Business Box Start free

Changelog

What changed, and what "v1" commits us to.

In short/v1 changes additively only. New fields and new operations can appear; existing fields are not removed, renamed or retyped. Write clients that ignore fields they do not recognise.

What v1 promises#

We will:

  • Add fields to response objects.
  • Add operations, query parameters and webhook event types.
  • Add error codes, for situations that do not have one yet.
  • Reword an error message, which is a hint and not a contract.

We will not, in v1:

  • Remove or rename a field, or change its type.
  • Remove an operation, or change what an operationId refers to.
  • Change the meaning of an error code.
  • Move the base URL. It is in other people's configuration files.

So: ignore fields you do not recognise, and treat an unknown error code as a generic failure. A client that rejects unexpected fields will break the first time we add one, and that is not a breaking change on our side.

Anything genuinely incompatible would be /v2, alongside /v1, announced here first.

Following along#

The OpenAPI document is generated from the running code and verified in continuous integration, so it is the most precise record of what exists. Diffing it between releases will show you every change, including ones too small to list here.

Releases#

1.0.0 — first release#

The API becomes available on every plan, including free.

  • Authentication with personal API keys, created under Settings → Integrations, in read-only and read-write forms.
  • 12 operations across 9 paths: the account, event types and their availability, bookings (list, read, create, cancel), single-use invite links, and webhook subscriptions.
  • Webhooks for booking.created, booking.rescheduled, booking.cancelled and booking.no_show, signed with HMAC-SHA256 in Stripe's scheme, retried with back-off, and switched off after a long run of failures.
  • Idempotency on the two operations that create something, so a retried timeout cannot double-book.
  • An OpenAPI 3.1 document at /openapi.json, needing no token, with webhook payloads under the 3.1 webhooks key.
  • 120 requests a minute per key, with RateLimit-* headers on every response.

Deliberately not included: editing event types or availability, rescheduling, refunds, calendar connections and profile editing. Every platform listing can launch without them, and a published field is harder to remove than to add. If your integration needs one, that is worth hearing.

Expected next#

Not commitments, and not dated:

  • OAuth 2.1 with PKCE, so an app can serve other people's accounts without asking them to paste a key.
  • A hosted MCP server, which the AI assistant directories require. See AI assistants.

Common questions

How will I hear about changes?

This page, and the OpenAPI document — it is generated from the code, so diffing it between releases shows every change including the small ones.

Will you ever remove a field from v1?

No. That is the whole point of the version. Something genuinely incompatible would appear as /v2 alongside /v1.

A field appeared that my client did not expect and it broke. Is that a breaking change?

Not on our side — v1 explicitly reserves the right to add fields, and clients are asked to ignore unknown ones. Configure your parser to be lenient, or generate your client from the OpenAPI document.

Last reviewed 28 September 2026.