# Changelog

Changes within `v1` are additive. A change that could break a client is announced here before it ships.

## API 0.3.0 · October 2026

Before founding brokers connect an AI host. Each change carries its class: additive, contract (it can break a client), agent behaviour (it changes what a host's model reads), operational, or commercial (prices, limits and access).

- **Contract, MCP.** A single nested input is now flat fields: `seller_note.amount` is `seller_note_amount`, and the same for `allocation` and `qsbs`. Lists such as `offers` stay lists.
- **Contract.** `quota_exhausted` (429, with `Retry-After`) replaces `rate_limited` for the inquiry quota and `fair_use` for the file-draft quota. `rate_limited` now means calls came too fast, and clears within seconds.
- **Contract.** `licence_not_accepted` is 403 wherever it is raised; it was 422 at approval.
- **Contract.** `GET /deals` pages: 25 deals by default, up to 100 with `limit`, and `cursor` continues the list. It returned up to 200 at once.
- **Contract.** `GET /listings` refuses a `cursor` it didn't return with 400 `invalid_cursor`; it read one as the first page.
- **Contract.** `PATCH /businesses/{business_id}` clears a field sent as `null`; it stored the null. An `Idempotency-Key` reused with a different query string returns `422 idempotency_key_reused`.
- **Contract.** The SBA price ceiling's `acquisition_type` no longer offers `esop_or_coop`, which always failed with 422.
- **Commercial, access.** An AI host signed in over OAuth gets the scopes your role can use, not all of them, and saves to a deal only once you grant it one. A host without a grant has a monthly limit of 1,000 credits.
- **Additive.** `has_more` on `GET /deals`. `business_name` and `listing_headline` beside a deal's IDs. MCP results carry `acquestor/request_id` in `_meta`. MCP errors carry `retryable` and `request_id`, with `acquestor/error_code` in `_meta`. `Acquestor-Max-Credits` works on the MCP server. A result cut to fit carries `truncated`.
- **Agent behaviour, MCP.** Every tool's description says what it returns, when to use it, when not to and its limits, and every parameter is described. The server instructions are five sentences. Errors open with their code; a used-up quota says when the same call can succeed, with `retry_after_ms`. A result stays within about 4,000 tokens, text and `structuredContent` together, and a cut page's `next_cursor` continues right after its last row; `get_deal` gives the newest saved runs that fit, each summarized by its headline figures. Its text states every field, and broker-written text, including a deal's listing headline, arrives labelled and without hidden characters, HTML or images.
- **Operational.** A 401 without a credential carries no error code in `WWW-Authenticate`; a token that isn't valid carries exactly one.
- **Operational.** `get_source` works over MCP; it answered not found for every source. `GET /sources` and `GET /sources/{source_id}` are documented as public, as they always were. The MCP server's `serverInfo.version` is the API version, 0.3.0.

## API 0.2.0 · October 2026

The founding-broker beta.

- Computed tools: SBA price ceiling, coverage stress test, capital stack, after-tax proceeds (federal, plus Texas, Florida, California, New York and Washington), offer comparison.
- Lookups: rates (H.15 prime, SOFR, Treasury yields, SBA rate caps), market salary (BLS OEWS, including national estimates), SBA acquisition lenders, the source registry.
- Listings: search and detail with both SBA ceiling cards; drafts from a broker's own file, a CSV or JSON; inquiries that API and MCP callers create as pending until the buyer confirms.
- Deals through a one-deal grant: figures, document reading, proof of cash, saved runs.
- Closed-deal contributions, pending the broker's attestation. Held until their page on acquestor.com ships (October 11, 2026): the operation saves nothing and the MCP tool isn't listed.
- The MCP server, on the 2026-07-28 protocol and the 2025 versions, with sign-in through OAuth or an API key.
- `Idempotency-Key` on writes and priced calls; a stored result replays for 24 hours.
