Changelog
What changed in the UPINOW API and integrations, newest first.
On this page
28 Sep 2026
- The orders API now answers
429 rate_limited(with aretry_afterfield and aRetry-Afterheader) once an address or API key sends too many requests a minute. - Merchants can now hold more than one UPI account. Create-order, get-order, list-orders and the
embedded widget gain an optional
payment_account_id(orpaymentAccountId) field; leaving it out keeps using your default account, exactly as before. Two new errors:400 invalid_payment_accountand402 payment_account_paused(withupgrade_url).
27 Sep 2026
402 plan_limit_reachednow includesupgrade_urland usage fields (plan,limit_paise,collected_paise,resets_on).- A business inside its account-deletion window now answers
403 merchant_disabled, the same as any other disabled business:GET /orders/{id}andGET /ordersnow answer it too, not only create.
23 Sep 2026
- New base path
/api/v1; the older/api/public/v1paths are kept as aliases. - On
/api/v1, the API key is accepted only in a header (no?api_key=or JSON body field there). - New API keys start with
upn_live_. - Webhooks now carry a
typefield (payment.paid,payment.expired,payment.failed); the oldereventfield and theX-Eventheader keep their old names. GET /api/v1/ordersadded: list your orders with cursor paging.X-Webhook-Idis now unique per delivery attempt.- Webhook delivery now has a 10-second deadline for the whole exchange, does not follow redirects, and refuses a URL that resolves to a private address.
- The embedded widget is now served at
/embed/upinow.jswithUPINOW.mount; the older/embed/panme-pay.jsfile andPanMePayname are kept.