Skip to content

Changelog

2026-09-30

  • The API base URL is now https://api.cloudpay365.com/api/v1/ (was https://api.hivemind.co.ke/api/v1/). Every example request on the site uses the new host; paths, methods, and payloads are unchanged.
  • The docs site moved to https://docs.cloudpay365.com.

2026-09-22 (sandbox)

  • Added From Signup to Live: the end-to-end path a new merchant follows, from creating an account through to production credentials, with what blocks each step.

  • Sandbox is real. Merchants now create their own sandbox credentials in the portal, at any tier, without contacting support — and a sandbox application charges a separate sandbox wallet with a play balance. Previously an application's environment was recorded and then ignored, so "sandbox" credentials moved real money.

  • Added Sandbox and Going Live: what differs between the two environments, and the go-live checklist.
  • Sandbox Credentials & Test Numbers replaces its placeholder table with the real outcome-by-destination table: success, cancelled, insufficient funds, timeout, ambiguous payout, and late result.
  • Test Scenarios rewritten around those six outcomes, including the failure cases that are hard to arrange deliberately in production.
  • IP Whitelisting now states that the check is production-only and fails closed there, and that registering an address is a go-live requirement rather than something to discover on your first live request.
  • Verifying & Testing Webhooks now documents sandbox as the supported way to test a handler, including callbacks that fail, never arrive, or arrive late.
  • Production credentials are now gated. They are issued only once a merchant is verified and has proved the integration in sandbox — a successful collection, a successful payout, a webhook that returned 2xx, and a whitelisted IP. Going live does not disable the sandbox application; merchants keep both.

2026-09-15

  • Rebranded the site as Hivemind Payments: new name throughout, Hivemind Payments logo and favicon, and the brand color palette (orange #FB5607, rust #C15227, black) in light and dark modes. The API base URL is now https://api.hivemind.co.ke/api/v1/ (was https://api.nextplay.co.ke/api/v1/).
  • Removed the API Applications page (GET /integrations/applications/) from the API Reference. Client credentials are obtained from Hivemind Payments.
  • Added an Authentication page to the API Reference for GET /auth/token/, using the standard endpoint layout.
  • Updated links on the Home, Overview, Quickstart, Sandbox Credentials, IP Whitelisting, and Result URL Callbacks pages to match.

2026-07-02 (webhook payload confirmed)

  • Payload Reference now documents the real result_url callback payload instead of an inferred shape.
  • Confirmed the callback body is the transaction object unwrapped (no {"success", "data"} envelope, unlike every other endpoint response), and that its fields match Transaction Status Query's data object exactly.
  • Still Unconfirmed: webhook signature/authenticity verification mechanism and result_url vs. webhook_url precedence.

2026-07-02 (update)

  • Updated from a revised Hivemind Payments API Postman collection that adds real saved request/response examples for every endpoint (_postman_id: 1d8aa75a-627a-4674-84db-652eea37cc8d).
  • Response schemas are no longer inferred/illustrative for: auth/token, payments/initiate, payments/status-query, merchants/wallets, transactions, and integrations/applications — each page now shows a real (redacted) success example, and error envelopes are now confirmed as {"success": false, "message": "..."}.
  • Notable corrections from what was previously guessed:
    • Access tokens expire after 3600 seconds (1 hour); no refresh token is issued.
    • POST /payments/initiate/ returns 202 Accepted, not 200.
    • GET /merchants/wallets/ returns an array of wallets, not a single object.
    • GET /transactions/ pagination uses links/count/pages/current_page, not a DRF-style next/previous/results shape.
    • GET /integrations/applications/ returns a generated client_id/client_secret pair, reinforcing that this call likely creates an application despite being sent as GET.
    • IP whitelisting is confirmed enforced (403 with a specific message), and the whitelist is tracked per application.
  • Still Unconfirmed: exact error schema for 400/404/429/5xx, webhook payload shape and signature verification, result_url vs. webhook_url precedence, and whether approved_on reflects a required approval step for new applications.

2026-07-02 (initial)

  • Initial version of this documentation site, generated from the original Hivemind Payments API Postman collection.
  • Covers: authentication, API applications, initiate payment, transaction status query, account balance, transactions statement, and webhook callbacks, as captured in the source collection at generation time.
  • Several areas were marked Unconfirmed pending confirmation from Hivemind Payments: token expiry/refresh, the API Applications method/purpose, all response schemas (no saved examples existed in the source collection at the time), webhook payload shape, webhook signature verification, result_url vs. webhook_url precedence, and the exact error response schema.

This page should be updated whenever the underlying API or the source Postman collection changes.