Skip to content
Last updated

1.1

API versionStatusMost recent API update
1.1PreviousSeptember 4, 2026

Version 1.1 adds Trusted Server Connection using mutual TLS (mTLS). This gives issuers a certificate-based alternative to source-IP allowlisting for server-to-server access.

New: Trusted Server Connection

For each environment, choose one connection option:

  • Source-IP allowlist: Percents permits requests originating from the approved public IP addresses using the standard environment URL.
  • mTLS: Your server presents a client certificate during the TLS handshake to a dedicated mTLS URL. The request must also include the standard API token.

mTLS does not replace API-token authentication. It proves that the connecting server holds the private key associated with the issued client certificate; the API token continues to authorize requests.

Getting started

Generate a private key and certificate signing request (CSR) in your environment, then send only the CSR to your assigned Percents account manager. Never send the private key. Percents returns a signed client certificate after the request is approved and configured.

Use the certificate, its private key, and the mTLS URL for the target environment. Endpoint paths and API-token behavior are unchanged from the standard URL. See Trusted Server Connection for the full quickstart, supported URLs, and request examples.

Compatibility

Existing source-IP allowlist integrations continue to use their standard environment URLs without changes. mTLS clients must use the dedicated mTLS hostname for their environment; sending a client certificate to a standard URL does not enable mTLS.