API changelog
Every change, dated, including the ones that were corrections.
All notable changes to the Stria Partner API contract are documented here.
Format follows Keep a Changelog principles.
[1.2.0] — 2026-08-09
Fixed
- **
updated_sinceis now a real modification delta onGET /api-v1/projectsand
GET /api-v1/clients** (migration 20261114000000). Both routes previously sorted on
created_at, so an edit never appeared in a poll: a renamed or reassigned client, and
a project moving active → completed, were invisible. The response was 200 with an
empty page, so an integration had no signal that it had gone stale.
projects has carried an updated_at column and trigger since migration
20260624037000; the route did not use it because of an incorrect comment stating the
column did not exist. clients.updated_at is new, backfilled from created_at rather
than from the migration timestamp — so a record never edited does not report as edited,
and the first sweep after upgrading is not a full resync.
Action: none. A client that ignored updated_since is unaffected; a client that
used it starts receiving the modifications it should always have received. If you
built a workaround that re-reads the full collection nightly, you can now narrow it.
Added
updated_aton theProjectandClientresponse schemas — the cursor and
updated_since sort key for those resources.
Changed
invoice:issueis reserved, not grantable (migration20261114000100). It remains
published in the scope catalogue, and create_api_token now refuses it with `Scope not
available yet` (distinct from the error for an unknown scope). No endpoint has ever
honoured it, so it granted nothing; it was possible to mint a token holding it, which
would have meant the permission arriving pre-authorised if issuing later shipped.
Tokens already holding invoice:issue are unaffected and continue to authenticate —
the point of reserving the name is that no re-mint is needed when the capability lands.
[1.0.0] — 2026-07-12
Added
- Documented partner API surface:
GET /api-list-clients,POST /api-create-deliverable. - OpenAPI 3.1 specification (
openapi.yaml). - Enterprise documentation set under
docs/api/.
Security
- Enforced
api_accessplan capability on:
- create_api_token / create_webhook_endpoint (Postgres)
- Partner API request path (Edge Functions)
- Fixed-window rate limit: 60 requests / organization / minute.
- Structured
403(upgrade_required/api_access) and429(rate_limit_exceeded) responses.
Notes
- Prior to 1.0.0, the two Edge Functions existed for Zapier/Figma but were not entitlement-gated; any org admin could mint tokens. Operators should audit tokens created before this release on non-entitled plans and revoke as needed.
More reference
- Authentication — How tokens are minted, stored, presented and revoked.
- Endpoints — Every request and response shape, with worked examples.
- Outbound webhooks — Signed HTTPS POSTs when work is signed off, a change order moves, or an invoice is paid — plus how to verify one and how to survive a duplicate.
- Rate limits — Per organization, per minute, and published rather than discovered as a random failure.
- Errors — What each status means, what the body carries, and which ones to retry.
- Compatibility and versioning — What may change without notice, what may not, and how you are told.
OpenAPI specification · API access is on every paid plan · Start your 14-day trial