Punchh Platform Release Notes - 31 March 2026 Deployment

The updates described in these release notes and the affected/linked documentation will not be available in the Punchh platform until the target deployment date.

Wallet and Passes

Smart Passes: Offer Passes are Now Live!

We’re excited to launch Offer Passes for Apple Wallet and Google Wallet, a modern digital offer experience that makes it easy for guests to save, access, and redeem offers — all without downloading an app.

Offer Passes support:

  • Redeemables (for loyalty guests)
  • Coupons
  • Promo / Redemption Code Campaigns (for both loyalty and non‑loyalty guests)

Guests can save offers directly to their Apple or Google Wallet, where key details like offer status and expiration are clearly displayed. When an offer expires, it automatically moves to the expired section of the wallet, removing guesswork and reducing frustration. Offer Passes do not require a Loyalty Pass or mobile app, making them a powerful acquisition and engagement tool for reaching new audiences while still delivering value to existing loyalty guests. Offer Passes automatically reflect the imagery of the offer itself, using the image configured on the Redeemable, Coupon Campaign, or Promo Campaign. When an offer does not include an image, the pass seamlessly falls back to your configured Offer Pass branding, ensuring a consistent, visually polished experience for every guest. Overall, Offer Passes deliver a frictionless, mobile‑first alternative to traditional digital and paper coupons, helping brands increase visibility, engagement, and redemption. (CAM-6724, CAM-6705, EDDBA-806, CAM-7074, PDOC-3354, PDOC-3674, PDOC-3675, PDOC-3676)

See the following article(s) for more details:

Instant Reward Visibility for Loyalty Passes

Give your guests instant visibility into their rewards—right on their loyalty pass. You can now display 1–5 active rewards directly on the back of Apple and Google Loyalty Passes, prioritized by soonest expiration. This makes it easy for guests to see what’s available to redeem without opening the app or searching through messages. Reward visibility stays up-to-date as rewards are earned or redeemed:

  • Apple Wallet passes refresh shortly after reward activity or when the guest "pulls to refresh" on the pass
  • Google Wallet passes refresh on a scheduled cadence (up to every 24 hours)

Prefer not to show rewards? Set the value to 0 to hide rewards entirely from the pass. (CAM-7095, PDOC-3674, PDOC-3675)

See the following article(s) for more details:

System Messages for Apple Pass Errors

When Apple Wallet personalization fails during loyalty pass enrollment due to an existing loyalty account with a matching email but no phone number on file, the system will automatically send a recovery email to the guest.

The email:

  • Explains why enrollment could not be completed
  • Confirms the guest already has a loyalty account
  • Includes a call‑to‑action to download the Apple Loyalty Pass
  • Brands can enable and customize this notification under System Messages > Apple Pass Personalization Failure (CAM-7015, CAM-6996, CAM-7121, CAM-7075, PDOC-3716)

See the following article(s) for more details:

Guest Identity Service (GIS)

The Guest Identity Service (GIS) continues to evolve as the centralized authentication layer for PAR products, helping deliver a more secure, flexible, and seamless guest login experience across solutions like Punchh and Ordering. (EC-545, EC-544, EC-184)

Available Now

Advanced Authentication: GIS supports Advanced Authentication powered by Auth0, enabling passwordless login using one-time passwords (OTPs). This gives brands a modern authentication option that reduces friction for guests by removing the need to remember passwords.

Benefits:

  • Passwordless login using OTPs
  • Faster and simpler guest access
  • Modern, secure authentication experience

See the following article(s) for more details:

Basic Authentication: GIS also supports Basic Authentication using email and password. This provides a familiar sign-in option while keeping authentication centralized within GIS.

Benefits:

  • Standard email/password login flow
  • Consistent authentication experience
  • Centralized identity management

Social Login: GIS supports social login through Facebook, Google, and Apple. This gives guests more convenient ways to sign in and helps reduce barriers during registration and login.

Benefits:

  • Faster sign-in and sign-up
  • Improved guest convenience
  • Support for commonly used social identity providers

Platform Direction - Coming Next

Going forward, all authentication-related enhancements and updates will be delivered through GIS. This ensures a more unified authentication strategy and a stronger foundation for identity across PAR products. As part of this direction, GIS is designed to support a single centralized rotating token model that enhances security and enables a more seamless cross-product experience. This will help guests move across products such as Punchh and Ordering without needing to log in again for each experience.

GIS will continue to expand with additional authentication capabilities, including:

  • Passkeys for a faster and more secure sign-in experience
  • BYOIDP (Bring Your Own Identity Provider), allowing businesses to continue using the identity provider of their choice

Business Value

These enhancements help brands deliver:

  • More secure guest authentication
  • Lower login friction
  • Greater flexibility through multiple sign-in options
  • A more consistent experience across products

Action Required: Enabling GIS for a brand requires migration of the existing user base from the Punchh database to GIS, along with necessary authentication attributes (e.g., email, phone, password).

Segments

Segments Added to Target Google Pass

We’ve added a new guest segmentation attribute under Profile Details that allows marketers to identify guests who have added a Google Pass to their Android Wallet. This enhancement makes it easier to build targeted campaigns and exports for guests based on their Google Pass engagement state. (SB-3841, SB-3888, PDOC-3711)

A new attribute is now available in the Segment Builder:

  • Segment Type: Profile Details
  • Attribute: Added Google Pass to Wallet

With this new attribute, you can now:

  • Segment guests who have added a Google Pass to Wallet
  • Combine this filter with Onboarding Channel = GooglePass
  • Build more targeted campaigns and exports based on pass enrollment and wallet adoption

See the following article(s) for more details:

Segment Export Schedule Correction

We resolved an issue where segment exports could generate multiple files due to a recently introduced performance enhancement. That enhancement has been temporarily rolled back, and segment exports are now functioning as expected while we finalize a fix before reintroducing the improvement. (EPS-11197)

Campaigns

Campaigns Beta Workflow Now Limited

The Campaigns Beta workflow has been soft‑deprecated to streamline the campaign experience and focus ongoing enhancements on Classic Campaigns.

As of this release:

  • New Beta Campaigns can no longer be created
  • Existing Beta Campaigns can no longer be duplicated
  • Drafted Beta Campaigns can still be edited and scheduled to run
  • Campaigns already scheduled will continue to run through completion

All new campaigns should be created using the Classic Campaigns workflow, which remains the supported and recommended path forward. (CAM-7028, CAM-7118, CAM-7119, CAM-7030, PDOC-3706)

Consumer Experience

Passwordless Onboarding

The Punchh loyalty iframe now supports passwordless onboarding flows using a one-time passcode (via the Advanced Authentication product). Reach out to your Punchh representative to learn more. (CX-2893, CX-2908, CX-2923, CX-2925, DEVOPS-16699, CX-2928, CX-2929, CX-2940, CX-2946, CX-2943, CX-2948, CX-2949, CX-2954, CX-2958, PDOC-3629, CX-2975)

Offers

Solution for Expired Redeemables and Dynamic Rewards

Previously, when a redeemable attached to a dynamic reward had expired, it was automatically removed by the system. This resulted in broken reward flows and confusion during configuration and gifting. Now, expired redeemables will no longer be automatically removed from dynamic rewards. Instead, the system will now display the following validation message: "The attached redeemable has expired and can no longer be gifted to members. Please update it accordingly." This ensures reward flows remain intact while clearly flagging expired redeemables. (OMM-1719, EPS-10851, OMM-1801)

Reporting and Analytics

UI Improvements for Guest-driven Analytics Reports

We’ve refreshed the Customer Metrics report in the Punchh platform to make your data easier to find, understand, and act on.

The previous two-tab view (Customer Analytics and Location Acquisition Report) has been redesigned:

  • Customer Analytics Report and User Acquisition by Location Report now appear as separate options in the left side navigation, so you can jump directly into the insights you need.
  • The Customer Analytics Report gives you a clear, comprehensive view of customer behavior, engagement, and lifecycle performance across your program.
  • The User Acquisition by Location Report highlights how customer sign-ups and engagement vary by location, helping you quickly spot top-performing stores and growth opportunities.

We’ve also enhanced the UI for both reports to improve readability and make it easier to navigate, filter, and interpret your data. These updates make it faster and simpler to get to the metrics that matter, so your teams can spend less time clicking through reports and more time turning insights into campaigns, optimization, and revenue. (INT1-2094, PDOC-3730, INT1-2089, PDOC-3731)

See the following article(s) for more details:

Data Schema Changes

As a part of database maintenance, we are updating the data type of several columns from 'int' to 'bigint'. Review the following documents for the complete list. (DL-2424, PDOC-3708)

See the following article(s) for more details:

Integrations

Salesforce Segment Export Now Deprecated

We've deprecated the Salesforce Marketing Cloud Integration segment export feature because it hasn’t been actively used across customers and is highly specific. Additionally, the feature/app is no longer listed on the Salesforce marketplace. (INT1-2107, INT1-2132, PDOC-3713)

See the following article(s) for more details:

Developers Corner

Olo Promotion Specs 2.0 - Additional Supported APIs

We previously announced Punchh support for the Olo transactional promotion APIs in the September 9 2025 Release Notes (See Olo Promotions Spec (2.0) Support - Full Transactional Flow Implemented in the Developers Corner). In this release, we have added support for two additional Olo Promotions Specs 2.0 API endpoints. These endpoints comply with Olo Promotions Specs 2.0 and include request and schema validation as per the Olo documentation, ensuring real-time integration, robust error handling, and transactional integrity. (PDOC-3678, PDOC-3679)

  • POST /promotions/accounts - Olo uses this endpoint to create a loyalty account in the Punchh system using user-level information, such as first name, last name, email, phone number, and an external identifier. It will return the Punchh loyalty account ID, along with any balance and reward details available. This endpoint will specifically be invoked during the Create or Get SSO-Linked Olo User flow where Olo links a user from an authorized (OAuth) third-party login provider a new loyalty account within the provider's system, and an Olo user. Note this is only applicable when the feature is enabled for a brand.
  • GET /promotions/accounts - Olo uses this endpoint to find a loyalty account in the provider's system using a customer's loyalty membership number. It will specifically be invoked during the manual linking process where Olo links an Olo user to their loyalty account in the provider's system using a membership number recognized by the provider.

These Olo APIs are implemented in Punchh. However, the main API documentation for these APIs is maintained on the Olo website. See the following article(s) for more details:

Loyalty Short Code Integration With Single Scan Flow (SSF)

The Loyalty Short Code feature has been enhanced to integrate with the Single Scan Flow (SSF), enabling loyalty members to use the short code for both loyalty identification and payment initiation. The Short Code Pay using SSF feature must be enabled for the business to allow payments using the short code. (PDOC-3688, LPE-1774)
The Generate a Single Scan Code API (POST /api2/mobile/single_scan_tokens) has been updated to support the loyalty short code flow. The API will now accept two new additional parameters in the request body: a boolean parameter, short_code, and location_id to generate a short code.
When short_code is set to true, the API follows the short code flow and generates a short alphanumeric code along with a single scan code. The short code generated is returned in the response, while the single scan code is stored in the Punchh backend and associated with the short code. The user can share the short code verbally at the drive-thru window for faster account look-up at the POS. When short_code is set to false, the API follows the legacy single scan token flow and does not return a short code in the response.

POS User Look-up API Returns single_scan_code for Short Code Flow

As part of this enhancement, the User Look-up and Fetch Balance API (GET /api/pos/users/search) response now includes a new parameter single_scan_code when the POS calls the API with the short code. Punchh retrieves the single scan code associated with the short code to look up the user, along with any rewards and payment information selected by the user when generating the short code from the mobile app. (PDOC-3685, LPE-1653)
The User Look-up and Fetch Balance API returns the single_scan_code in the response, which the POS can use for further actions such as check-in, redemptions, and payments.

Mobile API — Program Meta Updates

We have added two new configuration parameters in the Program Meta API (GET /api2/mobile/meta.json) response for mobile clients to support drive-thru short code payments and loyalty identification behavior: (PDOC-3722, LPE-1648, LPE-1650)

  • enable_drive_thru_pay (boolean) — Indicates whether the short code can be used for drive-thru payments when Single Scan Flow is supported.
  • guest_identification_type (string) — Defines short code look-up behavior for locations that do not support Single Scan Flow (restrict_pay_allow_lookup, restrict_lookup).

See the following article(s) for more details:

New Mobile API Endpoints for Peer-to-Peer Loyalty Transfers

Three new APIs have been added to enable loyalty users to transfer points, currency, or rewards to other loyalty members directly from the mobile app. All three APIs require the user's password for authentication before completing the transfer. (PDOC-3690, PDOC-3691, PDOC-3692, LPE-1684)

  • Transfer Loyalty Points (POST /api2/mobile/loyalty_transfers/points) - Enables a user to transfer loyalty points from their account to another user's account by specifying the recipient's email address and the number of points to transfer.
  • Transfer Loyalty Currency (POST /api2/mobile/loyalty_transfers/currency) - Enables a user to transfer loyalty currency from their account to another user's account by specifying the recipient's email address and the amount to transfer.
  • Transfer Loyalty Reward (POST /api2/mobile/loyalty_transfers/reward)- Enables a user to transfer a loyalty reward from their account to another user's account by specifying the recipient's email address and the reward ID to transfer.

Program Meta API Update for Peer-to-Peer Loyalty Transfers

We have added a new configuration parameter p2p_authentication_type in the Program Meta API (GET /api2/mobile/meta.json) response to indicate the authentication type required for peer-to-peer (P2P) loyalty transfers. Possible values: none and email_password_authentication (PDOC-3689, LPE-1685)

See the following article(s) for more details:

New Mobile API Endpoints for Collectibles

PAR Punchh introduces two new Mobile API endpoints: GET /api2/mobile/collectibles and GET /api2/mobile/users_collectibles. These endpoints allow mobile apps to access collectibles for business and user‑specific collectibles from the Punchh platform. Using these APIs, brands can surface loyalty collectibles within the mobile experience and give users visibility into their collectible activity. These endpoints are available for brands with Collectibles enabled. (LPE-1720, PDOC-3687, LPE-1721, PDOC-3686)

Get Collectibles (Business Level) - GET /api2/mobile/collectibles
Mobile apps can use this endpoint to dynamically retrieve collectible definitions configured for a business. The API also provides an option to filter collectibles by collectible categories. The response returns collectible attributes, such as the collectible name, image, description, category name, category ID, and other details for all collectibles or selected categories.

Get User Collectibles (User-Level) - GET /api2/mobile/users_collectibles
Mobile apps can use this endpoint to dynamically retrieve a user's collectibles. The API provides options to filter collectibles by collectible categories and to specify whether disappeared collectibles should be included. The response returns collectible attributes, such as the collectible name, image, description, category name, category ID, disappeared at (when applicable), and other details for all collectibles or for selected categories. (PDOC-3686, LPE-1721, PDOC-3687, LPE-1720)
See the following article(s) for more details:

Guest Identity Service (GIS) APIs Available

Guest Identity Service (GIS) APIs are now available on the PAR Developer Portal. These APIs support GIS-powered authentication and identity management across supported products and experiences. A Getting Started guide and API documentation are also available. (PDOC-3610, EC-544, EC-545, EC-184)

Key highlights:

  • Authentication methods — APIs support two authentication methods: the client request body parameter (generated from Punchh Business Dashboard with the AdvanceAuth scope) and Bearer JWT tokens for authenticated endpoints.
  • Token-Based Authentication — APIs support authentication using access tokens (JWT) with refresh tokens for session renewal.
  • API Groups
    • Advanced Authentication — Passwordless OTP authentication via email or SMS.
    • Auth — User registration, sign-in, token refresh, and sign-out.
    • Password — Forgot password, reset password, and change password flows.
    • Social Login — Google, Apple, and Facebook sign-in.
    • Business Config — Server-to-server business authentication configuration sync.
    • Health — Liveness probe endpoint.
  • Authentication Flows — Supports Email/Password (Basic Auth), Social Login, Password Recovery, and iframe SSO.
  • Error Handling — Supports a consistent error response structure with an errors object and correlation_id for diagnostics.
  • Correlation ID — Optional X-Correlation-Id request header for end-to-end tracing.

See the following article(s) for more details:

Removed allow_payment from Generate Drive-Thru Short Code API

Removed allow_payment from the request body of the Generate a Drive-Thru Short Code API (POST /api2/mobile/drivethru_code), as payment is not supported for the drive-thru short code. (PDOC-3722, LPE-1851)
See the following article(s) for more details:

Google Wallet Support — Added google_pass_url Response Parameter

Mobile apps will now provide users with a direct link to add their loyalty pass to Google Wallet, as provided for Apple Wallet. We have added a new response parameter, google_pass_url, in multiple APIs. The user can use the google_pass_url to download the user's associated loyalty Google Pass. (PDOC-3729, CAM-7089)

A new string parameter, google_pass_url, has been added to the user object returned in the response of the following APIs:

  • POST /api2/mobile/users/login
  • POST /api2/mobile/users
  • PUT /api2/mobile/users
  • POST /api2/mobile/users/connect_with_facebook
  • POST /api2/mobile/apple_registrations
  • POST /api2/mobile/users/google_sign_in
  • GET /api2/mobile/users/profile

See the following article(s) for more details: