Improved
Checkout SDK Updates — Web v1.8.0, Android v1.4.0
September 29th, 2026
Web SDK — v1.8.0 (2026-09-28)
Added
- Optional CVV support in Hosted Fields via
setCVVOptional(boolean)— an empty CVV passes client-side validation and an emptycvvvalue is sent at tokenization, while a typed CVV is still fully validated. Recache and Click to Pay are unaffected and always require a CVV. - Express Checkout optional/hidden CVV: init-time config on
uiConfig.cardPaymentFormFields.verification_value(isRequired: falseto show but not require,isHidden: trueto not render), plus runtime setterssetCVVOptional(boolean)andsetCVVHidden(boolean). - Paze
mount()/isMounted(): the SDK creates its own<paze-button>inpaymentElements.pazewith an optionalbuttonStyle;displayMode: 'dynamic'inserts it hidden until an eligiblecanCheckout(). - Paze
environmentKeyconfig so a standalone Paze integration (no other Spreedly SDK on the page) can still be attributed to your environment. - New Paze events
pazeButtonClicked(emitted by the SDK-owned button beforegetCheckoutOptions()runs) andpazeEligibilityChecked(emitted on everycanCheckout()resolution with{ eligible }).
Changed
- Card brand logos now render in the card number field for both Hosted Fields and Express Checkout (Visa, Mastercard, Amex, Discover, Diners Club, JCB, Maestro, UnionPay, Elo; generic icon otherwise), replacing the text badge. No API change — existing hide toggles still work.
- Hosted Fields inputs now set their own padding instead of inheriting the browser's, so text sits consistently across browsers (
setStylesstill overrides). - Breaking (Paze): the SDK now owns the
<paze-button>.paymentElements: { paze: '<id>' }and a synchronousgetCheckoutOptionsare now required, andcheckout()no longer starts a flow (START_FLOWis rejected — onlyCHANGE_CARDandCHANGE_SHIPPING_ADDRESSare supported). See docs/paze/INTEGRATION_GUIDE.md for migration steps.
Fixed
- Hosted Fields: non-digit characters no longer flash in the card number and CVV inputs. No public API, event, or payload change.
Android SDK — v1.4.0 (2026-09-16)
Changed
- Compiles with Kotlin 2.1.20 (was 2.3.10) so React Native 0.82–0.86 hosts no longer need to pin Kotlin 2.3.10; AGP, Gradle, and Compose BOM are unchanged.
- Custom loggers (
setLogger) now receive already-sanitized tag, message, and throwable — no original exception type or PAN/CVV in log text. - Recache CVV and the in-flight spinner are no longer restored after rotation.
Breaking Changes
SpreedlyApiErrorDetailstored strings (rawErrorBody, messages, validation errors) are now capped and redacted and may not be valid JSON — usestatusCode/errorKey/safeDescription(); do not parserawErrorBodyas wire JSON.- ACH account-number validation is ciphertext-only; a raw account number in callbacks or validators fails and will not tokenize — use
SPLTextField(FormFieldType.ACCOUNT_NUMBER). - Plaintext digits on
onCardNumberChangeno longer setcardScheme— drive PAN throughSPLTextField.
Deprecated
SpreedlyEncryption/Encryptor/FormFieldType.shouldEncrypt()are lint-deprecated and restricted to the library group — useSPLTextFieldfor card and bank fields.
Fixed
- Extensive Click to Pay fixes: leaked host-ingress threads on WebView detach, saved-card tokenization failures caused by over-redacted Mastercard flow/correlation IDs, missing CSP/allowlist hosts for Visa, Amex and Discover networks (identity lookup, enrollment, saved-card art, and fingerprinting), an invalid email/phone ending checkout instead of allowing retry, and stuck states after OTP-with-no-cards or a declined new card.
Security
- Log-safe
toString()for failed payment, 3DS challenge, and API-error results;LogSanitizerredaction of PAN-like digit runs (12+, including separated or embedded) and labeled CVV, including across the 8 KiB cap. - Click to Pay hardening: host WebView uses origin-checked messaging instead of
JavascriptInterface; script-src CSP uses a SHA-256 hash instead ofunsafe-inlinewith an explicit per-network host allowlist; the bridge origin check is narrowed back to Mastercard-only; CDN hosts are no longer valid main-frame navigation targets; andshouldInterceptRequestnow enforces the navigation policy for main-frame POSTs. FLAG_SECUREis retained until the last overlapping Spreedly screen closes (merchant-set flag preserved), and corrupt optional card/CVV/account ciphertext returnsValidationFailedinstead of tokenizing empty values.

