Deposit addresses
Where an invoice's deposit address comes from, how long it belongs to the invoice, and who can move the money on.
Every invoice gets a deposit address that belongs to it alone while it is open. That exclusivity is how a payment is matched to its invoice without a transaction id (how payments are matched), and the kind of address decides who can move the money on.
The life of an address
- Lease. An address is leased to one invoice for 24 hours (or until the invoice is paid, expired or cancelled).
- Cooldown. After the lease it rests for 72 hours, still attributed to the same invoice, so a slow payment still lands where it should (as a late payment).
- Back in the pool. Only then can it be leased to another invoice. Two invoices never hold one address at the same time; the database refuses overlapping leases.
A transfer to an address outside any lease, or to a retired one, is not guessed at: it is held for a person to resolve, and the address is not leased again until it is.
On EVM networks an invoice has one address, the same on every EVM network your account uses, so a payment on the wrong one of those networks is still credited. TRON addresses are leased separately.
Where the addresses come from
| Kind | Chains | Who moves the money on | Availability |
|---|---|---|---|
| Forwarder | EVM, TRON | Anyone may trigger the forward, and it can only go to your registered payout address. The address is a CREATE2 contract address: its code is fixed, has no owner and no upgrade path. | Test mode only: the contracts are not deployed on a public network yet. |
| Your own addresses (an "EOA pool") | EVM, TRON | You do: these are ordinary wallet addresses you own. Tillsafe has no keys and cannot move the funds. See importing your addresses and sweeping. | Live and test mode. Live mode needs this today. |
| Your xpub | Bitcoin | A fresh address per invoice, derived from your account key. Funds land directly in your wallet. See Bitcoin with your xpub. | Test mode only, until a production price feed. |
| Connected wallet | EVM, TRON | No deposit address: the payer pays your payout address directly, from a wallet bound to the invoice with a unique amount. See connected wallet. | Live and test mode. |
Your payout addresses
Your registered payout addresses ("destinations") are where forwarders send the money and where
connected-wallet payments go. They are listed in registered_destinations on
GET /v1/merchant/settings, and they cannot be changed with an API key: a change goes through the
dashboard with a passkey confirmation, an email to every owner and admin, and a 24-hour delay. See
security model.
The checkout verifies every address
Before the checkout shows an address, it recomputes it on the payer's device from the option's
address_derivation, and refuses to show any address that fails. Your own addresses are only shown when
they are in your pins, so pass them with the embed loader. See
security model.