Changelog

Changes to the public /api/v1 surface. Entries that could alter an existing integration's behaviour are marked Behaviour change; everything else is additive.

We do not make breaking changes inside v1 — see versioning.


2026-10-04

GET /orders/{id} now accepts an order reference. Previously it matched on the resource id alone, so GET /orders/SMP-ALGQS4ATP returned 404 even though POST /orders/SMP-ALGQS4ATP/cancel on the same order worked. Both endpoints now take either form. Existing calls using resource ids are unaffected.

Documentation. Added Quickstart, API conventions and this changelog. Documented the OAuth 2.0 flow, which had been available but entirely undocumented, and POST /orders/estimate, which shipped undocumented.


2026-09-27

Added: POST /orders/{id}/cancel. Cancel and refund an order in full, within one hour of placing it. After that the work has been released to a print partner. Previously this endpoint returned 501.

Added: POST /orders/estimate. Prices a basket through the same code path as order creation, charging and reserving nothing. Requires only orders:read.

Added: Webhooks. Seven order events delivered to an HTTPS endpoint you own, signed with HMAC-SHA256. Manage subscriptions at /webhooks.

Added: products write API. Create, update and archive customer products via POST, PATCH and DELETE /products/{id}.

Behaviour change: sandbox mode removed. The portal issues pat_live_ tokens only. pat_test_ tokens never isolated anything — the prefix was a label, and orders placed with one were charged and fulfilled like any other. Existing pat_test_ tokens keep working unchanged; no new ones can be issued. See Testing safely.

Behaviour change: order totals round at source. Money fields on POST /orders responses and webhook payloads are now rounded to 2 decimal places before they reach you. Previously a total could surface as 15.984. The amount charged never changed — only its representation.

Fixed: mockup_url returned a bare storage key rather than a fetchable URL.

Fixed: a product's decorated areas are now exposed, and ordering a print area the product does not carry is rejected rather than silently accepted.

Fixed: the per-IP 429 now carries the same X-RateLimit-* headers as the per-token one, with X-RateLimit-Scope distinguishing them. See Errors & rate limits.