September 2026: safer transfers, faster updates, payroll approvals by API
Nothing you have built stops working. Review the items marked Action if you reuseclientReference values or retry failed transfers automatically.
Transfers
clientReferenceis now a strict idempotency key. Sending the same reference again with the same amount and destination returns the original transfer instead of sending a second one. A reused reference with a different amount or destination is refused with409 CLIENT_REFERENCE_CONFLICT. Action: use a new reference for every new transfer. Idempotency- Timeouts no longer refund. If the bank network does not answer, the send
returns
202 Acceptedwith the transfer pending, instead of refunding and inviting a retry that could pay twice. Action: never resend on a202; wait for the webhook or poll status. Unknown outcome - Automatic refunds on final declines. A transfer declined with a final code (for example insufficient funds or invalid account) is refunded, fee included, straight away. Other declines are reviewed first.
- Faster outcomes.
transfer.settledandtransfer.failednow arrive within about 10 minutes instead of the next day, and carry thefee. GET /money-transfer/statusreturnssettlementStatus(pending,delivered,failed,reversed) and thefee.
Webhooks
- New events:
transfer.reversed,wallet.funded,wallet.balance.low. - New headers:
X-Hyparrow-Event,X-Hyparrow-Timestamp, andX-Hyparrow-Signature-256(HMAC-SHA256 overtimestamp.body) for replay protection.X-Hyparrow-Signatureis unchanged. - Retries now run the full documented schedule, up to 24 hours. Webhooks
Wallet
- Low-balance alert. Set a level on your wallet page or with
PUT /wallet/low-balance-alertand get notified once per drop. wallet.fundedfires when a deposit is credited.
Payroll
- Approval mandates. An integration can approve the payroll it creates by API, within limits you arm once in the dashboard with your authenticator code. API approval mandates
Reconciliation
GET /transactions/exportreturns a CSV statement for a date range, withclientReferenceon transfers, fees and reversals.GET /transactionsnow caps pages at 200 rows. Export a statement
Idempotency-Key header
- A key reused with a different body now returns
422 IDEMPOTENCY_KEY_REUSED. - Only successful responses are remembered, so a request refused with a
4xx(for example insufficient balance) can be retried with the same key.
Sandbox
- Transfer amounts ending in
.01are rejected and refunded,.99stay pending, and.98return202for a transfer that went through. Settlement webhooks now fire in the sandbox. Sandbox

