Skip to main content

v1.11.19

September 25, 2026 Core SDK
  • three_ds.completed now reports the 3DS outcome instead of the payment outcome
    When the 3DS authentication succeeds and the acquirer then declines the payment, three_ds.completed reports result: authenticated and the decline stays on payment.resolved. The result is read from the last transaction of the payment the SDK already receives (its provider and response code). When that transaction is not available, for example when the final status arrives through the websocket, the result still follows the payment outcome as before. Known limit: providers that authenticate and authorize in a single transaction and do not expose a 3DS response code, today Adyen (about 200 Adyen 3DS sessions per week), report their 3DS declines as authenticated until.
Customer form
  • Brazil Pix: document type inferred from the number, and one Full name input instead of first + last name
    For Brazil, when the available documents are CPF and CNPJ (a PASSPORT entry is ignored for Pix), the document-type selector is no longer rendered: the field is labelled “CPF / CNPJ” and the type is inferred from the digits (11 or fewer → CPF, more → CNPJ), so masking, validation and the submitted payload are unchanged. The customer form also renders a single “Full name” input in place of first and last name, split on the first whitespace run into first_name / last_name; languages that write names without spaces (ja, ko, zh, th) keep the two inputs. The document auto-detect is on by default and can be switched off per account through the sdk-ms feature document_type_auto_detect. The Full name input is on for the Moon Active experience and otherwise opt-in per account through the sdk-ms feature unified_full_name; the all-merchants roll-out follows with a Checkout Builder choice (“Full name” vs “First + last name”). Each name part must have at least 2 characters (the same minimum the two separate inputs applied), so “Ana B” is rejected with the “Enter your first and last name” message; the 100-character cap is unchanged. Customer-field copy (global, no experience gate): the slim Full name input reads “Enter full name” instead of the first-name hint; the slim phone group carries one “Phone” label over the prefix selector and the number input keeps only its placeholder (only the number box turns red on error); in English the e-mail field is labelled “Email” (Stripe spelling); on the default floating-label form the prefix selector shows its “Country” label only while no prefix is selected, so the preselected flag + prefix sit centred in the box.
Card form
  • Slim card form keeps the installments while expiry and CVV are typed
    The slim card form keeps the installment options, and the shopper’s selected plan, while the expiration date and CVV are being typed. Only card-number events refresh the card information and the installments, so a new card number still reloads them.
  • Rotating card-brand logos in the empty card-number field (Moon Active experience)
    When the Moon Active experience is enabled for the account, the empty card-number field now shows Visa, Mastercard and Amex plus a fourth slot that rotates Discover, Diners Club, Maestro and Elo every 3 seconds, until the shopper types enough digits for the brand to be detected. The SDK forwards the moonActiveExperience flag to the card form; the logos are rendered by sdk-web-card 1.89.3. Merchants without the Moon Active experience are unaffected.

v1.11.17

September 24, 2026 PayPal
  • PayPal Enrollment button no longer hidden or stuck on stale sessions
    The PayPal Enrollment express button (PayPal JS SDK v6) no longer requires provider_token_id to render for vault enrollment; only the billing agreement flow uses it. When the merchant creates the payment, the button now gives PayPal the setup token of the enrollment that payment created, falling back to the one from the config, and only the latest click waits for the payment, so a cancelled attempt can no longer be resolved by a later one.
  • Venmo button on the PayPal v6 express button
    The PayPal express button now reads the merchant’s ENABLE_FUNDING provider-config param: when it includes venmo, the SDK creates the PayPal JS SDK v6 instance with the venmo-payments component and renders a Venmo button under the PayPal button once PayPal confirms the buyer is eligible (US buyer paying in USD). Venmo pays the same PayPal order. On sandbox credentials the SDK also sends testBuyerCountry=US, as PayPal’s Venmo test guide requires, so QA outside the US sees the button; production never sends it.
Core SDK
  • Yuno Pay Button in the Enrollment Flow
    With the Yuno Pay button enabled, the enrollment Save button looks disabled until the form is complete and stays clickable to reveal pending errors. With the Yuno Pay button disabled, enrollment and payment forms keep the always-enabled button.
Apple Pay
  • Apple Pay Card Acceptance Filters
    The Apple Pay request now takes merchantCapabilities and supportedCountries from the checkout session’s wallet_card_acceptance (supported_funding_types and supported_countries), so ineligible cards are greyed out in the sheet. Sessions that declare nothing keep today’s behaviour.
Google Pay
  • Google Pay sheet shows a translated “Total”
    The Google Pay payment sheet now labels the amount with “Total” in the checkout language instead of Google’s default merchant line. When the payment includes a valid summary_items breakdown, the sheet keeps the breakdown’s own total label.
Alternative Payment Methods
  • Explicit institution number and transit number fields for Canadian PAD
    Canadian pre-authorized debit (PAD) now collects the bank’s Institution number (3 digits) and Transit number (5 digits) as their own explicit fields, instead of relying on the shopper deriving a combined routing number. Both preserve leading zeros as strings and are optional everywhere, so existing integrations that still send routing_id are unaffected.

v1.11.16

September 22, 2026 Core SDK
  • Fraud scripts and the Samsung Pay Portuguese button follow the white-label host
    With apiUrl / assetUrl set in Yuno.initialize(), the Yuno-hosted Forter script, the Riskified SRI beacon and the Portuguese Samsung Pay button image loaded straight from *.y.uno instead of the merchant’s proxy. They now load from the configured host first. If the proxy can’t serve them (route missing, no CORS for SRI scripts, stale copy), they load from Yuno as before, so no fingerprint or button is lost. To keep them on the merchant host, the proxy must forward /sdk-static-bundles-ms/* (with its query string, and CORS for SRI) to <env>.y.uno and /wallets/* to sdk.prod.y.uno. Merchants that do not use white-label are unaffected.

v1.11.15

September 22, 2026 Payment Actions
  • Fixed False Payment Timeout Error
    The processing loader no longer shows “Transaction failed” after it has been closed or while the page is in the background, and it now uses the timeout configured for the checkout.

v1.11.14

September 22, 2026 Card Payments
  • Minimal card form copies are translated in every supported language
    The labels and placeholders of the minimal card form (minimal_card_form_enabled) were only translated in 10 of the 34 languages the SDK ships, so merchants on any other language — Greek among them — saw the raw translation keys (minimal_card_number_label, minimal_card_number_placeholder, …) inside the card form instead of the copies. The seven copies now exist in all 34 languages, reusing each language’s existing card terminology. Merchants without the flag are unaffected.

v1.11.13

September 22, 2026 Card Payments
  • Card brand icons follow the white-label host
    With apiUrl / assetUrl set in Yuno.initialize(), the card brand logo in the card number field (the other icons inside the card fields) loaded from icons.prod.y.uno instead of the merchant’s proxy. The SDK now passes both hosts to every card iframe it creates (card form, secure fields mediator, each secure field), so those icons load from the configured host. The saved-card preview logo also needs sdk-web-card 1.89.2. An empty apiUrl / assetUrl string is now treated as unset. Merchants that do not use white-label are unaffected.
  • Minimal card form for merchants with card as the only selectable method
    Behind the minimal_card_form_enabled feature flag (off by default, enabled per account by Yuno), the Full checkout renders a bare card form when card is the only selectable payment method and the unfolded card form is on: no radio row or list frame, a label above every field, expiry and CVV as two separate boxes, and the card brand shown at the start of the number field once the BIN resolves. Express buttons (Google Pay, Apple Pay, PayPal) keep rendering above it. The regular list is used whenever there is a second selectable method, a saved card, Click to Pay, or the slimmer form. Requires sdk-web-card 1.89.2. Merchants without the flag are unaffected.

v1.11.12

September 21, 2026 Core SDK
  • The Full checkout shows its payment methods once, fully loaded
    The Full and Seamless Full checkouts show a compact loader until the express buttons (Google Pay, Apple Pay, PayPal and the others) and the card fields are ready, then grow into the complete payment method list in one short animation, instead of showing the list first and adding each button as it loads. After 2 seconds the list is shown anyway and a slower button appears when it is ready. Enabled per merchant with the reveal_methods_together_enabled feature flag; without it the checkout loads as before.

v1.11.11

September 21, 2026 Core SDK
  • Payment Link: the selected payment method follows the Payment Link accent color
    On a Payment Link, the border of the selected payment method took the accent color of the SDK Checkout styling instead of the one published for the Payment Link in Checkout Builder. The Payment Link page now hands its accent color to the SDK, which uses it in place of the SDK Checkout one. Payment Links without published styling, and every other integration, keep the current behavior. No merchant integration changes are required.

v1.11.10

September 19, 2026 Apple Pay
  • Android phones no longer load Apple Pay resources
    Android phones now skip Apple Pay right away: the SDK no longer downloads the Apple Pay button code or Apple’s SDK there, and no longer requests the Apple Pay configuration, including in the external buttons flows. On those phones Apple answered that the device cannot pay in nearly every production session, and these downloads took up to several seconds on slow connections, competing with the other wallet buttons. Because Apple Pay no longer takes the express slot on those phones, Google Pay is shown as the express button instead of in the payment method list. As a result, the rare Android phones where Apple allowed paying through a QR code no longer show the Apple Pay button. Android tablets and desktop browsers still ask Apple and keep showing it where Apple allows it, and so does any page that already loads Apple’s SDK itself.

v1.11.9

September 18, 2026 PayPal
  • PayPal Enrollment on JS SDK v6
    The PayPal enrollment button (vault and billing agreement) now uses PayPal’s JS SDK v6, the same one as the PayPal payment button, so a checkout no longer downloads two PayPal SDKs and the button renders directly in the page instead of inside an iframe.
  • PayPal retry after a failed start
    When PayPal’s checkout window failed to open, clicking the button again created a second payment for the same purchase. The retry now reuses the payment that was already created instead of creating another one.
Core SDK
  • The PayPal Enrollment button gets its configuration earlier on the Full checkout
    The Full and Seamless Full checkouts request some payment method configurations early, before the payment method list is known, so the express buttons that need them do not wait. The early PayPal request was almost never used, because very few checkouts enable the standard PayPal button. It is replaced by an early request for PayPal Enrollment, which is enabled far more often.
  • The Google Pay button checks eligibility earlier
    The Full and Seamless Full checkouts and the external buttons start the Google Pay eligibility check as soon as the checkout knows Google Pay is enabled, instead of after the payment method list renders, so the button appears sooner. Shoppers who cannot use Google Pay see exactly what they saw before.
  • Express buttons load faster inside the Instagram and Facebook apps on Android
    Inside the Instagram and Facebook apps on Android, the fraud prevention scripts that the express buttons (PayPal, Google Pay, Apple Pay, Samsung Pay, Revolut Pay) and the preselected payment method start while the checkout loads now start once those buttons have finished loading, or after 3 seconds at most. The buttons appear sooner on these devices and are less likely to be hidden by the load timeout. If the shopper pays before the scripts have started, they start at that moment and the payment waits a little longer for the fraud data. Other browsers are unchanged.
Apple Pay
  • Devices that cannot pay with Apple Pay no longer request its configuration
    The Apple Pay button now asks Apple whether the device can pay before it requests the Apple Pay configuration, instead of after. On devices where the answer is no (most Android phones), the SDK skips the configuration request, the backend Apple Pay session behind it and the amount request, which frees network and main-thread time for the other wallet buttons. The early configuration requests of the Full checkouts follow the same rule. Every device that shows the Apple Pay button today keeps showing it, including third-party desktop browsers and the Android devices where Apple allows paying through a QR code.
Payment Methods
  • Click to Pay email form is fully translated
    After the “or” separator fix in 1.11.8, the rest of the Click to Pay email form was still in English in Arabic, German, French, Italian, Japanese, Korean, Dutch, Polish, Russian, Swedish, Turkish, Vietnamese and Chinese (simplified and traditional): both option labels, the “How does Click to Pay use my information?” helper and its tooltip, and the “add this card to Click to Pay” checkbox are now translated. Filipino, Indonesian, Malay and Thai had no translation for this form and showed it in English; they are now translated too. The transaction error message is also translated in Korean and corrected in Japanese and Turkish, where it wrongly said the payment method could not be deleted.
Performance
  • Checkouts with a session request country data once
    Every checkout mount asked for country data twice when it had a checkout session: once by country and once by session. Both answers carry the same country list, links and payment method data, and the session one also carries the merchant’s own document types, so the SDK now asks only by session and keeps the request by country for flows without a session. Phone prefixes, document types, privacy links and card brands come from that single answer across card, customer, Click to Pay and PayPal Braintree forms.

v1.11.8

September 18, 2026 Payment Methods
  • Click to Pay shows the “or” separator in the shopper’s language
    The separator between “access my linked cards” and “enter the card manually” in the Click to Pay email and one-time-code screens read “Ó” in Portuguese and Spanish, and stayed in English in fourteen other languages. It now reads “OU” in Portuguese, “O” in Spanish, and is translated in Arabic, German, French, Italian, Japanese, Korean, Dutch, Polish, Russian, Swedish, Turkish, Vietnamese and Chinese.

v1.11.7

September 17, 2026 Core SDK
  • Internal logging improvements
    Better internal performance logs for the express buttons. No functional or API changes.

v1.11.6

September 17, 2026 Core SDK
  • SDK events carry the public SDK version and the retry-chain root from the first attempt
    Every SDK event now includes sdk_version_external (the public version the merchant installs) next to the internal sdk_version, and connection_effective_type when the browser exposes it. original_checkout_session is sent from the first attempt, equal to the checkout session itself until a retry links it to its root. Starting a new checkout in the same page no longer inherits the previous retry chain, and the status page keeps retry_count and payment_method.saved for the session it shows.
  • checkout.abandoned sends the attributes its contract requires
    checkout.abandoned now carries reason (tab_switch when the page is hidden, close_button when the enrollment is closed), elapsed_ms since checkout.opened, and the interaction counters. fields_errored is emitted with the other counters on checkout.abandoned and checkout.completed, counting the field validation errors shown during the checkout.

v1.11.4

September 16, 2026 Checkout
  • Granular loading events for progressive checkout rendering
    The onLoading callback now reports two new milestones: PAYMENT_LIST_RENDERED as soon as the payment method list is ready, and ALL_PAYMENT_METHODS_RENDERED once every express button above the fold has loaded or failed. Integrators can remove their skeleton when the list is ready instead of waiting for the slowest express button or its 5s timeout. SEAMLESS_LIST_BUTTONS is unchanged, so existing integrations are not affected. Removing a saved payment method puts all three milestones back into loading while the list reloads.

v1.11.3

September 15, 2026 Core SDK
  • Authorization Copy Under the Single Pay Button Sticks to the Selected Method
    With the Yuno pay button in FLOATING or STICKY position, the stored-credential authorization copy shown below the button could disappear or belong to another method after the shopper visited more than one payment method: a form left mounted in the payment method list was publishing its own save state under the newly selected method. Each form now publishes only under the method it opened with.

v1.11.2

September 15, 2026 Card Payments
  • Honor the Keyboard Next Key Across the Card Form Secure Fields
    Pressing Next on the mobile keyboard now advances focus through the card secure fields and on to Cardholder Name after the last one, in both the full card form and the split secure fields form, for every account, including those with automatic field advancement turned off.
  • Load the Unfolded Card Form Without Waiting for Customer Data
    The unfolded card form in the payment method list now starts loading its secure card fields as soon as it is rendered, instead of waiting for the issuers, country data, and installment requests that feed the customer fields. A placeholder holds the place of the customer fields until that data arrives; the fields then appear with the phone and document country pre-filled, and the card fields keep what the shopper already typed. Until the customer fields are shown, the form reports itself as not valid. A payment started before the data arrives keeps the loader up (emits onLoading with DOCUMENT), waits for the data and the card fields, then runs the normal validation. No merchant integration changes are required.
Core SDK
  • Contextual authorization copy for stored payment methods
    Card and other non-direct-debit payment methods now render the stored-credential authorization text sent by the backend (localized and with the merchant’s business name). The payment + save wording (mandate_type RECURRENT) shows once the method will be stored: the buyer ticks “save” or the merchant forces card.vaultOnSuccess. The enrollment and subscription wordings (mandate_type ENROLLMENT / SUBSCRIPTION) are settled by the backend from the session and render as they arrive, as will any future scenario; such a wording keeps the payment method form on screen even when the buyer has nothing left to fill in. The text is Yuno-owned and follows the Yuno pay button: with yuno_pay_button_position ACCORDION it sits right below the inline button, with FLOATING or STICKY it moves below the single pay button (above the Powered by Yuno badge), and with a merchant-rendered button it stays at the bottom of the payment method form. Direct-debit mandates keep their scheme text inside the form. Wallets never show it.
  • Faster Express Buttons in the Full Checkout
    The Full and Seamless Full checkouts now request the configuration of every enabled payment method as soon as the payment method list is known, in parallel with the initial settings call, instead of one method at a time after the first render. Express buttons (Apple Pay, Google Pay, PayPal, PayPal enrollment, Samsung Pay, Revolut Pay, PayPal Braintree), Click to Pay and the card 3DS check find their configuration already loaded, which removes a full network round trip from the mount on slow connections. No merchant integration changes are required.
  • Lighter SDK Boot: Browser Detection Moved Server-Side
    The SDK no longer bundles and runs a user-agent parser on every page load to describe the browser, OS and device in its monitoring events; Yuno’s backend now derives that information from the request itself, with a handful of navigator hints sent along to keep the same accuracy (Brave, iPadOS in desktop mode, mobile flag). The bundle shrinks by roughly 8 KB gzipped and SDK boot does less work on slow devices. No integration changes are required.
PayPal
  • PayPal JS SDK v6 Support
    The PayPal button now uses PayPal’s JS SDK v6, which renders the button directly in the page instead of inside an iframe, so it appears sooner and re-renders instantly. Sandbox integrations now load PayPal from www.sandbox.paypal.com instead of www.paypal.com; if your page sets a strict script-src, allow both hosts.

v1.11.1

September 14, 2026 Card Payments
  • Faster, Lighter Card Field Iframes
    The card form and Secure Fields iframes now talk to the SDK through the SDK’s own cross-frame bridge instead of the zoid library, so each card iframe ships about 100 KB less JavaScript and renders noticeably faster on slow devices and networks. No integration changes are required.

v1.11.0

September 12, 2026 Core SDK
  • Regional static hosts: chunks and card iframes follow the host the SDK was loaded from
    Until now the bundle served from sdk-web.<region>.y.uno (EU: sdk-web.prod.eu.y.uno, MENA: sdk-web.mena.staging.y.uno) still fetched every lazy chunk from the US host it was built for and both card iframes from sdk-web-card.prod.y.uno. The SDK now records the host main.js was actually loaded from and, when it is a Yuno static host other than the built one, serves lazy chunks from that same directory and loads the card form and secure-field iframes from the matching sdk-web-card.<region> host. The same build works on every regional bucket, so no build variants or infra changes are needed. Merchant apiUrl / assetUrl overrides keep precedence, and a bundle self-hosted on a non-Yuno domain behaves as before. No merchant integration changes are required.

v1.10.25

September 24, 2026 Core SDK
  • three_ds.completed now reports the 3DS outcome instead of the payment outcome
    When the 3DS authentication succeeds and the acquirer then declines the payment, three_ds.completed reports result: authenticated and the decline stays on payment.resolved. The result is read from the last transaction of the payment the SDK already receives (its provider and response code). When that transaction is not available, for example when the final status arrives through the websocket, the result still follows the payment outcome as before. Known limit: providers that authenticate and authorize in a single transaction and do not expose a 3DS response code, today Adyen (about 200 Adyen 3DS sessions per week), report their 3DS declines as authenticated until.

v1.10.24

September 23, 2026 PayPal
  • Venmo renders in sandbox for testers outside the US
    On sandbox credentials the SDK now loads the PayPal JS SDK with buyer-country=US whenever the merchant’s ENABLE_FUNDING includes venmo, as PayPal’s Venmo test guide requires, so QA outside the US sees the Venmo button. Production builds never send it.

v1.10.23

September 18, 2026 Payment Methods
  • Click to Pay shows the “or” separator in the shopper’s language
    The separator between “access my linked cards” and “enter the card manually” in the Click to Pay email and one-time-code screens read “Ó” in Portuguese and Spanish, and stayed in English in fourteen other languages. It now reads “OU” in Portuguese, “O” in Spanish, and is translated in Arabic, German, French, Italian, Japanese, Korean, Dutch, Polish, Russian, Swedish, Turkish, Vietnamese and Chinese.

v1.10.22

September 17, 2026 PayPal
  • PayPal button container grows with the rendered buttons
    The PayPal, PayPal enrollment and PayPal Braintree button containers now grow with the buttons PayPal decides to render (e.g. PayPal + Venmo + Pay Later) instead of overlapping the content below. With a single button nothing changes. Stable __wrapper and __loading class names were added for merchant styling.
  • PayPal enable-funding support (Venmo)
    The SDK now reads the merchant’s ENABLE_FUNDING provider-config param and passes it as enable-funding when loading the PayPal JS SDK (button and enrollment flows), so funding sources such as Venmo can render.

v1.10.20

September 15, 2026 Core SDK
  • Authorization Copy Under the Single Pay Button Sticks to the Selected Method
    With the Yuno pay button in FLOATING or STICKY position, the stored-credential authorization copy shown below the button could disappear or belong to another method after the shopper visited more than one payment method: a form left mounted in the payment method list was publishing its own save state under the newly selected method. Each form now publishes only the copy of the method it opened with, and only while that method is selected.

v1.10.19

September 15, 2026 Core SDK
  • Contextual authorization copy for stored payment methods
    Card and other non-direct-debit payment methods now render the stored-credential authorization text sent by the backend (localized and with the merchant’s business name). The payment + save wording (mandate_type RECURRENT) shows once the method will be stored: the buyer ticks “save” or the merchant forces card.vaultOnSuccess. The enrollment and subscription wordings (mandate_type ENROLLMENT / SUBSCRIPTION) are settled by the backend from the session and render as they arrive, as will any future scenario; such a wording keeps the payment method form on screen even when the buyer has nothing left to fill in. The text is Yuno-owned and follows the Yuno pay button: with yuno_pay_button_position ACCORDION it sits right below the inline button, with FLOATING or STICKY it moves below the single pay button (above the Powered by Yuno badge), and with a merchant-rendered button it stays at the bottom of the payment method form. Direct-debit mandates keep their scheme text inside the form. Wallets never show it.

v1.10.18

September 14, 2026 Card Payments
  • Honor the Keyboard Next Key Across the Card Form Secure Fields
    Pressing Next on the mobile keyboard now advances focus through the card secure fields and on to Cardholder Name after the last one, in both the full card form and the split secure fields form, for every account, including those with automatic field advancement turned off.

v1.10.17

September 10, 2026 Payment Methods
  • Fixed the expanded payment method list preselecting nothing for returning shoppers
    When the preferred flag landed on an express-rendered method (PayPal, Apple Pay, Google Pay) and the radio list held more than one row, no payment method was preselected and the shopper had to pick one manually. The single-regular-method rule now counts distinct method types instead of rows, so a saved card and the new-card row collapse into one Card method and the first card row is auto-selected. Express buttons demoted into the radio list by horizontal stacking no longer break the count, and a lone demoted express button is still preselected as before. Checkouts offering several distinct payment methods still require a manual selection, and a preferred express button that never finishes rendering is still never auto-selected.

v1.10.16

September 6, 2026 Lite Web SDK
  • Enrollment OTP screen shows the branding of the method being enrolled
    The OTP step of an enrollment always rendered the DaviPlata logo and title, whatever payment method was being enrolled — an ACH enrollment through Stripe showed a DaviPlata header. The header now uses the icon and name the enrollment itself carries, so every method shows its own branding, and it falls back to the generic OTP title when the enrollment has neither. DaviPlata enrollments keep the header they had.
Core SDK
  • The ACH account type and account holder type fields offer their options during enrollment
    Both fields read their dropdown options from the backend ui object, and the enrollment flow never put that object on the store. The two selects rendered empty, so a customer enrolling an ACH bank account could not pick an account type and could not finish the form. The enrollment response already carries the ui object, and it now reaches the store, which also lets the backend-driven labels, placeholders and error copies apply to the rest of the enrollment form.

v1.10.15

September 5, 2026 Fraud & Risk
  • Merchant-configurable ThreatMetrix session_id prefix for Cielo CyberSource
    The FINGERPRINT_PREFIX connection param is prepended to the ThreatMetrix script URL session_id only, while the device fingerprint id reported to Yuno stays the bare session id.
Checkout
  • Google Pay honours showPaymentStatus when the payment fails
    The error path in completeGooglePayPayment hardcoded the status screen, so merchants with showPaymentStatus: false still got the SDK’s full-page “Transaction failed” screen over their own UI. It now respects the flag, consistent with the payment-action path.

v1.10.14

September 4, 2026 Revolut Pay
  • Fixed Revolut Pay Late Authorization Expiry
    When a shopper closed the Revolut Pay widget while an authentication challenge was still in progress, the SDK expired the payment immediately, and an authorization that Revolut completed afterwards could not be applied, leaving funds on hold with no visible payment. The SDK now keeps the payment open on those cancellations so a late authorization is reflected correctly.

v1.10.13

September 3, 2026 Google Pay
  • Improved Google Pay Double-Tap Handling
    A rapid second tap on the Google Pay button is now ignored while the payment sheet is loading, and the SDK no longer reloads the merchant page in that case.
Lite Web SDK
  • PayPal Enrollment Element Render and Customization
    PayPal enrollment in mountEnrollmentLite now supports renderMode.type: 'element', shows a loading skeleton while the button loads, and accepts externalButtons.paypal for button customization.
Payment Actions
  • Merchant Redirects After 3DS No Longer Cancelled
    While a 3DS challenge is open, the SDK adds a browser history entry so the back button can cancel the payment. It removed that entry just after telling the merchant the payment had finished, which cancelled any redirect the merchant started from yunoPaymentResult or from a result-screen button and left the shopper on the loader. The entry is now removed just before the merchant is notified, so the redirect completes. Browser back still cancels the challenge as before.

v1.10.12

September 2, 2026 Core SDK
  • Direct Debit Authorization and Save for Future Payments
    Direct-debit payment methods (ACH, SEPA, Bacs, PAD, iDEAL) now render the mandate authorization text sent by the backend — switching between the one-off and recurrent copies as the buyer opts into saving, with the mandatory acceptance checkbox where the scheme requires it (SEPA / iDEAL) — and send the mandate acceptance evidence on the one-time token and enrollment requests. Adds the savePaymentMethodEnabled option to startCheckout: when the merchant enables it and the method supports saving, the checkout renders a “Save payment method for future payments” checkbox and the buyer’s choice travels as vault_on_success (sent only when ticked). Off by default; card keeps its own card.cardSaveEnable / card.vaultOnSuccess configuration.
  • Plugin attribution on every SDK event
    Yuno.initialize accepts an optional plugin block identifying the commerce platform the SDK is embedded in — vtex, shopify, magento, woocommerce, prestashop or other — along with the plugin’s own version and the merchant’s host-platform version. When it is present, every event the SDK emits carries plugin_platform, plugin_version and host_platform_version on the envelope, and application reports plugin instead of sdk. This lets the existing funnel, latency and A/B views be split by commerce platform without adding a single new event. A direct merchant integration omits the block and nothing changes: the three attributes are null and application keeps its current value.

v1.10.11

September 1, 2026 Checkout
  • Apple Pay capability detection hardened for older Safari
    applePayCapabilities() is now feature-detected before use (the API only exists in Safari on iOS 18 / macOS Sequoia and newer), and a failed capabilities call falls back to the legacy canMakePayments() check instead of hiding the Apple Pay button. A successful call reporting no card in the wallet still hides the button. This makes the capability-based detection safe to enable by default for all merchants.
Core SDK
  • onChange reports whether the payment form is complete
    Merchants that hide the SDK pay button with showPayButton: false and render their own can now tell when the form is ready to be submitted. onChange reports { form: { isValid } } every time it changes, covering every required field including the card fields the SDK renders in its secure iframes. It is available on startCheckout and on mountEnrollmentLite, and works for card, saved card and alternative payment method forms.
  • Only the selected payment method is submitted, and the loading state always closes
    When a customer filled in one payment method and then switched to another, the SDK could submit both and create more than one payment token. Only the payment method the customer currently has selected is submitted now. Separately, when creating the token failed on an alternative payment method, onLoading never reported that it had finished, leaving merchants with a loading state that never closed. The alternative payment method form also left its own loading flag stuck on after the first submit, so anything reading it stayed in a loading state for the rest of the session.

v1.10.10

August 31, 2026 Core SDK
  • SDK events renamed to the event taxonomy
    Every SDK event now uses its taxonomy name (object.verb): checkoutSdk_started becomes checkout.opened, payment_resolved becomes payment.resolved, the per-form events collapse into form.viewed / form.submitted / form.closed / form.copied with a form_type attribute, the status-page events into result.viewed / result.returned, and the whole enroll* family into the same events with flow: enrollment. Adds the events the taxonomy defines that had no counterpart before: payment_method.viewed (with the reasons a served method was not mounted), payment_method.saved / .deleted, payment.retried, installment.*, three_ds.*, wallet.* for Apple Pay and Google Pay, and field.*. Event payloads now carry the attributes under attributes, with the producer and sequence number that make client-side event loss measurable.
  • Configurable Express Buttons Stacking
    Express buttons follow the stacking chosen in the Checkout Builder: horizontal keeps the current row of up to three buttons, and vertical shows every express button full width, one per line, with the previous shorter and rounded design.

v1.10.9

August 27, 2026 Checkout
  • Slimmer Forms sized to Stripe parity
    Slimmer Forms fields now render at a 44px height (Apple HIG touch minimum) with 16px input text and 13px labels, and form sections are spaced 41px apart. The 16px input text also stops iOS Safari from auto-zooming the page when a field gets focus, including the card number, expiration and CVV fields, and the divider between expiration and CVV now renders as 1px like every other border.
  • Default Inter font loads as external woff2 subsets
    The default checkout font stylesheet now references external woff2 files per unicode subset instead of a single 584 KB base64 CSS, so a latin cold load downloads ~56 KB (-90%) and other scripts fetch their subset on demand. No visual change.
Fraud & Risk
  • Accertify Device Fingerprinting Support
    The SDK now loads Accertify’s device tag when an Accertify fraud-screening connection is configured, and forwards the resulting device ID with the payment. The tag URL is read from the connection, so it is configured per merchant and per environment rather than hardcoded. If the tag fails to load or times out, the payment proceeds and no Accertify device entry is sent.
Payment Actions
  • Button Links Block in Payment Actions
    Payment actions can now render a row of destinations for the shopper to pick from, each with its own name and icon. Flows such as UPI Autopay use it to offer the apps the payment can be completed in. The destinations come from the provider on each transaction, and the block only renders when the action includes it.
  • White-Label Embedded 3DS Challenge Completion
    When the SDK is initialized with a white-label apiUrl, the embedded 3DS challenge (render_iframe) is served from the merchant’s own origin. The SDK now accepts the challenge result from that origin, so the payment flow continues after the challenge instead of staying on the loader.
Samsung Pay
  • Portuguese Samsung Pay button via locale-based asset override
    When the checkout locale is Portuguese (pt/pt-BR), the Samsung Pay express button renders a Yuno-hosted Portuguese asset instead of the Samsung-hosted English one. The asset is preloaded first so a load failure falls back to Samsung’s default asset, and the override is scoped to the Samsung button only. Interim workaround until Samsung publishes an official localized asset on their CDN.
Lite Web SDK
  • Enrollment sends each bank transfer field on its own
    Enrollment only sent the account number, beneficiary name and routing number when all three were filled in, so methods that do not ask for a routing number (SEPA Direct Debit) lost the other two. Each field is now sent whenever it has a value.
Core SDK
  • Third-party script error watchers no longer replace window.onerror
    The antifraud and Secure Card on File script watchers assigned window.onerror directly, replacing any handler set by the merchant page and by other SDK modules, so their browser errors went unreported. The SDK now registers error event listeners instead, keeping the merchant handler and the SDK’s own error reporting intact.

v1.10.8

August 22, 2026 Core SDK
  • Yuno Pay Button
    The SDK can now render its own Pay button, controlled by the yuno_pay_button_position setting: FLOATING places it at the end of the payment method list, STICKY keeps it fixed at the bottom of the screen on mobile (falling back to FLOATING on desktop), and ACCORDION renders it inside each payment method. A new stickyPayButton.lastElementSelector option in startCheckout lets merchants tell the SDK which element to pad so the sticky bar never overlaps their page content.
  • Live Form Validation Feedback
    Payment forms now validate continuously as the customer types, errors appear only after leaving a field, and pay buttons look disabled until the form is complete while staying clickable to reveal pending errors.
Google Pay
  • Google Pay sheet now offers a shipping method selector
    The Google Pay payment sheet can display the merchant’s shipping methods so the buyer picks one directly on the sheet, with amounts updated on each selection.
  • Google Pay payment sheet now shows the order breakdown
    Google Pay displays the order line-item breakdown (subtotal, shipping, tax, discounts) on the payment sheet when the checkout session provides summary items.
  • Google Pay notifies shipping address changes in real time
    Merchants can register an onShippingAddressChanged callback to receive the shipping address selected on the Google Pay sheet and return updated amounts while the buyer checks out.
Payment Actions
  • Shipping Callbacks for Apple Pay
    The Apple Pay sheet can now open with your delivery options and price breakdown already in place, and tell you when the customer picks or changes a shipping address. When the checkout session carries shipping_methods or summary_items, the sheet renders them as-is — the first delivery option is preselected and its breakdown drives the total, and your labels are shown exactly as you wrote them. Set externalButtons.onShippingAddressChanged to be called with the address the wallet exposes (city, state, postal code and country) and answer with new totals, new delivery options, or an error message that rejects the address. Switching between delivery options is answered from the SDK’s own cache, so your handler is only called when the address itself changes, and the option the customer chose travels with the one time token alongside the shipping address. Checkout sessions without these fields and integrations without the handler behave exactly as before.
  • Worldpay 3DS Device Data Collection
    Card payments routed through Worldpay’s own 3DS now run the device data collection step and report the resulting device fingerprint back to the provider, so the authentication challenge behaves correctly instead of being silently degraded. The same fix applies to the headless flow, and other 3DS providers now also forward the device session they collect.

v1.10.7

August 19, 2026 Installments
  • Tell the card fields when a connection prices installments per card
    The card secure fields now receive installments_require_full_card from the payment method, so they wait for the complete card number before quoting when a routed connection prices each term against that exact card.

v1.10.6

August 19, 2026 Card Payments
  • Card number validation on unknown or failed BIN lookup
    Previously, an unknown or failed card BIN lookup silently skipped Luhn validation, letting structurally invalid card numbers through to tokenization. The card form now defaults to validating unless the backend explicitly says not to.
Click to Pay
  • Fixed Missing Card Type in Click to Pay One-Time Token
    Previously, non-dual enrolled cards left the OTT cardType empty, so the backend derived the type from the network token BIN against the card-iin table, which misclassifies credit cards as debit and gets payments rejected by the acquirer (kind DEBIT + installments, returnCode 54).

v1.10.5

August 14, 2026 Alternative Payment Methods
  • Removed the default heading from alternative payment method forms
    Alternative payment method forms no longer display the “Enter the following details to continue” heading, reducing visual noise. Context-specific headings, such as the NuPay enrollment title, are still shown.
Card Payments
  • Fixed Clipped Field Borders and Focus Animation in the Card Form
    Card form field borders no longer render cut off on some mobile devices, and the focus animation is no longer clipped.
  • Fixed Installment Selection Issues in the Card Form
    The selected installment is kept while typing in the card form, and onInstallmentSelected notifies the last selection again when returning to the card payment method.
Google Pay
  • Improved Google Pay Double Tap Handling
    Fixed an issue where quickly tapping the Google Pay button twice caused a page reload while the payment sheet was open, leaving the sheet unable to complete the payment.
  • Fixed Google Pay Button Stuck Hover State
    Fixed the Google Pay button staying in its gray hover state on touch devices after the payment sheet was opened and dismissed.
Core SDK
  • Improved Checkout Load Performance
    The checkout now displays a loading skeleton instead of a blank space while its resources download, and external payment buttons render faster thanks to smaller, parallelized downloads. Also fixes a race condition that could leave the document type dropdown empty.

v1.10.4

August 10, 2026 Core SDK
  • Faster Lite and External Buttons Loading
    The Lite, Seamless Lite and standalone external button flows now load faster: SDK resources download in parallel with the initial API calls and mounting only waits for the settings request, reducing the time to show the payment form and express buttons.
Payment Actions
  • Fixed showPaymentStatus on Payment Failures
    When showPaymentStatus is set to false, the SDK no longer renders the full-screen “Transaction failed” message on early payment failures (payment not found or not yet processed); the error is delivered through the onError callback instead.

v1.10.3

August 5, 2026 Core SDK
  • Dead analytics events cleanup
    Removes 17 analytics emit methods that had zero callers (verified against develop plus a cross-repo audit of the card iframe and mobile SDKs), including the miswired securityCodeForm.* methods that emitted enrollStatus_pageViewed. No emitted event changes: every event that fires today keeps firing; enrollPaymentMethodForm_submitted keeps its live inline emitter and payment_created stays reserved for the audit pipeline.
  • Phone Country Code Autofill From Customer
    The checkout form phone country-code dropdown now preselects the country matching the customer’s phone prefix sent at session creation, disambiguated by the customer’s country, instead of always defaulting to the session country.
Card Payments
  • Null onInstallmentSelected event when installments become unavailable
    The onInstallmentSelected callback now fires with a null payload when installment options that were previously notified become unavailable — most commonly when the shopper switches from a card with installments to a card without them. The null event only fires if a real installment selection was notified before; forms where installments were never available stay silent. Callback invocations are also wrapped so a merchant handler that throws on null cannot break the card form. Applies to new-card, secure-fields, enrolled-card, and Click to Pay flows.
  • Environment-Aware 3DS Host Resolution
    Resolve the sdk-3ds host (challenge.html, session-id.html and the 3DS event origin) from the SDK’s runtime environment — encoded in the public API key — instead of freezing it into the bundle at build time. A bundle built for one environment (e.g. prod) but run against another (e.g. sandbox) was sending an environment-mismatched 3DS session token to the wrong sdk-3ds.<env>.y.uno host, where the session-binding verifier rejected it with 403 Forbidden and the challenge never loaded. The API and WebSocket hosts already resolve per environment this way; the 3DS host now does too. Backward-compatible: a concrete host with no _ENVIRONMENT_ placeholder passes through unchanged.

v1.10.2

August 3, 2026
  • PayPal Enrollment
    Resolve the payment status reported to the merchant from the server instead of assuming SUCCEEDED when PayPal approves, and avoid double error handling when the payment lookup fails after approval — the error screen or merchant error callback now fires exactly once, honoring showPaymentStatus.

v1.10.1

July 30, 2026 Core SDK
  • Faster Full Checkout Loading
    The Full and Seamless Full checkouts now load faster: SDK resources and express button scripts download in parallel with the initial API calls, reducing the time to show the payment method list and express buttons.
Samsung Pay
  • Samsung Pay Sheet Close Reports Cancellation
    Closing the Samsung Pay payment sheet now reports a user cancellation instead of showing a “Transaction failed” screen, and no longer leaves the merchant loading state stuck.
Card Payments
  • Fixed Enrolled Card Installment Notifications
    The onInstallmentSelected callback now fires only from the enrolled card the customer selected: it notifies the default installment on first selection, changes made while the card is active, and the last selection when returning to the card. Cards not selected no longer emit duplicate notifications when switching payment methods.

v1.10.0

July 29, 2026 Samsung Pay
  • Samsung Pay support in the Web SDK
    Adds Samsung Pay as an external wallet button. The SDK loads Samsung’s Web Checkout SDK, reads the sdk_provider configuration returned by the backend, opens the Samsung payment sheet and forwards the tokenized payment credential to Yuno for authorization.
Card Payments
  • Streamlined Saved Card Display
    Removed the card image preview from the saved (tokenized) card flow and replaced it with a compact preview showing the card brand, last four digits, cardholder name and expiry date.
  • Improved Enrolled Card Form Rendering
    The enrolled card form no longer reserves empty space when it has no fields to display, and now renders the card holder name field when the payment method configuration requires it.
  • onInstallmentSelected Callback for Enrolled Cards
    Added support for the onInstallmentSelected callback on enrolled cards.
Google Pay
  • Fixed Google Pay Button Colors
    The Google Pay button now always honors an explicitly configured buttonColor (white or black), even when the page runs in dark mode. The default setting keeps adapting to the page color scheme automatically.
Core SDK
  • Improved Express Buttons Layout
    The full checkout now renders up to three express payment buttons side by side with unified default styles. Express buttons that do not fit in the row are shown inside the payment method list and render their native button when selected.
  • EU Region Initialization Support
    The Web SDK can now be initialized against the EU region, routing all SDK network calls to the EU checkout API. Existing integrations without a region set continue to use the current endpoint unchanged.
  • Checkout Lifecycle Analytics Events
    Adds checkoutSdk_started and payment_resolved, and enriches the existing checkoutSdk_completed with UX attributes (clicks, taps, keystrokes, scroll), so a checkout can be measured end to end: when it starts, how the payment resolved, and — from the presence of checkoutSdk_completed — whether it was completed or abandoned. Both new events flush on emission so they are not lost to the batch debounce.
PayPal
  • PayPal Billing Agreement Enrollment Support
    The SDK now supports enrolling customers with PayPal billing agreements (PAYPAL_BA_ENROLLMENT) and sends the PayPal partner attribution ID when loading the PayPal SDK.
Checkout
  • Express-Only Payment Methods Callback
    Added an optional onlyExpressPaymentMethods callback to the full checkout configuration that reports true when every available payment method renders as an express button (Apple Pay, Google Pay, PayPal, PayPal enrollment, PayPal Braintree, Revolut Pay) and false otherwise. When only express methods are available, the “Or pay with” divider is no longer rendered below the express buttons.
  • Click to Pay footers use the shared modal footer
    The Click to Pay card form, enrolled card, and installment selection screens now render the shared modal footer instead of a Click to Pay-specific copy, matching the full-width button and centered “Powered by Yuno” tag redesign. The legacy CSS hooks (sdk-payments-c2p-button-bottom__modal-bottom, __button-continue, __button-back) are preserved and the shared classes are added alongside them; the internal wrapper classes sdk-payments-c2p-button-bottom__buttons-content and __button-wrapper no longer exist in the DOM. The Click to Pay footer badge now links the country-specific privacy policy URL instead of always the global fallback.
  • Full-width action button in modal footers
    The action button in the shared modal footer now spans the full width on every viewport, with the “Powered by Yuno” privacy tag centered above it. Lite keeps the tag below the button. Embedded forms rendered with renderMode: element are unchanged.

v1.9.46

September 24, 2026 Core SDK
  • three_ds.completed now reports the 3DS outcome instead of the payment outcome
    When the 3DS authentication succeeds and the acquirer then declines the payment, three_ds.completed reports result: authenticated and the decline stays on payment.resolved. The result is read from the last transaction of the payment the SDK already receives (its provider and response code). When that transaction is not available, for example when the final status arrives through the websocket, the result still follows the payment outcome as before. Known limit: providers that authenticate and authorize in a single transaction and do not expose a 3DS response code, today Adyen (about 200 Adyen 3DS sessions per week), report their 3DS declines as authenticated until.

v1.9.45

September 19, 2026 Lite Web SDK
  • Fixed SEPA Enrollment Bank Details
    Enrollment only sent the account number, beneficiary name and routing number when all three were filled in, so methods that do not ask for a routing number (SEPA Direct Debit) lost the other two. Each field is now sent whenever it has a value.

v1.9.44

September 18, 2026 Payment Methods
  • Click to Pay shows the “or” separator in the shopper’s language
    The separator between “access my linked cards” and “enter the card manually” in the Click to Pay email and one-time-code screens read “Ó” in Portuguese and Spanish, and stayed in English in fourteen other languages. It now reads “OU” in Portuguese, “O” in Spanish, and is translated in Arabic, German, French, Italian, Japanese, Korean, Dutch, Polish, Russian, Swedish, Turkish, Vietnamese and Chinese.

v1.9.42

September 14, 2026 Card Payments
  • Honor the Keyboard Next Key Across the Card Form Fields
    Pressing Next on the mobile keyboard now advances focus through the full card form fields and on to Cardholder Name after the last one, for every account, including those with automatic field advancement turned off.

v1.9.36

August 21, 2026 Payment Actions
  • Worldpay 3DS Device Data Collection
    Card payments routed through Worldpay’s own 3DS now run the device data collection step and report the resulting device fingerprint back to the provider, so the authentication challenge behaves correctly instead of being silently degraded. The same fix applies to the headless flow, and other 3DS providers now also forward the device session they collect.

v1.9.34

August 17, 2026 Card Payments
  • Card number validation on unknown or failed BIN lookup
    The card form now validates the card number by default when the BIN lookup fails or returns an unknown IIN, instead of silently skipping validation.

v1.9.33

August 14, 2026 Card Payments
  • Hebrew and Persian RTL in the Card Form
    Card form secure fields now render right-to-left for Hebrew and Persian, matching the checkout shell direction.

v1.9.32

August 13, 2026 Card Payments
  • Fixed Clipped Field Borders and Focus Animation in the Card Form
    Card form field borders no longer render cut off on some mobile devices, and the focus animation is no longer clipped.

v1.9.30

August 13, 2026 Google Pay
  • Fixed Google Pay Button Stuck Hover State
    Fixed the Google Pay button staying in its gray hover state on touch devices after the payment sheet was opened and dismissed.

v1.9.29

August 12, 2026 Google Pay
  • Improved Google Pay Double Tap Handling
    Fixed an issue where quickly tapping the Google Pay button twice caused a page reload while the payment sheet was open, leaving the sheet unable to complete the payment.

v1.9.28

August 10, 2026 Card Payments
  • Fixed Installment Selection Issues in the Card Form
    The selected installment is kept while typing in the card form, and onInstallmentSelected notifies the last selection again when returning to the card payment method.

v1.9.27

August 9, 2026
  • Environment-Aware 3DS Host Resolution
    Resolve the sdk-3ds host (challenge.html, session-id.html and the 3DS event origin) from the SDK’s runtime environment — encoded in the public API key — instead of freezing it into the bundle at build time, and ship the deploy-time half so it actually takes effect. The three sdk-3ds URLs now use the _ENVIRONMENT_ templated form in the shared environment file, so resolveEnvHost resolves them at runtime. Until now every published bundle carried a concrete host baked at build time: a sandbox merchant running the prod bundle kept landing on sdk-3ds.prod.y.uno with a sandbox-signed session token and got a bare 403 Forbidden instead of the 3DS challenge, leaving the payment stuck in PENDING / WAITING_ADDITIONAL_STEP. When the public API key carries no recognizable environment prefix, the host falls back to the environment the bundle was built for so the placeholder never reaches a request.

v1.9.25

August 6, 2026 Payment Actions
  • Fixed showPaymentStatus on Payment Failures
    When showPaymentStatus is set to false, the SDK no longer renders the full-screen “Transaction failed” message on early payment failures (payment not found or not yet processed); the error is delivered through the onError callback instead.

v1.9.24

August 3, 2026
  • PayPal Enrollment
    Avoid double error handling when the payment lookup fails after approval — the error screen or merchant error callback now fires exactly once, honoring showPaymentStatus.

v1.9.23

July 31, 2026
  • PayPal Enrollment Payment Status
    Resolve the payment status reported to the merchant from the server instead of assuming SUCCEEDED when PayPal approves.

v1.9.19

July 29, 2026 Card Payments
  • onInstallmentSelected Callback for Enrolled Cards
    Added support for the onInstallmentSelected callback on enrolled cards.

v1.9.18

July 28, 2026 Checkout
  • Express-Only Payment Methods Callback
    Added an optional onlyExpressPaymentMethods callback to the full checkout configuration that reports true when every available payment method renders as an express button (Apple Pay, Google Pay, PayPal, PayPal enrollment, PayPal Braintree, Revolut Pay) and false otherwise. When only express methods are available, the “Or pay with” divider is no longer rendered below the express buttons.

v1.9.17

July 20, 2026 Core SDK
  • Payment method radio moved to the leading edge (RTL-aware)
    BREAKING (visual default): the payment-method selection radio now renders at the leading (left) edge of each row, mirrored to the right automatically in RTL locales (Arabic, Hebrew, Persian, Urdu). Merchants with custom CSS targeting the old right-aligned radio may need to adjust their selectors. The trailing position remains available via the RadioButton showRadioLeft= prop in sdk-web-core.
  • Six New Checkout Languages
    Adds Greek, Hebrew, Romanian, Slovak, Serbian (Latin), and Ukrainian localization to the Web SDK checkout.
Fraud & Risk
  • Braintree Device Data Collection

v1.9.16

July 14, 2026 Card Payments
  • Fixed Installments for Dual Cards in Credit-Only Mode
    Installment options now load correctly for Brazilian dual cards when credit_card_only_processing is enabled, ensuring payments are tokenized as credit with the proper installment selection.
APM
  • Slim Form Support for Bank Transfer Fields
    Added slim form support to the bank transfer fields.

v1.9.15

July 10, 2026 Fraud & Risk
  • CyberSource Fingerprint Session ID Override
    CyberSource/Cielo CyberSource fingerprint now honors the per-provider session_id override (deviceFingerprints), enabling merchant-specific MID prefixes on the ThreatMetrix session id.
Card Payments
  • Consistent Card Field Labels
    The card number, expiration date, and CVV fields now resolve their labels from the same UI copy source across all card form variants, so the full checkout and the Lite SDK render identical texts for the same checkout session configuration.

v1.9.14

July 9, 2026 Core SDK
  • Backend-driven checkout field labels and required fields
    The checkout form now renders from the configuration returned with each payment method. Field labels, placeholders, validation messages, selection options, and which fields are shown are driven by the backend, so the form always reflects exactly what each payment method and provider requires, displayed in the shopper’s language. When this configuration isn’t provided, the SDK falls back to its built-in localized text, so existing integrations keep working with no code changes required.
Card
  • Consistent installment dropdown format
    The installment dropdown now renders every option with the same template (Nx of {value} - Total {total}) regardless of whether the option includes financial costs, fixing mixed layouts when a plan combines options with and without financial_costs.
APM
  • ACH Direct Debit Account Fields
    Added two new fields to the bank transfer form: Account Type (Checkings/Savings) and Account Holder Type (Individual/Company).
PayPal
  • Improved PayPal Braintree Button Loading
    The loading placeholder now matches the button style configured via externalButtons.paypalBraintree.style (width, height and border radius), removing the visual mismatch while the button loads

v1.9.13

July 7, 2026 Address Autofill
  • Address Autofill via Google Places + Brazil ViaCEP
    A single feature flag address_autofill_enabled enables a new address autofill experience. For non-Brazilian countries the user gets a Google Places combobox with up to 5 live suggestions, cadence guard, silent fallback to manual entry and analytics events. For Brazil the field collapses to the CEP only, and ViaCEP auto-fires when the postal code matches the regex /^\d{5}-?\d{3}$/ (with blur as fallback); the remaining fields unfold after the attempt succeeds or fails. The form country drives the decision and resets cleanly across switches. 6 new i18n keys translated in 26 locales.

v1.9.12

July 6, 2026 PayPal
  • Improved PayPal Braintree Checkout Flow
    Improves the PAYPAL_BRAINTREE external button payment method, now built on braintree-web and PayPal Web SDK v6

v1.9.11

July 2, 2026 Payment Actions
  • Payment retry in Lite checkout
    Payment retry now works in the Lite checkout flow (mountCheckoutLite). A declined or errored card payment shows inline field errors and retries without restarting checkout, gated by settings.card.enable_payment_retry.

v1.9.10

June 30, 2026 Checkout
  • Localized currency formatting by merchant language
    Amounts now follow the merchant-configured YunoLanguage + per-checkout countryCode (via Intl.NumberFormat) instead of being derived from the currency, fixing decimal/thousand separators, symbol position and spacing for non-English checkouts. The currency still drives symbol vs ISO code and decimals.
Alternative Payment Methods
  • Render the BLIK OTP Input in Every Checkout Display Mode
    BLIK now prompts for its one-time code in all checkout display modes — unfolded, modal (Lite SDK) and render — instead of only the unfolded flow. The entered code is sent in the One Time Token request so the payment can be completed from any integration mode.
Core SDK
  • Auto-Select Single Payment Method
    When there is no enrolled payment method and only a single non-button payment method is available, it is now preselected automatically.
Payment Actions
  • Status Action Notification
    The SDK now notifies the onActionExecuted callback with a CHECK_STATUS action when the payment status screen is shown, so merchants can reliably dismiss their own loaders.

v1.9.9

June 24, 2026 Core SDK
  • Pass a per-session JWT to challenge.html and add a postMessage handshake with nonce/origin verification for the 3DS frame-restriction flow.

v1.9.8

June 23, 2026
  • FIXED: Enable downloading the QR image for client-generated QR codes (GENERATE_QR, e.g. QRIS/Xendit). The “Download QR image” button now renders for these payment methods and saves the on-screen code as a PNG generated on the client with qrcode. Previously the button only appeared for ready-to-use image QRs (URL/BASE64), so QRIS never showed it even though the backend sent the download_qr label.
Card Payments
  • Per-Scheme Card Number Length Validation
    Card number length is now validated per card scheme using backend-driven rules combined with the Luhn check, reducing false rejections of valid cards. Gated behind a feature flag.
  • FIXED: Route sdk-web-card iframe assets (secure-field pages, card form, mediator) through the asset host in whitelabel mode. They were resolved against apiUrl, so when a merchant set a distinct assetUrl carrying a proxy sub-path (e.g. /hosted-payment-methods/orchestrator) the sub-path was dropped and secure fields loaded from the wrong path in enrollment and enrolled-card flows.

v1.9.7

June 17, 2026 Payment Actions
  • Report The Executed Payment Action
    continuePayment() now tells you which payment action is running: it resolves with the executed action and accepts a new optional onActionExecuted callback that fires for each action. Use it to keep your loader on screen until a 3DS redirect navigates, avoiding the card-form flash before the challenge.
Card Payments
  • Card Form Title No Longer Flashes While Loading
    In the slim card form embedded with elementSelector, the “Card information” title now appears together with the card fields once they finish loading, instead of showing above an empty form.
Core SDK
  • Consistent Payment Method Preselection
    Payment method preselection is now consistent between the checkout state and the UI across the expanded and collapsed lists: the selected method is always reflected in the list, and one method is preselected when the backend doesn’t specify a preference.

v1.9.5

June 15, 2026 Secure Fields
  • Fixed Card Field Console Error
    The card form no longer throws an uncaught error when entering a card whose network does not require a card PIN.

v1.9.4

June 15, 2026 Core SDK
  • Prepend the configured whitelabel base path to host-overridden asset, iframe and WebSocket URLs so the SDK stays under a proxy mounted at a sub-path (e.g. .../orchestrator) instead of dropping to the bare origin. The 3DS postMessage origin opts out.
Revolut Pay
  • Revolut Pay Mobile Return Support
    Revolut Pay now returns shoppers to the checkout reliably on mobile after the redirect or app-to-app handoff.

v1.9.2

June 11, 2026 Core SDK
  • Stronger Phone and Document Validation
    Phone and document number fields now block invalid characters as you type, and document numbers run checksum validation — enabled gradually via the real-time validation rollout.
Payment Actions
  • Checkout Completed Event For All Methods
    The checkoutSdk_completed event is now emitted for every payment method that completes through the shared payment-action router (card, Google Pay, APMs), matching the existing Apple Pay and PayPal behavior. It fires once per checkout.
Revolut Pay
  • Revolut Pay Support
    Adds Revolut Pay as an external payment button. Supports both seamless and merchant-driven checkout flows, with a configurable button (variant, size, radius, action, and locale).
Card Payments
  • Fixed Slim Variant Card Form Styles
    Fixed an issue in SDK 1.9 where the slim input variant rendered incorrectly in the card form and address fields: grouped border radius, focus and error border colors, and hidden inline error messages were not applied.

v1.9.1

June 3, 2026 Checkout
  • When only one regular payment method is available, it is now automatically pre-selected and its radio button appears checked on render — regardless of whether the backend marks it as preferred.
  • In whitelabel mode (when apiUrl or assetUrl is set at initialize()), the data privacy / terms-and-conditions text is hidden, matching the “Secure by Yuno” badge behavior.
Core SDK
  • QR codes for QR-based payment methods (like Nequi) now render with extra whitespace around the pattern, improving scan reliability on phones that auto-crop the camera view.
  • Yuno-hosted static assets (such as brand logos) now can be served via the proxy. Only Yuno hosts are rewritten, leaving external asset URLs untouched.

v1.9.0

May 26, 2026 White Label
  • Whitelabel Class Names and IDs Prefix Change
    Yuno class names and IDs prefix changed to sdk-payments. For example, yuno-checkout becomes sdk-payments-checkout.
  • Whitelabel-Neutral Public API
    Public-facing CSS class names, DOM ids, and event/callback names have been renamed to neutral, whitelabel-friendly identifiers. Existing window.Yuno, the yuno-sdk-ready event, and yuno* callback aliases continue to work, so existing merchant integrations need no changes. window.Yuno deprecated in favor of window.SdkPayments.
  • Custom API and Asset URLs
    Added options.apiUrl and options.assetUrl initialization overrides so the SDK can point at partner-hosted backends, 3DS endpoints, secure-field iframes, and card-form assets instead of the default Yuno URLs. The override is also forwarded to the monitoring layer, mediator, and card-form iframes.
  • Hide Secure Payment Badge on Custom Hosting
    When apiUrl or assetUrl overrides are set, the Secure Payment with Yuno badge is automatically hidden in both the standard checkout and the Click to Pay flow.
Core SDK
  • More Resilient Asset Resolution
    Guard the webpack public path when running under Vite, skip duplicate /v<x.y> suffixes when the asset URL already includes one, and use the configured apiUrl directly as the API client base URL to avoid region-prefix corruption.

v1.8.17

September 24, 2026 Core SDK
  • three_ds.completed now reports the 3DS outcome instead of the payment outcome
    When the 3DS authentication succeeds and the acquirer then declines the payment, three_ds.completed reports result: authenticated and the decline stays on payment.resolved. The result is read from the last transaction of the payment the SDK already receives (its provider and response code). When that transaction is not available, for example when the final status arrives through the websocket, the result still follows the payment outcome as before. Known limit: providers that authenticate and authorize in a single transaction and do not expose a 3DS response code, today Adyen (about 200 Adyen 3DS sessions per week), report their 3DS declines as authenticated until.

v1.8.16

September 18, 2026 Payment Methods
  • Click to Pay shows the “or” separator in the shopper’s language
    The separator between “access my linked cards” and “enter the card manually” in the Click to Pay email and one-time-code screens read “Ó” in Portuguese and Spanish, and stayed in English in fourteen other languages. It now reads “OU” in Portuguese, “O” in Spanish, and is translated in Arabic, German, French, Italian, Japanese, Korean, Dutch, Polish, Russian, Swedish, Turkish, Vietnamese and Chinese.

v1.8.7

July 9, 2026 Card
  • Consistent installment dropdown format
    The installment dropdown now renders every option with the same template (Nx of {value} - Total {total}) regardless of whether the option includes financial costs, fixing mixed layouts when a plan combines options with and without financial_costs.

v1.8.1

May 22, 2026 Core SDK
  • Mongolian Language Support
    Adds Mongolian (mn) as a supported locale for the web SDK checkout experience.
  • Auto-Select Single Payment Method
    When the checkout renders with exactly one regular (non-express) payment method available, that method is now auto-selected so the customer goes straight to the form. Express buttons (Apple Pay, Google Pay, PayPal) are no longer treated as a backend-preferred method that short-circuits this flow.
  • Detailed Errors from generateOTT()
    When apiClientPayment().generateToken (generateOTT) fails, the rejected error now contains the backend response body (with error codes and detail) instead of just the generic axios error. Merchants catching this call receive actionable error information.
Click to Pay
  • Deferred Installments in Click to Pay Golden Flow
    Installment plans in the Click to Pay Golden Flow are now shown on a dedicated screen after the customer picks between Click to Pay and the standard card rail, instead of being fetched automatically while the PAN is typed. The card form stays mounted underneath so secure-field state is preserved between screens.

v1.8.0

May 14, 2026 Apple Pay
  • Apple Pay Address Collection
    Apple Pay payment sheet can now collect billing and shipping addresses when configured via required_fields. Default behavior is unchanged when not configured.
  • Apple Pay BIN Available Pre-Payment
    DPAN BIN is now available in the OTT before payment, enabling BIN-based promotions and discounts. Existing card BIN flow is unaffected.
  • Improved Apple Pay Availability Detection
    Apple Pay button now appears more accurately on supported devices, reducing cases where the button shows for users who cannot complete an Apple Pay payment.
Google Pay
  • Google Pay Address Collection
    Google Pay payment sheet can now collect billing address, shipping address, and cardholder name when configured via required_fields. Address detail level adjusts automatically based on what is requested.
  • Google Pay Contact Field Collection
    Google Pay payment sheet can now collect customer email and phone number when configured via contactFields. Works in both standard and seamless external-button integrations.
Card Payments
  • Separate Billing and Shipping Sections
    Card form now renders billing and shipping as distinct sections with their own headers and an optional Address line 2 field. When both addresses are required, a Billing address is the same as shipping checkbox appears, enabled by default.
  • Compact Card Form Layout
    New slimmer card form layout with tighter spacing, grouped card details, and inline field-level error messages. Available across all SDK form variants. Behind a feature flag for A/B testing.
  • Card Form Auto-Advance
    Card form auto-advances focus once fields reach their expected length (PAN by detected scheme, expiry, CVV), reducing the number of taps to complete the form. Manual selection always takes precedence. Behind a feature flag, default off, for A/B testing.
  • Real-Time Card Field Validation
    Card form fields now validate on blur once the user has interacted with them, instead of only on Pay click. Errors clear immediately when the user corrects an invalid field.
Core SDK
  • Dynamic Enrollment Actions
    Enrollment flow now supports server-driven dynamic UI components: image, OTP, PIN, and info screens, rendered based on the fields returned by the server.
  • Smarter Currency Display
    Currency now shows a symbol only for the 21 currencies with globally unique symbols (€, £, etc.). All others display the 3-letter ISO code (for example COP 9.200.000, MXN 1.500,00). USD is the only currency that owns the $ symbol.
  • Hide Yuno Secure Payment Badge
    The Secure Payment with Yuno badge can now be hidden via Checkout Builder. When disabled, the badge is fully removed from the DOM in both the standard checkout and the Click to Pay flow.
Fraud & Risk
  • EBANX Device Session Reliability
    Improved reliability of device ID propagation in payment requests, fixing Payment Link flows where it was occasionally dropped before reaching EBANX.

v1.7.4

May 26, 2026 Core SDK
  • Reliable Document Number Validation
    When the backend specifies a validationFunction for a document type that the SDK doesn’t recognize, the field now falls back to regex validation instead of marking every value invalid. Prevents broken document inputs when a new validation function rolls out backend-first.

v1.7.3

May 11, 2026 Fraud & Risk
  • Improved EBANX Device Session Handling
    Improved EBANX device session recovery in supported fraud flows.

v1.7.2

May 11, 2026 Core SDK
  • POST Redirect Support
    Added support for payment providers that require POST redirects.
  • Expanded Required Field Support
    Added support for additional required payment data such as shipping_address in supported flows.
Secure Fields
  • Improved Session Handling
    Improved Secure Fields behavior in session-based payment flows.
Card Payments
  • Improved Card Retry Flows
    Enhanced retry behavior for card payments in supported checkout flows.

v1.7.1

May 11, 2026 Core SDK
  • More Reliable Payment Status Updates
    Improved payment status handling when real-time connection tracking is interrupted.
Payment Actions
  • Improved QR, Barcode, and Image Rendering
    Improved rendering for payment steps that rely on images, QR codes, or barcodes.
  • Improved OTP and PIN Flows
    Refined OTP and PIN-based payment steps for a smoother authentication experience.
Google Pay
  • Improved Button Rendering
    Improved Google Pay button rendering for a more consistent checkout experience.

v1.7.0

May 11, 2026 Click to Pay
  • Card Type Filtering Support
    Added support for card type restrictions in Click to Pay flows.
  • Transaction Amount Support for Passkey Flows
    Click to Pay initialization now includes transaction amount metadata for supported passkey flows.

v1.6.22

May 27, 2026 Fraud & Risk
  • Cybersource Fraud Session ID from Provider
    The Cybersource fraud device-fingerprinting session now uses the provider-supplied session_id when present, falling back to checkoutSession if the provider doesn’t supply one. Aligns the fingerprint session ID with what the fraud provider expects, improving fingerprint match rates.

v1.6.21

May 26, 2026 Core SDK
  • Reliable Document Number Validation
    When the backend specifies a validationFunction for a document type that the SDK doesn’t recognize, the field now falls back to regex validation instead of marking every value invalid. Prevents broken document inputs when a new validation function rolls out backend-first.

v1.6.20

May 13, 2026 Card Payments
  • Card Form Top Error Banner
    On payment retry, a banner appears at the top of the card form describing why the previous attempt failed. The banner scrolls into view and is highlighted if the customer tries to submit again without correcting the issue. Invalid-card-data errors and unknown response codes are now surfaced through this banner instead of per-field errors.

v1.6.19

May 8, 2026 Click to Pay
  • Card form button alignment on desktop
    Restored correct LTR alignment for the action button and the “Secure Payment by Yuno” badge in the Click to Pay card form (regression on v1.6.x; v1.5 and v1.7 were unaffected). RTL layout is preserved.

v1.6.18

May 7, 2026 Card Payments
  • Card Number Length Validation
    Card tokenization now waits for the BIN/IIN lookup to complete before submitting, so card numbers are validated against the correct scheme-specific minimum length. Previously, a short Luhn-valid PAN submitted before the BIN lookup settled could be sent to the provider and rejected; users now see an inline length error instead.

v1.6.17

May 6, 2026 Apple Pay
  • More Accurate Cancellation Reasons
    Apple Pay cancellations are now reported with a precise reason, distinguishing user dismissal (CANCELLED_BY_USER) from merchant-validation or provider failures (CANCELLED_BY_PROVIDER). Improves the accuracy of drop-off analytics and provider health signals; no integration changes required.

v1.6.16

April 16, 2026 Core SDK
  • Cancel 3DS Challenge on Browser Back
    Pressing the browser back button during a 3DS challenge now cancels the challenge cleanly. Merchants receive the cancellation via yunoPaymentResult with status PENDING / CANCELLED_BY_USER; no yunoError is emitted and the modal unmounts without leaving stale state.
Click to Pay
  • Action Button Order on Mobile
    On mobile and tablet viewports, the Click to Pay action buttons in the card form have been reordered so the primary action sits below the secondary, improving the UX hierarchy. Desktop layout is unchanged.

v1.6.8

April 15, 2026 Core SDK
  • unMountSdk() Helper
    Introduced a new top-level unMountSdk() method for explicit SDK cleanup. Call it when removing the SDK from the page to avoid memory leaks.
  • Rollback Cancel Flow
    Unified cancel flow events. The SDK now explicitly reports CANCELED_BY_USER in the yunoPaymentResult callback for all cancellation scenarios.
  • Legacy Event Rollback
    Legacy cancel-related events have been consolidated into the standard result flow. No new API changes required.
  • Forter Token Listener
    Added a listener for the ftr:tokenReady event to ensure reliable capture of the Forter session token. Previously the token could be missed on slow page loads.
Apple Pay
  • Metadata Support
    The cancel flow now includes a metadata parameter with a paymentCreated boolean, letting merchants determine whether a payment object was created before cancellation.
  • Contact Info Passthrough
    The SDK now automatically collects and forwards the customer’s email, phone, and name from shippingContact. No configuration required.
PayPal
  • No OTT Flow
    Added support for a REDIRECT workflow that skips OTT creation, enabling PayPal payments without a prior server-side session.
  • PayPal Button Modal
    New PaypalButtonModal component that renders the PayPal button inside a modal overlay, useful for merchants using a custom checkout UI.

v1.6.7

March 31, 2026 Card Payments
  • Card Password Field for Korean Cards
    New secure field for the first 2 digits of the cardholder PIN required by Korean issuers. Available across standard card, step-by-step, and Click to Pay (new + enrolled) flows. Enable by passing cardPinElementSelector in startCheckout config; the field renders when enabled for the merchant.
Click to Pay
  • Passkey Activation with Multiple Card Providers
    When multiple card providers are configured, the SDK now searches all of them for valid 3DS parameters instead of only the first. Passkey now activates correctly when the 3DS-capable provider is not listed first.
Core SDK
  • Hindi, Bengali, Malayalam, and Urdu Translations
    Available via language: 'hi' | 'bn' | 'ml' | 'ur'.
  • Merchant Installments via onGetInstallments
    Merchants can supply their own installment options via the onGetInstallments(cardBin) callback; the SDK falls back to Yuno installments when the callback returns empty. A new onInstallmentSelected callback fires on both auto-selection and user picks across all card flows. Merchant-supplied installments are omitted from one-time-token creation since the merchant handles them server-side.
  • subStatus in yunoPaymentResult
    The callback now receives subStatus as a second argument: yunoPaymentResult(status, subStatus?), giving finer-grained outcome information (notably on cancel flows).
  • Bundle Size Reduction (-16%)
    SWC env.targets configured to eliminate ES5 polyfills on modern browsers.
PayPal
  • PayPal Locale
    SDK language is now passed as locale to the PayPal loadScript call so the PayPal UI matches the configured checkout language.

v1.6.6

March 26, 2026 Apple Pay
  • externalButtons Customization
    New configuration on externalButtons for per-wallet button customization (Apple Pay, Google Pay, PayPal).
Core SDK
  • WebSocket Race Condition in Redirect Flows
    Resolved a race that could lose status updates.
  • WebSocket Error Handling
    Added error handling for WebSocket initialization to prevent unhandled failures in status polling.

v1.6.5

March 20, 2026 Apple Pay
  • Unified Apple Pay Button
    Legacy Apple Pay implementation was removed; the SDK now uses a single Apple Pay button consistently across standard checkout and mountExternalButtons integrations, driven by the SDK payment flow.
  • Faster Apple Pay Button Render
    Apple Pay SDK loading, amount lookup, and config fetch now run in parallel, with a styled placeholder shown until the real button is ready.
  • Earlier Fraud Signal Collection
    Fraud signals are collected during Apple Pay button initialization for broader coverage on wallet flows.
Google Pay
  • Google Pay Button Placeholder
    A styled placeholder is shown while the Google Pay SDK loads, replacing the previous skeleton.
Enrollment
  • APM Enrollment Button Text
    The enrollment confirmation button for APMs now reads “Continue” across Full, Lite, Seamless, and Render Mode flows.
Card Payments
  • Inline Payment Method Selection Error (Desktop)
    Clicking “Pay” without selecting a payment method now shows an inline error message below the payment method list on desktop. Mobile continues to use the existing toast.
Payment Actions
  • Backend-Driven Warning Banner
    Flexible payment instructions can now render an optional warning banner returned by the backend, enabling provider-specific notices such as the Punto Pago disclaimer.

v1.6.4

March 19, 2026 Fraud & Risk
  • Riskified Integration
    The Riskified script now loads with the correct shop and session identifiers, restoring reliable fraud signal collection when the shop domain is configured on the fraud provider.

v1.6.3

March 18, 2026 Core SDK
  • Unified User-Cancel Flow
    Wallet, APM, Click to Pay, 3DS modal and lite checkout cancellations now emit yunoPaymentResult with PENDING status and CANCELLED_BY_USER substatus, replacing the previous ERROR CANCELED_BY_USER event. Integrations that branched on the legacy error should switch to the substatus.
  • Additional Load-Time Optimizations
    Google Pay and Apple Pay scripts are now preloaded, and startCheckout/startSeamlessCheckout prefetch payment methods earlier.
Customer Fields
  • Document Type Options
    Removed a redundant country filter that could hide valid document types in some locales.

v1.6.1

March 12, 2026 Apple Pay
  • Billing Contact Collection
    Apple Pay can now capture the cardholder’s billing name and postal address from the Apple Pay sheet when enabled via merchant configuration. The cardholder name is forwarded in the payment payload on completion.
  • Free Trial Support for Recurring Payments
    Apple Pay now supports recurring billing with trial periods, configurable via merchant config (Apple Pay JS v14).
Card Payments
  • Network Selector
    Dropdown across step-by-step payment, card unfolded, card modal, enrollment, and Click to Pay. Driven by server-side merchant configuration.
Fraud & Risk
  • Cielo CyberSource Fraud Provider
    Cielo CyberSource added as a fraud provider, routed through the existing CyberSource integration.
  • EBANX Device Fingerprint Provider
    New device-fingerprinting provider with country-based initialization. Customer country is now propagated through the fraud pipeline.
Core SDK
  • Crash with External-Buttons-Only Sessions
    Fixed a crash that occurred when only external buttons (e.g. Apple Pay) were configured without SDK-rendered payment methods.
  • Enrolled Card Form Crash
    Prevents a runtime crash when card metadata is missing while detecting Amex on enrolled cards.
  • Sanitize Functions from Log Payloads
    Functions in the merchant-provided initial state are stripped before debug log serialization, preventing serialization issues across checkout, seamless checkout, headless payment/enrollment, and status flows.

v1.6.0

March 20, 2026
  • Subresource Integrity Support
    The SDK script tag now supports the integrity attribute for SRI-compliant loading, preventing unauthorized code injection. The @yuno-payments/sdk-web npm package exposes a loadScript method for SRI-compliant dynamic loading.
  • Arabic Language and RTL Layout
    Added Arabic (ar) language support. The checkout UI automatically switches to a Right-to-Left layout when Arabic is selected — no extra configuration required.
  • Faster Initialization
    Improved initialization performance for both Lite and Full SDKs, reducing time-to-interactive on first load.
  • Detailed Error Codes
    Configuration errors now surface more descriptive error codes, making it easier to diagnose integration issues during development.
  • 3DS Modal Centering
    Fixed an issue where the 3DS challenge modal was not centered on mobile devices. The modal now correctly fills and centers within the viewport.

v1.5.26

May 27, 2026 Card Payments
  • Compact Form Variant (1.5 backport)
    Backports the slimmer card, customer, and billing-address form layout from 1.6.x onto the 1.5.x line. Opt-in via the slimmerFormEnabled feature flag — disabled by default, no behavior change for merchants who don’t toggle it.

v1.5.25

May 26, 2026 Core SDK
  • Reliable Document Number Validation
    When the backend specifies a validationFunction for a document type that the SDK doesn’t recognize, the field now falls back to regex validation instead of marking every value invalid. Prevents broken document inputs when a new validation function rolls out backend-first.

v1.5.20

April 7, 2026 Apple Pay
  • Cancel Flow
    When the customer aborts an Apple Pay session, the cancel error now carries a metadata object with paymentCreated and ottCreated booleans so merchants can tell how far the flow had progressed. If a payment is created after the user has cancelled, the SDK automatically abandons the checkout session to prevent payments getting stuck in PENDING. (Backport of the v1.6.8 fix to the 1.5.x line.)

v1.5.19

April 2, 2026 Fraud & Risk
  • Forter token isolation
    Tokens are now scoped per Forter siteId so concurrent or sequential checkout sessions no longer read a stale token from a previous provider/session.
  • Forter beacon script
    Consolidated to a single URL (https://prod.y.uno/sdk-static-bundles-ms/v1/static/js/forter/forter.js) with an updated SRI hash for both sandbox and production. Merchants with a strict CSP script-src allowlist should ensure prod.y.uno is permitted.

v1.5.17

April 1, 2026 Core SDK
  • sdkType initialization option
    New option on Yuno.initialize() for identifying integrations (plugins, embedded contexts) via the x-sdk-type request header for downstream attribution.
Fraud & Risk
  • Forter Token Capture
    Token capture now uses a listener-based approach for reliable session capture across page lifecycles.

v1.5.15

March 19, 2026 Payment Actions
  • Backend-Driven Warning Banner
    Flexible payment-action screens (e.g. Punto Pago) can now render a server-driven banner (title + description) after the instruction steps. Configured server-side; no merchant code change required.

v1.5.14

March 19, 2026 Core SDK
  • APM Enrollment Button Text
    The enrollment confirmation button for APMs now reads “Continue” instead of “Save”.
Fraud & Risk
  • Riskified Beacon Parameters
    Missing query parameters added to the default beacon URL, restoring fraud signal collection.

v1.5.11

March 9, 2026 Apple Pay
  • Billing Contact Collection
    Apple Pay can now collect the cardholder’s billing name and postal address from the Apple Pay sheet when enabled via merchant configuration. The cardholder name is forwarded in the payment payload. No SDK code change required by merchants.
Fraud & Risk
  • EBANX Device Session Collection
    New EBANX fraud collector with automatic script mounting, retry, and unmount handling.
  • Cielo CyberSource Fraud Provider
    Added Cielo CyberSource as a supported fraud provider.
  • Country-Aware Fraud Collection
    Fraud signal collection now uses the customer’s country across payment methods, lite flow, secure fields, PayPal, Google Pay, Apple Pay, and the headless API client, improving provider routing and accuracy.

v1.5.8

February 24, 2026 Apple Pay
  • Wallet Domain URL
    Apple Pay transactions now include the wallet domain URL.
Card Payments
  • Financial Cost in Enrolled Cards
    Financial cost detail is shown for enrolled card payments.
Click to Pay
  • Financial Cost in C2P
    Financial cost detail is shown for Click to Pay flows.
Google Pay
  • Third-Party Gateway Support
    Google Pay can now route through third-party gateways (Adyen, Stripe, etc.) with the gateway and merchant ID supplied via a new SDK provider configuration.

v1.5.5

February 16, 2026 Google Pay
  • Reload on Already-Open Sheet
    Reloads if the Google Pay sheet is already open, preventing a stuck state.

v1.5.4

February 16, 2026 Core SDK
  • Document Types by Country
    New general-settings configuration for document types per country (server-side merchant config; no merchant code change).

v1.5.0

January 15, 2026
  • mountExternalButtons Method
    New mountExternalButtons(buttons) method lets merchants render Google Pay and Apple Pay buttons in any custom location within their UI, providing full control over button placement and styling.
  • Button Unmounting Methods
    Added unmountExternalButton(paymentMethodType) to remove a single external wallet button and unmountAllExternalButtons() to remove all mounted wallet buttons at once.
  • Wallet Buttons as Direct Buttons
    Google Pay and Apple Pay now appear as direct action buttons instead of radio-button list items, providing a cleaner and more prominent placement in the checkout UI.
  • PayPal Enrollment UX
    The PayPal payment sheet now opens immediately after the customer selects PayPal for enrollment or payment, removing an extra confirmation step for a faster checkout experience.
Lite Web SDK
  • Lite SDK External Buttons Required
    Google Pay and Apple Pay in the Lite Web SDK now require explicit mounting via mountExternalButtons(). Previously they rendered automatically as radio buttons. Lite SDK integrations must add a mountExternalButtons call — Full SDK integrations are not affected.
    Migration guide →

v1.4.0

October 15, 2025
  • Card Payment Voucher Messages
    Added voucher messaging for card payments, giving customers clear confirmation and transaction details immediately after a successful payment.
  • Language Override for Loader
    The Yuno loader now accepts a language property, allowing explicit UI language control independent of browser settings. Useful for multi-language environments.
  • Enhanced Click-to-Pay Rendering
    Improved rendering support for Click-to-Pay (C2P) elements, streamlining the checkout experience for enrolled cards.
PayPal
  • PayPal Installments Enrollment
    Customers can now enroll in PayPal installment plans directly through the PayPal payment flow, providing flexible payment options at checkout.
  • PayPal External Button Redirect
    PayPal can now be integrated via redirect flow with external buttons, giving merchants greater flexibility in building their payment UI.

v1.3.0

March 20, 2025
  • Smart Payment Method Grouping
    When a customer has an enrolled payment method, all other available methods are grouped under a collapsible “More options” dropdown. The enrolled method is prominently displayed by default.
  • European and Asian Language Support
    Added support for German (de), Dutch (nl), Swedish (sv), French (fr), Italian (it), Japanese (ja), and Korean (ko). Pass the corresponding code via the language initialization parameter.
  • General Bug Fixes
    Resolved various stability issues to improve reliability across payment flows.
  • Enhanced Styling and Branding
    Improved visual consistency and expanded customization options across checkout components.

v1.2.0

February 20, 2025
  • Optional Initialization Options
    Added an optional options parameter to Yuno.initialize for teams with advanced use cases such as custom session handling or tracking requirements.
  • Extended continuePayment Parameters
    continuePayment now accepts checkoutSession, showPaymentStatus, yunoPaymentResult, yunoError, countryCode, and language, allowing configuration overrides during payment continuation without restarting the checkout.
  • 21+ Language Support
    Expanded language coverage to over 21 locales including Chinese Simplified (zh-CN), Chinese Traditional (zh-TW), Vietnamese (vi), Russian (ru), Turkish (tr), Polish (pl), and more. Pass the language code to the language parameter in startCheckout.
Lite Web SDK
  • Lite SDK continuePayment Overrides
    The Lite SDK continuePayment method now accepts the same configuration overrides available in the Full SDK, enabling dynamic session, language, and callback changes during payment continuation.
  • Lite SDK Expanded Language Support
    Lite SDK v1.2 adds support for 18+ locales (up from 7 in v1.1), including European and Asian language codes such as de, fr, it, ja, ko, ru, and zh-CN.

v1.1.0

January 20, 2025
  • Async SDK Methods
    The initialize(), mountCheckout(), and startCheckout() methods now return Promises. Add await or .then() to each call — synchronous usage will no longer work.
    Migration guide →
  • continuePayment Method
    Introduced continuePayment() for handling complex payment flows. Call it when the API response includes sdk_action_required: true — the SDK then automatically renders 3DS challenges, external wallet steps, or redirects as needed.
  • Simplified 3DS Integration
    3DS data collection and setup are now bundled into the payment creation step. Remove any standalone 3DS setup service calls — implement continuePayment() and yunoPaymentResult() callbacks instead.
  • Boleto Bancário Support
    Boleto Bancário is now available for merchants operating in Brazil, expanding local payment options for customers who prefer offline payment methods.
  • Hybrid Cards Default to Credit
    Brazilian hybrid cards are now processed as credit by default, improving authorization rates for Brazil-based merchants.
  • Airwallex Security Integration
    Integrated Airwallex as an additional security layer for web payments, enhancing fraud protection without requiring extra configuration.
  • Forter Fraud Prevention
    Integrated Forter’s fraud prevention technology. The SDK automatically collects device signals; no separate setup is required.
  • Checkout.com 3DS Support
    Added support for Checkout.com as a 3DS provider. The SDK renders the authentication page automatically when the transaction provider is checkout3ds.
  • Unlimit 3DS Support
    Introduced 3DS authentication support for Unlimit payments, enhancing fraud prevention for merchants using the Unlimit provider.
  • Click-to-Pay Enhancements
    Terms & Conditions and card logos now update dynamically based on the selected card. C2P options are hidden for unsupported cards. A phone number field has been added for C2P registration. Compliance settings for privacy and tnc are forwarded with each card.
  • Inline Card Input
    Customers can now enter card details directly beneath the Card option without navigating to a separate screen. Fields persist when switching payment methods, and the flow is fully compatible with installments and the card selector.
Lite Web SDK
  • Lite SDK Initial Release
    Launched the Lite Web SDK (v1.1) — a streamlined integration offering essential payment methods, async initialize() support, and core callbacks (yunoPaymentResult, yunoError) with reduced setup complexity.

v1.0.3

May 26, 2026 Core SDK
  • Resilient Payment Status Updates
    If WebSocket initialization fails (network blip, blocked port, browser restriction), the SDK now logs the error and falls back to HTTP polling for payment status instead of blocking the checkout. No integration change required.

v1.0.0

January 1, 2025 Core SDK
  • Initial SDK Release
    First stable release of the Yuno Web SDK. Provides four integration variants: Full Checkout SDK, Lite Checkout SDK, Seamless SDK, and Headless SDK — covering a full range of UI customization needs.
  • Core Payment Methods
    Out-of-the-box support for credit and debit cards, digital wallets (PayPal, Apple Pay, Google Pay), bank transfers, direct debits, and regional local payment methods across multiple currencies and countries.
  • Three Integration Modes
    SDK can be loaded via an HTML <script> tag, dynamic JavaScript, or as an npm module (@yuno-payments/sdk-web), supporting both classic and modern JavaScript framework workflows.
  • Seven Language Support
    Initial international support includes Spanish (es), English (en), Portuguese (pt), Filipino (fil), Indonesian (id), Malay (ms), and Thai (th).
  • Core SDK Methods
    Provides Yuno.initialize(), startCheckout(), mountCheckout(), and startPayment() as the foundational API surface. All methods are synchronous in v1.0.