Docs

General · Help

Changelog

Notable changes to Monato APIs and docs. Today only Fincore publishes a changelog.

This page tracks changes that might make you adjust code, business logic, monitoring or expectations. Today only Fincore publishes release notes. For questions about a release, write to support@monato.com.

Each entry has a type (Added, Changed, Removed, Fixed or Security) and impact tags:

Tag Meaning
Breaking Requires changes to avoid failures.
Behavior Outcomes or rules changed, but not necessarily breaking.
Operational Affects retries, delivery, latency or runtime expectations.
Docs Documentation only, no functional change.
Security Security-related change.

2026-05-07 · Fincore

Money Out unified routing.

Changed: Money Out unified routing

Tags: Behavior

POST /v1/transactions/money_out now handles both external and internal transfers. When the destination instrument belongs to a Finco Pay (Monato) account, the transaction is routed as an internal book-to-book transfer automatically. No SPEI is used, settlement is near-real-time and the request body does not change. The response subCategory is SPEI_DEBIT for external and INT_DEBIT for internal transfers.

Action: none for existing integrations. New integrations should use POST /v1/transactions/money_out for all outbound transfers.

Changed: Money In webhook sub_category

Tags: Docs

INT_CREDIT can now come from POST /v1/transactions/money_out when the destination belongs to a Finco Pay account.

Action: none. If you filter on sub_category: INT_CREDIT, it behaves the same whatever the originating endpoint.

Migration notes: new integrations should use POST /v1/transactions/money_out for all outbound transfers, both external (SPEI) and internal (Finco Pay). No flags or extra fields are needed; routing is automatic based on the destination instrument.

See Send money to a CLABE and Receive money.

2026-03-13 · Fincore

Private account lifecycle.

Added: Private Account Lifecycle guide

Tags: Docs

A new guide explains the public lifecycle actions for private accounts, with supported state transitions and example requests.

Action: read it if you need to block, reactivate or permanently cancel private accounts.

Added: cancel, block and activate endpoints

Tags: Behavior, Docs

  • Cancel permanently: PUT /v1/clients/{clientId}/accounts/{accountId}/cancel
  • Block temporarily: PUT /v1/clients/{clientId}/accounts/{accountId}/block
  • Restore a blocked account to ACTIVE: PATCH /v1/clients/{clientId}/accounts/{accountId}/activate

Tags: Docs

The Quickstart now points to the lifecycle guide after you create a private account.

Action: none.

See Private accounts.

2026-03-11 · Fincore

Idempotency docs update.

Fixed: canonical JSON hashing

Tags: Docs

The Idempotency guide now explains how to compute body_hash: canonicalize the request body first, sorting object keys alphabetically at every level and serializing consistently.

Action: review your code if you generate deterministic Idempotency-Key values yourself, especially outside Python.

Fixed: Python and Node.js key generation samples

Tags: Docs

The samples have clearer comments and normalization logic. No backend behavior changed.

Action: if you copied an earlier sample, check that semantically identical payloads, including nested objects, give the same hash.

Migration notes:

  1. Sort object keys consistently before you compute the SHA-256 hash.
  2. Keep UUID v5 generation unchanged: name = client_id + method + body_hash and Idempotency-Key = UUIDv5(namespace, name).
  3. If you copied an earlier example into production, check it against the canonicalization rules.

See Idempotency.

2026-01-28 · Fincore

When internal transfers emit MONEY_IN.

Changed: Money Out webhook emission rules

Tags: Docs, Operational

For internal routing through POST /v1/transactions/money_out:

  • The API response returns the debit (source) leg.
  • The credit leg can trigger a MONEY_IN webhook only when the destination instrument belongs to a different owner_id than the initiator, even under the same client_id.
  • Self-transfers under the same client_id and owner_id do not generate a MONEY_IN event.
  • Use the dashboard “resend webhook” only when a webhook event exists. Self-transfers have nothing to resend.

Action: if your automation expects MONEY_IN for every internal transfer, stop expecting INT_CREDIT for self-transfers. Confirm and reconcile them with the API response or transaction reads.

Changed: MONEY_IN internal credits note

Tags: Docs

The MONEY_IN reference now states that INT_CREDIT is emitted only for inbound credits to a different owner, explains that owner_id is the receiving owner, and shows how to tell external from internal credits with sub_category and payer_institution.

Action: none.

See Receive money.

2026-01-07 · Fincore

Penny Validation description and external_reference.

Added: Penny Validation request fields

Tags: Behavior

POST /v1/transactions/penny_validation now accepts:

  • description (optional): up to 40 characters, letters, numbers and spaces only. No special characters except ñ and Ñ.
  • external_reference (optional): numeric string, up to 7 digits.

Action: none. Both fields are optional.

Changed: backend defaults

Tags: Behavior

If you leave them out, the backend sets description to "Validacion de cuenta" and external_reference to the operation date as ddmmaa (for example, 24/11/2025 becomes "241125").

Action: if you relied on empty values, update your expectations.

Changed: propagation to reads and webhook

Tags: Behavior, Operational

Both fields now appear in GET /v1/clients/{clientId}/transactions/{transactionId} and in the CEP webhook payload (for example payment_concept and external_reference).

Action: you can store them for reconciliation and traceability.

See Validate a bank account.

2026-01-05 · Fincore

JWT-first authentication, client-scoped webhooks and the changelog launch.

Added: public changelog

Tags: Docs

Track API and documentation changes in one place, with daily release notes.

Added: client-scoped webhook management

Tags: Behavior, Operational

Manage webhooks per client:

  • GET /v1/clients/{clientId}/webhooks: list webhooks
  • POST /v1/clients/{clientId}/webhooks: create a webhook
  • GET /v1/clients/{clientId}/webhooks/{id}: retrieve a webhook
  • PATCH /v1/clients/{clientId}/webhooks/{id}: update a webhook
  • DELETE /v1/clients/{clientId}/webhooks/{id}: delete (soft-delete) a webhook

Action: prefer the client-scoped endpoints for all webhook operations.

Added: WebhookUpdateRequest schema

Tags: Behavior

Update a webhook partially, for example url, token, webhook_status or optional auth_* fields.

Action: send only the fields you want to change.

Changed: JWT-first authentication

Tags: Behavior, Operational

x-api-key is now bootstrap-only: use it to get a JWT. After that, send only Authorization: Bearer <JWT>.

Action: stop sending x-api-key on operational calls. Keep it only for JWT bootstrap flows (reference: POST /v1/clients/{clientId}/auth/credential-tokens).

Changed: CEP webhook for Penny Validation

Tags: Docs, Operational

The CEP webhook fires only for Penny Validation transactions (amount = 0.01 MXN). INITIALIZED can appear on API reads but is never sent by the CEP webhook. Treat it as PENDING.

Action: do not expect INITIALIZED events in your CEP webhook consumer.

Migration notes:

  1. JWT-first auth: use x-api-key to obtain a JWT, then use Authorization: Bearer <JWT> for all subsequent API calls.
  2. Webhook creation: use the client-scoped endpoint POST /v1/clients/{clientId}/webhooks.

See Authentication and Fincore webhook events.