General · Help
Changelog
Notable changes to Monato APIs and docs. Today only Fincore publishes a changelog.
This page tracks changes that might make you adjust code, business logic, monitoring or expectations. Today only Fincore publishes release notes. For questions about a release, write to support@monato.com.
Each entry has a type (Added, Changed, Removed, Fixed or Security) and impact tags:
| Tag | Meaning |
|---|---|
| Breaking | Requires changes to avoid failures. |
| Behavior | Outcomes or rules changed, but not necessarily breaking. |
| Operational | Affects retries, delivery, latency or runtime expectations. |
| Docs | Documentation only, no functional change. |
| Security | Security-related change. |
2026-05-07 · Fincore
Money Out unified routing.
Changed: Money Out unified routing
Tags: Behavior
POST /v1/transactions/money_out now handles both external and internal transfers. When the destination instrument belongs to a Finco Pay (Monato) account, the transaction is routed as an internal book-to-book transfer automatically. No SPEI is used, settlement is near-real-time and the request body does not change. The response subCategory is SPEI_DEBIT for external and INT_DEBIT for internal transfers.
Action: none for existing integrations. New integrations should use POST /v1/transactions/money_out for all outbound transfers.
Changed: Money In webhook sub_category
Tags: Docs
INT_CREDIT can now come from POST /v1/transactions/money_out when the destination belongs to a Finco Pay account.
Action: none. If you filter on sub_category: INT_CREDIT, it behaves the same whatever the originating endpoint.
Migration notes: new integrations should use POST /v1/transactions/money_out for all outbound transfers, both external (SPEI) and internal (Finco Pay). No flags or extra fields are needed; routing is automatic based on the destination instrument.
See Send money to a CLABE and Receive money.
2026-03-13 · Fincore
Private account lifecycle.
Added: Private Account Lifecycle guide
Tags: Docs
A new guide explains the public lifecycle actions for private accounts, with supported state transitions and example requests.
Action: read it if you need to block, reactivate or permanently cancel private accounts.
Added: cancel, block and activate endpoints
Tags: Behavior, Docs
- Cancel permanently:
PUT /v1/clients/{clientId}/accounts/{accountId}/cancel - Block temporarily:
PUT /v1/clients/{clientId}/accounts/{accountId}/block - Restore a blocked account to
ACTIVE:PATCH /v1/clients/{clientId}/accounts/{accountId}/activate
Changed: Quickstart links to lifecycle management
Tags: Docs
The Quickstart now points to the lifecycle guide after you create a private account.
Action: none.
See Private accounts.
2026-03-11 · Fincore
Idempotency docs update.
Fixed: canonical JSON hashing
Tags: Docs
The Idempotency guide now explains how to compute body_hash: canonicalize the request body first, sorting object keys alphabetically at every level and serializing consistently.
Action: review your code if you generate deterministic Idempotency-Key values yourself, especially outside Python.
Fixed: Python and Node.js key generation samples
Tags: Docs
The samples have clearer comments and normalization logic. No backend behavior changed.
Action: if you copied an earlier sample, check that semantically identical payloads, including nested objects, give the same hash.
Migration notes:
- Sort object keys consistently before you compute the SHA-256 hash.
- Keep UUID v5 generation unchanged:
name = client_id + method + body_hashandIdempotency-Key = UUIDv5(namespace, name). - If you copied an earlier example into production, check it against the canonicalization rules.
See Idempotency.
2026-01-28 · Fincore
When internal transfers emit MONEY_IN.
Changed: Money Out webhook emission rules
Tags: Docs, Operational
For internal routing through POST /v1/transactions/money_out:
- The API response returns the debit (source) leg.
- The credit leg can trigger a
MONEY_INwebhook only when the destination instrument belongs to a differentowner_idthan the initiator, even under the sameclient_id. - Self-transfers under the same
client_idandowner_iddo not generate aMONEY_INevent. - Use the dashboard “resend webhook” only when a webhook event exists. Self-transfers have nothing to resend.
Action: if your automation expects MONEY_IN for every internal transfer, stop expecting INT_CREDIT for self-transfers. Confirm and reconcile them with the API response or transaction reads.
Changed: MONEY_IN internal credits note
Tags: Docs
The MONEY_IN reference now states that INT_CREDIT is emitted only for inbound credits to a different owner, explains that owner_id is the receiving owner, and shows how to tell external from internal credits with sub_category and payer_institution.
Action: none.
See Receive money.
2026-01-07 · Fincore
Penny Validation description and external_reference.
Added: Penny Validation request fields
Tags: Behavior
POST /v1/transactions/penny_validation now accepts:
description(optional): up to 40 characters, letters, numbers and spaces only. No special characters exceptñandÑ.external_reference(optional): numeric string, up to 7 digits.
Action: none. Both fields are optional.
Changed: backend defaults
Tags: Behavior
If you leave them out, the backend sets description to "Validacion de cuenta" and external_reference to the operation date as ddmmaa (for example, 24/11/2025 becomes "241125").
Action: if you relied on empty values, update your expectations.
Changed: propagation to reads and webhook
Tags: Behavior, Operational
Both fields now appear in GET /v1/clients/{clientId}/transactions/{transactionId} and in the CEP webhook payload (for example payment_concept and external_reference).
Action: you can store them for reconciliation and traceability.
2026-01-05 · Fincore
JWT-first authentication, client-scoped webhooks and the changelog launch.
Added: public changelog
Tags: Docs
Track API and documentation changes in one place, with daily release notes.
Added: client-scoped webhook management
Tags: Behavior, Operational
Manage webhooks per client:
GET /v1/clients/{clientId}/webhooks: list webhooksPOST /v1/clients/{clientId}/webhooks: create a webhookGET /v1/clients/{clientId}/webhooks/{id}: retrieve a webhookPATCH /v1/clients/{clientId}/webhooks/{id}: update a webhookDELETE /v1/clients/{clientId}/webhooks/{id}: delete (soft-delete) a webhook
Action: prefer the client-scoped endpoints for all webhook operations.
Added: WebhookUpdateRequest schema
Tags: Behavior
Update a webhook partially, for example url, token, webhook_status or optional auth_* fields.
Action: send only the fields you want to change.
Changed: JWT-first authentication
Tags: Behavior, Operational
x-api-key is now bootstrap-only: use it to get a JWT. After that, send only Authorization: Bearer <JWT>.
Action: stop sending x-api-key on operational calls. Keep it only for JWT bootstrap flows (reference: POST /v1/clients/{clientId}/auth/credential-tokens).
Changed: CEP webhook for Penny Validation
Tags: Docs, Operational
The CEP webhook fires only for Penny Validation transactions (amount = 0.01 MXN). INITIALIZED can appear on API reads but is never sent by the CEP webhook. Treat it as PENDING.
Action: do not expect INITIALIZED events in your CEP webhook consumer.
Migration notes:
- JWT-first auth: use
x-api-keyto obtain a JWT, then useAuthorization: Bearer <JWT>for all subsequent API calls. - Webhook creation: use the client-scoped endpoint
POST /v1/clients/{clientId}/webhooks.
See Authentication and Fincore webhook events.