> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vellaro.io/llms.txt
> Use this file to discover all available pages before exploring further.

# What's new

> API changes that matter to developers building on Vellaro.

## October 11, 2026

### Cart

* At sign-in the guest cart merges into the account's cart, at checkout too: no more lost
  items when the store asks shoppers to sign in to pay.
  [Details](/en/guides/build-storefront).

## October 10, 2026

A major release of the admin area and the storefront. The changes are designed not to break
existing clients, but some need action on your side. This entry also covers the October 9
changes not yet described here: "sign out everywhere", 2FA enabled with the current password,
validation errors in the standard envelope (`validation.failed`).

<Warning>
  **To do in your clients**

  * **Always** store the new refresh token returned by every `POST /auth/refresh`.
  * In the cart show `unit_price`, not `variant.price` or `variant.sale_price`.
  * Take the payment methods from `GET /settings/payment-methods` and always send
    `payment_method`: the checkout rejects methods that are switched off.
  * Treat the `refunded` status (Admin API and MCP) as a money movement.
  * Translate the new `error_code` values listed below.
</Warning>

### Security and authentication

* **Rotating refresh tokens** with reuse detection: every refresh returns a new refresh
  token. A 60-second grace period covers tabs and concurrent requests; for a staff account,
  reusing a superseded token closes the session (401 `auth.refresh_token_reused`). Tokens
  issued before the release are valid once and then move to the new scheme.
  [Details](/en/authentication).
* `POST /auth/logout` closes the session of the refresh token presented; `?all=true` closes
  every session of the account (401 `auth.session_revoked` on earlier tokens).
* **Single-use** TOTP codes and **10 recovery codes** on first 2FA activation, which can be
  regenerated with `POST /auth/2fa/recovery-codes`. `GET /auth/me` exposes
  `recovery_codes_remaining` and `is_owner`.
* Deleted store: 403 `auth.tenant_unavailable` at login and refresh.

### Cart, checkout, and gift vouchers

* The cart exposes `items[].unit_price` (the applied price), `min_order_total`, and
  `guest_checkout_enabled`; `variant.sale_price` is `null` outside the sale window.
* The checkout enforces the store rules: 422 `checkout.min_order_not_met`, 401
  `checkout.login_required`, 422 `checkout.payment_method_disabled`.
* **Gift voucher** at checkout with `voucher_code`: balance reserved and released if the
  payment doesn't go through, order paid directly (`payment_method: "voucher"`) when the
  voucher covers everything, `voucher.*` errors.
* A coupon's discount never exceeds the subtotal; a "free shipping" coupon zeroes the shipping
  cost.
* "Pay now" (`POST /orders/{order_id}/pay`, which reopens the payment of an online order) is
  now documented; capturing PayPal on a canceled order answers 400 `order.not_payable`.
  [Details](/en/guides/build-storefront).

### Pricing and catalog

* Cart and checkout apply **special prices** and the customer-group rule: what the cart shows
  is what the checkout charges.
* The product detail has `special_price` and `stock_status_name`; the `in_stock` and price
  filters and the price ordering work on the effective price.
* Special prices and quantity discounts only with a price greater than zero (422
  `product.price_rule_not_positive`).

### Orders, subscriptions, and storefront

* The order history the customer sees contains only status changes and public notes.
* Subscriptions: new terminal status `completed`; at purchase the customer pays the product
  price and the trial only moves the first renewal.
* `POST /marketing/track` counts visits from campaign links; `GET /settings/store-info`
  exposes `catalog` and `seo`.

### Admin API

* Refunds and "mark as paid" only for some roles (403 `order.refund_forbidden`,
  `order.payment_forbidden`); affiliate payment details also require the `reports`
  permission.
* Stable, protected store owner (`is_owner`, 403 `user.owner_protected` and
  `user.owner_only`, 409 `user.last_admin`).
* API tokens don't manage users or credentials (403 `auth.api_token_forbidden`).
* `PATCH /admin/orders/{id}` to `refunded` performs a **real refund**; returns start from the
  order lines.
* `POST /admin/products` saves every field and creates inline variants (409
  `product.sku_taken`).
* Validated coupons and real deletion of never-used ones; gift vouchers with balance and
  history.
* Recurring plans: `duration` = interval, `cycle` = total charges.
* Customer anonymization, affiliate commissions per currency, reports with net revenue in the
  store's currency and time zone, `orders.guest_checkout_allowed` setting.
  [Details](/en/guides/admin-api).

### Webhooks

* HTTPS-only URLs to public hosts (422 `webhooks.url_https_required`,
  `webhooks.url_not_public`, `webhooks.url_invalid`).
* Test delivery, redelivery, secret rotation, and a safe excerpt of the response in the
  delivery log. [Details](/en/webhooks).
* New `order.refunded` event for total and partial refunds; every order event carries
  `amount_refunded`.

### MCP

* The admin `update_order_status` tool with `status: "refunded"` performs a **real refund** of
  the remaining amount through the payment gateway. The other tools are unchanged.
  [Details](/en/ai-mcp).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.