Changelog¶
Changes to TransactAPI that affect your integration: a change in how an endpoint behaves, a deprecation, a removal, or anything that needs action on your side. Changes that need action are announced here at least 30 days before they take effect. Dates are when a change reached production.
Upcoming¶
November 1, 2026: card and bank link URLs expire¶
Starting November 1, 2026, each URL returned by these endpoints is valid for 24 hours after it is generated and for one successful completion:
| Endpoint | One completion |
|---|---|
linkCreditCard | One card saved |
updateLinkedCreditCard | One card saved |
linkExternalAccount | One bank account linked |
updateLinkExternalAccount | One bank account linked |
Reopening the page within the 24 hours still works, including after a failed Plaid attempt. The URL's params value becomes a fixed 64-character string. URLs generated before November 1 keep working for 24 hours after the change.
What to do: request a new URL each time an investor links or replaces a card or bank account, instead of storing and reusing one. Treat the URL as opaque. See Credit Card and ACH.
Past¶
September 29, 2026¶
- SMS notifications removed. The SMS notification option is removed from the Transact Portal webhook pages.
- Replacing a bank account through Plaid.
updateLinkExternalAccountnow works for accounts whose bank account was entered withupdateExternalAccount.
September 28, 2026¶
createCustodyFundMovewebhook. The deposit status is now sent understatus, matchingupdateCustodyFundMove. It was previously sent under the key0. See Webhooks.updateKycAmlwebhook. Clients with more than one URL registered forupdateKycAmlnow receive one delivery per URL.
September 24, 2026¶
- HTTPS webhook URLs. Webhook URLs that do not use HTTPS are rejected when saved.
getApiCountdeprecated. See Serverless APIs.
September 10, 2026¶
- Webhook encryption key length. A new or changed webhook payload encryption key must be exactly 32 characters with no whitespace. Leave it empty for unencrypted webhooks. Existing keys are not affected: webhooks keep using them, and other settings can be saved without changing them. See Setting Up Encrypted Webhooks.
August 18, 2026¶
createTradefees.feesmust be a non-negative number; other values return error code106. The minimum and maximum purchase check now applies to the trade amount including fees. SeecreateTrade.
August 13, 2026¶
- Webhook request headers. Every webhook delivery sends
User-Agent: NorthCapital-TAPI/1.0, andX-NC-Tokenwhen identification tokens are set up for your organization. See Identifying Webhook Traffic. - Unchanged trade status updates. When an
updateTradeStatuscall changes nothing, it no longer adds an entry topartyDetailsingetTradeand no longer sends theUpdate-Trade-Statuswebhook.