The one-sentence version
Your customer pays into a contract that can only pay you, and you withdraw from it whenever you want.The full flow
Step by step
Your pool gets created
A pool is a small contract that belongs to you. When it’s created, your payout address is baked into it permanently.Two signatures, both yours. The first is free: an off-chain message from your payout wallet, proving you control the address before it is written into the pool’s immutable code. The second is the deploy itself — a wallet-paid transaction you broadcast, with a live network-fee estimate shown first, one per chain you want to accept on. Nothing is fronted on your behalf and nothing comes back out of your share later for it.
A customer reaches checkout
You call our API for a quote, or the embedded widget does it for you. The quote locks a price for a short window and produces a payment identifier.
The checkout verifies us
Before showing a single payment option, the widget reads your payout address directly from the blockchain and re-computes what your pool address should be.If that doesn’t match what our servers said, the checkout stops and tells the customer not to pay. This is the mechanism that means a breach of our database still cannot redirect your money. How the verification works.
The customer pays
Either by connecting a wallet and signing, or by sending a plain transfer to a one-time address we show them. The two ways to pay.
We confirm and tell you
We watch the chain. Once the payment is final — not merely seen — you get a webhook. Ship when the payment is captured: the point at which the customer’s transfer has reached the required confirmation depth and the money can only reach your pool.If the customer sent a plain transfer, capture is
pool.deposit.confirmed, and pool.swept follows once we’ve moved the funds into your pool. If they paid by connecting a wallet, pool.swept is both the capture and the only event. The one exception is payer screening set to Enforce, where you wait for pool.swept on both. We also send pool.distributed when a balance is released, plus pool.refunded and pool.tamper_suspected. Finality.The balance pays out
Payments accumulate in your pool and normally leave it without you doing anything: our keeper runs every few minutes and, on your settlement schedule (by default, at least once every 24 hours after funds land), splits the balance and sends your share to your payout address.If you want it sooner, the Pool tab has Release now to split the balance and Withdraw to move your share. Those are two separate transactions today, not one button. Claiming.
Who controls what
Nobody can block your withdrawal, including us — the function that releases funds is callable by anyone. That’s deliberate. A processor that could freeze your funds is a custodian, with everything that implies.
Things that surprise people
There are no chargebacks — in both directions
There are no chargebacks — in both directions
Nobody can reverse a payment against you. You also cannot reverse one yourself. Refunds are something you send manually, from your own wallet, to an address the customer gives you. Refunds.
Money accumulates rather than arriving per order
Money accumulates rather than arriving per order
Payments pile up in your pool and the balance is released in batches — one settlement transaction for a hundred orders instead of a hundred. On the automatic schedule that doesn’t change what it costs you at all: our keeper fronts and absorbs that gas, whatever the batch size, and nothing is carved out of your share for it. It only saves you money on a withdrawal you sign and pay for yourself. You choose the cadence.
A payment that arrives late is still honoured
A payment that arrives late is still honoured
Quotes expire, but we keep watching the payment address for a bounded window — 7 days by default, configurable from one hour up to seven. On EVM chains, a payment arriving inside that window is still credited; it’s marked as paid late rather than clean, but the money reaches you. The chain is the source of truth, not our quote timer.Two limits worth knowing. On TRON, monitoring stops when the quote expires — one hour by default — so a slow exchange withdrawal that lands after that isn’t picked up automatically and needs us to recover it. And on any chain, a payment sent to an address whose order has already settled isn’t detected automatically either. Roadmap.
Who pays the network fees
Who pays the network fees
We front gas in exactly one place, and it’s the one place we also recover it from: the deposit rail. When a customer sends a plain transfer, our keeper fronts the gas to deploy the one-time address and sweep it into your pool, and recovers that by holding back a small network fee — capped on-chain at 10% of what arrived, fixed into that address before the customer is ever shown it, and verified by their own browser before they pay. It’s a per-payment deduction taken at the forwarder, not a cut of your share at settlement.Everything else, you pay for directly, or we absorb without recovering it:
- Deploying your pool is your wallet-paid transaction — one signature and one network fee per chain you activate.
- Automatic settlement — our keeper calling
distribute()andclaim()on your schedule — runs on our gas, and we don’t recover it. Nothing is carved out of your share for it. - A manual Withdraw or Release now, if you press it yourself, is your transaction and your network fee, in that chain’s native token.
Now build it
The quickstart takes about 15 minutes.