| API version | Status | Most recent API update |
|---|---|---|
| 1.1 | Previous | September 4, 2026 |
Version 1.1 adds Trusted Server Connection using mutual TLS (mTLS). This gives issuers a certificate-based alternative to source-IP allowlisting for server-to-server access.
For each environment, choose one connection option:
- Source-IP allowlist: Percents permits requests originating from the approved public IP addresses using the standard environment URL.
- mTLS: Your server presents a client certificate during the TLS handshake to a dedicated mTLS URL. The request must also include the standard API token.
mTLS does not replace API-token authentication. It proves that the connecting server holds the private key associated with the issued client certificate; the API token continues to authorize requests.
Generate a private key and certificate signing request (CSR) in your environment, then send only the CSR to your assigned Percents account manager. Never send the private key. Percents returns a signed client certificate after the request is approved and configured.
Use the certificate, its private key, and the mTLS URL for the target environment. Endpoint paths and API-token behavior are unchanged from the standard URL. See Trusted Server Connection for the full quickstart, supported URLs, and request examples.
Existing source-IP allowlist integrations continue to use their standard environment URLs without changes. mTLS clients must use the dedicated mTLS hostname for their environment; sending a client certificate to a standard URL does not enable mTLS.