LoyumiDeveloper docsOpen Sandbox
CHANGE HISTORY

Know what changed before you upgrade.

Read API and Web Widget contract changes, compatibility guidance, deprecation policy, and limitations that remain visible by design.

Developer docs · no accountSandbox firstAPI 1.13.0 · 121 operations · 106 paths

Merchant-operated Shopify and Klaviyo mapping conformance, with no connector claim.

  • SDK

    @loyumi/sdk 2.3.0 remains aligned to all 121 Public API 1.13.0 operations and adds exported JavaScript plus TypeScript declarations for Shopify, Klaviyo, and their local conformance runner.

  • Shopify

    Webhook normalization is pinned to API 2026-07, requires merchant-verified HMAC over the exact raw body, maps paid orders and exact merchandise refunds, separates email-marketing consent from program consent, and fails closed on unsupported or ambiguous value.

  • Klaviyo

    Profile-import and lifecycle-event builders are pinned to revision 2026-07-15, use external_id only, omit provider authorization, and never mutate channel subscriptions. The merchant supplies minimum-scope credentials at send time.

  • Synthetic transcript

    The bundled local runner returns eight of eight deterministic synthetic, nonfinancial vectors passed, with providerStatus: configuration_required. It performs no network request and does not claim a Shopify app, Klaviyo connector, hosted sync, installation, provider approval, delivery, migration, or customer result.

  • Distribution

    The official versioned archive is 193,541 bytes with SHA-256 6ae6ca12753af4168e4cd3a041d9cd4d153d005ae790320ef2a316d3af6611a2. The immutable historical loyumi-sdk-2.2.0.tgz archive remains published at 172,756 bytes with SHA-256 60e87333b3e9b020e62ab8c3955a23f6bb2093294483ed3a68fb6ce0fda45013; public npm-registry presence is not claimed.

A persisted, replay-safe proof loop for the official Loyumi Sandbox API.

  • CLI

    @loyumi/cli 1.5.1 adds quickstart proof, an opt-in command for one published Sandbox program.

  • Real state

    The command creates or reuses an unmistakably synthetic member, records explicit synthetic consent, posts one purchase twice under one idempotency key, and reads back the exact transaction and balanced ledger.

  • Guardrails

    Only the exact official HTTPS API is accepted, and redirects are denied. Authoritative context must report an active Sandbox; Production-identifying and non-official targets fail closed.

  • Evidence boundary

    The package contains no built-in mock, fixture-response, or fallback branch for this command. Publishing the package does not claim that a live proof ran for the current site deployment or any merchant Sandbox.

  • Distribution

    The official versioned archive is 66,971 bytes with SHA-256 146a0a459b4210c275381bedb379242df175685f5439a11ad1c0d57ec5d09146. Public npm-registry presence is not claimed.

Recipient-bound Reward Gifts, complete typed coverage, and portable evidence.

  • API contract

    Public API 1.13.0 publishes 121 operations across 106 paths. The rendered reference and downloadable OpenAPI document use the same checked-in contract.

  • Reward Gifts

    An invitation-first lifecycle lets one enrolled member spend points to offer another enrolled member one of up to four recipient-bound catalog entitlements. Points transfer, cash-out, reload, resale, and regifting are not supported.

  • SDK

    @loyumi/sdk 2.2.0 is the official stable download aligned to all 121 operations, with the enterprise Reward Gifts framework and raw-body webhook verification.

  • CLI

    @loyumi/cli 1.4.0 was the official stable download for common operating workflows and portability 1.6 at this release point. It wrote API 1.11 project configuration and did not claim 121-operation parity.

  • Webhooks

    The public catalog contains 40 privacy-minimized event types, including 17 Reward Gifts events. Signature verification does not replace event-ID deduplication.

  • Portability

    Schema 1.6.0 covers 53 business-state collections, including durable gift invitations, choices, delivery evidence, entitlements, and use evidence while excluding short-lived authority that must be reissued.

  • Distribution

    SDK and CLI packages are versioned public downloads. Public npm-registry presence, service general availability, SLA coverage, production certification, and merchant adoption are not claimed.

Calculate correctly, close exactly, and notify every material lifecycle.

  • Finance close

    A new program-period report returns exact decimal-string roll-forward, movement by event type, double-entry controls, policy valuation in currency micros, readiness checks, and a deterministic SHA-256 evidence hash under the existing analytics:read scope.

  • Rule correctness

    Optional rational earn rates, ISO currency exponents, loyalty-unit precision, explicit rounding, deterministic multi-rule evaluation, campaign audiences, and every matching campaign rule are supported while legacy whole-currency behavior remains unchanged.

  • Event time

    Late events can explicitly pin an immutable configuration published at occurredAt plus the historically observed member tier. Receipt-time current-configuration evaluation remains the safe default.

  • Lifecycle webhooks

    The public catalog expands from points.earned to twenty versioned, privacy-minimized membership, publication, redemption, fulfillment, dispute, adjustment, import, and partner-clearing events. Existing subscriptions remain unchanged.

  • Runtime

    Rate-limit claims are atomic, credential activity writes are sampled, Production evidence expiry fails forward-value operations closed without mutating on customer requests, maintenance drains larger bounded pages, and console responses receive security headers.

  • Queries

    Eighteen additive Query & Operations endpoints add cursor-paged member, transaction, redemption, adjustment, import, operation, audit, webhook-endpoint, and delivery reads with separate least-privilege scopes.

  • Ledger

    Transaction search filters program, customer, event, source reference, state, and bounded time. Detail returns the stored business evidence and balanced ledger entries without exposing command secrets.

  • Operations

    Long-running operation status and environment-attributed audit search let operators follow work and preserve actor, action, target, time, and request evidence.

  • Analytics

    A bounded ledger summary reports real descriptive aggregates for at most 90 days. It is a best-effort request view—not revenue attribution, incremental lift, or a financial-close report.

  • Webhooks

    Public endpoint create, read, update, secret rotation, non-PII test, delivery inspection, and governed retry are available. Create and rotation return the secret once; public delivery views omit payloads.

  • Membership

    Public API 1.10 retains identity-only member creation, explicit evidence-backed program enrollment, and governed zero-value unenrollment. Value entry paths require active enrollment at the database write boundary.

  • Program limits

    Program manifests publish a supported maximum of 16 active tiers per immutable version. Choice benefits allow 16 simultaneously effective sets per program under half-open [startsAt, endsAt) schedules.

  • SDK

    @loyumi/sdk 1.1.0 is the official stable download aligned to all 70 API 1.10.0 operations, including exact ledger close and twenty typed webhook event names.

  • React

    @loyumi/react 1.0.0 is the official stable downloadable wrapper for Web Widget v1 and supports React 18.2 and 19.

  • CLI

    @loyumi/cli 1.1.0 is the official stable API 1.10 download with exact reports ledger-close, twenty-event webhook configuration, explicit member lifecycle, and common operating commands. It does not claim command parity with all 70 public operations.

  • GraphQL

    The account-free GraphQL Beta guide publishes a POST-only HTTPS endpoint, aligned SDL, bounded execution, selected API 1.10 reads, and one governed value mutation per operation. It delegates to existing scopes and state machines and does not claim 70-operation parity.

  • iOS

    LoyumiMobile 1.1.0 is the official dependency-free Swift source distribution for iOS 15+ and macOS 12+. It calls a merchant backend and adds Native UI Kit 1.0.0-beta.1 with SwiftUI rewards components.

  • Android

    com.loyumi.mobile 1.1.0 is the official Kotlin source distribution for Android API 23+. It calls a merchant backend and adds Native UI Kit 1.0.0-beta.1 using Android framework Views.

  • AI-native

    Semantic rewards surface 1.0 Beta projects a published widget into privacy-minimized component and action JSON. Native entitlement redemption requires an exact-origin session, explicit confirmation, and stable idempotency key.

One current API. Separate package release states.

API compatibility and package maturity are different facts. The checked-in OpenAPI document is the source for the public HTTPS JSON API contract; the rendered API reference uses that same document.

HTTPS JSON API + OpenAPI

Current: 1.13.0. The account-free contract publishes 121 operations across 106 paths and 40 privacy-minimized webhook event types.

GraphQL API

Beta · selected lifecycle. POST-only JSON over HTTPS with checked-in SDL, bounded execution, one top-level mutation, and delegation to the existing scope and value paths. It does not claim 121-operation parity.

@loyumi/sdk

2.3.0 → API 1.13.0. Official stable downloadable ESM server package with all 121 operations, 40 webhook event types, Reward Gifts frameworks, portability 1.6, and merchant-operated Shopify 2026-07 and Klaviyo 2026-07-15 mapping conformance for Node.js 20+ and compatible Web Crypto edge runtimes.

@loyumi/cli

1.5.1 · API 1.11 project config. Stable downloadable release for common integration and operating workflows, including the opt-in official-origin Sandbox proof, with portability 1.6. It does not claim command parity with all 121 API 1.13 operations.

Web Widget

v1 · Available Beta. Use /widgets/v1/ for compatible loader fixes or the immutable /widgets/v1.0.0/ loader with its published SRI. That freezes the merchant-page loader, not the hosted iframe runtime.

@loyumi/react

1.0.0 → Web Widget v1. Official stable downloadable wrapper, typed and SSR-safe for React 18.2 and 19, with event callbacks, theming, session handoff, and optional immutable loader URL plus SRI; public npm-registry availability is not claimed.

LoyumiMobile for iOS

1.1.0 · stable source distribution. Swift Package for iOS 15+ and macOS 12+ with typed merchant-gateway calls and additive Native UI Kit 1.0.0-beta.1. It has no Loyumi API-key setting and is not claimed on a package registry.

Loyumi Mobile for Android

1.1.0 · stable source distribution. Kotlin library for Android API 23+ with typed merchant-gateway calls, coroutines, and additive Native UI Kit 1.0.0-beta.1 built with framework Views. It has no Loyumi API-key setting and is not claimed on a package registry.

AI-native rewards surface

1.0 · Beta. Versioned, privacy-minimized semantic JSON derived from a published widget deployment, with a checked-in JSON Schema and confirmed, idempotent native-entitlement redemption action.

Portability export

1.6.0 · 53 collections. Preserves migration-critical business state, including durable Reward Gifts evidence, while excluding and naming the authority and runtime records that must be reissued.

Integration starters

One synthetic mapping pack plus three contract-reviewed patterns. Shopify and Klaviyo mapping conformance, commerce earn and return, recipient-bound Reward Gifts, and signed webhooks are published with merchant-owned boundaries. The provider mapping status remains configuration_required; a native or connected provider integration and broad turnkey connector catalog are not claimed.

The prior value lifecycle remains intact; finance evidence and notifications expand.

GET /reports/ledger-close

Generates one program-period exact roll-forward, double-entry controls, policy valuation, readiness checks, and deterministic integrity evidence without claiming independent audit approval.

20 public webhook types

Adds versioned membership, publication, redemption, fulfillment, dispute, adjustment, import, and partner-clearing outcomes while preserving points.earned.

Purchase evaluation policy

Supports explicit event-time pinned configuration and historical member-tier evidence; receipt-time current configuration stays the default.

Rule definition earn controls

Adds rational rates, currency exponent, loyalty precision, rounding, multi-rule decisions, campaign audiences, and deterministic evaluation.

API 1.9 operations

Identity and explicit enrollment, cursor-paged investigations, bounded descriptive analytics, webhook management, imports, operations, audit evidence, and complete governed value lifecycle remain published.

Visible by design.

  • The TypeScript SDK 2.3.0 and CLI 1.5.1 are official stable downloads; iOS and Android remain official stable 1.1.0 source downloads; the React wrapper remains official stable 1.0.0. Public package-registry availability and service general availability are not claimed.
  • Native UI Kit 1.0.0-beta.1, GraphQL, Web Widget v1, Widget Studio, and AI-native rewards surface 1.0 remain Beta. GraphQL exposes a selected lifecycle rather than all 121 HTTPS JSON operations; the AI-native surface does not claim model-provider integration or a general agent identity protocol.
  • @loyumi/cli 1.5.1 writes API 1.11 project configuration, includes the opt-in official-origin Sandbox proof, and covers common operating workflows but does not claim one command for every one of the 121 API 1.13 operations.
  • The iOS and Android clients are source distributions for a merchant-owned backend gateway. No live merchant-gateway integration, App Store or Play distribution, or physical-device validation is claimed. Native apps must never hold a Loyumi API credential, and browser-origin-bound Web Widget session codes must not be repurposed for native identity.
  • Copy-paste alone provides guest mode. Personalized identity, balances, history, eligibility, and redemption require a merchant-backend widget session.
  • The immutable Web Widget v1.0.0 URL and SRI freeze the merchant-page loader only. No public immutable full hosted-runtime deployment option is claimed.
  • No broad first-party Shopify, Salesforce Commerce Cloud, POS, coupon, fulfillment, analytics, fraud, or third-party reward-network connector catalog is claimed. Hosted redemption supports Loyumi-native entitlements; external fulfillment remains merchant-integrated.
  • A Production opening-balance member import is allowed only while a new Production environment is locked and before activation is requested. Requesting activation atomically seals the fully reconciled import set and permanently closes that migration window; a rejected approval, later evidence expiry, or critical incident lock does not reopen it.
  • The webhook URL check rejects URL credentials, obvious loopback or private literals, local hostnames, and redirects. It is a syntax-layer SSRF boundary; production DNS resolution, egress enforcement, firewalling, and monitoring remain infrastructure responsibilities.
  • The public webhook contract supports 40 versioned, privacy-minimized lifecycle events, including 17 Reward Gifts events. webhook.test remains internal. Deployed trigger uptime is not claimed; test delivery and governed retry are explicit operations, and retry only re-queues the existing record.
  • The bounded ledger-summary endpoint is descriptive and best-effort. It is not a financial-close snapshot, revenue attribution, incremental lift, campaign analytics, cohort analysis, forecasting, ROI, fraud analytics, or a BI replacement.
  • No public turnkey fraud engine, linked-account or device risk service, risk scoring, or case-management product is demonstrated. Merchants must supply and test external signals, decisions, holds, and review workflows.
  • SAML/OIDC enterprise SSO, SCIM, organization-enforced MFA, configurable session policy, IP restrictions, periodic access certification, customer-managed keys, and a documented SIEM feed are not represented as published. An audited access-review CSV is available, but it does not automate certification or deprovisioning.
  • The privacy procurement package remains incomplete: no public DPA, subprocessor register, retention schedule, cross-border treatment, or operating subject-request evidence is claimed. Governed receipt-response scrubbing does not erase ledger, transaction, consent, or audit records.
  • Partner exchange requires a versioned bilateral agreement and records settlement evidence; Loyumi does not move external settlement funds.
  • The deterministic portability 1.6 export preserves 53 business-state collections, including durable Reward Gifts evidence. Exact cross-request export snapshots, broader historical transaction and configuration import, independent buyer reconstruction, timed exit, and verified deletion remain open evidence. Webhook delivery jobs, idempotency replay caches, live coupon codes, contact destinations, claim authority, access roles, credentials, and sessions are explicitly not transferred and require the manifest's drain, re-entry, or reissue steps.
  • Production-topology performance, independent penetration testing, SOC 2 or comparable assurance, SLA, RPO/RTO, DR, customer references, and executed commercial protections remain open gates.
  • Only the nonbinding $15,000 Reconcile & Launch starting pilot price is public. No guaranteed quote, generally available SaaS list price, Production entitlement, support tier, response-time commitment, service-credit schedule, liability allocation, or termination-assistance schedule is claimed; require final terms in an executed agreement.
  • Academy practical labs are self-checked; the Foundations credential validates the knowledge assessment, not an observed production implementation.
  • The public certification endpoint does not provide account-based identity assurance.

Contracts change with evidence.

OpenAPI

Additive, compatible updates increment the minor version. Breaking request or response changes require a new major contract and migration guidance.

Web Widget

The /widgets/v1/ URL pins major version 1. Compatible fixes may ship within v1; breaking element, attribute, event, or theme-token changes require a new major.

Deprecation

A supported widget major receives a published notice, migration guide, and end-of-support date before retirement.

Certification

Credentials retain the exam and credential version used at issue time. Revocation changes status, not history.