API changelog: 2026
Every change to the Kintsugi API in 2026, newest first. For the latest changes and every release, see the API changelog.
2026-10-02
Applies one access rule to every address changeAddresses
The five endpoints that change addresses now accept the same callers: any member of the organization, a portfolio Owner or Admin who manages it, or an API key for the organization. A portfolio Member now receives 403 with code forbidden from POST /addresses/approve, which accepted them before. The other four, which accepted only the organization's Owner among its own users, now also accept its Admins and Members, who received 403 before. An organization you cannot access still answers 404, and API keys work on all five as before.
- Have a portfolio Owner or Admin approve addresses, or approve with the organization's API key.
- Handle
403with codeforbiddenfromPOST /addresses/approve. - If your app hid these address actions from organization Admins and Members, you can now offer them.
Keeps an address's unincorporated setting when an edit leaves it outAddresses
Editing a transaction address through PUT /addresses/transactions or PATCH /transactions/{transaction_id}/addresses used to reset its unincorporated setting to false, so changing only a street or postal code could apply city tax rates to an address outside city limits. Both endpoints now accept an optional isUnincorporated: true keeps city rates from applying, false clears the setting, and leaving it out or sending null keeps the saved value. A new address created by an edit is saved as false when the field is left out. Changing only this setting on a verified address keeps it verified and recalculates the transaction's tax. Transaction addresses in responses now include isUnincorporated.
- Review
isUnincorporatedon addresses you edited through these endpoints before this fix. - Send
isUnincorporatedonly when you mean to change it.