Skip to documentation content

Changelog and compatibility

Current contract notes and compatibility guidance for Carden's provider APIs and seven server SDKs.

On this page

Current documented contract

Reviewed against implemented public v1 routes, provider permissions, the checked-in seven-language SDK release catalog, and current Stripe payment-line-item guidance on September 28, 2026. This is an implementation review date, not a guarantee that external requirements remain unchanged.

AreaContract note
IdentityWorkOS AuthKit identifies people; merchant membership and explicit permissions authorize actions.
QuickBooksIntuit OAuth authorizes the source; bounded import, incremental checkpoints, and reconciliation remain separate from readiness.
Provider linksQuickBooks links independently to Stripe or Square inside one merchant and environment; existing keys are unchanged.
Invoices v1invoice.list and invoice detail expose imported facts, readiness, revisions, and source provenance.
Stored preparationExact full unpaid invoice preparation returns provider fields plus immutable preparation; preparation.id correlates reports.
StripeInline CanonicalInvoice enrichment and immutable merchant-reported PaymentIntent observations remain separate resources.
SquareInline or linked Order enrichment and immutable merchant-reported Payment observations remain separate resources.
Outbound webhooksCarden events use timestamp/body HMAC and event identity for idempotent consumers.

Provider-first documentation routes

QuickBooks, Stripe, and Square now have ordered trees for overview, setup, linked-source work, SDK usage where applicable, API contracts, and troubleshooting. Shared authentication, SDK installation, errors, webhooks, platform operations, evidence, and security remain single-source.

Previous public documentation URLs permanently redirect to canonical provider-first routes. Canonical metadata, navigation, search, sitemap, product links, package metadata, and tests use only the new destinations.

SDK package status

The release catalog contains Node.js, Ruby, Python, PHP, Java, Go, and .NET package coordinates. Every entry is currently preview and unpublished, so no public version or registry install command is asserted. Carden supplies approved preview artifacts directly; direct HTTP remains available.

Provider SDK examples remain available for all seven native languages plus HTTP under the Stripe and Square integration trees. Shared language pages contain release state, client configuration, common errors, and links to provider usage.

Compatibility checklist

  1. Confirm endpoint path and object/api_version envelope.
  2. Run canonical source and provider fixtures without fabricating newly required facts.
  3. Run report retries, duplicate acknowledgment, unknown outcome, capture, and refund tests.
  4. Verify no helper can repeat payment after report failure.
  5. Exercise raw-body webhook signature verification and duplicate delivery.
  6. Validate merchant, environment, provider, and key scope before cutover.

The evidence boundary remains unchanged