Resources
Frequently asked questions
The questions merchants ask before integrating, answered with what is true of the platform today. Anything that depends on your business — rates, methods, limits — is answered by a person after underwriting, not here.
Can I open an account myself?
No. Onboarding is underwritten, so there is no self-serve signup. The form at /get-started asks about ten questions — what you sell, where your customers are, how you settle, your dispute history — and a person answers with what we can do. Submitting it does not create an account.
Is the sandbox free, and do I need a contract to use it?
The sandbox is free and available from the moment an account is created, before any contract is signed. It issues test API keys, publishes the magic card numbers that produce each outcome, simulates a 3-D Secure challenge, and delivers real signed webhooks to your endpoint.
Do you store card numbers?
No. Card details are entered into hosted fields or the hosted payment page, never into your servers or ours in storable form. What is kept against a payment is the brand, the last four digits, the issuing range, the expiry, the issuer country, the funding type and a fingerprint.
Are webhooks signed?
Yes. Every delivery carries a Cleared-Signature header with a timestamp and one HMAC per active signing secret, computed over the raw request body. Verify it against the raw body before parsing the JSON, and reject a timestamp more than five minutes old. Reference implementations in Node, Python and PHP are published in the documentation.
What happens when I roll a key or a signing secret?
Both are designed so a rotation causes no failed requests. A rolled signing secret keeps verifying for 24 hours, during which deliveries are signed with the old and the new secret. A rolled API key keeps working for a grace window you choose. Secrets are shown exactly once, at creation, and stored as hashes after that.
What happens if my endpoint is down when an event fires?
The event is stored first and delivered after. Failed deliveries are retried on a fixed schedule from ten seconds out to 24 hours, stopping 72 hours after the event, after which the event is dead-lettered and the account owner is emailed. Every attempt is visible with its HTTP status, duration and response body, and any event can be resent by hand.
Can I safely retry a request that timed out?
Yes, if you send an Idempotency-Key with it. A replay with the same key returns the stored response rather than creating a second payment, and carries a header saying it was a replay. The same key sent with a different payload is refused rather than guessed at.
How many payment methods are there, and can I have all of them?
There are 55 methods in the catalogue, across cards, wallets, bank transfer and open banking, buy now pay later, vouchers and crypto rails. Which of them you can use depends on your markets, your business and the outcome of underwriting, so the answer to that part comes from a person rather than a page.
Why is there no public rate card?
Because a rate that does not depend on what you sell, where you sell it and what your disputes look like would be wrong for almost everyone. The pricing page publishes indicative bands and what drives a rate; the number itself comes with the underwriting answer.