What changed in each version of the Screen & Protect API, the fields and endpoints affected, whether the change was breaking, and what an integrator needed to do about it.
Dates are production release dates.
What changed. A new optional field, protection.currency, sets the currency a verification request is invoiced in, which is also the currency of its startingLevel and extendedAmount: one of GBP, USD, EUR, AUD, CAD, ZAR, CHF, PLN. Omitting it means the account's currency, as before. One account can now be invoiced in more than one currency. The amounts accepted are the same in every currency. Retrieve a verification request returns it as protection.currency: the currency sent on create, or the account's currency when none was sent.
Fields affected. protection.currency, on Create and on Retrieve.
Breaking. No: the field is optional, and a request without it is handled exactly as before. A currency outside the supported list is rejected with 400: currency must be one of (GBP, USD, EUR, AUD, CAD, ZAR, CHF, PLN).
Integrator action. None required. Send currency when a verification request should be invoiced in a currency other than the account's.
What changed. protection.startingLevel now accepts 0 on Complete Protection. Sending 0 is the same as omitting the field, which still means a starting level of 0. The other values are unchanged.
Fields affected. protection.startingLevel, on Create.
Breaking. No: nothing that was accepted before is rejected now, and a startingLevel of 0, which used to be rejected with 400, is now accepted. The 400 message for an unsupported value now lists 0: startingLevel must be one of (0, 250, 500, 1000, 5000, 10000).
Integrator action. None required. Send 0 or omit the field.
What changed. A new endpoint, GET /v1/verificationRequests/{verificationId}, which returns the current record of a verification created by Create or by Screening Only. Dates and pet values changed by Modify, and a cancellation, show as they are now. It takes no body and no echo token, and its metadata carries timeStamp only, on a success and on an error.
Endpoints affected. The new endpoint only. Create, Modify, Cancel and Screening Only are unchanged.
Breaking. No. The endpoint is new, and nothing that was accepted before is rejected now.
Integrator action. None required. See Retrieve a verification request to use it.