Idempotency on every mutation
An Idempotency-Key header on every public mutation, and a correlation id that runs from the start of an operation through to the webhook you receive. Retrying is always safe.
Developers
The merchant API is in design, and the contract is being written before the code — which is the useful moment to hear from you. Below is what is already decided.
There is no public endpoint and no key to issue today. Everything on this page is a design commitment, and the reason it is published this early is that integrators are the right people to argue with about a wire contract while it can still change cheaply.
An Idempotency-Key header on every public mutation, and a correlation id that runs from the start of an operation through to the webhook you receive. Retrying is always safe.
Signed with HMAC, carrying a nonce, delivered with retries and a dead-letter queue. The event is written in the same database transaction as the state change it reports, so a delivery failure is a delivery problem and never a lost payment.
Amounts cross the wire as integers with explicit decimals per token. No floats, anywhere, in any direction — your side formats, ours calculates.
Underpaid, overpaid, expired, wrong network and reorged are documented statuses with defined transitions, not edge cases discovered in production.
The specification is written first and the server is validated against it at runtime, so drift between docs and behaviour is rejected rather than discovered. Clients are generated from the same document.
An org-scoped key can prepare a payout batch; it cannot approve one. Signing stays with a key holder on a device, which is the same boundary the wallet draws.
Illustrative — the published contract is what binds, and it is not published yet.
Tell us what you are integrating and what your last crypto integration got wrong. Early access goes out in the order those conversations happen.
Request early access