Skip to content
LogoLogo

Changelog

This page lists the changes to the merchant API and dashboard. The newest changes are first. Each date is the date of the production release that contained the change. A new code or a new field is not a breaking change. A changed or removed code or field has the label Breaking.

3 October 2026

Wallet API and webhooks

  • Breaking: BLOX now credits a token deposit a short time after confirmation, not at confirmation. A confirmed deposit now has the status PROCESSING until BLOX credits it. Then the status changes to COMPLETED. This usually takes a few minutes after confirmation. On Ethereum, it takes longer when network fees are high. See GET /v1/wallet/deposits/{id}.
  • Breaking: BLOX sends wallet.deposit.updated and payout.deposit.updated two times for each deposit. BLOX sends the event one time at PROCESSING and one time at COMPLETED. Only COMPLETED tells you that the tokens are in your wallet. A trigger address starts its bank transfer only after COMPLETED. See Wallet Webhook Events.
  • BLOX sends deposit webhook events for Solana deposits. BLOX now sends both deposit events for deposits on Solana.
  • Retry a deposit returns 400 INVALID_REQUEST until the deposit is COMPLETED.

10 September 2026

Payout API

  • Name check rules. strict now compares with the name as it is on the IC of the account holder. strict accepts punctuation, accents, and a title that the bank adds. It also accepts BIN or BINTI on one side only, and a long name that the field of the bank truncated. loose accepts all names that strict accepts. loose also accepts a name in a different order, or a part of the name. For example: different word boundaries, the surname at the other end, one holder of a joint account, or one side of an @ alias. It also accepts a name of two or more words that the name at the bank contains. See Create beneficiary.
  • BENEFICIARY_NAME_MISMATCH no longer returns the holder name from the bank. If strict fails on a name that loose accepts, the message gives only this information. See Payout Errors.
  • Sandbox 7777 changed. Punctuation now passes strict. Thus, this suffix now returns your name with different word boundaries. For example, BLOX returns ACMESDNBHD for ACME SDN BHD. With this suffix, strict fails and loose passes. See Sandbox Testing.

2 September 2026

Payout API

  • BLOX checks every beneficiary with the bank. When you register a beneficiary or send one inline, the bank confirms that the account number is valid for the selected bank. If the bank rejects the account, the request fails with 400 INVALID_REQUEST. If BLOX cannot connect to the bank, the response is 503 SERVICE_UNAVAILABLE. In this case, BLOX creates nothing. Retry with the same Idempotency-Key. See Step 4: Choose the beneficiary.
  • Optional name check. Send nameCheck: "strict" or "loose" on Create beneficiary or on an inline beneficiary. BLOX then compares the name that you send with the holder name at the bank. If the names do not agree, the request fails with 400 BENEFICIARY_NAME_MISMATCH. If the bank cannot give a result for the name, the response is 400 NAME_CHECK_UNAVAILABLE. To register the beneficiary without verification, retry without nameCheck.
  • Verify a registered beneficiary. POST /v1/payouts/beneficiaries/{id}/verify does the bank check and the name check on a beneficiary that you already registered. It records the result on the beneficiary. A payout with a beneficiaryId does not do a new check.
  • New fields on the Beneficiary object. bankAccountVerified, bankAccountVerifiedAt and bankAccountNameMatch show the result of the last check.
  • New error codes. BENEFICIARY_NAME_MISMATCH and NAME_CHECK_UNAVAILABLE. Both have the status 400. Payout Errors lists them.
  • Fixed: BLOX no longer returns 503 for a 400 error in your request. Before this change, BLOX sometimes stopped payout creation for a period. During that period, BLOX returned 503 SERVICE_UNAVAILABLE for INSUFFICIENT_BALANCE. It also returned 503 for an amount that was less than the RM1 minimum after the fee. BLOX now returns 400 for these errors at all times. This changes the retry rule for these errors. BLOX keeps a 400 response for 24 hours. Thus, correct the request and send it with a new key. Do not retry with the same key.
  • An idempotency key collision now returns the code 422 CONFLICT. Before this change, a request that used a key again with a different body returned VALIDATION_FAILED. VALIDATION_FAILED is also the code for a malformed body. The status did not change. This change applies to every /v1 route that accepts an Idempotency-Key. See Idempotency.
  • BLOX removed an unwanted colon from validation messages. Before this change, messages for body-level rules started with : . For example, "Provide exactly one of beneficiaryId or beneficiary". Field-level messages keep their field: prefix.
  • A repeat registration returns the existing beneficiary. If you register a destination that you already registered, BLOX returns the existing beneficiary. BLOX does not create a duplicate. This applies to the API and to the dashboard. A repeat registration does not use an active-beneficiary slot.
  • Sandbox suffixes for bank checks. There are two new suffixes for account numbers: 8888 (different name at the bank) and 7777 (same name, more punctuation). The suffix 9999 (the bank rejects the account) continues to operate. All three suffixes apply to every check. See Sandbox Testing.

Merchant dashboard

  • API failures page. This page lists every 4xx response to a payout API request in the last 30 days. Each row shows the requestId, method, path, status, code, message, and the Idempotency-Key that you sent. You can search by requestId or Idempotency-Key, and filter by status or code. The page does not list 401, 429, and 5xx responses. See Payout Errors.
  • Verify account holder name is available on a registered beneficiary. Beneficiaries and bank accounts show the bank-check status and the name-match level.
  • Beneficiary lists refresh after each payout. Deposits and withdrawals show the user who created them.

User guide

  • Bank accounts use the name on your BLOX account. BLOX writes the holder name from your verified account. You cannot edit the holder name. BLOX sends each transfer to a linked account in that name. See Bank Accounts.

24 August 2026

Payout API

  • DuitNow proxy beneficiaries. A beneficiary can be a DuitNow proxy instead of a bank account. The proxy is a mobile number, NRIC, passport, business registration, or army number. Each beneficiary has exactly one destination. See Create beneficiary.
  • Fixed: BLOX no longer reports a payment network outage as an invalid beneficiary. If a temporary failure at the bank occurs during a beneficiary check, BLOX now returns 503 SERVICE_UNAVAILABLE. Before this change, BLOX returned 400 INVALID_REQUEST.
  • The default active-beneficiary limit increased to 10,000 from 1,000. If you exceed the limit, BLOX returns 403 LIMIT_EXCEEDED.
  • Prefund top-up by bank transfer. FPX top-up of the prefund balance is not available. To add money to the prefund balance, send a bank transfer from the dashboard.

Onramp API

  • The minimum FPX top-up is RM10.

15 August 2026

Payout API

  • GET /v1/payouts/active-banks lists the banks that can receive payouts. If a beneficiary is at a bank that is not on that list, BLOX rejects it with 400 UNKNOWN_BENEFICIARY when you create it. Thus, you do not get a reversed payout later.
  • Merchants can select who pays the payout fee in the payout settings of the dashboard.

Wallet API and webhooks

  • Breaking: the WALLET webhook type replaces the AUTO_WITHDRAWAL webhook type. BLOX did not move the existing auto-withdrawal endpoints to the new type. Register them again on WALLET or PAYOUT. See Webhooks.
  • BLOX now sends wallet.withdrawal.updated for fiat withdrawals. This includes the fiat withdrawals that you create directly with POST /v1/wallet/fiat/withdrawals. BLOX sends a webhook event for every token deposit on the channel that owns the deposit.
  • You can disable an allowed sender and keep it. Send PATCH .../address/whitelist/{senderId} with { "active": false }. Requests that change the whitelist have a rate limit. See Onchain Trigger.
  • New routes on the wallet and payout channels let you get a deposit, check for a missed deposit, and retry a deposit.

Onramp API

  • Breaking: POST /v1/checkout must contain type. The value is BLOX_ACCOUNT, FPX_HOSTED, or FPX_DIRECT. If the body does not contain type, BLOX returns 400. See Onramp API.