Runtime source
Read capabilities from the server.
OpenDoc exposes its service name, protocol version, capability flags, event paths, error shape, permissions, and tool catalog from /protocol. Use it for feature detection instead of hardcoding assumptions.
curl https://api.opendoc.com/protocol
const protocol = await client.protocol();
if (protocol.version !== "1.0.0-headless") {
console.warn("Review OpenDoc compatibility before deploying");
}
Compatibility
What counts as breaking.
BreakingRemoving a route/tool, changing required auth, renaming stable error codes, changing transaction state semantics, or changing required request fields.Non-breakingAdding optional response fields, adding new tools, adding new error codes, adding event types, or clarifying human-readable messages.Client ruleSwitch on stable codes and IDs, ignore unknown optional fields, and feature-detect capabilities from /protocol.Log
Recent documentation and protocol-facing changes.
2026-08-06Events rebuilt on a transactional outbox: at-least-once webhook delivery with retries (30sā24h, 7 attempts), timestamped signatures (t=<unix>,v1=<hex>; legacy bare-hex header deprecated), x-opendoc-event-id dedupe key, permission-filtered SSE/webhooks, and new delivery-log + redeliver endpoints. SDK verifies both signature schemes.2026-08-06Truth pass: new sandbox quickstart (signup ā committed S0āS4 booking) with the stable sandbox fixture IDs published; API-reference links repointed at the live contract (GET /protocol + /protocol/openapi.json) and the v1.1 spec relabeled as a design archive; sandbox keys documented as pre-satisfying the Health-Key/IA2/consent preconditions; legacy local mock server (sandbox-server.js) removed; llms.txt/robots.txt added for agent crawlers; agent contract JSON files now ship in the built site.2026-07-29Docs status pass: every capability is labeled live-today (sandbox) or opening-with-first-partners (live mode); SDK distribution status corrected.2026-07-04Sandbox self-serve opened: POST /developers/signup issues instant odk_sandbox_ keys confined to a synthetic provider with simulated payments. Live mode remains partner-gated.2026-06-03Added live docs for SDK, auth, transactions, provider onboarding/access, events, errors, testing, discovery/offers, environments, security/PHI, changelog, and provider payouts.2026-06-03Aligned docs branding with the marketplace brand system and static OpenDoc mark.2026-06-02Protocol discovery points to https://docs.opendoc.com; API root returns minimal service and documentation metadata.1.0.0-headlessCurrent runtime protocol version exposed by GET /protocol.Partner process
Before upgrading an integration.
1
Fetch
/protocol.Record version, tool list, auth requirements, permissions, and event paths.2
Run public smoke.Check
/health, /protocol, and one route from each public discovery family you use.3
Run protected smoke in sandbox mode.There is no separate staging host ā use a sandbox key against
api.opendoc.com with synthetic actors, synthetic slots, simulated payment mode, and stable idempotency keys (see Environments).4
Archive evidence.Save commands, correlation IDs, route results, and environment class for support and audit traceability.