TillsafeDocstillsafe.comRequest early access

Connected wallet

Payers who use a browser wallet pay your payout address directly, matched by their address and a unique amount.

When the payer has a browser wallet (MetaMask or any EIP-6963 wallet on EVM networks, TronLink on TRON), the checkout offers Pay with wallet. The money then goes straight from the payer's wallet to your registered payout address: no deposit address, no forwarding, no sweep.

How a payment is matched without a deposit address

Many payers pay the same payout address, so the address alone cannot say who paid. Instead the checkout binds the payer's wallet to the invoice before they sign:

  1. The payer connects their wallet. The checkout calls POST /v1/checkout/invoices/{id}/wallet_binding with the asset and the payer's address (sender).
  2. The response names your payout address (treasury), the token contract, and an exact amount: the amount due plus a tiny suffix (steps of 0.000001, always less than one cent, sometimes zero) that no other open binding from the same wallet to that address on that chain shares.
  3. The checkout verifies the treasury against your pins, the token contract and the amount, then asks the wallet to sign an ordinary token transfer.
  4. A transfer is credited only when the chain, token, destination, sender, exact amount and time window all match one binding. Anything else is not guessed at.

The suffix stays with you: an excess under one cent never makes an invoice overpaid.

What you need

  • A registered payout address on the chain family (TRON, or EVM).
  • Pins, if your deposit addresses are your own (an EOA pool): the checkout compares the treasury against them, and refuses the wallet path without them. Pass them with the embed loader's pins option (see embedding the checkout).

Limits

  • A binding lasts until the invoice's window closes (plus the 10-minute grace), and only while the invoice is awaiting_payment.
  • At most 5 wallets per invoice and chain (wallet_binding_limit).
  • No Bitcoin: BTC invoices are paid by address and QR code.
  • On phones there is no WalletConnect: the checkout opens the invoice in the wallet's own in-app browser (MetaMask, Trust Wallet, TronLink).
  • TronLink cannot be switched between networks by a page: the payer must select the right one.