General
What does Zapyd do?
What does Zapyd do?
Zapyd is a stablecoin on-ramp and off-ramp API. Payin turns fiat into stablecoins. Payout turns stablecoins into fiat paid to a bank account. Zapyd also offers remittance (the RDA flow for India, standard payouts elsewhere) and prefunded payouts. Zapyd runs the KYC, banking rails, blockchain transfers and compliance. See Core concepts.
Which countries and currencies do you support?
Which countries and currencies do you support?
See Supported geographies for markets per product, and Stablecoins and networks for asset and network pairs.
How do I choose between the API, the widget and the dashboard?
How do I choose between the API, the widget and the dashboard?
See Choose your integration. Use the API for full control, the widget to launch in days, and the dashboard for manual operations with no code.
Getting started
How do I get API credentials?
How do I get API credentials?
Email partnerships@zapyd.com or book a call. You get sandbox credentials after approval. Production credentials come after an integration review.
How long does an integration take?
How long does an integration take?
Most API integrations take one to two weeks. A widget integration usually takes a few days. The Quickstart gets a sandbox order through in about 10 minutes.
Do you have SDKs?
Do you have SDKs?
Not yet. Use the REST API directly: the Quickstart has a complete request helper in Node.js and Python. You can also generate a client from the OpenAPI spec, or let a coding agent write one. See Build with AI.
Is there a sandbox?
Is there a sandbox?
Yes. The sandbox host is
https://sandbox.zapyd.com. It uses separate credentials, and mock endpoints let you set KYC and order statuses. See Sandbox testing.Troubleshooting
I get AUTH_INVALID_SIGNATURE. What's wrong?
I get AUTH_INVALID_SIGNATURE. What's wrong?
Run the test vector through your code. The usual causes are:
- Spaces in the JSON.
- Nested keys that aren’t sorted.
- Signing a GET body other than
{}. - Hex output instead of Base64.
- Sending a body that differs from the one you signed.
I get AUTH_TIMESTAMP_EXPIRED.
I get AUTH_TIMESTAMP_EXPIRED.
X-TIMESTAMP must be Unix time in seconds, within 300 seconds of server time. Create a new timestamp for each request and sync your server clock.I get a 404 on an endpoint that exists.
I get a 404 on an endpoint that exists.
Check the module prefix. Customer endpoints use
/cms/api/v1, payin uses /pis/api/v1, payout uses /pos/api/v1, limits and EDD use /ren/api/v1, and webhooks use /org/api/v1. See base URLs.My quotation expired. What now?
My quotation expired. What now?
Create a new one. A quotation locks the rate until
expiry_time and can be used once.A customer failed KYC. Can they retry?
A customer failed KYC. Can they retry?
Yes. Each customer has three attempts. Read
failure_reason and resubmit only the failed part through the update endpoints. See KYC sharing.I'm not receiving webhooks.
I'm not receiving webhooks.
Check that the URL is registered, is public HTTPS, and returns
2xx within a few seconds. For local development, use a tunnel such as ngrok. Poll the order endpoint as a fallback. See Webhooks.Money and compliance
What are the fees?
What are the fees?
Pricing depends on volume, corridor and integration. Contact partnerships@zapyd.com. Every quotation returns the full
fees breakdown for that order.Can a user pay from someone else's bank account?
Can a user pay from someone else's bank account?
No. Payin funds must come from an account in the user’s KYC name. Third-party payments are rejected. See rules Zapyd enforces.
What is EDD and when does it apply?
What is EDD and when does it apply?
Enhanced Due Diligence is an extra review, triggered by volume thresholds, risk signals or a limit increase request. See Limits and EDD.