Rules Zapyd enforces
Breaking these rules gets the order rejected, refunded or held. There’s no soft error.Checklist
Customers and KYC
- Customers are created with your
client_reference_id, and you store the Zapydid - Orders are blocked until the customer is
VERIFIED -
FAILEDKYC shows the user what to fix, and only the failed part is resubmitted - A customer blocked after three attempts is handled
Payins
- The rate, fees and
receiving_amountshown come from the quotation -
deposit_instructionscome from each quotation and are never cached - The transfer reference is collected and sent as
transaction_reference_id - Crypto is credited only on
SUCCESS, never onON_HOLD,FAILEDorREFUNDED
Payouts
- Asset, network and
wallet_addressare read from the quotation for every transfer - Per-order payouts are initiated with the matching
transaction_hash -
IN_REVIEWwith anrfi_linksends the customer to answer it - The UTR from
SUCCESSis shown to the user
Webhooks
- The signature and the timestamp window are checked on every event
- The endpoint returns
2xxfast and processes the event asynchronously - Events are deduplicated on
idandevent - Orders without a final status after a set time are polled, and you get an alert
Errors and operations
- Signing passes the test vector in a unit test
- Code branches on
err_code, and only429and5xxare retried, with backoff - Users never see raw
err_codevalues - Requests, Zapyd IDs and responses for money-moving calls are logged
Security
- The API secret lives in a secrets manager and never reaches a browser or mobile app
- Widget Initialize runs server-side, and only
widget_linkreaches the client - Sandbox and production credentials are kept separate
Switch to production
Get production credentials
Share your sandbox results with the Zapyd team. After review, you get production keys.
Change the configuration
Change the host from
sandbox.zapyd.com to api.zapyd.com. Swap the keys and the widget app_id. Move from Sepolia to mainnet networks. Register your production webhook URL.Remove sandbox-only code
Remove the mock status calls and your test customers.
Run a small live order
Complete one small real order in each direction you support, then roll out.