
Diagnosing memory issues in your extensions just got significantly easier. This month introduces Memray memory profiling support directly into the SDK. Enable it by setting the Q2SDK_ENABLE_PROFILING=true environment variable, and control where the profiling output lands with the new Q2SDK_PROFILING_FILE environment variable. No extra tooling setup required — just flip the flag and start profiling.
.nvmrc files must now contain a full semver version for frontend builds, ensuring a consistent and predictable Node.js environment across all projects. To support this, q2 check now validates your .nvmrc for a full semver value and automatically suggests the latest patch version of the newest supported Node.js major — so you always start from a solid, up-to-date baseline.
Additionally, q2 check now detects and warns about package-lock.json files in extension frontends, recommending pnpm as the preferred package manager for faster, more reliable installs and better dependency consistency across teams.
A new async helper in q2_requests lets you send HTTP requests with non-standard or custom HTTP methods that are not covered by the standard verb functions (get, post, put, etc.). json_response flag addition to hq requests so that the response is returned as fully parsed JSON.
This month the SDK introduces several DBObject additions across multiple areas:
RestrictedEntitlementMode DBObject for managing REM profile configuration. This introduces cli entrypoint support to retrieve profile, profile groups, profile transactions, and profile audit actions.ExternalTransaction and checks if OAuth token is enabled across all OAuthLookup methods.Our October release (26.10.0) of the Q2Mobility iOS app, scheduled for 09/30/2026, will update Xcode to version 26.6. To ensure seamless compatibility with the Q2 build system, we kindly request that you review and update your module if it includes any SDKs or third-party dependencies built with earlier versions of Xcode.
We are also targeting support for Xcode 27.x by the end of the year. Please stay tuned for additional details and the exact timing of this update.
We're planning to upgrade to Swift 6 in an upcoming iOS release. Timing isn't finalized yet, but the upgrade may introduce language, compiler, and dependency compatibility changes.
What to do now: Start reviewing your modules and any third-party dependencies for Swift 6 readiness. We'll share detailed timelines as they firm up.
We are targeting to update the Q2Mobility Android app to Android API level 37 (Android 17) by the end of the year. The minimum supported Android API continues to be level 29 (Android 10). To ensure seamless compatibility with the Q2 build system, we kindly request that you review and update your module if it includes any SDKs or third-party dependencies built with earlier versions of Android. Please stay tuned for additional details and the exact timing of this update.

Company admins can manage team members directly from My Organization → Members. Select any member to enable or disable accounts, restart password resets, toggle self-service tool access, and manage sandbox permissions. You can also disable two-factor authentication when needed and control shared development server access for customer accounts. All member management happens in one place—no support ticket required for routine user administration tasks.
This Tecton release is packed with polish across the design system.
Radio Group now supports a separator and configurable orientation, giving you more control over how option groups lay out. Checkbox and Radio Group both gained a label line-height token for cleaner multi-line labels, and Input picked up a visible-last-count property so you can control how many trailing characters stay visible in masked fields.
Card Image now supports an additional status, Buttons get a full style refresh across every interactive state, Radios receive a visual update, and Icons recieve sizing improvements.
Aesthetics gained new color-scheme and contrast custom properties, giving platforms finer control over how themes render.
Calendar gets updated WCAG compliance fixes, Select now speaks more clearly to screen readers when searchable, and Stepper content is now properly grouped for assistive tech.

This month, we have added a new endpoint (Get REM Customers) designed for retrieving customers currently in REM. This further facilitates fraud and risk integrations and provides greater visibility into customers whose entitlements have been restricted. Results can be filtered to retrieve the customers relevant to a particular time period.
We're expanding the Caliper API's SMART capabilities with new support for managing Imported Audiences and Simplified Audiences.
New Imported Audience functionality makes it easier to bring audiences from external marketing platforms into Q2 SMART, where they can be used in Audience Builder and combined with existing SMART data to create more targeted audiences. Imported audience membership can be associated with users through Q2 User IDs or email addresses, opening up more opportunities to connect marketing efforts inside and outside of Digital Banking. We've also expanded Simplified Audience support with endpoints for creating and deleting audiences directly through the API. To learn more about getting started with SMART and the available audience capabilities, visit our SMART Endpoints Guide.
New Purge User Sessions and Purge Admin Sessions endpoints provide API-level control over active Digital Banking sessions. User sessions can be invalidated using either a User ID or (Admin) login name. Once purged, the affected active sessions are no longer valid, giving integrations a direct way to manage session termination when needed.
Caliper SDK (Python) v2.339.0 - CHANGELOG
Mobile SDK v26.9.1 - CHANGELOG
Tecton SDK (Javascript) v1.72.0 - CHANGELOG
Marketplace (Python) v0.8.9 - CHANGELOG
Caliper API (Python) v1.55.0-rc.2 – CHANGELOG
Senior Program Manager