API changelog

Every change, dated, including the ones that were corrections.

All notable changes to the Stria Partner API contract are documented here.

Format follows Keep a Changelog principles.

[1.2.0] — 2026-08-09

Fixed

  • **updated_since is now a real modification delta on GET /api-v1/projects and

GET /api-v1/clients** (migration 20261114000000). Both routes previously sorted on

created_at, so an edit never appeared in a poll: a renamed or reassigned client, and

a project moving active → completed, were invisible. The response was 200 with an

empty page, so an integration had no signal that it had gone stale.

projects has carried an updated_at column and trigger since migration

20260624037000; the route did not use it because of an incorrect comment stating the

column did not exist. clients.updated_at is new, backfilled from created_at rather

than from the migration timestamp — so a record never edited does not report as edited,

and the first sweep after upgrading is not a full resync.

Action: none. A client that ignored updated_since is unaffected; a client that

used it starts receiving the modifications it should always have received. If you

built a workaround that re-reads the full collection nightly, you can now narrow it.

Added

  • updated_at on the Project and Client response schemas — the cursor and

updated_since sort key for those resources.

Changed

  • invoice:issue is reserved, not grantable (migration 20261114000100). It remains

published in the scope catalogue, and create_api_token now refuses it with `Scope not

available yet` (distinct from the error for an unknown scope). No endpoint has ever

honoured it, so it granted nothing; it was possible to mint a token holding it, which

would have meant the permission arriving pre-authorised if issuing later shipped.

Tokens already holding invoice:issue are unaffected and continue to authenticate —

the point of reserving the name is that no re-mint is needed when the capability lands.

[1.0.0] — 2026-07-12

Added

  • Documented partner API surface: GET /api-list-clients, POST /api-create-deliverable.
  • OpenAPI 3.1 specification (openapi.yaml).
  • Enterprise documentation set under docs/api/.

Security

  • Enforced api_access plan capability on:

- create_api_token / create_webhook_endpoint (Postgres)

- Partner API request path (Edge Functions)

  • Fixed-window rate limit: 60 requests / organization / minute.
  • Structured 403 (upgrade_required / api_access) and 429 (rate_limit_exceeded) responses.

Notes

  • Prior to 1.0.0, the two Edge Functions existed for Zapier/Figma but were not entitlement-gated; any org admin could mint tokens. Operators should audit tokens created before this release on non-entitled plans and revoke as needed.

More reference

  • Authentication — How tokens are minted, stored, presented and revoked.
  • Endpoints — Every request and response shape, with worked examples.
  • Outbound webhooks — Signed HTTPS POSTs when work is signed off, a change order moves, or an invoice is paid — plus how to verify one and how to survive a duplicate.
  • Rate limits — Per organization, per minute, and published rather than discovered as a random failure.
  • Errors — What each status means, what the body carries, and which ones to retry.
  • Compatibility and versioning — What may change without notice, what may not, and how you are told.

OpenAPI specification · API access is on every paid plan · Start your 14-day trial