TillsafeDocstillsafe.comRequest early access

API reference

Version 1.0.0. Generated from the API's OpenAPI 3.1.0 description at build time.

Base URL https://api.tillsafe.com

Early access: keys are issued on request. The API is not open to the public yet. Request early access

Errors Every error's doc_url points into the error codes.

Tillsafe: non-custodial stablecoin and crypto payments.

  • Authenticate with Authorization: Bearer <secret key> (cp_test_sk_… / cp_live_sk_…). Test keys see only test-mode objects on testnets; live keys only live ones.
  • Every POST requires an Idempotency-Key header.
  • Money is always a decimal string plus an asset or currency code, never a JSON number.
  • Errors share one shape: {"error": {type, code, message, param, doc_url, request_id}}.
  • Webhooks are signed: x-cryptopay-signature: t=<unix>,v1=<hex HMAC-SHA256(secret, "{t}.{body}")>.

Authentication

publishable_key: Authorization: Bearer cp_{test|live}_pk_…

Publishable key: checkout endpoints only.

publishable_key_query: query parameter key

Publishable key as a query parameter (for EventSource). Secret keys are refused here.

secret_key: Authorization: Bearer cp_{test|live}_sk_…

Secret key. Server-side only; never in a browser or a URL.

Endpoints

Invoices

Requests for payment

Payments

On-chain transfers attributed to invoices

  • GET /v1/payments List payments (on-chain transfers attributed to invoices), newest first.

Webhooks

Delivery log and replay

Merchant

Settings for the key's mode

Checkout

Payer-facing, publishable-key endpoints

Reusable, shareable links that create one invoice per payer

Refunds

Non-custodial refunds: the payer claims, we screen, you send from your wallet

Reconciliation

The ledger vs the chain vs the invoices for a period, with every difference explained or flagged

Refund claims

Payer-facing; the claim token from the refund link is the credential

Test helpers

Test mode only: simulate chain activity

Health

Liveness and readiness

  • GET /healthz Liveness: the process is up and serving HTTP. Never touches dependencies.
  • GET /readyz Readiness: the payment service can take traffic.

Subscriptions

Plans, customers and invoice-based recurring billing: renewal invoices, reminders, retries, prepaid credit