> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.givechariot.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.givechariot.com/_mcp/server.

# Changelog

## September 8, 2026

## Summary

OAuth 2.0 for the Chariot API

### What's new?

Applications can now act on a nonprofit's behalf using OAuth 2.0 instead of an API key. The nonprofit authorizes your application, and you receive an access token limited to what they approved.

The new [OAuth guide](/guides/oauth) covers:

* **Authorization Code flow with PKCE** — Generating the code verifier and challenge, the consent screen, and exchanging the code for tokens
* **Scopes** — `read_only` and `read_write` grant their level of access across every resource, so you don't have to request a scope per resource or add new ones as the API grows
* **Identity** — Request the `openid` scope to receive an `id_token` and use Chariot as an OpenID Connect provider for single sign-on. See [Identity](/guides/oauth/identity)
* **Environments** — Authorization, token, and discovery endpoints for production and sandbox
* **Token lifetimes** — Access tokens last 15 minutes; refresh tokens use a 31-day sliding window with a 365-day maximum
* **Redirect URI requirements** and **IP whitelisting**

OAuth access is not self-service. Contact us at [support@givechariot.com](mailto:support@givechariot.com) to register your application and receive client credentials.

### FDX API

FDX authentication now points to the OAuth guide instead of repeating the flow, and the [FDX introduction](/fdx) lists the values specific to FDX: the `read_only` scope, per-environment credentials, and IP whitelisting. Sandbox endpoints replace the previous staging endpoints.

## May 22, 2026

## Summary

FDX API updates

### What's new?

* **`GET /customers/current`** — New endpoint to retrieve the authenticated customer's organization-level identity (nonprofit name, EIN, address) directly from the OAuth token, without requiring an account ID.
* **`organizationId` on list accounts** — The `GET /accounts` response now documents the `organizationId` field, which identifies the organization that owns the accounts. This value is equivalent to the `customerId` returned by `GET /customers/current`.

### Authentication updates

* **Scope documentation** — Clarified that `read:bank_accounts` and `sync:connected_accounts` are mutually exclusive per FDX authorization. A client may hold both scopes, but each authorization must contain exactly one.
* **Token exchange details** — Added explicit `Authorization: Basic base64(client_id:client_secret)` header format and request body field tables for both token exchange and refresh flows.

## May 15, 2026

## Summary

FDX API v6 (Beta)

### What's new?

We've added support for the [Financial Data Exchange (FDX)](https://financialdataexchange.org/) v6.3 standard, providing authorized financial data aggregators with read-only access to bank account data.

The FDX API includes 7 endpoints organized around

deposit accounts

:

* **Accounts** — List accounts, get account details, and get account contact information
* **Statements** — List statements and download statement documents (PDF, CSV, BAI2)
* **Customers** — List organization identity associated with an account
* **Transactions** — List transaction history with pagination and date filtering

Authentication uses OAuth 2.0 Authorization Code flow with IP whitelisting. To request FDX API credentials, contact us at [support@givechariot.com](mailto:support@givechariot.com).

> **Info**
>
> Chariot is a financial technology company, not a bank. Chariot Accounts come with a Demand Deposit Account through our banking services partner, Column N.A., Member FDIC. Deposits in Chariot Accounts are eligible for FDIC insurance up to \$250,000 per depositor, for each insurable capacity in which the account is held.

## May 8, 2026

## Summary

DAFpay Donor Accounts (Beta)

### What's new?

We've introduced **DAFpay Donor Accounts** — a new identity-based DAFpay flow designed for Donor Advised Fund providers integrating with DAFpay.

Donors authenticate with their DAFpay Identity (email-verified, DAFpay-managed) and submit Grant Requests. DAFs use new Chariot APIs to verify the donor and decision Grant Requests. Two flows are supported on the same data model:

1. **Donor-Initiated Verification** — DAFpay emails a one-time code to the donor after they submit a Grant Request; the donor relays it to the DAF; the DAF calls a single API to verify and approve the Donor Account.
2. **DAF-Initiated Setup** — DAF creates a Donor Account and Authorization Token in advance via their portal; donor enters the code into DAFpay during profile setup, auto-approving their account.

### New APIs

* [Donor Accounts](/api/donor-accounts) — create, list, get, update, disable, enable.
* [Authorization Tokens](/api/authorization-tokens) — create, list, get, revoke, verify.
* [Giving Pools](/api/giving-pools) — list, get.
* [Grant Requests](/api/grant-requests) — list, get, submit, reject (DAF decisioning on Grant Requests).

### New webhook events

* `donor_account.created`, `donor_account.updated`
* `authorization_token.created`, `authorization_token.updated`
* `grant_request.created`, `grant_request.updated`

### New guides

* [Donor Accounts overview](/guides/dafpay/donor-accounts/overview)
* [Donor-Initiated Verification](/guides/dafpay/donor-accounts/donor-initiated-verification)
* [DAF-Initiated Setup](/guides/dafpay/donor-accounts/daf-initiated-setup)
* [Grants Lifecycle](/guides/dafpay/donor-accounts/grants-lifecycle)

### Availability

Donor Accounts are currently in beta and are available as part of a pilot program with a handful of design partners. If you're a DAF provider and interested in integrating with DAFpay this way, please reach out to [contact@givechariot.com](mailto:contact@givechariot.com).

## January 14, 2026

## Summary

Gift Processing APIs (Beta)

### What's new?

We've added new Guides and APIs to make it easier for nonprofits to automate and streamline their gift processing.

These new APIs are currently in beta and are available as part of a pilot program with a handful of design partners.
If you're interested in trying them out, please reach out to us at [contact@givechariot.com](mailto:contact@givechariot.com) to get on the waitlist!

## May 1, 2025

## Summary

Header API Key In List Grant APIs

### What's new?

We've remove the `x-chariot-api-key` header from the List Grants API as a requirement. In the past, this header was used to filter the list of grants by a specific Connect. This is no longer necessary as the `connect_id` query parameter can be used for this purpose instead. Additionally, for those who have multiple Connects, omitting the `connect_id` query parameter will return the grants for all of your Connects.

## March 17, 2025

## Summary

Grantmaking Disbursement APIs (Beta)

### What's new?

We've added new Guides and APIs to make it easier for grantmaking platforms to disburse payments to nonprofits.

These new APIs are currently in beta and are available as part of a pilot program with a handful of design partners.
If you're interested in trying them out, please reach out to us at [contact@givechariot.com](mailto:contact@givechariot.com) to get on the waitlist!

## February 24, 2025

## Summary

Authentication Update: Transition from OAuth 2.0 to API Keys

### What's new?

We've updated our authentication method from OAuth 2.0 to API Keys. This change simplifies the
integration process by eliminating the need to manage token expiration and refresh cycles.
With API Keys, you can authenticate requests more straightforwardly, reducing the complexity of
maintaining session states.

> **Tip**
>
> If you have any feedback or suggestions, please reach out to us at [developers@givechariot.com](mailto:developers@givechariot.com)

## September 20, 2024

## Summary

New Documentation Site!

### What's new?

We've launched a new documentation site thanks to our friends at [Fern](https://www.buildwithfern.com/)!

> **Tip**
>
> If you have any feedback or suggestions, please reach out to us at [developers@givechariot.com](mailto:developers@givechariot.com)