Frequently asked questions
What businesses ask most about 402pay, grouped by payments, webhooks, wallet, keys and billing.
- Payments and checkout What customers can pay with, and what happens when they pay the wrong amount. 8 questions
- Webhooks Deliveries that don't arrive, retries, and testing your handler. 4 questions
- Wallet Custody, deposits, and connecting a wallet you already use. 5 questions
- Keys and security Signing in, passwords, API keys, and what to do when one leaks. 8 questions
- Billing Rates, flat fees, your fee statement and how fees are collected. 4 questions
Looking up an error? See troubleshooting. Not sure what a term means? See the glossary.
Payments and checkout
402pay is a payment processing platform for businesses that want to accept cards and crypto through one checkout, without handing custody of their revenue to a third party.
Your team shares hosted checkouts or creates payments from your own systems through the API. Customers pay by card, Apple Pay, Google Pay or crypto, and every payment lands directly in a self-custody wallet your business controls.
There are no balances to withdraw, payout schedules or reserves: funds are yours as soon as the network confirms them.
No. Create a payment link in the dashboard and share it anywhere. When you're ready to integrate, the API and signed webhooks let you create payments from your own systems, and test keys let you rehearse every outcome before you go live.
USDC, USDT, Bitcoin, Ether and Solana, across Polygon, Ethereum, Solana, Tron and Bitcoin. You decide which ones checkout offers. See supported networks.
Yes. Enable cards in Settings and send customers to the payment or payment-link URL. Hosted checkout shows the available methods and opens a secure page for card details, the final total and any required identity checks.
Your deposit arrives in a supported coin and network. Read the payment's settlement details and fulfill the order after verifying
payment.succeeded. Checkout handles unsuccessful attempts and offers another try when available.A transfer short by no more than your underpayment tolerance, 0.5% unless you change it, counts as paid in full. Less than that makes the payment
underpaid: checkout asks the customer for the rest, and you can request it later or accept what arrived. More than the amount due lands in your wallet in full, andpayment.overpaidtells you the excess. See underpayments and overpayments.A transfer that arrives after the quote expired still reaches your wallet, but the rate no longer holds, so the payment becomes
needs_review. Accept it as it is, or send the funds back. See needs review.Refunds stay under your control: you send them from your wallet, in the asset and amount you choose, for card and crypto payments alike. There's no refund endpoint, since money never moves on an API key. See refunds, returns and disputes.
Cardholders can still dispute a card payment with their bank. You'll be asked for evidence, and a clear description of what customers are buying, with your refund policy shown at checkout, keeps disputes rare.
No. Every paid payment has a hosted receipt the customer sees after paying. Link to it, or send your own confirmation when your webhook hears the payment succeeded.
Webhooks
Every attempt is recorded with its signed request and your server's answer, which you can read in the dashboard under Developers, then Webhooks. Check that the endpoint is turned on, subscribes to the event type and answers over HTTPS. A local 402pay records deliveries without sending them. See troubleshooting webhooks.
A delivery gets 8 attempts in all, spread over about 28 hours and starting 5 seconds after the first one fails. After the last, resend it from the dashboard or with
POST /webhook-deliveries/{id}/resend.Yes.
GET /eventslists every event with a snapshot of its subject, whether or not a webhook delivered it, and any delivery can be resent.Send a test event from the dashboard or with
POST /webhooks/{id}/test. It's signed like any delivery, withtest: trueand a made-up subject whosedataholds only itsid, so skip it before you fulfill anything.
Wallet
No. 402pay is non-custodial. Payments land in a wallet whose keys only your business holds, so we can't move, freeze or reverse your funds.
As fast as the network allows. A crypto payment is in your wallet once it has the confirmations its network needs, typically seconds on Polygon or Solana and minutes on Bitcoin. Card payments follow the same network confirmations after the payment reaches its destination.
Yes. Connect it as an external wallet by its public keys: an xpub or zpub, or one fixed address, for each network family. Networks you leave out aren't offered at checkout, and sends happen in that wallet's own app. See wallet and deposits.
No. An API key can read balances and transactions, but sends happen only in the dashboard, signed in your browser with your encryption password. An external wallet sends from its own app.
402pay can't recover either one: the phrase is encrypted in your browser, and only the encrypted copy is stored. Back both up somewhere safe and offline before you take real payments.
Keys and security
Your team signs in with a passkey, or with an email and a password, confirmed by a code we email, plus optional two-step verification, and sees a list of every active session. We email you about new sign-ins, passkeys added or removed, and changes to your email, password or two-step verification. API keys can be limited to exactly what each integration needs, every webhook is signed, and your wallet's recovery phrase is encrypted in your browser before anything reaches us.
Use Forgot password on the sign-in page. We email a link that works once, for 30 minutes. If two-step verification is on, you'll also need a code from your app or a recovery code. Resetting signs out every device. If you've lost those too, contact us at support@402pay.co.
Check your spam folder. A minute after the last code, you can ask for a new one on the same page. Each code works for 15 minutes, and a sign-up waits a day to be confirmed. If you closed the page, sign in with the same email and password in the same browser to pick up where you left off, or open the link in the email.
Some changes decide where payments go or who can reach your business: adding or deleting the wallet, changing its encryption password, creating API keys or webhooks, changing a webhook's URL, adding or removing a passkey and deleting a business. If you haven't signed in or confirmed it's you in the last 15 minutes, the dashboard asks first: use a passkey, or your password and, when two-step verification is on, a code. We also email you whenever the wallet changes.
Yes. A restricted key gets none, read or write on each resource:
GETneeds read and every other method needs write. Give each integration only what it uses. See restricted keys.Create a new key in the dashboard under Developers, then API keys, deploy it, then revoke the old one, which stops working at once. Only a hash of each secret is stored, so a lost secret can't be shown again either. See security best practices.
Five wrong codes in a row lock that person's codes for 15 minutes, counted across every sign-in, so starting over doesn't help. Wait for the lock to end, then use a code from your authenticator or one of your recovery codes.
Five failed sign-ins in a row lock that email for a minute, and each further five lock it for longer, up to an hour. A browser you've signed in with before keeps its own count, so someone guessing from elsewhere can't lock you out of it. After 100 in a row from other browsers, the password stops working in them until it's reset, and we email the account. Signing in successfully or resetting the password clears the count.
Billing
An intro rate of 0% per crypto payment and 3% per card payment. On top of that, $0.25 per successful payment, and $5 a month for a self-custody wallet or $15 a month for an external one. There's no setup fee. See pricing for every add-on.
No. Every payment, by card or crypto, lands in your wallet whole. Its rate, in
reporting.fee, and the $0.25 per transaction, inreporting.transaction_fee, go on your fee statement with the wallet's monthly fee.reporting.netis what you keep once they're paid.You don't have to do anything. Once you owe $25.00, 402pay sends some of your payments to its own address instead of your wallet, whole, until what you owe is paid. Your customers pay as usual, and those payments show as collected as fees. An overpayment becomes credit for future fees. See fees and billing.
Yes. Under Settings, Payments, choose who pays 402pay's fees. When your customers do, checkout adds the rate for their method and the $0.25 flat fee to their total, worked out on your price, so you keep the whole price. Each payment shows it in
customer_fee, and an API payment can choose for itself withfee_payer. See passing fees on.