PayPal module changelog
Reconstructed history of paypal, covering 0.9 through 1.0.6.2, using all 13 available source snapshots and historical in-module notes. There are 13 version entries, newest first.
The active module is modules/paypal.py modules/paypal.py, as selected by modules.json modules.json. All 12 backups and the active module are included. The earliest backup uses the filename paypal-0.9.py; subsequent backups contain a newline before .py. The current author notes reach back only to 1.0 and omit multiple later patches.
How to read this history
- Snapshot evidence: each release links to its exact source and preceding available snapshot. Bullets describe source changes; an addition means the first preserved implementation, not a guarantee that it was bug-free.
- Author notes: notes from every available snapshot were checked. Claims that differ from the source are identified explicitly; all versions named in the preserved notes have a source snapshot.
- Gaps: No source before 0.9 is available. Missing version numbers are not inferred as releases.
- Approximate dates: each date is the source file’s last-modified timestamp converted to UTC, not a confirmed release date. Saves, backup creation, and copies may be later than publication; equal timestamps do not prove simultaneous releases. This workspace has no usable Git history to confirm dates.
- Scope: library behavior, API changes, meaningful documentation edits, and demonstration/startup changes are included. Routine whitespace is omitted. Historical sources were read and compared without importing them, starting servers, or contacting external services.
Compatibility changes to notice
- OAuth URL/user helpers arrive in 1.0–1.0.1.1, but the bare-code branch of
extract_user_tokenremains unimplemented in the preserved source. - The asynchronous token descriptor changes in 1.0.1.2; its cache duration drops from one day to 30 seconds in 1.0.6.1.
- Token construction gains retry and diagnostic handling in 1.0.2–1.0.4, with date/nonce parsing changes in 1.0.5–1.0.6.
- Webhook verification, transaction reporting, and payout IDs on idempotency errors arrive in 1.0.6.2.
Releases
1.0.6.2
Approximate date: 2026-07-30 (snapshot timestamp, UTC).
- Added
Client.verify_webhook_signature(headers, event, webhook_id), posting transmission metadata and the event to the verification endpoint and returning whether the result isSUCCESS. - Added
Client.list_reporting_transactions(start_date, end_date, page=1, page_size=500), requesting all fields for a page of reporting transactions and returning parsed JSON. Both new helpers suppress the generatedPayPal-Request-Idheader. - Extended
IdempotencyErrorwith the original error data and an extractedpayout_batch_idfrom payout links; passed the error payload when raising it forUSER_BUSINESS_ERROR. - Changed direct script execution to use
primary_mod=Truein the self-update call. These implementation additions extend beyond the latest in-module release note, which is 1.0.5.
Evidence: Snapshot 1.0.6.2 modules/paypal.py; compared with Snapshot 1.0.6.1 backups/paypal_1.0.6.1\n.py.
1.0.6.1
Approximate date: 2026-07-30 (snapshot timestamp, UTC).
- Reduced
Client.tokendescriptor-cache expiration from 86,400 seconds to 30 seconds; the adjacent “24 hours” comment is stale. The underlying token is still reused until its own expiration check calls for renewal. - Replaced embedded client credentials in the demonstration with
PAYPAL_CLIENT_IDandPAYPAL_CLIENT_SECRETenvironment variables, and removed an older duplicate demonstration function.
Evidence: Snapshot 1.0.6.1 backups/paypal_1.0.6.1\n.py; compared with Snapshot 1.0.6 backups/paypal_1.0.6\n.py.
1.0.6
Approximate date: 2026-06-02 (snapshot timestamp, UTC).
- Extended the token nonce parser with a trailing
<extra>field afterZand explicitly selected non-regex parsing, allowing the timestamp extraction to accommodate trailing nonce data.
Evidence: Snapshot 1.0.6 backups/paypal_1.0.6\n.py; compared with Snapshot 1.0.5 backups/paypal_1.0.5\n.py.
1.0.5
Approximate date: 2026-04-27 (snapshot timestamp, UTC).
- Added a fallback to current UTC time when parsing the token response’s
Dateheader fails. - The fallback is timezone-aware while
expires_instill subtracts a naivedatetime.utcnow(). Thus the change is evidence of a fallback attempt, not a verified fix for every expiration calculation.
Evidence: Snapshot 1.0.5 backups/paypal_1.0.5\n.py; compared with Snapshot 1.0.4 backups/paypal_1.0.4\n.py.
1.0.4
Approximate date: 2026-04-24 (snapshot timestamp, UTC).
- Removed
from Nonewhen raisingUnknownErrorafter token-construction failure, preserving the underlying exception context in tracebacks.
Evidence: Snapshot 1.0.4 backups/paypal_1.0.4\n.py; compared with Snapshot 1.0.3 backups/paypal_1.0.3\n.py.
1.0.3
Approximate date: 2026-04-24 (snapshot timestamp, UTC).
- Added
UnknownError, formatting response JSON/text or dictionary data for diagnostics, and raised it when token construction fails after the retry. This initially suppresses the previous exception’s context withfrom None.
Evidence: Snapshot 1.0.3 backups/paypal_1.0.3\n.py; compared with Snapshot 1.0.2 backups/paypal_1.0.2\n.py.
1.0.2
Approximate date: 2026-04-06 (snapshot timestamp, UTC).
- Added
fetch_token(retry=True): if building aTokenfails, wait 0.1 seconds and fetch once more with retries disabled. HTTP error checking still occurs before this retry block.
Evidence: Snapshot 1.0.2 backups/paypal_1.0.2\n.py; compared with Snapshot 1.0.1.2 backups/paypal_1.0.1.2\n.py.
1.0.1.2
Approximate date: 2026-04-02 (snapshot timestamp, UTC).
- Changed the asynchronous
Client.tokendescriptor from plainpropertytotoolbox.CachedProperty(expire=86400). The author labels this a token-property fix; the existing_tokenreuse/expiration logic remains inside the getter.
Evidence: Snapshot 1.0.1.2 backups/paypal_1.0.1.2\n.py; compared with Snapshot 1.0.1.1 backups/paypal_1.0.1.1\n.py.
1.0.1.1
Approximate date: 2025-12-04 (snapshot timestamp, UTC).
- Handled non-JSON general 4xx responses with an exception containing the status and response text; removed token-payload debug printing and allowed missing scopes or
app_idinToken. - Changed callback-code extraction from
LinkInfo.querytoLinkInfo.qs. Added theschema=openidquery and form content-type header toget_user_info. - Disabled automatic execution of the guarded demonstration again.
Evidence: Snapshot 1.0.1.1 backups/paypal_1.0.1.1\n.py; compared with Snapshot 1.0.1 backups/paypal_1.0.1\n.py.
1.0.1
Approximate date: 2025-10-22 (snapshot timestamp, UTC).
- Added
Client.extract_user_tokento obtain an authorization code from a callback URL/request and exchange it for aToken, plusget_user_infoto fetch OpenID user information with the supplied bearer token. - The source places the exchange inside the URL-detection branch, so a bare authorization-code string falls through without an exchange. Its initial query lookup uses
LinkInfo.query; 1.0.1.1 changes it toqs. - Re-enabled the guarded demonstration, now printing a generated OAuth URL before returning.
Evidence: Snapshot 1.0.1 backups/paypal_1.0.1\n.py; compared with Snapshot 1.0 backups/paypal_1.0\n.py.
1.0
Approximate date: 2025-10-22 (snapshot timestamp, UTC).
- Added
Client.generate_oauth_url(redirect_uri, scope="openid", state=None), generating a PayPal Connect authorization-code URL with encoded redirect, scope, and optional state; list scopes are joined with spaces.
Evidence: Snapshot 1.0 backups/paypal_1.0\n.py; compared with Snapshot 0.9.1 backups/paypal_0.9.1\n.py.
0.9.1
Approximate date: 2025-10-22 (snapshot timestamp, UTC).
- Commented out the direct-execution demonstration and its exception-printing example. The client implementation is unchanged from 0.9.
Evidence: Snapshot 0.9.1 backups/paypal_0.9.1\n.py; compared with Snapshot 0.9 backups/paypal-0.9.py.
0.9
Approximate date: 2025-04-05 (snapshot timestamp, UTC).
- Earliest available source; no preceding snapshot is available. Already provides a sandbox/live
Client, client-credentials authentication,Tokenexpiration metadata, authenticated GET/POST/DELETE requests, invalid-token retry, and optional waiting against a shared local rate limiter. - Already supports creating/fetching batch payouts and serializing
PayoutItemvalues in USD for email, PayPal ID, user-handle, and phone recipients; user-handle/phone payloads select the Venmo wallet. - Already includes authorization, invalid-token, insufficient-funds, and idempotency exceptions; updater bootstrapping/self-updating; and the import-time assignment
toolbox.TxtParser.use_regex = False. Contains a guarded live-service demonstration, which was not executed for this history.
Evidence: Snapshot 0.9 backups/paypal-0.9.py; earliest available baseline.