October 2026
2026-10-05
- Payments Library: Documented the result summary fields added in Payments Library 1.11.10:
selectedPaymentMethod,transactionAmount,transactionCurrency,transactionTimestamp,providerTransactionId,providerAuthorizationCode,providerAccountIdand theattemptshistory. See Validate Operation Results and the library reference. - Google Pay: Corrected the Google Pay Setup page: PCI Booking uses Google’s Direct integration, and registration needs the PCI Booking public encryption key and the full Attestation of Compliance, both available from support.
- Universal Payment Gateway: Added gateway guidance for SLIM CD and SumUp, and documented both Payzone 3D Secure pending codes (521 and 524).
2026-10-02
- Documentation: New Working with Third Parties page explaining how the four ways of passing card data to and from third parties fit together, with examples.
- Token sharing: Documented that a customer a token is shared with can share it onward, and the new
DelegationChainfield. See Third-Party Permissions. - Universal Payment Gateway: Documented the 29-second limit and that a timeout is an unknown result, not a failure. See Timeouts.
- Payments Library: Documented how Apple Pay and Google Pay payments are processed, and how to choose the billing and shipping details the payer is asked for. See Supported Payment Methods and Library Reference.
- 3D Secure: Documented the case where your payment provider performs the authentication itself. See 3DS Merchant Setup.
- Property Management: Now closed to new accounts. Existing integrations continue to be supported.
- Card storage regions: Documented the regions where card data can be stored, the default, and how to choose a region per request. See Card Storage Regions.
- Documentation: Minor corrections and clarifications across many pages, including gateway-specific guidance, sandbox limits, Card By Link webhooks, PCI scope and SAQ guidance, and network tokenization.
2026-10-01
- Documentation: New complete checkout example with the HTML page and server code (Node.js and C#) for capturing a card with 3D Secure and charging it through the Universal Payment Gateway.
- Documentation: New Live Demos page listing the demo pages, now linked from the related guides.
- Documentation: Clarified how the card entry form reports results through postMessage, what
UnavailThreeDSAuthcovers, and why 3D Secure test cards do not work with a live account.
September 2026
2026-09-29
- Documentation: Every page in the API reference now states which authentication the method accepts (API key, access token, session token, or none for public methods) and which it does not. See Authentication for how to use each option.
2026-09-27
- Documentation: The Introduction now says who PCI Booking is for, and every page points to one place to request a sandbox account.
- Documentation: Reference pages corrected against the API’s actual behaviour, including error responses, UPG transaction responses, Store 3DS, rate limits, CVV retention, user permissions, token replacement and SFTP/FTPS.
2026-09-25
- Fallback payment gateways: Documented automatic retry of a declined charge through other payment gateway accounts, in the order you choose, for the Universal Payment Gateway and the Payments Library. See Fallback Payment Gateways.
- Access tokens and Card By Link: Documented that access tokens and Card By Link requests can be valid for up to 72 hours. See Authentication.
- sFTP and FTPS: Documented deleting a file on a remote server, for example a source file that contained card data. See Delete File from sFTP or FTPS.
- Card display form: Documented the
removeBaseCssparameter. See Request Card Display Form. - Card entry form: Documented the full list of session properties and the webhook statuses. See Create Card Entry Form Session.
2026-09-15
- Content filters: Documented the
renameattribute for card data fields. See Content Filters.
2026-09-07
- Moving to production: New guide on importing sandbox configuration into your production account, and what must be recreated. See Moving Configuration to Production.
August 2026
2026-08-28
- Card entry form: Documented how to restrict the card brands the form accepts. See Hosted Card Entry Form.
2026-08-23
- Customization: New guides for General Customization and Email Templates.
- BankPay: Documented the supported countries and currencies. See BankPay Setup.
2026-08-19
- Token use: New page comparing the Universal Payment Gateway and Token Replacement. See UPG vs Token Replacement.
- Payments Library: Documented the CardPay stored cards capability. Pass up to 3 previously tokenized cards in the session creation request to let returning customers pay with a saved card by entering only its CVV. See Supported Payment Methods.
July 2026
2026-07-03
- New PSP: Added Fabrick (Payment Orchestra) as a new payment gateway integration in the Universal Payment Gateway, supporting MOTO transactions via Fabrick’s REST API.
June 2026
2026-06-24
- New PSP: Added PayWay (payway.com.au) as a new payment gateway integration in the Universal Payment Gateway: Charge, PreAuth, Capture, Void and Refund. 3D Secure is not yet available on PayWay.
2026-06-17
- New PSP: Added CreditGuard as a new payment gateway integration in the Payments Library.
- eWallet Library: Added CardPay
GATEWAY_TOKENIZEoperation and CardPay iframe display mode. Added Pelecard as a bank provider.
2026-06-15
- Fix: eWallet payments processed via NEXI with Apple Pay or Google Pay now correctly populate the 3DS “ppo” parameter sent to NEXI.
2026-06-11
- Fix: Resolved a bug in 3DS data tokenization affecting Universal Tokenization and Tokenization on Response flows.
May 2026
2026-05-31
- New PSP: Added Checkout.com as a new payment gateway integration in the Universal Payment Gateway.

