Version 26.03
September 2026 · API v35 LATEST
Released with DOMPloy 6.5.0.
New Features
-
DOM Online Mesh topology management: see how repeaters, gateways and devices are linked, and check the connection quality of each link. Repeaters can now also be decoupled.
Global view
Add and edit a plan
Delete a plan
View by level
-
PLC management is now integrated into DOMPloy for the ACM, in the device's SPS tab.

-
Update rollback: if a DOMController update fails during the process, it is cancelled automatically and the controller is restored to its previous version. An error message appears in the update status in DOMPloy.

-
Online / offline switching on the ACM, directly from the ACM panel with the Set offline / Set online button.

-
Support for the DOM Guard and DOM Loq devices.
- New permission routes to replace all permissions (
PUT /api/permissions,PUT /api/permissions/{credential}) and to delete them all (DELETE /api/permissions/all,DELETE /api/permissions/{credential}/all). - New mobile group permissions.
- Device Privacy Protection.
- Offline OS package update bundles can be applied on the DOMController for critical patches.
- The transponder battery status is now updated from OSS events.
- The updated RBAC matrix is applied and enforced across API roles.
- Improved display of pending data in DOMPloy.
- Breaking change: in
GET /api/devices,featuresnow uses the same format asGET /api/devices/features(kebab-case keys, each holdingavailableandenabled), and thehas-errorfield is removed. - Behaviour change (OSS): a credential can now hold two permissions on the same door with different roles. The permission uniqueness key is extended to credential / door / role, so a client that relied on a same-role overwrite to change a permission's role must now delete the previous permission explicitly. Whitelist and wireless-online modes are unchanged.
Fixes
- Behaviour change: removing the last permission that references a global week schedule no longer silently resets that schedule.
DELETE /api/schedulesgains an opt-inclear-unusedquery parameter (boolean, defaultfalse) to reset unreferenced slots explicitly. - Permission routes now reject
site-id(OSS) andprefix(whitelist / wireless-online) with a400when sent in a mode where they do not apply, instead of silently matching the wrong permission. - Replacing or deleting all permissions no longer removes special cards (battery, emergency, permanently open/closed, master key) from devices. A permission that does not fit on a full device is now reported in
error-listinstead of being silently dropped, anossentry withoutdoor-idorgroup-idis rejected with a400, and deleting an unknown permission returns a404. Whitelist and wireless-online permissions of the same credential no longer block each other. - Permissions can no longer be given to a credential used as a special card, and a credential that holds permissions can no longer become a special card.
- In ACM/UPDATER mode with remote access, the DOMController now correctly checks the permission validity dates and week schedule. External readers and office mode are not supported in this mode.
- Replacing an RFNM with an online gateway now requires all its devices to run firmware 6.0 or later.
- The
write-key-file-nbrfield is now handled correctly when the value is invalid. GET /api/oss/{credentialId}/permissions/{siteId}now returns400instead of500when the credential id length is invalid.- Device configuration requests no longer fail with a server error when
oss-configis omitted. POST /api/config/logsnow returns the standard success response.- A template validation error no longer causes a fatal crash when submitting a template.
- Update files are now removed once an update completes; leftover files could previously prevent the system from detecting the end of the update.
- Restoring a backup now correctly restores the mastercard.
- OSS credential ids are now canonicalised (case and zero-padding), so permissions are written and read under a single key.
- OSS badge data no longer contains empty 00:00–00:00 time periods for no-access days.
- Full reprogramming now syncs promptly on the Gateway when Fast Online is enabled.
- The repeaters-update job no longer aborts on a stale database connection and no longer leaves repeaters stuck in "update in progress".
- DOMPloy: the key field for wireless permissions is now correct under the new permission model.
- Includes all the security fixes of 26.02.01 and 26.02.02, including the web-server restriction (breaking change for the legacy OSS SOAP web service).
Known Issues
No known issues for this version.
Download
Installation files are not published yet for this version. They will be available on the DOM Security SharePoint, in the
DOMConnect v.26.03folder.