Changelog
This page lists the changes to the merchant API and dashboard. The newest changes are first. Each date is the date of the production release that contained the change. A new code or a new field is not a breaking change. A changed or removed code or field has the label Breaking.
3 October 2026
Wallet API and webhooks
- Breaking: BLOX now credits a token deposit a short time after confirmation, not at confirmation. A confirmed deposit now has the status
PROCESSINGuntil BLOX credits it. Then the status changes toCOMPLETED. This usually takes a few minutes after confirmation. On Ethereum, it takes longer when network fees are high. SeeGET /v1/wallet/deposits/{id}. - Breaking: BLOX sends
wallet.deposit.updatedandpayout.deposit.updatedtwo times for each deposit. BLOX sends the event one time atPROCESSINGand one time atCOMPLETED. OnlyCOMPLETEDtells you that the tokens are in your wallet. A trigger address starts its bank transfer only afterCOMPLETED. See Wallet Webhook Events. - BLOX sends deposit webhook events for Solana deposits. BLOX now sends both deposit events for deposits on Solana.
- Retry a deposit returns
400 INVALID_REQUESTuntil the deposit isCOMPLETED.
10 September 2026
Payout API
- Name check rules.
strictnow compares with the name as it is on the IC of the account holder.strictaccepts punctuation, accents, and a title that the bank adds. It also acceptsBINorBINTIon one side only, and a long name that the field of the bank truncated.looseaccepts all names thatstrictaccepts.loosealso accepts a name in a different order, or a part of the name. For example: different word boundaries, the surname at the other end, one holder of a joint account, or one side of an@alias. It also accepts a name of two or more words that the name at the bank contains. See Create beneficiary. BENEFICIARY_NAME_MISMATCHno longer returns the holder name from the bank. Ifstrictfails on a name thatlooseaccepts, the message gives only this information. See Payout Errors.- Sandbox
7777changed. Punctuation now passesstrict. Thus, this suffix now returns your name with different word boundaries. For example, BLOX returnsACMESDNBHDforACME SDN BHD. With this suffix,strictfails andloosepasses. See Sandbox Testing.
2 September 2026
Payout API
- BLOX checks every beneficiary with the bank. When you register a beneficiary or send one inline, the bank confirms that the account number is valid for the selected bank. If the bank rejects the account, the request fails with
400 INVALID_REQUEST. If BLOX cannot connect to the bank, the response is503 SERVICE_UNAVAILABLE. In this case, BLOX creates nothing. Retry with the sameIdempotency-Key. See Step 4: Choose the beneficiary. - Optional name check. Send
nameCheck: "strict"or"loose"on Create beneficiary or on an inlinebeneficiary. BLOX then compares the name that you send with the holder name at the bank. If the names do not agree, the request fails with400 BENEFICIARY_NAME_MISMATCH. If the bank cannot give a result for the name, the response is400 NAME_CHECK_UNAVAILABLE. To register the beneficiary without verification, retry withoutnameCheck. - Verify a registered beneficiary.
POST /v1/payouts/beneficiaries/{id}/verifydoes the bank check and the name check on a beneficiary that you already registered. It records the result on the beneficiary. A payout with abeneficiaryIddoes not do a new check. - New fields on the Beneficiary object.
bankAccountVerified,bankAccountVerifiedAtandbankAccountNameMatchshow the result of the last check. - New error codes.
BENEFICIARY_NAME_MISMATCHandNAME_CHECK_UNAVAILABLE. Both have the status400. Payout Errors lists them. - Fixed: BLOX no longer returns
503for a400error in your request. Before this change, BLOX sometimes stopped payout creation for a period. During that period, BLOX returned503 SERVICE_UNAVAILABLEforINSUFFICIENT_BALANCE. It also returned503for an amount that was less than the RM1 minimum after the fee. BLOX now returns400for these errors at all times. This changes the retry rule for these errors. BLOX keeps a400response for 24 hours. Thus, correct the request and send it with a new key. Do not retry with the same key. - An idempotency key collision now returns the code
422 CONFLICT. Before this change, a request that used a key again with a different body returnedVALIDATION_FAILED.VALIDATION_FAILEDis also the code for a malformed body. The status did not change. This change applies to every/v1route that accepts anIdempotency-Key. See Idempotency. - BLOX removed an unwanted colon from validation messages. Before this change, messages for body-level rules started with
:. For example, "Provide exactly one of beneficiaryId or beneficiary". Field-level messages keep theirfield:prefix. - A repeat registration returns the existing beneficiary. If you register a destination that you already registered, BLOX returns the existing beneficiary. BLOX does not create a duplicate. This applies to the API and to the dashboard. A repeat registration does not use an active-beneficiary slot.
- Sandbox suffixes for bank checks. There are two new suffixes for account numbers:
8888(different name at the bank) and7777(same name, more punctuation). The suffix9999(the bank rejects the account) continues to operate. All three suffixes apply to every check. See Sandbox Testing.
Merchant dashboard
- API failures page. This page lists every
4xxresponse to a payout API request in the last 30 days. Each row shows therequestId, method, path, status,code,message, and theIdempotency-Keythat you sent. You can search byrequestIdorIdempotency-Key, and filter by status or code. The page does not list401,429, and5xxresponses. See Payout Errors. - Verify account holder name is available on a registered beneficiary. Beneficiaries and bank accounts show the bank-check status and the name-match level.
- Beneficiary lists refresh after each payout. Deposits and withdrawals show the user who created them.
User guide
- Bank accounts use the name on your BLOX account. BLOX writes the holder name from your verified account. You cannot edit the holder name. BLOX sends each transfer to a linked account in that name. See Bank Accounts.
24 August 2026
Payout API
- DuitNow proxy beneficiaries. A beneficiary can be a DuitNow proxy instead of a bank account. The proxy is a mobile number, NRIC, passport, business registration, or army number. Each beneficiary has exactly one destination. See Create beneficiary.
- Fixed: BLOX no longer reports a payment network outage as an invalid beneficiary. If a temporary failure at the bank occurs during a beneficiary check, BLOX now returns
503 SERVICE_UNAVAILABLE. Before this change, BLOX returned400 INVALID_REQUEST. - The default active-beneficiary limit increased to 10,000 from 1,000. If you exceed the limit, BLOX returns
403 LIMIT_EXCEEDED. - Prefund top-up by bank transfer. FPX top-up of the prefund balance is not available. To add money to the prefund balance, send a bank transfer from the dashboard.
Onramp API
- The minimum FPX top-up is RM10.
15 August 2026
Payout API
GET /v1/payouts/active-bankslists the banks that can receive payouts. If a beneficiary is at a bank that is not on that list, BLOX rejects it with400 UNKNOWN_BENEFICIARYwhen you create it. Thus, you do not get a reversed payout later.- Merchants can select who pays the payout fee in the payout settings of the dashboard.
Wallet API and webhooks
- Breaking: the
WALLETwebhook type replaces theAUTO_WITHDRAWALwebhook type. BLOX did not move the existing auto-withdrawal endpoints to the new type. Register them again onWALLETorPAYOUT. See Webhooks. - BLOX now sends
wallet.withdrawal.updatedfor fiat withdrawals. This includes the fiat withdrawals that you create directly withPOST /v1/wallet/fiat/withdrawals. BLOX sends a webhook event for every token deposit on the channel that owns the deposit. - You can disable an allowed sender and keep it. Send
PATCH .../address/whitelist/{senderId}with{ "active": false }. Requests that change the whitelist have a rate limit. See Onchain Trigger. - New routes on the wallet and payout channels let you get a deposit, check for a missed deposit, and retry a deposit.
Onramp API
- Breaking:
POST /v1/checkoutmust containtype. The value isBLOX_ACCOUNT,FPX_HOSTED, orFPX_DIRECT. If the body does not containtype, BLOX returns400. See Onramp API.