Products
Objects
Environments and base URLs
Each API module has its own path prefix. Full URL = host + module prefix + endpoint path.
Example:
POST /payout/quotation in sandbox is https://sandbox.zapyd.com/pos/api/v1/payout/quotation.
Authentication
Every request is signed with your API secret. The signature is Base64 HMAC-SHA256 overapiKey|timestamp|canonicalJsonBody. GET requests sign {}. See Authentication for helpers in three languages and a test vector.
Response envelope
Every response uses the same envelope. Checkstatus first, then read data or err_code.
err_code, not on message. Create endpoints for quotations and orders return HTTP 201. See Error handling for retry rules.
Amounts and currencies
- Send amounts as strings (
"10000","60.50") so you don’t lose precision. - On a quotation, send either
sending_amountorreceiving_amount, never both. - The quotation response returns both amounts, the
rateand afeesbreakdown. Show the user these values, not your own calculation. - Asset and fiat codes are case-insensitive (
usdtorUSDT). Networks are lowercase (tron,polygon,sepolia). - Check supported pairs in Stablecoins and networks and Supported geographies.
Idempotency and your own IDs
Sendclient_reference_id (your own ID) on customers and orders. Save both your ID and the Zapyd id in your database.
- Customer create: if you send a
client_reference_idthat already exists, Zapyd returns the existing customer. You can retry this call safely. - Orders: a quotation can be used only once, so a retried initiate can’t create a second order from the same quotation.
- Webhooks can arrive more than once. Deduplicate them on the object
idandevent.
Order lifecycle
SUCCESS, FAILED and REFUNDED are final. ON_HOLD (payin) means the payment is held for review: don’t release crypto, and contact support with the payin ID. IN_REVIEW (payout) means compliance needs more information. The webhook may include an rfi_link for the customer. The Status reference lists every status and what to do in each one.