Reference
Changelog
Every change to this documentation, dated.
i
Following along: Check this page before an upgrade. Breaking changes never land in v1; they ship as a new version path.
July 2026#
Documentation 1.1 — scoped to the Republic of Congo launch (XAF, mobile money) and resolved against the consolidated review.
- Corrected the base URL: it includes
/v1, and endpoint paths are written relative to it without repeating the version. - Fixed the tax rule:
amount.valueis always the total charged. - Defined the balance identity:
available=total_inwardminustotal_outward, with settlements on the outward side. - Clarified that payouts reserve against
availableat submission, and that payouts cannot expire. - Documented the customer phone format, the list response envelope, date filters, line-item arithmetic and idempotency scope.
- Defined the payout field set and marked payment-only fields.
- Added key lifecycle, deprecation policy, incident and vulnerability reporting.
- Added a legal and regulatory notices page, including the prohibited-data rule for free-text fields.
- Simplified to a single XAF wallet and removed the display-currency balance endpoint from the launch docs.
- Documented a single production environment with guidance for testing against it; no sandbox at launch.
- Documented rate-limit behaviour: the gateway sheds load with 503 and no Retry-After; treat any 503 as back off and retry.
- Added standard service levels on the support page, with the agreement prevailing.
- Noted that all example phone numbers and identifiers are illustrative sample values.
Resolved in this revision#
- Webhook signing: HMAC-SHA256 over the timestamp and raw body, with worked verification code — Verifying webhooks.
- Rate-limit behaviour, service levels, environment and testing guidance, and the tax, phone, list and idempotency rules.
- Confirmed the regulatory framing: Maly is a technology provider only; custody of funds and wallets sits with the licensed institution — Legal and regulatory notices.
Still pending confirmation#
Three items depend on facts about the running system or on internal sign-off, and are marked in place until confirmed:
- The identifier field on a payout webhook — Webhooks.
- How a reversal or correction appears in the ledger after a final status — Status lifecycle.
Maly Payments API v1 · Documentation 1.1 · July 2026
Maly Tech Ltd. This guide is provided for information. Where it differs from your signed agreement, the agreement applies.
Maly Tech Ltd. This guide is provided for information. Where it differs from your signed agreement, the agreement applies.