Announcements

Platform updates, deprecation notices, and other things you should know about.

New

V2 API Keys & Endpoints

Released March 2026

We have introduced a new unified API key system following industry-standard conventions. V2 keys replace the three legacy authentication mechanisms (Standard API Key, Passport OAuth JWT, and Publishable Token) with a single, consistent format.

  • Secret keys (bapi_sk_live_… / bapi_sk_test_…) - for server-side requests. Keep these private.
  • Publishable keys (bapi_pk_live_… / bapi_pk_test_…) - for client-side or browser-based requests, optionally restricted to whitelisted domains.
  • The environment (live vs test) is determined by the route prefix (/api/v2/* for live, /api/test/v2/* for test) - no more testTransmissionIndicator field in the request body.
  • Keys can be rolled instantly or with a 24-hour grace period, and managed from your Dashboard.

We recommend all new integrations use V2 keys. See the Authentication guide for full details.


Upcoming

V1 Endpoints & Auth Keys - Planned Deprecation

The legacy V1 authentication mechanisms and endpoints will be deprecated in a future release. This includes:

  • Standard API Key (Authorization: Bearer <token> via the old key format)
  • Passport OAuth2 JWT tokens
  • Publishable tokens
  • V1 route prefix (/api/v1/* and /api/test/v1/*)

From 10 April 2026, legacy authentication credentials (Standard API Key, Passport OAuth JWT, and Publishable Token) will no longer be accepted. V1 endpoints (/api/v1/*) will continue to function until 10 May 2026, but only with V2 credentials.

To migrate, generate a new V2 key from your Dashboard and update your integration to use V2 credentials. Refer to the Authentication guide and the Endpoints Summary for the updated route structure.


Info

Platform & Gateway Status

We publish real-time uptime information for all Business API services and the external gateways we depend on (ASIC, ATO, ABR, payment processors, and email providers) on our Status Page.

If an external gateway is temporarily unavailable, your lodgements are not lost. Every request is queued and transmitted to the gateway automatically as soon as connectivity is restored - no action is required from you.

We encourage you to bookmark the Status Page so you can check the health of individual services at any time.