{"templateId":"markdown","versions":[{"version":"1.0","label":"1.0","link":"/omni-api/1.0/changelog/releases/v1.1","default":false,"active":false,"folderId":"6bec560c"},{"version":"1.1","label":"1.1","link":"/omni-api/1.1/changelog/releases/v1.1","default":false,"active":false,"folderId":"6bec560c"},{"version":"1.2","label":"1.2","link":"/omni-api/changelog/releases/v1.1","default":true,"active":true,"folderId":"6bec560c"}],"sharedDataIds":{"sidebar":"sidebar-omni-api/@1.0/changelog/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"1.1"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"11","__idx":0},"children":["1.1"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"API version"},"children":["API version"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Status"},"children":["Status"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Most recent API update"},"children":["Most recent API update"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["1.1"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Previous"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["September 4, 2026"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Version 1.1 adds Trusted Server Connection using mutual TLS (mTLS). This gives issuers a certificate-based alternative to source-IP allowlisting for server-to-server access."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"new-trusted-server-connection","__idx":1},"children":["New: Trusted Server Connection"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For each environment, choose one connection option:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Source-IP allowlist:"]}," Percents permits requests originating from the approved public IP addresses using the standard environment URL."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["mTLS:"]}," Your server presents a client certificate during the TLS handshake to a dedicated mTLS URL. The request must also include the standard API token."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["mTLS does not replace API-token authentication. It proves that the connecting server holds the private key associated with the issued client certificate; the API token continues to authorize requests."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"getting-started","__idx":2},"children":["Getting started"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Generate a private key and certificate signing request (CSR) in your environment, then send only the CSR to your assigned Percents account manager. Never send the private key. Percents returns a signed client certificate after the request is approved and configured."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the certificate, its private key, and the mTLS URL for the target environment. Endpoint paths and API-token behavior are unchanged from the standard URL. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/omni-api/overview/mtls-access"},"children":["Trusted Server Connection"]}," for the full quickstart, supported URLs, and request examples."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"compatibility","__idx":3},"children":["Compatibility"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Existing source-IP allowlist integrations continue to use their standard environment URLs without changes. mTLS clients must use the dedicated mTLS hostname for their environment; sending a client certificate to a standard URL does not enable mTLS."]}]},"headings":[{"value":"1.1","id":"11","depth":1},{"value":"New: Trusted Server Connection","id":"new-trusted-server-connection","depth":2},{"value":"Getting started","id":"getting-started","depth":2},{"value":"Compatibility","id":"compatibility","depth":2}],"frontmatter":{"seo":{"title":"1.1"}},"lastModified":"2026-10-02T20:53:32.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/omni-api/changelog/releases/v1.1","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}