SDK PHP
Un file, nessuna dipendenza. createInvoice(), getInvoice() e verifyWebhook() — inseriscilo in qualsiasi progetto.
Un singolo SDK PHP senza dipendenze: crea fatture, reindirizza al checkout ospitato e verifica i webhook firmati. REST è disponibile per qualsiasi linguaggio.
api.payora.moneyUna chiamata API con un ID ordine e un importo in fiat o criptovaluta restituisce un URL di pagamento ospitato.
Scelgono una moneta, scansionano il QR o aprono un portafoglio, e il checkout conferma in tempo reale sulla finalità.
Verifica la firma HMAC, accredita l'ordine una volta e guarda il pagamento arrivare sul tuo saldo.
Un file, nessuna dipendenza. createInvoice(), getInvoice() e verifyWebhook() — inseriscilo in qualsiasi progetto.
Le richieste e i webhook sono firmati HMAC-SHA256 con skew di timestamp e chiavi di idempotenza.
JSON semplice su HTTPS — integra da qualsiasi stack, non solo PHP.
<?php
require 'Payora.php';
$payora = new Payora('https://api.payora.money', getenv('PAYORA_KEY'), getenv('PAYORA_SECRET'));
// 1 — create an invoice (fiat-priced; the payer picks a coin)
$inv = $payora->createInvoice([
'order_id' => 'ORDER-42',
'mode' => 'fiat',
'amount' => '9.99',
'return_url' => 'https://shop.example/thanks',
'lang' => 'en',
], 'ORDER-42'); // Idempotency-Key: a retry never creates a second invoice
header('Location: ' . $inv['pay_url']);
// 2 — webhook endpoint: ALWAYS verify the signature first
$event = $payora->verifyWebhook(file_get_contents('php://input'), getallheaders());
if ($event === null) { http_response_code(400); exit; }
if ($event['status'] === 'paid') {
creditOrderOnce($event['id'], $event['order_id'], $event['amount'], $event['currency']);
}
http_response_code(200); // 2xx stops retriesconst Payora = require('./payora');
const payora = new Payora('https://api.payora.money', process.env.PAYORA_KEY, process.env.PAYORA_SECRET);
// 1 — create an invoice and redirect
app.post('/checkout', async (req, res) => {
const inv = await payora.createInvoice({ order_id: 'ORDER-42', mode: 'fiat', amount: '9.99' }, 'ORDER-42');
res.redirect(inv.pay_url);
});
// 2 — webhook: verify over the RAW body
app.post('/payora/webhook', express.raw({ type: '*/*' }), (req, res) => {
const event = payora.verifyWebhook(req.body, req.headers);
if (event === null) return res.status(400).end();
if (event.status === 'paid') creditOrderOnce(event.id, event.order_id);
res.status(200).end();
});import os
from payora import Payora
payora = Payora('https://api.payora.money', os.environ['PAYORA_KEY'], os.environ['PAYORA_SECRET'])
# 1 — create an invoice and redirect
inv = payora.create_invoice({'order_id': 'ORDER-42', 'mode': 'fiat', 'amount': '9.99'}, 'ORDER-42')
return redirect(inv['pay_url'])
# 2 — webhook: verify over the RAW body
event = payora.verify_webhook(request.get_data(), dict(request.headers))
if event is None:
return ('', 400)
if event['status'] == 'paid':
credit_order_once(event['id'], event['order_id'])
return ('', 200)# signature = lowercase hex HMAC-SHA256(api_secret, timestamp + "." + raw_body)
BODY='{"order_id":"ORDER-42","mode":"fiat","amount":"9.99"}'
TS=$(date +%s)
SIG=$(printf '%s.%s' "$TS" "$BODY" | openssl dgst -sha256 -hmac "$PAYORA_SECRET" | cut -d' ' -f2)
curl -X POST https://api.payora.money/v1/invoice \
-H "X-Payora-Key: $PAYORA_KEY" -H "X-Payora-Timestamp: $TS" \
-H "X-Payora-Signature: $SIG" -H 'Idempotency-Key: ORDER-42' \
-H 'Content-Type: application/json' -d "$BODY"
# → 201 { "invoice_id": …, "status": "pending", "pay_url": "https://pay.payora.money/i/…", "expires": … }Ottieni la tua chiave API e il segreto creando un account. Il SDK completo è nel tuo dashboard.
Every call except /v1/health carries three signed headers. The signature proves the request comes from the holder of your api_secret and was not changed on the way.
| Intestazione | Valore | Descrizione |
|---|---|---|
X-Payora-Key | pk_… | Il tuo api_key pubblico. Identifica il negozio. |
X-Payora-Timestamp | unix seconds | Il momento in cui hai firmato la richiesta, in secondi Unix. |
X-Payora-Signature | hex · 64 | HMAC-SHA256 esadecimale in minuscolo di timestamp + "." + corpo raw, chiave con il tuo api_secret. |
X-Payora-Test | 1 | Segna una fattura come un test della tua integrazione: è reale e può ricevere monete, ma rimane esclusa dai rapporti di domanda e conversione. |
Idempotency-Key | string | Opzionale su POST /v1/invoice e POST /v1/payout. Un tentativo con la stessa chiave restituisce il primo risultato invece di creare un duplicato; la stessa chiave con un corpo diverso risponde 409. |
Content-Type | application/json | Richiesto su richieste che portano un corpo. |
hex( HMAC-SHA256( api_secret, timestamp + "." + raw_body ) )Firma esattamente i byte che invii. La ricodifica del JSON dopo la firma — anche riordinando le chiavi o aggiungendo uno spazio — rompe la firma.
Per una richiesta GET il corpo è vuoto, quindi la stringa firmata è il timestamp seguito da un punto.
L'API rifiuta un timestamp più di 120 secondi lontano dal suo orologio. Tieni il tuo server sincronizzato con NTP.
Tieni api_secret sul tuo server. Firma richieste e webhook allo stesso modo: chiunque lo detenga può creare fatture a tuo nome e falsificare callback.
<?php
$body = json_encode(['order_id' => 'ORDER-42', 'mode' => 'fiat', 'amount' => '9.99'], JSON_UNESCAPED_SLASHES);
$ts = (string) time();
$sig = hash_hmac('sha256', $ts . '.' . $body, $apiSecret); // lowercase hex
$ch = curl_init('https://api.payora.money/v1/invoice');
curl_setopt_array($ch, [
CURLOPT_POST => true, CURLOPT_POSTFIELDS => $body, CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'X-Payora-Key: ' . $apiKey,
'X-Payora-Timestamp: ' . $ts,
'X-Payora-Signature: ' . $sig,
'Idempotency-Key: ORDER-42',
'Content-Type: application/json',
],
]);
$invoice = json_decode(curl_exec($ch), true);const crypto = require('crypto');
const body = JSON.stringify({ order_id: 'ORDER-42', mode: 'fiat', amount: '9.99' });
const ts = String(Math.floor(Date.now() / 1000));
const sig = crypto.createHmac('sha256', API_SECRET).update(ts + '.' + body).digest('hex');
const res = await fetch('https://api.payora.money/v1/invoice', {
method: 'POST',
headers: {
'X-Payora-Key': API_KEY,
'X-Payora-Timestamp': ts,
'X-Payora-Signature': sig,
'Idempotency-Key': 'ORDER-42',
'Content-Type': 'application/json',
},
body, // send exactly the bytes you signed
});import hashlib, hmac, json, time, urllib.request
body = json.dumps({'order_id': 'ORDER-42', 'mode': 'fiat', 'amount': '9.99'}, separators=(',', ':'))
ts = str(int(time.time()))
sig = hmac.new(API_SECRET.encode(), (ts + '.' + body).encode(), hashlib.sha256).hexdigest()
req = urllib.request.Request('https://api.payora.money/v1/invoice', data=body.encode(), method='POST', headers={
'X-Payora-Key': API_KEY,
'X-Payora-Timestamp': ts,
'X-Payora-Signature': sig,
'Idempotency-Key': 'ORDER-42',
'Content-Type': 'application/json',
})
invoice = json.load(urllib.request.urlopen(req))# GET has an empty body: the signed string is just the timestamp and a dot
TS=$(date +%s)
SIG=$(printf '%s.' "$TS" | openssl dgst -sha256 -hmac "$PAYORA_SECRET" | cut -d' ' -f2)
curl https://api.payora.money/v1/invoice/1042 \
-H "X-Payora-Key: $PAYORA_KEY" \
-H "X-Payora-Timestamp: $TS" \
-H "X-Payora-Signature: $SIG"Tutti opzionali tranne order_id e amount. La modalità fiat consente al pagatore di scegliere qualsiasi moneta abilitata sul tuo account; la modalità crypto richiede anche currency.
| Parametro | Tipo | Descrizione |
|---|---|---|
order_id | string · required | Il tuo riferimento d'ordine unico (≤190 caratteri). Una ripetizione viene rifiutata con 409 — sicura contro invii doppi. |
amount | string · required | Importo fiat (mode=fiat) o importo crypto esatto (mode=crypto). |
mode | fiat | crypto | Fiat predefinito: tasso bloccato per moneta al checkout. La crypto fissa la moneta + l'importo in anticipo. |
fiat_currency | string | Codice fiat ISO per la modalità fiat (predefinito USD). |
currency | string | Moneta per la modalità crypto (es. TON, TRX, USDT_TRON). |
return_url | https URL | Dove il pulsante “Return to store” del checkout riporta il cliente indietro — il tuo sito. Solo http(s) assoluto. |
lang | en·ru·uk·es·de | Lingua del checkout, quindi un cliente del tuo negozio russo vede il checkout russo — non in inglese. Impostabile anche come ?lang=ru sull'URL di pagamento. |
ttl | seconds | Quanto tempo la fattura rimane pagabile (120–86400 secondi, default 1800). |
customer_email | Opzionale — ricevuta + inviata via email al pagatore. | |
notes | string | Nota libera memorizzata sulla fattura. |
return_url e lang funzionano anche come parametri di query aggiunti al pay_url fornito dall'API — <pay_url>&lang=ru&return_url=https://shop.example/thanks. Invia sempre l'acquirente al pay_url restituito dall'API: contiene un token di accesso unico per fattura, quindi una pagina di checkout non può essere raggiunta indovinando i numeri delle fatture. Non ricostruire il link dall'id della fattura.
Compila i campi e copia un comando cURL pronto. Si firma da solo nella tua shell con $PAYORA_KEY e $PAYORA_SECRET — questa pagina non vede mai le tue chiavi e non invia nulla.
BODY='{"order_id":"ORDER-42","mode":"fiat","amount":"9.99","fiat_currency":"USD","return_url":"https://shop.example/thanks","lang":"it","ttl":1800}'
TS=$(date +%s)
SIG=$(printf '%s.%s' "$TS" "$BODY" | openssl dgst -sha256 -hmac "$PAYORA_SECRET" | cut -d' ' -f2)
curl -X POST https://api.payora.money/v1/invoice \
-H "X-Payora-Key: $PAYORA_KEY" \
-H "X-Payora-Timestamp: $TS" \
-H "X-Payora-Signature: $SIG" \
-H 'Idempotency-Key: ORDER-42' \
-H 'Content-Type: application/json' \
-d "$BODY"Niente viene inviato da questa pagina.
Quando una fattura o un pagamento cambia stato, Payora invia un evento JSON firmato al tuo URL di callback. Verifica prima la firma, accredita l'ordine una volta, rispondi 2xx.
| Evento | status | Quando si attiva |
|---|---|---|
invoice.paid | paid | Il pagamento è confermato on-chain. Contiene l'importo, la moneta e tx_hash. |
invoice.underpaid | underpaid | La fattura è scaduta dopo che è arrivato meno dell'importo previsto. |
invoice.expired | expired | La fattura è scaduta senza ricevere nulla. |
invoice.cancelled | cancelled | La fattura è stata annullata. Il denaro che era già arrivato, se presente, è descritto nell'evento. |
invoice.cancel_settled | — | Il denaro che è arrivato su una fattura annullata è stato gestito: accreditato o restituito. |
invoice.late_payment | — | Denaro che è arrivato su una fattura dopo che è stata annullata. Inviato una sola volta per ogni deposito di questo tipo; il risultato indica se è stato accreditato o se viene restituito. |
payout.sent | sent | Un lotto di pagamento è stato firmato e trasmesso. Contiene ogni elemento con il suo tx_hash. |
| Intestazione | Valore | Descrizione |
|---|---|---|
X-Payora-Id | uuid | ID evento unico, lo stesso di id nel corpo. Conservalo per ignorare i ripetuti. |
X-Payora-Event | invoice.paid | Nome dell'evento. |
X-Payora-Timestamp | unix seconds | Quando questo tentativo è stato firmato. |
X-Payora-Signature | hex · 64 | Stessa modalità delle richieste: HMAC-SHA256 di timestamp + "." + corpo raw con il tuo api_secret. |
| Campo | Tipo | Descrizione |
|---|---|---|
id | uuid | ID evento per la deduplicazione. |
event | string | Nome dell'evento. |
invoice_id | int | Numero fattura Payora. |
order_id | string | Il tuo riferimento ordine, come inviato quando è stata creata la fattura. |
status | string | paid per invoice.paid. |
currency | string | Moneta utilizzata dal pagatore, ad es. USDT_TRON. |
amount | decimal string | Importo ricevuto. |
amount_units | integer string | Lo stesso importo nelle unità più piccole della moneta — usalo per confronti esatti. |
expected | decimal string | Importo richiesto dalla fattura. |
fiat_amount | decimal string | null | Prezzo fiat della fattura come l'hai creata; null per le fatture in modalità crypto. |
fiat_currency | string | null | Codice ISO di fiat_amount; null per le fatture in modalità crypto. |
tx_hash | string | Hash della transazione on-chain. |
paid_at | unix seconds | Quando è stato creato l'evento. |
test | bool | true per fatture sandbox. |
{
"id": "6f1c2a4e-8b0d-4c1e-9a57-2f3d9e1b7c40",
"event": "invoice.paid",
"invoice_id": 1042,
"order_id": "ORDER-42",
"status": "paid",
"currency": "USDT_TRON",
"amount": "9.99",
"amount_units": "9990000",
"expected": "9.99",
"fiat_amount": "9.99",
"fiat_currency": "USD",
"tx_hash": "3f9a…c21e",
"paid_at": 1758038400,
"test": false
}Quando l'importo ricevuto differisce dalla fattura, amount_received e amount_expected vengono aggiunti.
Qualsiasi cosa diversa da 2xx, o nessuna risposta entro 15 secondi, viene ripetuta con un backoff esponenziale limitato a un'ora tra i tentativi — fino a 12 tentativi. Ogni tentativo è nuovamente firmato con un nuovo timestamp; il corpo e l'ID evento rimangono gli stessi, quindi deduplica per ID.
Dopo l'ultimo tentativo, l'evento è contrassegnato come fallito e il proprietario del negozio riceve un'email. I reindirizzamenti non vengono mai seguiti e l'URL di callback deve essere raggiungibile da Internet — niente indirizzi localhost o privati.
hash_equals, crypto.timingSafeEqual, hmac.compare_digest.<?php
require 'Payora.php';
$payora = new Payora('https://api.payora.money', getenv('PAYORA_KEY'), getenv('PAYORA_SECRET'));
$raw = file_get_contents('php://input'); // raw, before any parsing
$event = $payora->verifyWebhook($raw, getallheaders()); // HMAC + ±300 s window, constant-time
if ($event === null) { http_response_code(400); exit; } // bad / forged / stale
if ($event['event'] === 'invoice.paid' && !alreadyProcessed($event['id'])) {
creditOrder($event['order_id'], $event['amount'], $event['currency'], $event['tx_hash']);
rememberProcessed($event['id']);
}
http_response_code(200); // 2xx stops retries// Express: capture the RAW body for this route
app.post('/payora/webhook', express.raw({ type: '*/*' }), (req, res) => {
const event = payora.verifyWebhook(req.body, req.headers); // HMAC + ±300 s, timingSafeEqual
if (event === null) return res.status(400).end();
if (event.event === 'invoice.paid' && !alreadyProcessed(event.id)) {
creditOrder(event.order_id, event.amount, event.currency, event.tx_hash);
rememberProcessed(event.id);
}
res.status(200).end(); // 2xx stops retries
});# Flask: request.get_data() is the exact raw body
@app.post('/payora/webhook')
def payora_webhook():
event = payora.verify_webhook(request.get_data(), dict(request.headers))
if event is None:
return ('', 400) # bad / forged / stale
if event['event'] == 'invoice.paid' and not already_processed(event['id']):
credit_order(event['order_id'], event['amount'], event['currency'], event['tx_hash'])
remember_processed(event['id'])
return ('', 200) # 2xx stops retries# Recompute the signature of a delivery you saved byte-for-byte to body.json
TS='1758038400' # X-Payora-Timestamp
SIG='…' # X-Payora-Signature
EXPECTED=$(printf '%s.' "$TS" | cat - body.json | openssl dgst -sha256 -hmac "$PAYORA_SECRET" | cut -d' ' -f2)
[ "$EXPECTED" = "$SIG" ] && echo valid || echo forgedInserisci un segreto, un timestamp e il corpo raw per vedere la firma esatta che Payora invierebbe — o controlla una che hai ricevuto.
Funziona nel tuo browser con WebCrypto. Nulla di ciò che digiti lascia questa pagina. Usa un segreto di test, non uno reale, su un computer condiviso.
1758038400.{…}X-Payora-Timestamp: 1758038400
X-Payora-Signature: …Incolla una firma da confrontare
Invia crypto a un massimo di 500 portafogli in una richiesta firmata e idempotente — per payroll, pagamenti affiliati o prelievi. Il totale del batch più la commissione per articolo è trattenuto sul tuo internal balance istantaneamente; il operatore firma e trasmette, quindi si attiva un webhook firmato payout.sent. Stessa autenticazione HMAC come tutto il resto.
# create a payout batch — funds held instantly, sent by the operator
curl -X POST https://api.payora.money/v1/payout \
-H 'X-Payora-Key: pk_…' -H 'X-Payora-Timestamp: 1700000000' \
-H 'X-Payora-Signature: <hmac-sha256>' -H 'Idempotency-Key: payroll-2026-01' \
-d '{"currency":"USDT_TRON","items":[
{"address":"TR7…","amount":"250.00"},
{"address":"TX9…","amount":"99.50","tag":"batch-A"}]}'
# → 201 Created
{ "batch_id": 812, "status": "pending", "currency": "USDT_TRON",
"item_count": 2, "total": "349.50", "fee": "…", "items": [ … ] }
# poll status, or receive a signed payout.sent webhook when it is sent
curl https://api.payora.money/v1/payout/812 -H 'X-Payora-Key: …' …<?php
// The one-file PHP SDK covers invoices and webhooks; payouts are one signed POST.
$body = json_encode(['currency' => 'USDT_TRON', 'items' => [
['address' => 'TR7…', 'amount' => '250.00'],
['address' => 'TX9…', 'amount' => '99.50', 'tag' => 'batch-A'],
]], JSON_UNESCAPED_SLASHES);
$ts = (string) time();
$sig = hash_hmac('sha256', $ts . '.' . $body, $apiSecret);
$ch = curl_init('https://api.payora.money/v1/payout');
curl_setopt_array($ch, [CURLOPT_POST => true, CURLOPT_POSTFIELDS => $body, CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ['X-Payora-Key: ' . $apiKey, 'X-Payora-Timestamp: ' . $ts, 'X-Payora-Signature: ' . $sig,
'Idempotency-Key: payroll-2026-01', 'Content-Type: application/json']]);
$batch = json_decode(curl_exec($ch), true); // 201: batch_id, status, totals, fee, itemsconst batch = await payora.createPayout({
currency: 'USDT_TRON',
items: [
{ address: 'TR7…', amount: '250.00' },
{ address: 'TX9…', amount: '99.50', tag: 'batch-A' },
],
}, 'payroll-2026-01'); // Idempotency-Key: a retried run never doubles
const status = await payora.getPayout(batch.batch_id);
// still pending? await payora.cancelPayout(batch.batch_id) releases the holdbatch = payora.create_payout({
'currency': 'USDT_TRON',
'items': [
{'address': 'TR7…', 'amount': '250.00'},
{'address': 'TX9…', 'amount': '99.50', 'tag': 'batch-A'},
],
}, 'payroll-2026-01') # Idempotency-Key: a retried run never doubles
status = payora.get_payout(batch['batch_id'])
# still pending? payora.cancel_payout(batch['batch_id']) releases the holdLa validazione è rigorosa: qualsiasi indirizzo errato o importo eccessivamente preciso rifiuta l'intero lotto (HTTP 422) con gli indici degli elementi problematici — un pagamento stipendiale non elimina mai silenziosamente un destinatario. Annulla un lotto ancora in attesa con POST /v1/payout/{id}/cancel per rilasciare la sospensione. Vedi il documento sull'architettura.
Ogni endpoint parla JSON semplice su HTTPS a api.payora.money. Tutti tranne /v1/health utilizzano la stessa autenticazione della richiesta HMAC-SHA256. La specifica leggibile dalla macchina si trova su openapi.json.
| Endpoint | Accesso | Descrizione |
|---|---|---|
GET/v1/health | no auth | Stato del servizio più l'elenco delle valute abilitate. |
POST/v1/invoice | auth | Crea una fattura (modalità fiat o crypto). Supporta Idempotency-Key. Restituisce 201 con invoice_id, status, pay_url e expires; la modalità crypto aggiunge l'indirizzo, l'importo e il deeplink. |
GET/v1/invoice/{id} | auth | Stato della fattura (solo fatture proprie): status, remaining, e il charge — valuta, indirizzo, importi attesi/ricevuti e tx_hash. |
POST/v1/payout | auth · Pro+ | Crea un lotto di pagamento di massa (validazione rigorosa, fondi trattenuti immediatamente). Supporta Idempotency-Key. Restituisce 201 con la vista del lotto: batch_id, status, totali, commissione, articoli. |
GET/v1/payout | auth | Elenca i tuoi recenti lotti di pagamento (?limit=, predefinito 50). |
GET/v1/payout/{id} | auth | Stato del lotto di pagamento e articoli (solo lotti propri). |
POST/v1/payout/{id}/cancel | auth | Annulla un lotto ancora in attesa e rilascia il saldo trattenuto. Restituisce 409 se il lotto non è più cancellabile. |
Nessun endpoint corrisponde.
File singoli senza dipendenze. Ogni SDK firma le richieste e verifica i webhook allo stesso modo.
PHP 7.4+ con cURL, un file. createInvoice, getInvoice e verifyWebhook.
Node.js con https e crypto integrati solo. Fatture, saldo, pagamenti e verifyWebhook.
Solo libreria standard di Python. Fatture, saldo, pagamenti e verify_webhook.
Una collezione Postman che firma ogni chiamata per te.
La specifica leggibile dalla macchina di ogni endpoint, per generatori di codice e client API.
Un modulo pronto fa tutto quanto sopra per te: fattura, reindirizzamento e un webhook verificato.
Risposte dirette, comprese quelle scomode: custodia, commissioni e cosa succede quando qualcosa va storto.
Centro assistenzaInstalla il PHP SDK in un unico file (senza dipendenze) o chiama direttamente l'API REST. Crea una fattura con createInvoice(), reindirizza il cliente al suo pay_url e gestisci un evento webhook: status=paid. Un sviluppatore competente è attivo in 30–60 minuti.
Sì. Tutto è semplice JSON su HTTPS, quindi puoi integrare da qualsiasi linguaggio. Il PHP SDK è un wrapper di convenienza attorno agli stessi endpoint — crea fattura, ottieni fattura e verifica le firme dei webhook.
Sì. Passa return_url quando crei la fattura (o ?return_url= sul link di pagamento) e il checkout mostra un pulsante “Torna al negozio” per tornare al tuo sito nella schermata di successo — e mentre si paga. Passa lang (en, ru, uk, es, de), o ?lang= sul link, in modo che un cliente del tuo negozio russo atterri sul checkout russo invece che in inglese. Entrambi sono opzionali; return_url deve essere un URL http(s) assoluto.
Le richieste e i webhook sono autenticati con HMAC-SHA256 sul timestamp e sul corpo raw utilizzando il tuo api_secret, con una finestra di skew di ±120 secondi e chiavi di idempotenza. Le firme vengono confrontate in tempo costante per prevenire attacchi di timing.
Crea un account gratuito. La tua api_key pubblica e il tuo api_secret segreto appaiono nel dashboard, insieme al SDK scaricabile e alla completa referenza dei webhook. Ruota le chiavi in qualsiasi momento dalle impostazioni.
Un evento JSON firmato con l'id della fattura, il tuo order_id, lo stato (ad esempio pagato), l'importo e la valuta, e un id evento unico per l'idempotenza. Verifica sempre la firma prima di accreditare un ordine, quindi registra l'id evento per evitare elaborazioni duplicate nei tentativi.
Sì. POST /v1/payout invia crypto a un massimo di 500 wallet in una richiesta — un {indirizzo, importo, tag opzionale} per elemento, in qualsiasi moneta abilitata sul tuo account. Utilizza la stessa autenticazione HMAC-SHA256 e Idempotency-Key dell'API delle fatture, quindi una richiesta ripetuta non crea mai un lotto duplicato. Il totale del lotto più la commissione per elemento è riservato sul tuo saldo immediatamente; l'operatore firma e trasmette, quindi si attiva un webhook di pagamento firmato. La validazione è rigorosa — qualsiasi indirizzo non valido o importo eccessivamente preciso rifiuta l'intero lotto (422) quindi un'operazione di pagamento non scarta mai silenziosamente un destinatario.
Crea l'elenco dei destinatari nel tuo sistema, quindi chiama POST /v1/payout una volta per esecuzione con una Idempotency-Key stabile (ad esempio payroll-2026-01). Interroga GET /v1/payout/{id} o aspetta il webhook payout.sent per confermare la consegna e registrare ogni tx hash. Inviare il batch riserva fondi ma non li sposta da solo — l'operatore firma e trasmette, quindi nulla esce con una sola chiamata API.
Un singolo SDK PHP senza dipendenze: crea fatture, reindirizza al checkout ospitato e verifica i webhook firmati. REST è disponibile per qualsiasi linguaggio.