Skip to main content

Q3 2026 Public API Updates

Quarter at a glance

Q3 2026 opens score webhooks for testing and cleans up unused feed fields. Further EUDR public API changes are coming in Q4 2026; details will be announced before release. OpenAPI / Swagger remains the source of truth for request and response shapes when these features are enabled for your organization.

Highlights:

  • August — Removed unused deprecated statusId from v1 alert response DTOs (always null since July); removed GET /public/v1/disruptions/alerts (use GET /public/v2/feed); optional statusUpdates on GET /public/v2/feed when enabled for your organization; deprecated GET /public/v1/feed in favor of GET /public/v2/feed (removal May 31, 2027); deprecated ctype.priority and earliestAlert will be omitted from 1 November 2026 (contact support if this causes a problem)

  • September — score webhooks available for testing (contact support for early access); further EUDR public API changes coming in Q4 2026

The August cleanup removes a field that has been unused (null) since the alert-status feature was dropped, and deprecates GET /public/v1/feed (the endpoint still works until May 31, 2027).


August 2026

Removed unused statusId from v1 alert responses

The deprecated statusId field is removed from v1 alert JSON responses (PublicAlertDTO). It had been always null since the legacy per-user alert-status feature was dropped (July 2026). Feed v2 never returned this field; use relevancy on v2 alerts instead.

Affected endpoints (response shape only):

Method

Path

GET

/public/v1/feed

GET

/public/v1/target/{systemId}/{targetId}/alerts

Clients that ignored statusId (or treated null as “no status”) need no change. Clients that required the key to be present should drop that requirement.


Removed disruption alerts endpoint

GET /public/v1/disruptions/alerts is removed from the public API. Do not call it.

Use GET /public/v2/feed instead (permission ACCESS_PUBLIC_USER_FEED). See Deprecated GET /public/v1/feed for the v1 → v2 feed mapping.


Optional statusUpdates on feed v2

GET /public/v2/feed can include a statusUpdates array on each alert (who assigned a status, when, optional comment, and the status key such as confirmed / denied / resolved / outdated).

When the field is not enabled for your organization, statusUpdates is omitted from the JSON. When it is, the array is always present (empty if the alert has no updates).


Deprecated GET /public/v1/feed

GET /public/v1/feed is deprecated and will be removed on May 31, 2027. Responses include a Sunset HTTP header (RFC 8594) with that date.

Migrate to GET /public/v2/feed. Same permission: ACCESS_PUBLIC_USER_FEED.

V1

V2

/public/v1/feed

/public/v2/feed

collectionId

collectionIds (same comma-separated IDs)

from or newerThan (milliseconds)

from only; UTC ISO 8601 (e.g. 2024-01-01T00:00:00Z)

Omit date (varies)

Last 90 days of data

Numeric timestamps (createdAt, predictedAtStart, predictedAtEnd)

ISO 8601 strings in UTC

New in V2: to, timeFilterBy, minTier / maxTier; isSituationReport, active, relevancy; structured eventTypes, eventTypeGroups, alertTypes, labels instead of infotags; mentionedTargets, previousAlerts, flagged, useCaseDetails; optional statusUpdates when enabled for your organization. V2 is also faster.

Removed in V2: statusId (use relevancy); infotags (use the structured fields above).

The v1 endpoint continues to work until the sunset date. See the V2 operation documentation in OpenAPI / Swagger for request and response schemas.


Optional omission of ctype.priority

Nested ctype objects on public targets (PublicTargetDTO) include a deprecated priority field. This is an unused leftover sort rank for facility types — it is not alert High/Mid/Low. Display order uses ordering.

From 1 November 2026 this field will be omitted from the JSON for all organizations. Until that date it may still be returned for some organizations. If omitting ctype.priority causes a problem for your integration, contact [email protected] or your Customer Success Manager.

Affected endpoints (nested ctype on a full target object):

Method

Path

GET

/public/v1/feed

GET

/public/v2/feed

GET

/public/v1/target/{systemId}/{targetId}

GET

/public/v1/target/{systemId}/{targetId}/parents

PUT

/public/v1/target/{systemId}/{targetId}/data

POST

/public/v1/target/targets/bulk-fetch

GET

/public/v1/target/{systemId}/{targetId}/alerts

GET

/public/v1/suppliers (deprecated)

GET

/public/v1/network/{collectionId}/tree-graph (deprecated)

GET

/public/v1/network/{collectionId}/commodity-graph (deprecated)

GET

/public/v1/network/tree/{commodityTreeId}/commodity-graph (deprecated)

GET

/public/v1/suppliers/{systemId}/{targetId}/supplier-graph (deprecated)

On feed and target-alerts responses, this is the nested target on locations, primaryTargets, and mentionedTargets. v2 network / v2 supplier-graph responses are not affected (they do not nest a full target object).


Optional omission of earliestAlert

Public target objects (PublicTargetDTO) and v2 supplier details (PublicSupplierDetailV2DTO) include a deprecated earliestAlert timestamp. This is an unused leftover.

From 1 November 2026 this field will be omitted from the JSON for all organizations. Until that date it may still be returned for some organizations. If omitting earliestAlert causes a problem for your integration, contact [email protected] or your Customer Success Manager.

Affected endpoints:

Method

Path

GET

/public/v1/feed

GET

/public/v2/feed

GET

/public/v1/target/{systemId}/{targetId}

GET

/public/v1/target/{systemId}/{targetId}/parents

PUT

/public/v1/target/{systemId}/{targetId}/data

POST

/public/v1/target/targets/bulk-fetch

GET

/public/v1/target/{systemId}/{targetId}/alerts

GET

/public/v1/suppliers (deprecated)

GET

/public/v1/network/{collectionId}/tree-graph (deprecated)

GET

/public/v1/network/{collectionId}/commodity-graph (deprecated)

GET

/public/v1/network/tree/{commodityTreeId}/commodity-graph (deprecated)

GET

/public/v1/suppliers/{systemId}/{targetId}/supplier-graph (deprecated)

GET

/public/v2/suppliers/sites/find-by-identifier

Same nested-target rule as ctype.priority on feed and target-alerts. GET /public/v2/suppliers/sites/find-by-identifier is the extra v2 path: it has earliestAlert on the supplier detail object and does not have ctype.priority. GET /public/v2/suppliers/sites (list) is not affected.


September 2026

September opens score webhooks for testing. Further EUDR public API changes are coming in Q4 2026.


Score webhooks (early access)

Score webhooks are available for testing. When a supplier’s score changes, Prewave can send an HTTP payload to an HTTPS URL you provide, so you can react immediately without polling the scores API.

This is early access, not general availability. Payloads and subscription behaviour may still change, and the subscription API is not listed in the public OpenAPI spec yet.

If you want to try it: email [email protected] (or your Customer Success Manager) and ask for score-webhook early access. We will enable it for your organization and help you set it up.


Upcoming EUDR public API changes

Further EUDR public API changes are coming in Q4 2026. Details will be announced before release. Watch the What’s New section on dev.prewave.com and this changelog.

Existing EUDR v2 endpoints keep today’s behaviour until then.


💬 Questions?

For questions or support with these changes:

Did this answer your question?