What’s new at Yativo this October, and what you need to do before 14 October.
This month we’re shipping three updates: a more secure way to authenticate with the Yativo API, new virtual accounts in Nigeria, the UAE and Colombia, and new payment links for Argentina, Bolivia and Nigeria. One of them needs action from every API integrator, so let’s start there.
1. API keys with IP whitelisting (action required)
We’ve replaced login-based bearer tokens with dedicated API keys. Your servers now send two headers, X-Api-Key and X-Api-Secret, on every request. There’s no login call, no token refresh and no expiry.
Every key is also locked to the public IPs of the servers you list. A request from any other IP is rejected, even if the key and secret are correct.
Why we made the change:
- Revocable one at a time. Keys belong to your business, not to a person’s login. Revoke one key without touching the others or changing a password.
- Tied to known servers. A leaked key is useless outside your whitelisted IPs.
- Simpler integrations. No more token caching or refresh logic. Request and response bodies don’t change.
We’ve also added passkeys for the dashboard. Everyone on your team can now sign in with Face ID, Touch ID, Windows Hello or a security key. Email code sign-in stays available as a fallback.
Key dates
| Date | What happens |
|---|---|
| Now | API keys and passkeys are live. Create keys and test in sandbox. |
| Midnight, 14 October 2026 | IP whitelists are enforced. Requests from unlisted IPs get a 403. |
| 15 October 2026 | Legacy login cut off. Bearer tokens only work inside the dashboard. |
What to do now
- In the dashboard, go to Developers → API Keys and click Generate key.
- Add the public egress IPs of every server that calls Yativo.
- Replace the
auth/logincall and bearer token withX-Api-KeyandX-Api-Secret. - Test in sandbox, then call
GET /api/v1/ip-whitelist/checkfrom each production server. - Deploy before 14 October 2026.
The full step-by-step guide, with code samples and an FAQ, is here: Yativo API Authentication Changes: Integrator Brief.
2. New virtual accounts: NGN, AED and COP
You can now receive local payments in three new markets, all on local rails.
| Virtual account | Market | Settles in |
|---|---|---|
| NGN | Nigeria | NGN |
| AED | United Arab Emirates | AED |
| COP | Colombia | USDC |
Your customers pay like a local, and you receive funds without correspondent banking delays. COP collections settle in USDC, so you can hold or move value without taking on peso exposure.
To get set up, contact your account executive. They’ll walk you through eligibility, onboarding and how to start collecting.
3. New payment links: ARS, BOB and NGN
Payment links now support Argentine pesos, Bolivian bolivianos and Nigerian naira. Create a link, share it with your customer, and get paid in their local currency, with no integration needed.
Contact your account executive for pricing and setup details.
Questions?
Reach out to your account executive or our support team. We’re here to help you get every integration moved over well before the deadline.