public and unauthenticated: GET https://smtp.allyone.com.br/api/status.
History
2026-10-06
- Security The audit trail is now immutable at the database level: no changes are accepted to records (action, actor, entity, before/after state and date), not even from database administrators. The only exception is the automatic anonymization of the IP address and user agent after 365 days, performed by a dedicated routine with restricted permissions, in line with LGPD data minimization. No change is required in your integration.
2026-10-05
- Fix Recording an email open could overwrite the status of other interactions on the same message (for example, a click recorded minutes earlier turned into "opened"). Each interaction now keeps its own status.
- New The Operations panel (Command Center) now has an "All clients" filter for agency accounts, and the rollup sums the whole agency.
- Fix Uniqueness violations (for example, registering an IP or domain that already exists on the platform) now return
409instead of500. - Fix Pausing an IP manually logged the incident without linking it to the agency and client that own the IP; the incident now shows up for the IP owner.
- Security Isolation between agencies and clients is now also enforced in the database (row-level security), in addition to the API: a query made in the context of one agency cannot see another agency's data. No change is required in your integration.
- Security The DKIM signature now also covers the
List-UnsubscribeandList-Unsubscribe-Postheaders (RFC 8058), which protects one-click unsubscribe against tampering. No change is required in your integration. - Fix The plain-text version of emails used to come out with junk (Outlook conditional comments, hidden preview text and entities such as
‌). It is now generated clean and short, with links preserved, including the unsubscribe link.
2026-10-01
- Fix Webhooks: every event goes through the same delivery path, with up to 3 attempts (right away, ~1 min, ~2 min) and automatic pause after 10 consecutive failures — previously opens, clicks, complaints and unsubscribes had a single attempt.
blockedandincident_escalatedcan now be subscribed to. - Security
/api/v2routes now require a scope (sendfor sending and customer SMTP,readfor senders). Webhook delivery no longer follows redirects and pins the validated IP. - Fix Login and the other authentication routes respond
400(no longer500) when a field is missing.GET /api/statusno longer exposes the count of customer incidents. - Docs Fixed route paths (
/api/v1/...,/api/v2/messages,/api/v1/auth/me), the key prefix (zm_live_) and the per-key limit. New pages: Errors and limits and this Changelog.
2026-09-24
- New Data subject rights through the API:
/api/v1/privacy/exportand/erasure, with the newprivacyscope;suppressscope to only add suppressions. - Fix One-click unsubscribe fixed; suppression is now case-insensitive.
2026-09-23
- Fix Webhook deliveries had been failing since 09-21 due to a DNS-resolution bug in the SSRF protection. If you missed events in that period, resend them from the delivery history.
- Change The public reference at
/docsnow lists only the integration API.
2026-09-16
- New
POST /api/v2/messageswithidempotency_key: retrying a send never duplicates the email.
