API Release Notes, September 2026
New This Month
Deprecation of Latest Bookings and Opportunities
Effective September 14, 2026, the Latest Bookings and Opportunities APIs are deprecated. Decommission will follow.
New Client SSL Certificate for *.api.concursolutions.com
SAP Concur will renew the security certificate for *.api.concursolutions.com on November 10, 2026. In most cases, certificate renewal is automatic and transparent, and no action is required.
This renewal is part of SAP Concur’s preparation for the upcoming DigiCert Global Root G5 migration (April 2027). As part of the renewal, the Client Authentication extended key usage will be removed from this certificate. This extension is not used on this certificate, and its removal has no impact on service functionality.
Important: Due to industry-wide changes to maximum certificate validity periods — reducing to 199 days in 2026 and 47 days in 2029 — SAP Concur will no longer be able to provide advance announcements for certificate renewals. Certificates will be rotated more frequently and automatically. Changes to Intermediate or Root CA certificates will still be announced in advance.
SAP Concur will issue the new certificate on the following schedule:
| Certificate | Implementation Date | Applicable Data Centers |
|---|---|---|
*.api.concursolutions.com |
November 10, 2026 at 10PM PDT | US2, EU2, APJ1 |
Note: Root and Intermediate certificates remain the same for this renewal. The root certificate will change to DigiCert Global Root G5 in April 2027. See the DigiCert Global Root G5 Migration section below for details.
Certificate Pinning Guidance
Clients who have not pinned the expiring certificate do not need to take any action. Most clients do not pin the certificate.
Note: Certificate pinning is not recommended. If your implementation requires certificate pinning, pin the Intermediate or Root CA certificate instead of the leaf/end-entity certificate. Pinning the leaf certificate will result in frequent service disruptions as renewal cycles become shorter. If you are unable to migrate to pinning the Intermediate or Root CA certificate, contact SAP Concur Support before November 10, 2026.
DigiCert Global Root G5 Migration
DigiCert is transitioning its certificate chain to the DigiCert Global Root G5. SAP Concur will migrate all public certificates to G5 starting April 2027. Clients who pin certificates must add the new root certificates to their trust stores before the migration date:
- RSA: DigiCert TLS RSA4096 Root G5
- ECC/ECDSA: DigiCert TLS ECC P384 Root G5
For full details, including certificate download links and feature activation, refer to the Concur Shared Release Notes: SSL Certificates Renewal for *.api.concursolutions.com.
Now Available: Hotel Service v4 — Traveler Title Field
A new field has been added to the Hotel Service v4 reservation request that allows the traveler’s title to be sent when present in their profile. The new field is part of the guests array:
"guests": [
{
"firstname": "Blake",
"middleName": "Jordan",
"lastname": "Smith",
"title": "Mister",
"address": {
"addressLines": [
"910 Mainland Street"
]
}
}
]
Ongoing
New Client SSL Certificate for ESS webhook.api.concursolutions.com
In an effort to ensure the ongoing security of our products and services, on September 24, 2026, ESS will be issuing a new webhook.api.concursolutions.com SSL certificate. We will always use the same client x509 certificate with the following subject: C=DE, ST=Baden-Württemberg, L=Walldorf, O=SAP SE, CN=webhook.api.concursolutions.com.
All details will be published in the Event Subscription Service v4 documentation soon.
Important! Upcoming Shutdown of Request V1, V3, and V3.1
Updated Effective Date: November 3, 2026
As previously announced, the Concur Request APIs v1.0, v3.0, and v3.1 have been decommissioned. These versions will be retired and no longer accessible as of November 3, 2026. Customers currently using these versions must migrate to the successor API, Request API V4, to ensure uninterrupted functionality. Please reach out to your Concur representative for more information.
Previews
In general, this table lists items that will be shipping in the next 30-60 days. For a broader view of features that are coming, please see our Road Map Explorer.
| Date | API | Preview |
|---|---|---|
| 08/2026 | Detokenizer v5 – Get Banking Info API | The Detokenizer v5 API will include a new endpoint to retrieve bank account details: POST /detokenizer/v5/bankaccounts/{loginId}. This endpoint returns the most recently modified active bank account for the given employee loginId, with sensitive fields decrypted and the full payload re-encrypted with the caller’s AES symmetric key. |
| 06/2026 | Trips v5 API with Configurable Trip Event Subscriptions | The Trips v5 API will provide a scalable and performant way to retrieve trip data based on a configurable event-based subscription model, with divisional view support for TMC partners. |
| 01/2026 | Additions to Reservation and Search Requests in Hotel Service v4 | This API will add travel arranger details to a reservation request. It will also add the GIATA ID to a hotel search request. |
| 07/2025 | New Attributes for Spend User v4.1 | The Spend User v4.1 API will allow you to access the processorReportAccess field in the User Preference extension and the User extension will allow you to access the following fields: officeLocationCountry, officeLocationStateProvince, officeLocationCity. |
| 04/2025 | New Fields Added to Financial Integration Services (FIS) v4 API | For customers of the Concur Expense Professional Edition using the Financial Integration Services (FIS) v4 API, additional fields will be included in the Expense report document payload and mileage fields will be added to the payroll document schema. |
| 05/2024 | Retention Period for Credit Card Data Files | For compliance reasons, SAP Concur will be implementing a process wherein card data files received from external sources (Issuing banks, Card associations) will be deleted from systems after 90 days. |
| 01/2024 | Hotel Service v4 | Updates to Hotel Service v4 that will remove existing elements from the |
Deprecations and Decommissions
APIs are being deprecated or decommissioned in accordance with the SAP Concur API Lifecycle & Deprecation Policy.
| Date | API | Details |
|---|---|---|
| 06/2026 | Decommission of Launch External URL V1 | Effective June 23, 2026, the Launch External URL V1 callout API was decommissioned. Customers must migrate to Launch External URL V4, which provides full functional equivalence with no known gaps. |
| 06/2026 | Deprecation of Company Cards Transactions v1 | Effective June 8, 2026, the Company Cards Transactions v1 API was deprecated. This has been replaced by Cards v4 API. Decommission will follow. |
| 10/2025 | Deprecation of Locations v3 | Effective October 10, 2025, the Locations v3 API will be deprecated. This has been replaced by Localities v5. Decommission will follow. |
| 07/2025 | Deprecation of Expense Group Configurations v3 | Effective June 26, 2025, the Expense Group Configurations v3 API was deprecated. This has been replaced by the Expense Configuration v4 API. Decommission will follow. |
| 07/2025 | Deprecation of Expense v3 DELETE | Effective June 26, 2025, Expense v3 DELETE was deprecated. This has been replaced by Expense v4 Delete. Decommission will follow. |
| 07/2025 | Deprecation of Attendees v3 API | Effective July 1, 2025, the Attendees v3 API was deprecated. This has been replaced by Attendees v4. Decommission will follow. |
| 07/2025 | Deprecation of Attendee Types v3 API | Effective July 1, 2025, the Attendee Types v3 API was deprecated. This has been replaced by Attendee Types v4. Decommission will follow. |
| 04/2025 | Deprecation of Attendees v1, v1.1, and v2 | Effective October 9, 2018, we have deprecated the Attendees v1, v1.1, and v2 APIs. Decommission will follow. |
| 03/2024 | Deprecation of Spend User Retrieval 4.0. | The decommission of password provisioning via file import will occur in April 2025. |
| 01/2023 | Move from the Travel Request External Validation Callout v1 to the Event Subscription Service (ESS) | This callout was designed to work with the Concur Request v1 API that is in the process of being decommissioned. Users are strongly recommended to move to the Event Subscription Services (ESS) in order to subscribe to the Request events. |
| 01/2021 | List v3 API | Effective April 16, 2021, we have deprecated the List v3 API. This API is replaced by the List v4 API. List v3 is planned to be retired in a future release. |
| 01/2021 | List Item v3 API | Effective April 16, 2021, we have deprecated the List Item v3 API. This API is replaced by the List Item v4 API. List Item v3 is planned to be retired in a future release. Please migrate to the List Item v4 API as soon as possible. |