Changelog and compatibility
Current contract notes and compatibility guidance for Carden's provider APIs and seven server SDKs.
On this page
Current documented contract
Reviewed against implemented public v1 routes, provider permissions, the checked-in seven-language SDK release catalog, and current Stripe payment-line-item guidance on September 28, 2026. This is an implementation review date, not a guarantee that external requirements remain unchanged.
| Area | Contract note |
|---|---|
| Identity | WorkOS AuthKit identifies people; merchant membership and explicit permissions authorize actions. |
| QuickBooks | Intuit OAuth authorizes the source; bounded import, incremental checkpoints, and reconciliation remain separate from readiness. |
| Provider links | QuickBooks links independently to Stripe or Square inside one merchant and environment; existing keys are unchanged. |
| Invoices v1 | invoice.list and invoice detail expose imported facts, readiness, revisions, and source provenance. |
| Stored preparation | Exact full unpaid invoice preparation returns provider fields plus immutable preparation; preparation.id correlates reports. |
| Stripe | Inline CanonicalInvoice enrichment and immutable merchant-reported PaymentIntent observations remain separate resources. |
| Square | Inline or linked Order enrichment and immutable merchant-reported Payment observations remain separate resources. |
| Outbound webhooks | Carden events use timestamp/body HMAC and event identity for idempotent consumers. |
Provider-first documentation routes
QuickBooks, Stripe, and Square now have ordered trees for overview, setup, linked-source work, SDK usage where applicable, API contracts, and troubleshooting. Shared authentication, SDK installation, errors, webhooks, platform operations, evidence, and security remain single-source.
Previous public documentation URLs permanently redirect to canonical provider-first routes. Canonical metadata, navigation, search, sitemap, product links, package metadata, and tests use only the new destinations.
SDK package status
The release catalog contains Node.js, Ruby, Python, PHP, Java, Go, and .NET package coordinates. Every entry is currently preview and unpublished, so no public version or registry install command is asserted. Carden supplies approved preview artifacts directly; direct HTTP remains available.
Provider SDK examples remain available for all seven native languages plus HTTP under the Stripe and Square integration trees. Shared language pages contain release state, client configuration, common errors, and links to provider usage.
Compatibility checklist
- Confirm endpoint path and object/api_version envelope.
- Run canonical source and provider fixtures without fabricating newly required facts.
- Run report retries, duplicate acknowledgment, unknown outcome, capture, and refund tests.
- Verify no helper can repeat payment after report failure.
- Exercise raw-body webhook signature verification and duplicate delivery.
- Validate merchant, environment, provider, and key scope before cutover.