> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hyparrow.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Changelog

> What changed in the Hyparrow API, and what, if anything, you need to do.

## September 2026: safer transfers, faster updates, payroll approvals by API

Nothing you have built stops working. Review the items marked **Action** if you
reuse `clientReference` values or retry failed transfers automatically.

### Transfers

* **`clientReference` is now a strict idempotency key.** Sending the same
  reference again with the same amount and destination returns the original
  transfer instead of sending a second one. A reused reference with a different
  amount or destination is refused with `409 CLIENT_REFERENCE_CONFLICT`.
  **Action:** use a new reference for every new transfer.
  [Idempotency](/money-transfer#idempotency)
* **Timeouts no longer refund.** If the bank network does not answer, the send
  returns `202 Accepted` with the transfer pending, instead of refunding and
  inviting a retry that could pay twice. **Action:** never resend on a `202`;
  wait for the webhook or poll status. [Unknown outcome](/money-transfer#unknown-outcome-202)
* **Automatic refunds on final declines.** A transfer declined with a final
  code (for example insufficient funds or invalid account) is refunded, fee
  included, straight away. Other declines are reviewed first.
* **Faster outcomes.** `transfer.settled` and `transfer.failed` now arrive
  within about 10 minutes instead of the next day, and carry the `fee`.
* **`GET /money-transfer/status`** returns `settlementStatus` (`pending`,
  `delivered`, `failed`, `reversed`) and the `fee`.

### Webhooks

* New events: `transfer.reversed`, `wallet.funded`, `wallet.balance.low`.
* New headers: `X-Hyparrow-Event`, `X-Hyparrow-Timestamp`, and
  `X-Hyparrow-Signature-256` (HMAC-SHA256 over `timestamp.body`) for replay
  protection. `X-Hyparrow-Signature` is unchanged.
* Retries now run the full documented schedule, up to 24 hours.
  [Webhooks](/webhooks)

### Wallet

* **Low-balance alert.** Set a level on your wallet page or with
  `PUT /wallet/low-balance-alert` and get notified once per drop.
* **`wallet.funded`** fires when a deposit is credited.

### Payroll

* **Approval mandates.** An integration can approve the payroll it creates by
  API, within limits you arm once in the dashboard with your authenticator
  code. [API approval mandates](/payroll#api-approval-mandates)

### Reconciliation

* **`GET /transactions/export`** returns a CSV statement for a date range, with
  `clientReference` on transfers, fees and reversals. `GET /transactions` now
  caps pages at 200 rows. [Export a statement](/transactions#export-a-statement)

### Idempotency-Key header

* A key reused with a different body now returns `422 IDEMPOTENCY_KEY_REUSED`.
* Only successful responses are remembered, so a request refused with a `4xx`
  (for example insufficient balance) can be retried with the same key.

### Sandbox

* Transfer amounts ending in `.01` are rejected and refunded, `.99` stay
  pending, and `.98` return `202` for a transfer that went through. Settlement
  webhooks now fire in the sandbox. [Sandbox](/sandbox)
