5.16.8.0

New Features

AI Assistants

  • MCP Server for AI Assistants - AI tools such as Claude, Cursor and ChatGPT can connect to your account over MCP from the new Tools > Integration > AI assistants (MCP) screen: the assistant signs in with your merchant login through OAuth, you choose read-only or read and write access, and connected assistants can be revoked at any time. Available tools cover affiliates, commissions, campaigns, banners, clicks, traffic and top affiliates reports, refunds and chargebacks, and an order diagnosis that explains why an order did not create a commission; bearer tokens are available for tools without OAuth, and only the merchant role is supported in this version (#16557) (#16933)

Domain Settings

  • Managed Let's Encrypt Certificates - Hosted accounts with a custom domain can choose a managed Let's Encrypt certificate that is issued and renewed automatically instead of uploading their own, and the Domain settings screen was redesigned with a Set custom domain dialog that first asks for the certificate type (#15451)

Integrations

  • Ecwid Plugin - The Ecwid plugin was rebuilt for Ecwid's current API: it connects with the Store ID and secret token of a private app created in your Ecwid Control Panel, approves, refunds or declines commissions automatically from Ecwid order status webhooks, and supports multiple stores as separate configuration tabs. Automatic status updates are optional and require the plugin's webhook URL and the app's client secret to be set up (#9031)

Webhooks and Application Callbacks

  • Payout Fields in Affiliate Profile Change Webhook - The Affiliate Profile Change Webhook plugin can now watch and send the affiliate's payout method, minimum payout and payout method fields such as bank account or PayPal email, and signup Application Callbacks can include the same payout fields as variables. Payout values are masked in the event log (#14292)

Improvements

REST API v3

  • Search Filters and Operators - The q parameter accepts >= and <= operators, date-only range bounds include the whole end day, and new filter fields were added: visitor_id, ip, approved_at and starred on GET /transactions, alias, is_default, account_id and starred on GET /campaigns, and is_confirmed, destination_url and starred on GET /banners. The campaign type filter and transaction type values such as refund, chargeback and cpm now work (#16989)
  • Partial Refunds and Notes - The refund and chargeback endpoints accept total_cost to reverse only part of a commission, and refund, chargeback and status change requests accept a system_note visible only to merchants; the note of PATCH /transactions/{id}/status is now stored (#16989)
  • Typed Response Fields - starred is returned as a boolean in affiliate, campaign, banner and transaction rows, application.currency_decimals in GET /settings is an integer, empty logo_url and product_ids are null, GET /banners/{id} returns campaign_name, GET /affiliates/{id} returns every custom field defined in the affiliate form, and campaign rows no longer include the duplicate campaignid and the unused networkstatus (#16989)
  • URL Parameter Names in Settings - GET /settings returns the configured URL parameter names for affiliate, banner and campaign IDs, data1, data2 and the destination URL under tracking.url_parameter_names, so integrations can build correct tracking links without API v1 (#16957)

Lifetime Referrals

  • Lifetime Referrals Export and Import - The Lifetime referrals grid and CSV export offer optional Commission group ID and Channel code columns whose values are accepted as-is on re-import, and the import option was renamed to "Update existing relations" with a clearer explanation that only the columns present in the CSV are updated (#16955)

Banners and Campaigns

  • Collapsible Category Filters - Banner and campaign category filters in the merchant and affiliate panels show only main categories when the whole tree does not fit, a click expands or collapses a whole branch, and a chevron in the header expands or collapses all; search results keep their parent categories and the path to already selected categories is expanded (#13887)

Integrations

  • Shopify Imported and Old Orders - Orders older than 7 days by their placement date are no longer processed when Shopify reports them as created, and status notifications for such orders are ignored unless a commission already exists, so bulk imports of historical orders no longer delay tracking. Orders without a storefront checkout, such as POS or draft orders, are processed on the first attempt without retries (#16981)
  • Shopify Diagnostics - The event log shows the visitor ID on created Shopify sales and warns when a customer who came through an affiliate link could not be matched to the affiliate; an updated checkout pixel code in the plugin configuration reports pixel-side failures and should be pasted again into Shopify Customer events (#16980)

Security

  • Login Hardening - Strengthened protection of the merchant, affiliate and API logins against automated login attempts (#16946) (#16948)

Bug Fixes

Site Replication

  • Links and Embeds on Replicated Sites - Links that open in a new tab from a replicated site, such as the Back Office link to the affiliate login, work again. A new "Sandbox replicated sites" option under Features > Site Replication > Configure, enabled by default, can be turned off to allow embedded videos and cookies on replicated pages if you trust every replicated site (#16871)

Banners

  • Rebranded PDF Banner Filenames - Rebranded PDF banners with accented or other non-ASCII characters in the file name now download with the correct name (#16938)

Plugins

  • Affiliate Profile Change Webhook Responses - Fixed false critical errors in the event log when the webhook endpoint accepted the request with a success status other than 200, such as 201 or 204 (#17022)
  • Plugin Configuration Layout - Removed the empty space below plugin and feature configuration forms with conditionally hidden fields (#16930)