Changelog¶
2026-09-30¶
- The API base URL is now
https://api.cloudpay365.com/api/v1/(washttps://api.hivemind.co.ke/api/v1/). Every example request on the site uses the new host; paths, methods, and payloads are unchanged. - The docs site moved to
https://docs.cloudpay365.com.
2026-09-22 (sandbox)¶
-
Added From Signup to Live: the end-to-end path a new merchant follows, from creating an account through to production credentials, with what blocks each step.
-
Sandbox is real. Merchants now create their own sandbox credentials in the portal, at any tier, without contacting support — and a sandbox application charges a separate sandbox wallet with a play balance. Previously an application's
environmentwas recorded and then ignored, so "sandbox" credentials moved real money. - Added Sandbox and Going Live: what differs between the two environments, and the go-live checklist.
- Sandbox Credentials & Test Numbers replaces its placeholder table with the real outcome-by-destination table: success, cancelled, insufficient funds, timeout, ambiguous payout, and late result.
- Test Scenarios rewritten around those six outcomes, including the failure cases that are hard to arrange deliberately in production.
- IP Whitelisting now states that the check is production-only and fails closed there, and that registering an address is a go-live requirement rather than something to discover on your first live request.
- Verifying & Testing Webhooks now documents sandbox as the supported way to test a handler, including callbacks that fail, never arrive, or arrive late.
- Production credentials are now gated. They are issued only once a merchant is verified and has proved the integration in sandbox — a successful collection, a successful payout, a webhook that returned 2xx, and a whitelisted IP. Going live does not disable the sandbox application; merchants keep both.
2026-09-15¶
- Rebranded the site as Hivemind Payments: new name throughout, Hivemind Payments logo and favicon, and the brand color palette (orange
#FB5607, rust#C15227, black) in light and dark modes. The API base URL is nowhttps://api.hivemind.co.ke/api/v1/(washttps://api.nextplay.co.ke/api/v1/). - Removed the API Applications page (
GET /integrations/applications/) from the API Reference. Client credentials are obtained from Hivemind Payments. - Added an Authentication page to the API Reference for
GET /auth/token/, using the standard endpoint layout. - Updated links on the Home, Overview, Quickstart, Sandbox Credentials, IP Whitelisting, and Result URL Callbacks pages to match.
2026-07-02 (webhook payload confirmed)¶
- Payload Reference now documents the real
result_urlcallback payload instead of an inferred shape. - Confirmed the callback body is the transaction object unwrapped (no
{"success", "data"}envelope, unlike every other endpoint response), and that its fields match Transaction Status Query'sdataobject exactly. - Still Unconfirmed: webhook signature/authenticity verification mechanism and
result_urlvs.webhook_urlprecedence.
2026-07-02 (update)¶
- Updated from a revised
Hivemind Payments APIPostman collection that adds real saved request/response examples for every endpoint (_postman_id: 1d8aa75a-627a-4674-84db-652eea37cc8d). - Response schemas are no longer inferred/illustrative for:
auth/token,payments/initiate,payments/status-query,merchants/wallets,transactions, andintegrations/applications— each page now shows a real (redacted) success example, and error envelopes are now confirmed as{"success": false, "message": "..."}. - Notable corrections from what was previously guessed:
- Access tokens expire after
3600seconds (1 hour); no refresh token is issued. POST /payments/initiate/returns202 Accepted, not200.GET /merchants/wallets/returns an array of wallets, not a single object.GET /transactions/pagination useslinks/count/pages/current_page, not a DRF-stylenext/previous/resultsshape.GET /integrations/applications/returns a generatedclient_id/client_secretpair, reinforcing that this call likely creates an application despite being sent asGET.- IP whitelisting is confirmed enforced (
403with a specific message), and the whitelist is tracked per application.
- Access tokens expire after
- Still Unconfirmed: exact error schema for
400/404/429/5xx, webhook payload shape and signature verification,result_urlvs.webhook_urlprecedence, and whetherapproved_onreflects a required approval step for new applications.
2026-07-02 (initial)¶
- Initial version of this documentation site, generated from the original
Hivemind Payments APIPostman collection. - Covers: authentication, API applications, initiate payment, transaction status query, account balance, transactions statement, and webhook callbacks, as captured in the source collection at generation time.
- Several areas were marked Unconfirmed pending confirmation from Hivemind Payments: token expiry/refresh, the API Applications method/purpose, all response schemas (no saved examples existed in the source collection at the time), webhook payload shape, webhook signature verification,
result_urlvs.webhook_urlprecedence, and the exact error response schema.
This page should be updated whenever the underlying API or the source Postman collection changes.