Build - the name of the maintenance release build the change was introduced in.

Service - the name of the service/services which is/are affected.

Method - the name of the method/methods which is/are affected.

Message - the message that explains what was changed.

Schema changed - shows whether it is required to rebuild WSDL/XSD-generated stubs for .net, Java and other static typing languages.

TT - a link to a ticket related to the change.

Build

Service

Method

Message

Schema changed

Backward compatible

TT

Resolution for system update

MR130-0

Template

get_template_data_field_list
update_template_data_field_list
get_template_group_field_list
update_template_group_field_list

Marked "i_format_type" as readonly in TemplateDataFieldInfo and TemplateGroupFieldInfo. The field is still returned in responses but is no longer accepted on update — it is now derived from "i_format".

YesYesYT:BA-46962

Values sent in this field on update are silently ignored.

MR130-0

Notification

update_notification_template

Removed "i_format_type" from the variables array in input. The value was redundant and is now derived from "i_format".

YesNoYT:BA-46962

Stop sending "i_format_type" in the variables array — only "i_format" is needed.

MR130-0

Service

update_service

It's possible to set i_tax_transaction_code value for predefined (system) services

NoNoYT:BA-46495


MR130-0

Session

login

A new credential pair (login, one_time_password) is now accepted from the customer and account realms — the one-time-password authenticates the user directly, without a static password. Available only from IP addresses listed in the Security.AllowLoginByOTPFrom configuration option. When the one-time-password was issued with a specific domain, the login request must originate from the same domain, otherwise it is rejected. When the user has multi-factor authentication configured, the returned session still requires 2FA confirmation before it can be used.

YesYesYT:BA-43428


MR130-0

AccessControl

create_otp

Two optional inputs added: "otp_domain" binds the issued one-time-password to a domain (the default OTP notification templates append a trailing "@<otp_domain> #<password>" line so mobile clients can auto-fill the code, and a subsequent Session/login that uses this OTP is accepted only when the request originates from the same domain), and "skip_auth" (when set to 1) binds the OTP to the target entity instead of the caller's session, so the entity itself can later consume it via Session/login (the call must originate from an IP listed in the Security.AllowLoginByOTPFrom configuration option). The "notification_type" input is no longer mandatory — it may be omitted when an ESPF handler for the new Notification/PlatformManagement/OTPVerificationCode event is enabled, in which case the OTP is delivered via ESPF only.

YesYesYT:BA-43428


MR130-0

Generic

get_config_data

Removed:

  • Web.UseNewInterfaceForReseller
  • Web.UseNewInterfaceForDistributor
YesYesYT:BA-43953


MR130-0

Vendor

add_vendor
add_vendor_advanced
update_vendor
get_vendor_info
get_vendor_list

Removed:

  • i_acl

  • login

  • password

  • in_date_format, in_time_format

  • out_date_format, out_time_format, out_date_time_format

  • password_lifetime (for get_vendor_info)
YesYesYT:BA-43953


MR130-0

Product

clone_product

Added optional input field "end_user_name" — sets the user-visible product name on the cloned product. When omitted, the new product retains the prior behavior: admin-realm clones inherit "end_user_name" from the parent product, reseller-realm clones default it to the new product "name".

YesYesYT:BA-34310


MR130-0

Generic

get_config_data

Config options was extended with Customers.AllowedCleanupPeriod

NoYesYT:BA-46102


MR130-0

Account, Customer

Account.get_emergency_details,
Customer.get_emergency_details,
Customer.get_customer_site_emergency_details

New read-only methods that return Bandwidth E911 emergency endpoint details (caller name and address) for an account, customer, or customer site.

YesYesYT:BA-47219


MR130-0

TTS

get_capabilities

get_voice_list

New service with 2 new methods.

get_capabilities: returns voice-related capabilities for a Text-to-Speech provider - list of synthesis models with supported languages and an example of the per-voice settings payload.

get_voice_list: returns the list of available Text-to-Speech voices for a provider, optionally filtered by language and model.

YesYesYT:BA-46030


MR130-0

CallControl

say

Synthesizes text and plays it as a prompt during an active IVR call using a Text-to-Speech provider. Supports codec selection (u_law, a_law, wav, mp3), provider-specific voice settings, and the same playback controls as the play method (repeat, interrupt on input, callbacks). In standalone mode, only previously cached audio is available.

NOTE: API methods for CallControl service are not reflected in API docs (that's by design)

YesYesYT:BA-46030


MR130-0

DialingRule

add_dialing_rule
update_dialing_rule

Translation rule safety validation (tr_rule_from_local, tr_rule_to_local) now applies to all rule types (pbx, plan, advanced).

Previously it only applied to advanced. Rules containing unsafe code will be rejected with errEvalTranslationRule.

NoNoYT:BE-5445


MR130-0

UA

get_ua_profile_info

The used field in ua_profile_info is now returned as the documented 'Y'/'N' string. Previously it was returned as the integer 0/1, contrary to the schema. get_ua_profile_list already returned 'Y'/'N'.

NoNoYT:BA-47422

Clients that consume ua_profile_info.used must accept 'Y'/'N' instead of 0/1.

MR130-0

Product

add_product
update_product

It's not allowed to use fraud_protection='Debit' for input (the value is obsolete now) - the error is raised if you provide it in add/update API request.
But all existing products with 'Debit' are returned as is and you still can change fraud_protection mode for them.

NoNoYT:BA-47315


MR130-1

DiscountPlan

add_vd_threshold
update_vd_threshold

For a Service Wallet (top-up) bundle item, notify_threshold_type now accepts only remaining_amount; other values (and a non-negative warning_threshold) are rejected with a fault instead of silently saving a zero threshold.

NoNoYT:BA-47513


MR130-1

Product

add_product
update_product

Enabling a service feature whose service is not included in the product is now rejected with a fault (e.g. "emergency" on a product without the Voice Calls service). Disabling, clearing, or inheriting such a feature is still allowed.

NoNoYT:BA-47586

Stop enabling service features for services the product does not include.

MR130-1

Account

add_account
update_account

Enabling a service feature whose service is not covered by the account's product or add-ons is now rejected with a fault. Disabling, clearing, or inheriting such a feature is still allowed.

NoNoYT:BA-47586

Stop enabling service features for services not included by the account's product or add-ons.

MR130-1

Invoice

review_invoice
review_invoice_list

Added a new value pdf_regenerate to the action field. It regenerates the invoice PDF from the current template for an invoice under review (e.g. after the invoice template was changed), without recalculating charges or payments — the invoice stays under review. The existing approve and regenerate actions are unchanged.

YesYesYT:BA-47673
MR130-1

BundlePromotion

delete_bundle_promotion

delete_bundle_promotion is now allowed for the reseller realm — a reseller/sub-reseller can delete a bundle promotion they own (previously admin-only). Deletion is still rejected when the promotion is in use.

YesYesYT:BA-47704
MR130-1

XDRMediator

get_xdr_list

Output: gains a new "disconnect_time" field — the date and time when the billing session was disconnected, analogous to "connect_time". It is taken from the stored disconnect timestamp or derived from connect time plus session length, and is empty for records with no voice-style session (e.g. non-voice or error records).

YesYesYT:BA-47741


MR130-1

Generic

get_session_data

Output: gains a new operating_mode field reporting the operating mode of the PortaSwitch site that served the request, so an integration can poll it out-of-band and detect when it is safe to route API traffic back to the main site. Possible values:

  • normal — the main site, operating in the normal mode;
  • secondary — a secondary site in the normal mode (a replica of the main site);
  • standalone — a secondary site running in the standalone (delta) mode while the main site is unavailable;
  • read_only — the main site, operating in the read-only mode.
YesYesYT:BA-47641


MR130-1

Account

get_emergency_details

Added an optional with_inheritance flag ('Y'/'N', default 'N'). When 'Y', the endpoint inherited via the address cascade (account → customer site → customer) is returned instead of only the account's own endpoint.
The response gains a new level field indicating the tier of the returned endpoint ('Accounts', 'CustomerSites', 'Customers').

YesYesYT:BA-47635
MR130-1

IPTV

get_channel_package_list
get_service_package_list
get_provider_list

The IPTV methods get_channel_package_list, get_service_package_list and get_provider_list are now available on the reseller, distributor and representative realms (previously admin-only), so those realms can read the IPTV channel/service package and provider catalog. The admin-realm contract is unchanged.

YesYesYT:BA-47840


MR130-1

Account

add_followme_number
add_followme_number_list
update_followme_number_list

"redirect_number", "name" and "domain" are no longer mandatory when a follow-me number is created, matching the update path which already allowed them to be empty. A follow-me number can now exist with call forwarding enabled and no destination configured. The format of a supplied "domain" is still validated, and a non-UDP transport without a domain falls back to UDP.

NoYesYT:BA-47489


MR130-1

Account

get_account_followme

"redirect_number", "name" and "domain" are now nillable in the FollowMeNumberInfo structure - when empty they are returned as null instead of being omitted from the response, matching "period", "period_description" and "max_sim_calls".

YesYesYT:BA-47489


MR130-1

Account

update_followme_number_list

Pushing more than one brand new entry (without "i_follow_me_number") in a single request is now rejected for the Simple forwarding and Forward to SIP URI modes, which allow only one follow-me number per account. Previously this limit was not enforced for new entries added through this method.

NoNoYT:BA-47489

Add follow-me numbers one per request for these forward modes.

MR130-1

Template

clone_template

A reseller can now clone a rate upload template under a name that is already used by an administrator - the new name is checked only within the owner's own namespace instead of across the whole environment, and the clone is stored under the reseller's own ownership. Templates of other types keep the administrator namespace and are unchanged.

NoYesYT:BA-47229


MR130-1

Template

update_template

Renaming a template to a name already taken within the same owner namespace is now refused with the "update_template.not_unique_name" fault instead of failing on a database constraint. Changing only the letter case of the current name is allowed.

NoYesYT:BA-47229


MR130-1

AccessControl

generate_mfa_config
confirm_mfa_config

A user who must enroll in two-factor authentication before signing in can now complete the mandatory enrollment while holding only the Read permission on their own two-factor authentication (Auth_Parameters.mfa). Previously these methods required the Modify permission, which also let the user disable two-factor authentication for themselves. The permission check is waived only while the mandatory enrollment is still pending (two-factor authentication enabled but not yet configured); disabling it via set_mfa still requires Modify.

NoYesYT:BA-47923


MR130-1

Notification

add_notification_preset

A notification preset of the "user" type can no longer be created with an owner ("i_customer") - such a preset could never be assigned to anyone, because only a preset without an owner can belong to an administrator. A reseller session is offered the "customer_class" type only; an administrator can still create a "user" preset without an owner.

NoNoYT:BA-47853

Create user-type notification presets without an owner; use the customer class type for presets managed by a reseller.

MR130-1

User

get_user_info
get_user_list
add_user
update_user
delete_user
get_notification_list
get_notification_category_list
update_notification_list
get_rt_ticket_list

Administrators whose login is listed in the "Superusers" configuration option are now protected from API users that are not superusers. "get_user_info" and "get_user_list" return such a record reduced to "i_user", "login", "description", "email", "status", "class", "i_acl", "i_role", "role_name", "hide_personal_info" and "is_super_user" - the remaining fields, including "api_token", are withheld. "update_user", "delete_user", "get_notification_list", "get_notification_category_list", "update_notification_list" and "get_rt_ticket_list" return the "Access to the superuser is enabled only for superusers" fault. "add_user" and "update_user" additionally refuse a login listed in that option with the "Only a superuser can assign a login from the Superusers list" fault.

NoNoYT:BA-47946

An integration that has to read or manage superuser records must authenticate as a superuser.

MR130-1

WebLog

get_web_log_list

The web log records about an administrator whose login is listed in the "Superusers" configuration option are no longer returned to API users that are not superusers, for any filter and for a request with no filter. What a superuser did to other entities stays visible to every administrator of the environment.

NoNoYT:BA-47946


MR130-2

Tariff

add_tariff
update_tariff
get_tariff_info
get_tariff_list

The "email_from" field of "authorized_email_list" is now compared with the real sender address of the message, exactly and ignoring letter case. Before, the stored value worked as a regular expression, and the search ran over the whole raw "From:" header. So a value that is not a plain email address no longer matches any message, and the email tariff upload is refused.

NoNoYT:BA-48124

Store a plain email address in "email_from". A value that holds a pattern must be replaced.

MR130-2

DiscountPlan

add_discount

Adding a bundle item is now refused when it would make two products of one account use one usage counter - the same add-on priority, service, destination group and peak level. The error names both products.

NoNoYT:BA-47723

Change the service, the destination group or the peak level of the new item, or use a new bundle.

MR130-2

Account

update_account
get_service_features_metainfo

When the account takes the "emergency" service feature flag from the product, the "emergency_administrative_unit" value sent with the request is now stored. A request that omits the attribute keeps the stored value; an explicitly empty value still clears it. get_service_features_metainfo now reports "mandatory" for this attribute when the configured E911 plug-in needs it.

NoYesYT:BA-45107


MR130-2

User
Customer

get_user_info
get_customer_info

The "rt_auth_info" block is no longer hidden from a user who has "Mask personal information in data accessed by this user" enabled. Such a user got masked values before, so the trouble ticket integration did not work. The "rt_login" and "rt_pass" fields hold the credentials of the user who makes the request, not of the requested user or customer. Their descriptions were corrected.

NoYesYT:BA-48106


MR130-2

Notification

update_notification_template

Added validation of the template variable formats. A variable format that belongs to another format type is rejected. A custom formatting rule is rejected unless the variable format is "Other:". Format changes within the variable's own format type work as before.

NoNoYT:BA-48191

Send a format of the variable's own format type. Send a custom formatting rule only together with the "Other:" format.

MR130-2

Customer

update_customer_extension

The "i_account" field no longer accepts an empty value. The account assigned to an extension can be replaced, but it cannot be removed. A request with an empty "i_account" now fails with the "i_account.not_set" error.

YesNoYT:BA-48244

Omit the "i_account" field to keep the current account. Pass another account ID to replace it.

MR130-2

Session

login
login_to_realm
reset_password
change_password

The "login" field is now limited to 128 characters. A longer value is rejected with the "too_long.login" error. The longest login that can be stored is 128 characters for an account and 64 for a customer, representative, or user, so a longer value never matched an existing login.

NoYesYT:BA-48274


MR130-2

CustomReport

execute_custom_report_query (and scheduled report runs)

Custom report generation now applies the query owner's scope to the stored customer ids. Ids that the owner cannot access are ignored. A query whose inputs refer only to inaccessible customers does not produce a report.

No

No

YT:BA-46577


MR130-2

Customer

add_customer
add_subreseller
update_customer
validate_customer_info

The "new_i_billing_period" field of the "customer_info" structure is now validated against the supported billing periods. Only the IDs 1 to 6 are accepted; any other value is rejected with the "invalid_customer_info.new_i_billing_period" error. Such a value was stored before and only failed later, when the scheduled billing change became due. Clearing a scheduled billing change is unaffected: an empty or null value works as before. The accepted IDs are now listed in the API reference for the field.

NoYesYT:BA-48225


MR130-2

Customer

update_customer_extension
delete_customer_extension

An extension that represents a hunt group is no longer accepted by these methods, whatever fields the request carries. Such a request is now rejected with the "cannot_update_group_extension" or "cannot_delete_group_extension" error. Before, the update was refused only when the request carried "i_account", and the delete was not refused at all; both left the hunt group inconsistent, so calls to it failed and it could no longer be deleted. Use update_customer_huntgroup and delete_customer_huntgroup to manage a hunt group and its extension. Extensions of the "Account" and "Unassigned" types are unaffected, and a parking slot is refused as before. The "i_c_ext", "i_account", "i_c_group" and "type" descriptions in the API reference now state which types each method accepts.

NoYesYT:BA-48196


MR130-2

AsyncRequest

delete_request_list
cancel_request

The delete_request_list and cancel_request methods are now available on a secondary site in the normal mode (previously both were rejected with a secondary_site fault), so a finished background request can be cleared and a running one cancelled from a secondary site. The main-site contract is unchanged.

NoYesYT:BA-48353


MR130-2

DID

get_number_list
update_number_list
delete_number_list

The "owner_batch" filter now treats the null value as "no pricing batch on either level". For an administrator the result no longer includes DID numbers that fall under the pricing batch of the reseller that manages them. For a reseller the result is unchanged. The same filter selects the numbers that update_number_list and delete_number_list act on.

NoNoYT:BA-48174

To list or change the numbers managed by a reseller, filter by that reseller's pricing batch ID instead of the null value.

MR130-2

Account

add_account
update_account
validate_account_info

A product or add-on change that enables Static IP is now rejected if the account's IP address or netmask is empty.

NoNoYT:BA-48242

Send the IP address and netmask when you assign a product or add-on that enables Static IP

MR130-2

Account

move_account

A move that changes the product to one enabling Static IP is now rejected if the account's IP address or netmask is empty.

NoNoYT:BA-48242

Set the IP address and netmask before you move an account to a product that enables Static IP

MR130-2

Customer

add_customer
update_customer

Deprecated "i_tariff" and "i_tariff_incoming" in the CustomerInfo structure. Assign the reseller tariffs on the product instead. Both fields are now checked the same way on add_customer and on update_customer: the tariff must be of the voice service type, be a reseller tariff and match the customer's currency. Before, only "i_tariff" was checked, only on add_customer, and only against the built-in "Voice Calls" service.

NoNoYT:BA-48147

A tariff built on a custom service of the voice type is now accepted. A tariff of another service type, another currency, or a non-reseller tariff is now rejected on update_customer.

MR130-2

Product

add_product
update_product
add_subscription

A product shared with resellers can now be combined only with subscriptions accessible to resellers, in "i_subscription" and in "i_reseller_subscription". Otherwise the request fails with "Server.Product.i_subscription.shared_product_with_nonshared_subscription" or "Server.Product.i_reseller_subscription.shared_product_with_nonshared_subscription". update_product also fails when "shared" is set to "Y" for a product that has a non-shared subscription.

NoNoYT:BA-47169

Use subscriptions shared with resellers on shared products. Products that already have a non-shared subscription are not changed.

MR130-2

Subscription

update_subscription

"shared" cannot be changed to "N" when a product shared with resellers uses the subscription. The request fails with "Server.Subscription.subscription_used_by_shared_product".

NoNoYT:BA-47169

First remove the subscription from the shared products, or unshare those products.

MR130-2

Customer

add_callqueue
update_callqueue
add_customer_huntgroup
update_customer_huntgroup

A callback overflow action with a custom prompt is now rejected with "callqueues.custom_prompt_requires_wait_confirmation" also when the request omits "wait_confirmation" or "i_callqueue_action". On update, an omitted value is taken from the stored call queue. On create, an omitted "wait_confirmation" counts as 'N'. A request with "prompt_action" set to 'unset' counts as having no custom prompt. The "wait_confirmation" description in the OnIncomingCallLimitInfo, OnMaximumWaitingTimeInfo and OnMaximumRingingTimeInfo structures now states this rule.

NoNoYT:BA-48373

Send "wait_confirmation" 'Y' with a custom callback prompt, or remove the prompt with "prompt_action" 'unset'. A call queue already stored with a custom callback prompt and confirmation disabled rejects any update to that overflow action until one of these is sent.


  • No labels