InvoiceKit Improves Payment Safety, Currency Handling, and Public Links

SmartKit Updates
August 15, 2026

InvoiceKit has received an important reliability and security update focused on safer payment recording, cleaner invoice editing, stronger public links, and more trusted media handling.

This release improves how InvoiceKit protects invoice balances, handles draft currencies, manages converted quotes, and creates public invoice access links.

Safer Payment Recording

InvoiceKit now updates invoice balances under a JSON lock when payments are recorded.

This helps protect invoice data when multiple requests happen close together, reducing the chance of balance conflicts during payment submission.

Duplicate Overpayment Protection

During payment submission, InvoiceKit now re-checks the current invoice balance before accepting the payment.

This prevents duplicate or parallel requests from accidentally recording more payment than the invoice actually allows.

Cleaner Receipt Number Generation

Receipt numbers are now generated only after a payment is accepted.

This keeps receipt numbering cleaner by avoiding unused receipt numbers from payment attempts that fail validation.

Draft Currency Preservation

Existing draft invoices and quotes now keep their original currency when edited.

This makes editing safer for businesses that work with multiple currencies and prevents accidental currency changes during updates.

Converted Quotes Are Now Locked

Quotes that have already been converted are now locked from further editing.

This helps preserve the accuracy of the original quote once it has moved forward in the invoicing workflow.

Stronger Public Invoice Access

Public invoice pages now require both an enabled public link and a matching stored token.

This strengthens access control for shared invoices and ensures public pages only open when the stored sharing details are valid.

Smarter Invoice Email Links

When sending an invoice by email, InvoiceKit now creates a fresh valid public link when one is needed.

If a public token cannot be generated, the link creation now fails cleanly instead of leaving the user with an unclear or broken state.

Trusted Shared Logo Selection

Shared logo selection now accepts only trusted SmartKit user-upload image URLs.

This helps keep invoice branding safer while still allowing businesses to reuse their uploaded media across InvoiceKit.

Verified PHP Stability

All InvoiceKit PHP files were checked for syntax validity as part of this release.

These improvements make InvoiceKit safer and more reliable for businesses that depend on accurate balances, secure invoice sharing, and clean financial records.