Skip to main content
Work through this page in sandbox. The Zapyd team reviews the same points before issuing production credentials.

Rules Zapyd enforces

Breaking these rules gets the order rejected, refunded or held. There’s no soft error.

Checklist

Customers and KYC

  • Customers are created with your client_reference_id, and you store the Zapyd id
  • Orders are blocked until the customer is VERIFIED
  • FAILED KYC shows the user what to fix, and only the failed part is resubmitted
  • A customer blocked after three attempts is handled

Payins

  • The rate, fees and receiving_amount shown come from the quotation
  • deposit_instructions come from each quotation and are never cached
  • The transfer reference is collected and sent as transaction_reference_id
  • Crypto is credited only on SUCCESS, never on ON_HOLD, FAILED or REFUNDED

Payouts

  • Asset, network and wallet_address are read from the quotation for every transfer
  • Per-order payouts are initiated with the matching transaction_hash
  • IN_REVIEW with an rfi_link sends the customer to answer it
  • The UTR from SUCCESS is shown to the user

Webhooks

  • The signature and the timestamp window are checked on every event
  • The endpoint returns 2xx fast and processes the event asynchronously
  • Events are deduplicated on id and event
  • Orders without a final status after a set time are polled, and you get an alert

Errors and operations

  • Signing passes the test vector in a unit test
  • Code branches on err_code, and only 429 and 5xx are retried, with backoff
  • Users never see raw err_code values
  • Requests, Zapyd IDs and responses for money-moving calls are logged

Security

  • The API secret lives in a secrets manager and never reaches a browser or mobile app
  • Widget Initialize runs server-side, and only widget_link reaches the client
  • Sandbox and production credentials are kept separate

Switch to production

1

Get production credentials

Share your sandbox results with the Zapyd team. After review, you get production keys.
2

Change the configuration

Change the host from sandbox.zapyd.com to api.zapyd.com. Swap the keys and the widget app_id. Move from Sepolia to mainnet networks. Register your production webhook URL.
3

Remove sandbox-only code

Remove the mock status calls and your test customers.
4

Run a small live order

Complete one small real order in each direction you support, then roll out.