Changelog

This page is for public product changes that matter to merchants and developers. Use it to understand what changed across hosted checkout, memberships, webhooks, SDKs, merchant operations, docs, and public integrations. Entries describe the product at the time of each release. Use the newest entry and the current product guides for today’s supported contract.

Common questions

What changes appear here?

This changelog covers public product changes that affect merchants, developers, integrations, buyer flows, or operational workflows.

Where is the public developer contract?

The supported public contract is represented by the developer docs, SDKs, Postman assets, and approved developer-assets snapshots. The changelog explains product-level changes in human language.

September 2026

  • Added Hilt Pay API MPP session channels for streaming and repeated Solana USDC usage
  • Added capped channel creation, cumulative voucher authorization, idempotent delivery reservation, durable delivery evidence, merchant inspection, and recovery settlement
  • Pinned the Solana mainnet payment-channel program and native USDC mint in every session contract
  • Added serialized PostgreSQL channel mutations and an expiry worker that settles only the highest voucher Hilt has already verified
  • Added payment-channel methods to TypeScript and Python SDK 1.5.0
  • Published the complete lifecycle, security model, fee-policy boundary, recovery behavior, and integration guide

August 2026

  • Added a public PayMe MPP payment action for wallet-capable agents to pay active verified handles in native SOL or Solana USDC without a payer account, OAuth grant, or Hilt API key
  • Added official HTTP 402 challenge and retry semantics, exact recipient-plus-fee transaction binding, durable replay protection, finalized-chain receipt recovery, and machine-readable payment receipts
  • Published the direct PayMe agent-payment contract across OpenAPI, docs, LLM files, sitemaps, and public agent discovery while keeping it separate from the OAuth PayMe MCP connector and Hilt Pay API x402 access
  • Added protectEndpoint to TypeScript SDK 1.4.0 so Fetch-compatible routes can enforce Hilt’s complete consume, HTTP 402, settle, consume, and serve sequence with one wrapper
  • Added protect_request to Python SDK 1.4.0 as the same framework-neutral paid-request decision boundary
  • Added a dedicated Protect an endpoint guide, runnable examples, endpoint-protection tests, and updated agent discovery for the new SDK workflow
  • Changed Hilt Pay API Live to $0/month plus a 1% fee on each successful settlement
  • Added native SOL as a live hosted-payment settlement option alongside Solana USDC
  • Kept Hilt x402 V2 on Solana USDC and native Solana subscriptions USDC-only
  • Added the native SOL hosted-payment path to API rail discovery, payment-session adapters, receipts, entitlements, webhooks, SDK types, docs, and agent discovery
  • Verified the native SOL flow end to end through one signed, expiring API checkout handoff, exact payment-session reuse, direct merchant settlement, a 1% fee, receipt creation, entitlement activation, and replay-safe confirmation
  • Published TypeScript SDK 1.3.0 and Python SDK 1.3.0 with native SOL hosted-session guidance and expanded payment-session fields
  • Retired new Hilt Pay API subscription checkout; historical billing records remain readable for existing accounts
  • Added an atomic PayMe flow for sending native SOL to two to five verified recipients with one wallet transaction approval
  • Added standard Solana Action discovery for PayMe profile links so Action-aware clients can render native SOL payments as Blinks
  • Added exact finalized-chain verification and group receipts for the new PayMe payment-order flow
  • Added PayMe Wallet Security for future receiving-wallet changes
  • Added current-wallet approval before Authenticator enrollment, standard six-digit TOTP codes, and single-use recovery codes
  • Added a wallet-recovery path that accepts Authenticator or a recovery code plus a signature from the new receiving wallet
  • Blocked self-service wallet replacement when the old wallet is inaccessible and Wallet Security was not enabled beforehand
  • Published a complete setup, recovery-scenario, and troubleshooting guide for PayMe recipients
  • Published first-class PayMe and Direct Checkout documentation with clear product and custody boundaries
  • Renamed the PayMe connector guide around the client-neutral remote MCP standard while preserving the previous URL as a redirect
  • Expanded the official WooCommerce guide with current runtime requirements, Checkout Blocks support, and canonical support paths
  • Added natural send payment instructions to the Hilt PayMe connector for compatible AI clients
  • Added durable outgoing payment IDs with wallet-approval, authorization, confirmation, expiry and cancellation state
  • Added sent and received PayMe activity with Solana transaction evidence when available
  • Added self-shared payment links and removed targeted payment requests from the connector’s advertised tools
  • Added cancellation for unapproved outgoing payments and unused payment links
  • Kept every outgoing payment subject to user wallet review and approval under Hilt’s zero-custody model

July 2026

  • Added x402 V2 settlement and atomic metered-entitlement consumption for paid agent requests
  • Added idempotent settlement reconciliation so retries can reuse a finalized Solana transaction without asking the buyer to pay again
  • Published TypeScript SDK 1.2.0 and Python SDK 1.2.0 with x402 V2 helpers, typed settlement methods, and usage-consumption methods
  • Published a complete agent micropayment reference implementation using current Solana Kit transaction and token clients
  • Added the AI-to-AI micropayment flow to Hilt’s article index, agent manifest, discovery catalog, LLM files, sitemap, and public developer assets
  • Confirmed that the July 2026 live settlement scope was Solana USDC and that x402 is the HTTP 402 Payment Required protected-resource protocol shape
  • Added a complete Grok Build integration guide for Hilt Pay API
  • Published a runnable Next.js protected-resource example with local, Hilt sandbox, and live modes
  • Added repository AGENTS.md rules and a Grok project skill for Hilt Pay API implementation and review
  • Added automated checks for HTTP 402 responses, x402 protocol wording, Solana USDC settlement wording, customer-bound confirmation, entitlement-gated access, and browser-safe responses
  • Added the Grok Build guide and example to Hilt’s agent manifest, catalog, discovery prompts, LLM files, docs sitemap, SDK READMEs, and public developer-assets export
  • Documented Agentverse MCP Lite as an optional Grok discovery path, separate from Hilt Pay API and settlement

June 2026

  • Native Solana USDC subscriptions are live across the merchant builder, Get Started wizard, merchant template docs, and Hilt Pay API docs
  • SDK and developer assets are updated to version 1.1.0, including structured errors, request ids, idempotency handling, webhook helpers, sandbox helpers, recurring examples, and refreshed Postman assets
  • Merchant renewal models are now clearer: one-off payments and native automatic renewals
  • Native automatic renewals are described as buyer-approved Solana USDC subscriptions, not generic background charging
  • Hilt’s native collection path keeps the operating layer intact: collection evidence, receipt records, membership period extension, webhook delivery, support context, analytics, and audit history
  • Native cancellation semantics are period-aware: future collection stops immediately while access can remain available through the paid-through date before post-period revoke or close handling
  • The quick-start wizard, Product Studio, and docs now present one-off and native automatic renewal products as distinct setup paths

May 2026

  • Hilt Pay API is now the primary developer and agent-facing surface for AI tools, APIs, bots, datasets, paid software, and private products
  • The Developers page now leads with Hilt Pay API, Agent Bootstrap, setup intents, x402 protected-resource protocol flows, Solana USDC settlement, SDKs, Postman, OpenAPI, and GitHub developer assets
  • Added an Agent setup guide covering sandbox setup intents, manifests, owner approval, rail settings, setup readiness, payment sessions, x402 HTTP 402 requirements, and entitlement checks
  • Pricing now separates Hilt Pay Workspace from Hilt Pay API, with API tiers for Sandbox, Starter, Growth, Scale, and Enterprise plus an API-specific estimator up to $1m/month
  • Hilt LLM files now describe the Workspace/API split, exact API pricing, x402 protocol boundary, Solana USDC settlement, and the current public settlement scope
  • Hilt Pay for WooCommerce is now approved on WordPress.org at wordpress.org/plugins/hilt-pay-for-woocommerce
  • WooCommerce docs now install from WordPress.org first, with the direct ZIP retained as a fallback
  • Merchant Operating Layer V1 is live: merchant Analytics now has clearer revenue-by-day reporting, date ranges, product lenses, checkout-funnel reporting, and day-level summaries
  • Starter-and-above operating tools now include merchant analytics, buy notifications, CSV/PDF exports, and tax/export records, with public receipt proof kept privacy-conscious
  • Support ticket workflows now send email updates around ticket creation and replies, while ticket context can stay linked to payment, receipt, member, or checkout details
  • Billing now exposes the Stripe customer portal more plainly when a Stripe customer record exists, so merchants can manage payment methods, invoices, and cancellation in Stripe
  • Launch Wizard V1 is live for new merchants, covering link-only, embed, WooCommerce, Telegram, Discord, redirect, download, and custom handoff setup paths
  • The launch checklist now stays visible in the merchant dashboard until the first setup steps are complete
  • Discord setup now surfaces the Hilt Connect invite path before merchants rely on Discord role automation
  • Hilt Pay for WooCommerce first shipped as a self-hosted plugin ZIP before the later WordPress.org approval
  • The WooCommerce page now explains order handoff, hosted Hilt checkout, signed webhook confirmation, buyer return, and merchant-owned payout flow
  • Embed checkout is now live, so merchants can add a Hilt checkout button to external pages and keep a direct checkout link as the fallback
  • Checkout now supports a unified multi-wallet flow across desktop and mobile, reducing the old Phantom-only buyer path
  • The homepage has been simplified into six clearer sections that explain who Hilt serves, how checkout works, and why the custody model matters
  • Learn is now the home for buyer education, articles, FAQ, and release updates, with navigation cleaned up around merchant-facing discovery
  • The public FAQ has moved into Learn so merchants and buyers can find product answers alongside guides and articles
  • Public site pages now use a cleaner white-background presentation and tighter title treatment where that improves readability
  • Official JavaScript and Python SDKs now install from npm and PyPI respectively, with dedicated public GitHub repos for each package
  • Approved OpenAPI snapshots, Postman imports, and example webhook payloads now also live in a public developer-assets GitHub repo
  • The public CLI now covers webhook endpoints, delivery logs, re-send flows, sandbox sessions, recurring recovery, delivery diagnostics, and direct receipt proof sending
  • Hilt now provides sandbox API testing without claiming a separate fake settlement rail
  • Public merchant and developer playbooks now turn webhook launch, delivery rescue, recurring recovery, proof handling, and go-live checks into dedicated guides
  • Official TypeScript and Python SDK download artifacts are now published from Hilt alongside a first-party Postman collection and environment
  • Developer docs and the public Developers page now point to real Hilt SDK and Postman install paths instead of telling teams to generate their own first
  • Merchant analytics now shows a real checkout funnel with hosted checkout opens, payment session starts, confirmed payments, and daily open → connect → confirmed reporting
  • Product reporting now combines take-home, fees, renewal pressure, delivery-failed rate, and support load so merchants can see what needs attention without stitching together multiple screens
  • Admin analytics now includes merchant-operations reporting with workspace attention signals, product heat, and cross-platform renewal, delivery, and support pressure
  • Hosted checkout opens are now recorded as a first-class analytics signal instead of being inferred from broader website traffic
  • Webhook operations now include signed test events, payment or membership event timelines, and a stronger merchant delivery-log workflow around self-serve Re-send webhook
  • Telegram and Discord access recovery now includes live provider diagnostics plus support-linked escalation actions in merchant workflows
  • Recurring operations now expose expiring-soon cohorts, collection timing, cancellation state, recent renewal events, and product-level renewal reporting for native recurring flows
  • Receipt proof now has a richer public proof page, PDF generation, invoice metadata, receipt search filters, and direct “send proof link” actions from merchant and admin workflows
  • Support tickets can now carry structured payment, membership, and receipt context so retry delivery, proof sharing, and renewal recovery actions stay tied to the case
  • Recurring access flows are now cleaner across checkout, members, support, admin operations, and public pricing
  • One-off payments and native recurring flows are now treated as separate commercial modes instead of one fuzzy recurring setup
  • Recurring access keeps buyer approval explicit while Hilt records collection, receipt, access, webhook, support, and audit state
  • Merchant webhook delivery logs now include a self-serve Re-send webhook action for retry-scheduled and dead-letter deliveries in the dashboard
  • Tightened the public pricing ladder so one-off payments and native automatic subscriptions are described more plainly
  • Updated the pricing calculator, comparison cards, and Developers page so the plan story stays consistent across the site
  • Reworked the webhook docs into a first-class integration surface with quickstart, event catalog, signature verification, delivery behavior, idempotency, and migration guidance
  • Template renewal modes are now explicit: one-off payment versus native recurring flows instead of one fuzzy recurring setup
  • Updated the merchant builder, pricing language, and developer examples so payment model and renewal model are clearer before launch
  • Access automation rescue is now queue-backed for failed membership delivery and failed expiry revoke paths
  • Added a dedicated Delivery operations desk in admin with due-job sweeps, manual-review visibility, readiness gaps, and recent attempt history
  • Updated the merchant and developer docs so post-payment delivery now reflects automatic rescue plus manual retry controls
  • Native Hilt webhooks are live for payments, memberships, receipts, failed delivery, and support ticket creation
  • Added signed outbound delivery with retry scheduling, dead-letter handling, and replay controls in the Hilt admin workspace
  • Updated the developer docs so webhook integrations are now first-class, while payment polling remains a valid fallback during active checkout flows

April 2026

  • Rebuilt the public docs around merchant and developer audiences only
  • Tightened the public language so merchant and developer workflows stay clearer throughout the docs
  • Clarified the relationship between dashboard templates and API or CLI products
  • Refocused the public developer guidance on the live Hilt API