TillsafeDocstillsafe.comRequest early access

Importing your addresses

Use wallet addresses you already own as deposit addresses, so the keys never leave your hands.

Instead of forwarder contracts, your deposit addresses can be ordinary wallet addresses that you own: an EOA pool. Each invoice still leases one of them exclusively (see addresses and attribution), payers pay it, and the money stays on that address, under your keys, until you sweep it to your treasury. Tillsafe never has those keys.

During early access the import is done with you as part of onboarding; there is no API or dashboard page for it yet. This page is what to prepare.

What to provide

Either a list of addresses, as a text file with one address per line, or a CSV/TSV file with the address in the first column (,, ; or tab separated). Blank lines, # comments, quotes, a byte-order mark and one header row are fine.

Or an extended public key (xpub) and the index range to derive, for example indexes 0..500 (end-exclusive, at most 10,000 per import). Give the account path it belongs to when it is not the default (m/44'/195'/0' for TRON, m/44'/60'/0' for EVM). Before anything is written you get the derived addresses back, to compare with your wallet's.

Name the chain: TRON, an EVM network (BSC, Ethereum, Base, Arbitrum, Polygon), or Solana. Test-mode imports use the testnets, live imports the mainnets.

What is checked

  • Every address: TRON addresses are 34 characters starting with T with a valid checksum; EVM addresses are 0x and 40 hex digits, with a valid EIP-55 checksum when mixed-case. The zero address is refused.
  • Nothing is shared: an address already used by another merchant (on any chain), one of your forwarder addresses, or any merchant's payout address is refused.
  • All or nothing: one bad line fails the whole import, with every problem listed. Importing the same list again changes nothing.

Before go-live

  • A quiet period. Freshly imported addresses can be held for some hours (up to 30 days) before they are leased, so payments still arriving from their previous use are not mistaken for an invoice's.
  • Pins. The checkout only shows one of your own addresses when it is in your pins, so your embed's pins (or the checkout's configured pins) must list every imported address. Otherwise payers see an error instead of an address.
  • Retiring an address. An address you no longer control (lost key, frozen by the token issuer) can be retired permanently; it is never leased again.