# Changelog

3 releases published for this instance, newest first. 0 of them declare breaking changes.

## Release 2026.07.441

2026-07-20

WinkPG Release 2026.07.441

### Payments & Transactions
- Added support for sending the original network transaction ID on eligible Visa stored-credential authorizations for TSYS and Fiserv, improving processor handling for these follow-on payments.
- Convenience fees are now automatically suppressed when card-brand rules do not allow them, such as certain card-present and recurring/installment scenarios.
- Hosted Payment Page sessions can now send webhooks when a customer saves a card or bank account for future use.
- ACH validation has been strengthened with routing-number checksum checks and stricter format validation, helping catch invalid bank details earlier.
- ACH payment details now receive the same sensitive-data protections already applied to card data.
- The Hosted Payment Page now supports ACH for save-with-initial-charge flows when enabled for the merchant.
- Account-verification transactions are now shown in transaction lists and transaction details.
- Customers can now save an ACH payment method without an immediate charge by using an internal verification step.
- Recurring and merchant-initiated ACH payments can now be charged using a previously saved payment method.
- Transaction source values are now stamped by the server for save-card requests, preventing clients from mislabeling how a transaction was initiated.
- Virtual Terminal ACH payments can now capture authorization evidence for TEL and PPD transaction types.
- Locked-amount Hosted Payment Page sessions now enforce the full total server-side, including any locked tax, shipping, and convenience fee amounts.
- Save-only Hosted Payment Page sessions are now allowed for ACH-capable merchants.
- Fixed-amount Hosted Payment Page pages now enforce the configured amount on the server, not just in the browser.
- Save-only Hosted Payment Page sessions can now hide the card option when zero-dollar card verification is not available.
- Hosted Payment Page payment results now include digital wallet as a payment method where applicable.
- TSYS authorization processing can now capture and retain the processor token at authorization time.
- VeriCheck v2 ACH transactions now sync return and settlement status updates back into WinkPG.
- Apple Pay certificate selection now uses the public key hash, improving reliability when multiple certificates are available.
- VeriCheck v2 ACH status sync now retries transient failures more gracefully, and the reconciliation lookback window is configurable.
- The Hosted Payment Page now uses clearer “Save Payment Method” wording, shows no-charge messaging that matches the selected payment type, and offers in-app save-only flows for ACH-capable merchants.

### Security & Access
- Paze payment tokens are now verified against Paze signing keys before they are trusted, adding an extra layer of protection against tampered wallet payloads.
- The Paze signing-key endpoint is now available without authentication so wallet key retrieval works correctly.

### User Experience
- The Hosted Payment Page create-session dialog now shows the session’s amount mode, making it clearer whether the amount is fixed, suggested, or customer-entered.
- The Hosted Payment Page create payment link dialog now includes copyable API request JSON to make setup and troubleshooting easier.
- When a Hosted Payment Page session uses a locked amount, the streamlined page now shows that amount as read-only text.

### Bug Fixes
- Fixed a Hosted Payment Page validation issue that could reject valid save-card-with-initial-charge pages when card was the only payment method offered.
- Fixed an issue where ACH save-only Hosted Payment Page webhooks could use the wrong completed payment type.
- Fixed a transaction screen issue that could prevent the application from loading after ACH authorization evidence fields were added.
- Fixed TSYS settlement parsing for approved card-not-present e-commerce transactions.
- Fixed a Hosted Payment Page issue so successful Classic page completions keep the correct session ID for downstream processing.
- Fixed merchant usage billing to use ledger data instead of delayed aggregate data, improving billing accuracy.

## Release 2026.07.363

2026-07-20

WinkPG Release 2026.07.363

### Payments & Transactions
- Added support for caller-supplied idempotency keys on transaction operations, helping prevent accidental duplicate processing when the same request is retried.
- Hosted Payment Page sessions can now control how the payment amount is handled, including customer-entered, suggested, or locked amounts.
- Added a chargeable public reference to Hosted Payment Page webhook events and transaction responses to make downstream reconciliation and follow-up actions easier.
- Added support for capturing and returning the required NACHA WEB single-debit authorization on ACH payments completed through the Hosted Payment Page.
- Merchants can now override the ACH WEB authorization text shown on the Hosted Payment Page using a template.
- Convenience fees are now blocked for card-not-present configurations where they should not be allowed.
- Added a stable error code for requests that are rejected because the transaction is not in a valid state for that operation, making integrations easier to handle consistently.
- Added the foundation for processor routing, improving support for directing transactions through the appropriate processing path.

### Security & Access
- Apple Pay requests now include signature verification for stronger validation of Apple Pay payment data.
- API keys now support access controls at the individual record level for more precise permission management.
- Added an endpoint to create API keys for merchant users with scope checks applied.
- Transaction history now redacts an internal payment token value that should not have been exposed through the API.

### Reporting & Settlement
- Dashboard view controls have been consolidated into a single toolbar menu to reduce clutter and make reporting options easier to find.

### User Experience
- The Streamlined Hosted Payment Page now validates non-card fields in real time, helping customers correct issues before submitting payment.
- Merchant-defined custom fields now appear on the Streamlined Hosted Payment Page for a more consistent experience across payment surfaces.
- The Hosted Payment Page session setup now includes a selector for stored-credential consent scope.
- Save-card choices on the Hosted Payment Page have been simplified by replacing conflicting checkboxes with a single behavior selector.
- In preview mode, the Hosted Payment Page now disables the Pay button and updates its label to make it clearer that no live payment will be submitted.

### Bug Fixes
- Fixed an issue where deleting or updating customers with stored ACH payment methods could fail.
- Fixed a configuration issue that could prevent the application from loading correctly after recent transaction-processing changes.
- Fixed a similar startup issue related to idempotency tracking on transactions that could cause pages to hang or fail to load.
- Fixed transaction creation and initialization so routing information is preserved correctly during parallel processing.
- Fixed partial updates so card-not-present-only settings are preserved when processor profile data is omitted from the request.
- Updated asset loading so customer-facing pages resolve CDN-hosted files correctly across environments.

## Release 2026.07.309

2026-07-20

WinkPG Release 2026.07.309

### Payments & Transactions
- Added support for saving a card on the Hosted Payment Page with an initial charge, including recurring-plan setup for future billing.
- Added installment-based payment plans so invoice balances can be split into scheduled payments.
- Added a stored payment method picker when setting up invoice payment plans, so staff can enable automatic collection from a saved card.
- Added a Force transaction type for voice authorizations in the Virtual Terminal.
- Added a Sale/Authorize capture-mode option for Hosted Payment Pages, making delayed capture flows available from HPP checkout.
- Added per-transaction soft descriptor overrides at settlement.
- Added direct card entry for merchant billing stored payment methods in the admin experience.
- Added direct ACH entry for merchant billing stored payment methods, so staff can securely save bank-account details without sending the payer to a separate page.
- Added the ability to send a secure payment-method capture link to a merchant, with status tracking, resend, cancel, and automatic completion handling.
- Added the ability to reactivate a previously stored but inactive merchant billing payment method.
- Improved recurring merchant billing so charge requests are tracked through completion, linked to the resulting transaction, and can be retried when a recurring charge fails.
- Made recurring billing dispatch more resilient so duplicate or interrupted background processing is less likely to create billing issues.
- Added clearer billing-run results, including reasons a merchant was skipped and a distinction between no usage and usage that stayed within allowance.
- Added support for canceling a billing run with optional attribution and reason tracking.
- Added convenience-fee options for fixed or percentage fees, plus debit and prepaid exemptions where allowed.
- Added convenience-fee disclosure confirmation in the Virtual Terminal and a platform-managed disclosure block on Hosted Payment Pages when a fee is shown.
- Added transaction decision notes on the transaction detail page to explain certain system-generated outcomes more clearly.
- Added support for stored-credential and card-on-file indicators needed by processors for card-on-file and recurring payment scenarios.
- Added support for Paze wallet authorization through TSYS after secure token decryption.
- Improved processor behavior for Fiserv and TSYS in several payment flows, including $0 auth, reversals, partial reversals, partial approvals, refunds, voids, offline adjustments, Level 3 data, and brand handling.
- Added support for processor metadata discovery and boarding endpoints for integrations that need to configure processor connections.

### Customer Management
- Customer names now accept punctuation and accented characters, so common real-world names no longer fail validation.
- Fixed updates to stored customer payment methods so edits now save correctly and the update action no longer gets stuck.
- Customer records now prevent saving empty or partial addresses.
- Added a merchant picker when creating a customer, with scope checks so users can only assign customers to merchants they are allowed to access.
- Added merchant-facing self-service custom field management, with reseller control over whether merchants can edit these fields themselves.
- Stored customer payment methods now enforce only one default card and one default ACH/check method at a time.

### Security & Access
- Added a current-sessions page under My Account so users can review and revoke their own active sessions.
- Added a stricter Content Security Policy for the public Hosted Payment Page to better protect checkout sessions.
- Improved Hosted Payment Page security policy handling so required real-time connections continue to work correctly across browsers while keeping CSP protections in place.
- API-key authenticated requests are now exempt from anti-forgery validation, improving compatibility for server-to-server integrations.
- Added merchant and permission scoping to payment-token APIs to better protect access to stored payment methods.
- Improved impersonation and scope handling so admins and delegated users see the correct data more reliably without getting stranded in empty views.
- Strengthened telemetry privacy controls by scrubbing sensitive request details from external monitoring data.

### Reporting & Settlement
- Added refund-status indicators, entry mode details, and new filters to Transaction Explorer, making it easier to understand how a payment was made and whether refunds are still pending.
- Added reverse refund linkage so you can navigate from a sale to its related refunds more easily.
- Added settlement batch controls and visibility improvements, including batch-number override tools, processor-aware current batch views, retry options, auto-refresh, failure reasons, duration tracking, and dashboard tiles for batch status and failures.
- Settlement history now records zero-transaction outcomes and shows net amounts more clearly.
- Added Hosted Payment Page interaction reporting, including funnel reporting, dashboard widgets, and conversion charts.
- Added invoicing dashboard tiles for aging, status mix, and collection rate.
- Added self-service usage reporting under My Account so reseller and merchant users can review their own current-period usage.
- Added support for multiple saved dashboard views per scope, including create, clone, rename, delete, set default, and automatic restoration of the active view.

### User Experience
- Improved page titles and navigation behavior in the dashboard and other admin pages.
- Cleaned up user-facing text across the product.
- Added address autocomplete across more admin and payment-entry surfaces, with improved suggestions, autofill behavior, and layout polish.
- Added onboarding tours, guided setup flows, and Getting Started experiences across merchant, reseller, settlement, invoicing, and user-management areas.
- Added self-service settings pages and editing tools for merchant and reseller users, including support for reseller-overridable settings.
- Added a View reseller shortcut from the merchant edit page and improved related navigation and labeling.
- Added a reusable searchable merchant picker and improved merchant search performance in selection lists.
- Added a searchable multi-select merchant/reseller picker for user scope management.
- Added in-app guides, contextual help, and a consolidated Help & Resources entry point.

## See also

- [All documentation](https://devportal-simpay-sbx.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
