Semantic versioning. Breaking changes (fields renamed, endpoints removed, auth scheme changed) only land in a new major version under a new URL prefix /v2/. Within /v1/ only additive changes happen (new optional fields, new endpoints).
v1.1.0 (2026-09-23)
- POST /v1/orders: config_options only accepts options and values that are visible in the shop, and quantities within their limits. Visible options you omit receive the first listed value, exactly like in the shop. GET /v1/products/{id} lists only orderable options and returns quantity.min and quantity.max.
- New order status awaiting_setup with the field awaiting_setup for products that the KernelHost team sets up manually. Automatically provisioned services are provisioned exactly once.
- Request bodies are limited to 64 KB (HTTP 413). A per-account limit of 120 requests per minute applies across all keys, and an account can hold up to 20 active keys. Failed authentication no longer locks a key, and the Idempotency-Key is bound to method and path.
- Requests with more than one query parameter (for example GET /v1/services?limit=10&offset=0) were rejected with HTTP 401. The signature now covers the query string exactly as documented.
v1.0.0 (2026-05-14)
- Initial release. All 15 endpoints, HMAC auth, AES-GCM secret storage, rate limits, idempotency, audit log.
- GET
/v1/me,/v1/products,/v1/products/{id} - POST
/v1/orders, GET/v1/orders/{id} - GET
/v1/services,/v1/services/{id},/v1/services/{id}/credentials - POST
/v1/services/{id}/actions - GET
/v1/billing/balance,/v1/billing/invoices,/v1/billing/invoices/{id}/pdf - GET/PUT
/v1/webhooks - HMAC-SHA256 signing, AES-256-GCM secret storage, replay protection, idempotency.

