Skip to content

Generated SDK #2897331076 (major) - #211

Merged
sdk-generation-automation[bot] merged 1 commit into
masterfrom
fireblocks-api-spec/generated/2897331076
Sep 30, 2026
Merged

sdk-generation-automation[bot] merged 1 commit into
masterfrom
fireblocks-api-spec/generated/2897331076

Conversation

@sdk-generation-automation

@sdk-generation-automation sdk-generation-automation Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Changelog

2026-09-30

Breaking Change

Lower limit on UTXOs per labelling request

Products: UTXO Management (Beta)

Scope: API + SDKs

  • What's new
    The maximum number of UTXO identifiers accepted in a single labelling request has been reduced from 200 to 50.

  • Impact
    Integrations submitting more than 50 identifiers in one request will need to split them into smaller batches.

Affected endpoints:

  1. Attach or detach labels to/from UTXOs

Stricter validation for UTXO transaction hashes

Products: UTXO Management (Beta)

Scope: API + SDKs

  • What's new
    Transaction hashes used to identify UTXOs must now be lowercase hexadecimal and no longer than 64 characters; uppercase hashes are no longer matched.

  • Impact
    Integrations sending uppercase or malformed transaction hashes will need to update their values to match this stricter format.

Affected endpoints:

  1. Attach or detach labels to/from UTXOs

Update required Canton onboarding parties

Products: Canton (Beta)

Scope: API + SDKs

  • What's new
    Onboarding a Canton participant no longer requires a provider party id, and now requires an upgrader party id used for model upgrade authority.

  • Impact
    Existing integrations must remove the provider party id and add the new upgrader party id when onboarding a Canton participant.

Affected endpoints:

  1. Make a Canton call

Simplify allocation withdrawal request

Products: Canton (Beta)

Scope: API + SDKs

  • What's new
    Withdrawing an allocation no longer requires specifying the vault account or asset, since these are derived automatically from the original transaction.

  • Impact
    Existing integrations that send vaultAccountId or asset when withdrawing an allocation will need to remove those fields.

Affected endpoints:

  1. Make a Canton call

Rename Canton offer domain values

Products: Canton (Beta)

Scope: API + SDKs

  • What's new
    The values identifying an offer's domain when responding to a Canton offer have changed from plural to singular form.

  • Impact
    Existing integrations that reference the plural domain values will need to be updated to use the new singular values.

Affected endpoints:

  1. Answer an offer

Add structured time-in-force type field

Products: Trading (Beta)

Scope: API + SDKs

  • What's new
    The time-in-force value for limit orders is now a structured object with a type field instead of a plain text value.

  • Impact
    Existing integrations that use fill-or-kill time-in-force will need to update how they specify it.

Affected endpoints:

  1. Create an order
  2. Get order details

OAuth credentials reference an mTLS configuration

Products: Webhooks V2

Scope: API + SDKs

  • What's new
    OAuth credentials now point at an mTLS configuration by webhookMtlsId, the same field and the same resource webhooks use, instead of carrying their own certificate. One certificate signed from GET /webhooks_settings/mtls_csr can serve both the token endpoint and the receiver. Deleting an mTLS configuration is refused while OAuth credentials reference it as well as webhooks; forceDelete=true detaches both and returns detachedWebhookOauthIds alongside detachedWebhookIds.

  • Impact
    Customers configure and rotate the certificate for their token endpoint the same way as for delivery, and can share one configuration between them. Existing certificates on OAuth credentials are migrated to an mTLS configuration automatically.

Affected endpoints:

  1. Create OAuth credentials
  2. Update OAuth credentials
  3. Get OAuth credentials by id
  4. Get all OAuth credentials
  5. Delete an mTLS configuration

Manage mTLS client certificates as their own resource

Products: Webhooks V2

Scope: API + SDKs

  • What's new
    The signed client certificate moves off the webhook and onto its own resource under /webhooks_settings/mtls, with endpoints to upload, list, read, replace and delete one. Several webhooks can share a configuration, so replacing the certificate is a single call instead of one per webhook. A webhook now references it by webhookMtlsId, alongside webhookOauthId. Deleting a configuration is refused with 409 Conflict while any webhook still references it, unless forceDelete=true is passed, which detaches those webhooks and returns their ids.

  • Impact
    Customers rotating an mTLS certificate used by several webhooks do it once, and can see which webhooks a configuration is in use by before removing it. Existing callers that set or read the certificate on the webhook itself must move to the new field names.

Affected endpoints:

  1. Create an mTLS configuration
  2. List the uploaded mTLS configurations
  3. Get an mTLS configuration by id
  4. Update an mTLS configuration
  5. Delete an mTLS configuration

Change travelRuleProviders from fixed enum to string

Products: Compliance

Scope: API + SDKs

  • What's new
    Changes the travel rule provider field from a fixed enum to a plain string to support dynamic provider lists and match actual API wire format.

  • Impact
    Customers using strict enum validation must update their code to handle any string value.

Affected endpoints:

  1. Look up legal entity by blockchain address

Add required proofOfOwnershipAvailable field to legal entity

Products: Compliance

Scope: API + SDKs

  • What's new
    Adds a required boolean field indicating whether Proof of Ownership creation is available for a given address, and updates example values for travel rule providers.

  • Impact
    Customers must update their models to include this new required field in legal entity responses.

Affected endpoints:

  1. Look up legal entity by blockchain address

Added

Detailed errors for failed UTXO labelling

Products: UTXO Management (Beta)

Scope: API + SDKs

  • What's new
    When a UTXO labelling request can't be completed, the response now lists each identifier that blocked it along with the specific reason it failed.

  • Impact
    Customers can identify exactly which identifiers failed and why, and resubmit the request with only the valid ones.

Affected endpoints:

  1. Attach or detach labels to/from UTXOs

Delete console users via API (beta)

Products: Console User

Scope: API + SDKs

  • What's new
    Adds an endpoint to request deletion of a console user, which goes through the workspace's configured approval policy before the user is removed.

  • Impact
    Customers can trigger console user deletion programmatically instead of using the console UI; this is a non-breaking addition and existing integrations continue to work.

Affected endpoints:

  1. Request deletion of a console user

Add customer-initiated Canton call operation type

Products: Off exchanges, Transactions

Scope: API + SDKs

  • What's new
    Transactions can now report a new operation type for customer-initiated Canton actions, such as withdrawing an allocation or responding to an offer.

  • Impact
    Customers can distinguish customer-initiated Canton operations from other transaction types in the API.

Affected endpoints:

  1. Create a new transaction
  2. Estimate transaction fee
  3. Add Collateral
  4. Remove Collateral

Add Canton transaction details to transactions

Products: Transactions

Scope: API + SDKs

  • What's new
    Transactions that are part of a Canton flow now include a cantonDetails block describing the offer, call, or settlement context.

  • Impact
    Customers can identify and inspect Canton-related transactions directly from the transaction response.

Affected endpoints:

  1. Get a specific transaction by external transaction ID
  2. Get a specific transaction by Fireblocks transaction ID
  3. Get transaction history

Support allocation withdrawal via Canton calls

Products: Canton (Beta)

Scope: API + SDKs

  • What's new
    The endpoint for submitting Canton operations now supports withdrawing an allocation, returning a real result instead of a not-implemented response.

  • Impact
    Customers can now withdraw Canton allocations through the API; other unimplemented call types are unaffected.

Affected endpoints:

  1. Make a Canton call

Add new trade execution failure reasons

Products: Trading (Beta)

Scope: API + SDKs

  • What's new
    Adds additional failure reason codes covering credit limits, quote expiration, desk rejection, requoting, and fill-or-kill cancellations.

  • Impact
    Customers get more specific information about why a trade execution failed.

Affected endpoints:

  1. Create an order
  2. Get order details

Add post-trade settlement type

Products: Trading (Beta)

Scope: API + SDKs

  • What's new
    Adds a post-trade settlement option where settlement happens bilaterally between the provider and customer after execution, rather than on-platform.

  • Impact
    Customers can select post-trade settlement for trades, in addition to the existing prefunded and DVP options.

Affected endpoints:

  1. Create an order
  2. Get order details
  3. Get trading provider by ID
  4. Get providers

Add limit order execution type

Products: Trading (Beta)

Scope: API + SDKs

  • What's new
    Adds support for placing and executing limit orders at a specified price, in addition to market and quote-based execution.

  • Impact
    Customers can now execute trades using limit orders through the API.

Affected endpoints:

  1. Create an order
  2. Get trading provider by ID
  3. Get providers
  4. Get order details

Add optional baseAmount to rate requests

Products: Trading (Beta)

Scope: API + SDKs

  • What's new
    Rate requests now accept an optional baseAmount field that specifies the amount to convert from, allowing quotes to be priced for a specific conversion size.

  • Impact
    Customers can request amount-specific rate quotes, and because the field is optional, existing requests continue to return rates unchanged.

Affected endpoints:

  1. Get rates

Add Address Registry Proof of Ownership endpoints

Products: Compliance

Scope: API + SDKs

  • What's new
    Adds endpoints to create and verify Proof of Ownership PDFs for blockchain addresses, enabling customers to prove address ownership for compliance purposes.

  • Impact
    Customers can generate verifiable PDF proofs of address ownership to share with counterparties or banks.

Affected endpoints:

  1. Create a Proof of Ownership PDF for an address
  2. Verify a Proof of Ownership export

Add UTXO selection config endpoints (beta)

Products: UTXO Management (Beta)

Scope: API + SDKs

  • What's new
    Adds beta endpoints to get and upsert workspace-level UTXO selection strategy configuration. Strategies include ASC, DESC, and ADAPTIVE.

  • Impact
    Customers can configure and inspect UTXO selection strategies at the workspace level through the API.

Affected endpoints:

  1. Get UTXO selection config
  2. Upsert UTXO selection config
  3. Get vault and asset UTXO selection config
  4. Upsert vault and asset UTXO selection config

Changed

Connected Accounts exits beta

Products: Connected Accounts

Scope: API + SDKs

  • What's new
    The connected accounts feature, including listing and adding connected accounts, is now generally available and no longer marked as beta.

  • Impact
    Customers can rely on the connected accounts endpoints as stable, generally available functionality.

Affected endpoints:

  1. Get connected accounts
  2. Add a connected account
  3. Get public key to encrypt connected account credentials
  4. Get connected account
  5. Disconnect connected account
  6. Get allowlist for connected account
  7. Sync allowlist for connected account
  8. Get a single allowlist entry for a connected account
  9. Get balances for an account
  10. Update connected account credentials
  11. Get supported trading pairs for an account
  12. Get exchange rates for an account
  13. Rename Connected Account

Clarify quote expiration time semantics

Products: Trading (Beta)

Scope: API + SDKs

  • What's new
    Clarifies that a quote's expiration time is provided directly by the liquidity provider and is not adjusted with any safety margin by the API.

  • Impact
    Customers should apply their own safety margin when using quote expiration times, if one is needed.

Affected endpoints:

  1. Create a quote
  2. Get all offers

Standardize Address Registry error responses

Products: Compliance

Scope: API + SDKs

  • What's new
    Updates error responses to use the standard error schema and adds 403/429 response documentation for rate limiting and blocked workspace scenarios.

  • Impact
    Customers get consistent error handling and clearer error documentation across address registry endpoints.

Affected endpoints:

  1. Look up legal entity by blockchain address
  2. List vault-level address registry opt-outs (paginated)
  3. Add vault accounts to the address registry opt-out list
  4. Get whether a vault account is opted out of the address registry
  5. Remove a single vault account from the address registry opt-out list

Fixed

Clarify Canton onboarding response guidance

Products: Canton (Beta)

Scope: API + SDKs

  • What's new
    Documentation for accepting or rejecting Canton onboarding offers now correctly points to where the available response options and offer status can be found.

  • Impact
    No behavior change; documentation is now accurate for integrations checking whether an offer can still be answered.

Affected endpoints:

  1. Answer an offer

Mark nullable fields in TravelRuleVASP schema

Products: Travel Rule

Scope: API + SDKs

  • What's new
    Adds explicit nullable: true annotations to VASP fields that may return null, including address fields, travel rule protocol statuses, and optional metadata.

  • Impact
    Customers using strongly-typed SDK clients will have accurate nullability information for VASP response fields.

Affected endpoints:

  1. Get VASP details
  2. Get All VASPs

Fix TravelRuleIssuers required field list

Products: Travel Rule

Scope: API + SDKs

  • What's new
    Removes regulatoryAuthorities, logo, and description from the required fields list to accurately reflect that these fields may be absent in responses.

  • Impact
    Customers will no longer see validation errors for missing optional VASP issuer fields.

Affected endpoints:

  1. Get VASP details
  2. Get All VASPs

@github-actions github-actions Bot added the major label Sep 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thank you for raising this! We will review it shortly. (Note that this SDK code is auto generated)

@sdk-generation-automation
sdk-generation-automation Bot merged commit ca350b2 into master Sep 30, 2026
32 checks passed
@sdk-generation-automation
sdk-generation-automation Bot deleted the fireblocks-api-spec/generated/2897331076 branch September 30, 2026 13:09
Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/node-releases/-/node-releases-2.0.54.tgz",
"integrity": "sha512-YHs7BmmcsdAI5Ozuf8JZo6PT0mv2GIWC9vMfvUC3dp65M8hn7Ux8CPL+2oBI7juNuj9d0ndhTcznq2ODBps9cQ==",
"version": "2.0.55",
"resolved": "https://registry.npmjs.org/node-releases/-/node-releases-2.0.55.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/node-releases/-/node-releases-2.0.55.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion
  1. Update the project’s .npmrc to use the approved internal JFrog/Artifactory npm registry, for example registry=https://<approved-internal-registry>/artifactory/api/npm/<repository>/. Use the exact registry URL provided by your organization.

  2. Remove the existing dependency installation and lockfile so npm does not retain public registry URLs:
    $ rm -rf node_modules package-lock.json

  3. Regenerate the dependencies using the configured internal registry:
    $ npm install

  4. Confirm the regenerated package-lock.json uses the approved internal registry for every resolved URL, including the node-releases package, and does not reference registry.npmjs.org or another public registry. Regenerating the lockfile is required because manually changing a single URL can invalidate the dependency metadata or leave other public references unchanged.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.420.tgz",
"integrity": "sha512-2yD6XreGusOfNV+dUcvipJEXc3n/n7fgr7996aszTG+YY5E4mqM4tOq/3uhP129cazL9YHbVWSpc79ePotWtPA==",
"version": "1.5.425",
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.425.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.425.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.425.tgz",
"resolved": "https://<VERIFIED_VALUE_REQUIRED>/artifactory/api/npm/npm-virtual/electron-to-chromium/-/electron-to-chromium-1.5.425.tgz",
View step-by-step instructions
  1. Configure the project to use the approved internal Artifactory npm registry in .npmrc. Replace the example URL with the registry URL provided by your organization:
    registry=https://example.com/artifactory/api/npm/npm-virtual/

  2. Authenticate to Artifactory using your organization’s approved method, such as npm login or environment-provided credentials. Do not store usernames, passwords, or tokens directly in .npmrc or source control.

  3. Remove the existing dependency installation and lockfile so npm does not retain public registry URLs:
    $ rm -rf node_modules package-lock.json

  4. Regenerate the dependencies using the configured internal registry:
    $ npm install

  5. Confirm the regenerated package-lock.json resolves packages through the approved Artifactory host, including electron-to-chromium, rather than registry.npmjs.org or another public registry.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.8.tgz",
"integrity": "sha512-V2NpofLblG64mfOtSgDhOJESZEGogzDMBv/q+W6oc4LXWP/q75eOXoOaaOu1EOadB9U4Bwx/e0yzbvwKH8zalA==",
"version": "4.28.9",
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.9.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/browserslist/-/browserslist-4.28.9.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.9.tgz",
"resolved": "https://<VERIFIED_VALUE_REQUIRED>/browserslist/-/browserslist-4.28.9.tgz",
View step-by-step instructions
  1. Update the project’s .npmrc to use the approved internal Artifactory registry, replacing the example URL with the registry supplied by your organization:
    registry=https://example.com/artifactory/api/npm/<approved-repository>/

  2. Configure registry authentication through the environment or an approved secret store. Do not commit credentials or tokens in .npmrc.

  3. Remove the existing dependency installation and lockfile:
    $ rm -rf node_modules package-lock.json

  4. Regenerate the dependency tree through the internal registry:
    $ npm install

  5. Confirm that package-lock.json contains internal Artifactory URLs for every resolved package entry, including browserslist, rather than registry.npmjs.org or another public registry. Do not manually edit individual URLs because the lockfile must be regenerated consistently.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.20.tgz",
"integrity": "sha512-H0ulySigv6icDJ1F7SjtdCD6PrhTpdYCmP0CactWy1+ekh0AFd0o1Wn5T8b+hnTmdBx19u9yhL6wvCylXMY7zw==",
"version": "2.11.21",
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.21.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.21.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.21.tgz",
"resolved": "https://artifactory.example.com/artifactory/api/npm/<VERIFIED_VALUE_REQUIRED>/baseline-browser-mapping/-/baseline-browser-mapping-2.11.21.tgz",
View step-by-step instructions
  1. Update the project .npmrc to use the approved internal Artifactory npm repository:
    registry=https://artifactory.example.com/artifactory/api/npm/<approved-repository>/
    Replace the placeholder with the exact registry URL provided by your organization.

  2. Configure Artifactory authentication using the project’s existing secure credential mechanism. Do not commit usernames, tokens, or passwords to .npmrc, package.json, or the lockfile.

  3. Remove the dependencies and lockfile so npm resolves every package through the internal registry:
    $ rm -rf node_modules package-lock.json

  4. Regenerate the lockfile with the internal registry:
    $ npm install

  5. Confirm the regenerated package-lock.json contains internal Artifactory URLs for every resolved entry, including baseline-browser-mapping, and does not contain registry.npmjs.org or another public registry URL.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants