
Developer updates roundup: what's new on Zid for partners
New Wallet and Blogs APIs, webhook health tracking, a Sept 30 deadline for profile and webhook changes, more pricing plans, and new AI tools for building on Zid.
Two required changes due September 30, 2026
Two changes announced in June on the partner changelog have the same deadline: September 30, 2026. Check both before anything else.
GET v1/managers/profileis being retired. Move to the new Account API endpoints, each with its own OAuth scope: Account Identity and Account Profile, plus store endpoints for details, branding, localization, social, operations and business information.- Basic Authentication becomes mandatory for webhooks. Provide a
usernameandpasswordwhen you create or update a webhook. Zid then sends anAuthorization: Basicheader with every delivery, so your server can verify the request came from Zid.
New and expanded APIs
- Wallet APIs (Sept 8, 2026): 16 new endpoints in three areas: Cashback Rules (5), Wallet Analytics (2) and Manager Customer Wallet (9), which covers balances, transactions, pending cashback, credits and debits, and exports.
- Blogs API (July 22, 2026): a v2 API with 41 endpoints to manage a store's blog end to end, including settings, categories, posts, post media, tags and read-only storefront reads. It supports bulk operations, content import and export, and scheduling via
scheduled_at. - Order attribution (July 12, 2026): the View Order response now includes an optional
marketing_channel_sourceobject withvisit_source,campaign_name,referrer_link,device_type,browserandoperating_system. Every field can benull, and no existing fields changed.
More reliable webhooks, clearer rate limits
Webhook Health Tracking (June 28, 2026) gives every webhook a health_status of healthy, degraded or broken, based on failures in a sliding one-hour window:
- Degraded: 10 or more failures in the past hour. Delivery continues, but you should investigate.
- Broken: 30 or more failures in the past hour. Delivery stops until you recover the webhook with a new target URL. Reusing the same URL isn't allowed.
- Each event is retried up to 3 times (after 1, 5 and 15 minutes) before it counts as a failure, and HTTP 429 responses don't count at all.
- Three new endpoints: health summary, list broken webhooks, and recover broken webhooks.
The same day, the rate limit was set at 60 requests per minute, per application per store, with the Leaky Bucket algorithm handling the queue. For status tracking, Zid recommends webhooks over polling.
App Market changes
- Up to 8 subscription plans per app (June 2026), up from 4. That's enough for 4 tiers, each with monthly and annual billing.
- In-app support channel (July 14, 2026): every app must now include a visible, working support channel inside the app: a live chat widget, an in-app support form, or a direct link to a ticketing system. Since July 17, 2026, apps in review without one are rejected.
For theme developers
- Product Brands (Sept 15, 2026): use
brands.jinjafor the/brandspage andbrand.jinjafor a single brand.product.jinjanow exposesproduct.brand.nameandproduct.brand.logo. - Bank Discounts (Aug 20, 2026, action required): add
{% include 'vitrin:shared/bank_discounts.jinja' %}to your product details and cart pages, or merchants' bank discounts won't appear there. Checkout needs no theme changes. - Coupon visibility (Aug 19, 2026): merchants can now hide the coupon field. Check
store.settings.checkout.is_coupon_form_enabledand hide the whole coupon section only when it is explicitlyfalse.
Available now in the docs
These guides don't come with a release date, but they're live on docs.zid.sa and worth a look:
- Zid AI Agent Skill: an open-source skill that helps Claude, Claude Code, opencode and other agents build Zid integrations with the correct OAuth, multi-tenant and error-handling patterns. It was announced on September 8, 2026.
- Our custom MCP server: connect Cursor or VS Code with Cline to Zid's API documentation.
- Embedded Apps: run your app inside the merchant dashboard, using the six-step auth flow.
- Zid MUI and Zid SDKs: UI components that match the dashboard, and a Python SDK, with Laravel and TypeScript listed as coming soon.
Key takeaways
- Before September 30, 2026, migrate off
GET v1/managers/profileand add Basic Auth to your webhooks. - New Wallet (16 endpoints) and Blogs (41 endpoints) APIs open new app categories.
- Watch your webhooks'
health_status. A broken webhook stops receiving events until you recover it. - Apps now need a working in-app support channel, and can offer up to 8 plans.
Sources
- [Docs Update - Apps] Action Required: Upcoming API Changes by September 30, 2026
- [Docs Update - Apps] Action Required: Webhook Security Changes by September 30, 2026
- ZID Weekly Updates: Agent Skill & New Wallet APIs
- [New Feature - Apps] Blogs API: 41 New Endpoints to Manage a Store's Blog
- [Improvement - Apps] Marketing Channel Source Now Available in the View Order Response
- [New Feature - Apps] Webhook Health Tracking
- [Improvement - Apps] Updates to Apps Rate Limiting
- [Improvement - Apps] More Pricing Flexibility: Up to 8 Subscription Plans per App
- [New Requirement - Apps] Add a Working In-App Support Channel
- New Coupon Visibility Setting for Vitrin Themes
- Vitrin Changelog - Zid Docs
- Webhook Health Tracking - Zid Docs
- Rate Limiting - Zid Docs
- Create Webhook - Zid Docs
- Zid AI Agent Skill - Zid Docs
- Our custom MCP server - Zid Docs
- Embedded Apps - Zid Docs
Start building on Zid
Sign up in the partner portal, then build and test on a development store.


